Get Support
Recently active
Simple suggestion: Could you please integrate Jamf App Catalog in Mac Onboarding so we can deploy Apps from the Jamf App Catalog? Many Apps we deploy today in Mac Onboarding would be available through the Catalog but we currently need to deploy them as Policies.
We are experiencing an issue where a users, suddenly get signed out of their Google account and unable to sign back in. When they attempt to log in, password is not accepted. The strange part is that no one changed password — not the user, nor either of our Jamf admins or Google Workspace admins. local Mac password (which is supposed to stay in sync with their Google password through Jamf Connect) still works fine, but his Google account password no longer matches. To clarify: User was logged in normally and did not request or initiate any password change. Users unexpectedly signed out of their Google account. When attempting to sign back in, Google reports the password is incorrect. Their local password on the Mac still works and allows them to log in to their device. Jamf Connect is deployed, and their local and Google passwords had been synced properly before this incident. We verified that no password reset or forced password change was made from the Google Admin Consol
So as of recently, our iPad 5th Gens are not able to enroll after factory reset to 16.7.12. We’ve had to do factory resets on iPads that are out of space. Our 6th and higher version iPad’s (17.7.10 / 18.7.1) appear to fine at the moment. Jamf Pro still claims to be supporting iPadOS 16, where JamfNow supports a minimum of 17.x. Has documentation not been updated regarding iPadOS 16?Not sure where to go at this point as we have a plethora of 5th Gen iPads still in our school environment.
I figured this would be helpful here. We use it to remotely grab logs from a Mac. Throw the script in a check-in policy and assign a computer to it. At next check-in, you will have their logs.This script will output the network quality. It then uses the API Role/Client 'Computer Attachments' (Update Computers, Read Computers, Create Computers) to pull the JAMF Computer ID using Mac serial number. It then runs sysdiagnose to create logs. It will then upload the logs to the Attachments section in the JSS portal. I set access token time to 300 because the file it uploads can be 400MB.Logs can be then downloaded from JAMF - Computers - Computer - Attachments.#!/bin/zsh --no-rcs## AUTHOR: Joshua Clark## DATE: 09/06/2025## PURPOSE: This script uses the API Role/Client 'Computer Attachments'## to pull the computer id using Mac serial number. It then runs## sysdiagnose to create logs. It will then upload the logs to the Attachments## section in the JSS portal.## NOTE: Client ID and secret
Hello guys, i am affected by the MS latest security patch Microsoft Active Directory Strong Certificate Mapping Requirements. My devices cant connect to wifi via certificates after the latest patch. My devices are not in domain, also users are local , so when i tried the objectsid Extension attribute it didnt work even though i have cloud idp as azure connected and i guess its because users are local. Do anyone have any idea how to tackle this :) Can we use UPN or some other attribute for macbbos that uses local user account and not in domain?
Hi So i’m working in school where we are setting up Apple Tvs we wanted make slideshow, although github is a good shout it is too public to use, is there any private websites that follow GDPR that could be a good recommendation? I was thinking about sharepoint, but not sure if that would work
I know JNUC 2025 in Denver isn’t even out of the gates yet but I enjoy speculating about future things. Many people seemed to think it was Denver before it was officially announced. It seems JAMF likes state capitols so far. My wife is even interested too since she normally pops along with me. The top 5 most populated state capitols are:Phoenix, AZ Austin, TX (JNUC 2023) Columbus, OH Indianapolis, IN Denver, CO (JNUC 2025)I have no knowledge of where, I just enjoy speculating. My wife hopes it will be Boston. I’d hope for Salt Lake City personally. My bet is on Indianapolis though. Just a guess though.Any guesses, insights or desires for a future JNUC (next year or beyond)?
If I turn off our current Cloud Identity Provider configuration with Google, will that remove the existing attributes from users’ User and Location fields in their profiles? My understanding is that it won’t, which would be a good thing in my case. I’m transitioning to Okta LDAP and want to make sure the current attributes remain, since I have smart groups based on department fields.
I have a custom script that I use to upload an ipa file to an in-house Jamf Pro mobile device app. I am using the endpoint: {URL}/JSSResource/fileuploads/mobiledeviceapplicationsipa/id/{app_id}?FORCE_IPA_UPLOAD=trueThe file does get added to the app in Jamf correctly, however the upload will stop at 99.9% or 100% and just hang until my timeout limit has been reached. So the script throws a timeout error. I have a check for a timeout and then check to see if the file exists in Jamf after, but this feels like a weird workaround. Am I doing something wrong? Why is Jamf not responding with a success 201 after my POST?
Does anyone have any SwiftDialog progress bar .sh examples they’re using during PreStage enrollment to enhance the end-user experience? I’m working on improving our setup workflow and would love to see how others have implemented theirs.
We have not transitioned to Jamf Self Service+ and Jamf Connect 3.x due to concerns about potential confusion among employees and the need to train them on resetting passwords and utilizing the new Self Service+. I perceive Self Service+ as a separate application that is not seamlessly integrated into Jamf. Additionally, our current Self Service is customized with our logo, which the new version does not support, which I guess is a minor inconvenience. Since Self Service is placed in the Dock during enrollment, switching to the new version would require reconfiguration using DockUtil. I am cautious about adopting it and would like to see if Jamf will replace the existing Self Service. Furthermore, Jamf Connect 3.x removes the capability to sync or change passwords via Intune, necessitating the installation of Self Service+ for this functionality. I am curious to know how many others are postponing this transition. Ideally, Jamf would update the existing Self Service to the + version. H
Hello Nation, got a request to install the Cyberark Chrome extension. no problem there. Request was made to per-configure portal URL. Cyberark gave very vague instructions on how to create this. Asking if any one has already deployed this. I am assuming it would be additional keys inside of the extensionforceintsall settings but have no idea and have not been able to track at least something similar down. already had the team open a ticket with Cyberark to at least send a vanilla profile. thans in advance for any assitance
My organization uses Jamf Setup and Jamf Reset for our users to sign in with their SSO account with Microsoft Entra ID. The user will sign in with Jamf Setup at the start of their shift and then sign out at the end. However, Jamf Reset frequently does not fully sign the user out of their SSO account, leading to the next users unable to log in. I have found that a power cycle and attempt to sign out using Jamf Reset usually fixes this problem. From what I can tell from comparing our Jamf Reset App configuration and "Managed App Configuration for Jamf Reset" documentation on learn.jamf.com, we have the standard configuration set up. Has anyone else ran into issues with Jamf Reset "hanging up"?
Today we released Jamf Connect 3.4.0; this release addresses the following product issues:[PI138079] Fixed: The offline multifactor authentication prompt closes after an incorrect entry, requiring users to enter their username and password before attempting to authenticate again. [PI139042] Fixed: Users without a local account are prompted to re-enter their Microsoft Entra ID password after entering their username and temporary password during local account creation. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hello Jamf Nation!To those of you headed to JNUC this week, we’re very excited to see all of you for another year of our amazing community coming together. We’ve released Jamf Pro 11.22.0 beta which features MDM Server Migration with App Preservation for iOS and iPadOS Devices, a number of fixes and improvements, and more!How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
This guide represents the synergy of the latest technologies from Apple and Jamf. It harnesses the power of the new Declarative Device Management (DDM) framework built into macOS 15 (Sequoia). This modern approach is unlocked by Jamf Pro version 11.8.0 or later, which introduces Software Update Blueprints. Critically, this entire workflow is powered by the Jamf Account SSO, which connects your instance to the cloud micro-services required for Blueprints to function, creating a truly modern administrative experience.The guide outlines the modern, three-part strategy for managing macOS 15 and newer in Jamf Pro. It leverages DDM via Blueprints for a reliable, automated workflow and is based on enterprise best practices for both aggressive and controlled rollouts.PrerequisitesBefore you begin, ensure your environment meets these minimum requirements:Jamf Pro: Version 11.18.0 or later. Target Computers: macOS 15 (Sequoia) or later. Device Supervision: Devices must be Supervised. Administrat
I’ve federated our domain. We never had any conflicts. I have to assist a client with capturing their domain - but we already know they’ll have conflicts.I know the end user will get an email and have to create a personal account, but what happens on the device? A person creates a new iCloud account - does the login on the device auto-switch to the new account?I’d take an educated guess Apple does their stuff to make sure purchased content moves to that account.Do they have to sign out to get to the managed ORG ID?Question is - does the device automagically become the managed ID - or do they have to sign out / into the captured ORG ID?If it’s the latter, does their purchased content get purged from the device? Or is it more of a BYOD situation where they’re logged into both?
Hello everyone, After spending hours digging through forums trying to find a reliable way to fully automate the AVID NEXIS Client Manager installation on macOS, I’m sharing this step-by-step guide to save others the same trouble I went through.Unfortunately, Avid doesn't provide much help on this topic, so I hope this helps streamline your deployment.I’m aware that this isn’t the most secure or ideal approach, and there’s definitely room for improvement — but it works for us.If you have suggestions or improvements, feel free to share!If this can help new Mac admins or anyone else, all the better! Useful resources I consulted: Managing Legacy Kernel Extensions in macOS Using Jamf Pro - Technical Articles | Jamf System extensions in macOS - Apple Support (CA) System Security Prerequisites Before any installation, it's critical to adjust macOS security settings to allow the required kernel extensions for AVID NEXIS to load properly. For Apple Silicon Macs (M1/M2/M3):Boot into recovery m
At the begining of the year we set up a Jamf Migration app with and .mobileconfig profile to assit users in moving thier company managed machine from Mosyle to Jamf. I recenlty updated the .mobileconfig profile to extend the removal date however Im experiancing an new issue that once the profile is installed and we try runninf the migration app I get a new error stating the jamf Migrate could not enroll in the destination JAMF Pro Server. What would be the next steps to resovle this?
We have some entra integration in our environment. We use connect, have enroll enrollment customizations, etc. The issue I’m having is while I can see AD groups, it seems jamf can’t see memberships (I’m assuming). When I attempt to scope a policy/config profile to an AD group (scope to everyone, limit to the AD group), it still goes to everyone with no limiting. I’m sure there’s a setting I’m missing. Has anyone seen this?
Our school district would like to defer the upcoming macOS 26 upgrade (scheduled for release on September 15) but still allow security updates for macOS Sequoia.What is the best way to configure this in Jamf Pro so that the major OS upgrade is blocked, while security updates and minor patches for Sequoia remain available? Thanks
This October, I’ll be heading to Denver, Colorado, for the Jamf Nation User Conference (JNUC 2025). It’s a week that brings together community, learning, and all things new with Jamf, and this year, I’m especially honored to be attending as one of the recipients of the JNUC Diversity Sponsorship. The Sponsorship ExperienceThe Diversity Sponsorship program reflects Jamf’s commitment to amplifying the voices of underrepresented individuals in the tech industry. Now in its ninth year, the program selects up to 10 individuals to attend JNUC with full conference registration, a travel stipend, and access to exclusive networking opportunities. Being chosen for this year’s sponsorship is both humbling and energizing. It’s not just about attending sessions or seeing the latest product announcements—it’s about being recognized as part of a broader effort to ensure diverse perspectives are present in conversations that shape the future of Apple administration and security. Why I AppliedThis will
Hi everyone,we are currently trying to figure out how to deploy apps which are only available in specific regions, e.g. Shopee (which is only available in some Asian regions if I’m not mistaken). In ABM, we can only find apps from our origin region.I cannot really find any resources on this topic. Does anyone have an idea on how to achieve this?
As part of my rollout of platform single sign-on I created a script that checks the user’s password expiration date so that we can alert the user that their password is expiring within 14 days. I want the script to run once a day. I created a launch daemon to run the script. The script and the launch daemon get installed on every Mac with PSSO setup. If the user’s password is expiring on a date that is more than 14 days away the script slimply logs the expiration date and how many days are remaining. The problem I have run into is that if the Mac is not currently connected to the internet when the launch daemon runs the script, there will be no results from the password expiration check with Microsoft. How can I get the launch daemon to run the script again? Currently I have the launch daemon configured to run at a specific hour and minute daily. The deployment script that writtes the password expiration check script and the lauch daemon takes note of the current hour and minute and us
I remember before the renovation of jamf dashboard there was an option to clear all users on shared ipad. Now with the new dashboard I didn't find it, can someone tell me where was that option? Thank you,
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!