Get Support
Recently active
https://community.jamf.com/p/jamf-heroes
Running into this for iOS and macOS? Vote if interested.Be nice if admins could customize the verbiage for users that fall out of compliance in your organization. Will give the customer a better workflow and user experience. Less calls to the “IT administrator.” Link: https://ideas.jamf.com/ideas/JPRO-I-1479
Hey Jamf Nation, We're opening the doors on something new: Product Office Hours, a live weekly space on Jamf Nation where you get direct access to the people building the product.Each Thursday, members of our Product and Leadership teams sit down with the community for a new theme. Think behind-the-scenes looks at Jamf, product how-tos or big-picture thinking. Submit (and upvote) questions, and get them answered live. No fluff, no script - just real conversation with the people behind the product. 📅 Starts: Thursday, August 13🕒 Time: 3 p.m. BST / 10 a.m. EDT / 9 a.m. CT / 4 p.m. CEST⏱ Length: 45 minutesFirst session: AI Governance: What is it and what can we do with it?Want to see what's coming up, or get a question in early? Head to the Product Office Hours hub. That's where we'll post the theme for each upcoming session, and it's the place to drop your questions before, during, or after any call. REGISTER HERE for upcoming sessions. See you there!Lysette
Anyone else getting errors when working with devices in ASM today? I’ve had two Windows users report it to me, one on Chrome and the other on Edge… then I just got it in Safari on my Mac. Apple status lights are all green right now.
Issue: Mobile Devices on iOS and iPadOS 26 or later Booting are occasionally booting into Recovery Mode. Standard expected workflow: We have Microsoft Entra ID SSO extension configured with the Jamf Setup and Jamf Reset apps. When a user signs out using Jamf Reset three different configuration profiles are removed:Profile with a Passcode payload Profile with a Restrictions payload Profile with a Lock Screen Message payload When the above profiles are removed, two profiles are installed:Profile with a Restrictions payload Profile with a Lock Screen Message payload The issue appears to occur during Jamf Reset sign out as one configuration profile is removed (confirmed by completed command logs) and can vary between the Passcode payload profile or the Restrictions payload profile while the other two commands are left pending.Example pending commands that occur at the time of issue:Clear PasscodeEnable App StoreProfile ListCertificate List I have not been able to reproduce the issue on tes
Hello !Since Tahoe, my profile for the login window doesn’t work anymore as expected.We use Fast User Switching and everything worked fine. I use a profile to enable it and a script to configure it as needed (Full user’s name). But since macOS Tahoe, even if the profile has the checkbox marked, every Mac computer has the user’s full name greyed out instead of white and I can’t switch users. If I remove the profile, everything is fine and the user’s name is white. No matter if the checkbox is marked or not.Is it a bug ? Is there a solution ? I need the Login Window profile for some configs, but maybe that I could script this instead of using a profile ?Any help is welcome !
At the moment it seems that JAMF is unable to turn off private wifi addresses via configuration policy even though they have an option for "Disable MAC Address Randomization (macOS 15 or later)". After testing with JAMF and confirming this function does not work in setting this to OFF (there currently are no granular settings in the MDM framework for this), they recommended I raise a developer case with Apple for this. Shouldn't JAMF be doing this to allow this functionality in their MDM instead of us as a user?? Our vendor is incredibly upset and recommending we drop JAMF as a product due to their response on this.
Lots of posts about return to service, but nothing I have found about the Wi-Fi profile used in the Prestage Enrolment.As this profile cannot have anything except the Wi-FI payload (why??) There’s a workaround for Enterprise networks which have such things as a certificate payload.The workaround is to add the certificates to the profile after you have added the profile to the Prestage Enrolment. But when you go to save the modified profile, you are given a choice between sending to all devices or only devices without the profile.Well none of the devices have the profile yet, and if it’s a clone of your normal enterprise Wi-Fi profile, what will happen if you go ahead? Will you end up with two profiles with the same Wi-FI payload? I am reluctant to go ahead as changing WI-Fi profiles midstream is fraught...
I'm setting up automation for a COW of iPads. These are (mostly) DEP enrolled devices. I'm using cfgutil to restore/pair/prepare and then the last step is to load a configuration profile that is used to add the devices to a smart group based on what they're going to be used for. It all works fairly well, but i always get the error: "cfgutil: error: User interaction on the device is required to install this profile.(Domain: ConfigurationUtilityKit.error Code: 625)" the profile even gets installed if I load it before prepare, but i always get the error. Is there something i could do to remove the need for user interaction?
Apple releases security updates to macOS Tahoe, Sequoia, and Sonoma The release build for each system is:• macOS Sonoma 14.8.9 (23J631)• macOS Sequoia 15.7.9 (24G830)• macOS Tahoe 26.6.1 (25G76)Link Here
I've worked in IT for over 20 years, and I've seen plenty of changes. But AI is the biggest shift I've faced yet. Like any new technology, it brings real benefits and real challenges. That's especially true in training. Most of the students I work with are already using AI, and the rest plan to start soon. It's making them faster and more efficient. But it's also introducing a new risk, the quality of the answers their AI tools hand back. This is where I think Jamf has gotten something right. Their own AI Assistant, built into Jamf Pro, takes a different approach than the general AI tools my students reach for. AI Assistant can read, analyse, explain, and surface information from your Jamf environment. But it can't modify configurations, push policies, enrol devices, or take any action that changes your fleet's state. It's built to help you understand, not to act on your behalf. What makes it useful is where its answers come from. When you ask it a question, it pulls from two places b
In JAMF Protect i have devices incorrectly showing as failing compliance on Bluetooth Sharing Disabled. I have a Configuration Profile created using JAMF Compliance Editor for this and shows on the devices as being disabled and controlled by a configuration profile yet JAMF Protect still reports the devices as failed complianceIs there a detection method i am missing that JAMF Protect is using ?I have also tried setting up a Blueprint for this also and JAMF Protect still shows the device as not compliant
Hello everyone, IDK if anyone is using the great add on to Macs, but if you are can you help me get 4 Tiles to work? Tile #1 - Submit a Service Desk Ticket - the link is mailto:#servicedesk@mycompany.com. Nothing happens. Tile #2 - Battery - can't get it to display the battery level. Tile #3 - Storage - can't get the amount of storage to display. Tile #4 - Privacy and Security - can't figure put how to open this one. We want end users to be able to open Privacy & Security directly without going through SystemSettings>Privacy and Security. Other than that, it is a great addition to our JAMF program. If you haven't tried it - check it out. https://github.com/root3nl/SupportApp JNUC 2021 release with training: https://www.youtube.com/watch?v=LijCmR6gQAM
Hi there - I’m new here so if I’m somehow off-target with this post, please let me know! I looked around for a Welcome message with guidelines, but had no luck. Sorry if I misunderstand anything. Here is what I’ve come to ask:What is the simplest effective way to properly secure 1-3 Macbooks? The scale is small but security requirements happen to be high (imagine a law firm, for example). I need both a professional configuration, which I’ll tweak for our purposes, and a deployment tool, but an entire MDM solution is way too much. Some background: I’m an experienced admin on other platforms, I’ve lightly used and helped out people with Macs for a long time but I’m new to actual, professional Mac adminsitration. Now I have just a few Macbooks, one to start. To narrow scope, I’m not worried about configuring or locking down user behavior, productivty, or updates and management (for this purpose). I need to lock down system and network behavior, including protecting identity (so no iCloud,
Where I work two different teams manage the MacOS and iOS devices. It would be nice to limit the iOS team to only devices and MacOS team to only computers. I know you can do this by creating a site but it seems like a lot of work to move all our iOS stuff to a new site.
What’s the best way to add an app to Restricted Software that has a number (e.g. App Name 3.app, App Name 4.app, etc) Activity monitor shows the process name with the number as well? Do I just need to create a separate entry for each version?
Hi all,I'm running 2 macOS VMs on a bare-metal Mac (host is also macOS). I'm seeing inconsistent iMessage sign-in behavior depending on the Apple ID type and whether it's bare metal or virtualized:Managed Apple ID (ABM-issued): signs into iMessage fine on the bare-metal host.Same Managed Apple ID: fails to sign into iMessage inside the VM on the same physical machine.Personal/basic Apple ID: signs in fine in the VM without issue.Has anyone run into this specific combination — MAID working on bare metal but not inside a VM, while a personal ID works fine in both?
I’m using a Jamf Pro Policy to remove dock items from student laptops. Process works slick, except for the Apple TV app, which stubbornly hangs in there, in spite of my efforts. Anyone else experience this problem, and perhaps found a solution? I’ve read about the dockutil, and will probably fool around with it when I have time, but the JAMF GUI would be my preferred solution, if it would work. Please share ideas. Thanks
Hi,so I just noticed that the configuration profile payload that defers macOS Updates up to 90 days is deprecated. So I was wondering how you are supposed stop your users from updating to the next macOS Version, once this is removed. Does anyone know? Kind regards
Hi All, Does anyone has a method after User has action SSO on the system that Jamf Pro will extract all there details from Entra ID included there department to the User and Location information for there system in Jamf ProThanks in Advance
Hi, anyone know how I can suppress this notification, what should one configure in the configuration profile? I think it might have something to do with the management action app, based on the icon. I’ve configured a Management Action profile with a notifications payload a coupla months back but looks like it don’t work. I’m concerned users are going to start logging tickets for this
Trying to offboard a business org user who is keeping their laptop but it has to be wiped. However it is not accepting the activation unlock code.Steps taken: 1 - device was locked from jamf now2 - device was erased by sending “Erase device” command from jamf now.3 - Unlock code was provided to user to unlock. It failed. 4 - Tried to use activation unlock from Apple Business Manager. ABM now says the activation lock disabled, but device still shows activation lock screen. What else can I try as the MDM admin/ABM contact?
Hi team,We are looking to strengthen our change management and security controls within Jamf Pro. Specifically, we're exploring ways to implement a peer review workflow for high-risk payloads like Config profiles, policies and scripts.Currently, any admin with edit permissions can save and deploy those changes immediately. For us, having a single admin able to make immediate, wide-reaching changes introduces significant risk—whether from accidental misconfiguration or compromised admin credentials.We’ve considered reducing the permission scope of admins and granting limited time admin elevations, but we’re mostly interested in payload-level security here which we think is best to solve the problem.Curious to hear if you’ve thought of this, or if there’s any non-native way to solve it.I tried searching through the this forum and the mac-admins slack but couldn’t find any previous discussions on it. Feel free to point me to one if it already exist.Thanks!
Hey So Im looking to turn the hadware history of inventory into an extension attriubute that udaptes when the OS changes. I mnot sure if this is the right way to go however I made a script that runs during invetnory check in however its only pulling in with the OS was downloaded to install. Any suggetions on how to get this set up so other techs can use the extension t oassist with troubleshooting?
Hi everyone,I've been working through a deployment of Platform SSO Simplified Setup on macOS 26 using Microsoft Company Portal 5.2604.1 (5.2604.0 or newer is required per documentation), and I've hit a wall with username/account name mapping that I wanted to share in case others are running into the same thing and could potentially provide some alternative options.---Our Setup- Jamf Pro 11.28.1- macOS 26- Microsoft Company Portal 5.2604.1 (deployed as a PreStage package)- Microsoft Entra ID- PSSO profile with Simplified Setup enabled (EnableCreateFirstUserDuringSetup + EnableCreateNewUserAtLogin both true)- Authentication method: Password- Associated Domains payload included in the same profile---The ProblemEverything works end-to-end — Simplified Setup fires during the Setup Assistant, the user signs in with their Entra credentials, and a local account gets created. However, the local account short name is being set to the full preferred_username value (e.g. John.Smith@company.com), w
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!