Get Support
Recently active
Greetings JAMF Nation! Apologies in advance if this has been covered and I've just missed it. I'd like to know if there is a way to rearrange the columns I choose to display when I check the items under "Inventory Display". I provided a screenshot to try to explain what I'm after...in my example, "last update" is the second column but I'm asking if there is a way to tell jamf to display that one at the end. So "name" then "model" then "OS" and finally "last update". The end goal is to export the reports into an Excel spreadsheet but I'd like to not have to rearrange everything in Excel after it's exported. Would be nice to have it report in the order I want to export it. -SP
We have a requirement to use a exam application for proctored exams through Proctorio on iPads.Our specific need is:• Enable camera access exclusively for this exam application.• Currently, we have disabled the camera from the profile side to prevent other apps from accessing it.We need a solution that:• Allows the exam application to record via camera,• While keeping the camera disabled for all other applications.
For awhile both Jamf Pro and Jamf Protect had a Resource box on the dashboard page. Both are gone now and we are just redirected to countless webpages to click through to find the information buried. Another useful tool gone….
A swiftDialog and LaunchDaemon pair for “set-it-and-forget-it” end-user messaging of Apple’s Declarative Device Management-required macOS updates Overview While Apple’s Declarative Device Management (DDM) provides Mac Admins a powerful method to enforce macOS updates, its built-in notification tends to be too subtle for most Mac Admins.DDM OS Reminder evaluates the most recent EnforcedInstallDate entry in /var/log/install.log, then leverages a swiftDialog-enabled script and LaunchDaemon pair to dynamically deliver a more prominent end-user message of when the user’s Mac needs to be updated to comply with DDM-configured macOS version requirements.Continue reading …
Have recently built out a PlatformSSO config, and have seen varied results upon the devices on which I’m testing it. To my understanding it appears one has to scope a minimal AppSSOKerberos config in order for the PSSO config to properly register. I say this because, and this only appears to effect Apple Silicon devices running macOS 15+, when the config appear to bork itself registration is always unsuccessful.The underlying cause seems to be simultaneous writes to the AppSSOAgent and the AppSSO Daemon; what then happens is that underlying JSON config becomes corrupted, the config is discarded, and the system initiates a remediation by requesting a re-registration. It appears to be a concurrency bug causing an OS-level race condition. For whatever reason Intel Macs don’t seem to be impacted, but from what I can tell it’s an OS issues and not related to the M-series hardware.Has anyone else seen this? Anyone have any ideas toward a fix/remediation?
Afternoon Im trying to deploy Zbrush which is dmg which has .app file wrap inside it.I have packaged this into temp location \\private\tmp Im then running a script to install it.Having all sorts off issue trying to get the script to mount the dmg.Seems to work fine through terminal using hdiutil attach /private/tmp/MaxonZbrush.dmgDoes anyone have experience with working with DMG or any good resources.Thanks in advance Tom
This is kind of a shot in the dark, since it’s a somewhat obscure Zoom setting -- but does anyone know how to manage the “Show green border around my shared content” option? (It’s under Settings > Share Screen.) I can’t find a key for it in ~/Library/Preferences/us.zoom.xos.plist, and toggling the setting appears to do nothing to that file.
Does anyone have a step-by-step for creating a basic content filter for Mobile Devices? Looking through the documentation online it keeps sending me to how to set it up on macOS but not iOS/iPadOS. Basic Question: Does the filter name matter?
Has anyone had any luck in blocking the Games app? The only thing that appears under “Restrictions>Apps” is Game Center and that does not block the new app.
I just want to take a moment to say thank you.It was truly an honor to meet all the recipients and everyone who helped make the event happen. I’ll be honest — I was completely unprepared for how emotional it would be. I was genuinely amazed.Speaking with the JAMF executives and hearing their journeys was inspiring. The consistent theme of family and unity — that sense of inclusion and belonging to something greater than yourself — was powerful and real.I’m deeply grateful to have been one of the recipients. Thank you again for such an incredible experience.
Back from JNUC? Learned a lot of new things, haven’t you? Missed even more I guess…Don’t worry, let me remind you what news we announced in Compliance benchmarks! Review the Keynote, Commercial State of the Union, and dedicated Compliance sessions (once available) for more details.NIST 800-53 rev 5 BaselinesYes, those from mSCP - low, moderate, and high - are now available in the built-in capability in Jamf Pro. You can build a benchmark out of them TODAY - as always, we recommend to start with monitor only, and roll-out gradually from small test group all the way to the target population.Compliance ScoreUsing Compliance in Protect? Like the simple compliance percentage as an overall indicator? It is NOW in Jamf Pro as well! Each benchmark shows a compliance score that tells you the compliance status over the assigned computers to know how you are doing. Any questions? Curious about where we are heading next? Let me know!
Is there a way to force set the "Listen for" setting under Siri settings to Off?We have disabled the assistant overall, as well as applied a config profile blocking the use of Siri. However, when disabling the assistant via a plist edit, if the "Listen for" setting was set to anything other than Off when this change took place, the user now gets a popup stating "You do not have permission to use Siri" whenever they say something out loud that sounds remotely similar to "Siri".
Some additional IP address have been included in the Outbound traffic from Jamf Cloud. Please see the “Permitting Inbound/Outbound Traffic with Jamf Cloud” document located here: Permitting Inbound/Outbound Traffic with Jamf Cloud - Technical Articles | Jamf
How do we configure a computer smart group to show which computers have Touch ID configured/enrolled for locking/unlock? I’ve tried ChatGPT, Gemini, and Claude to help configure a computer extension to no avail.
Has anybody figured out how to get Language Chooser to run at first boot?if I make my image from a Install OS X.app it seems to assume that since i ran that App in English that is the language I will want everybody to use, and well my customers tend to be Global. I can make it run, but it runs on top of setup assistant and well its ugly and can be problematic if people start clicking on setup assistant before language chooser appears. Any ideas would be greatly appreciated.
Hello- Let me start by saying that I am unfamiliar with VMs. We are a 1:1 Apple School. One of our HS student’s is taking a cybersecurity class online and has requested I install Virtual Box on their MacBook, along with Ubuntu. What sort of security, privacy issues am I looking at here? We have JAMF Safe installed on all our computers. Will they be able to skirt our filters?
I wanted to see what are the options for example a user losing their password login and on the admin side resetting it. I’m aware there is FileVault and giving a recovery key but they messes up specific keychains and some other settings (portnox). I’d like to see if there is a way an admin can assist without that option. I’m planning to do a writeup after suggestions here and have documentation steps for a user.
I just found out that Pre-stage Enrollment Customization Panes do not work at all with Return to Service. How are people getting authenticated users with SSO (Cloud IDP with Entra is already setup with the connector as is Jamf Account), which translates to SSO on the device itself, also working with automatically assigned Prestage Enrollment and Return to Service? Are there good resources for best practices? I've found the documentation is lacking and Jamf 100 classes are basic. Support has mentioned Jamf Setup but that looks like it requires Shared iPads and I’d like to avoid those and we’re 1:1 with thousands of devices already. I see mention of Microsoft Authenticator with the SSO App Extension - I have this set up in Jamf School in our current implementation already but I don’t see how this works in Jamf Pro without the Azure webclip login if I can’t use a Customization Pane with Return to Service - the latter being one of the primary reasons for the move. Thanks!
We are using a PPPC profile to allow the Users to set the screensharing option by themselves. Until 26.01 it worked fine, but with 26.1 Beta the option is locked and marked as this option is set by your administrator. In Jamf itself we are only able to set the option to deny or allow the user to configure. Where we have set allow. If we remove the profile, the user needs an admin to set this option, but at least it is possible to set. Anyone experiencing the same? I already gave feedback to Apple about it.
I’ve been running a script in our labs for the last couple of years to do macOS updates after caching the installer onto devices, the script is this:/usr/bin/su -l ladmin -c "echo ADMINPASSWORD | /Applications/Install\ macOS\ Sequoia.app/Contents/Resources/startosinstall --nointeraction --agreetolicense --forcequitapps --user ADMINACCOUNT --stdinpass"This has worked perfectly fine, and continues to work on our iMacs and Mac Minis, but when I’ve tried to update our MacBooks from Sonoma to Sequoia I’m being met with this bizarre message:Result of command:Error: You must be root to do this…I don’t understand this at all, because as far as I was aware everything the Jamf binary does is already run as root. Is anybody able to shed any light as to why this is failing please?Much thanks!
Hi,I have had some issues with Jamf Pro 10.48 and had to revert back to 10.47. Unfortunately I am now stuck at the welcome screen at the welcomescreen at "Analyzing webhook_display_fields". I let it sit there for half an hour but it does not seem to do anything. When I try to restart anything it just breaks the database and I have to restore again.Has anyone had this issue and can tell me how to get out of this?Kind regardsAndreas Baumeister
Jamf School currently assigns users and devices based on the following premises:Each user is assigned a username, which Jamf School treats as a unique identifier. Devices are linked to users via this username.However, there is a design flaw in the current implementation:It is possible to create new users with an already existing username, either manually or via CSV import. Jamf School does not issue a warning or automatically adjust the username (e.g., by appending a number). The original user is silently deleted, and a new user with the same username is created. All devices previously assigned to the original user are now assigned to the new user. This behavior occurs across the entire Jamf School instance, including across different locations.Jamf School should enforce globally unique usernames across all locations.Since location managers can only view users within their own location, they cannot verify whether a username already exists elsewhere.Therefore, Jamf should implement a ce
Today we are releasing a maintenance version of Jamf Pro; highlights include: Platform SSO Reporting Functionality for the Jamf Management FrameworkJamf Conditional Access.app, which is part of the Jamf management framework installed on enrolled computers and used for device compliance with Microsoft Entra, can now report on Microsoft Entra ID Platform SSO registration status and provide additional information about the registration state, including device ID and user UPN. Resolved IssuesJamf Pro Server: Security IssuesJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI141347] Fixed: A known vulnerability in a third-party library (CVE-2025-41249). [PI141349] Fixed: A known vulnerability in a third-party library (CVE-2025-41248). [PI141856] Fixed: A cross-site scripting (XSS) issue. [PI141857] Fixed: A cross-site scripting (XSS) issue.Jamf Pro Server[PI120484] Fixed: Jamf Pro's PreStage enrollment displays iOS 17.5 as an available minimum OS ver
We removed JAMF from a laptop but it failed to remove the MDM profile. Now, without JAMF on the machine, what is the best way to remove the profile?
I just set up a new iPad for a teacher and after enrolment all apps that should be deployed are marked as Waiting for Licenses despite having hundreds available. Things I've tried to resolve: Restart iPad Refresh Apple VPP token Re-apply profiles Re-apply apps Reset iPad and re-enrol Nothing works. Still stuck on "Waiting for Licenses". Does anyone have any ideas about what I should do to resolve this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!