Get Support
Recently active
Hello Jamf Nation!We’ve released Jamf Pro 11.23.0 beta which features multiple wifi payloads support in return to service, accessible terms and conditions added to the App Installers and more!How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
I got a request to have the Multitasking option to have the apps in full screen or windowed mode blocked. I’m not seeing a way in Jamf Pro to do this. Does anybody know of a way to restrict that or all of the multitasking settings or if it’s on the horizon to come at a later date?
I can’t login to account.jamf.com.
When will see Web Clips updated in Jamf Pro to include the TargetApplicationBundleIdentifier string so that we can set an app to open a Web Clip on iPadOS (e.g. set Google Chrome to open a Web Clip instead of Safari)?More information here:https://developer.apple.com/documentation/devicemanagement/webcliphttps://emm.how/t/ios-14-changes-in-configuration-profiles/1285/2 (scroll down to WebClip Payload)
HiDoes anyone know how to fully restrict an app using the safelist and blocklist payload in Jamf School? I added the path and it kind of works, but our students are Administrators on the computers so all they need to do Is click "allow once" and then use their admin login. this kind of defeats the whole purpose of blocking apps in Jamf. I also noticed that renaming the blocked app to anything else enables the user to use the app, is there any way around this?
Creating a report of our Apple TVs you are able to include the wireless mac addresses but there seems to be no option to include the wired Mac Address. Has anyone found a way to include the wired MAC in a report?
Hi, I want to have a dynamically updating swiftDialog UI appear in the login window. Each disparate part of this endeavor goes fine: swift dialog works, my launchagent works in the loginwindow domain, I can even get swiftDialog windows to spawn in the login window! Success, right? No. As soon as you bring this commandfile business into it, it stops working entirely. I’ve captured error from the /usr/local/bin/dialog script, and it reports that the “loginwindow” user cannot open the specified command file. I understand this to be a symptom of the sandboxing inflicted on the loginwindow process. I cannot find a combination of file locations, permissions, and owners that would allow me to get this working. So… I just have to ask: is this possible whatsoever? Am I barking up the wrong tree here? Could using Outset maybe make this possible?
Hello,I am trying to make a LaunchDaemon that will run a script I packaged in composer when it sees that MDM profiles have been removed from the machine.The idea is to make it easier for our end users to be enrolled into JAMF from our past MDM. As I understand it there might still be some user interaction needed but we are trying to make it as seamless as possible given that wiping is not really an option on our side nor do we have the bandwidth among the team to be able to this. In essence we deploy the package and the plist files to the end users machines(using current MDM), and when the machine becomes unmanaged from said MDM, it kicks off the process of running the pkg which contains a script to renew MDM profile. I think if the pkg is signed then we should not see too much need for user interaction. Let me know if this is feasible. Our other thought was to create a swiftDialog that walks users through running the pkg themselves but of course that is not foolproof.
Hey guys, Anyone know of a way to transparently do this on Mountain Lion or (pushing it) Lion? I've gone through the fdesetup options in Mountain Lion and nothing stands out.
Platform Single Sign On extension (PSSOe) is a framework built into macOS introduced in 2022 with the release of macOS Ventura. Intended as an extension of the Extensible Single Sign-On extension (SSOe) for cloud resources, it adds the optional functionality of syncing a local macOS UNIX user account password with a cloud identity provider password. Version 2 of the specification introduced with macOS Sonoma in 2023 extended the ability to use the cloud identity provider password at the login window and certain authorization prompts. It also introduced two additional authentication methods that allow for paired SmartCards (also known as PIV or CAC cards) for passwordless authentication and a Secure Enclave backed key that has no effect on the local account password but offers a non-phishable authentication factor for accessing cloud resources. The goal of Platform Single Sign-On is to allow users to easily access their organization resources that are gated by
Hi everyone,Does anyone know if there’s a way to block or remove Google’s AI Overview feature when using Google Search on an iPad?Our customer is currently using Safari as the browser. I’ve seen that adding “&udm=14” to the search URL can disable AI Overview on desktop browsers, but as far as I know, it’s not possible to edit the search engine URL in Safari on iPadOS.Using a different browser or switching to another search engine could work, but that feels a bit excessive.Has anyone found a workaround for this?
So I posted asking for help on this here site with a script to automatically force log off users after 30 minutes and to wipe the desktop. A helpful soul provided me with something which does that and deletes the profile which does clear the desktop. Unfortunately that would not work for the people requesting this and they came back with a new wrinkle: they wanted 2 desktop shortcuts to a couple of websites which need to be preserved when the log out and wipe takes place.I thought I found the right way to go which works in Terminal as well as when the following lines are in their own script in Jamf.find /Users/libuser/Desktop -type f -not -name "Click Here to Open a Ticket with ITS.webloc" -and -not -name "Library Homepage.webloc" -exec rm {} \;killall loginwindowThe problem is, the find command doesn’t run even though the killall loginwindow one does. If I can just get the find command to run then I’ll be all set. I read that maybe glob would work better instead of find here but I can
Anyone else out there noticing an issue where updating iPad to 26 is logging users out of their Apple ID’s??
Is there any Jamf Pro API (not the Classic API) that allows retrieval of the membership of a given static computer group?I found the endpoint GET /v2/computer-groups/smart-group-membership/{id}, which returns the membership of a smart computer group, but I couldn’t find a corresponding endpoint for static groups.If there isn’t a Jamf Pro API for retrieving the current membership of a static computer group, what’s the recommended way to add a computer to an existing static group using only the Jamf Pro API?
Dear JAMF Support Team,We have configured NDES on our internal Root CA and verified that the iPad can reach the NDES URL (https://ip/certsrv/mscep/mscep.dll) — communication is working correctly.For testing, we created a new SCEP profile in JAMF School and pushed it to the iPad. The Root CA certificate payload was successfully pushed and is reflecting on the iPad.Issue: The client certificate is not being issued. There is no certificate request appearing in the Certificate Authority. Communication between iPad SCEP profile and CA is not occurring as expected. Steps already completed: Root CA certificate pushed to iPad via JAMF School → verified installed. NDES installed and configured on Windows Enterprise CA. SCEP profile created in JAMF School with correct NDES URL and shared secret. Verified iPad can access the NDES URL via Safari. We request: JAMF School NDES / SCEP documentation to verify proper configuration. Guidance on troubleshooting why the SCEP profile is not gen
Issue:Jamf Pro / Jamf Protect CIS Level 2 profile is blocking AirDrop on my MacBook.Profile:Sequoia_cis_lvl2-security.firewall Firewall: Enabled (incoming connections restricted) Stealth Mode: Enabled (ICMP responses blocked) Problem:With this profile active, AirDrop detects my MacBook but fails to connect. The firewall blocks incoming connections needed for transfers.Request:Looking for a way to allow AirDrop while keeping the CIS Level 2 firewall policy in place — ideally via a Jamf exemption or configuration tweak that preserves compliance.
Return to Service is working well for our loan devices, but unfortunately we can no longer use the Jamf Reset app as it destroys the necessary wifi profile. The app has been a great time saver when returning devices, and we’d like it back in servic.We should be able to modify the app config with something like <key>ReturnToServiceEnabled</key> <true/>Tried that and it didn’t work. Has anyone had success with this?
Hi,We’re using Jamf Radar and I created a group where internet access should be completely blocked except for a few allowed sites (internal tools and Jira, mostly).At the moment, full blocking works as expected. I then added some test domains under Custom Rules with "Allow" selected, but they’re still being blocked.What’s strange is that a domain like reddit.com, which is allowed via a custom rule inherited from the root level, works fine. But any domain added directly at the group level doesn’t work, even if the rule looks identical.Is there a known issue with group-level custom rules not applying correctly?Is there a better way to block all internet traffic for a group and only whitelist a few domains?Thanks,Michał
I uploaded the Protect plan to Jamf Pro configuration profile. I was wondering if Protect also works on devices? I tried to upload the same file to the devices but it ends up failing. If there is any documentation for deploying to devices, please point me to it!
We have a wireless network name with an underscore in the name which has not been a problem until now. We are unable to edit the scope for the configuration profile. The page does not load properly and when clicking the add button a spinning icon appears but the search input box and list of computers never appear.
Got platform SSO working with Entra on 15 and now that 26 is out, trying to get registration during setup working. Keep getting the following error during setup: Unable to Sign-InThe single sign-on extension could not validate the domain. Contact your administrator to help get single sign-on set up.
Today, we’re excited to share news regarding Jamf’s next chapter. We’ve entered into an agreement with Francisco Partners (“FP”) to acquire all the outstanding shares of Jamf. FP is a leading global investment firm that specializes in partnering with technology and tech-enabled businesses. You can read the press release we issued here. We believe, as a private company, we will have greater flexibility to support our goals and drive continued, sustainable, long-term growth. Notably, this is expected to include increasing our investments in innovation and M&A and accelerating the value that we provide to you.Importantly, our commitment to you remains unwavering. For all of us, it’s business as usual in all respects. Our entire team remains focused on providing the same best-in-class platform, services, and support that you have come to expect from Jamf. Your Jamf point of contact will remain the same and we will continue to work with you as we always have.Thank you for your continued
Although I'm just about to build it for testing, i've seen random posts & mentions that umad no longer works in Ventura, let alone Sonoma. Does anyone have alternatives they can suggest to move users without erasing? I'm shooting to maintain the overall idea of UMAD with a dialog box that walks the user through the steps to install the new profile.
Has anyone had to upgrade phones and switch AT&T service from the old device to the new? The current phones are mainly iPhone 12 and iPhone 12 mini with physical SIMs. The new phones will be iPhone 16e. Everything old/new is supervised and none of them have AppStore or AppleID/iCloud.In the past we moved from SE 2020 to the 12, but in that case we just moved the SIM over. This time it isn’t an option. There are a few changes in Jamf Pro I am considering:Change our Prestage to display the “Add Cellular Plan” during iOS Setup Assistant. Update our default iOS restrictions payload “Modifying cellular plan” and “Modifying eSIM settings” from Disabled to Enabled.I am not sure the first one is strictly required, but my testing with an iPhone 12 we cancelled the line for previously doesn’t display the options in Settings unless I enable the eSIM modification. Are there any other settings I should look out for?ATT says they are pre-registering the eSIM, so we might not even need to change
Has anyone else encountered this yet and has a fix or work around? On the lock screen of an iOS 11 device (that is managed and supervised) a box appears at the bottom that says "This device is managed remotely. You can leave remote management in Settings." This message could be very bad if students see this. Has anyone figured out a way to remove the message or even modify it? I'd be happy leaving the first sentence and removing the second :)
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!