Get Support
Recently active
As some of you may know MS messed up the the last version of Defender and it does not let the install go forward because tamper protection is set to block. Usually it sets it to enable the install and then back on. Does anyone have an easy way to do this in Jamf. I am not great with scripting and the only way I see to do it is via a few policies.
HelloI thought this was related CIS level 2 config which I have been testing but I have seen the same issues on Tahoe device which hasnt had any CIS level config applied.New admin users login via Jamf connect seem to get a Filevault pop up Im aware securetoken plays a role here.Has anyone else seen this with Tahoe its only effecting our labs as our Macbooks are encrypted by default.Thanks
Hello I have started testing CIS level 2 for MacOS 26.I get this prompt as soon as the screen is locked I though it has something to do with screensaver but i have removed all CIS config and it still seems to be happening. Im guessing its some left over config somewhere but havent been able track it down. Does anyone know if there anyway to undo this, we use the snowagent and its possible that might be causing it ThanksTom
Hi So, we got a case in my school where we want to start restarting Apple TV on a weekly basis, Having an issue getting back to api after sometime, I’ve managed to get the GET command to read the smart group but have issues for find the correct command to reboot, can anyone help?
Hi everyone,I’m running into an issue trying to upgrade Jamf Connect across our environment and hoping someone from Jamf or the community has seen this before.Until recently, I was able to update Jamf Connect using the dropdown underSettings → Jamf Apps → Jamf Connect → Deployment and Update Settings.That list used to automatically show each new version as Jamf released it (for example, 2.44 → 2.45).Now the dropdown has stopped updating — it’s capped at 2.45.1, even though 3.4.0 has been released publicly for several weeks.I’ve tried to manually handle the upgrade:• Downloaded JamfConnectLogin.pkg (3.4.0) from account.jamf.com.• Uploaded it into Jamf Pro (Cloud Distribution Point).• Created a policy to deploy it to test devices and tied it to our existing PreStage.• Policy runs successfully, reports “completed,” but the actual version on the Mac remains 2.45.1 — both in Get Info and when checking the bundle version via Terminal.• I’ve confirmed the correct PKG is being used, deleted th
Is there a control that we can set for how long it takes until Self Service+ will time out and require user login again? Thanks,Jim
Trying to install Dockutil during JSM but it fails. Based off the logs its because its attempting to install to the system (/usr/local/bin). My pkg was created in Composer with the appropriate R/W permissions applied to all elements of the pkg but still no luck. Any help is appreciated!
I’m fairly new to Jamf and inherited a Jamf Pro instance that I’m having to update/change as we get new devices and new software. We have Adobe Creative Cloud pushed to all computers using Mac Apps, but need the Shared License pushed to just our public computers. Right now we have a policy to install the Shared License, but it fails each time it runs. I’m assuming this is because it’s already installing the regular license through Mac Apps. My question is, can I change the target on Mac Apps to be only computers that aren’t public (using a smart group) and it not affect computers that already have the app installed? I don’t want to mess with our staff’s computers by pushing out any updates or reinstalls that they aren’t expecting.Thanks in advance for any help!Kayla
Hi all 👋🏻 I’m planning on getting Self Service+ deployed to devices in my Jamf environment. Could anyone point me in the right direction on where to best place a policy for Self Service+ so it can be applied to enrolling devices during DEPNotify? Our current process is as follows: Setup AssisitantRemote Management Entra Sign-inMore set-up steps, Accessibility/Data & Privacy/Apple Intellegence/Choose Your Look DEPNotify UI pop-up to ‘Register Your Mac’ For devices already live in our environment, I’m planning on creating a policy that installs Self Service+ and uninstalls the classic variant. I’m on a tight deadline to get this on 240 devices before the 4th Feb, so any fast responses would be hugely appreciated 🙏🏻 Many thanks, Luke Mutlow
Hello!I have, hopefully, a simple question. For JAMF Connect we deploy the JamfConnectLogin and the JamfConnectLaunchAgent via packages but I noticed that JAMF Connect Login is available through the JAMF apps catalog. Can I replace pushing those two packages with just pushing the app from the catalog or does it actually just installs one of them and I would still need to push the remaining one as a package?Thanks
I'm trying out the new PCM Device Compliance feature for macOS and am running into a problem. When running the "Microsoft Device Compliance" policy, it launches Company Portal, I login and it seems to complete the registration without issues. When I lookup the device in InTune, it's not there at all. In Azure I see the following:Join Type: Azure AD registeredMDM: NoneCompliant: N/AI configured the feature according to this technical paper: https://learn.jamf.com/bundle/technical-paper-microsoft-intune-mobile-devices-current/page/Integrating_with_Microsoft_Endpoint_Manager_Introduction.htmlAny help would be appreciated.
Hey, how the title says.Last year around July our with jamf pro enrolled devices have started showing up in intune.So we enroll our devices via PreStage. Installs also the MS Defender and the Devices are onboarded in MS Defender Portal but managed locally via Configuration Profile via Jamf Pro.We also use Device Compliance with Company Portal and the SSO Extension.Defender Configuration and Company Portal (SSO Extensions) are untouched for a long time. The only thing we updated in the defender config (but never in the defender onboarding config) are extensions.So someone an idea why the devices are now visible in Intune too.The devices are showing up since beginning of defender onboarding in MDE Portal and since beginning to use Company Portal in Entra.I just try to understand what happened and what happens and why not all of our devices are visible in intune when all have exact the same configurations. Thank you in advanceRegardsJ
I have a 2019 iMac running Sequoia that uses the same Connect setup as 700 other systems that is showing this error message. It only seems to come up when logging onto the system using an ID that was created a long while ago. I tried using an account that hadn't been used on this system before and it works fine. And continues to work fine for that new ID. Nothing has changed in our EntraID configuration and it is currently working fine for systems in that lab as well as all across campus. Any ideas?
Does anyone know if we will have the ability to get the new Creator Studio through ASM? I have a department head who has previously bought Final Cut for multiple labs using his personal apple id, and signed into EVERY SINGLE MAC using his ID, then signing out just to download Final Cut, With the new Creator Stuido, it would be much cheaper and we might be able to use a managed apple id.
Your configuration may need to be updated on your iPads. On their tech call today they mentioned adding the device name to the config so that the name will show in the COS. The info in their PDF did not make sense to me who is not a coder. With some help from the Jamf AI this is the config that worked for me. Make sure to change the ouIds to your COS Org Unit ID <dict> <key>ouIds</key> <string>1234567890</string> <key>deviceName</key> <string>$DEVICENAME</string></dict>
I have Garageband listed under Mac App Store Apps in my JSS. It has successfully installed on the end users accounts. However, each user now needs to go in and download the sounds library which takes quite a bit of time per user and hinders their use in the classroom. Is there a way to push the sounds library remotely?
It's not possible to perform patch management for After Effects 2026 Combined Definition. Is anyone else having this problem?When defining the smart group with older machines and versions of After Effects, no machines appear to be available for update.
Hello, Jamf Nation! We’re kicking off 2026 by celebrating you, an incredible community of wickedly smart and super kind humans who believe sharing knowledge, and supporting each other, is what makes Jamf Nation special. You’re invited to Celebrating Jamf Nation: A Kickoff to 2026 with special guest, Chris Schembra, on January 27. Featured in Rolling Stone, Fast Company and Entrepreneaur, Chris received global recognition for his unique approach to building community. He’s gathered Fortune 500 executives, NFL players and complete strangers to simple pasta dinners that create life-changing moments. Chris is someone you want to meet, so we’re thrilled to have him join us in a virtual experience to kick off 2026! Whether you’re deeply involved in Jamf Nation or just beginning your journey with us, this is a chance to connect with fellow community members - and even some Jamfs - in a meaningful, energizing way. If you need a jolt of inspiration – mark your calendar now! 📅 Date: Tues
While watching Jamf’s new AI assistant demo, I noticed the assistant confidently instructs the user to create a Smart Group using an OS version value of 24.99. macOS 24 doesn’t exist, Apple jumped from macOS 15 to macOS 26. The presenter follows the incorrect instructions exactly and saves the group. For an official Jamf-produced video meant to showcase the accuracy of their AI, this is a pretty embarrassing oversight. Curious if others caught this too.
Now that here are all new Keynote, Pages, and Numbers app that have Premium features locked behind a subscription model, I’m curious how everyone is handling that. We’ve always automatically installed those apps on ever Mac, and Keynote is very heavily used within our organization.If we do nothing, users are locked into version 14.5 forever and never get any new features or bug fixes. We could optionally deploy both 14.5 AND 15.1, but it’s gross having two versions of each app installed. Or, we can rip the bandaid off and remove the old version and deploy the new version to everyone.Tradeoffs everywhere! Interested in learning what others are doing or considering doing.
Looking for an independent macOS admin for paid diagnostic work.We have multiple Apple Silicon Macs on macOS Tahoe.Adobe InDesign 2025 launches but never initializes its user support folder:~/Library/Application Support/Adobe/InDesign/24.0Scripts panel is disabled.Reinstalls and permissions have been exhausted.Issue predates InDesign 2026.Suspect macOS TCC or user-profile related issue.Initial focus is diagnosing and fixing this problem.If it’s a good fit, there is likely other macOS / systems work we could use help with.Remote session is fine.
I'm needing to delete a ton of Smart Device Groups but they all have apps associated to them. How can I delete these groups without having to go into each one and remove the apps first. I have 80+ groups and do not want to do each one manually.
Good day all,I’m deploying the google chrome extensions using the below.Installing the forced extensions work (regardless if there is a user logged in to chrome or not)However, one of my test computers doesnt have the user logged in to chrome and that blocks all extensions, even the ones in the allow list.And when Im testing against my every drivers that Im logged in, I have the opposite effects. Im allow to install all extensions. and none of them are getting blocked.I different set of eyes would be appreciated. I wish it was like some of the other post where people wait and then it works, but for me it hasnt been the case.
I had a use case that it would have been extremely nice to be able to use an advanced search or smart group to be able to gather data about computers in specific sites. However sites aren't meant to be scope-able per Jamf, and that really made my life difficult. Specifically I was looking for unmanaged computers in the "none" or "Full Jamf Pro" site, and there is no way to make a search for this. I did some searching and saw several posts of folks who wanted Jamf to make sites a useable criteria, but saw that Jamf specifically said it was not planned (https://www.jamf.com/jamf-nation/feature-requests/1365/smart-computer-groups-based-on-site). I was able to create a workaround for this and thought I'd share. I first made a custom extension attribute named "Site" with a string data type and a text field for the input type. Then I was able to make a script utilizing the API to read the current site of a computer and write that data to a XML file that gets uploaded to Jamf and sets t
Hello, I'm new here, I'm a student I got a school ipad and I was able to download absolutely any app I want. I signed in to an apple account then I use spotlight to find an app : like MailChimp or candy crush and when the result from the app store is showed I can press the get button that will install the app. App store is restricted on the device but using spotlight can bypass this. Maybe I'm not in the right place but just wanted to report this bug. I'm on iPados 26.1
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!