Get Support
Recently active
Hi everyone,Does anyone know if there’s a way to block or remove Google’s AI Overview feature when using Google Search on an iPad?Our customer is currently using Safari as the browser. I’ve seen that adding “&udm=14” to the search URL can disable AI Overview on desktop browsers, but as far as I know, it’s not possible to edit the search engine URL in Safari on iPadOS.Using a different browser or switching to another search engine could work, but that feels a bit excessive.Has anyone found a workaround for this?
So I posted asking for help on this here site with a script to automatically force log off users after 30 minutes and to wipe the desktop. A helpful soul provided me with something which does that and deletes the profile which does clear the desktop. Unfortunately that would not work for the people requesting this and they came back with a new wrinkle: they wanted 2 desktop shortcuts to a couple of websites which need to be preserved when the log out and wipe takes place.I thought I found the right way to go which works in Terminal as well as when the following lines are in their own script in Jamf.find /Users/libuser/Desktop -type f -not -name "Click Here to Open a Ticket with ITS.webloc" -and -not -name "Library Homepage.webloc" -exec rm {} \;killall loginwindowThe problem is, the find command doesn’t run even though the killall loginwindow one does. If I can just get the find command to run then I’ll be all set. I read that maybe glob would work better instead of find here but I can
Anyone else out there noticing an issue where updating iPad to 26 is logging users out of their Apple ID’s??
Is there any Jamf Pro API (not the Classic API) that allows retrieval of the membership of a given static computer group?I found the endpoint GET /v2/computer-groups/smart-group-membership/{id}, which returns the membership of a smart computer group, but I couldn’t find a corresponding endpoint for static groups.If there isn’t a Jamf Pro API for retrieving the current membership of a static computer group, what’s the recommended way to add a computer to an existing static group using only the Jamf Pro API?
Dear JAMF Support Team,We have configured NDES on our internal Root CA and verified that the iPad can reach the NDES URL (https://ip/certsrv/mscep/mscep.dll) — communication is working correctly.For testing, we created a new SCEP profile in JAMF School and pushed it to the iPad. The Root CA certificate payload was successfully pushed and is reflecting on the iPad.Issue: The client certificate is not being issued. There is no certificate request appearing in the Certificate Authority. Communication between iPad SCEP profile and CA is not occurring as expected. Steps already completed: Root CA certificate pushed to iPad via JAMF School → verified installed. NDES installed and configured on Windows Enterprise CA. SCEP profile created in JAMF School with correct NDES URL and shared secret. Verified iPad can access the NDES URL via Safari. We request: JAMF School NDES / SCEP documentation to verify proper configuration. Guidance on troubleshooting why the SCEP profile is not gen
Issue:Jamf Pro / Jamf Protect CIS Level 2 profile is blocking AirDrop on my MacBook.Profile:Sequoia_cis_lvl2-security.firewall Firewall: Enabled (incoming connections restricted) Stealth Mode: Enabled (ICMP responses blocked) Problem:With this profile active, AirDrop detects my MacBook but fails to connect. The firewall blocks incoming connections needed for transfers.Request:Looking for a way to allow AirDrop while keeping the CIS Level 2 firewall policy in place — ideally via a Jamf exemption or configuration tweak that preserves compliance.
Return to Service is working well for our loan devices, but unfortunately we can no longer use the Jamf Reset app as it destroys the necessary wifi profile. The app has been a great time saver when returning devices, and we’d like it back in servic.We should be able to modify the app config with something like <key>ReturnToServiceEnabled</key> <true/>Tried that and it didn’t work. Has anyone had success with this?
Hi,We’re using Jamf Radar and I created a group where internet access should be completely blocked except for a few allowed sites (internal tools and Jira, mostly).At the moment, full blocking works as expected. I then added some test domains under Custom Rules with "Allow" selected, but they’re still being blocked.What’s strange is that a domain like reddit.com, which is allowed via a custom rule inherited from the root level, works fine. But any domain added directly at the group level doesn’t work, even if the rule looks identical.Is there a known issue with group-level custom rules not applying correctly?Is there a better way to block all internet traffic for a group and only whitelist a few domains?Thanks,Michał
I uploaded the Protect plan to Jamf Pro configuration profile. I was wondering if Protect also works on devices? I tried to upload the same file to the devices but it ends up failing. If there is any documentation for deploying to devices, please point me to it!
We have a wireless network name with an underscore in the name which has not been a problem until now. We are unable to edit the scope for the configuration profile. The page does not load properly and when clicking the add button a spinning icon appears but the search input box and list of computers never appear.
Got platform SSO working with Entra on 15 and now that 26 is out, trying to get registration during setup working. Keep getting the following error during setup: Unable to Sign-InThe single sign-on extension could not validate the domain. Contact your administrator to help get single sign-on set up.
Today, we’re excited to share news regarding Jamf’s next chapter. We’ve entered into an agreement with Francisco Partners (“FP”) to acquire all the outstanding shares of Jamf. FP is a leading global investment firm that specializes in partnering with technology and tech-enabled businesses. You can read the press release we issued here. We believe, as a private company, we will have greater flexibility to support our goals and drive continued, sustainable, long-term growth. Notably, this is expected to include increasing our investments in innovation and M&A and accelerating the value that we provide to you.Importantly, our commitment to you remains unwavering. For all of us, it’s business as usual in all respects. Our entire team remains focused on providing the same best-in-class platform, services, and support that you have come to expect from Jamf. Your Jamf point of contact will remain the same and we will continue to work with you as we always have.Thank you for your continued
Although I'm just about to build it for testing, i've seen random posts & mentions that umad no longer works in Ventura, let alone Sonoma. Does anyone have alternatives they can suggest to move users without erasing? I'm shooting to maintain the overall idea of UMAD with a dialog box that walks the user through the steps to install the new profile.
Has anyone had to upgrade phones and switch AT&T service from the old device to the new? The current phones are mainly iPhone 12 and iPhone 12 mini with physical SIMs. The new phones will be iPhone 16e. Everything old/new is supervised and none of them have AppStore or AppleID/iCloud.In the past we moved from SE 2020 to the 12, but in that case we just moved the SIM over. This time it isn’t an option. There are a few changes in Jamf Pro I am considering:Change our Prestage to display the “Add Cellular Plan” during iOS Setup Assistant. Update our default iOS restrictions payload “Modifying cellular plan” and “Modifying eSIM settings” from Disabled to Enabled.I am not sure the first one is strictly required, but my testing with an iPhone 12 we cancelled the line for previously doesn’t display the options in Settings unless I enable the eSIM modification. Are there any other settings I should look out for?ATT says they are pre-registering the eSIM, so we might not even need to change
Has anyone else encountered this yet and has a fix or work around? On the lock screen of an iOS 11 device (that is managed and supervised) a box appears at the bottom that says "This device is managed remotely. You can leave remote management in Settings." This message could be very bad if students see this. Has anyone figured out a way to remove the message or even modify it? I'd be happy leaving the first sentence and removing the second :)
When using Erase Device in Jamf School and using the Return to Service option, all goes well except the device is remembering its former user, which is not the behavior we want.We want it to be unassigned. I can’t figure out what setting I’m missing and have tried many combinations, but attached is the current enrollment settings for our School instance. There could be other settings somewhere else I’m hoping someone can point out to me!I’ve fixated on playing with two settings on under Enrollment with no change.We’ve always had the Assigned Owner option unchecked, which seems like the obvious culprit but since we haven’t had it checked is baffling. I’ve playing with the Location setting as something to try even though I wouldn’t think it would affect this. Our default was Do not change user’s or device’s location during enrollment.Please point out my obvious omission if you know!
I’ve built a number of multi-layered Advanced Searches recently, and only after using them for a while, I realized that to add these custom searches into the Dashboard, I have to create Smart Groups, but I then found out that there is no direct way for me to convert a saved Advanced Search into a Smart Group! That is such a missed opportunity for streamlining two similar processes, to convert an advanced search used for testing results into a tangible Smart Group for long-term management. Should I just stop building Advanced Searches and just build Smart Groups moving forward then? Just wanted to hear from the community about your thoughts and workflows on this matter.
With Jamf Pro 11.22, preserve apps and their data during MDM migration to Jamf Pro, deploy more configuration profile payloads with blueprints, and use compliance benchmarks with three new templates based on National Institute of Standards and Technology (NIST) publications!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Today we are releasing Jamf Pro 11.22; highlights include: MDM Server Migration with App Preservation for iOS and iPadOS DevicesYou can migrate iOS and iPadOS devices from other MDM solutions to Jamf Pro while preserving installed apps and their data. This capability leverages Apple Business Manager and Apple School Manager migration workflows, enabling you to transition devices to Jamf Pro without the traditional need to wipe or reinstall apps on the devices. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance.To upgrade manually: Log in
Updated to Jamf Pro 11.21 yesterday afternoon and have found that when enrolling iPads with a name set in Prestage and the “Enforce Mobile Device Names” option checked, the device record will have the checkbox unchecked when I click Edit on the general tab. I see 11.21.1 is out this morning, perhaps need to update again and see if this was silently resolved?
Microsoft AutoUpdate runs perfect for all Microsoft apps except Teams it always gives an “Update error” Removed it an install it again but the problem stays, any idea where to look?
Within ABM, we currently have our main domain verified, company.com. Within the “Managed Apple Accounts” section of ABM, this domain is not ‘Locked’ and ‘Domain Capture’ is not set up. Jamf Support sent us steps on how to setup Account Driven Enrollment, which requires 3 steps.Associate the domain with ABM (and verify it) Setup Federated Authentication (following the instructions found here) Host the Service Discovery JSON FileJamf told us we should create a separate domain for this task, such as company-byod.com. That we would be able to use this as a plain domain to utilize the user-initiated account driven enrollment. But unfortunately, when we try to add our IdP, it does not work.After getting off the phone with ABM Support, they stated that we must lock the domain and turn on the domain capture process. While ‘Lock’ is available for the new domain (company-byod.com), the ‘Domain Capture’ option is not available. This is most likely due to no accounts being associated with that new
Hi everyone,Has anyone run into a screensaver issue on macOS 15 after enforcing the CIS Level 1 benchmark with Jamf Pro?When the screen locks (either manually or from inactivity), the background just turns black, and the configured screensaver doesn't start.If anyone has seen this or knows of a fix, any guidance would be greatly appreciated.Thanks!
Hi All,I’ve come across a strange issue stopping me rolling out M1 MacBook Pros to our users to replace older Intel machines.I’m unable to use ARD to screen share onto an M1 Mac in these scenarios:Filevault on and Firewall onFilevault on and Firewall off Works if Filevault is off and Firewall on or Filevault is on and Firewall is off.I’ve tested a MacBook Pro 14inch and 16inch M1 running Monterey 12.0 through to 12.2 with the same result. If I test an Intel Mac with the same Filevault/Firewall on, ARD works no problem. Not sure if I’ve missed something daft on these M1 machines or a bug in Monterey on Apple silicon. Cheers,Robert.
Hello folks,I am looking to make a deployment package for our Macs that we can push via Addigy which will enroll our Mac machines into JAMF and un-enroll the devices from Addigy.Probably 99% of our devices were enrolled using Apple Configurator so most were not in DEP. But ideally we need to make this as hands off the team as possible. Hoping that we can automate most of this.What would be the best way to go about this? And how should I structure the script!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!