Get Support
Recently active
Is there a way to force set the "Listen for" setting under Siri settings to Off?We have disabled the assistant overall, as well as applied a config profile blocking the use of Siri. However, when disabling the assistant via a plist edit, if the "Listen for" setting was set to anything other than Off when this change took place, the user now gets a popup stating "You do not have permission to use Siri" whenever they say something out loud that sounds remotely similar to "Siri".
Some additional IP address have been included in the Outbound traffic from Jamf Cloud. Please see the “Permitting Inbound/Outbound Traffic with Jamf Cloud” document located here: Permitting Inbound/Outbound Traffic with Jamf Cloud - Technical Articles | Jamf
How do we configure a computer smart group to show which computers have Touch ID configured/enrolled for locking/unlock? I’ve tried ChatGPT, Gemini, and Claude to help configure a computer extension to no avail.
Has anybody figured out how to get Language Chooser to run at first boot?if I make my image from a Install OS X.app it seems to assume that since i ran that App in English that is the language I will want everybody to use, and well my customers tend to be Global. I can make it run, but it runs on top of setup assistant and well its ugly and can be problematic if people start clicking on setup assistant before language chooser appears. Any ideas would be greatly appreciated.
Hello- Let me start by saying that I am unfamiliar with VMs. We are a 1:1 Apple School. One of our HS student’s is taking a cybersecurity class online and has requested I install Virtual Box on their MacBook, along with Ubuntu. What sort of security, privacy issues am I looking at here? We have JAMF Safe installed on all our computers. Will they be able to skirt our filters?
I wanted to see what are the options for example a user losing their password login and on the admin side resetting it. I’m aware there is FileVault and giving a recovery key but they messes up specific keychains and some other settings (portnox). I’d like to see if there is a way an admin can assist without that option. I’m planning to do a writeup after suggestions here and have documentation steps for a user.
I just found out that Pre-stage Enrollment Customization Panes do not work at all with Return to Service. How are people getting authenticated users with SSO (Cloud IDP with Entra is already setup with the connector as is Jamf Account), which translates to SSO on the device itself, also working with automatically assigned Prestage Enrollment and Return to Service? Are there good resources for best practices? I've found the documentation is lacking and Jamf 100 classes are basic. Support has mentioned Jamf Setup but that looks like it requires Shared iPads and I’d like to avoid those and we’re 1:1 with thousands of devices already. I see mention of Microsoft Authenticator with the SSO App Extension - I have this set up in Jamf School in our current implementation already but I don’t see how this works in Jamf Pro without the Azure webclip login if I can’t use a Customization Pane with Return to Service - the latter being one of the primary reasons for the move. Thanks!
We are using a PPPC profile to allow the Users to set the screensharing option by themselves. Until 26.01 it worked fine, but with 26.1 Beta the option is locked and marked as this option is set by your administrator. In Jamf itself we are only able to set the option to deny or allow the user to configure. Where we have set allow. If we remove the profile, the user needs an admin to set this option, but at least it is possible to set. Anyone experiencing the same? I already gave feedback to Apple about it.
I’ve been running a script in our labs for the last couple of years to do macOS updates after caching the installer onto devices, the script is this:/usr/bin/su -l ladmin -c "echo ADMINPASSWORD | /Applications/Install\ macOS\ Sequoia.app/Contents/Resources/startosinstall --nointeraction --agreetolicense --forcequitapps --user ADMINACCOUNT --stdinpass"This has worked perfectly fine, and continues to work on our iMacs and Mac Minis, but when I’ve tried to update our MacBooks from Sonoma to Sequoia I’m being met with this bizarre message:Result of command:Error: You must be root to do this…I don’t understand this at all, because as far as I was aware everything the Jamf binary does is already run as root. Is anybody able to shed any light as to why this is failing please?Much thanks!
Hi,I have had some issues with Jamf Pro 10.48 and had to revert back to 10.47. Unfortunately I am now stuck at the welcome screen at the welcomescreen at "Analyzing webhook_display_fields". I let it sit there for half an hour but it does not seem to do anything. When I try to restart anything it just breaks the database and I have to restore again.Has anyone had this issue and can tell me how to get out of this?Kind regardsAndreas Baumeister
Jamf School currently assigns users and devices based on the following premises:Each user is assigned a username, which Jamf School treats as a unique identifier. Devices are linked to users via this username.However, there is a design flaw in the current implementation:It is possible to create new users with an already existing username, either manually or via CSV import. Jamf School does not issue a warning or automatically adjust the username (e.g., by appending a number). The original user is silently deleted, and a new user with the same username is created. All devices previously assigned to the original user are now assigned to the new user. This behavior occurs across the entire Jamf School instance, including across different locations.Jamf School should enforce globally unique usernames across all locations.Since location managers can only view users within their own location, they cannot verify whether a username already exists elsewhere.Therefore, Jamf should implement a ce
Today we are releasing a maintenance version of Jamf Pro; highlights include: Platform SSO Reporting Functionality for the Jamf Management FrameworkJamf Conditional Access.app, which is part of the Jamf management framework installed on enrolled computers and used for device compliance with Microsoft Entra, can now report on Microsoft Entra ID Platform SSO registration status and provide additional information about the registration state, including device ID and user UPN. Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI141347] Fixed: A known vulnerability in a third-party library (CVE-2025-41249). [PI141349] Fixed: A known vulnerability in a third-party library (CVE-2025-41248). [PI141856] Fixed: A cross-site scripting (XSS) issue. [PI141857] Fixed: A cross-site scripting (XSS) issue.Jamf Pro Server[PI120484] Fixed: Jamf Pro's PreStage enrollment displays iOS 17.5 as an available minimum OS ver
We removed JAMF from a laptop but it failed to remove the MDM profile. Now, without JAMF on the machine, what is the best way to remove the profile?
I just set up a new iPad for a teacher and after enrolment all apps that should be deployed are marked as Waiting for Licenses despite having hundreds available. Things I've tried to resolve: Restart iPad Refresh Apple VPP token Re-apply profiles Re-apply apps Reset iPad and re-enrol Nothing works. Still stuck on "Waiting for Licenses". Does anyone have any ideas about what I should do to resolve this?
Simple suggestion: Could you please integrate Jamf App Catalog in Mac Onboarding so we can deploy Apps from the Jamf App Catalog? Many Apps we deploy today in Mac Onboarding would be available through the Catalog but we currently need to deploy them as Policies.
We are experiencing an issue where a users, suddenly get signed out of their Google account and unable to sign back in. When they attempt to log in, password is not accepted. The strange part is that no one changed password — not the user, nor either of our Jamf admins or Google Workspace admins. local Mac password (which is supposed to stay in sync with their Google password through Jamf Connect) still works fine, but his Google account password no longer matches. To clarify: User was logged in normally and did not request or initiate any password change. Users unexpectedly signed out of their Google account. When attempting to sign back in, Google reports the password is incorrect. Their local password on the Mac still works and allows them to log in to their device. Jamf Connect is deployed, and their local and Google passwords had been synced properly before this incident. We verified that no password reset or forced password change was made from the Google Admin Consol
So as of recently, our iPad 5th Gens are not able to enroll after factory reset to 16.7.12. We’ve had to do factory resets on iPads that are out of space. Our 6th and higher version iPad’s (17.7.10 / 18.7.1) appear to fine at the moment. Jamf Pro still claims to be supporting iPadOS 16, where JamfNow supports a minimum of 17.x. Has documentation not been updated regarding iPadOS 16?Not sure where to go at this point as we have a plethora of 5th Gen iPads still in our school environment.
I figured this would be helpful here. We use it to remotely grab logs from a Mac. Throw the script in a check-in policy and assign a computer to it. At next check-in, you will have their logs.This script will output the network quality. It then uses the API Role/Client 'Computer Attachments' (Update Computers, Read Computers, Create Computers) to pull the JAMF Computer ID using Mac serial number. It then runs sysdiagnose to create logs. It will then upload the logs to the Attachments section in the JSS portal. I set access token time to 300 because the file it uploads can be 400MB.Logs can be then downloaded from JAMF - Computers - Computer - Attachments.#!/bin/zsh --no-rcs## AUTHOR: Joshua Clark## DATE: 09/06/2025## PURPOSE: This script uses the API Role/Client 'Computer Attachments'## to pull the computer id using Mac serial number. It then runs## sysdiagnose to create logs. It will then upload the logs to the Attachments## section in the JSS portal.## NOTE: Client ID and secret
Hello guys, i am affected by the MS latest security patch Microsoft Active Directory Strong Certificate Mapping Requirements. My devices cant connect to wifi via certificates after the latest patch. My devices are not in domain, also users are local , so when i tried the objectsid Extension attribute it didnt work even though i have cloud idp as azure connected and i guess its because users are local. Do anyone have any idea how to tackle this :) Can we use UPN or some other attribute for macbbos that uses local user account and not in domain?
Hi So i’m working in school where we are setting up Apple Tvs we wanted make slideshow, although github is a good shout it is too public to use, is there any private websites that follow GDPR that could be a good recommendation? I was thinking about sharepoint, but not sure if that would work
I know JNUC 2025 in Denver isn’t even out of the gates yet but I enjoy speculating about future things. Many people seemed to think it was Denver before it was officially announced. It seems JAMF likes state capitols so far. My wife is even interested too since she normally pops along with me. The top 5 most populated state capitols are:Phoenix, AZ Austin, TX (JNUC 2023) Columbus, OH Indianapolis, IN Denver, CO (JNUC 2025)I have no knowledge of where, I just enjoy speculating. My wife hopes it will be Boston. I’d hope for Salt Lake City personally. My bet is on Indianapolis though. Just a guess though.Any guesses, insights or desires for a future JNUC (next year or beyond)?
If I turn off our current Cloud Identity Provider configuration with Google, will that remove the existing attributes from users’ User and Location fields in their profiles? My understanding is that it won’t, which would be a good thing in my case. I’m transitioning to Okta LDAP and want to make sure the current attributes remain, since I have smart groups based on department fields.
I have a custom script that I use to upload an ipa file to an in-house Jamf Pro mobile device app. I am using the endpoint: {URL}/JSSResource/fileuploads/mobiledeviceapplicationsipa/id/{app_id}?FORCE_IPA_UPLOAD=trueThe file does get added to the app in Jamf correctly, however the upload will stop at 99.9% or 100% and just hang until my timeout limit has been reached. So the script throws a timeout error. I have a check for a timeout and then check to see if the file exists in Jamf after, but this feels like a weird workaround. Am I doing something wrong? Why is Jamf not responding with a success 201 after my POST?
Does anyone have any SwiftDialog progress bar .sh examples they’re using during PreStage enrollment to enhance the end-user experience? I’m working on improving our setup workflow and would love to see how others have implemented theirs.
We have not transitioned to Jamf Self Service+ and Jamf Connect 3.x due to concerns about potential confusion among employees and the need to train them on resetting passwords and utilizing the new Self Service+. I perceive Self Service+ as a separate application that is not seamlessly integrated into Jamf. Additionally, our current Self Service is customized with our logo, which the new version does not support, which I guess is a minor inconvenience. Since Self Service is placed in the Dock during enrollment, switching to the new version would require reconfiguration using DockUtil. I am cautious about adopting it and would like to see if Jamf will replace the existing Self Service. Furthermore, Jamf Connect 3.x removes the capability to sync or change passwords via Intune, necessitating the installation of Self Service+ for this functionality. I am curious to know how many others are postponing this transition. Ideally, Jamf would update the existing Self Service to the + version. H
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!