Get Support
Recently active
We have a script to disable the macOS randomization, it’s been working prior to macOS 15.6. Since 15.6 it has not worked, it also does not work on the beta of Tahoe. The script would hard code the MAC randomization to OFF, and set the default for all new networks to “NOT SET” which then becomes “OFF”.Has anyone else experienced issues with MAC randomization on 15.6 or the Tahoe beta?
Is there a way to get set up a search to show any user without a device (iPad) assigned to them? I am trying to clean out our user database.
Hello,We are evaluating ways to enhance our IT support workflows and are particularly interested in leveraging customer support automation software alongside Jamf Pro. Our goal is to streamline tasks such as ticket creation, device status updates, and end-user communication without compromising service quality.Has anyone successfully implemented such integrations within a Jamf-managed environment? What challenges did you encounter and what measurable benefits such as efficiency gains or improved user satisfaction did you observe?Any recommendations for best practices or compatible tools would be greatly appreciated.
I have several iPads that need unenrolled from our Jamf Pro MDM. Unfortunately, they have expired device identity certificates and recently expired signing certificates. Is there an efficient way to simply unenroll them? I’m a novice at this, so please ask me the necessary questions.
Sometimes when an app or profile is scoped to devices, they get stuck in a pending status indefinitely, but a blank push command will "wake up" the process and it will complete. I'd like a way to send a blank push to all devices if a major profile or app gets deployed to speed up distribution.I can pull up a smart group of managed devices, go into the action menu and send commands to the group, but sending a blank push is not an option as a remote command using this method. And I'm not interested in doing it on an individual device basis from the management menu.Is there a way to send a blank push remote command to all devices or a group of devices?Thanks,Rob
Hello world. Mike here. I wanted to let you know that MUT v6.2.0 was released today! The biggest change you're probably excited for is that MUT now uses bearer tokens for all authentication of all API calls, which means it is fully ready for the deprecation of Basic Auth for the Classic API. There's also a new settings menu. You can access it from MUT > Settings. All existing settings (Allow untrusted SSL, delimiter selection, etc.) have moved to this new menu, and you'll notice a few new options as well. Of note, there is now an option to select a log level, so you can cut down on the chatter and only get errors if you're looking to troubleshoot an issue. Additionally, credentials are now stored in Keychain by default, as opposed to user defaults that they were stored in before. If you'd rather use the legacy method, it's available in the new settings menu--but know that (as always) password storage is not available in user defaults. If you choose to store credentials
I have one user who cannot log in through the LDAPS login at initial setup. No other user has this issue. Their username can be queried through the LDAPS search test and each field populates correctly. They have no issues with other platforms that use LDAPS. I have changed their password and it has made no difference. Are there restrictions that can be placed on a user that I am missing?
We've got a profile that blocks the social media category on iPads as per school policy. However, on some devices (not all) it's blocking Duolingo and Picsart as well. Duolingo is categorised as Education and Picsart Photo & Video. There's no other restrictions blocking apps.I've tried removing the user from Jamf and resyncing with ASM/reassigning to the device but it didn't work.Has anyone else seen this?
Having a strange issue with JAMF Connect computers. We use Google SSO at the login in screen and it works normally, however, when the user logs out you are not able to click in the email box to sign in again. A restart will fix it but wondering if anyone has seen this.
Hello jamfnation, I have a question. I try to rename some user accounts to match the company pattern. We want to do this process as smooth as possible for the user and admins. Therefore I've written a script which checks values and asks the user several questions which in the end creates a plist with some variables. After that the script reboots the computer and uses Rich Troutons "First Boot Package Install" (script almost completely rewritten) to show a log to the user what is happening. At that window the script, which is started by a LaunchDaemon, uses dscl to change the homefolder, uses mv to move the homefolder and again uses dscl to change the username. Now my problem:In order for dscl or mv to be able to change the homefolder it needs access to it (PPPC). My script is signed and stays signed, and a PPPCP is in place to allow for my script to access Admin Files and/or All Files. I also tried the unsecure way and allowed /bin/bash access to AdminFiles/AllFiles.However it is not
We are trying to figure out why most of our Macs updated to macOS 15.6.1 after I used Software Update in Jamf Pro to enforce getting Macs updated to macOS 15.6. When I set the update to go out, I specifically selected 15.6, not 15.6.1. I always check a few Macs in the group I selected to update to verify that they received the correct scheduled update. I confirmed that they had received the scheduled update for 15.6. Right after pushing out another update command, I saw that my own Mac already runnning 15.6 displayed an alert that it would update to 15.6.1 at the scheduled time. We have a profile installed that defers updates for 21 days. I confirmed that it is working using Macs not yet updated to 15.6. They all show 15.6 in Software Update. Macs running 15.6 do not show updates available. I wonder if the enforced update is responsible for this. I was very careful to specifially select 15.6 as the update we wanted to run. Has anyone else seen this behavior?
We upgraded some of our iPads to ios 7 and are unable to disable iMessage and Game Center. We do not use Apple Configurator as we are a Windows school. The iMessage option IS disabled in the restrictions for this profile group but still shows up on the individual iPads. We deleted the profiles on the iPad and it still came back.
Jamf is showing as disconnected after changing the user group membership (Version 11.19.1-t1754574720728).We are getting the following alert:"Exception_Group is actively targeted in the scope of the objects listed below. Changes to this group membership may require more time to deploy than usual due to the increased network traffic associated with redeploying certain content. Jamf Pro may be unusable or unstable during this time."After this message, if we save the assignment changes, the user device gets disconnected and does not accept any sudo commands.
Did someone have the problem logging in from a computer and this window appear? Some computers on our system do throw this if our trainees are trying to log in. They are on the same network as other devices and this appears on multiple browsers.
Hi, I’m trying to manage our recurring license limit in Jamf School since we’ve just renewed a couple days ago. I’ve already released the devices from our organization and they don’t even show up in the Inventory > Devices menu anymore. When I select them under the License Assignment menu, I only get the option to “Assign a Perpetual License” and there’s no option to remove a recurring license: Thank you in advance.
To prevent user from syncing Chrome data with their personal google account, a custom setting for Google Chrome can be set and deployed by Jamf Pro. Preference Domain: com.google.ChromePlist file content: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>RestrictSigninToPattern</key> <string>(?:.*@domain1.com|.*@domain2.com)</string> </dict> </plist> let's check the managed chrome policy status and the sync result.
Disabling an Existing Local Account for FileVaultLog in to the JSS with a web browser.Click Computers at the top of the page.Click Policies.On a smartphone, this option is in the pop-up menu.Click New images/download/thumbnails/5832871/New_icon.png .In the General payload, enter a display name for the policy. For example, “Disable Local Account for FileVault“.images/download/attachments/12979842/DEC_Policy.pngSelect a trigger and execution frequency.Select the Local Accounts payload and click Configure.Choose “Disable User for FileVault 2” from the Action pop-up menu.images/download/attachments/12979842/LocalAccounts_DisableforFV2.pngEnter the username of the user you want to disable for FileVault.(Optional) Select the Maintenance payload and then select the Update Inventory checkbox so that the FileVault-enabled status for the local account is updated in inventory immediately when the policy runs.Click the Scope tab and configure the scope of the policy.Note: If applicable, you can us
Hi everyone, I have an JAMF managed I-pad that we use for testing. I need to connect it to my Macbook pro to run debugging. When I connect it to the Macbook the Ipad does not show the Trust this computer pop up. Is there anything I can do to be able to see this alert in JAMF?
Hello everyone,With the release of macOS Sequoia, I’ve run into an issue with our podium iMacs that are connected to projectors. By default, they no longer mirror the display to the projector screen, even when using scripts or third-party tools from GitHub.Currently, I have to manually adjust the display settings to enable mirroring for each instructor who logs in.Has anyone encountered this and found a reliable solution or workaround?Thank you in advance for any suggestions!
I’m getting Jamf Self Service error loading content when accessing self-service to download apps.
Name and information link Available for Release date iOS 18.6.2 and iPadOS 18.6.2 iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later 20 Aug 2025 iPadOS 17.7.10 iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation 20 Aug 2025 macOS Sequoia 15.6.1 macOS Sequoia 20 Aug 2025 macOS Sonoma 14.7.8 macOS Sonoma 20 Aug 2025 macOS Ventura 13.7.8 macOS Ventura 20 Aug 2025 CVE patched ...https://support.apple.com/en-us/100100
Outlook Search is Broken Problem: When you search in Outlook, you get "No Results," even when you know the email is there. Solution: Force the Mac to rebuild its search index for Outlook. Quit Outlook . Go to System Settings and navigate to Siri & Spotlight . Click the Spotlight Privacy button. In a new Finder window, click Go → Go to Folder, from the menu bar. Paste this path and press Enter: ~/Library/Group Containers/UBF8T346G9.Office/Outlook/Outlook 15 Profiles Drag the "Outlook 15 Profiles" folder into the Spotlight Privacy list. Wait about a minute, then click on the folder you just added and click the minus button to remove it. Mac will start re-indexing in the background. It might take a few hours, but search will work again when it's done. Mac is Slow After Update Problem: Mac feels sluggish and shows the spinning beachball a lot after updating to Sequoia Solution: This is often temporary. Here are the main things to check. Wait it Out: Af
Dear Team,Anyone can address which domains or settings need to bypass in DNS settings to login cloudflare warp client successfully? My Jamf Web Protection only enable Internet Content Filtering, therefore MAC OS machine no need Jamf Trust, it only needs profile configuration , UEM connect settings in place.I have the issue that When the DNS settings disable I am able to login CloudFlare WARP client If the the DNS settings enable, i can not login the CloudFlare WARP client with the error message "CF_DNS_LOOKUP_FAILURE." and here is the solution Verify that the network the user is on has DNS connectivity.Verify that DNS resolution works when WARP is disabled.Ensure that no third-party tools are interfering with WARP for control of DNS.Ensure that no third-party tools are performing TLS decryption 5 on traffic to the WARP IP addresses 4.I already tried to bypass these domains without help in configuration proflie<string>*.cloudflareclien
I recently had to rebuild a device because it would not install any updates, so I started from scratch. I got Sequoia installed and when I attempted to use Jamf.OUR.COMPANY/enroll, it did not download the normal MDM & CA profiles, but the QuickAdd.pkg. Even with enabling all pkgs via “sudo spctl --master-disable” and “-allowUntrusted” when using “sudo installer” the package still continues to fail because it is untrusted. Is there any way to manually download the MDM & CA from jamf pro since the /enroll will not download it? Or just another workaround in general? Thank you!~G
We recently implemented Content Filtering and saw that the “Clear All” button for safari is now disabled. In providing support to our users, we often tell them to clear their cookies and cache when they are having issues loading a website. Now that content filtering is enabled, this is no longer an option.How have you overcome this? Any recommendations?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!