Get Support
Recently active
Hello Nation, got a request to install the Cyberark Chrome extension. no problem there. Request was made to per-configure portal URL. Cyberark gave very vague instructions on how to create this. Asking if any one has already deployed this. I am assuming it would be additional keys inside of the extensionforceintsall settings but have no idea and have not been able to track at least something similar down. already had the team open a ticket with Cyberark to at least send a vanilla profile. thans in advance for any assitance
My organization uses Jamf Setup and Jamf Reset for our users to sign in with their SSO account with Microsoft Entra ID. The user will sign in with Jamf Setup at the start of their shift and then sign out at the end. However, Jamf Reset frequently does not fully sign the user out of their SSO account, leading to the next users unable to log in. I have found that a power cycle and attempt to sign out using Jamf Reset usually fixes this problem. From what I can tell from comparing our Jamf Reset App configuration and "Managed App Configuration for Jamf Reset" documentation on learn.jamf.com, we have the standard configuration set up. Has anyone else ran into issues with Jamf Reset "hanging up"?
Today we released Jamf Connect 3.4.0; this release addresses the following product issues:[PI138079] Fixed: The offline multifactor authentication prompt closes after an incorrect entry, requiring users to enter their username and password before attempting to authenticate again. [PI139042] Fixed: Users without a local account are prompted to re-enter their Microsoft Entra ID password after entering their username and temporary password during local account creation. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hello Jamf Nation!To those of you headed to JNUC this week, we’re very excited to see all of you for another year of our amazing community coming together. We’ve released Jamf Pro 11.22.0 beta which features MDM Server Migration with App Preservation for iOS and iPadOS Devices, a number of fixes and improvements, and more!How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
This guide represents the synergy of the latest technologies from Apple and Jamf. It harnesses the power of the new Declarative Device Management (DDM) framework built into macOS 15 (Sequoia). This modern approach is unlocked by Jamf Pro version 11.8.0 or later, which introduces Software Update Blueprints. Critically, this entire workflow is powered by the Jamf Account SSO, which connects your instance to the cloud micro-services required for Blueprints to function, creating a truly modern administrative experience.The guide outlines the modern, three-part strategy for managing macOS 15 and newer in Jamf Pro. It leverages DDM via Blueprints for a reliable, automated workflow and is based on enterprise best practices for both aggressive and controlled rollouts.PrerequisitesBefore you begin, ensure your environment meets these minimum requirements:Jamf Pro: Version 11.18.0 or later. Target Computers: macOS 15 (Sequoia) or later. Device Supervision: Devices must be Supervised. Administrat
I’ve federated our domain. We never had any conflicts. I have to assist a client with capturing their domain - but we already know they’ll have conflicts.I know the end user will get an email and have to create a personal account, but what happens on the device? A person creates a new iCloud account - does the login on the device auto-switch to the new account?I’d take an educated guess Apple does their stuff to make sure purchased content moves to that account.Do they have to sign out to get to the managed ORG ID?Question is - does the device automagically become the managed ID - or do they have to sign out / into the captured ORG ID?If it’s the latter, does their purchased content get purged from the device? Or is it more of a BYOD situation where they’re logged into both?
Hello everyone, After spending hours digging through forums trying to find a reliable way to fully automate the AVID NEXIS Client Manager installation on macOS, I’m sharing this step-by-step guide to save others the same trouble I went through.Unfortunately, Avid doesn't provide much help on this topic, so I hope this helps streamline your deployment.I’m aware that this isn’t the most secure or ideal approach, and there’s definitely room for improvement — but it works for us.If you have suggestions or improvements, feel free to share!If this can help new Mac admins or anyone else, all the better! Useful resources I consulted: Managing Legacy Kernel Extensions in macOS Using Jamf Pro - Technical Articles | Jamf System extensions in macOS - Apple Support (CA) System Security Prerequisites Before any installation, it's critical to adjust macOS security settings to allow the required kernel extensions for AVID NEXIS to load properly. For Apple Silicon Macs (M1/M2/M3):Boot into recovery m
At the begining of the year we set up a Jamf Migration app with and .mobileconfig profile to assit users in moving thier company managed machine from Mosyle to Jamf. I recenlty updated the .mobileconfig profile to extend the removal date however Im experiancing an new issue that once the profile is installed and we try runninf the migration app I get a new error stating the jamf Migrate could not enroll in the destination JAMF Pro Server. What would be the next steps to resovle this?
We have some entra integration in our environment. We use connect, have enroll enrollment customizations, etc. The issue I’m having is while I can see AD groups, it seems jamf can’t see memberships (I’m assuming). When I attempt to scope a policy/config profile to an AD group (scope to everyone, limit to the AD group), it still goes to everyone with no limiting. I’m sure there’s a setting I’m missing. Has anyone seen this?
Our school district would like to defer the upcoming macOS 26 upgrade (scheduled for release on September 15) but still allow security updates for macOS Sequoia.What is the best way to configure this in Jamf Pro so that the major OS upgrade is blocked, while security updates and minor patches for Sequoia remain available? Thanks
This October, I’ll be heading to Denver, Colorado, for the Jamf Nation User Conference (JNUC 2025). It’s a week that brings together community, learning, and all things new with Jamf, and this year, I’m especially honored to be attending as one of the recipients of the JNUC Diversity Sponsorship. The Sponsorship ExperienceThe Diversity Sponsorship program reflects Jamf’s commitment to amplifying the voices of underrepresented individuals in the tech industry. Now in its ninth year, the program selects up to 10 individuals to attend JNUC with full conference registration, a travel stipend, and access to exclusive networking opportunities. Being chosen for this year’s sponsorship is both humbling and energizing. It’s not just about attending sessions or seeing the latest product announcements—it’s about being recognized as part of a broader effort to ensure diverse perspectives are present in conversations that shape the future of Apple administration and security. Why I AppliedThis will
Hi everyone,we are currently trying to figure out how to deploy apps which are only available in specific regions, e.g. Shopee (which is only available in some Asian regions if I’m not mistaken). In ABM, we can only find apps from our origin region.I cannot really find any resources on this topic. Does anyone have an idea on how to achieve this?
As part of my rollout of platform single sign-on I created a script that checks the user’s password expiration date so that we can alert the user that their password is expiring within 14 days. I want the script to run once a day. I created a launch daemon to run the script. The script and the launch daemon get installed on every Mac with PSSO setup. If the user’s password is expiring on a date that is more than 14 days away the script slimply logs the expiration date and how many days are remaining. The problem I have run into is that if the Mac is not currently connected to the internet when the launch daemon runs the script, there will be no results from the password expiration check with Microsoft. How can I get the launch daemon to run the script again? Currently I have the launch daemon configured to run at a specific hour and minute daily. The deployment script that writtes the password expiration check script and the lauch daemon takes note of the current hour and minute and us
I remember before the renovation of jamf dashboard there was an option to clear all users on shared ipad. Now with the new dashboard I didn't find it, can someone tell me where was that option? Thank you,
Hi, Tried to enable memcached across 3 servers. config as per documentation. memcached is communicating , however, i'm getting this error on the non primary servers Type Status Report https 404 - not found Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.
Right. Where do I begin.... I am going to try and be as constructive as possible rather than just complaining. We've been running Jamf Pro (currently 11.4.2) for almost two years. Since day one we had issues with out of the box or EACAS Macs fully completing enrolment. The usual state they would end up in was for the profiles to install fine, VPP apps to install, etc, but for no policies to run nor for Self Service to install. When I looked on Jamf Nation and other sources I saw that this can sometimes happen and so because I'm a scripting god I came up with an amazingly complex script that is installed as part of an PreStage Profile's enrolment package workflow. The script does the following:/usr/local/bin/jamf policyThis immediately caused enrolment to complete, the Self Service app appeared in /Applications and everything was once more right in the world. A reboot would achieve the same, but we didn't want to randomly reboot the Mac halfway through enrolment or ask the user to
I have discovered a new problem, new computers enrolled in jamf using Dep and onboarding are not fully enrolling also computers that are already enrolled when an inventory runs the computer record is not updated, looking at the logs the last inventory should have updated on the 11th / 9.on new Macs I can run recon, policy manage and renew profiles and even push the framework from the api they still don't get an enrollment complete policies and profiles get installed but no apps,on already enrolled Macs everything works except the inventory does not update I have tried stripping back the enrolling all different Macs also different networksthe jamf management daemon is not installed also self service does not launch bellow is a log from an new enrolled computer Sun Sep 28 03:12:45 iMac jamf[1139]: The SSL Certificate for https://xxxx.jamfcloud.com must be trusted for the jamf binary to connect to it.Sun Sep 28 03:12:45 iMac jamf[1139]: Enrolling computer...Sun Sep 28 03:12:46 iMac jamf[1
Good day, all! I have a couple of PreStages set up to configure newly purchased Macs for our environment that utilize JSM to install apps and configure the systems. I want to now tackle Macs already in our environment by having the customers, or our technicians, manually enroll them via the web, chiefly because they’ve already been in use and configured, and wiping them to put them in ASM isn’t an option. I want to utilize JSM to do some configuration and prompt for inventory information (ID, email, location info, etc.). Based on this discussion thread on JSM’s GitHub (https://github.com/jamf/Setup-Manager/discussions/88), I know that it’s possible to use JSM for user-initiated enrollments. My problem is that I cannot find anything on how to actually do it. Anyone out there have or know of a site, documentation, group discussion, or anything that would help me? Thanks in advance!-Terry
Hi all I’ve got an problem with my Jamf deployment at the moment and the way we use our iPads. Essentially, our filtering and monitoring solution relies upon an app being running in order to re-connect the filtering VPN if disconnected. When teachers restrict students to a specific app or apps, the filtering and monitoring app gets disabled and thus the VPN disconnects.Is there a way to force an app to never be able to be disabled by Jamf Parent or Jamf Teacher? ie. I’d like it so that if a teacher says “Right, no more anything other than Goodnotes” the filtering and monitoring app is not disabled and continues to run. Thanks in advance for any advice with this.
Hi All,I need to disable most of the "More Gestures" (third tab of System Pref>Trackpad ) for MN Online Assessments.I have tried a custom Config Profile/user level which I created by uploading the trackpad plist, but while I was able to save it, it would not deploy.The rest of my profiles appear to be working, and the test computer is receiving all other expected profiles.MCX Settings in this area specifically say 10.6 onlySo I'm trying to package using Composer>Monitor File System ChangesThe files it appears to effect are~/Library/Preferences/ByHost/.GlobalPreferences.xxxxxxxx.plist~/Library/Preferences/com.apple.driver.AppleBluetoothMultitouch.trackpad.plist~/Library/Preferences/.GlobalPreferences.plist I have tried packaging and deploying every combination of these filesDeploy via login policy with: FEU, FUT, Fix ByHost Files The settings are not applying on my target computer (and not after logging out and back in) On my package creator computer with all de
Looking for an alternative to Carddav to push a shared contact list out to shared devices. We have several shared devices that no one will log into M365 on so sharing a contact list to a group of M365 users won't work. What if I set up a shared M365 account, created a standard contact list, created an Exchange Activesync profile in Jamf, and pushed it out to the shared devices as that shared M365 user? In Activesync settings I could deselect everything except contacts.I could share that contact list from the shared account to the entire department so that everyone in the department had the shared contact list in Outlook when signed in to M365. And for the people with an assigned device and sign into M365 on that device, I could direct them to use the contact sync option in Outlook mobile to copy the shared contact list to the native IOS contacts app.Then, I could delegate access to the shared account to designated people in the department so they can manage the shared contact list that
We started implementing Homebrew packages in our deployments.and there are permissions needed for them to run smoothly. When I try get the CDHASH for the binary, they report as not signed. codesign --display -vvvvvv <binary>code object is not signed at allwhen running tccprofile on our test computer, (tccprofile) it reports cdhash for binary <dict> <key>Authorization</key> <string>Allow</string> <key>CodeRequirement</key> <string>cdhash H"5703c8d7d913bc20bb2e219173cd89267b200400"</string> <key>Identifier</key> <string>/usr/local/Cellar/restic/0.18.0/bin/restic</string> <key>IdentifierType</key> <string>path</string> </dict>my question is how to get the cdhash , or how does apple get it when its not signed?
Hi all,Anyone have any skills with deploying NinjaOne to Macs through Jamf?I’m having some troubles deploying Ninja to my environment in Jamf pro. I’m deploying the pkg using a policy. I pulled the pkg direct from my Ninja admin site using their method of acquiring the necessary file. I’m also deploying a config file to allow the necessary streamer application to run in the background and quiet install (see screenshot for config.) Every time I deploy through Jamf, the NC Streamer file does not go to the device, and the device does not enter my Ninja console. When I manually install the same pkg without Jamf, the NC Streamer installs fine and the device is added as a local machine. I’m trying to figure out where I’m going wrong with my install and why this is isn’t working through Jamf. It’s just a simple PKG in a policy and a small config file.Please let me know if anyone has suggestions for me or if I need to provide more info.I have contacted NInja support already. They claim it’s a
With Jamf Pro 11.21, administrators can see impact alert notifications when saving deployable objects, skip a new Setup Assistant pane in macOS Tahoe, and deploy even more configuration profile payloads with blueprints!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
HiI am a teacher and have two Mac suites, each with 17 machines. Is there a way to store the machine in the cloud as at the moment pupils are tied to always using the same machine, which isn’t always feasible.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!