Get Support
Recently active
We’ve recently removed admin rights on Macs for all of our users. Does anyone know of a way to enable users to always be able to administer preferred/saved Wifi networks which are saved on their machines without having to grant them temporary admin rights?
HelloI have had someone inquire about a custom longin screen, I know its not super easy to accomplish I guess I am wondering if anyone uses a 3rd party app or found another way besides disabling SIP.
Configure Kerberos SSO for Microsoft Entra Platform Single Sign-On Reference: https://learn.microsoft.com/en-us/entra/identity/devices/device-join-macos-platform-single-sign-on-kerberos-configuration The native Kerberos Single Sign-On (Kerberos SSO) extension can work in conjunction with the Microsoft Entra Platform Single Sign-On (PSSO) extension to obtain user Kerberos certificates without binding the Mac to an on-premises domain controller. The Kerberos SSO payload can either be deployed as a separate configuration profile or added to an existing configuration profile with a payload to deploy PSSO. Single Sign On-Extension payload settings If the Setting is not listed below, the setting should not be included in your payload and left blank. Payload Type: Kerberos Realm: The name of your Kerberos realm which must be properly capitalized (e.g. EXAMPLE.COM) Hosts: Add all of the following hosts. Substitute example.com with the fully qualified
We have a configuration in place where all company MacBooks receive a push notification prompting users to activate FileVault.After entering the password, the FileVault recovery key is successfully escrowed and the process is completed as expected.However, one of our colleagues continues to receive the FileVault activation prompt several times a day — even though the recovery key has already been successfully stored in Jamf Pro.This behavior seems to affect only this specific device. How can we stop this behavior?
Hi, Has anyone yet figured a way to write an extension attribute to report whether a device is TouchID capable or not? bioutil does not seem to give any indication of capability regardless whether it's run on a TouchID capable device or not. There doesn't seem to be anything returned by system_profiler to indicate. Struggling to find anything that could be leveraged... CheersDan
Hey Jamf Nation!Do you have questions around Admin SSO in Account or are you running into issues configuring it? We are here to help!Starting next Wednesday October 29th at 2PM CST we’ll be hosting the first session of our Admin SSO in Account Outreach series. These sessions will occur twice monthly for an hour with an open format where Jamf experts will be online to help you through enabling Admin SSO in Account and answer any questions you may have!To sign up for an upcoming session please email beta@jamf.com. These sessions are capped at 10 customers and are first come first serve to best support a small group conversation and ensure you leave with answers or guidance towards setting up Admins SSO in Account.We’re excited to hear from you!
Hello, I am trying to create a configuration profile on Jamf to deploy it to my mac laptop.The .mobileconfig is built using the template mentioned here (docker.mobileconfig): https://docs.docker.com/enterprise/security/enforce-sign-in/methods/#macos-configuration-profiles-method-recommended When I try to upload this in Jamf (we use Jamf Pro) using the “Upload” option shown below, it fails with the error “File Cannot be processed” I am able to create the profile using the “New” button where I copy and paste my profile in the Property List box.I don’t suspect anything wrong with the template structure as using “New” button I am able to upload it and also I am able to directly add my profile on my mac laptop.Any idea why I am getting “File Cannot be processed” error when I use “Upload” option ?I have reviewed few old posts reporting similar error, but they are slightly different than my issue.Appreciate any help.
I'm trying to setup the GoGuardian app for a small group of our iPads. I have everything working except that I can't find a way in Jamf Pro to turn on the setting for "Allow Notifications" in the Screen Sharing section. It's off by default but it needs to be enabled so that teachers can send notifications to the iPad requesting it to open a browser tab for the student.I'm guessing that's just not something Apple allows Jamf to set, but I wanted to check with group and make sure I'm not missing something obvious. Thanks!
Attending JNUC 2025 in Denver was an incredible experience, a mix of innovation, collaboration, and community. Being surrounded by Apple IT professionals, consultants, and Jamf engineers reaffirmed how rapidly the Apple ecosystem is evolving across management, automation, and security. Key Takeaways 1. Jamf Blueprints and Compliance FrameworksThe new Blueprints feature truly changes how we approach configuration management. The ability to combine configuration profiles, policies, and restrictions into modular blueprints simplifies deployment and compliance alignment, especially for large environments.It also pairs perfectly with automated compliance reporting and remediation workflows, something I’m already planning to test in our sandbox. 2. Jamf Pro + AI IntegrationOne of my favorite announcements was the AI integration in Jamf Pro, providing smart recommendations, faster troubleshooting insights, and context-aware automation. This is going to significantly reduce admin time on repet
Hey Community! 🚨 Big reward alert!!! 🚨 From October 1st through December 31st, you can unlock SSO in your Jamf environment and instantly earn a massive 1,000 points. Yes - you heard that right: 1,000 points, our biggest reward yet! Why should you configure SSO in Jamf Account?Well, by configuring your Jamf ID or IdP with OIDC in Jamf Account, you’ll gain access to a seamless and consistent login experience across all supported Jamf products, including Jamf Pro, Jamf Protect and Jamf Security Cloud, while unlocking powerful platform features like Blueprints and Compliance Benchmarks. This unified authentication approach not only maintains your existing access policies, multi-factor authentication, and centralised identity management but also provides immediate access to current and future platform services. Need help getting started?Resources are available through Jamf Learning Hub including detailed setup guides for SSO configuration.For technical assistance, administrators can acces
Hey,I’ve tried looking for this all over and found some partial solutions that don’t really work so I wanted to ask here.I’ve been asked to set up several iMacs to auto-log off or reboot after 30 minutes of inactivity AND (this is the kicker) delete all files on Desktop, Downloads, and Documents.I found the Configuration Profile Login Window setting to auto log-off but I’ve seen that if people left unsaved documents over it doesn’t work. It seems to me some scripting is needed here and that’s still a weak spot for me so I’m putting this out to this community in the hopes of some help.Thanks in advance!
Check this new article on the Tech Thoughts Blog from @Alvaro1337 , “My JNUC Experience 2025 –Denver,Co” !
Hi everyone, I’m looking for the best way to convert mobile accounts to local accounts without using Jamf Connect, and to do it cleanly. The goal is to improve compatibility with FileVault, since it generally works better with local accounts. I’ve tested version 3.0 of https://github.com/BIG-RAT/mobile_to_local.The script seems to correctly convert the mobile account into a standard local user and successfully removes the Mac from the domain.However, after that step, I wanted to test joining the domain again the rejoin works, but I can no longer log in with any AD accounts. No matter which account or password I use, authentication just fails. Has anyone else experienced this issue or found a more reliable method ?
Troubleshooting done - Usually outlook case space issue happens if user has local archives, migration to new outlook will cause storage space issue. Outlook size remains same - Checked for logs , nothing unusual. - ran disk space analyzer didn't find anything unusual in size. - no time machine snapshots found. - if i initiate indexing in the mac, system data space reduces immediately more than 150 Gb but it increases quickly to around 50 GB within 15 - 20 min. - if i boot the mac to safe mode, the storage size remains same nothing changes. - checked launchagents, launch daemons, login items, nothing unusual, if anyone has faced this issue, let me know
Hi, I accidently Turn On "Enable LAPS for PreStage accounts", now all my DEP macbook password automatically updated. Now user not able to login to their macbook. Is there a way to revert this? Thank you.
Hey All,we are working on POC to identify settings needed to rollout JAMF Trust with Okta as per the documentation specified here : https://learn.jamf.com/en-US/bundle/jamf-security-cloud-setup-guide/page/Authorizing_Jamf_Security_in_Your_Okta_Organization.html Issue : when jamf trust is launched it will display “Onelast Thing Sign-in” window, redirects to Okta for login, upon entering credentials and MFA it will throw error message unauthorized.What was done so far. Device belongs to correct smart computer group which syncs with securitycloud. activation profile targetting correct device group. double and triple checked all settings on Okta integration and everything is correct. In Jamf Pro “User and Location” contains Email address which is exactly same as Okta user email address. including case sensitiveness. Okta application integration shows success everytime tries to login using okta credentials. But the Security cloud logs shows this Any help or tips or anyone come across
Hey All,we are working on POC to identify settings needed to rollout JAMF Trust with Okta as per the documentation specified here : https://learn.jamf.com/en-US/bundle/jamf-security-cloud-setup-guide/page/Authorizing_Jamf_Security_in_Your_Okta_Organization.html Issue : when jamf trust is launched it will display “Onelast Thing Sign-in” window, redirects to Okta for login, upon entering credentials and MFA it will not throw error message unauthorized.What was done so far. Device belongs to correct smart computer group which syncs with securitycloud. activation profile targetting correct device group. double and triple checked all settings on Okta integration and everything is correct. In Jamf Pro “User and Location” contains Email address which is exactly same as Okta user email address. including case sensitiveness. Okta application integration shows success everytime tries to login using okta credentials. But the Security cloud logs shows this Any help or tips or anyone come acr
I have a 4th gen Apple TV that was assigned to Apple Business Manager via Config 2. From there it was assigned to my Jamf and then I scoped it to a prestage enrollment. When the device boots up it attempts to activate and then jumps over to my remote management and attempts to download a config from my Jamf when the request times out. Any ideas why its not getting what its looking for. Im not even sure where I can find logs to see what is failing.
Hi all,I have been using a script that sets the Recovery Lock password on Silicon Macs without the correct Recovery Lock password already set using the following APIhttps://JAMF_PRO_URL/api/preview/mdm/commands As mentioned here:https://learn.jamf.com/en-US/bundle/technical-articles/page/Recovery_Lock_Enablement_in_macOS_Using_the_Jamf_Pro_API.htmlHowever it looks like the /preview/mdm/commands has been deprecated, can someone confirm and is there another way to do it or can it only be done with PreStage now? Source: https://developer.jamf.com/jamf-pro/docs/privileges-and-deprecations
Hello, I have been receiving the error Unable to Decrypt Encrypted profile when I push the network profile to the MacOS devices. Now none of the MacOS devices connect with the office Wifi. Any suggestions. AD CS Connector Certificate seems to be fine.
A significant update to the practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service Overview Mac Health Check provides a practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service.Built using the open-source utility swiftDialog, the solution acts as a “heads-up display” presenting real-time system health and policy compliance status in a clear and interactive format.Administrators can customize the user interface using swiftDialog’s visual capabilities, making the experience both informative and approachable.The tool logs results for review, while not altering device configuration, and a new “Silent” Operation Mode makes Mac Health Check ideal for IT visibility without end-user intrusion. Continue reading …
I’m curious about your experiences deploying Self Service Plus alongside a Jamf Connect 3.x update. I’m currently testing this and have a policy set up to install both Jamf Connect 3.x and Self Service Plus via policy.However, I’m wondering if it’s better to just upgrade Jamf Connect and use the “Use Self Service+ as the default end user application” option directly from the Jamf Pro server instead.Has anyone tested or noticed any issues in the app’s behavior or reliability during deployment with each approach?
I have created USB disabled policy and pushed over JAMF. which was success but I have noticed that through Android File transfer we are still able to send the confidential file to smart phones. is there any way to completely block file transfer to other devices like mobile phone.
In iPadOS there is a new system app, Phone.But it doesn’t seem to be blockable using a Profile, since it doesn’t seem to be present in the list of Default Applications.Has anybody found the same issue? And, more importantly, a solution?Thanks in advance.
Trying to install Chrome for Mac using the app installer. When it installs, chrome will no allow me to update manually. If I manually install chrome, then there isn’t an issue.I do not have a configuration profiles loaded for chrome.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!