Get Support
Recently active
When using Erase Device in Jamf School and using the Return to Service option, all goes well except the device is remembering its former user, which is not the behavior we want.We want it to be unassigned. I can’t figure out what setting I’m missing and have tried many combinations, but attached is the current enrollment settings for our School instance. There could be other settings somewhere else I’m hoping someone can point out to me!I’ve fixated on playing with two settings on under Enrollment with no change.We’ve always had the Assigned Owner option unchecked, which seems like the obvious culprit but since we haven’t had it checked is baffling. I’ve playing with the Location setting as something to try even though I wouldn’t think it would affect this. Our default was Do not change user’s or device’s location during enrollment.Please point out my obvious omission if you know!
I’ve built a number of multi-layered Advanced Searches recently, and only after using them for a while, I realized that to add these custom searches into the Dashboard, I have to create Smart Groups, but I then found out that there is no direct way for me to convert a saved Advanced Search into a Smart Group! That is such a missed opportunity for streamlining two similar processes, to convert an advanced search used for testing results into a tangible Smart Group for long-term management. Should I just stop building Advanced Searches and just build Smart Groups moving forward then? Just wanted to hear from the community about your thoughts and workflows on this matter.
With Jamf Pro 11.22, preserve apps and their data during MDM migration to Jamf Pro, deploy more configuration profile payloads with blueprints, and use compliance benchmarks with three new templates based on National Institute of Standards and Technology (NIST) publications!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Today we are releasing Jamf Pro 11.22; highlights include: MDM Server Migration with App Preservation for iOS and iPadOS DevicesYou can migrate iOS and iPadOS devices from other MDM solutions to Jamf Pro while preserving installed apps and their data. This capability leverages Apple Business Manager and Apple School Manager migration workflows, enabling you to transition devices to Jamf Pro without the traditional need to wipe or reinstall apps on the devices. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance.To upgrade manually: Log in
Updated to Jamf Pro 11.21 yesterday afternoon and have found that when enrolling iPads with a name set in Prestage and the “Enforce Mobile Device Names” option checked, the device record will have the checkbox unchecked when I click Edit on the general tab. I see 11.21.1 is out this morning, perhaps need to update again and see if this was silently resolved?
Microsoft AutoUpdate runs perfect for all Microsoft apps except Teams it always gives an “Update error” Removed it an install it again but the problem stays, any idea where to look?
Within ABM, we currently have our main domain verified, company.com. Within the “Managed Apple Accounts” section of ABM, this domain is not ‘Locked’ and ‘Domain Capture’ is not set up. Jamf Support sent us steps on how to setup Account Driven Enrollment, which requires 3 steps.Associate the domain with ABM (and verify it) Setup Federated Authentication (following the instructions found here) Host the Service Discovery JSON FileJamf told us we should create a separate domain for this task, such as company-byod.com. That we would be able to use this as a plain domain to utilize the user-initiated account driven enrollment. But unfortunately, when we try to add our IdP, it does not work.After getting off the phone with ABM Support, they stated that we must lock the domain and turn on the domain capture process. While ‘Lock’ is available for the new domain (company-byod.com), the ‘Domain Capture’ option is not available. This is most likely due to no accounts being associated with that new
Hi everyone,Has anyone run into a screensaver issue on macOS 15 after enforcing the CIS Level 1 benchmark with Jamf Pro?When the screen locks (either manually or from inactivity), the background just turns black, and the configured screensaver doesn't start.If anyone has seen this or knows of a fix, any guidance would be greatly appreciated.Thanks!
Hi All,I’ve come across a strange issue stopping me rolling out M1 MacBook Pros to our users to replace older Intel machines.I’m unable to use ARD to screen share onto an M1 Mac in these scenarios:Filevault on and Firewall onFilevault on and Firewall off Works if Filevault is off and Firewall on or Filevault is on and Firewall is off.I’ve tested a MacBook Pro 14inch and 16inch M1 running Monterey 12.0 through to 12.2 with the same result. If I test an Intel Mac with the same Filevault/Firewall on, ARD works no problem. Not sure if I’ve missed something daft on these M1 machines or a bug in Monterey on Apple silicon. Cheers,Robert.
Hello folks,I am looking to make a deployment package for our Macs that we can push via Addigy which will enroll our Mac machines into JAMF and un-enroll the devices from Addigy.Probably 99% of our devices were enrolled using Apple Configurator so most were not in DEP. But ideally we need to make this as hands off the team as possible. Hoping that we can automate most of this.What would be the best way to go about this? And how should I structure the script!
We’ve recently removed admin rights on Macs for all of our users. Does anyone know of a way to enable users to always be able to administer preferred/saved Wifi networks which are saved on their machines without having to grant them temporary admin rights?
HelloI have had someone inquire about a custom longin screen, I know its not super easy to accomplish I guess I am wondering if anyone uses a 3rd party app or found another way besides disabling SIP.
Configure Kerberos SSO for Microsoft Entra Platform Single Sign-On Reference: https://learn.microsoft.com/en-us/entra/identity/devices/device-join-macos-platform-single-sign-on-kerberos-configuration The native Kerberos Single Sign-On (Kerberos SSO) extension can work in conjunction with the Microsoft Entra Platform Single Sign-On (PSSO) extension to obtain user Kerberos certificates without binding the Mac to an on-premises domain controller. The Kerberos SSO payload can either be deployed as a separate configuration profile or added to an existing configuration profile with a payload to deploy PSSO. Single Sign On-Extension payload settings If the Setting is not listed below, the setting should not be included in your payload and left blank. Payload Type: Kerberos Realm: The name of your Kerberos realm which must be properly capitalized (e.g. EXAMPLE.COM) Hosts: Add all of the following hosts. Substitute example.com with the fully qualified
We have a configuration in place where all company MacBooks receive a push notification prompting users to activate FileVault.After entering the password, the FileVault recovery key is successfully escrowed and the process is completed as expected.However, one of our colleagues continues to receive the FileVault activation prompt several times a day — even though the recovery key has already been successfully stored in Jamf Pro.This behavior seems to affect only this specific device. How can we stop this behavior?
Hi, Has anyone yet figured a way to write an extension attribute to report whether a device is TouchID capable or not? bioutil does not seem to give any indication of capability regardless whether it's run on a TouchID capable device or not. There doesn't seem to be anything returned by system_profiler to indicate. Struggling to find anything that could be leveraged... CheersDan
Hey Jamf Nation!Do you have questions around Admin SSO in Account or are you running into issues configuring it? We are here to help!Starting next Wednesday October 29th at 2PM CST we’ll be hosting the first session of our Admin SSO in Account Outreach series. These sessions will occur twice monthly for an hour with an open format where Jamf experts will be online to help you through enabling Admin SSO in Account and answer any questions you may have!To sign up for an upcoming session please email beta@jamf.com. These sessions are capped at 10 customers and are first come first serve to best support a small group conversation and ensure you leave with answers or guidance towards setting up Admins SSO in Account.We’re excited to hear from you!
Hello, I am trying to create a configuration profile on Jamf to deploy it to my mac laptop.The .mobileconfig is built using the template mentioned here (docker.mobileconfig): https://docs.docker.com/enterprise/security/enforce-sign-in/methods/#macos-configuration-profiles-method-recommended When I try to upload this in Jamf (we use Jamf Pro) using the “Upload” option shown below, it fails with the error “File Cannot be processed” I am able to create the profile using the “New” button where I copy and paste my profile in the Property List box.I don’t suspect anything wrong with the template structure as using “New” button I am able to upload it and also I am able to directly add my profile on my mac laptop.Any idea why I am getting “File Cannot be processed” error when I use “Upload” option ?I have reviewed few old posts reporting similar error, but they are slightly different than my issue.Appreciate any help.
I'm trying to setup the GoGuardian app for a small group of our iPads. I have everything working except that I can't find a way in Jamf Pro to turn on the setting for "Allow Notifications" in the Screen Sharing section. It's off by default but it needs to be enabled so that teachers can send notifications to the iPad requesting it to open a browser tab for the student.I'm guessing that's just not something Apple allows Jamf to set, but I wanted to check with group and make sure I'm not missing something obvious. Thanks!
Attending JNUC 2025 in Denver was an incredible experience, a mix of innovation, collaboration, and community. Being surrounded by Apple IT professionals, consultants, and Jamf engineers reaffirmed how rapidly the Apple ecosystem is evolving across management, automation, and security. Key Takeaways 1. Jamf Blueprints and Compliance FrameworksThe new Blueprints feature truly changes how we approach configuration management. The ability to combine configuration profiles, policies, and restrictions into modular blueprints simplifies deployment and compliance alignment, especially for large environments.It also pairs perfectly with automated compliance reporting and remediation workflows, something I’m already planning to test in our sandbox. 2. Jamf Pro + AI IntegrationOne of my favorite announcements was the AI integration in Jamf Pro, providing smart recommendations, faster troubleshooting insights, and context-aware automation. This is going to significantly reduce admin time on repet
Hey Community! 🚨 Big reward alert!!! 🚨 From October 1st through December 31st, you can unlock SSO in your Jamf environment and instantly earn a massive 1,000 points. Yes - you heard that right: 1,000 points, our biggest reward yet! Why should you configure SSO in Jamf Account?Well, by configuring your Jamf ID or IdP with OIDC in Jamf Account, you’ll gain access to a seamless and consistent login experience across all supported Jamf products, including Jamf Pro, Jamf Protect and Jamf Security Cloud, while unlocking powerful platform features like Blueprints and Compliance Benchmarks. This unified authentication approach not only maintains your existing access policies, multi-factor authentication, and centralised identity management but also provides immediate access to current and future platform services. Need help getting started?Resources are available through Jamf Learning Hub including detailed setup guides for SSO configuration.For technical assistance, administrators can acces
Hey,I’ve tried looking for this all over and found some partial solutions that don’t really work so I wanted to ask here.I’ve been asked to set up several iMacs to auto-log off or reboot after 30 minutes of inactivity AND (this is the kicker) delete all files on Desktop, Downloads, and Documents.I found the Configuration Profile Login Window setting to auto log-off but I’ve seen that if people left unsaved documents over it doesn’t work. It seems to me some scripting is needed here and that’s still a weak spot for me so I’m putting this out to this community in the hopes of some help.Thanks in advance!
Check this new article on the Tech Thoughts Blog from @Alvaro1337 , “My JNUC Experience 2025 –Denver,Co” !
Hi everyone, I’m looking for the best way to convert mobile accounts to local accounts without using Jamf Connect, and to do it cleanly. The goal is to improve compatibility with FileVault, since it generally works better with local accounts. I’ve tested version 3.0 of https://github.com/BIG-RAT/mobile_to_local.The script seems to correctly convert the mobile account into a standard local user and successfully removes the Mac from the domain.However, after that step, I wanted to test joining the domain again the rejoin works, but I can no longer log in with any AD accounts. No matter which account or password I use, authentication just fails. Has anyone else experienced this issue or found a more reliable method ?
Troubleshooting done - Usually outlook case space issue happens if user has local archives, migration to new outlook will cause storage space issue. Outlook size remains same - Checked for logs , nothing unusual. - ran disk space analyzer didn't find anything unusual in size. - no time machine snapshots found. - if i initiate indexing in the mac, system data space reduces immediately more than 150 Gb but it increases quickly to around 50 GB within 15 - 20 min. - if i boot the mac to safe mode, the storage size remains same nothing changes. - checked launchagents, launch daemons, login items, nothing unusual, if anyone has faced this issue, let me know
Hi, I accidently Turn On "Enable LAPS for PreStage accounts", now all my DEP macbook password automatically updated. Now user not able to login to their macbook. Is there a way to revert this? Thank you.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!