Get Support
Recently active
I’m pretty new to JAMF. I’ve got JAMF Connect 3.5.0, Self Service+, and JAMF Connect Launch Agent 3.5.0 deployed on my Mac Mini test device. I deployed these so I could start working on Tahoe support. After upgrading to Tahoe, everything seems to be working fine, except I now have to log-in twice when rebooting. The first login seems to be Filevault for unlocking the disk, and the second is the Entra web sign-in window from JAMF Connect.With Sequoia and the older version of JAMF Connect that most users are on, they only have to log-in once with the Entra web sign-in window.I’m using all the same config profiles as the old machines. Is this expected in Tahoe or is there some config change needed to get SSO sign-in to cover both filevault and OS login? Also, I have to enter the username in the second login as well. I’m pretty sure this was pre-populated before. I’m not 100% sure if this was caused by the new JAMF Connect apps versions, or only after the Tahoe upgrade. Is there anything I
We currently have an instance installed on tomcat and working on getting memcached working.memcached out of the box works fine, but it supports TLS encryption. When we enabled this, it appears that JAMF doesnt know what to do with the TLS connection.We will firewall off that port as suggested. But TLS seems like a good idea.
Is there any expectation that the Self Service+ icon will be Liquid Glass compatible when using custom branding? This would be helpful for consistent appearances across the new macOS UI. I created a .icns file using Icon Composer that contains icons using our own branding for Default, Dark, and Mono themes but, I’m unsure if there’s a preferred or supported method to deploy these icons in a way that ensures compatibility with Liquid Glass design standard.
Apple now supports Platform SSO during Automated Device Enrollment (ADE) in macOS 26. This allows users to authenticate with Entra ID directly in the Setup Assistant, create a local macOS account, and gain immediate SSO access to apps and websites.Currently, the Microsoft Platform SSO plug-in does not support this flow, and Microsoft has not announced full support.Could this serve as a workaround for first-time login on a JAMF-managed Mac?A possible setup using Entra ID:1. Start the Mac → Setup Assistant2. Sign in with Managed Apple ID (federated with Entra ID)3. Redirect to Entra ID → authenticate4. Create a local macOS user5. Enroll the device in MDM6. Configure Platform SSO later using the Entra ID user This approach enables initial device setup while allowing Platform SSO to be activated once the local user account is established.
Is there a way to prevent local administrators from removing the JAMF Binary with jamf removeFramework ? We still need local administrator accounts for our professors but don't want them to be able to delete the JAMF Framework.
Hi all,I’m looking for some advice on improving our macOS update workflow. Current setupRight now we’re using a mix of:Restrictions payload with no deferral for our tester group, 1week deferral for everyone else.Nudge -separate config profiles depending on whether we want to push a required update or just remind users.This works, but managing multiple profiles every time there’s a new macOS version isn’t ideal.What I’d like to achieve is: A cleaner process for forced updates for everyone when needed.A standard workflow where users get UI prompts to update (Nudge-style), based on our deferral policy.Ideally: define the update version and handle the user prompts from one place, without juggling several profiles. Does Jamf Pro offer any built-in way to handle both the update logic and user prompts together?Or is Nudge still the best option?If you have a setup that avoids maintaining multiple profiles per update, I’d love to hear how you do it.Thanks!
Hi! As my institution's Jamf admin I'm working on developing procedures to manage our to-this-point large pool of essentially unmanaged iOS devices. Prestage Enrollment isn't new to me, but managing iOS very much is. I'm currently working on bringing management to a pool of loaner iPads, but with an eye towards managing personally assigned iOS devices once I've got the loaners under control. I've been playing around with Jamf Reset, Jamf Setup, and Apple Configurator 2, and I'm still confused on a few points. 1) I think I already know the answer to this (No) but... there's no way to wipe an iOS device via Configurator, Jamf Reset, or any other method that wipes everything EXCEPT a wireless profile, right? Doing so would actually allow us to provide the "over the air" functionality everyone likes to talk about. 2) Activation Lock seems to be a sticking point. I definitely want "Prevent user from enabling Activation Lock" since that's burnt us before, but if I enable "Enable
Today we are releasing a maintenance version of Jamf Pro; highlights include: Resolved IssuesJamf Pro Server[PI122411] Fixed: After making changes to a user level configuration profile that is made available in Self Service, Jamf Pro unexpectedly redistributes the profile when devices update inventory, sometimes resulting in devices losing network access. [PI134378] Fixed: When attempting to upload a file (e.g., configuration profiles, in-house apps, eBooks, certificates) the page refreshes or the Upload dialog closes before the upload is complete. [PI148308] Fixed: The Jamf Pro API endpoint POST /v1/devices/{id}/erase does not clear Activation Lock for computers, despite clearing Activation Lock when erasing computers with a remote command via the Jamf Pro interface. [PI148751] Fixed: Attempting to create or retrieve patch software titles using the /JSSResource/patchsoftwaretitles endpoint of the Classic API results in a 500 Internal Server Error. For additional information on what's
To all those who celebrate/observe, may you and your families have a Happy Channukah/Hannukah/Hanukah/Festival of Lights!
Update 12 December 2025: Standard Cloud upgrades are scheduled for the weekend of 9–10 January 2026 (details below). We appreciate your patience with the revised schedule. Today we are releasing Jamf Pro 11.23; highlights include:New Settings for Privacy Preferences Policy Control and Platform Single Sign-onJamf has expanded support for additional Privacy Preferences Policy Control restrictions and the Single Sign-on Extensions payload with new computer configuration profile keys. This update enables administrators to define and deploy more granular privacy and security permissions for macOS devices while streamlining the user experience.Return to Service EnhancementYou can now add more than one payload to a configuration profile when configuring Return to Service in a PreStage enrollment. Previously, only one Wi-Fi payload could be used. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro,
Today we are releasing Jamf Pro 11.20; highlights include:Compatibility with Apple Operating SystemsCompatibility and new feature support are based on testing with the latest Apple beta releases of macOS Tahoe 26, iOS 26, iPadOS 26, tvOS 26, visionOS 26, and watchOS 26. Simplified Setup for Platform Single Sign-OnJamf Pro can now support deployment of a Platform Single Sign-on (Platform SSO) application during the Setup Assistant with macOS 26* using the Simplified Setup for Platform Single Sign-on workflow in a computer PreStage enrollment. This workflow allows for Platform SSO to be enforced through the Setup Assistant during Automated Device enrollment, requiring registration with an identity provider (IdP) and the ability for macOS to create a user account based on the user’s information from the IdP.*Feature support is based on testing with the latest Apple beta releases. Full functionality requires compatible implementation from supported identity providers (Okta and Microsoft
I use the API to set an owner and it works fine however, the documentation states that to remove an owner the owner should be set to zero and the message I get back is user not foundhttps://api.zuludesk.com/docs/#api-Devices-Assign_owner
A couple users updated to MacOS 26.2 over the weekend and are seeing this in Jamf Trust. I updated my computer and I’m seeing the same. I’m guessing that Trust just doesn’t recognize 26.2 yet? Or is there something I need to do on the admin side of things to fix this? I don’t think I’ve ever had to touch macOS versions in trust before. “MacOS is outdated”MacOS version 26.2
Hello, We have an issue where iPads running 26.0.1 are working absolutely fine no issues whatsoever however as soon as they upgrade to 26.1 their internet connection stops working. Devices can be connected to the network no issues and appear to be working fine but you are unable to access the internet and they refuse to talk to JAMF.I found the following : https://discussions.apple.com/thread/256182709?sortBy=rank which appears to be the same issue. Wiping the devices hasn’t helped and the problem persists.
I’m trying to install a driver for a robotics course in our school division. The teacher says that this is the correct version for their devices:https://www.silabs.com/software-and-tools/usb-to-uart-bridge-vcp-drivers?tab=downloadsUnfortunately it doesn’t seem to have a PKG installer. The drivers are a system extension and are installed through an app and not a pkg. There is a pkg in the dmg but it doesn’t install the system extension as far as I can see.I did attempt to package using Composer to monitor for changes but when I run the created pkg afterwards it fails. I’m assumning due to the system extension needing additional permissions perhaps.I have investigated this and it may be that Sonoma and beyond have the driver installed by default as per an article here:https://forum.netgate.com/topic/187597/cp210x-usb-to-uart-driver-for-mac-sonoma/3I don’t have a device to test with but will check it out tomorrow hopefully.I can handle the security for system extensions via a configur
I am new to Jamf, exploring on webhooks where iam confusing about authentication which we have to use for webhooks and do we need API access for webhooks?
Hi, kind of new to this and I don't know if there's a better place to post this question.I’m having trouble retrieving and modifying the student device restrictions using the version 4 API. I’ve used version 4 for teacher lessons, and it works fine. However, the retrieve current student device restrictions API doesn’t provide the correct information. It does not show any restrictions when there are. This is what I get back.[ { "studentId": 142 }, { "studentId": 143 }]https://api.zuludesk.com/docs/#api-Teacher-ModifyProfiles and https://api.zuludesk.com/docs/#api-Teacher-GetProfiles So, the APIs are executing, but they’re they are not working.Similarly, the modify restrictions API doesn’t give an error, but it doesn’t do anything either.For example, if I use Jamf Teacher Application to restrict a student and and I see those restrictions in effect on the JAMF teacher console, using the API to retrieve those restrictions doesn't work. It doesn't return any restrictions. It loo
Friday. Yes. Friday.macOS/iOS 26.2.• https://support.apple.com/en-us/100100
A maintenance release to Mac Admins’ new favorite, MDM-agnostic, “set-it-and-forget-it” end-user reminder for Apple’s Declarative Device Management-enforced macOS update deadlines that further simplifies enterprise-wide deployment and adds user warnings for excessive uptime and low disk space OverviewWhile Apple’s Declarative Device Management (DDM) provides Mac Admins a powerful way to enforce macOS updates, its built-in notification is often too subtle for most administrators.DDM OS Reminder evaluates the most recent `EnforcedInstallDate` and `setPastDuePaddedEnforcementDate` entries in `/var/log/install.log`, and then leverages a swiftDialog-enabled script plus a LaunchDaemon to deliver a more prominent end-user dialog that reminds users to update their Mac to comply with DDM-enforced macOS update deadlines.Continue reading …
Hello everyone,I have a problem in PreStage Enrollment, when passing through the sAMAccountName, maybe someone here has a solution for it.We need user certificates per configuration profile, which is why I set up a new PreStage Enrollment for MDM Enabled Users, but currently the ShortName (sAMAccountName) is not taken over for the AccountName if the value contains capital letters (which is unfortunately often the case here).The other attributes were already in use, which is why we used "Room" for mapping the sAMAccountName/onpremisessamaccountname, which works so far, but in PreStage only as long as there is no capital letter. If there is a uppercase letter in it, the value is not filled in the macOS account setup and the fields are not locked.AD and AAD are set up and Entra ID as IDP for SSO.There are already hundreds of rolled out Macs in this cloud instance and various dependencies on the username, which is set to the UPN. This is why we cannot generally change the usernam
A five-question self-assessment to help you plan your 2026 Mac Admin open source contributions InvitationPlease accept my personal invitation to increase — or, for you Jedi-Ninjas, to maintain — your contributions to the Mac Admin community’s various open-source projects during 2026.Take the self-assessment
So I’ve started seeing an issue with macOS 26.1 trying to set up new machines.The enrollment customization is not passing the user info from the SAML token, which is a known issue but usually sending the workaround profile that sets those attributes works fine. Here is the payload:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"> <dict> <key>EnrollmentRealName</key> <string>$REALNAME</string> <key>EnrollmentUserName</key> <string>$USERNAME</string> </dict></plist>it’s not working now, I’m not even seeing the computer’s username change in Jamf Pro after signing in through the enrollment customization like I used to. Once setup assistant completes, Jamf Connect is installed, but when I get the re-enter your password screen I cannot progress past that sin
With 15.6 and beta macos 26The EA I was using for report back a macs SSID is now broken/blocked.Does any happed to have one that will works? Thanks #!/bin/sh# Jamf Extension attribute to return SSID## Check for SSID namewifi_name=$(ipconfig getsummary en0 | awk -F ' SSID : ' '/ SSID : / {print $2}')# Check if SSID is foundif [ -z "$wifi_name" ]; then result="No Wi-Fi network found."else result="$wifi_name"fi# Result for Jamfecho "<result>$result</result>"
Jamf announced in January that the Jamf Pro Classic API will no longer support basic authentication in a future release. Classic API scripts can still run—administrators just need to make a simple change in how they authenticate. Let’s look at why this change is coming and how to convert Classic API scripts to use bearer tokens for authentication instead of usernames and passwords. The token obtained during this workflow will allow authentication to either the Classic API or the more modern Jamf Pro API. We’ll cover: How bearer tokens improve security Request the first token Parse the token Use the token to send an API command Expire the token Renew the token How bearer tokens improve security This change to move away from supplying usernames and passwords as credentials for authenticating to Jamf Pro is a good thing. Bearer tokens improve security by reducing the number of times credentials are sent to the server. Instead of sending them with every request, a token is sent instead,
We are excited to share that we’ve updated our Privacy Notices across our services to enhance clarity and transparency.Our Privacy Policy has been revised to provide greater transparency regarding our use of AI within our Services, specifically for automated email sentiment analysis, which enables us to better understand and support customer needs while maintaining data privacy standards.Jamf is certified under the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF — international frameworks that ensure robust data protection standards. In alignment with these frameworks, we have updated our Employee Privacy Notice to reflect our continued commitment to the DPF principles. We have also refined the language and defined terms in the notice.You can access the updated Privacy Policy and Employee Privacy Notice on the Jamf Trust Center Privacy page. We encourage you to review these updates. If you have any questions or concerns, please contact
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!