Get Support
Recently active
Hello , Is there any way to block all apps except the chosen ones? I saw on Apple developer that whitelisted app were deprecated whitelistedAppBundleIDs[string],but solution with allowListedAppBundleIDs didn't work for me. In my case I need to push policy to block everything except preinstalled apps and 5 chosen by IT.
Important notice: Beginning with this version, Jamf is no longer sending maintenance release email messages. We will continue to send Jamf Pro release announcement email messages for major and minor releases (e.g., 12.0.0, 11.21.0, respectively). Today we are releasing a maintenance version of Jamf Pro; highlights include:Resolved IssuesJamf Pro Server[PI134363] Fixed: When configuring a computer configuration profile with a Network payload with "Any ethernet" selected, Jamf Pro incorrectly uses the string "AnyEthernet" instead of the required "GlobalEthernet" in the payload, preventing computers from successfully joining corporate 802.1x wired networks. [PI139045] Fixed: Activation Lock status fails to display for eligible iOS devices in the Management > Activation Lock bypass category of a mobile device inventory record. [PI140234] Fixed: Static groups fail to display in the Management > Mobile Device Groups category of a mobile device inventory record. [PI140306] Fixed: Jamf P
Howdy all, I am facing an issue that I can’t seem to solve with running Microsoft AutoUpdate via script from Jamf to keep our mac office apps updated. I have had this set up for several years and it had been working beautifully as a hands off solution. I am not sure exactly when it started failing, I recently noticed the problem and started digging into it. I am wondering if anyone is facing the same problem, or has advice on what to try.The setup is fairly simple, a policy that runs against a smart group of any macs with office apps that are not the latest version once a day. It runs a script to use the MAU command line msupdate to pull and install any available updates.Script is below, it only worked under user context originally so that is why it is set that way.The error I am seeing on every run now is related to the XPC connection, this happens on all clients no matter what, -reinstalled MAU with latest version, brand new mac build with latest install etc. I have the original PPP
Has anyone had luck hiding the 4 slides that appear after an upgrade to Tahoe?
Hey all, Wondering if anyone has any ideas on this? I am wanting to utilise SAM to lock down our iPads to a specific app. Trying to scope this through a department group but the device isn’t showing in the logs for the configuration profile. There are devices in there, just not the two that I specifically need. Both devices that aren’t showing in the logs are supervised and managed institutionally so unsure on what the issue is here… I have also checked to see if I can manually add the two devices but they are not showing when I try to search for them? Getting increasingly confused as the devices that are showing scoped currently, and are in the profiles logs, are NOT supervised...
Morning,Despite my best efforts i haven’t found a solution online so my question is, can i deploy an automator workflow i’ve created via Jamf Pro as some sort of policy of which i can then distribute to selected machines?Thanks
Hi All, We have setup Jamf Pro SSO and Cloud idP for to EntraID. We then tried to use the EntraID groups for the targeting of applications/configuration profiles but they wouldn’t scope correctly. I logged a ticket with jamf support and their theory was that because we map UserPrincipalName (i.e. Full email address), this doesn’t match the username on the local account because it doesn’t support the @ symbol. Their suggestion is to drop anything after the @ symbol on the mapping but it’s not that simple as we use the full UPN for other configurations in Jamf.So i guess my question is does anyone else have iDP setup with Jamf and do you sync the full UPN and able to target users via EntraID groups? TIA.
I’m trying to implement Jamf Setup Manager. I have everything aligned regarding the configuration profile and the Jamf Setup Manager PKG assigned as an enrollment package. But the PKG won’t install. I’m not seeing any logging or the app in the Utilities folder after enrollment. Any suggestions would be appreciated.
Hi All, so i’ve had an issue for a few months, I’ve been trying to find the bash command line to turn on accessibility keyboard, so looking around in ventura this was easy to do and now the location has now changed, main thing is i don’t where. As i work in a school some teachers want on screen keyboard when they connect to the white boards, so i wanted to add an option in self service to deploy a shortcut to the keyboard
Startup Power is a macOS application built with SwiftUI that allows you to configure your MacBook’s automatic startup behavior.It directly modifies NVRAM variables (BootPreference for Apple Silicon, AutoBoot for Intel) to control these options.The app automatically adapts its behavior depending on your Mac type.If this can help the community, the application and the source code are available here:https://github.com/chrisbasse/Startup-Power
Hey Guys,I already talked to Jamf and got this issue escalated for me. You may want to check if this problem applies to you.I was trying to enable activation lock through a static and smart group via selecting the group>View>Action>send remote command>enable activation LockAfter talking to Jamf they are aware that it is not accurately reporting if the device has AL turned on in the inventory screen so I was checking with ASM. There I discovered AL was off. I tried it again the same way and the issue persisted. If I went to the device>Management>Activation Lock>Enable activation Lock it seems to send out the same command but does enable activation lock. To test it I did the same this again with the group command and the device turned it off and could not turn it back on with the same command. I had to go back to the specific device and turn it on again. My problem was with a small number of iPads so this wasn’t a huge issue for me, but if you manage lots of Macs and
Get ready to supercharge your scripting and automation expertise at Level Up JNUC 2025! Running Monday, October 6, the day before JNUC 2025 kicks off, this exclusive, in-person training is your chance to dive deep into hands-on learning with a Jamf instructor. From IF statements to APIs, loops to user interaction, you'll gain the practical skills needed to automate like a pro. Full-day training (9:00 a.m. – 5:00 p.m.) Lunch & refreshments included Hands-on scripting & automation challenges Digital badge, swag & bragging rights upon completion 📢 Limited spots available – secure yours for just $99! New to scripting? No worries! Check out the Bash Scripting Foundations and Bash Scripting Automation courses in the Jamf Online Training Catalog to prep. Don’t miss this opportunity to level up before JNUC 2025! 🔥 Register HERE now!
We have a bunch of machines that R7 is reporting the version.plist file in the safari.app container contains vulnerabilities. The app container is in the cryptexes folder and is listed as version 18.x. The machine itself is on macOS 15.6.1. I assume the container in question is in the reboot environment? I’m not sure how to fix this.When I try to remove the vulnerable plist file it comes back as operation not permitted. Can I even remove this file? Should I remove this file? Is this a matter of the recovery environment not being up to date? Looking for any insight I can get. Thank you in advance.
During post-release window for at least the last 4 minor macOS releases, our users have reported that the Mac only lets them unlock with password, not allowing their fingerprint.If the user restarts the device, then logs in, the fingerprint option for unlocking is available but, reverts to not being available shortly after. This behaviour appears when a new macOS update is released, then is only resolved once the device is updated.We’ve confirmed that the fingerprint is setup and works for other auth with the device unlocked - never seen this behaviour before, anyone else experiencing this?For reference, this has happened on at least;macOS 15.4 → 15.4.1 macOS 15.4.1 → 15.5 macOS 15.5 → 15.6 macOS 15.6 → 15.7
Hello,We have an LDAP server (Active Directory) configured on our JSS.We will move to Azure AD.For this, we have configured "Cloud Identity Providers" to integrate with our Azure AD.Everything seems ok with tests. We can query for groups, users and get "true" for membershipWe are trying to scope and limit policies (Self Service) to group memberships from AzureAD (via Cloud Identity Provider). I can search for the group and add it to the Limitations section of the policies.But when I try to test the policies on computers, the policies are not available when users connect to Self Service using the Azure AD accounts in the target groups.When we try with Active Directory groups, that works well but not with Azure AD groups.Do you know if this is normal? Can't scopes with Azure AD groups?We have Jamf Cloud 10.33.Thank you for your help
Self Service + with JAMF 11.18 adds a menu bar icon by default with no way to natively disable it from self-service. Does anyone have any menu bar techniques to remove icons that do not involve using third party apps? Thank you in advance
This. So much this. Now if we could get granulated details of impact or history into the jamf app catalog for things such as “failures” or “unsupported”….Anyways, this is a step in the right direction for sure!
Is any one else having issues logging into the JNUC app? Even when I select “Forgot Password” I don’t receive an email to change it.
Hello,I have a brand new instance of JAMF Pro, about a month old so nothing is expired. I have about 80 iPads and when I send a remote command it sits in the pending status until someone wakes the iPad. This is very inconvenient because it slows down work flows in the morning and causes Apps/OS to update during their work time. I have force app updates on and it checks every day at 4:00AM EST, but it never actually updates at that time.Is there any solution to this?
I am attempting to run npm installs via a script from self service. However there are nothing but errors, these installs work fine if run from terminal.Have tried the following:su -l $currentuser -c npm install aws-cdk-lib su $currentuser -c npm install aws-cdk-lib sudo -H -iu $currentuser npm install aws-cdk-libThese all return an error of "Script result: zsh:1: command not found: npm"Picking apart a brew install script I have, I noticed it referenced an exec file for the "brew" portion of the install command located in the /opt/homebrew/bin/brew folder. There is no such npm folder, so I had to improvise and found a similarly named exec file.Trying to replicate this I created the following:npm=/Users/${currentuser}/.nvm/versions/node/v21.1.0/lib/node_modules/npm/bin/npm cd ~ sudo -H -iu ${currentuser} ${npm} install aws-cdk-libThis returns the most educated error of "Script result: Could not determine Node.js install directory"I feel like I'm getting closer, but am hitting a wall
Hey folks, I'm having trouble allowing users to use ChatGPT. We allow Apple Intelligence on all machines, and so have all the allow buttons ticked in the Restrictions profile, aside from 'Allow integration with external intelligence services (macOS 15.2 or later, supervised)'. I've removed a few test machines from the scope of the standard config profile, and duplicated the Restrictions Config profile, and then only included a few test machines, and this time allowed integration with external intelligence services (macOS 15.2 or later, supervised). The initial ChatGPT entry is fine: but I'm seeing a strange blue box that almost looks like you could press it. If you try to Use ChatGPT with an account, it doesn't allow that too (last screen shot). Has anybody else experienced this?
In our Jamf Pro integration, we use `GET /v1/computers-inventory` and `GET /v1/computers-inventory/{id}`. What’s new in the v2 version of those endpoints? Is migrating to the new version a matter of changing the number or is there anything extra that I need to take care of?I wasn’t able to spot any differences when consulting the API reference or the changelog. https://developer.jamf.com/jamf-pro/reference/get_v1-computers-inventory https://developer.jamf.com/jamf-pro/reference/get_v2-computers-inventory https://developer.jamf.com/jamf-pro/changelog/11200-changes https://developer.jamf.com/jamf-pro/changelog/11200-deprecations https://developer.jamf.com/jamf-pro/changelog/11200-additions
My Microsoft Tenant has started warning me to update my Webhooks URLs, the new URLs being longer (going past 255 characters, in case that’s a common limit). As a result, a couple of my workflows have stopped working (on the Microsoft side they’re not being triggered). Anyone know of any solutions, I’d rather not sign up for any risky url-shortening services.
Hey All,Running into an issue, I assume it’s simple, but I’m blanking as to what I am doing wrong. #!/bin/zsh --no-rcsclient_id="REMOVED"client_secret="REMOVED"url="https://REMOVED"##Gets Access TokengetAccessToken() { response=$(curl --silent --location --request POST "${url}/api/oauth/token" \ --header "Content-Type: application/x-www-form-urlencoded" \ --data-urlencode "client_id=${client_id}" \ --data-urlencode "grant_type=client_credentials" \ --data-urlencode "client_secret=${client_secret}") access_token=$(echo "$response" | plutil -extract access_token raw -) token_expires_in=$(echo "$response" | plutil -extract expires_in raw -) token_expiration_epoch=$(($current_epoch + $token_expires_in - 1))}checkTokenExpiration() { current_epoch=$(date +%s) if [[ token_expiration_epoch -ge current_epoch ]] then echo "Token valid until the following epoch time: " "$token_expiration_epoch" else echo "No valid token available, getting new token" getAccessToken fi}# I run the function h
Hi there, I have a strange issue with our office printer. The *.ppd file is not pushed to the devices when the printer is installed. I have followed this guide https://hcsonline.com/images/PDFs/Jamf_Printers.pdf but also used the Jamf Printer Tool to check if I am doing something wrong. Here is the point where I am stuck:the path to the PPD is correctly created on the Macs but empty first I thought it is related to a wrong path (if you install locally the pkg, the path is /private/etc/ppd/RICOH_IM_C3000_PS.ppd and when uploading the *.ppd in Computer Management > Printers , the path is /Library/Printers/PPDs/Contents/Resources/RICOH_IM_C3000_PS.ppd. This is also the path in the linked documentation above. Therefore I assume, it should also be used Worth to mention, the printer driver comes as DMG https://support.ricoh.com/bb/pub_e/dr_ut_e/0001343/0001343934/V11300/Ricoh_IM_C3000_C3500_C4500_LIO_1.13.0.0.dmg and I just mounted the DMG and took the *.pkg from it. I do not have to to
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!