Get Support
Recently active
A quick-fix during Platform Single Sign-on testing for when users can’t unlock their Macs via Touch ID Background We’ve been testing multiple vendors’ implementation of Apple’s Platform Single Sign-on for the past few months.During our testing, we inadvertently discovered that users can’t unlock their Macs via Touch ID when transitioning from one Platform SSO vendor to another.The following quick-fix should get your users back to normal.Continue reading …
This guide will walk you through setting the local macOS account pictures for end-users via Jamf Connect Requirements: Jamf Pro Jamf Connect Formatted ID Token Path setup in Jamf Connect Login Config (/private/tmp/token) Azure Storage Blob Email addresses of users follow a pattern for all users (john.smith@myorg.com, jsmith@myorg.com, etc..) Tested with: Azure AD and Jamf Connect Test User: John.smith@ericsontech.com Steps: 1. First step is to get all of your user images. To make this easy on yourself name them the same as the user's email address. So for John Smith his email is john.smith@ericsontech.com I would name his image as john.smith@ericsontech.com.png and upload that image and all other user's images to an Azure Storage blob. Example: 2. Setup this script to run via Jamf Pro. I have mine setup to run via Jamf Connect Notify Note: You will need to update this with your Azure Storage Blob url curl -L "https://myazureblobname.blob.core.windows.net/mdm/$EMAIL.png" -o /tmp/
This article is based off of the presentation at JNUC given by @tommypatzius , @Jordy-Thery and @glennu Our session at this year’s JNUC 2025 was designed to present a list of helpful tools available to Mac Admins of all skill levels and backgrounds. We know that everyone’s experience with Apple device management is different, so we’ve pulled together a collection of tools that are approachable, practical, and, in many cases, free. Many of them have a low learning curve, making them accessible whether you’re brand new to managing Macs or have years of experience. Our goal is that everyone walks away with at least one new tip, trick, or tool they didn’t know before. To make things clear and easy to follow, we’ve divided the tools into categories by function: Apple apps, Jamf tools, maintenance, setup & customization, notifications & support, and inspection tools. We took a closer look at a few specific highlights—Jamf Helper Constructor, Self Service+, and IBM Data Shift—befo
I am attempting to install an endpoint agent on all Macs in Jamf, however I cannot seem to get it to run correctly. I have the package added to Jamf, I believe it is the script that is the issue.
we are getting a screen time alert while accessing any new link in the chrome or safari browser it very frustrating for us to ok it every time while access to new link. any idea how we can bypass or restrict this alert using config profile or Policy?
Today we are releasing Jamf Pro 11.21; highlights include:Impact Alert Notifications for Deployable ObjectsImpact alert notifications include enhanced visibility and control when modifying deployable object configurations. These notifications help prevent unintended large-scale deployments by giving administrators insight into how their modifications will affect devices and existing configurations across their organization. When editing the scope of any deployable object (e.g., policies, configuration profiles, apps), a confirmation dialog displays an alert message that indicates that significant changes may cause increased network traffic and temporary application instability. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade ScheduleYour Jamf Pro server, includi
Hi All, I have several MDM Profile that have not checking and I would like to remove the MDM Profile from the Macbooks, I have try the following script: sudo jamf removeMdmProfilesudo jamf removeframework I don’t want to use recovery mode. Can anyone help?
Hello everyone,We install TeamViewer for some of our clients via the Jamf App Catalog. This also install TeamViewer in the LaunchAgents, which we don't want.Deleting the plist files doesn't work, and you can't specify anything in the configuration file either.Has anyone else encountered this issue and perhaps found a solution?Thanks & best regards
I used the “Defer software update” function so that our users could not upgrade to iOS 26 since it seems to be killing the battery on our phones. However, I wanted to send out iOS 18.7 for security reasons. I was able to send it out via Software Updates but if our users don’t catch the update prompt the first time it is sent to them, they will hit an error, and they can not install it other than going to General > Software Update which we have blocked.I was wondering if anyone has reached a similar obstacle and was able to find the best way to proceed. Thank you!
Im not sure what happened here, but starting on Oct 12 a bunch of my user devices no longer displayed the user attributes from Okta like full name, username, email address and title - now it only shows the local username on the machine. I have the LDAP integration with Okta setup using a service account, and that looks like it’s still active as when I test it - it returns user info. This has affected about 50% of my machines. I also have jamf connect setup with Okta as the idp on those machines. Anyone experience this issue recently?
What is the best practice for app deployment? Is it using the “Mac Apps” menu and setting them to auto install instead of self service store, or deploying apps using Policies?My best guess is to add app-specific scripts and settings, but is there anything else that gives benefits using policy instead of just making it mandatory in the other way?
In other MDM’s, when we enable Lost Mode, we have the ability to see where the device location is after it successfully enables.In JAMF Pro, I can put a phone into Lost Mode, I can see a “DeviceLocation” command sent to the device, but where can I see a map of that device’s location?
I have a MacBook Air that I have locked remotely through JAMF with the passcode.The user, has managed to lock themself out of the machine by typing in the wrong passcode code multiple times.Therefore, the timer has kicked in and locked them out for 26031963 minutes ( 49.5 years)Have spoken with Apple support, who suggested I contact JAMF.Is there a way we can reset the timer to allow the user to type in the correct code to unlock the machine? Many thanks
I am trying to change a computer's name by editing it in the computer's Jamf Pro inventory > General page. I have a policy to change all of my managed computers' names to match the names set in Jamf, so theoretically this name change should be pushed out to the machine after I updated it in Jamf. This is an iMac running MacOS14.4.1. But when I change the name on this machine and save it, the page reverts back to the default "iMac" name. I've done this hundreds of times and have never had an issue getting a name change to stick in the Jamf Pro inventory. Has anyone else seen this issue?
I work in an education environment.I want to allow Staff to enter the name of a lab via a prompt ran from Self Service and get back a list of Applications installed there.Querying the API via a script seems like it'd be the way to go....I'm just not exactly sure how to go about it.Anybody got an idea where I'd start?
Morning all am looking to see how people have there ipad updates setup currently am going in to software update and selecting bunch of ipads asking them to update should i be setting config up so updates get push automatically just seeing what others do.
I am putting together some data on iPad breakages in schools. If you’d be happy to share annual percentage of physically damaged iPads together with the case solution you use and the total number of iPads you have I would be grateful. If you have data by year group even better . I will share results once I have them collated.
Hi all, Background:I’m fairly familiar with the Apple ecosystem but just not getting into managing Apple devices. I am working on getting MacOS to a baseline standard internally at my company. Issue:SelfService+ is working great but I’m noticing that I need to sign into it every time the app is launched. Is this normal? Side Note:I do have SSO turned and working, which makes this less of an issue, but I was experiencing it before SSO was enabled as well. Thanks!
Hey all, Anyone know how would I go about scheduling clearing the shared ipad cache on all devices as an automated weekend task? I keep getting storage errors a lot so I think this might help. Doesn’t seem like it’s releasing the profiles of signed out users.
We don’t have ldap integration yet.So when we automatically enroll a computer (when new or wiped) the first user account is always admin. Which is impractical if the machine is shipped directly to the user.We create our admin user at prestage enrollment. or should the admin account we are about to use for troubleshooting etc be created using a configuration profile? What is the best practice i’m asking.In any way, after wipe or at first boot, the user that gets created WILL be created with admin rights. My question is if there is a way to create the first user with user-only rights as we create our admin account way before this step.Thanks
I wanted to highlight a gem that got burried in the Education State of the Union at JNUC 2025 this year. It’s the Jamf App CATalog. I’m still diving into it myself. Had to chat with @Kelly_Conrad to get the low down on this. Seems it’s released on the app store already. Just chewing into it myself.The Admin Guide is available at https://jamf.it/appcat-setup.The Quick Start Guide is available at https://jamf.it/appcat-quickstart.The Quick Start Guide has all the basics and if you find it useful check out the Admin Guide.Without any configuration the app is in demo mode. My ears perked up for this as I think our teachers would find it useful to be able to give internal feedback about specific apps.It was mentioned that there was a way to give feedback through an email but I can’t find that in the app like I was shown. Maybe I’m missing something.Anyway, I hope you find this app helpful. I’m looking forward to learning more about it myself.Available on the App Store here:https://
User unable to login to AD bound Mac in Jamf Pro. Users with similar credentials are able to login with no issues. Deleted user in order to recreate the local account. Restarted the iMac. Checked network connection (on correct VLAN)
Hi,I discover that Jamf teacher app don't show students in the particular imported classes from Apple School Manager. The same classes in Jamf Pro however show its students and its teachers. On the teachers iPad using Jamf Teacher app there is a error message "You are not allowed to add students to managed classes. Contact your IT administrator for support". On the same device when teacher choose another class then there is no problem - all students are visible and the teacher can start a lesson. I have tested to remove the classes with the errors and then imported the same classes again in jamf pro but the error still exist. Anyone who had the same problem before?Thanks for feedback.
I’m fair new to Jamf Pro so forgive my for my beginner questions.Our Jamf Pro system is partly managed by and IT department above us.I uploaded our vpptoken and reclaimed (for whatever that means)Now if I modify an app to be available in the self service store it appears (it did not before uploading the vpp token). Didn’t try to install it yet. But they don’t get automatically installed if i set them to Install automatically/Prompt the users to install. Yet. Maybe I need to wait for the next xyz communication between the macbook and the jamf pro server?
Hello all,I am in the process of rolling out OneDrive to our Mac environment. I assigned the app from the Jamf app catalog and put together a plist with all of our settings. I discovered that OneDrive has to have full disk access in order to automatically back up the desktop folder. I used the Jamf PPPC tool to grant onedrive full disk access, however it does not seem to take. I check in system settings → general → device management and I see the config profile, however when I run sqlite3 /Library/Application\ Support/com.apple.TCC/TCC.db \ 'select client from access where auth_value and service = "kTCCServiceSystemPolicyAllFiles"' in Terminal, onedrive is not listed as one of the apps that has full disk access. Any ideas?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!