Get Support
Recently active
Hi,I noticed that rather many of my Mac clients are not FileVault encrypted even though I have configured a configuration that should take care of that. Now I wanted to ask what is the best practice to enable FileVault on all my Macs. As far as I know there is an option to enable it via Policy and one via Configuration Profiles. What is the difference there and what is recommended?
Hi , I tried all the topics on jamf and internet , but didn’t work , and it seems there is a missed step related to PList i think. the steps i did are as per below:1- from computers , select configuration profiles , add new2- scope = add computer you want, level is computer level.3- Application & custom Settings : add External Application and name it, application domain is com.microsoft.Egde , Edit Schema and add the JSON as below [ { "toplevel_name": "Managed Favourites" }, { "url": " https://keepersecurity.eu/vault/ ", "name": "Keeper" }]that didn’t take effect , but it has been applied according to JAMF logs.there is something missed ,specially i noticed the Plist preview didn’t change with JSON added as above
End User Experience Reference: https://learn.microsoft.com/en-us/mem/intune/configuration/use-enterprise-sso-plug-in-macos-with-intune?tabs=prereq-jamf-pro%2Ccreate-profile-jamf-pro#end-user-experience Secure Enclave After the configuration profile for PSSOe and the companion application for PSSOe are installed on the device, macOS will prompt the user to register. The message can be customized with the configuration profile value of “Display Account Name”. In this example, the Display Account Name was set to “Jamfse.io Entra ID”. The user is then prompted for their local macOS UNIX account password. This is used to determine the user is present and actively using the device. The next step requires the user enter a strong credential like a security key or Passkey enabled on another device. Other methods also include push with number challenge. Upon completion, the user is shown instructions to set up the device as a Passkey provider for
Posting this for anyone that works with an organization that wants to disable Microsoft AutoUpdate with a Jamf Pro configuration profile. Preference Domain: com.microsoft.autoupdate2 <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>ChannelName</key> <string>Custom</string> <key>EnableCheckForUpdatesButton</key> <false/> <key>HowToCheck</key> <string>Manual</string> <key>StartDaemonOnAppLaunch</key> <false/> </dict> </plist>
Any ideas what causing this issue, ive checked ABM and each app got enough licences so not sure what causing it.
Hello,I've enrolled new iPads in Jamf Pro. They are correctly configuring them. However, when downloading the apps, we get the following message: kCFErrorDomainCFNetwork error -1202.Any idea why this error is occurring?Possibly some pending configuration? Syncing between ABM works correctly and has available licenses for the app. The iPad is also connected to an unblocked network.
We have a smaller environment and some flexibility on our update schedule. There is an MDM profile we push out with a software update payload where everything is checked except “Restrict software updates to administrator users only”. It has been like this for years and usually it means after a few weeks some folks have updated and others need a little reminder. The recent 15.5 to 15.6 update appears to be different for us. This time it pushed out to everyone on either 8/5 or 8/6. Has anyone noticed a change in how the built-in software update runs in Sequoia with that kind of set it and forget it MDM payload? There are only 10 computers running Sequoia in our environment with another few dozen running a mixture of Sonoma and Ventura, so it might be sampling/anecdotal. The other releases are in their usual state of lag two weeks after the update and all of them are using the same payload. This all came to attention because the one Sequoia user who hadn’t updated reached out complaining
We've recently updated our Dev Jamf instance to 11.5, introducing the new DDM functionality, known as the BluePrint. I'm particularly interested in Password Policy and its implementation. Currently, we deploy the passcode policy via a Configuration profile, installing it during the Prestage to ensure that restrictions are applied during the initial account creation. I'm seeking insights on how to ensure that the Blueprint passcode policy is applied during the prestage. Any hints or tips on this would be greatly appreciated.
Hello,With the new version of Jamf Connect 2.45, I noticed an issue with the login window.The login banner takes up the full width of the screen.Is there a way to reduce it to the size of the EntraID login window?
Hi Team, Can you provide detailed steps to configure in jamf Pro in terms of configuration profile and also for Policy since Rapid7 agent install is not working on Mac & intel chips? https://docs.rapid7.com/insight-agent/mac-installation/
is anyone familiar with the incident ID: DD02DC66 while using company portal to enroll into intune
Hello everyone, For some time now, we have been going over all of our Apple TVs (ATV 4 and 4K) and making sure they are included in Jamf. We manage to add many devices with Apple Confiurator (those with USB-C) via Apple School Manager, while some do not. For those that do not succeed, we order DEP for them through our supplier. Once DEP is activated against Jamf and we reset them and restart them, the activation problem occurs.Does anyone know why this happens and if there is a way to solve it?Ordering new Apple TVs with DEP works immediately.
We got an email advising us to update our IP Addresses by August 20th, but the last change in the changelog is dated July 31, 2025Are the dates in the changelog referring to the date when the changes are announced or the date when they are live? If the latter, where can I find the changes done for August 20?
We’ve recently noticed that some new devices enrolled via Prestage are showing the unenrollment option in the MDM profile on Sequoia OS. I reached out to the Jamf Support team, but unfortunately, I didn’t receive a satisfactory response. They did share the article linked below, but I don’t believe this was the case previously. In our environment, we add devices to ABM using Apple Configurator and then assign the server for Prestage enrollment. I’m looking for a better understanding of this issue from the group. https://support.apple.com/en-gb/guide/apple-business-manager/axm200a54d59/web
Hi Everyone, Just curious if anyone else has found a solution to this issue below. In our environment, we have 89 users on MacBook Pros enrolled in JAMF Pro and bound to Active Directory (AD). Our password policy requires users to change their AD passwords every 90 days. However, after users change their passwords, their secure tokens appear to become corrupted, and the Mac no longer accepts their new passwords. The only workaround we’ve found is to disable and re-enable the secure token via Terminal, which resolves the issue temporarily. We’d like to prevent this from happening in the first place.
Hello, I am trying to figure out what the API call is to update a computer group with the “Patch Reporting Software Title” Criteria. a scripting beginner trying to automatically update a bunch of smart groups and for our Patching.the way we patch has us manually updating a bunch of smart groups to handle what applications need to be updated. we are not in a space to auto update with app installers so we have to manually (installomator/autopgk) apps for deployment.
Up until last week we had our device prestages set up to prompt to update to the latest iOS based on device eligibility. Sometime last week this no longer works. Not sure if trying to update via the new software update tool has the same issue. Dealing with the chatbot to try and submit a ticket is an extreme effort in frustration!!!!!!!
Went to the support portal to enter a ticket and has a link at the top to go to the new support portal which turns out to just be an AI chat bot. While its good for Jamf to have an AI chatbot try and “screen” support questions, I am wondering how well this will work out. The AI bot did not really have an answer to my question so I asked it to create a ticket and it said the team would email me back.I hope there is a way to track these support requests like you could with the old ticketing system. It can be important to have a ticket number.
Hi there. We’re looking at moving to PSSO, where we currently have Jamf Device Compliance on prod Macs, but have run into a wall.MDM=Jamf, IdP=Entra ID, PSSO profile uses Secure Enclave Key as the auth method because we have Jamf Connect managing accounts and password sync and understand that they can be complementary.On new builds when we deploy the PSSO profile before registering with Intune/Company Portal/Entra ID via our normal Jamf-driven Device Compliance workflow, it registers cleanly, works as expected, and CA permits access to protected data and apps, so it’s successfully replacing Device Compliance.On prod devices already registered with Device Compliance, with Entra ID device records, WPJ keys in keychain and the rest, when we deploy PSSO after, it initiates the registration, accepts the user credentials, creates a duplicate stub record in Entra ID, but at the last step where it would require MFA and then pop up the dialog prompting to allow CP Passkeys in System Settings, i
I’m slowly rolling out Jamf Connect 3.1 and probably Jamf Connect 3.2 with Self Service+ app (since the change was made).Has anyone used Passkeys or hardware keys (think Yubikey) with the new flow? Any issues? 3.1.0 (2025-07-07)Resolved Issues [PI131938] Fixed: For configurations using Microsoft Entra ID as their identity provider, the Jamf Connect login window displays an error message at the bottom of the screen when passkeys are an available authentication method. We do use Entra ID as our Idp. I know older versions of Jamf Connect pre 3.xx did not work.i’ll be doing some testing on my end soon. I was just curious if anybody had tried it yet.Thanks.
Hello, I have a user iPad who is not communication with jamf pro. All commands get stuck in pending or failed. I looked at the Device Management and saw that the SCEP Device Identity certificate is expired. How do I renew? Thanks
Hello,I am a ServiceNow developer and working with our internal JAMF team member. We have integrated the two with the out-of-the-box connector. The data is coming into ServiceNow, but we have noticed an issue on the JAMF side.In the User and Location area, it is not populating even though the SME says it is mapped and setup properly. It is linked to Active Directory but seems to not be populating this area though it seems to have everything that is needed. Any idea what might not be setup or mapped that could explain this area not getting populated? It is impacting our Hardware and Software asset processes. Any thoughts or suggestions would be appreciated.Thanks.
In this scenario, which would you use? • You're starting a new company in 2025 • Fresh Jamf Pro build • Fresh Apple Business Manager Do you use DEP Notify, Jamf Setup Manager, or something else? https://www.jamf.com/blog/apple-device-enrollment-jamf-setup-manager/
Hi there,How are you guys handling time zone/region changes for end users with standard user level privileges, I’ve tried with Self Service scripts but I’ve not found any that work consistently.Are there any Sequoia solutions to this issue?
Greetings everyone!I am working with the Jamf Pro API and cannot for the life of me figure out how to obtain a list of every title which is available in the Jamf App Catalog, even if I am not currently deploying it.I have experimented with several existing endpoints including /api/v2/patch-software-title-configurations, but only ever seem to get titles which are currently being deployed or patched.What I am trying to get is the FULL list of apps which would be present in Computers → MacApps → Jamf App Catalog → New → Jamf App Catalog, which (as of this posting) lists 265 titles.In Context, I am creating a Python script to acquire, analyse, normalize and update data which resides across a number of data sets (Excel, SQL etc). When we are deploying a new app, I effectively want to know if that title is available in the Jamf App Catalog.If someone could point me to the correct Classic or Jamf Pro API endpoint, it would be much appreciated! Thank you all in advance!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!