Get Support
Recently active
Hi there,A bit of background — I recently took over for our previous Jamf admin, who left unexpectedly. I have some Jamf experience (completed the training about eight years ago), but I’m still building up my troubleshooting skills.I’m working with an older iPad Pro that appears to max out at iOS 16.7.12. When I wipe the device, it doesn’t automatically grab the MDM profile or configuration during setup like our other iPads do. Instead, it just activates with Apple and sets up as a normal iPad. I can manually enroll it, but I’d prefer not to.I’ve confirmed that it’s listed in Apple School Manager, assigned to our MDM server, and included in the same PreStage Enrollment as the other iPads that work correctly after a wipe. I also tried deleting it from Jamf to see if it would re-sync, but it didn’t.One thing I’ve noticed is that under Automated Device Enrollment (DEP), the status shows “Sync Failed — Awaiting Next Sync.” However, other devices are enrolling fine, so I don’t think that’s
Not sure I’ve seen a CVE list quite like this one... But where is 18.7.2? • macOS 26.1 - fixes 100+ CVEs• macOS 15.7.2 - fixes 50+ CVEs• macOS 14.8.2 - fixes 40+ CVEs• iOS 26.1 - fixes 50+ CVEs • watchOS 26.1 - fixes 30+ CVEs• tvOS 26.1 - fixes 29 CVEs• visionOS 26.1 - fixes 40+ CVEs • https://support.apple.com/en-us/100100
This past July, I gave my third-ever presentation at a large conference: "swiftDialog for Overworked MacAdmins," at the Penn State University MacAdmins Conference. It wasn't my first time: I also presented in 2024 at MacAdmins on the topic of Compliance, and at the Consortium of Liberal Arts Colleges as part of our security response team on a phishing response workflow. I'm not a big name speaker. I'm not a well-known blogger, or tech writer, or popular person on Slack. I'm not on LinkedIn. I don't have any particular expertise, or much formal training. I'm not even a people-person. So what do I think I have to contribute to the community? I think, like you, that I have a lot to offer. Let me tell you why. If you're at all like me, and I think most IT admins are, we're just doing the best we can in often difficult circumstances: slim budgets, staffing issues, fractally-expanding scope of work. I don't know anyone who has enough time to do all the professional development work they thin
I have an issue were computers are retaining a profile even after the computer has been removed from the scope of the profile. I have a need to allow users to create computer level WiFi Profiles using their own user level credentials. Having been advised (by JAMF back when they offered support to customers) that it is better to remove a computer from scope then to delete the profile I have another script for de-scoping the WiFi Profile. Unfortunately this does not result in the computer removing the profile. I have a hunch this might be caused by a fault in our Managed JAMF instance since previously we had a very similar issue that could only be resolved by marking a profile with a duplicate UUID as deleted. Since JAMF no longer provide support to their customers I have no way of getting this resolved. Does anyone have any suggestions on how to ensure a de-scoped profile is removed? or how to get support from JAMF?
We have historically given users who teach in Xcode the "Privileges" app from SAP because they insist that they need to run every update that comes out from Apple. Recently we noticed that one user has been abusing this app and installing various unapproved applications without going through IT first. We are wanting to see if there is a way that we can give a standard user the ability to run updates on Xcode only without having administrative privileges to do anything else or install any other applications.It looks like, in the past, a device (or user maybe?) could have been put into a Developer group which would allow them access to do things in Xcode that a standard user wouldn't, but still not be an admin. From what I have read, this doesn't seem to still be a possibility. Does anyone know if there is a guide to allow this? Or are we stuck using the Privileges app or someone from IT manually entering the admin credentials every time there is an update?
We are looking at Reigning in Apple ID use on our Institutional Laptops for security reasons. We want to prevent users from using personal Apple IDs. We know we can block the Pane for managing them and that we can prevent making changes to internet accounts. That is great. However, if you are like us, we also need to get people logged out of their personal Apple ID and or change their email on the Apple ID to a private one so they retain control when we take over control of our Domain apple ids. Our issue was how to identify who we need to work with and what type of help they need. Enter JAMF Extension Attributes. The Script below can be added to an Extension Attribute so the Apple ID will be visible in JAMF. #!/bin/bashloggedInUser=$(stat -f%Su /dev/console)icloudaccount=$( defaults read /Users/$loggedInUser/Library/Preferences/MobileMeAccounts.plist Accounts | grep AccountID | cut -d '"' -f 2 )echo "User: $loggedInUser, Apple ID: $icloudaccount"echo "<result>$icloudaccou
We took an M4 MacBook Pro that was already being used by the end user and installed Jamf Pro, which then in turn installed Connect and Protect.The installation went well. Had the user reboot and user got the message about no network connectivity. We tried a few WiFi connections and an ethernet cable. For the WiFi they are joining the networks but are failing to pull an IP. I verified in our WiFi management there was no DHCP request being sent. Had the user log in locally and they went right to black screens with a curser. A reboot only recreated the problem.However, once we rebooted into safemode, they had full network connectivity but still ran into a black screen after logging in and authenticating against Entra. I ended up having to pull off all the JAMF product to get the user working again, but the no-network-connectivity outside of safemade still persists.
Hello Everyone, Happy Monday. I’m trying to get Jamf Account SSO enabled for my Jamf Cloud instance so we can use the compliance pane, but the OIDC app I created following the steps the Jamf Learning Hub provides does not create an Okta tile because the instructions tell you to set “Login initiated by” to “App Only” instead of “Either Okta or App”. However, when setting it to “Either Okta or App” it requires a “Initiate login URI” to save the settings. Other app documentation suggests using the “Sign-in redirect URI”, but then the tile goes to an error page.Is there a different URI I can use, or is what I’m wanting not possible, and I need create a bookmark to the Jamf Account login page?
Hello there, first time Poster here. I'm pretty new to the Administration of MacOS environments. My Company just started working with JamF, and I'm trying to figure out how to best handle OS Updates for the Users.I mainly found out about the options to use Nudge in combination with erase-install to have nice notifications and a solid way to force updates, or use SUPERMAN which seem to be able to do both, notifications and forcing updates. I have already tried around with Nudge for a bit and think its pretty cool. Im hoping someone can explain in a bit more detail what SUPERMAN does differently/better or worse than Nudge+erase-install and why they are using either of the solutions or even if they have a totally different approach!
Hello everyone,We’ve been running it to some problems with some computers. Some computers doesn’t show any management commands, looks like bellow.Is there anything you can do remotely or local on the computer without needing to reinstall or reenroll?
HiWhat is the difference between the two other than one is Jamf managed (?) and the other is getting stuff from the app store?Do both update?We have only 90 macs (won’t have much more..), and 1000 vpp licenses.Are both always on the same latest version, or App Store is more up to date?In use case is there a per-say difference?Thanks
Hey guys,I have a MacBook Pro 14” 2023 that I enrolled into Jamf a few months ago. The version of macOS on it is 15.7. User requested an update to 15.71.Using the Software Updates in Content Management I sent out a command to Download and install → Specific version → 15.7.1When I go to the device inventory → Management → Operating System I see Update in progress but under that under Current state: RejectingPlan. I also tried to push out the Latest minor version but it also gives the same result. I also tried Download, install and restart and also tried to set a specific date and time but it still fails.I did a clear on failed and pending commands and tried again 5 minutes later. I also disabled the Software Updates option and then enabled it again.Any suggestions?I used Software Updates a few months ago to update 30 computers in a lab and it worked on 29 of them.Thanks!
I need to get an inventory of VS Code extension in my enviromnent. I was going down the road of using Extension Attribute. I have this script created, and using Advnced Search to view the results.This script is returning the value of “Not Installed” for devices where VS code is not installed.Devices where VS Code do not report back any installed extensions. This is the code I am using#!/bin/bash# Define the location of the Visual Studio Code executable.VSCODE_APP_PATH="/Applications/Visual Studio Code.app"# Check if VS Code is installed.if [[ -d "$VSCODE_APP_PATH" ]]; then # List all installed extensions and their versions. # The output is piped to a series of commands to format it for readability in Jamf Pro. EXTENSIONS_LIST=$(/Applications/Visual\ Studio\ Code.app/Contents/Resources/app/bin/code --list-extensions | tr '\n' ',' | sed 's/,$//' | sed 's/,/, /g') echo "<result>$EXTENSIONS_LIST</result>"else # If VS Code is not installed, report "Not Installed".
Hi All,I've never had a problem before using composer to package apps until version 10.28. When packaging a drag and drop app such as Krita or Blender, Composer has started displaying this error message during the 'Build as PKG' build process - Couldn't communicate with a helper application. I've never seen this before, it's doing it on a clean install of Catalina 10.15.7 and on a different machine with an upgrade to Big Sur 11.2.3. It will package VLC successfully but not Krita or Blender.It will create DMGs ok for all three. All three are given the same owner/group & permissions before creating a new PKG. Root, Admin and 755. Has anyone else encountered this issue and were you able to resolve it?Thanks for any info!
Hello Jamf Nation!We’ve released Jamf Pro 11.23.0 beta which features multiple wifi payloads support in return to service, accessible terms and conditions added to the App Installers and more!How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
I got a request to have the Multitasking option to have the apps in full screen or windowed mode blocked. I’m not seeing a way in Jamf Pro to do this. Does anybody know of a way to restrict that or all of the multitasking settings or if it’s on the horizon to come at a later date?
I can’t login to account.jamf.com.
When will see Web Clips updated in Jamf Pro to include the TargetApplicationBundleIdentifier string so that we can set an app to open a Web Clip on iPadOS (e.g. set Google Chrome to open a Web Clip instead of Safari)?More information here:https://developer.apple.com/documentation/devicemanagement/webcliphttps://emm.how/t/ios-14-changes-in-configuration-profiles/1285/2 (scroll down to WebClip Payload)
HiDoes anyone know how to fully restrict an app using the safelist and blocklist payload in Jamf School? I added the path and it kind of works, but our students are Administrators on the computers so all they need to do Is click "allow once" and then use their admin login. this kind of defeats the whole purpose of blocking apps in Jamf. I also noticed that renaming the blocked app to anything else enables the user to use the app, is there any way around this?
Creating a report of our Apple TVs you are able to include the wireless mac addresses but there seems to be no option to include the wired Mac Address. Has anyone found a way to include the wired MAC in a report?
Hi, I want to have a dynamically updating swiftDialog UI appear in the login window. Each disparate part of this endeavor goes fine: swift dialog works, my launchagent works in the loginwindow domain, I can even get swiftDialog windows to spawn in the login window! Success, right? No. As soon as you bring this commandfile business into it, it stops working entirely. I’ve captured error from the /usr/local/bin/dialog script, and it reports that the “loginwindow” user cannot open the specified command file. I understand this to be a symptom of the sandboxing inflicted on the loginwindow process. I cannot find a combination of file locations, permissions, and owners that would allow me to get this working. So… I just have to ask: is this possible whatsoever? Am I barking up the wrong tree here? Could using Outset maybe make this possible?
Hello,I am trying to make a LaunchDaemon that will run a script I packaged in composer when it sees that MDM profiles have been removed from the machine.The idea is to make it easier for our end users to be enrolled into JAMF from our past MDM. As I understand it there might still be some user interaction needed but we are trying to make it as seamless as possible given that wiping is not really an option on our side nor do we have the bandwidth among the team to be able to this. In essence we deploy the package and the plist files to the end users machines(using current MDM), and when the machine becomes unmanaged from said MDM, it kicks off the process of running the pkg which contains a script to renew MDM profile. I think if the pkg is signed then we should not see too much need for user interaction. Let me know if this is feasible. Our other thought was to create a swiftDialog that walks users through running the pkg themselves but of course that is not foolproof.
Hey guys, Anyone know of a way to transparently do this on Mountain Lion or (pushing it) Lion? I've gone through the fdesetup options in Mountain Lion and nothing stands out.
Platform Single Sign On extension (PSSOe) is a framework built into macOS introduced in 2022 with the release of macOS Ventura. Intended as an extension of the Extensible Single Sign-On extension (SSOe) for cloud resources, it adds the optional functionality of syncing a local macOS UNIX user account password with a cloud identity provider password. Version 2 of the specification introduced with macOS Sonoma in 2023 extended the ability to use the cloud identity provider password at the login window and certain authorization prompts. It also introduced two additional authentication methods that allow for paired SmartCards (also known as PIV or CAC cards) for passwordless authentication and a Secure Enclave backed key that has no effect on the local account password but offers a non-phishable authentication factor for accessing cloud resources. The goal of Platform Single Sign-On is to allow users to easily access their organization resources that are gated by
Hi everyone,Does anyone know if there’s a way to block or remove Google’s AI Overview feature when using Google Search on an iPad?Our customer is currently using Safari as the browser. I’ve seen that adding “&udm=14” to the search URL can disable AI Overview on desktop browsers, but as far as I know, it’s not possible to edit the search engine URL in Safari on iPadOS.Using a different browser or switching to another search engine could work, but that feels a bit excessive.Has anyone found a workaround for this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!