Get Support
Recently active
Has anyone had luck getting Accessibility to "allow" or "let standard user approve"?Similar to the post here https://community.jamf.com/t5/jamf-pro/enabling-privacy-accessibility-setting-for-ms-teams/m-p/245576#M230198 we've used the PPPC Utility to "let standard users approve" Screen Recording but does not seem to work for accessibility. We have a handful of apps that needs Accessibility to "allow" or "let standard user approve" for non-admins but cannot get it to work. Apps like MS Teams, Logitech Logi Options will not work for the "Accessibility" section. I've attempted to use the PPPC utility and though the other options work it's "Accessibility" that will just not work.
Hi everyone, I. HATE. PRINTERS. That being said, we have to work with them. and... Canon does not make it easy. Here is what I was able to find out from several places online, in order to get this "installer" to actually work. So let's jump on to our Macs and get this over with.Downloading the "Installer"1. Log into your Uniflow Online (web)2. Start Printing (Side Bar)3. Install Printer Driver > Click [Download macOS printer driver] Navigate to Download FolderOpen SmartClientMac.iso > Open SmartClientMac Volume > Notice here you only have 1 file. But actually there are 4. 3 are hidden.On your Keyboard us the show hidden files shortcut: Command+Shift+.(Period)Getting Files in the Right LocationYou will now see 3 other files. We only need the SmartClientForMac.pkg and tenantcfg.plist files.Next, Go to Finder > Go > Go to Folder (Shift+Command+G)Enter 'private/tmp'Next create a new folder called 'uniflowclient'Which is now located in private/tmp/un
Today we are releasing a maintenance version of Jamf Pro to address the following product issue:Jamf Pro Server[PI-1431] Fixed: Advanced searches and smart group calculations that include User Group or Mobile Device Group criteria may cause performance degradation. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud UpgradesNote: Jamf Pro 11.29.2 will not be mass deployed to Standard Cloud environments. To upgrade manually: Log in to Jamf Account, click View details on the Jamf Pro tile, and then click Upgrade on the appropriate instance. Note: This capability is not available for GovCloud environments and is disabled for all instances one day prior to when the scheduled standard upgrades begin.
We’re truly excited about MCP and can’t wait to explore its potential. The idea of using the MCP (Model Context Protocol) connected to Claude for managing enterprise devices through simple chats is incredibly appealing to us. If we were able to achieve similar functionality with JamfPro’s MCP, it would certainly be a fantastic solution.
I have a user that has a Jamf connect sign in pop-up window that does not allow them to type into the sign in window, nor close the pop-up. We use Google Workspace as our IdP, that is connected to our macbooks, allowing users to sign into their systems via Google SSO. This pop-up appeared for a few different users last week, however this one user is not able to close this window. For all other users that received this pop-up they also received a secondary ‘Jamf connects wants to use your confidential information’ Mac keychain window, where the user’s were able to add their Google Workspace passwords into the keychain pop-up, then choose ‘always allow’, however this one particular user did not receive this Mac keychain window, so she does not have an opportunity to allow for her to add her Google Workspace password to the Mac keychain. All she sees is a Jamf | CONNECT with her username grayed out, that she can not interact with, or close. How do I stop this window from continuing to
Hey all!Just wondering if anyone has had a similar issue where they've deployed CIS benchmarking specifically CIS lvl1 (passwordpolicy) in JAMF for devices on Tahoe, and when users are upgrade to Tahoe from Seqouia they are locked out and are unable to login? this was advised to be implemented by our sec team whilst also having jamf connectthey are jus locked out on the default mac log in screen, we have a work around of going into recovery and resetting password but do not get why they are locked out as if it was the policy i was advised it should ask the user to reset their password if does not align with the cis password policy
A Jamf ID gets you into your admin experience, support, and Jamf Account, and it also satisfies the platform authentication requirement for capabilities like blueprints, compliance benchmarks, and AI Governance. One passkey strengthens all of that at once, since Jamf Pro, Jamf Security Cloud, Jamf Protect, and Jamf Account all draw on the same credential.Authentication is moving past the password industry-wide. According to Okta's 2025 Secure Sign-in Trends Report, workforce MFA adoption is now at 70%, with phishing-resistant authenticator adoption up 63% in a single year, as organizations replace older sign-in methods rather than just add to them. That shift makes sense once you look at what a password actually is. It's the same value every time, regardless of who enters it or where, and that's what makes it risky. The moment it's exposed anywhere, in a breach at an unrelated service, that same value still works everywhere else it's been used. A passkey removes that risk entirely. Th
I am installing AdobeUninstaller and I am getting the following message because I have me Gatekeeper set to Allow apps downloaded from: "Mac App Store and Identified developers" How can I whitelist the AdobeUninstaller App? I have tryed to create a PPPC Payload but that is not working. "AdobeUninstaller" Not Opened Apple could not verify "AdobeUninstaller" is free of Malware that may harm your Mac or compromise your privacy.
We have the policies to install the following Office 2024 components in order during our prestage deployment:2024 Volume SerializerMicrosoft Excel 2024Microsoft PowerPoint 2024Microsoft Word 2024For the past couple of years, this has worked exactly as intended. The volume serializer is installed to activate the license, then the individual apps are installed one by one. After deployment these have also opened and been activated. However, over the last week or so, the activation is no longer applying. I’ve tried everything I can to try and deactivate the license/reactivate it from self service etc, but the only fix appears to be completely removing all office components, and reinstalling them - only then does the volume serializer work. I thought this might be as a result of the latest Office apps, so I reverted to using older versions of the pkg files but the problem remains. I even tried using the whole Office suite pkg but the same thing is happening. Anyone else seen this before?
We cannot update our ipad 8 from ios to ios 26.5.2 because there is not enough memory available. There are 11,31 GB free. Only around 1 GB is used by apps. Only a few kb of photos and music. The huge part is iPadOS (2,88 GB reserved for updates, 12,11 GB iPadOS) and System files (4,63 GB).We are using jamf Now.Settings - General - Software updates says: More memory needed. … minimum 13,35 GB needed…How can I trigger this update? Can jamfnow helpl to free system mememory (cache etc)?
Hi everyone,ContextI’ve encountered several machines where multiple Teams accounts (professional, personal, etc.) were registered, and removing them from the system proved to be quite difficult.I looked into various solutions, but many of the recommended methods didn’t work in my case. Every time I opened Microsoft Teams, the accounts would reappear.Here are some of the resources I consulted: https://support.microsoft.com/en-us/office/sign-out-or-remove-an-account-from-microsoft-teams-a6d76e69-e1dd-4bc4-8e5f-04ba48384487 https://learn.microsoft.com/en-us/answers/questions/2202933/how-do-i-delete-an-old-teams-account-on-mac etc. What actually worked for meI manually removed the following items from Keychain Access: OneAuthAccount login.windows.net authority_mapAnother effective solution was using a script that I adapted to fit my needs.Hopefully, this can help someone.#!/bin/zsh# Original by PAUL BOWDEN - Completely remove Microsoft Office# Change to remove credent
If you are an admin that has access to the Adobe Admin Console, you can control what services and apps are available to users via the Creative Cloud desktop app. The following Adobe support articles document what customization options are availablehttps://helpx.adobe.com/enterprise/using/customize-creative-cloud-app.html The settings are controlled on the end user machine by the ServiceConfig.xml file that is installed alongside the Adobe application withing the following location /Library/Application Support/Adobe/OOBE/Configs/Since the launch of App Installers in Jamf Pro 10.37, the ServiceConfig.xml that App Installers installed alongside any Adobe deployments had the following settings configured: Adobe Admin Console optionAdobe Admin Console valueServiceConfig.xml keyServiceConfig.xml valueEnable self-service installNoAppsPanelfalseAllow non-admins to update and install appsNoSelfServeInstallsfalseDisable auto-update for end-usersYesAppsAutoUpdatefalseEnable self-se
We are deploying beyond trust jump clients on all of our macs and following the instructions by setting up a configuration profile to enable all screen sharing, disk sharing other settings on the backend through jamf without users being notifiied however still some of the users are presented with this which is annoying for the user as well as IT team . what could have been missing in the configuration profile . any help would be greatly appreciated
Today we released Jamf Connect 3.11.0; highlights include: Changes and ImprovementsThe Jamf Connect login window now includes Simplified Chinese and Italian as supported languages. Resolved Issues[PI-1193] Fixed: The Jamf Connect login window presents the following error during authentication with Microsoft Entra ID when Use Passthrough Authentication (OIDCUsePassthroughAuth) is enabled: Password verification unsuccessful: invalid password. Contact your IT administrator. [PI-1239] Fixed: MacBook Neo computers fail to connect to Wi-Fi after a restart, preventing the Jamf Connect login window from connecting to the identity provider. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
I joined Jamf as a training instructor in March of 2022. It was a strange move for me. Prior to that, I was a mostly lone-wolf Jamf Pro admin, enjoying my days in relative solitude with a CodeRunner window and my ticket queue open, communicating mostly by typing words into a document or a chat window. When I did have to hook my laptop into a projector or share a screen during an online meeting, the majority of the time I was meeting with colleagues that I knew well already. For an introvert, not really too big of a lift, I think. So jumping into a job role where I would not only be speaking, but managing a class full of a dozen different people, mostly not-colleagues, but customers, nearly every week for four days straight, was as you can maybe imagine, a bit of a shock to the system. There were a lot of lessons I had to learn very quickly, and some new problems to try and solve, though most of them are rather specific to this job I know few readers share. But there are a few I think a
Haven't posted in a while... glad to be back, at least to ask this question:When do normal Jamf Pro customers get this?https://datajar.co.uk/products/jamf-auto-update/This seems like something that Jamf App Catalog was meant to be. This company is now owned by Jamf. Hoping this product expands from being just for MSP's to Jamf Pro customers soon. Having automatically updating Mac packaged app catalog for over 800+ apps seems like something all Jamf customers deserve. The App Catalog in Jamf Pro has not expanded as quickly as hoped, and also continues to be unreliable at times with it using the Apple Enterprise Application install API's.Thoughts?
Hi,We’ve migrated our on-prem Intranet site to SharepointOnline and I’ve been tasked to deploy the new site to our Mac fleet of about 180 Macbooks. Microsoft Edge is our Organisational standard and the way it’s going to work is that whenever Edge is launched the landing page will be the new Sharepoint Online Intranet site. The issue is, upon launching Edge it keeps prompting to authenticate via login.microsoftonline.com before the site loads. On Google Chrome it works as expected without requiring authentication. Is there anything i must configure in the configuration profile? Our Macs are not domain joined.
Hello Jamf Nation,We are excited to announce that AI Governance for Mac launches today.Organizations are adopting AI tools on Mac fast, and until now there has been no way to see which tools are sanctioned, how they are configured, or prove it to leadership. AI Governance changes that. It gives IT and security teams a dedicated control plane to define policy for AI tools like Claude Desktop, Claude Code and Codex, push it tamper-proof through blueprints, and get a real view of AI posture across the fleet.To make sure you are ready for AI Governance, you will need to meet a few criteria. AI Governance is available as part of Jamf for Mac, Jamf for Mac Hi-Ed, Business Plan and Enterprise Plan.Here is what you need to have in place: Enable SSO with Jamf Account. OIDC authentication must be enabled in Jamf Pro, connecting your environment to Jamf Account via single sign-on. This ties your identity layer to AI Governance controls so the right people can see and act on AI activity across you
In Jamf Pro, We have policies to install the 2024 Microsoft Office suite LTSC during our Provision policy which is a script that calls each policy to install individual pieces of software we want to install on a Mac.Here is the order for the Microsoft install we have 2 policies:1. Install 2024 Microsoft Office 16.106.26020821.pkg(This is the older version from February. Testing. I tried the lastest version too)2. Install Microsoft_Office_LTSC_2024_VL_Serializer.pkg(I have also tried swapping the order)Ever since I can remember this has worked exactly as intended. The Office suite is installed then the volume serializer is installed to activate the license. At first launch it opens to the templates/recent documents page.However, over the last couple weeks of testing, the activation is no longer applying. I’ve tried everything I can to try and deactivate the license/reactivate it, but the only fix appears to be completely removing all office components, and reinstalling them - only then
We use a post install script to install Zscaler by combining the script in the package using Composer to populate UserDomain and several other settings and this works fine. However, we are considering moving away from that process and leveraging Profiles as documented herehttps://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-jamf-pro-macosStep 3 outlines the requirements for a Custom configuration which is responsible for providing the cloudName.The profile in System Settings shows that the cloudName is present, however when Zscaler launches it requires the user to enter their email address and then click Login at which point it presents two options; zscalerbetazscalertwo.The profile reflects that the setup should be zscalertwo without presenting the two options above.Has anyone come across this issue?The script method injects the cloudName and works fine but would be good to get the Profiles to work.
HI!I have a problem with our Jamf Pro System.The following problem only occours since about 3 weeks and only in prestage, not in userinitiated enrollements.We are using our admin-accounts to log into jamf for the prestage enrollment. This will create a local admin-support account for the IT. So far so good.Now, after completing the enrollment, jamf forces us to type in the password of the IT-User-Account used to log in while doing the prestage enrollment. It will create a user account on this device with this account. There is no way around it. I cant change to local login.And even after the creation of the unwanted account: if i delete it it forces me to tell jamf the password of the account and creates it again.Anyone has ideas or the same problem?We didnt change anything.P.s. yes, skip account creation is checked.
Hello! I hope someone can help me with this. I've look into several other links and it does not seem to work.We generally have the Sharing preferences disabled in our Jamf using the Config Profile. We have a certain group of people who needs Screen Sharing. While we can exempt them from Sharing preferences which allows Screen Sharing, this will open up the ability for them to enable File Sharing, Media Sharing, Content Caching, and so on. 1. Is there a way to keep Sharing preferences disabled and allow only Screen Sharing? 2. Is there a way to enable Sharing preferences, allow Screen Sharing but disable the rest inside the Sharing preferences (File, media, Content cache, Bluetooth, internet sharing, printer sharing...etc)I've tried the below but it doesnt seem to work. My test machine is on Sonoma.!/bin/bash /usr/libexec/PlistBuddy -c ‘Set :com.apple.screensharing:Disabled No’ /private/var/db/launchd.db/com.apple.launchd/overrides.plist launchctl load /System/L
Hello Jamf Nation!We’ve released Jamf Pro 11.30.0 beta. This release includes Inventory and API enhancements, logging improvements and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Overview · Setup decisions for admins Managing who has access to what and keeping it current as students move between classes is one of the more tedious parts of running a school's tech environment. RapidIdentity's rostering capability takes that off your plate by pulling class data from your external sources and automatically translating it into SSO app access and student group memberships.This post walks through how the pieces fit together and the key decisions you'll face when setting it up. For step-by-step configuration, head to the Help Center.How the sync worksRapidIdentity connects to your class data source, typically a student information system (SIS) like Clever, ClassLink, or a direct CSV feed, and syncs on a schedule you control. When a student is added to a class, they're added to the corresponding group. When they're removed, access goes away. No manual intervention required.That group membership drives everything downstream: which SSO-connected apps the student can see,
Today we are releasing Jamf Pro 11.29; highlights include:Simplified Setup for Platform Single Sign-on EnhancementThis feature previously supported only a single workflow configuration where the Single Sign-on Extensions (SSOe) profile installs after the computer is enrolled with Jamf Pro. This enhancement expands the functionality of Simplified Setup for Platform SSO by including an additional workflow configuration where the SSOe profile installs at the beginning of the enrollment process, forcing users to authenticate with your identity provider (IdP) before enrollment completes.Directory Service Group CriteriaNew directory service group criteria are available for smart groups and advanced searches. Smart groups and advanced searches with these criteria use a local cache to store user information obtained from an LDAP server or cloud identity provider (IdP). For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access ne
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!