Get Support
Recently active
Hello, We have an issue where iPads running 26.0.1 are working absolutely fine no issues whatsoever however as soon as they upgrade to 26.1 their internet connection stops working. Devices can be connected to the network no issues and appear to be working fine but you are unable to access the internet and they refuse to talk to JAMF.I found the following : https://discussions.apple.com/thread/256182709?sortBy=rank which appears to be the same issue. Wiping the devices hasn’t helped and the problem persists.
I’m trying to install a driver for a robotics course in our school division. The teacher says that this is the correct version for their devices:https://www.silabs.com/software-and-tools/usb-to-uart-bridge-vcp-drivers?tab=downloadsUnfortunately it doesn’t seem to have a PKG installer. The drivers are a system extension and are installed through an app and not a pkg. There is a pkg in the dmg but it doesn’t install the system extension as far as I can see.I did attempt to package using Composer to monitor for changes but when I run the created pkg afterwards it fails. I’m assumning due to the system extension needing additional permissions perhaps.I have investigated this and it may be that Sonoma and beyond have the driver installed by default as per an article here:https://forum.netgate.com/topic/187597/cp210x-usb-to-uart-driver-for-mac-sonoma/3I don’t have a device to test with but will check it out tomorrow hopefully.I can handle the security for system extensions via a configur
I am new to Jamf, exploring on webhooks where iam confusing about authentication which we have to use for webhooks and do we need API access for webhooks?
Hi, kind of new to this and I don't know if there's a better place to post this question.I’m having trouble retrieving and modifying the student device restrictions using the version 4 API. I’ve used version 4 for teacher lessons, and it works fine. However, the retrieve current student device restrictions API doesn’t provide the correct information. It does not show any restrictions when there are. This is what I get back.[ { "studentId": 142 }, { "studentId": 143 }]https://api.zuludesk.com/docs/#api-Teacher-ModifyProfiles and https://api.zuludesk.com/docs/#api-Teacher-GetProfiles So, the APIs are executing, but they’re they are not working.Similarly, the modify restrictions API doesn’t give an error, but it doesn’t do anything either.For example, if I use Jamf Teacher Application to restrict a student and and I see those restrictions in effect on the JAMF teacher console, using the API to retrieve those restrictions doesn't work. It doesn't return any restrictions. It loo
Friday. Yes. Friday.macOS/iOS 26.2.• https://support.apple.com/en-us/100100
A maintenance release to Mac Admins’ new favorite, MDM-agnostic, “set-it-and-forget-it” end-user reminder for Apple’s Declarative Device Management-enforced macOS update deadlines that further simplifies enterprise-wide deployment and adds user warnings for excessive uptime and low disk space OverviewWhile Apple’s Declarative Device Management (DDM) provides Mac Admins a powerful way to enforce macOS updates, its built-in notification is often too subtle for most administrators.DDM OS Reminder evaluates the most recent `EnforcedInstallDate` and `setPastDuePaddedEnforcementDate` entries in `/var/log/install.log`, and then leverages a swiftDialog-enabled script plus a LaunchDaemon to deliver a more prominent end-user dialog that reminds users to update their Mac to comply with DDM-enforced macOS update deadlines.Continue reading …
Hello everyone,I have a problem in PreStage Enrollment, when passing through the sAMAccountName, maybe someone here has a solution for it.We need user certificates per configuration profile, which is why I set up a new PreStage Enrollment for MDM Enabled Users, but currently the ShortName (sAMAccountName) is not taken over for the AccountName if the value contains capital letters (which is unfortunately often the case here).The other attributes were already in use, which is why we used "Room" for mapping the sAMAccountName/onpremisessamaccountname, which works so far, but in PreStage only as long as there is no capital letter. If there is a uppercase letter in it, the value is not filled in the macOS account setup and the fields are not locked.AD and AAD are set up and Entra ID as IDP for SSO.There are already hundreds of rolled out Macs in this cloud instance and various dependencies on the username, which is set to the UPN. This is why we cannot generally change the usernam
A five-question self-assessment to help you plan your 2026 Mac Admin open source contributions InvitationPlease accept my personal invitation to increase — or, for you Jedi-Ninjas, to maintain — your contributions to the Mac Admin community’s various open-source projects during 2026.Take the self-assessment
So I’ve started seeing an issue with macOS 26.1 trying to set up new machines.The enrollment customization is not passing the user info from the SAML token, which is a known issue but usually sending the workaround profile that sets those attributes works fine. Here is the payload:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>EnrollmentRealName</key> <string>$REALNAME</string> <key>EnrollmentUserName</key> <string>$USERNAME</string> </dict></plist>it’s not working now, I’m not even seeing the computer’s username change in Jamf Pro after signing in through the enrollment customization like I used to. Once setup assistant completes, Jamf Connect is installed, but when I get the re-enter your password screen I cannot progress past that sin
With 15.6 and beta macos 26The EA I was using for report back a macs SSID is now broken/blocked.Does any happed to have one that will works? Thanks #!/bin/sh# Jamf Extension attribute to return SSID## Check for SSID namewifi_name=$(ipconfig getsummary en0 | awk -F ' SSID : ' '/ SSID : / {print $2}')# Check if SSID is foundif [ -z "$wifi_name" ]; then result="No Wi-Fi network found."else result="$wifi_name"fi# Result for Jamfecho "<result>$result</result>"
Jamf announced in January that the Jamf Pro Classic API will no longer support basic authentication in a future release. Classic API scripts can still run—administrators just need to make a simple change in how they authenticate. Let’s look at why this change is coming and how to convert Classic API scripts to use bearer tokens for authentication instead of usernames and passwords. The token obtained during this workflow will allow authentication to either the Classic API or the more modern Jamf Pro API. We’ll cover: How bearer tokens improve security Request the first token Parse the token Use the token to send an API command Expire the token Renew the token How bearer tokens improve security This change to move away from supplying usernames and passwords as credentials for authenticating to Jamf Pro is a good thing. Bearer tokens improve security by reducing the number of times credentials are sent to the server. Instead of sending them with every request, a token is sent instead,
We are excited to share that we’ve updated our Privacy Notices across our services to enhance clarity and transparency.Our Privacy Policy has been revised to provide greater transparency regarding our use of AI within our Services, specifically for automated email sentiment analysis, which enables us to better understand and support customer needs while maintaining data privacy standards.Jamf is certified under the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF — international frameworks that ensure robust data protection standards. In alignment with these frameworks, we have updated our Employee Privacy Notice to reflect our continued commitment to the DPF principles. We have also refined the language and defined terms in the notice.You can access the updated Privacy Policy and Employee Privacy Notice on the Jamf Trust Center Privacy page. We encourage you to review these updates. If you have any questions or concerns, please contact
Since the A16 iPad doesn’t have serial numbers engraved anymore, I need a way to identify iPads in cases where the screen has died (water or physical damage). Are there any solutions like this that integrate with JamF School? If not, are there any recommendations?
I’m testing Jamf App Installers.One of my tests is Google Chrome and the other is Firefox.The other day I had an update for Chrome and received this message: When I checked the version of Chrome, it has updated and is now 142.0.7444.176 (Official Build) (arm64) which matches the version in the App Installers I struggled to find a log on the Mac, However, there is an item under Jamf Pro → Device → History → Management History on the server and that has an entry InstallEnterpriseApplication - Google Chrome - 142.0.7444.176 18/11/2025 at 10:29 AMWhich is a week ago not 24/11/2025 when I had the messageSo, I’m confused. Why the error message about the failure? What was the failure? How can I find out what it was? Can I suppress messages like this?
I am looking for the code for the Configuration dictionary for IXL iOS app to set the custom domain in the app. There is a setting for it in iOS Settings - IXL. Unfortunately IXL is anot aware of how to set this via MDM commands.
I'm looking to use an extension attribute to list a user's Azure AD group membership status. Once that is identified, I would like to then parse this information for certain data, such as a specific group, and then create a smart group based on this information. Once the device enters that smart group, I can then have certain policies (such as licensed software) automatically deploy there. Has anyone done this? Thanks in advance!
For strong certificate mapping, can two SAN types be used in the Subject Alternative Names field? Official guidance specifies using only the SCEP URI, and although the current configuration with multiple SAN types appears to work, it seems unreliable, as I’m seeing additional certificate-selection prompts. This change was made while I was out, so I need to confirm that this approach follows best practice.
Hello,I wanted to install Freeform on our iPad, but unfortunately I can't find the app at Apple School Manager.What can I do?Best Regards,Ralph
We’ve never fully standardized on having everyone in our org sync their Desktop and Documents folders to their OneDrive, and I’ve been working on getting that done recently. First step: create an extension attribute that shows the OneDrive redirection status on each Mac so I could build some smart groups.I kept it simple and just had it look to see whether the user’s Desktop and Documents folders were in their default locations, or if they had OneDrive in the file path of their locations. If it’s the former, it displays “Disabled.” If it’s the latter, it displays “Enabled.” If only one of the two folders are synced to OneDrive, it displays “Partial.”Just wanted to share in case this was useful for anyone else!#!/bin/bash# Extension Attribute to check if Desktop and Documents are syncing with OneDrive (KFM)# Author: John William Sherrod jwsherrod@mac.com# Version 1.0, Date: 08-28-2025# Get the currently logged-in user:loggedInUser=$(scutil <<< "show State:/Users/ConsoleUser" |
Hello Jamf Nation!We’ve just released our last Jamf Pro Beta of 2025, Jamf Pro 11.24.0. This beta features automatic Jamf Protect Tenant registration, a new Profile setting to remove apps from camera restrictions by bundle ID and moreHow to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Starting from scratch (new Jamf instance), how do you establish a baseline for configuration profiles that will be pushed to iPhones and iPads. Do you keep them separate for each type of device and should there be a config profile for every setting/configuration?
How does everyone utilize static groups and smart groups in your Jamf instance? Seems there's more ways than one to make it efficient. Would like to know particularly how it's used in a hospital or school environment where iPads or iPhones are the bulk of the devices being managed.P. S. I know the difference between the group types. Just want to get ideas on how different orgs might use them more efficiently.
Hi All, Does anyone has a method after User has action SSO on the system that Jamf Pro will extract all there details from Entra ID included there department to the User and Location information for there system in Jamf ProThanks in Advance
Hi All, Does anyone know how to create uninstall button in self service for an application? Thanks in Advances
Just in time for macOS Tahoe 26.2, a major update to Mac Admins’ new favorite, MDM-agnostic, “set-it-and-forget-it” end-user reminder for Apple’s Declarative Device Management-enforced macOS update deadlines — now with Configuration Profile support and a demo mode for easy reminder dialog testing OverviewWhile Apple’s Declarative Device Management (DDM) provides Mac Admins a powerful way to enforce macOS updates, its built-in notification is often too subtle for most end users to notice. DDM OS Reminder fills this gap by providing persistent, customizable reminders that ensure users are aware of upcoming update deadlines.New in 2.0.0Configuration Profile Support: Easily deploy and manage DDM OS Reminder settings via Configuration Profiles, making it simpler to customize reminders across your organization. Demo Mode: Test reminder dialogs effortlessly with a new demo mode, ensuring your configurations look and behave as expected before deployment.Continue reading …
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!