Get Support
Recently active
Hi,I tried to find a similar request among the existing discussions, but I haven’t been able to locate this exact situation yet.(Newbie here, so please don’t judge too harshly!)At the moment, updates for basic apps from the App Store are failing to install, resulting in:Failed command – Unhandled exception.(Emptying the list would result in recurring errors) So far, I haven’t noticed any correlation between macOS versions (ranging from 14.7.2 to 15.6.1) or hardware (M1 to M4 Pro), since updates have stopped installing for everyone.From the installation logs, it looks like this (screenshot attached). As far as I've understood, after bugging out with that script, ( cpuFeatures.split )Would anyone be able to suggest what might be causing this issue and how it could be resolved?
I’m unsure if this effects iPadOS 26.0 as I have just pushed out iPadOS 26.0.1 to devices this week. We have a Single App Mode profile for TD Snap (though app doesn’t really matter). After the device is rebooted it looks like on the home screen you can’t unlock the device.Swiping up just shows “No older notifications” but does not unlock the phone and take it to the Single App locked mode to TD Snap.Has anyone else experienced this?This iPad is on iPadOS 26.0.1. Didn’t have this issue prior to the update.
Hey Jamf Nation!Do you have questions around Admin SSO or running into issues configuring it? We are here to help!Next Monday November 17th at 2PM CST we’ll be hosting the second session of our Admin SSO series. These sessions will occur twice monthly for an hour with an open format where Jamf experts will be online to help you through enabling Admin SSO and answer any questions you may have!To sign up for an upcoming session please email beta@jamf.com. These sessions are capped at 10 customers and are first come first serve to best support a small group conversation and ensure you leave with answers or guidance towards setting up Admins SSO.We’re excited to hear from you!
Hello, We have been testing out Jamf Connect 3.5 the previous configuration we used with worked just fine with Jamf Connect 2.45.1 but after testing out Jamf connect 3.5 seems like no log in option appears during login it just shows the user. Normally we had options for SSO, local login, restart and etc. Thank you for any help in advance.
Hi All,Does anyone know a reliable method to adjust the default search provider in Safari on iOS - I am expecting it will be a custom plist.We need to shift the default search provider away from the usual google result, to “https://www.google.com?udm=14&q=<searchterm>”This forces the results into Web mode only, and prevents the AI overview returning results that are normally filtered out by Safe Mode set to Strict.Thanks
Does anyone know how to uninstall the DockUtil tool? We have been using the tool to set the Dock initially for users but macOS Big Sur does not list as supported so we want to remove it before our users upgrade. Thank you.
We look forward to JNUC all year. Then - in the blink of an eye - it’s over. Even though we’re tired (really tired), we miss it. Well, friends, you can now relive JNUC in our recap video!📸 Check it out!👉🏻 Did you see someone you know? Tag them below!👉🏻 What highlight did you like the best? Let us know in a comment. 👉🏻 Just loved the video? Shout out our talented Marketing team! Thanks for watching! I hope to see you next year!!!
Mac Admins’ new favorite, MDM-agnostic, “set-it-and-forget-it” end-user messaging for Apple’s Declarative Device Management-enforced macOS update deadlines Overview While Apple’s Declarative Device Management (DDM) provides Mac Admins a powerful method to enforce macOS updates, its built-in notification tends to be too subtle for most Mac Admins.DDM OS Reminder evaluates the most recent EnforcedInstallDate entry in /var/log/install.log, then leverages a swiftDialog-enabled script and LaunchDaemon pair to dynamically deliver a more prominent end-user message of when the user’s Mac needs to be updated to comply with DDM-enforced macOS update deadlines.Features 76-second Test-drive Implementation SupportContinue reading …
I have been tasked by our security team to limit the terminal app to only allow admin accounts to open it due to a vulnerability. Any suggestions or best practices/advice on this? I do not want to rescrict the app completely because we use it for troubleshooting but we want the standard user to be locked down as much as possible.
I was trying to deploy a screensaver custom on MacOS via jamf but wanted to understand how to do so ?
Hi everyone,I’ve recently taken over maintenance of the Jamf Protect Batch Delete project to bring it back to life and ensure it stays compatible with the latest Jamf Protect updates.The app now includes a few quality-of-life improvements most notably Select All and Deselect All buttons for easier batch management.I’ve also created a .zip release so the tool can be easily downloaded and used right away.I’d love to hear your feedback, feature ideas, or improvement suggestions to make the tool even better for the community.Feel free to comment here or open a new issue with your ideas!You can grab the latest version here:👉 Download Release v1.0Thanks for supporting this project let’s keep it alive together!— Bryanhttps://github.com/Layer-Group
Hello. This is more of a Microsoft question, but i'm not having luck down that route yet. We want Jamf Cloud to manage all of our institutionally owned iPads with MDM. We want Intune to manage all user-owned Apple devices with Application Protection Policies. The problem is, users only have 1 account. So if they sign into a corporate iPad, they get a mix of both Jamf MDM configuration profiles and Intune application protection policies on their corporate device. We want the Intune Application Protection Policies to ONLY apply when a user signs in on a personally owned device, and not a Jamf managed device. I don't know if that is possible since scoping an Application Protection Policy is based on AD group. If their ID is in that group then they get Intune App. I don't see any other criteria to filter out a device if it is Jamf MDM managed. Has anyone run into this or found a solution? Thanks
anyone getting this Sync failed: Communication error. Awaiting next sync. ????when creating a new prestage enrollments ?what's the sync interval? even after the sync interval has passed it is still displaying this Sync failed message
We have enabled Azure AD as a Cloud Identity Provider, as well as Azure AD SSO. We also have some iPads assigned to a Prestage that features an Enrollment Customization that includes an SSO Authentication pane. The pane is displaying as expected on the device, and I can sign in through that pane using my Azure AD credentials.We have enabled "Collect user and location information from Directory Service" under Inventory Collection settings.However, the "User and Location" portion of the device inventory remains blank. We've gone through multiple wipe and re-enrollment rounds with this device, as well as an "Update Inventory" MDM command... nothing.Jamf Pro’s documentation says that assigning a user to a computer or mobile device can be done “during user-initiated enrollment (LDAP users only)” - does this not include the Cloud Identity Providers such as Azure AD? Or do we have something misconfigured somewhere?
If you are wondering what the “Login Window Size” Options of WIDE, COMPACT and MAX looks like for Jamf Connect. Here they are, especially for Okta on the login screen. Not the prettiest of Login windows but at least they will give you a good idea what to expect.This was changed in 2.45.1 I believe and is still the same in 3.2.0CompactCompact Settings for Login Window SizeWideWide Settings is the same as Compact, except stretched side waysMaxMax Settings covers the date and time.
Another significant update — now including detection of outdated Electron apps which can slow down macOS 26 Tahoe — to the practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service Overview Mac Health Check provides a practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service.Built using the open-source utility swiftDialog, the solution acts as a “heads-up display” presenting real-time system health and policy compliance status in a clear and interactive format.Administrators can customize the user interface using swiftDialog’s visual capabilities, making the experience both informative and approachable.The tool logs results for review, while not altering device configuration, and a new “Silent” Operation Mode makes Mac Health Check ideal for IT visibility without end-user intrusion.Continue reading …
Anyone else using DUO on Chrome and get this new Chrome "bug" to allow DUO to access devices on the local network? I put together a teeny Config Profile to allow local network access to duo security. I’m told it will work with other Chrome extensions, such as Okta Fastpas as well.Here’s what the Plist preview looks like:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC “-//Apple//DTD PLIST 1.0//EN” “http://www.apple.com/DTDs/PropertyList-1.0.dtd”><plist version=“1.0"> <dict> <key>LocalNetworkAccessRestrictionsEnabled</key> <true/> <key>LocalNetworkAccessAllowedForUrls</key> <array> <string>[*.]duosecurity.com</string> </array> </dict></plist> Note: DO NOT neglect those box brackets if you’re using a wildcard.Create a new Configuration Profile in Jamf, Name it and apply Site and Categories as desired. Leave the settings to install on Computer Level and to Install A
I am trying to troubleshoot some problems I am having with a few of my machines. I keep seeing this error in the log files and am not sure exactly what it means JMFCommons.JamfKeychain.JamfKeychainSecurityError.failedToReadJmfKeychainPassword is what I keep seeing and I believe it is the root of all the other errors I am seeing. Can anyone shed some light on what causes this problem and how I can fix it. Thank you in advance
Does JAMF Sync suddenly require a your JAMF server to be cloud based? I’m suddenly having issues syncing jamf sync to our on prem jamf server and it has an error referencing a cloud based server which we dont have.
We experience blank/black screens after the Welcome to Mac screen. We performed a full reinstall via recovery, but experience the same again.Also tried to go into recovery, terminal, and remove /Volumes/Data/private/var/db/.AppleSetupTermsOfService but no success. Similar issues have been reported online - is there a fix for this?:https://www.reddit.com/r/mac/comments/1o3tt1i/does_anyone_know_why_its_stuck_on_the_welcome/ https://www.reddit.com/r/MacOS/comments/1kh2nbg/macbook_air_a2681_black_screen_after_welcome_to/
Today we are releasing a maintenance version of Jamf Pro; highlights include: Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI135989] Fixed: A broken access control issue.Jamf Pro Server[PI120239] Fixed: A failed declaration storage service (DSS) health check during Jamf Pro Server startup can cause an unhandled exception that prevents the server from initializing completely. [PI143843] Fixed: When opening a mobile device configuration profile's scope and returning to the Options tab, the Scope pane remains on the screen and blocks the view of the Options tab. [PI143897] Fixed: Increased CPU usage may occur when the InstallMedia command is queued in large batches. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutio
I am in a conundrum here. Fresh out of the box I need all Office Apps deployed to our users. Word, Excel, Outlook, OneNote, PowerPoint, Teams. In the last wipe and reset on a device, it was taking forever for the apps to become available. SelfService did not show them either as they are set to install automatically through the Jamf App Catalog. I am looking for advice from the community to help me figure out the best method for deployment. I need the apps to be there after deployment, my company requires them to be on the Current Channel and updated after each release of an update. I like having them visible in SelfService, but I do need the push method as well. Jamf App Catalog seems to limit this possibility unless someone has figured out a way around it. I am not on SelfService+ as of now.
I’m trying to create a policy for a screenshot repository that save screenshot to another device. Hope someone can help me.
We are having an issue with our managed Apple TVs since upgrading them to TVOS 26.Sometimes this message can be cleared by pressing the menu button on the remote or hitting “Not Now”, but most of the times it comes back, and it then takes multiple presses to clear the message.We thought we had rectified the issue by re-enrolling. But, after about a week the issue returned.We don’t sign into the Apple TVs with an account, but some of the teachers do if they are in the constantly in the same classroom. For example, the Primary school teachers. The issue still happens to them.
Hi there,A bit of background — I recently took over for our previous Jamf admin, who left unexpectedly. I have some Jamf experience (completed the training about eight years ago), but I’m still building up my troubleshooting skills.I’m working with an older iPad Pro that appears to max out at iOS 16.7.12. When I wipe the device, it doesn’t automatically grab the MDM profile or configuration during setup like our other iPads do. Instead, it just activates with Apple and sets up as a normal iPad. I can manually enroll it, but I’d prefer not to.I’ve confirmed that it’s listed in Apple School Manager, assigned to our MDM server, and included in the same PreStage Enrollment as the other iPads that work correctly after a wipe. I also tried deleting it from Jamf to see if it would re-sync, but it didn’t.One thing I’ve noticed is that under Automated Device Enrollment (DEP), the status shows “Sync Failed — Awaiting Next Sync.” However, other devices are enrolling fine, so I don’t think that’s
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!