Get Support
Recently active
Previously, we deployed the following script to allow standard users to change the date and time without requiring admin credentials. However, this is no longer working on Sequoia devices. Can someone assist in enabling this functionality on Sequoia devices? #!/bin/bash # Allows any user to change the date and time on their Mac. /usr/bin/security authorizationdb write system.preferences.dateandtime.changetimezone allow /usr/bin/security authorizationdb write system.preferences.datetime authenticate-session-owner-or-admin exit 0;
The heartbeat of Jamf has always been its customers. From day one, your passion and expertise have shaped a community unlike any other. What began as a simple email newsletter eventually grew into Jamf Nation - a space to troubleshoot, share wisdom, and connect with people who just get it. Along the way, we noticed a group of customers consistently going the extra mile, and that sparked the creation of Jamf Heroes - our deeply engaged, wildly generous champions who support Jamf and the wider community in incredible ways. Whether answering questions, offering solutions, or hopping on calls to help someone out, their impact was undeniable. But over time, we realised something bigger: meaningful contributions happen across our entire customer base, every single day. So, we built a way to recognise all of it. Enter Jamf Nation Rewards. We launched Jamf Nation Rewards at JNUC 2024 to celebrate the everyday actions that strengthen our ecosystem. Joining Jamf Nation discussions and thr
We are restricting the ability to add non-corporate email accounts to the native Apple mail client (which is easy to lock down in jamf by locking the Settings) but we would like to offer Outlook for iOS app as an alternative to the native client. So...couple of questions:1. Is it possible to push a config to the Outlook app so that is sets up the users Exchange email box?2. Is it possible to lock down the Outlook for iOS app so that users can't add additional email accounts?
I just want to ask, before we deploy PSSO for better MFA authentication, does Device Compliance need to be enabled in Jamf and does the device need to be registered in Entra? Is that correct? Because I thought we could deploy the company portal and then the configuration profile based on the Jamf documentation.
Hello everyone,I’ve added many ATV to our School Manager with latest Apple Configurator 2 without any problem. But now I’ve run in to two problems. When click prepare it takes some seconds and then I get the error as bellow. It’s a ATV 4 HD with USB-C. USB-C is connected to my computer and the computer and ATV is on the same network and the devices is updated to latest tvOS and reset. I’ve tried some times to set it in recovery mode but it just wont work. Does anyone have any idea what to do?
Hi All, Can someone help me with Global System Extension to the Global Protect package to be deploy from Jamf Pro to Devices? the Global System extension need to be excutable with the deploy as well? Thanks in Advance
Dear experts,I joined here because of a issue that we cannot resolve after almost a month (yes..) of troubleshooting. The problem is as follows:Jamf Pro with iPhones. No Computers etc.Apps will not install from Self Service. The device history shows that the license for the app is not found. I looked everywhere, each history tab for devices, location, any changes or things that line up with when the issue came up, unable to pin point anything. It unfortunately just stopped working, seemingly out of nowhere, and I wish I had anything more precise to say about this. What we did so far:renewed the VPP token as well as the .p7m server token file, taken from Apple Business Manager and uploaded them again in Jamf made sure that the Apple IDs match, same email address used in ABM as in Jamf for Admin as I saw in this thread, I looked for devices with no serial number but I didn’t find any. I also did everything from this thread, including deleting everything (devices and apps) from one loca
Running a Jamf Cloud instance, and testing various methods for software update management.I pushed out a managed software update to two test devices, update was configured to allow a max of three deferrals. This is the behavior experienced by both endpoints, each time a managed update was pushed:Maximum deferrals were selected, or deferral notifications otherwise ignored. Users received notifications that their computers would restart. No updates applied, computers did not restart. Logs reported that AvailableOSUpdates had changedBootstrap tokens are escrowed for every device in our inventory. Managed updates were pushed multiple times, reporting the same error at step four each time. No new updates were published between attempts.Unless I’m mistaken, shouldn’t updates automatically authorize if a valid bootstrap token is escrowed in Jamf? Why did the available updates never apply?
We would like to create a shared mac device where multiple users can login to with their personal accounts. We are utilizing Platform Single Sign-On and have enabled “Create new user at login”.Everything works as expected and multiple users can login with their personal Entra ID account but we have a funny issue here.The first user who logs in (via prestage) gets a local account like “user@domain.com” but all other users who are logging in at the login window are getting a local account like “userdomain.com” so without the @Mappings set in PSSO as:Full Name: NameAccount Name: preferred_usernameWe would like to create local accounts of users with full email. Any thoughts?
We (finally) got zero-touch working this year, but the only issue is we’re only targeting new hires so far. What we ran into is existing Mac users getting a lease replaced machine don’t have an automated way of getting the software they use today installed on their new machines. They would have to go to ServiceNow and request it all again. I was wondering if anyone had any experience via the API or scripts to look at what they had installed on an old machine assigned to the same user and scope the new machine for the same software (using maybe an allow/block list for things like licensed software)?
Anyone having issues with the API?I was using several scripts that suddenly broke yesterday, November 24 around 9:30 AM EST.I’ve got most of them fixed, but some aren’t working as consistently as they were previously. To give a little context, I was using /JSSResource/computers/serialnumber to get location data to set fields in the Login Window. I also use the location data fields like <realname> <building> <department> to set the machine name and to create a local user account.After adjusting scripts to use a bearer token, I was able to get this to work somewhat, but had to make several adjustments to the parsing of the data with awk commands to remove whitespace and newlines.Additionally, I’m seeing script failures for no apparent reason now.Has anyone experienced anything like this?-Chris
I’m deploying Snagit 2025 on macOS Tahoe. I’m following Techsmith’s documentation to the letter at the link below. I’ve deployed older versions on older OS versions without issue. The issue I’m having appears to be a permissions issue. https://support.techsmith.com/hc/en-us/articles/115007344888-Enterprise-Install-Guidelines-for-Snagit-on-MacOSThe issue happens the first time you attempt to open Snagit. On app execution, you are presented with the error below:In troubleshooting, I’ve added permissions to everyone to the first folder and still have the same issue. The second folder doesn’t exist yet. Has anyone else had this issue?
Hi guys. I need to configure VPN via the macOS VP client. Each user has a unique VPN login, can anyone assist me with a script or something which will allow zero-touch config of a devices VPN details - user/password/shared secret etc. Never done this before, so any support you can offer is very much appreciated, thanks. Devices are DEP enrolled and in Jamf Pro.
An original version of this post has been shared to Patch Notes and Progress. Reflections from JNUC 2025 — automation, openness, and community taking Mac management to new heights. Denver, Colorado | October 6 – 9, 2025Day 0 — Travel and New ConnectionsJNUC 2025 in Denver was my first in-person Jamf Nation User Conference — and my first time ever on a plane. Over three days, I watched Jamf redefine what MDM means in an API-first world, connected with the Mac Admins community I’ve long admired, and saw firsthand how automation, identity, and community are working to shape the next chapter of Apple device management services. As mentioned in a previous post: Prepping for JNUC 2025, I had been awarded sponsorship by Jamf to attend this year’s Jamf Nation User Conference in Denver Colorado. Before I even left Pittsburgh, Jamf had already dropped next year’s headline: JNUC 2026 will be held in Kansas City, Missouri (Sept 23– 25), with early-bird registration open. JNUC 2026 to be hosted at
Hello Is anyone doing ipad compliance everything is working great nearly.The self service process to register device in Entra. - All goodThem been mark as compliant - All good.We are struggling with these keys which when pushed with an app should stop app protection from applying. But where still seeing the prompts for it. <!-- Intune MAM Integration --> <key>IntuneMAMUPN</key> <string>$EMAIL</string>Has anyone else come accross this? ThanksTom
Now that ASM (finally) has warranty information, what is the possibility that JAMF will be able to read that information and populate the Warranty fields in JAMF Pro?
Hi there,I'm not sure if this functionality exists for MacOS, but it does for Chromebooks, and it's pretty amazing, so we'd like to leverage it for our iMac labs at the very least, and if it works there maybe go org-wide with it. The problem is I'm not sure what method to attack this problem with.Currently our iMacs (like the rest of our Apple computers) are AD bound. Users log in with a mobile account, and use Enterprise Connect for password management.I know that Macs support Kerb/SSO authentication, and also that Google's SecureLDAP can work for macOS as well, but what I really want is for the login screen to show me a Classlink login page so users can sign in with a QR code badge.Since our Google accounts use Classlink as their IDP and show the splash page when you try to log into them via web browser, I started going down the rabbit hole of getting a test machine bound to Google Secure LDAP, thinking it might spawn a splash page for Classlink login. But now I'm realizing that mech
We've had an issue twice in the last 2 months, where our wifi configuration profile that installs our certs fails to install. We get the following error "Install Configuration Profile Prod Wi-Fi Unable to decrypt encrypted profile" when desktop enrolls a mac. Everything else installs correctly with no issues. When we originally had this issue back in August, we had to add the new jamf IP's to the firewall and it that fixed it. We worked with out networking guys yeserday and they couldn't see anythin. The issue only last a day and it goes back to working. It broke on 11/19 9:30a and started working on 11/20 6a. Very weird issue. I opened a ticket with jamf.
Hi,we are using the erase-install tool from github to upgrade our Macs (I guess the Jamf mass action feature is still not working proper?) and facing the issue, that the pop up to enter the local mac user credentials are in another keyboard layout than the system has. I could not find anything on github or here where this was discussed. Any ideas? Thanks already
Hi Everyone I'm getting "Locate Hardware Information" stuck on one macbook air M4 laptop whilst tring to execute sudo jamf recon, i followed the steps and instructions found on https://community.jamf.com/t5/jamf-pro/jamf-recon-stalls-at-locate-hardware-information/td-p/315285 and https://community.jamf.com/t5/jamf-pro/recon-hangs-on-locating-hardware-information/m-p/284704 but when we execute the "sudo launchctl kickstart -k system/com.apple.softwareupdated" it fails with the error "Could not kickstart service "com.apple.softwareupdated": 150: Operation not permitted while System Integrity Protection is engaged". We then tried deleting the /Library/Preferences/com.apple.SoftwareUpdate.plist configuration file and restarting but that didnt work either. Anyone else have the same problem and or know how to resolve this?OS: 15.4 but this also happening on 15.3.2 as wellJamf Pro: 11.15.2
Hello Jamf Community, I'm currently experiencing an issue with Jamf Remote Assist — I haven't been able to successfully connect to any Mac devices for the past two weeks. Each attempt either times out or fails with no clear error message. I've tried the following so far: Confirmed that Remote Assist is enabled in Settings. Restarted Jamf Daemon and the local Jamf app on the affected Mac. Verified network/firewall configurations (no changes recently). Tested on both Intel and Apple Silicon Macs with the same result. Has anyone else encountered similar issues recently?Is there any known workaround or reliable fix that could help restore functionality? Any suggestions or guidance would be much appreciated. Thanks in advance!
I'm trying to setup a Custom Menubar Icon for Jamf Connect by following the instructions here:https://learn.jamf.com/bundle/jamf-connect-documentation-current/page/Menu_Bar_App_Preferences.htmlI created a 16x16 png file and saved it as /user/local/icon.png Then I added these lines to the Profile, <key>MenubarIcon</key <string>/usr/local/icon.png</string> I quit Jamf Connect and when it relaunches, I just get a white square where the icon should be. The details of the image are not there. So it is trying to display it, but it just can't parse the file? When I click on About Jamf Connect, it also displays a small white square where the icon should be. I made sure the file had 755 permissions on it. Is there a particular DPI or color pallet I need to set on the image? Is there something I'm missing?
Love connecting with the community? Want more ways to get involved with Jamf? Come join your fellow customers in Jamf Heroes! Designed as a space for our most passionate customers to learn, engage and grow with each other, Jamf Heroes is a space exclusively for those who want a different type of experience with Jamf. The Jamf Heroes program has helped me so much in my professional journey. I have made invaluable connections that have been encouraging, helpful, true geniuses behind keyboards (and away) and just downright delightful people to engage with. The community aspect of the Heroes program is like having that friend you don't see often, but when you see each other again, it is like no time has passed, they are always supportive and friendly. Through the Heroes program we are all able to share our knowledge, expertise, and good vibes with each other in a way I have not seen with any other tech system we utilize creating a truly unique experience that provides
Hi everyone,I’ve recently started working in an environment using Okta for authentication with Jamf Connect deployed, and we also use Self Service+. At this moment we haven’t approved macOS 26.1 for all users yet, but a few people upgraded on their own and experienced the issue described in the Jamf Connect release notes:[PI143263, PI144134] Fixed:Jamf Connect presents a one-time prompt on computers running macOS Tahoe 26.1 beta, both on the login window and on the desktop:“Self Service+ wants to use your confidential information stored in “Jamf Connect” in your keychain.”Source: https://learn.jamf.com/en-US/bundle/jamf-connect-release-notes/page/Jamf_Connect_macOS_Release_Notes.htmlWhile investigating, I found that the affected users were not running the latest version of Jamf Connect, even though Jamf Connect is deployed through Mac Apps.Then I checked my own device and noticed the following versions installed:JamfConnect:MenubarVersion: 2.45.1Build: 7204****************************J
Hello,we applied a FileVault policy, and it worked on every MacBook except one. We’re not receiving the FileVault key from that device, and the user keeps getting the policy pushed repeatedly.I also made the policy available in Self Service, but even from there it doesn’t work.What could be causing this issue?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!