Get Support
Recently active
We have enabled Azure AD as a Cloud Identity Provider, as well as Azure AD SSO. We also have some iPads assigned to a Prestage that features an Enrollment Customization that includes an SSO Authentication pane. The pane is displaying as expected on the device, and I can sign in through that pane using my Azure AD credentials.We have enabled "Collect user and location information from Directory Service" under Inventory Collection settings.However, the "User and Location" portion of the device inventory remains blank. We've gone through multiple wipe and re-enrollment rounds with this device, as well as an "Update Inventory" MDM command... nothing.Jamf Pro’s documentation says that assigning a user to a computer or mobile device can be done “during user-initiated enrollment (LDAP users only)” - does this not include the Cloud Identity Providers such as Azure AD? Or do we have something misconfigured somewhere?
If you are wondering what the “Login Window Size” Options of WIDE, COMPACT and MAX looks like for Jamf Connect. Here they are, especially for Okta on the login screen. Not the prettiest of Login windows but at least they will give you a good idea what to expect.This was changed in 2.45.1 I believe and is still the same in 3.2.0CompactCompact Settings for Login Window SizeWideWide Settings is the same as Compact, except stretched side waysMaxMax Settings covers the date and time.
Another significant update — now including detection of outdated Electron apps which can slow down macOS 26 Tahoe — to the practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service Overview Mac Health Check provides a practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service.Built using the open-source utility swiftDialog, the solution acts as a “heads-up display” presenting real-time system health and policy compliance status in a clear and interactive format.Administrators can customize the user interface using swiftDialog’s visual capabilities, making the experience both informative and approachable.The tool logs results for review, while not altering device configuration, and a new “Silent” Operation Mode makes Mac Health Check ideal for IT visibility without end-user intrusion.Continue reading …
Anyone else using DUO on Chrome and get this new Chrome "bug" to allow DUO to access devices on the local network? I put together a teeny Config Profile to allow local network access to duo security. I’m told it will work with other Chrome extensions, such as Okta Fastpas as well.Here’s what the Plist preview looks like:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC “-//Apple//DTD PLIST 1.0//EN” “http://www.apple.com/DTDs/PropertyList-1.0.dtd”><plist version=“1.0"> <dict> <key>LocalNetworkAccessRestrictionsEnabled</key> <true/> <key>LocalNetworkAccessAllowedForUrls</key> <array> <string>[*.]duosecurity.com</string> </array> </dict></plist> Note: DO NOT neglect those box brackets if you’re using a wildcard.Create a new Configuration Profile in Jamf, Name it and apply Site and Categories as desired. Leave the settings to install on Computer Level and to Install A
I am trying to troubleshoot some problems I am having with a few of my machines. I keep seeing this error in the log files and am not sure exactly what it means JMFCommons.JamfKeychain.JamfKeychainSecurityError.failedToReadJmfKeychainPassword is what I keep seeing and I believe it is the root of all the other errors I am seeing. Can anyone shed some light on what causes this problem and how I can fix it. Thank you in advance
Does JAMF Sync suddenly require a your JAMF server to be cloud based? I’m suddenly having issues syncing jamf sync to our on prem jamf server and it has an error referencing a cloud based server which we dont have.
We experience blank/black screens after the Welcome to Mac screen. We performed a full reinstall via recovery, but experience the same again.Also tried to go into recovery, terminal, and remove /Volumes/Data/private/var/db/.AppleSetupTermsOfService but no success. Similar issues have been reported online - is there a fix for this?:https://www.reddit.com/r/mac/comments/1o3tt1i/does_anyone_know_why_its_stuck_on_the_welcome/ https://www.reddit.com/r/MacOS/comments/1kh2nbg/macbook_air_a2681_black_screen_after_welcome_to/
Today we are releasing a maintenance version of Jamf Pro; highlights include: Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI135989] Fixed: A broken access control issue.Jamf Pro Server[PI120239] Fixed: A failed declaration storage service (DSS) health check during Jamf Pro Server startup can cause an unhandled exception that prevents the server from initializing completely. [PI143843] Fixed: When opening a mobile device configuration profile's scope and returning to the Options tab, the Scope pane remains on the screen and blocks the view of the Options tab. [PI143897] Fixed: Increased CPU usage may occur when the InstallMedia command is queued in large batches. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutio
I am in a conundrum here. Fresh out of the box I need all Office Apps deployed to our users. Word, Excel, Outlook, OneNote, PowerPoint, Teams. In the last wipe and reset on a device, it was taking forever for the apps to become available. SelfService did not show them either as they are set to install automatically through the Jamf App Catalog. I am looking for advice from the community to help me figure out the best method for deployment. I need the apps to be there after deployment, my company requires them to be on the Current Channel and updated after each release of an update. I like having them visible in SelfService, but I do need the push method as well. Jamf App Catalog seems to limit this possibility unless someone has figured out a way around it. I am not on SelfService+ as of now.
I’m trying to create a policy for a screenshot repository that save screenshot to another device. Hope someone can help me.
We are having an issue with our managed Apple TVs since upgrading them to TVOS 26.Sometimes this message can be cleared by pressing the menu button on the remote or hitting “Not Now”, but most of the times it comes back, and it then takes multiple presses to clear the message.We thought we had rectified the issue by re-enrolling. But, after about a week the issue returned.We don’t sign into the Apple TVs with an account, but some of the teachers do if they are in the constantly in the same classroom. For example, the Primary school teachers. The issue still happens to them.
Hi there,A bit of background — I recently took over for our previous Jamf admin, who left unexpectedly. I have some Jamf experience (completed the training about eight years ago), but I’m still building up my troubleshooting skills.I’m working with an older iPad Pro that appears to max out at iOS 16.7.12. When I wipe the device, it doesn’t automatically grab the MDM profile or configuration during setup like our other iPads do. Instead, it just activates with Apple and sets up as a normal iPad. I can manually enroll it, but I’d prefer not to.I’ve confirmed that it’s listed in Apple School Manager, assigned to our MDM server, and included in the same PreStage Enrollment as the other iPads that work correctly after a wipe. I also tried deleting it from Jamf to see if it would re-sync, but it didn’t.One thing I’ve noticed is that under Automated Device Enrollment (DEP), the status shows “Sync Failed — Awaiting Next Sync.” However, other devices are enrolling fine, so I don’t think that’s
Not sure I’ve seen a CVE list quite like this one... But where is 18.7.2? • macOS 26.1 - fixes 100+ CVEs• macOS 15.7.2 - fixes 50+ CVEs• macOS 14.8.2 - fixes 40+ CVEs• iOS 26.1 - fixes 50+ CVEs • watchOS 26.1 - fixes 30+ CVEs• tvOS 26.1 - fixes 29 CVEs• visionOS 26.1 - fixes 40+ CVEs • https://support.apple.com/en-us/100100
This past July, I gave my third-ever presentation at a large conference: "swiftDialog for Overworked MacAdmins," at the Penn State University MacAdmins Conference. It wasn't my first time: I also presented in 2024 at MacAdmins on the topic of Compliance, and at the Consortium of Liberal Arts Colleges as part of our security response team on a phishing response workflow. I'm not a big name speaker. I'm not a well-known blogger, or tech writer, or popular person on Slack. I'm not on LinkedIn. I don't have any particular expertise, or much formal training. I'm not even a people-person. So what do I think I have to contribute to the community? I think, like you, that I have a lot to offer. Let me tell you why. If you're at all like me, and I think most IT admins are, we're just doing the best we can in often difficult circumstances: slim budgets, staffing issues, fractally-expanding scope of work. I don't know anyone who has enough time to do all the professional development work they thin
I have an issue were computers are retaining a profile even after the computer has been removed from the scope of the profile. I have a need to allow users to create computer level WiFi Profiles using their own user level credentials. Having been advised (by JAMF back when they offered support to customers) that it is better to remove a computer from scope then to delete the profile I have another script for de-scoping the WiFi Profile. Unfortunately this does not result in the computer removing the profile. I have a hunch this might be caused by a fault in our Managed JAMF instance since previously we had a very similar issue that could only be resolved by marking a profile with a duplicate UUID as deleted. Since JAMF no longer provide support to their customers I have no way of getting this resolved. Does anyone have any suggestions on how to ensure a de-scoped profile is removed? or how to get support from JAMF?
We have historically given users who teach in Xcode the "Privileges" app from SAP because they insist that they need to run every update that comes out from Apple. Recently we noticed that one user has been abusing this app and installing various unapproved applications without going through IT first. We are wanting to see if there is a way that we can give a standard user the ability to run updates on Xcode only without having administrative privileges to do anything else or install any other applications.It looks like, in the past, a device (or user maybe?) could have been put into a Developer group which would allow them access to do things in Xcode that a standard user wouldn't, but still not be an admin. From what I have read, this doesn't seem to still be a possibility. Does anyone know if there is a guide to allow this? Or are we stuck using the Privileges app or someone from IT manually entering the admin credentials every time there is an update?
We are looking at Reigning in Apple ID use on our Institutional Laptops for security reasons. We want to prevent users from using personal Apple IDs. We know we can block the Pane for managing them and that we can prevent making changes to internet accounts. That is great. However, if you are like us, we also need to get people logged out of their personal Apple ID and or change their email on the Apple ID to a private one so they retain control when we take over control of our Domain apple ids. Our issue was how to identify who we need to work with and what type of help they need. Enter JAMF Extension Attributes. The Script below can be added to an Extension Attribute so the Apple ID will be visible in JAMF. #!/bin/bashloggedInUser=$(stat -f%Su /dev/console)icloudaccount=$( defaults read /Users/$loggedInUser/Library/Preferences/MobileMeAccounts.plist Accounts | grep AccountID | cut -d '"' -f 2 )echo "User: $loggedInUser, Apple ID: $icloudaccount"echo "<result>$icloudaccou
We took an M4 MacBook Pro that was already being used by the end user and installed Jamf Pro, which then in turn installed Connect and Protect.The installation went well. Had the user reboot and user got the message about no network connectivity. We tried a few WiFi connections and an ethernet cable. For the WiFi they are joining the networks but are failing to pull an IP. I verified in our WiFi management there was no DHCP request being sent. Had the user log in locally and they went right to black screens with a curser. A reboot only recreated the problem.However, once we rebooted into safemode, they had full network connectivity but still ran into a black screen after logging in and authenticating against Entra. I ended up having to pull off all the JAMF product to get the user working again, but the no-network-connectivity outside of safemade still persists.
Hello Everyone, Happy Monday. I’m trying to get Jamf Account SSO enabled for my Jamf Cloud instance so we can use the compliance pane, but the OIDC app I created following the steps the Jamf Learning Hub provides does not create an Okta tile because the instructions tell you to set “Login initiated by” to “App Only” instead of “Either Okta or App”. However, when setting it to “Either Okta or App” it requires a “Initiate login URI” to save the settings. Other app documentation suggests using the “Sign-in redirect URI”, but then the tile goes to an error page.Is there a different URI I can use, or is what I’m wanting not possible, and I need create a bookmark to the Jamf Account login page?
Hello there, first time Poster here. I'm pretty new to the Administration of MacOS environments. My Company just started working with JamF, and I'm trying to figure out how to best handle OS Updates for the Users.I mainly found out about the options to use Nudge in combination with erase-install to have nice notifications and a solid way to force updates, or use SUPERMAN which seem to be able to do both, notifications and forcing updates. I have already tried around with Nudge for a bit and think its pretty cool. Im hoping someone can explain in a bit more detail what SUPERMAN does differently/better or worse than Nudge+erase-install and why they are using either of the solutions or even if they have a totally different approach!
Hello everyone,We’ve been running it to some problems with some computers. Some computers doesn’t show any management commands, looks like bellow.Is there anything you can do remotely or local on the computer without needing to reinstall or reenroll?
HiWhat is the difference between the two other than one is Jamf managed (?) and the other is getting stuff from the app store?Do both update?We have only 90 macs (won’t have much more..), and 1000 vpp licenses.Are both always on the same latest version, or App Store is more up to date?In use case is there a per-say difference?Thanks
Hey guys,I have a MacBook Pro 14” 2023 that I enrolled into Jamf a few months ago. The version of macOS on it is 15.7. User requested an update to 15.71.Using the Software Updates in Content Management I sent out a command to Download and install → Specific version → 15.7.1When I go to the device inventory → Management → Operating System I see Update in progress but under that under Current state: RejectingPlan. I also tried to push out the Latest minor version but it also gives the same result. I also tried Download, install and restart and also tried to set a specific date and time but it still fails.I did a clear on failed and pending commands and tried again 5 minutes later. I also disabled the Software Updates option and then enabled it again.Any suggestions?I used Software Updates a few months ago to update 30 computers in a lab and it worked on 29 of them.Thanks!
I need to get an inventory of VS Code extension in my enviromnent. I was going down the road of using Extension Attribute. I have this script created, and using Advnced Search to view the results.This script is returning the value of “Not Installed” for devices where VS code is not installed.Devices where VS Code do not report back any installed extensions. This is the code I am using#!/bin/bash# Define the location of the Visual Studio Code executable.VSCODE_APP_PATH="/Applications/Visual Studio Code.app"# Check if VS Code is installed.if [[ -d "$VSCODE_APP_PATH" ]]; then # List all installed extensions and their versions. # The output is piped to a series of commands to format it for readability in Jamf Pro. EXTENSIONS_LIST=$(/Applications/Visual\ Studio\ Code.app/Contents/Resources/app/bin/code --list-extensions | tr '\n' ',' | sed 's/,$//' | sed 's/,/, /g') echo "<result>$EXTENSIONS_LIST</result>"else # If VS Code is not installed, report "Not Installed".
Hi All,I've never had a problem before using composer to package apps until version 10.28. When packaging a drag and drop app such as Krita or Blender, Composer has started displaying this error message during the 'Build as PKG' build process - Couldn't communicate with a helper application. I've never seen this before, it's doing it on a clean install of Catalina 10.15.7 and on a different machine with an upgrade to Big Sur 11.2.3. It will package VLC successfully but not Krita or Blender.It will create DMGs ok for all three. All three are given the same owner/group & permissions before creating a new PKG. Root, Admin and 755. Has anyone else encountered this issue and were you able to resolve it?Thanks for any info!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!