Get Support
Recently active
Today we are releasing Jamf Pro 11.31; highlights include:App Management Status Criteria for Mobile DevicesThis release adds an App Management Status criteria for mobile device smart groups and advanced searches. You can use it to find devices with unmanaged apps (e.g., App Name is X AND App Management Status is Unmanaged), or on its own to list all devices with any unmanaged app. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Subscribe to Jamf Learning Hub contentWhen logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is updated (i.e., a new version of Jamf Pro is available). For more information about the Subscribe feature, see Jamf Learning Hub Watchlist. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade ScheduleYour Jamf Pro s
• Nearly 30 CVEshttps://support.apple.com/en-us/148281
We are in the middle of a refresh for school secretaries from iMac to MacMini and are noticing an issue where some MacMini’s are not checking in with Jamf, so we are not able to push anything out to them. We used Data Migration, with Time Machine data and restored from that. We did not move over previous JAMF hidden admin account, only the account need for the user. Any thoughts on what may be happening?
If not, you really should check out https://github.com/Jamf-Concepts/Jamf-Extender (and take a look at the other repos under Jamf-Concepts while you're there). Versions for Safari, Firefox, and Chrome/Edge are available.I’m not going to list all of the capabilities of the current version, but a few that I’ve found to be _extremely_ useful are:The capabilities of MUT accessible directly from the Jamf Pro console Identify how may times a Smart Group is used as a Target or an Exclusion Convert unused Smart Groups to Advanced Computer Searches A Compare Profiles command to view the scope summary and which payloads are shared or unique (the settings in each payload are not displayed in the comparison however)Other areas where the extension adds capabilities are Blueprints, Jamf Security Cloud, and Jamf ProtectThanks to @Tribruin for calling out this very useful tool in the MacAdmins Slack #jamf-concepts-discussion channel
Hi Jamf Nation,Big news at Jamf. I'm thrilled to share that our Board of Directors has named Beth Tschida as Jamf's new CEO. Many of you already know Beth. She's been with Jamf for eight years, most recently as our CTO, and has served as Interim CEO since March.Beth has been at the heart of so much of what you rely on from Jamf: our cloud platform, our security portfolio, and our eight-year streak of same-day support for new Apple operating systems. She knows this community, she knows your work, and she knows that everything we build has to earn your trust.A quick word of thanks to John Strosahl, who led Jamf through our transition to private ownership earlier this year. John has been a great partner to this community, and we're grateful for everything he's done to set us up for what's next.Also important is what hasn't changed: our commitment to you. Managing and securing Apple at work is what we do, and with Beth leading the way, especially as AI reshapes how we need to think about w
Hey Jamf Nation!We're excited to announce SCIM-based provisioning and lifecycle management of administrator profiles in Jamf Account, now available in Beta.Inbound SCIM lets your identity provider push administrator profiles directly into Jamf Account without requiring those users to sign in first. Once configured, your IdP becomes the source of truth for administrator lifecycle events in Jamf. This beta supports Microsoft Entra ID and Okta as identity providers.Today, SCIM-provisioned profiles appear in Jamf Account, names stay current when updated in your IdP, and you can assign roles and privileges before an administrator's first login. This is the foundation for platform-wide administrator provisioning across Jamf Pro, Jamf Security Cloud, and other Jamf applications. When that work ships, your SCIM configuration carries forward with no changes required.When configuring your SCIM connection, you can also select the groups scope. Groups sync now but do not yet drive role assignments
Hello Jamf Nation!We’ve released Jamf Pro 11.32.0 beta. This release includes Inventory enhancements, a new UUID column for advanced searches and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this pr
iOS 26.6.1• Fixes 20+ security patcheshttps://support.apple.com/en-us/148282
We have been testing 27 beta with every version and I'm not sure why so late in the beta cycle during beta 5 apple decided to add new pop ups. Currently I do not see a way to manage these.
AI is being used for work every day, whether you've planned for it or not. This workshop is your chance to get in front of it instead of reacting to it.You'll learn how to see what AI apps are actually running across your Mac fleet, control them with the policy builder and Blueprints, and prove they're governed when someone asks with a PDF report. Jamf subject matter experts will walk you through it directly, and by the end, you'll have built and deployed an AI Governance policy yourself.It's free, it's 90 minutes, and it's hands-on; you're not just watching a demo, you're doing the work.Register now and pick a date and time once you're logged in with your Jamf ID.This workshop is for current Jamf customers with access to AI Governance. Not sure if that's you? Your account team can confirm — reach out anytime.Can't make this one, or want to explore more first?Watch the Jamf Short Read the AI Governance documentation Read the launch blog post Join our Product Office Hours each week wher
Hey Jamf Nation,We’ve just added our Jamf 100, 140 & 170 exam voucher codes to Jamf Nation Rewards. You could earn a free certification in the comfort of your home! The Jamf 140 course is our latest offering, launched in April this year 🎉.Check out your Jamf Account to see what’s new and start redeeming those hard-earned bytes.Not a member yet? Learn more and join here.Who’s going to be first to redeem their free exam code 👀
will their ever be a possibility that jamf adds Custom ODIC For Jamf Now, I love using jamf now in my little 1 device homelab and it would be fun if I can setup my Authentik as jamf now
Cisco Secure Client (CSC): Version 5.1.12.146MacOS: Tahoe 26.5Current issue we are facing is that when enrolling new MacBooks into our environment we are seeing that Cisco Secure Client is no longer passing through deviceID to azure to pass through conditional access policies. Previously our environment was running JAMF conditional access, and our devices were enrolling without a problem. All applications were passing deviceID and going through conditional access policies (CAPs) without any blockers. Recently we have shifted over to platform SSO as per many people’s recommendation as the old method was being deprecated. Since then, we have noticed that most applications are still working without issues, but unfortunately Cisco Secure Client is failing to pass deviceID and is now being blocked by our Azure CAPs. The main difference that I'm seeing is that the previously enrolled devices also received a WJP certificate, while the new enrollment method no longer utilizes this check. We or
Hi, I want to ask something about this issue. I’ll describe the test I’m performing.I have a macBook Pro enrolled with in Jamf Pro with Jamf connect. Authentication is done through MS Entra/Azure.The first user, user A, that logins gets a prompt to enable Filevault. User A is now a filevault enabled user.When restarting user A has to unlock the disk as expected.User A is logging out and user B logs in. Now this user is also able to unlock the filevault encrypted disk.User B is logging out and user A logs in again. User A shuts downs the macBook.And now comes the issue I’m facing. When restarting the macBook user B needs to unlock the disk. The name of user B is pre-filled and you have to enter B’s password. When pressing ‘option + enter’ you can choose for another user.So I thought, maybe because user B is the last user that was enabled for Filevault this user shows up. Still strange but let’s give it a try with user C. So after user A or B logs in and logs out again I log in with user
With Jamf Pro 11.31, use app management status as criteria in smart groups and advanced searches, group blueprint components into component blocks, and control the layout of Self Service+. Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Running RSA MFA Agent on macOS Tahoe in a Jamf-managed fleet. At the screensaver unlock, a legacy `SFAuthenticationController` "macOS wants to make changes" dialog appears before RSA's own OTP prompt. RSA has pointed us at Apple and Jamf, with no clear next step yet.While isolating it, one test stood out. Writing a stock right to `system.login.screensaver`:```sudo security authorizationdb write system.login.screensaver authenticate-session-owner-or-admin```gives the modern unlock UI (wallpaper + password) on a managed Mac, but the legacy black-screen unlock prompt on an unmanaged one — same right, same OS, only variable is management. So the legacy unlock path still exists in Tahoe; something on the managed side is suppressing it.Anyone seen this, or know what MDM-side setting (profile, restriction, DDM) would cause it? Trying to work out whether this is an Apple thing or a Jamf thing before going back to either vendor.
It would be a useful feature in ‘Classes’ if, when adding members by specifying a group, that user group were synchronised.Currently, if you add teachers and enter a complete group at the top of the selection window (‘Member of group’), only the current status of that user group is recorded. Annoyingly, it is not updated or synchronised when new teachers are added.
Need to identify and generate a report of Intel-based applications installed on Mac devices.As this is required to know application compatibility and identify software that still relies on Intel architecture, especially in preparation for future macOS 28.0 releases and Apple's ongoing transition away from Intel-based technologies such as Rosetta 2.
Happy Monday! So I just came across this issue. When a user tries to change their password using Jamf Connect, they get this Kereberos error 4.So they go into Okta and change it there. Later Jamf prompts them that the Local Password and Network password don’t match. They are able to enter the old and new passwords and get the local mac password changed to match. But Jamf still shows “password expires in 0 days”.I didn’t do the Jamf Connect setup, it was here when I joined the company, so I’m not sure exactly how to start fixing this. I’m hoping you have some tips, maybe someone has seen this before, really anything. I’ll keep doing my research, but It’s always nice to get some expert advice.-Pat
JNUC 2026 is coming to Kansas City, September 23–25*.Jamf CEO Beth Tschida sits down with Jen Kaplan to unpack this year's theme, *Power Up, and what's ahead for Apple device management.In this fireside chat, Beth explains why Kansas City's Power & Light District is the right metaphor for where Jamf is headed, how shadow AI is reshaping the work of Mac admins and CISOs, and gives a preview of one keynote moment: a workflow where the device tells you something is wrong before a frustrated user files a ticket.What's inside?What the JNUC 2026 theme "Power Up" means and why Jamf chose it for this yearHow Jamf is connecting Apple device management and endpoint security, and layering AI on topWhy shadow AI has become a day-to-day problem for IT and security teamsA preview of a JNUC 2026 keynote workflow: proactive device health before the support ticketHow to govern AI on an Apple fleetWhat the Jamf Nation Global Foundation is doing at JNUC 2026,CHAPTERS:0:00 Introduction: Jamf CEO Beth
Jamf Pro 11.30.2 (Jamf Cloud),SYMPTOMAn App Installer deployment stays IN_PROGRESS forever after the install hasalready completed successfully on the Mac. Once stuck, Jamf never issues anotherInstallEnterpriseApplication for that (Mac, title) pair. retryable is false, andper the docs "Retry all failed" does not cover in-progress deployments, so thereis no way back other than toggling the deployment off/on (a PUT to the deploymentre-dispatches it within minutes).WHAT MAKES THIS DIFFERENT FROM THE USUAL "STUCK IN PROGRESS" THREADSWe can point at a trigger. From /var/log/install.log on an affected Mac: until 2026-07-12: Will start wait for 1 apps to close with timeout: -1.0 from 2026-07-13: Will start wait for 1 apps to close with timeout: 172799July 13 is the day we set a global update deadline of 48h (previously: nodeadline, so timeout -1 = wait forever). Every stuck deployment we have datesfrom after that change. With no deadline, the install only ever happened whenthe user closed
Today we released Jamf Connect 3.12.0; highlights include: Changes and ImprovementsThe Jamf Connect login window now displays the time remaining before you can attempt to log in after an authentication lockout. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
We’re seeing an issue on multiple (more than 10 Macs, multiple hardware specs) Sonoma (14.8.8) devices which have attempted the 14.8.9 update in the last week. The OS update seems to fail, and the machine reboots, but afterwards no users are able to login (login window shakes as if incorrect password was entered, for all accounts).Booting to recovery we can use the existing user accounts to unlock the disk without any issue, so doesn’t seem to be a SecureToken issue. Using the resetpassword option from Recovery doesn’t fix the issue either, the users are all still unable to login after rebooting to the normal drive. Safe mode doesn’t help either. We can thankfully backup the users’ files (via the terminal in recovery) to an external drive, but the system itself seems to be completely hosed, and has to be erased and have a fresh OS installed.Any ideas what might be causing this sort of issue? I’ve never come across something like this before.
So as we approach the inevitable coming of Self Service + we have noticed something that would be great to remove if possible to bypass some potential issues.In the Mac menu bar the Self Service + icon does not go away no matter what at the moment, and it also has a “Get software” option in the menu that does not apply to us. So I have the following questions:1: Is there a way to automatically hide or disable the icon from showing up?or2: Is there a way to customize what menu options the icon has so that it is more applicable to different use cases where optional software deployed through self service is not a thing?
Thanks again, @boberito! https://github.com/boberito/sc_menu
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!