Get Support
Recently active
Hello, looking for some help/advice.Has anyone successfully deployed the Dameware Remote Everywhere Agent?Does anyone have a working script they could share?We have created the bulk agent and have the ID, but no success.Thanks for any info.
I need help with standard user elevation as user should be able to forget the Wi-Fi networks as they required. in my case if it asks for admin credentials to forget the network.is there any privilege management feature in jamf?
Hi everyone,I'm currently preparing to move about 500 devices from Jamf to another MDM. I've made sure all devices are updated to macOS and iOS/iPadOS 26 and have tested moving a few devices to confirm that it works without deleting them first.The question is, is there any way to see if they have been moved in Jamf? And if so, trigger a cleanup somehow?
Does anyone know if there is a to turn this setting off without admin credentials?Through terminal command or config profile? Thanks!
Evening All I have spent the best part off 3 months backwards and forwards with jamf support. Over why bootstrap tokens don't always get escrowed back to jamf pro during our enrollment process.My team off 3, have manual been through our 300 labs devices, to tidy up any machines that dont have a bootstrap token escrowed to Jamf. We did setup and extension attribute to try populate a smart group but this wasn't very reliable. It does seem this information isn't getting back to jamf during a inventory update.I'm still no closer in finding the root cause. As anyone else experienced this type of issue? I'm also after a script to create bootstrap token on the fly. As I'm moving onto sorting out our staff Devices next and don't want to recall them if I can help it.Thanks in advanceTom
We're excited to announce two new benchmarks have been added to Compliance Benchmarks in Jamf Pro to support Dutch government security requirements: NLMAPGOV Base – Establishes foundational security controls for Apple devices within Dutch government organizations, implementing essential protections aligned with the Government Information Security Baseline 2 (BIO2) requirements.NLMAPGOV Plus – Provides enhanced security controls for Apple devices in Dutch government environments, building upon the base protections with additional safeguards to meet elevated BIO2 compliance requirements and risk profiles.Both benchmarks align with BIO2, the mandatory standards framework for information security across all Dutch government organizations, ensuring unified risk-based controls in compliance with international ISO/IEC 27001:2023 and 27002:2022 standards and EU NIS2 Directive requirements. These benchmarks are available now in Jamf Pro's built-in Compliance Benchmarks feature, enabling Dutch g
The user is unable to elevate their privileges to an admin role using Self Service / Jamf Connect.When attempting to elevate, the following notification is displayed:Jamf ConnectA change in the system time has been detected.For more information, please contact your administrator.I verified that: Date and time are set to automatic Time zone is set correctly No manual time changes were performed by the user Despite this, Jamf Connect continues to block privilege elevation.Relevant Jamf Connect logs indicate a time-tampering detection eventTimestamp: 2026-02-10 09:35:29 +0000, Sender: Jamf Connect, subsystem: com.jamf.connect, Process: Jamf Connect, Category: PrivilegeElevation, Contents: temporary admin reason: Installation de logicielTimestamp: 2026-02-10 09:35:29 +0000, Sender: JCDaemon, subsystem: com.jamf.connect.daemon, Process: JCDaemon, Category: PrivilegeElevation, Contents: user is blocked from further elevations due to system time tamperingTimestamp: 2026-02-10 09:35:29 +00
Our students are cheating on test using the Keyboard setting “Show math results”. I created a ticket with Jamf but they told me the only way to fix this is to use Blueprints but we are not set up with SSO. Is there another way of fixing this issue. Some very important state test are coming and our students are spreading the word on how to cheat.
Hi to all i've followed instruction on this link https://www.jamf.com/blog/help-users-activate-microsoft-office-365-and-configure-outlook-in-one-click/ to activate office 365 versione 16.94 on mac but office apps are not signed and when i open outlook the account has not be setted. In profile setting on the mac the parameter $email has been setted correctly with the email address settted on jamf inventory. There is something wrong? Thanks for your help
This has come to my attention recently. So basically, our users would change their password via jamf connect, it would go through and successfully change their azure ad password. Then once they login to the computer, it would give them a prompt, telling them to enter their old password for the local account to sync with the new azure ad account, we also have filevault enabled. This was all working fine, but recently when an end user changes their password via jamf connect. It gives an error message (I didn’t see it yet, have to wait until someone changes their PW again) and it will act like it doesn’t go through, but it actually does go through. It will not update their jamf connect expiration date (For example now, some users say their passwords will expire in -10 days) even though they changed their azure ad password. Now we have had users getting locked out of filevault because when they sign out or restart their computer and are on the filevault page, the local account password doe
We’ll use Google Chrome and Mozilla Firefox for this questionI’m learning how to use Jamf Setup Manager. I followed the directions on GitHub but I made some changes. I have Google Chrome installing automatically with Jamf App Catalog so I decided to install Firefox to test. I also have the package on a policy instead of prestage to install after logging in with Jamf Connect. (the only prestage package is Jamf Connect). Jamf App Catalog should automatically update apps… correct? I don’t know if installing with JSM will stop something like this from happening. I have Firefox setup as available in Self-Service only (but still in Jamf App Catalog). I was also playing around with Jamf Pro AI and before all the troubleshooting to get Jamf Setup Manager to pop up, the AI told me that it may have confused me. During troubleshooting, it said:I need to be honest with you - based on the search results, I'm not finding specific documentation about a product called "Jamf Setup Manager" as a standal
I am trying to setup an extension attribute to verify if MS defender is enabled on devices in our environment. When I save the EA I only get a response from 1 device but I need responses from all of my devices. Any advice would be appreciated! Thanks #!/bin/sh echo "<result>`mdatp health | grep real_time_protection_enabled| awk '{print $3}'`</result>"
We have successfully setup Jamf Connect menu bar icon to allow privilege elevation for just our technicians by using Roles with our OIDC provider Entra. The reason for this is that we don’t want standard users to be able to request or be full admins. There are times though when an admin needs to do something with admin rights under a users profile. With our solution the idea was that a technician could be on site or remote in and use the privilege elevation feature and sign in with their own credentials to make the standard user a temporary admin. Do what they need to do and end the session. However, this is where we run into issues. First, Jamf Connect stores an Entra token for the session. If you select the privilege elevation option again it will skip the pop up Entra sign in screen and move straight to the reason for elevation and make you admin. This token we know last for quite a while. We can see the three tokens in keychain and remove them and the Entra sign in screen will prop
I would like to enable the apple seed for IT beta program using the Beta token from Apple school manager to allow a device to get betas with out needing to login with an Apple ID on the device.Reading documentation we are able to get the token using a script. But at that point Jamf is requiring you to use blueprints with this token. Since we are on prem we do not have access to bleuprints.Any way to deploy the token a device using a config profile? How are other MDM’s enabling this?
Since I could not find a solution or explanation for this error in the the great JAMF Nation / Google / Internet troubleshooting database, I would like to share one possible cause for Installation failed. The installer reported: installer: Cannot install on volume / because it is disabled. Background: Attempting to distribute package via policy in JSS. Received the error in policy log. The package is a .MPKG and being pushed through SMB. Solution: Turned out the software had a software requirement (could only run on Mac OS X 10.6 or later) and was failing on Mac OS X 10.5.x assets. I am also speculating that this error may occur if there is a hardware requirement issue as well.
Using Self Service, it says packages are installed - but they are not anywhere on the Mac. I can't see where anything is configured incorrectly.
Hello, has anyone come up with reliable easy way to disable Google Lens features? Managed Macbook environment. Students have access to Safari, Firefox, and Google. Looking to disable Google Lens feature.
Anyone know if there is a way to sync information such as purchase dates, enrollment dates, etc. from ASM to Jamf pro? We're looking at ways to track our warranty coverage without adding extra data attributes to track.
Hi ,i am new to JAMF, the JAMF implementation was done by a third-party resource. it was all fine till last week, suddenly when i try to enrol a device after the SSO login its got stuck in blank screen, pls guide me on how to check the logs and errors
Hello-I have 500 new iPads. I want 250 to be assigned to a standard prestage and I want 250 to go into a shared iPad prestage. Is there a way to do this in bulk, or am I stuck looking up serial numbers and assigning them to the prestage one by one?
How do I stop this pop up from always coming up.
Recently, we have had an unusually high load on our network.After digging into the problem a bit, logs and such, our suspicions have targeted our Jamf environment (Jamf Pro Cloud). We have discovered that a lot of traffic comes from AWS and in logs we also see the text "appinstaller".Once a year, when schools start after the summer, we install and distribute Mac computers to students. Since the turn of the year 2023/2024, we have added automatic installation of M365 - Word, Excel, Powerpoint, Outlook and Teams. So we suspect that the hard load obviously has something to do with this.However, it would be interesting for us to get a report that shows what has been installed, when and to which computers (or to whom) within a specific date range.Is there any way to produce such a report in Jamf?
Hi Everyone, I've been working on a script, in Powershell, to create what we call a support area using the API. I know you're probably wondering why I'm using powershell so I will get that out of the way. Long story short, we are working on a Powershell script to automate the creation of various resources across several different systems. This includes Active Directory OUs, AD security groups, SCCM resources, etc. Jamf is just one part. The thought is to be able to specify what we want these resources named then let Powershell do the rest. We're using a web interface into our Powershell server so this could potentially do this from a webpage. We also use sites very heavily for organization of our Jamf resources. I've got most everything working properly except for one thing. We have a number of default policies that run on all our computers. A good example is enabling the Firewall. We have a subset of machines that have different firewall requirements and cannot use the buil
Anyone else come across this pop up? Our teachers are getting it, if we click on Open System Settings, it doesn’t provide an option to allow or deny OSXvnc-server. I am trying to find a way to block the pop up completely.
I've been having a problem for some time now with a few MacBooks that can't be enrolled. When I try to enroll them, I get to the authentication step, but when I enter the login details, after a short while I get the error message: “Enrolling with management server failed. The request timed out.” However, the problem only affects very few MacBooks, like 5 out of 1000. Other devices work, even when I enroll them at the same time. I have already contacted Apple Business Support about this. They said that the problem is probably with Jamf. What can I do to solve this problem?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!