Get Support
Recently active
Hi there,I’m experiencing an issue that has suddenly appeared on several Macs in my fleet, which is managed using an on-premises Jamf Pro server.On an increasing number of Macs, the “Connect to Server…” option in the Finder’s “Go” menu has disappeared.I am not applying any specific configuration profile that blocks certain features. I only customize the Dock by adding quick access to applications from the Microsoft Office suite, our VPN, and the Macintosh HD icon on the desktop.A user can still browse the folders on their server through their Finder browsing history, but they can no longer access the “Connect to Server…” option.Could you please help me understand what might be causing this issue?Thank you.
We have a Jamf Pro license and according to what I can see Composer is part of this. But I can not find this software anywhere when I log into the backend ? - Where can I download this ?
My friend Claude and I developed a tool for Jamf and Iru. It allows you to schedule tasks such as activating policies at a specific time or deploying a configuration profile at a specific time. This tool is particularly useful when you need to have certain tasks completed without being physically present at your computer.https://github.com/kylejericson/mdm-scheduler
With Jamf Pro 11.32, support the next major Apple operating systems, use new inventory attributes to gain real-time visibility into computer enrollment and health, and enable a UUID column to distinguish between directory groups with identical names.Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Today we are releasing Jamf Pro 11.32; highlights include:Compatibility with Apple Operating Systems Compatibility and new feature support are based on testing with the latest Apple beta releases of macOS 27 Golden Gate, iOS 27, iPadOS 27, tvOS 27, visionOS 27, and watchOS 27. Inventory Reporting — New Computer and Mobile Device Inventory Attributes This release introduces new inventory attributes for computers and mobile devices that provide real-time visibility into enrollment status and device health, reducing reliance on MDM queries and lowering server load. All attributes require OS 27 or later on the platforms noted, and are based on testing with the latest Apple beta releases: Apple Enrollment Type — Supported on macOS 27, iOS 27, iPadOS 27, tvOS 27, visionOS 27, and watchOS 27. Awaiting Configuration — Supported on macOS 27, iOS 27, tvOS 27, and visionOS 27. Return to Service — Supported on iOS 27, iPadOS 27, and visionOS 27. Device System Health — Supported on iOS 27 and iP
Nobody knew what anyone else had builtThe first real AI problem on our team had nothing to do with model quality. It was that dozens of people had each built something genuinely useful, and none of them knew about the others. That’s where CSAssistNOW came in. All applications I have developed with AI end in the word “NOW” because it is directionally accurate to the time it takes to build, it is catchy, and almost a little bit annoying. It’s just a shared place to publish and find the prompts and skills people build.There are four reasons we wanted this. Visibility - Once a department gets past a certain size, AI use can very quickly become fragmented. Someone automates a renewal summary, someone else builds an account brief, then another builds a risk status dashboard. A library helps make the work visible and legible. You can see how AI is actually being used vs. how it’s supposed to be used, or what you see folks using it for on social media. Basic social features were added to try
Hello Team,We are currently using Jamf pro + Jamf Connect for privilege elevation on our macOS devices. From an audit and compliance perspective, we are looking for a solution that can monitor and track user activity after elevated privileges are granted and can Alert .Specifically, we are interested in capturing and reporting on:Commands executed using elevated privileges (sudo/admin actions) Applications launched while elevated System configuration changes Software installations/removals Security-related modifications Detailed audit logs for compliance and forensic investigationsWe would like to understand how other organizations are addressing this requirement in their macOS environments.Are there native Jamf Pro, Jamf Connect, capabilities that provide this level of auditing? If not, what third-party solutions are commonly integrated with Jamf pro for monitoring privileged user activity? Has anyone implemented this using CrowdStrike, SIEM/EDR platform? What has been your experience
Everyone learns differently, and at Jamf we want to meet you where you are. This may mean comprehensive written documentation. It may take the form of multimedia content like videos or podcasts. One of the best ways to practice a tool is to use it – navigate the interface, explore objects, discover new features, make mistakes, and learn from the experience. That’s why we’re offering new opportunities to train with our products in the form of software simulations. We want to provide realistic and meaningful learning experiences for new and seasoned users. Software simulations allow you to familiarize yourself with the interface, objects, and workflows without the worry of compromising your own server. In a simulated environment, we can provide guidance and tooltips. If you lose your way, we can help get you back on track. You’re in the virtual driver’s seat, and in a safe environment to practice before returning to manage your own fleet. At the Jamf Nation User Conference
I am trying to create a basic Time Machine Configuration Profile to backup users to a SMB share. After initially realising my mistake that the SMB share would need to authenticate based on the Computers AD credentials rather then the users credentials. (as the time machine process does not run as the console user) I am now able to see the SMB share listed as a valid time machine backup disk. The problem that I have is the client computers system disk has been added to the "Exclude from Backups list". Obviously I have not included this in the Configuration Profile and changing the various "Tick boxes" doesn't seem to help. Is there a reason the computers system disk would be added to the "Exclude from Backups list" As part of the MDM profile? As the result of the setting in another none time machine profile? Due to a setting on the the system disk? (Problem exists for both Arm and Intel's running Mac OS 15.2) Any help appreci
Hello,I manage a fleet of iPads used for exams with my on-premises Jamf Pro instance. I push a configuration profile to restrict all of the iPad’s features and only allow students to access Safari and a whitelist of approved websites.I was informed that students might be able to use ChatGPT on the iPads by exploiting a vulnerability.I haven’t been able to verify this yet, but is there a way to block access to ChatGPT through a configuration profile?Thank you in advance for your help.
We have one of our users who is trying to take their macbook off the domain. When they take their macbook and establish it on a network that is not our own, they cannot get signed into their computer. The machine will error stating incorrect username or password while off the networkWe attempted to setup active directory through the general settings area of Jamf Pro, we established “Directory Bindings”, entered our domain information. The computer OU format of OU=OU1,OU=OU2,OU=OU3,DC=DC1,DC=DC2 and went into “User Experience” and ensured “Create Mobile Account at Login” was checked. Now I am not sure what else I missed in setting up the domain or which settings we need to enable so our user can take their device offsite. I do not want to remove the configuration/enrollment from the device or create a local account. Does anyone have any suggestions?
Can someone help me how to block copilot app record option for corporate ios devices, i tried adding xml dictation on device apps> app configuration to block but did not worked
Hi Nation,Product Office Hours #4 - Jamf's Engineering AI: Nighthawk - A peek behind the curtainNext session: Thursday, 3rd Sep - 9am CDT / 3pm BST / 4pm CESTSpeakers: Akash Kamath, Chief Technology Officer, Martin Barnard, Senior Product Manager & Justin Wilke, Principal Enterprise ArchitectRegister here: https://jamf.it/ProductOfficeHours 🧵 Got a question? Drop it in the comments below ahead of time if you want it on our radar, though you don't have to. We'll be taking questions live on the call! Anything we don't get to, we'll follow up right here within 24 hours.See you Thursday 3rd!
Over the summer some of our computers has lost our Wi-Fi profile. I wonder what’s the best solution to get it back. For the moment they are using our guest Wi-Fi. But it’s very limited for the users so we need to get the profile back.I’ve created a smart computer group that show all the computers that don’t have the profile. Should I put the group in the scope? Won’t the loose the profile again when they’re not in the smart group anymore?
Hello all,First-time poster on Jamf Nation, so please criticize formatting, grammar, etc.We use Bomgar Remote Support on our Macs, but when deploying to a test machine running Sequoia, I get the message "Allow Remote Support Customer Client to find devices on local networks?" It looks like a PPPC popup with options to "Don't Allow" or "Allow", but I can't find a corresponding PPPC setting. We already have Accessibility, SystemPolicyAllFiles, and ScreenCapture set up according to this deployment guide, and I don't see another PPPC option that looks related to this error message. I'm not even sure why this is a permission that needs to be allowed. It feels like the Windows message to "allow this device to be discoverable on local networks," but it's going the opposite way. Why would I need permission to go out on the network and connect to the Bomgar server from my endpoint? Has anyone else seen this popup before or something similar?
Has anyone been getting unsuccessful GSX warranty lookups this week? I have been getting them since yesterday.
Hi.We’re using Jamf School as MDM (so please do not tell me all the wonderful things available in Pro 😅 ).Setting up MacBook Neo’s as new student devices. We want to block applications as: FaceTime, iMessage, Phone, iPhone mirroring during enrollment. As of today the only “half ass” solution is the “Safelist and Blocklist” payload, but this is deprecated : Are there any other good solutions for getting this to work?
My company has been using Jamf Pro to manage iPads for several years. I’m trying to get our Jamf Pro account configured with SSO using JumpCloud SAML and I have a few questions.First of all, I’m new to jamf and not too familiar with the nomenclature. I have an account in our Jamf Pro subscription but not in Jamf Account (apparently). I created a Jamf Account but it doesn’t seem to be connected to our Jamf Pro subscription in any way. I’m assuming that the Jamf Account is some umbrella account that manages all the other Jamf subscriptions (education, pro, etc.) Is a Jamf Account necessary if we only have a Jamf Pro subscription?If I’m reading the docs correctly, SAML is the deprecated way of managing user logins for Jamf Pro and we’re supposed to use OIDC from our Jamf Account account. Is that correct? We are not looking to do anything fancy through SSO, I just want to manage my employee’s Jamf Pro accounts. We’re not building apps or anything else that need OIDC.Can I just use
New Fortinet customer here. We are testing always-on IPSec VPN (split tunnel) on macOS 26 Tahoe.I have all the Fortinet recommended MDM profile payloads deployed to my test Macs (SEXTs, TCC/PPPC, Notifications, Content Filters, Login Items, etc). But Im still seeing a couple issue, including these 2:1 How do I suppress this user-facing pop-up: "FortiTray" Would Like to Add VPN Configurations All network activity on this Mac may be filtered or monitored when using VPN.2 Once approved (which is required for some reason), a virtual ‘VPN’ interface is INSTANTLY created in macOS Network Settings. Yet this interface is literally unusable, and never becomes active. And users are able to remove it manually if they so desire (i.e. it’s not locked). If a user does NOT allow this VPN, this pop-up will appear persistently until action is taken.How can I remove this pop-up and related interface? I dont want end-users to see this in the UI since it isnt ‘real’ and will just lead to confusion and fr
Hi all,I hope I'm posting this in the right place, but I am experiencing an issue with my jamf school shared iPad deployment regarding display names.From the list of selectable users, most users have their first name listed, but for a very select few users, their accounts are listed with their last name instead of their first name. This has become confusing for the younger students here at the school I manage. Hope that makes sense.I don't know why this is, their first names only range between four to six characters, and there aren't any users who share the same first or last name as the affected users in the system. If I could list their entire name that would be ideal, but I'm willing to take any advice or solutions to this problem.My users are provisioned through SFTP sync and uploaded to ASM. I have checked their users through Jamf and it looks like the first and last name are being populated correctly.Thanks!- sammy
Hello everyone We are trying to deploy FortiClient VPN only from this link https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/76cde386-1f8c-11ef-8c42-fa163e15d75b/FortiClient_7.4_Jamf_Deployment_Guide.pdfthe Application installed perfectly but we have issue with configuration of the app1- To grant FortiTray permissions to load and grant network access.2- To grant full disk access to load the following FortiClient processesI have made the same as what they mentioned in the pdf but the user get popup to allow them.what I want is:1- These configuration only install if they install FortiClient.2- Not popup any thing to the user when install FortiClient to allow for permission3- If someone can please shared with me the configuration.
Hi all !How can I enable/disable admin rights to change wifi setup, by script or config profile ?It’s located graphically in the advance pane on the wifi preference pane. Thank for all of your suggestions :-)
Hi all,I'm running into an issue with device naming in Jamf School (not Jamf Pro) and could use some clarification.Setup:Device: Mac mini (2024), macOS 26.6.2Enrollment: Automated Device Enrollment (User Approved Enrollment)Device Details > Name field shows "Set by policy"Issue:The Mac's local computer name was changed after enrollment (directly on the device), but this change is not reflected in the Jamf School console — the inventory still shows the old name. I tried the "refresh" button next to Details on the device page, but it does not pull in the updated name.Questions:What exactly does the "Enable Renaming Devices" checkbox under Organization > Settings > Enrollment do — does it affect already-enrolled devices, or only new enrollments/Setup Assistant?Since this device's name is "Set by policy" (likely from the ADE naming scheme/template), is there a way to sync the device's current local name into Jamf School's inventory, or does Jamf School always treat the naming poli
Through guided simulations, discussion, and some time with Jamf subject matter experts, you will get direct practice building and deploying blueprints in this workshop. It’s free, it’s two hours, and it’s hands-on: you’re not watching a demo, you’re doing the work.Register now and pick a date and time once you’re logged in with your Jamf ID. Can’t make this one or want to explore more first? Watch the Jamf Short video for Jamf Pro, Jamf School, or Elevate customers. Read the blueprints documentation for Jamf Pro, Jamf School, or Elevate customers. Check out the Jamf Nation Live demo session on the shift to the DDM only life. Learn how to configure identity and access management, a prerequisite for blueprints, with this training series. Quick Reminders Blueprints will also be covered during the Level Up full-day, hands-on learning experience prior to JNUC in a few weeks. Come join us in person! Stay up to date with all the latest training videos, release notes, Jamf Shorts, and
Hello everyone,This year we’ve got aboout 300 Macbook Neo’s. About up to 5% on the get an error. We enroll them just like we always have. The users log in with their Entra credentials during onboarding. After a while when the login is processed an error message pops up as shown bellow:The only thing for us to do is to format the drive and reinstall the computer. Then the users does the same without any problems. We had never had this error message before until Macbook Neo.Does anyone know we we get and/or what we can do to prevent it in the future?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!