Get Support
Recently active
Hi everyone,I’m trying to set a default font in Microsoft Outlook (macOS) using Jamf Pro, and I’m running into some trouble.By default, Outlook uses Aptos, but I’d like to change it to Book Antique, which is already available on the device.What I’ve tried: I attempted to use the 3rd-party tool OutlookFontPoke by Paul Bowden @ Microsoft. Here’s what I did:• Deployed the OutlookFontPoke script and TemplateRegDB.reg via a package (both located in /private/tmp/OutlookFontPoke-master).• Created a policy in Jamf that:• Extracts the current logged-in user• Fixes permissions• Run the command as that user: sudo -u "$loggedInUser" /private/tmp/OutlookFontPoke-master/OutlookFontPoke 'Book Antique' '11.0pt' 'black' Issue: Despite several variations of the above, I keep getting this error in the script logs:WARNING: Registry DOES NOT exist at path /Library/Group Containers/UBF8T346G9.Office/MicrosoftRegistrationDB.reg. Attempting to create...mkdir: USER/Library/Group Containers: No such file or dir
I have 2 questions with my Mac management with my on premise Jamf Pro instance.Before news MacOS is launch we would like to block the update while we made a couple of tests with our applications used in my university.What is the best way to block MacOS upgrade and for how long can we block the update? Second questions, After the pre stage enrollement i execute Jamf Setup Manager to install few applications and apply some configurations, i try to execute a script to reboot the computer but after reboot JSM runs again, how could i execute a reboot action after JSM properly?Thank you very much.
Hello, Just checking to see if anyone has found a way to update Libcurl on macOS without using Homebrew? There are several CVEs out for security issues related to the version of Libcurl in macOS. I’m not sure why macOS uses a version that is over two years old when there are updated versions available.
I'm @TyBorrell the product manager for Jamf AI Assistant. My second week at Jamf, I was at JNUC in Denver, talking with admins about AI. I haven't stopped since: what they're trying, what's working, what they're quietly unsure about. Here's what I keep hearing, and then I'd like to ask you something.At Jamf Nation Live London this year, 221 admins were asked what they need help with most, and AI integration topped the list at 84%. It came up across every career stage, from first-timers to people running teams. What I keep hearingMost of it comes back to a few questions:How do I use AI to manage my fleet more intelligently? How does it make me a more impactful contributor at my org? How do I free up time for the parts of the job I actually want to do?People are approaching AI every which way. Some have built plenty, some are just starting, and none of that is the point. If you'd like to work through it alongside other admins, there should be a place for that. An invitationI created a g
Enrolling new laptops and Self Service+ is installing. However at login we are seeing a pop up for intel based apps with the old Self Service logo stating this version of “Jamf” will not work with at future release of MacOS
Hello,Every year we roll out the current version of Logic to our student walk-up Macs. We have started working on next academic year's configuration, which we expect to include Logic 12.To our surprise, the way they handle the Extra Content has changed utterly. Instead of 1000+ PKG files, which we had a reasonably well-established mechanism for deploying, pulling down all the content now results in a single huge "bundle" file here:~/Music/Logic Pro Library.bundleThis is the worst-case scenario for us, because instead of having a single set of extra content installed to Logic proper, it wants each user to have their own copy of the vast extra content.We therefore want to move the content to a shared location, and they have a mechanism for doing that. My problem is that the location of the extra content is itself stored per-user. I obviously need to deploy the setting telling each user to look for the extra content in the shared location, rather than defaulting to the per-user location.I
Today we are releasing a maintenance version of Jamf Pro; highlights include:Improvements to Enhanced Log CollectionThe following improvements have been made to TriggerEnhancedLogCollection and related functionality:*Details for the TriggerEnhancedLogCollection command are now included in the Jamf Pro API. A CancelEnhancedLogCollection command has been added to the Jamf Pro API. When triggered, active log collection processes are stopped on the target device and logs are not sent to Apple. See the following developer documentation from Apple for more information: https://developer.apple.com/documentation/devicemanagement/cancel-enhanced-log-collection-command. Two new dedicated privileges, "Trigger Enhanced Log Collection" and "Cancel Enhanced Log Collection", have been added to Jamf Pro for their respective functionalities.*Feature support is based on testing with the latest Apple beta releases. Resolved IssuesJamf Pro Server[PI-33] Fixed: Jamf Pro incorrectly attempts to reinstall a
We are excited to share that we’ve updated our Privacy Notices to enhance transparency, improve readability, and reflect evolving privacy and AI requirements.Our Privacy Policy has been revised to provide greater transparency regarding our use of AI-assisted tools within our Services, including technologies that may help record, transcribe, summarize, and analyze customer and sales interactions. We have also added information about our commitment to responsible AI practices, including compliance with applicable AI regulations and safeguards around automated decision-making.Additionally, we have expanded our disclosures regarding advertising and marketing activities, including how we use certain technologies to measure the effectiveness of our campaigns. We have also enhanced our children's privacy disclosures, and introduced information about our process for submitting and resolving privacy-related complaints.We have also updated our Employee Privacy Notice to provide greater transpare
Hi all!We run Jamf Trust with enforced Secure DNS (DoH, ProhibitDisablement = true). The activation profile includes an OnDemandRules-SSIDMatch list with Action = Disconnect for typical captive portal networks (airlines, hotels), so that the DNS connection disconnects there and the login page loads.Problem: A colleague can’t access the captive portal on the Eurowings onboard Wi-Fi (SSID “Wings Connect”), neither on an iPhone nor on a Mac. The SSID is simply missing from the list. The same issue occurs with Lufthansa (“Telekom_FlyNet”), even though “FlyNet” and “Telekom_FlyNet” are included in the list; I suspect the actual SSID being broadcast differs (e.g., with “®”). My questions for you:1. Is this captive portal SSID list editable within the Jamf Security Cloud console itself? In our setup, under Settings > Service Controls, I only see “Privacy”—no “Dynamic Routing” or “SSID Bypass.” Am I missing something, or is this managed on the tenant side by Jamf and can only be changed thr
Im testing Jamf/Entra Device Compliance. Everything is working as expected (Smart Groups, compliant/non-compliant criteria, Entra/Intune connector, etc). Now its time to focus on the actual registration workflow and policy logic to make it as painless as possible for my users.Does anyone have a customize workflow that improves the registration user experience? Popping up the Company Portal auth UI is not an elegant way to register our employees.🙏🏻
I need to lock down some iPads to only display a single web page. These devices are supervised, and will be handed out to study participants in a lab. They’ll then interact with that single web page during the course of their participation in the study. We don’t want the participants to be able to launch any other app, configure any iOS settings, or visit any other website.This article, “Configuring Single App Mode for Web Clips in Jamf Pro,” which was just published four months ago, seems to be exactly the sort of thing I’m looking for. However, when I attempt to implement it on my test device, all I get is a blank white screen with the iOS status bar on top of it.I have tried using both com.apple.webapp and com.apple.webapp.managed as Bundle ID values in my Single App Mode payload. Both have the same result. The Jamf article seems to possibly imply I need to find a Bundle ID value that is specific to the web clip I’ve defined, as it references another article titled Determining the B
Jamf School is there a way of restricting a managed device to only use a managed apple ID. We are looking to go to managed apple Id’s with our Ipads and our New NEO’s. So we are interested if we can do this.
The need for skilled IT workers continues to grow. Many companies and schools rely on professionals who can manage Apple devices and systems. In partnership with Jamf, Maricopa Information Technology Institute (MITI) supports Mesa Community College to offer the Enterprise IT Professional Apple Technology course series to help meet this need and prepare students for today’s workforce.Under the leadership of instructor Carl Cortez, the program provides both knowledge and hands-on experience. Students learn how to work with macOS and iOS and how to manage devices in both business and education settings. Participants also earn Jamf 100, Jamf 170, and Jamf 200 certifications. Jamf is a widely used tool that helps organizations manage Apple devices. Through this training, students build practical skills in setting up, securing, and supporting devices at scale.A key strength of the program is its focus on real world learning. Students do more than attend classes. They complete a capstone proj
I am working on setting up SSO to use Teams on managed devices for Imprivata MAM. I followed this guide to set up the SSO plug in and it was working but now seems to have stopped. Configure iOS/iPadOS Enterprise SSO app extension with MDMs - Microsoft Intune | Microsoft LearnAfter setup, the authenticator app no longer shows Shared Device Mode, but just the normal add account screen. I’ve tried recreating the SSO configuration and changing to a personal network to confirm the issue isn’t network related. I reviewed this troubleshooting page by Microsoft, but that didn’t seem to help either. Troubleshooting the Microsoft Enterprise SSO Extension plugin on Apple devices - Microsoft Entra ID | Microsoft LearnAny other ideas?
Was this a feature add that administrators have been clamoring for over other features or is this just another case of everything needs to have AI jammed into it?
Does anyone know how to get rid of this option? I'm not very techy, but my daughter keeps bypassing onto bad websites by using this option. I'm using an image off the Internet as an example but this is exactly what it looks like. Thank you 😊
Hello,New to jamf school, I followed this page to install adobe with our shared device licence https://support.jamf.com/en/articles/12335537-deploying-adobe-applications-with-a-shared-device-license-with-jamf-schoolEverything runs perfectly but there is one major problem : The apps from the jamf “Apps installer” are only in english even if the creative cloud app from the package made with adobe console is in another language (as there is no link between them, except for licence I guess, cause Creative Cloud doesn’t detect the installations made from “Apps installer”) Is there any way to correct this ?
Hello, We are currently working on configuring Jamf Connect to get away from local AD binding. I have the initial login to macOS working (Google SSO Prompt and Duo MFA is working well.) After initial account creation when you’re prompted by Self Service + to sync your Google Account password to your local account, that is where it fails. The error is: “invalid password.” In testing... any account outside or bypassed from Duo can query LDAP successfully. Accounts encompassed by Duo receive the same “invalid password” message via Self Service + or when running the LDAP query manually via terminal. I’ve already spoken with Jamf support. They did some minor config changes, log searching, asked me to speak with Duo and then resolved the ticket. I have a support request into Duo at the moment but haven’t heard back. I’ve looked through both Duo’s policies and in Google Admin and haven’t come up with anything. What am I missing?
Hello everybody !I’ve been looking around, but without finding any real solution. Add to this changes from Apple / Jamf so what worked before may not work anymore, and of course what didn’t worked before may now be fine.I would like what’s the best practice to install minor or major updates of macOS on Apple silicon computers. Actually, I’m working on 2 scripts: one that will download the updates and another one that will install them later. The problem is: users have standard user account and of course, admin credentiales are needed.I’ve read that mdm commands aren’t very reliable, but as the posts are now from months ago, maybe that it’s working as expected now. And about those mdm commands, I don’t know if it downloads / installs only minor updates, or if it will install major ones if available.I was thinking of having the credentials as parameters for the scripts, but is is secure enough ?A last thing to ask: is there a way to install updates at the computer’s boot ? My main goal i
Hi, we would like to add a watermark text in the background to all our prints. The solution should be distributable over Jamf Pro to our workers. Since now I tried to create this watermark with cupsfilter and ghostscript. Unfortanely both ways didn’t get the watermark in the backgrounds. Have anyone another idea? Best regards Korbinian Eigner
Happy Monday! So I just came across this issue. When a user tries to change their password using Jamf Connect, they get this Kereberos error 4.So they go into Okta and change it there. Later Jamf prompts them that the Local Password and Network password don’t match. They are able to enter the old and new passwords and get the local mac password changed to match. But Jamf still shows “password expires in 0 days”.I didn’t do the Jamf Connect setup, it was here when I joined the company, so I’m not sure exactly how to start fixing this. I’m hoping you have some tips, maybe someone has seen this before, really anything. I’ll keep doing my research, but It’s always nice to get some expert advice.-Pat
I thought I had this right, but I’m not getting correct results…..Processor Type - Like - AppleandArchitecture Type - Is - amr64andOperating System - does not match regex - ^26(\..*)?$Still finding devices running 26. Someone have a better way to write this?Appreciate any nudges in the right direction!
Hi all, I'm trying to upload a specific DMG file to cache to Waiting Room and run a simple script that just installs a PKG that has to be in the same folder as a JSON file. I believe the silent install script I have should work fine, it's just the actual uploading of the DMG file that has me puzzled. I've done this exact same thing with other DMG files that contained items inside (a .app file that I successfully moved to the Applications folder) but this is a PKG file alongside a JSON file which I assume has some kind of configuration it needs. When i upload the DMG in the Packages section, it looks like it uploads, I run the Cached command in the Policy, and I get a corrupted error: [STEP 1 of 5] Executing Policy FireEye Agent [STEP 2 of 5] Caching package Fire Eye Agent 32 30 13... Downloading https://use1-jcds.services.jamfcloud.com//download/012345etc/IMAGEHXAGENTOSX323013.dmg?token=012345etc... Verifying DMG... Error: Could not verify the down
Hi all, I was wondering if I'm the only one no longer able to load the https://macadmins.software/ site that was previously hosted by Microsoft? When I go there now from any device I get a GoDaddy page, so it looks like they didn't renew the site hosting perhaps? I used this site all the time to get the most recent packages for Microsoft software. Is everyone else seeing the same thing as me? If so, has anyone heard anything about this, if this will be coming back or if that's it? I know for a while now while the links all pointed to the most recent versions of software, the version numbers listed on the site were stuck on some old version from many months back, but it was still working to download the most current releases as early as this month.
We're in the process of getting ready to implement JAMF Connect for syncing local accounts with Entra. Our current Wi-Fi is 802.1x PEAP where users sign in with their username and password, which we were told is not compatible. We're looking into certificate based auth using machine certs, but haven't found a clear answer on how to make this work. Our PKI is Microsoft ADCS, so we run up against the strong mapping requirements. We don't have SCEP right now and we are hoping to not open anything for inbound communication as we don't host anything on site anymore and have no real dmz for hosting things. We also don't want to bind to AD as that's pretty terrible. Has anyone gotten this set up in a similar environment? Thanks!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!