Get Support
Recently active
Hello everyone, you can probably help me with a request.I created a configuration profile for software updates in Jamf Pro, and I enabled "Automatically install app updates from the App Store" because I always want to have the latest updates for apps installed from the App Store.However, there is one app that I don’t want to update automatically, and that’s Xcode. This app must not auto-update, because newer versions of Xcode don't always work for our developers.I deploy Xcode via the Mac Apps - App Store section. In the settings, I disable "Automatically force app updates", but it still seems to update on its own.Do you have any idea what I could do?Jamf support told me that since it’s an app installed from the App Store, it’s not possible to block automatic updates for that app only.Any ideas?Thanks all
Looking at a JAMF instance that has this policy that runs once a day on recurring checkin. (scoped to ALL 4K+ macs)it’s just a files and processes: softwareupdate -ad --verboseI feel this policy is totally unnecessary. OS X caches updates BY DEFAULT. I’m watching this in real time on a workstation using jamf policy -verbose and it’s just sitting there doing nothing but burning up bandwidth cycles and preventing software install policies that the customers actually want from ever running.
Testing out GlobalProtect for our Mac users and running into this keychain issue. We are using a local Certificate for authentication but the machine wants to use the system keychain every time GP tries to connect. The goal is to have the users never have to authenticate or enter a password after the local cert is installed. I have already amended the ACL to include the GP app but the keychain still wants to be accessed. I am also using an administrator account, but still am prompted. If I manually unlock the System keychain from the keychain menu I am still prompted when I try and connect. Thank you for any help or tips someone may have.
A notice in “Other changes” in the 11.20.0 Release Notes mentionsApple deprecated the following keys in macOS 26*, iOS 26*, iPadOS 26*, and tvOS 26*. This change deprecates the Defer updates of settings in the Restrictions payload for computer configuration profiles and the Defer software update setting in the Restrictions payload for mobile device configuration profiles.This is not currently noted in the Restrictions profiles for devices or computers. They mention using Blueprint builder to manage deferrals going forward. Time to test Blueprints once we get past the last deferrals or 26 apparently.
Hi all. AirDrop is enabled for use between our shared iPads. However, when transferring files, the iPads emit a beep, but no notification appears to accept the transfer. Do you have any insights into what might be causing this issue? The devices are running iPadOS 18.3.1.Thanks in advance for your help!
On Saturday, October 4, 2025, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time us-gov-west-1 October 4, 2025 0800 AM CT 1200 PM CT
Important notice: This version is intended only for on-premise environments. Jamf Pro 11.20.2 will not be mass deployed to Standard Cloud environments or posted on Jamf Account for manual hosted upgrades. Today we are releasing a maintenance version of Jamf Pro; highlights include: Resolved Issue Jamf Pro Server: Security IssueJamf provides the CVE-ID for security issues with high or critical severity when possible.[PI141565] Jamf Pro 11.20.2 includes Tomcat 10.1.44, resolving a known security vulnerability in a third-party library (CVE-2025-48989). For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro.
I have a Configuration profile to set the wallpaper to the corporate wallpaper, but that give error on MAC OS 26 Tahoe.Any one with the same problem?
Hi there,I'm looking for some assistance please in coming up with a solution to sharing organisation contacts to 100+ iPhones as read-only.In our current setup we're hosting the contacts on a Google account and have configured the Contacts payload in JAMF with the Google CardDav server which works great, however is NOT read-only, meaning end users are able to add/modify/remove these shared contacts which we do not want...I've faffed around with different solutions such as CoContacts, however am yet to come up with a solution that works. Any assistance is greatly appreciated!!P.s we have no allegiance to Google contacts and are only using it as a temporary stop-gap, but happy to switch to another platform if it will allow for read-only contact sharing that can be deployed via JAMF. Thanks again.
As the subject says, if I have auto update for a VPP app for iOS is set to disabled, new version comes out, app updated on one device, users verify the new version is good to go, how do I send the update to a thousand devices at once? In our WS1 environment it’s simple, I just select the radio button next to the app and click Update.
I’ve tried testing a few times with Tahoe Beta and now Release and can’t get a Platform SSO to trigger an account creation. I’m tried just scoping profiles to target workstations, adding the profile as well as adding the profile to my Pre-stage. What am I missing? PSSO works great once an account is created, however I can’t get the Tahoe specific options to occur.
Hello , Is there any way to block all apps except the chosen ones? I saw on Apple developer that whitelisted app were deprecated whitelistedAppBundleIDs[string],but solution with allowListedAppBundleIDs didn't work for me. In my case I need to push policy to block everything except preinstalled apps and 5 chosen by IT.
Important notice: Beginning with this version, Jamf is no longer sending maintenance release email messages. We will continue to send Jamf Pro release announcement email messages for major and minor releases (e.g., 12.0.0, 11.21.0, respectively). Today we are releasing a maintenance version of Jamf Pro; highlights include:Resolved IssuesJamf Pro Server[PI134363] Fixed: When configuring a computer configuration profile with a Network payload with "Any ethernet" selected, Jamf Pro incorrectly uses the string "AnyEthernet" instead of the required "GlobalEthernet" in the payload, preventing computers from successfully joining corporate 802.1x wired networks. [PI139045] Fixed: Activation Lock status fails to display for eligible iOS devices in the Management > Activation Lock bypass category of a mobile device inventory record. [PI140234] Fixed: Static groups fail to display in the Management > Mobile Device Groups category of a mobile device inventory record. [PI140306] Fixed: Jamf P
Howdy all, I am facing an issue that I can’t seem to solve with running Microsoft AutoUpdate via script from Jamf to keep our mac office apps updated. I have had this set up for several years and it had been working beautifully as a hands off solution. I am not sure exactly when it started failing, I recently noticed the problem and started digging into it. I am wondering if anyone is facing the same problem, or has advice on what to try.The setup is fairly simple, a policy that runs against a smart group of any macs with office apps that are not the latest version once a day. It runs a script to use the MAU command line msupdate to pull and install any available updates.Script is below, it only worked under user context originally so that is why it is set that way.The error I am seeing on every run now is related to the XPC connection, this happens on all clients no matter what, -reinstalled MAU with latest version, brand new mac build with latest install etc. I have the original PPP
Has anyone had luck hiding the 4 slides that appear after an upgrade to Tahoe?
Hey all, Wondering if anyone has any ideas on this? I am wanting to utilise SAM to lock down our iPads to a specific app. Trying to scope this through a department group but the device isn’t showing in the logs for the configuration profile. There are devices in there, just not the two that I specifically need. Both devices that aren’t showing in the logs are supervised and managed institutionally so unsure on what the issue is here… I have also checked to see if I can manually add the two devices but they are not showing when I try to search for them? Getting increasingly confused as the devices that are showing scoped currently, and are in the profiles logs, are NOT supervised...
Morning,Despite my best efforts i haven’t found a solution online so my question is, can i deploy an automator workflow i’ve created via Jamf Pro as some sort of policy of which i can then distribute to selected machines?Thanks
Hi All, We have setup Jamf Pro SSO and Cloud idP for to EntraID. We then tried to use the EntraID groups for the targeting of applications/configuration profiles but they wouldn’t scope correctly. I logged a ticket with jamf support and their theory was that because we map UserPrincipalName (i.e. Full email address), this doesn’t match the username on the local account because it doesn’t support the @ symbol. Their suggestion is to drop anything after the @ symbol on the mapping but it’s not that simple as we use the full UPN for other configurations in Jamf.So i guess my question is does anyone else have iDP setup with Jamf and do you sync the full UPN and able to target users via EntraID groups? TIA.
I’m trying to implement Jamf Setup Manager. I have everything aligned regarding the configuration profile and the Jamf Setup Manager PKG assigned as an enrollment package. But the PKG won’t install. I’m not seeing any logging or the app in the Utilities folder after enrollment. Any suggestions would be appreciated.
Hi All, so i’ve had an issue for a few months, I’ve been trying to find the bash command line to turn on accessibility keyboard, so looking around in ventura this was easy to do and now the location has now changed, main thing is i don’t where. As i work in a school some teachers want on screen keyboard when they connect to the white boards, so i wanted to add an option in self service to deploy a shortcut to the keyboard
Startup Power is a macOS application built with SwiftUI that allows you to configure your MacBook’s automatic startup behavior.It directly modifies NVRAM variables (BootPreference for Apple Silicon, AutoBoot for Intel) to control these options.The app automatically adapts its behavior depending on your Mac type.If this can help the community, the application and the source code are available here:https://github.com/chrisbasse/Startup-Power
Hey Guys,I already talked to Jamf and got this issue escalated for me. You may want to check if this problem applies to you.I was trying to enable activation lock through a static and smart group via selecting the group>View>Action>send remote command>enable activation LockAfter talking to Jamf they are aware that it is not accurately reporting if the device has AL turned on in the inventory screen so I was checking with ASM. There I discovered AL was off. I tried it again the same way and the issue persisted. If I went to the device>Management>Activation Lock>Enable activation Lock it seems to send out the same command but does enable activation lock. To test it I did the same this again with the group command and the device turned it off and could not turn it back on with the same command. I had to go back to the specific device and turn it on again. My problem was with a small number of iPads so this wasn’t a huge issue for me, but if you manage lots of Macs and
Get ready to supercharge your scripting and automation expertise at Level Up JNUC 2025! Running Monday, October 6, the day before JNUC 2025 kicks off, this exclusive, in-person training is your chance to dive deep into hands-on learning with a Jamf instructor. From IF statements to APIs, loops to user interaction, you'll gain the practical skills needed to automate like a pro. Full-day training (9:00 a.m. – 5:00 p.m.) Lunch & refreshments included Hands-on scripting & automation challenges Digital badge, swag & bragging rights upon completion 📢 Limited spots available – secure yours for just $99! New to scripting? No worries! Check out the Bash Scripting Foundations and Bash Scripting Automation courses in the Jamf Online Training Catalog to prep. Don’t miss this opportunity to level up before JNUC 2025! 🔥 Register HERE now!
We have a bunch of machines that R7 is reporting the version.plist file in the safari.app container contains vulnerabilities. The app container is in the cryptexes folder and is listed as version 18.x. The machine itself is on macOS 15.6.1. I assume the container in question is in the reboot environment? I’m not sure how to fix this.When I try to remove the vulnerable plist file it comes back as operation not permitted. Can I even remove this file? Should I remove this file? Is this a matter of the recovery environment not being up to date? Looking for any insight I can get. Thank you in advance.
During post-release window for at least the last 4 minor macOS releases, our users have reported that the Mac only lets them unlock with password, not allowing their fingerprint.If the user restarts the device, then logs in, the fingerprint option for unlocking is available but, reverts to not being available shortly after. This behaviour appears when a new macOS update is released, then is only resolved once the device is updated.We’ve confirmed that the fingerprint is setup and works for other auth with the device unlocked - never seen this behaviour before, anyone else experiencing this?For reference, this has happened on at least;macOS 15.4 → 15.4.1 macOS 15.4.1 → 15.5 macOS 15.5 → 15.6 macOS 15.6 → 15.7
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!