Get Support
Recently active
I have created a configuration profile in Jamf Pro for MacBooks that we are deploying as part of a prison education program. Because of the environment, these devices are locked down fairly tightly with several restrictions in place.We have deployed Swift Playgrounds to all of the MacBooks through Jamf, and the application is installing successfully and appearing in the Applications folder. However, when I go to Restrictions > Applications > Allow Apps within the configuration profile, Swift Playgrounds does not appear as an available application to select.Since the application was downloaded through Jamf and successfully pushed to the devices, I am not sure why it is not being recognized in the Allow Apps list.Do you have any suggestions on what I may be missing or how I can get Swift Playgrounds to appear as an available application in the restriction settings?Any advice would be greatly appreciated.
We have been testing 27 beta with every version and I'm not sure why so late in the beta cycle during beta 5 apple decided to add new pop ups. Currently I do not see a way to manage these.
I recently had a test MacBook Air on which I had deployed Jamf Protect and also used Jamf Compliance Editor to generate CIS Level 1 controls for macOS Sonoma - all via Jamf Pro.Jamf Pro, Jamf Protect and the CIS Level 1 controls had all been successfully deployed and were operating on this laptop.As mentioned in the subject, the laptop battery ended up going flat. I therefore had plugin it in for a while to get enough charge to turn it on. Nothing unusual so far. The laptop as a result had also had its clock reset, again nothing unusual so far.When booted the Mac did not do a successful NTP sync to reset the clock correctly. This could be argued as being unusual. I am presuming this is because it was trying to do a secure e.g. SSL connection and because the clock was years incorrect that failed - certainly the web browser failed to load websites because of this and also the Jamf Pro agent was not able to sync to the Jamf Pro server for the same reason.Now where it gets more interesting
Let me bring you back to a version of me circa 2012–2015.I had been laid off from my job in a non-technical field. I wasn't in tech or IT at all, but I was a tech hobbyist. I'm sitting at home in my apartment looking at social media—what we would now call doomscrolling—and I come across a post looking for people interested in starting their own business fixing iPhones and iPads in their area.The hobbyist in me was very interested.That eventually led to me starting a small IT company where my bread and butter was fixing broken iPhone and iPad screens.My wife and I had just gotten married, and we moved out to the San Francisco Bay Area. Being in the heart of Silicon Valley, there was no shortage of broken iPhones and iPads (and eventually Samsung devices) to fix. But I could see a future where fixing five to eight phones a day would get tedious, and more importantly, wouldn't really scale financially.So I started the multi-year process of shutting down my company and focusing my career o
Hi everyone,I’m trying to set a default font in Microsoft Outlook (macOS) using Jamf Pro, and I’m running into some trouble.By default, Outlook uses Aptos, but I’d like to change it to Book Antique, which is already available on the device.What I’ve tried: I attempted to use the 3rd-party tool OutlookFontPoke by Paul Bowden @ Microsoft. Here’s what I did:• Deployed the OutlookFontPoke script and TemplateRegDB.reg via a package (both located in /private/tmp/OutlookFontPoke-master).• Created a policy in Jamf that:• Extracts the current logged-in user• Fixes permissions• Run the command as that user: sudo -u "$loggedInUser" /private/tmp/OutlookFontPoke-master/OutlookFontPoke 'Book Antique' '11.0pt' 'black' Issue: Despite several variations of the above, I keep getting this error in the script logs:WARNING: Registry DOES NOT exist at path /Library/Group Containers/UBF8T346G9.Office/MicrosoftRegistrationDB.reg. Attempting to create...mkdir: USER/Library/Group Containers: No such file or dir
Good morning All,Been trying to get my new MAC Neo’s (one for now) to authenticate at the machine level to WIFI so we can control them. We’re attempting to use the SSO extension, I actually have all of that setup. But my issue is that I don’t have WIFI at the login screen on the Mac. For the life of me I can’t figure out what I am missing or what I have configured wrong. It all appears right. The cert itself is deploying, and it does actually work to connect to WIFI and the SSID I have running. But the moment I log out as the user I lose WIFI and no one else can sign in. The Neo’s are going to be for a shared environment. That's why I want WIFI to work at that level. Any suggestions?
Hi! I need to create a profile that only allows students to access Google Classroom. This will require also having some web access to finish the login process; has anyone else done this?
For over 16 years, Apple admins have gathered at the Jamf Nation User Conference (JNUC) to learn, connect and discover better ways to manage and secure Apple devices. In its tenth year, the JNUC Diversity Sponsorship awards 10 individuals a full conference registration, a meet-and-greet with Jamf leaders, a networking happy hour and a $500 stipend to help cover expenses. We're looking for passionate people eager to learn and bring fresh perspectives to the tightest community in high tech.Applications close at 5 p.m. CST on May 1, 2026. Apply now!Read further to get all the details about Scooter and Alan's first-hand experience as scholarship recipients. SCOOTER’S STORYMy name is Scooter Kohler and I currently work at Alhambra ESD in Phoenix, Az. My journey with Apple hardware didn't start in a server room; it started in my daily life. I’ve been a MacBook user for the entirety of my adult life, drawn in by the clean hardware and stayed for the intuitive nature of the software. When the
I just wanted to share some feedback on setting up OIDC SSO with Jumpcloud. While the documentation was pretty good I do find the formatting quite congested, more spacing between steps would be good and not everything I needed wasn’t in the documentation such as the issuer URL which I used Gemini for the answer (https://oauth.id.jumpcloud.com/) if anyone is wanting to know.Other than that it’s all working and I can now get onto setting up blueprints for my devices. https://learn.jamf.com/r/en-US/jamf-account-documentation/JumpCloud
Hi,i ran into a deadend, where i need your help =) We are currently trying to setup the content cache with parent-child config.A simple ping and netcat are succeeding.I have declared the settings as followed for example:parent: 172.10.10.1child: 20.20.20.1 While reloadSettings it is showing my parent as reloaded. But with “AssetCacheManagerUtil status”i get the output:Parent: (none)i actually cannot get it running.
Is there a way to disable Notification Center completely? Or at least remove the "apps" in NC without students being able to add it back? We use LanSchool; Our math teachers are at a disadvantage since disabling "calculator.app" doesn't disable it in the NC. Restricting "calculator.app" via Jamf doesn't block it in NC, either. We're on macOS High Sierra, and the only thing I have found is the command line below (in quotes). However, I've found that due to Apple's BRILLIANT System Integrity Protection feature, you can't do this. You CAN turn SIP off, which would allow me to run the NC disable command, but can only be done in recovery mode via terminal; which of course, can't be done via Jamf. launchctl unload -w /System/Library/LaunchAgents/com.apple.notificationcenterui.plist killall NotificationCenter Any help would be really appreciated. Link on disabling, but doesn't work with High Sierra: https://gist.github.com/mikermcneil/10005651
Hi,I have an issue with Beyond Trust Bomgar client on Macs Managed with my Jamf Pro instance.I’ve made a Configuration Profile to allow Bomgar in the privacy settings, my test Mac got the rule but when i want to remote connect to my test Mac, i have to autorise 3 options.I saw many topic about this, but even if i made the same rule, it’s not working.If anyone has an idea? Thank you
Do we need to re-enroll all of our computers to make users MDM capable?
Today we released Jamf Connect 3.13.0; highlights include: Changes and ImprovementsCompatibility with macOS 27 Golden Gate To reduce excessive messaging in log files, the logs for Jamf Connect no longer include Wi-Fi interface is undefined and Couldn't retrieve hint of key 'pref.XYZ': -60005 statements. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
We have a few iMacs running Sequoia 15.5 and Jamf Connect that are going to black screens after you log in. Both local user accounts and IdP accounts are affected, but I can see the user folder is being created when we log in against our IdP, I get the account creation message but it just hangs on the black screen. Local admin account is having the same problem. I’ve tried uninstalling, restarting, and reinstalling Jamf Connect, but the problem persists. Uninstalling and logging in as a local admin user causes a beach ball to spin, but it sits there and doesn’t not progress. I’ve checked the config profiles and license and they’re all valid, and this isn’t happening fleet wide, just randomly.if I create a new user through Jamf, the user will create, but I can’t log into that account, it immediately dumps me back to the JC login window without any feedback. I can see the new user’s account by running dscl . -list /Users UniqueID but it still hangs. Resetting authchanger doesn’t help eit
Can someone help me how to block copilot app record option for corporate ios devices, i tried adding xml dictation on device apps> app configuration to block but did not worked
Hi, I’ve notice that since upgrade to macOS 26.6, I sometime get popup window requesting all kind of apps (such as browser) to access the “login” keychain. I dug a little inside the unified logs and saw that Jamf Connect get repeated exception from type “CSSMERR_DL_INVALID_DB_HANDLE”probably when trying to access the keychain. Any chance someone else also encountered this issue ? Thanks 2026-09-13 08:46:17.697211+0300 0x3477 Activity 0x9269f00 1421 0 Jamf Connect: (CFOpenDirectory) Open a given node2026-09-13 08:46:17.698036+0300 0x3477 Activity 0x9269f01 1421 0 Jamf Connect: (CFOpenDirectory) Querying records from directories2026-09-13 08:46:17.698807+0300 0x3477 Activity 0x9269f02 1421 0 Jamf Connect: (CFOpenDirectory) Open a given node2026-09-13 08:46:17.698816+0300 0x3477 Activity 0x9269f03 1421 0 Jamf Connect: (CFOpenDirectory) Querying records from directories2026-09-13 08:46:17.701048+03
We're making a behind-the-scenes improvement to how your Jamf products work together — no action needed, and nothing will be deployed to your devices as a result.Over the next several weeks, we're grouping the Jamf products you own — such as Jamf Pro, Jamf Protect, and Jamf Security Cloud — into a single "platform environment." This is the foundation for Jamf's future platform capabilities, letting your products work together as one connected experience. In most cases, we'll set this up for you; there's nothing to configure. If we can't, this has no impact on your current experience and we'll let you know in the coming weeks and provide you a way to create this Platform Environment in Jamf Account.What this means for you:Already connected Jamf Pro and Jamf Protect? Nothing changes. Your setup continues to work as it does today. Not yet connected? The two will connect automatically. Your Jamf Protect plans will appear in Jamf Pro, ready for you to review and deploy on your schedule. Set
Fortinet's recent FortiOS 5.4.1 release for their FortiGate security appliances prevents any version of FortiClient prior to 5.4.1 from registering to the appliance. Users may even get a "FortiClient is being actively blocked from registration" which can cause panic and confusion. The problem is that, as of this writing, FortiClient 5.4.1 has yet to be released. Talk about putting the cart before the horse. So let's say that you don't want to have a few hundred upset users and would rather uninstall FortiClient discretely, en masse. Fortinet's documentation tells you to run the FortiClientUninstaller GUI app to uninstall FortiClient. But here's a more streamlined and scriptable method: /Applications/FortiClientUninstaller.app/Contents/Resources/uninstall_helperrm -rf /Library/Application Support/Fortinet/ Optionally, check for the existence of the following file and delete if it exists/private/var/root/Library/Preferences/com.fortinet.FortiClientAg
I have an interesting issue. A student logins in via Jamf Connect two weeks ago.Account is created. Account has been used and logs in via Jamf Connect every day until yesterday.Teacher emails me today, saying every time the student logs in, it immediately logs him out. Remote into the Mac mini, log in via Jamf Connect, issue confirmed.Logged in via local account behind Jamf Connect, issue still exists. Looked into the device’s Computer Usage logs in Jamf… every time the sign in happens, Jamf registers the user as “root”. Now, I can purge this account and I’m sure it’ll recreate properly and log in correctly. But I’d like some insight on how this could’ve happened. Students don’t have terminal access or admin rights. And it just… randomly started yesterday.
Hello,On our Mac fleet managed with Jamf Pro, we use Jamf Connect with Google SSO. We also have a local account called “localadmin” on each Mac, and only the IT administrators know the password.We recently deployed Jamf Protect, and I would like to create an alert whenever someone logs in to the “localadmin” account on one of our Macs.I have already tried creating a Custom Analytic and using a Jamf Pro script, but I haven’t been able to get it working properly.Has anyone already implemented something similar with Jamf Protect?Ideally, I would like to receive an alert whenever a successful login to the “localadmin” account occurs.Any advice or examples of Custom Analytics would be greatly appreciated.Thanks!
I'm seeing this popup on some of our users devices since the upgrade to Monterey, but I'm not entirely sure what it's trying to do, and it seems like I need to know in order to prevent it from popping up by automating what it's trying to do. I think this is from trying to install FortiClient, but I'm not positive. How can I tell what it's doing so I can make this easier on our users?
I am trying to enroll a mac using user initiated enrollment using the enrollment url. but during the process only general profile is getting installed and the enrollment page is stuck and not moving forward.We have configured Okta as a CA with dynamic SCEP challenge. The general profile which is installed is the SCEP enrollment. Any thoughts?
Hey,First-time poster. We have an issue where we want to force install certain chromium-based extensions to certain devices. This is fine, add the custom plist with the ExtensionInstallForcelist with the GUID and update the manifest URL. This is then deployed to the required subset of users.The issue we have is scaling this with multiple extensions. This is fine if there is no overlap on the devices where this is being deployed but as soon as Extension A & Extension B are deployed to one device with multiple profiles then only one wins.Any ideas on how to deploy multiple extensions across multiple profiles when there might be overlap in the scope of devices? I’ve tried using just the plist within the preferences folder but it seems like it only respects/looks for policy within Managed Preferences instead.Many thanks for your help.
I'm seeing a number of Macs reporting that FileVault 2 is not enabled, despite the encryption state being displayed as Encrypted. I've also seen this sometimes change to show Enabled before reverting back to Not Enabled again. Is this a known issue? The machines appear to be completely fine and encryption seems to be on.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!