Get Support
Recently active
Is anyone else experiencing issues with the "Lock Desktop Picture" configuration with MacOS 15? I recently updated our fleet from 14 to 15.5 and it seems to have broken our branded desktop picture. Not only has it reset the wallpaper to the default, but it has also broken the functionality setting. I am also open to just making a policy that sets and locks the desktop if that is a better process.
Hi, I want to get backup of my data from the Gmail accoubts. I want any safe and fast tool which can proviode me accurate results.If anyone has the solution for my problem, please share.
Hi, I am managing a fleet of iMacs and MacBooks. I have disabled the “Accessibilty System Preference” panel in JAMF school profile but how can I disable it totally in order users cannot activate it using keyboard?Thank you
We recently ran workspace update 2025.05.10 and had a handul of devices that it installed but wouldn’t open. After a day all but one started working. We have one where it won’t open on the latest version, if you remove and put the old version it works. We tried running it different ways using the open -a command, but each time it said it couldn’t be found. If you boot in to safe mode, it opens. The tech ran the uninstaller and checked all the locations to make sure there wasn’t any residual files leftover. They checked to see if there were any login items that would be causing issues.
HiI’ve made a config profile on jamf pro to lock the screen after 5 minutes of inactivity, just a simple policy, nothing specialBut I had left the Log out users after 30 minutes ticked. I’ve now disabled that, and completely remade the config profile itselfBut the 30 minute log out is still enabled on the macs What am I doing wrong here? Is that even the right place I should be looking?Thanks
• iOS 18.6.1• watchOS 11.6.1 https://support.apple.com/en-us/100100
Today we released Jamf Connect 3.0.0. This release includes the following changes and improvements: Upcoming Changes to Jamf ConnectJamf Connect 3.0.0 continues to include the following login window capabilities and direct support for Jamf Connect Configuration:-Desktop multifactor authentication-macOS account provisioning Deprecation of Jamf Connect Menu Bar App CapabilitiesThe Jamf Connect menu bar app is now deprecated and will no longer receive updates. All menu bar app capabilities from Jamf Connect 2.45 and earlier will be unaffected by this deprecation. Future updates to the Jamf Connect menu bar app will be limited to macOS compatibility and security updates.Note: For customers deploying Jamf Connect with Jamf School, Jamf recommends to continue using version 2.45.1 instead of updating to version 3.0.0. This will preserve the existing menu bar capabilities for Jamf Connect and not affect existing deployments.No immediate action or migration efforts are necessary; however, Jam
Is there an issue in Jamf Cloud online currently.I added a new app from Apple School Manager this morning and it still has not arrived in Jamf Cloud for availability. I have double checked my VPP token, even downloaded and assigned a fresh one just to make sure it was not expired. I tested the same app by assigning a few licenses to Intune and they showed up within a few seconds in Intune. Not sure what else to check, I also forced a sync from Apple education support in Jamf Cloud.Earlier this morning I was unable to get apps deploying to new iPads that were already assigned in Jamf Cloud, it gave the error: “Pending - All licenses are in use or the license is not assigned yet” and took over an hour before they finally installed.
HelloWe have just completed MAC enrollment to JAMF with pre existing mobile users being converted to STD users after enrollment. We use entra for jamf connect. We have a SAN that users access to R/W data. If another user logs into the mac (creates std account) he cannot access the san b/c his GID/UID is not what the san expects. He can read but not write. Our workaround is to wipe the mac, delete from jamf, create the mobile account then enroll into jamf and that user is good. Anyone have a similar issue? Ideas to fix?
HelloI'm early in my JAMF API & Swift learning curve. I have worked through the wonderful Swift/JAMF API tutorial at:Part 2: https://www.jamf.com/blog/mac-admin-swift-jamf-pro-api-decoding-data-objects/and I am now attempting to expand the reported data pulled from the JSON. I have no problem pulling additional data returned from decoder.decode that is at the root level of general (for instance) such as id, name, ip_address etc. but I haven't been able to figure out how decoder.decode captures the remote_management data that goes a level deeper.Any suggestions would be greatly appreciated!Thanks!William JacobsonAutoclub, Costa MesaExample on how the data is decoded and referenced:guard let result = try? decoder.decode(ComputerResults.self, from: data) else { exit(1) } for computer in result.results { print(computer.id, computer.general.name, computer.operatingSystem.version, computer.hardware.model) } }Relevant part of the
Does anybody use a similar workflow for renewing SCEP certificates and or is this supported? Specifically adding $PROFILE_IDENTIFIER to an additional x509 attribute. Appreciate your insight!
Did the mission of Jamf Nation change with the recent update? The recent activity feed is full of volunteer stuff, did I miss a memo somewhere?
As I'm writing articles, I'll update this page with the latest articles: Updated 23SEPT2024 What is Platform Single Sign-On - An overview of the technology and how it works https://community.jamf.com/t5/jamf-pro/what-is-platform-single-sign-on/td-p/320251 Configure PSSOe for Microsoft Entra ID Jamf Technical Guide: https://learn.jamf.com/en-US/bundle/technical-articles/page/Platform_SSO_for_Microsoft_Entra_ID.html Sean's first draft guide: https://community.jamf.com/t5/jamf-pro/configure-platform-single-sign-on-pssoe-for-microsoft-entra-id/td-p/320252 Configure Kerberos SSO with Microsoft Entra PSSO - https://community.jamf.com/t5/jamf-pro/configure-kerberos-sso-for-microsoft-entra-platform-single-sign/m-p/323781#M278609 Some sample .mobileconfig files for you to modify - https://github.com/sean-rabbitt/jnuc-2024 Configure PSSOe for Okta Identity Engine https://community.jamf.com/t5/jamf-pro/configure-platform-single-sign-on-for-okta-identity-engine-with/m-p/3204
#!/bin/bash#Determine PSSO status of current console user logged in at time of recon#Get current user logged in to devicecurrentUser=$( /usr/sbin/scutil <<< "show State:/Users/ConsoleUser" | /usr/bin/awk -F': ' '/[[:space:]]+Name[[:space:]]:/ { if ( $2 != "loginwindow" ) { print $2 }}' )#Read local user directory record to see if AltSecurityIdentities attribute has been added by macOSpssoe_status=$(dscl . read /Users/$currentUser dsAttrTypeStandard:AltSecurityIdentities | awk -F'SSO:' '/PlatformSSO/ {print $2}')if [[ -z $pssoe_status ]]; then echo "<result>No PSSOe registration found</result>"else echo "<result>Yes Entra ID account $pssoe_status registered to $currentUser</result>"fi
Many of our sports teams use Hudl to view past games. We would like them to be able to watch the videos, but not during instructional time. I know that you can block certain sites, but there are no time limits available. I am not a script writer, so is there a way for us to do this? Thank you!
Is there any chance we could get a notification when the Compliance baselines get an update? I find myself checking everyday and it would be nice if that could be added to the notifications areahttps://ideas.jamf.com/ideas/JPRO-I-1572
Last year, when I was working on getting moved over to using LAPS instead of using an admin account that we installed using a Jamf Policy, some of my support team members discovered that the password for the Jamf management framework LAPS account was not working on several Macs. We could see in the managed local administrator account history that the password was being rotated on the schedule we set. So, why was the password not working? I recently discovered that the reason for this is that these Macs had been re-enrolled in Jamf Pro for some reason, likely using "sudo profiles renew -type enrollment". This appears to have broken the ability for Jamf Pro to change the account password on the Mac. I tested this idea on my test Mac. I checked the password, saved it, then re-enrolled the Mac. I waited the period of time we have set for rotation. I checked the password in Jamf Pro again, and found that a new password was recorded. I tried that new password on the Mac with the LAPS account
Jamf Nation was created to promote growth and success in the community that supports Apple in the enterprise. It’s a place to share ideas and information and learn from each other. We want Jamf Nation to be a community that is a welcoming, engaging, respectful and useful space for all. With that goal in mind, please remember the following Community Guidelines (“Guidelines”) when posting in Jamf Nation. Getting Started There is no obligation to post on Jamf Nation, and contributions are voluntary. If you want to post messages, comments, images, content and other materials ("User Content") on Jamf Nation, you will need to create an account. Do not use an inappropriate or misleading name, and don’t try to impersonate someone else with your username. Keep your account details secure and don’t share them with other users. Content Rules Jamf Nation is meant to be an engaging and educational space. Before posting, ask yourself if your post contributes to t
Hello there, maybe someone has an idea for solving this issue. We have started to enroll MacBooks to employees without admin rights. We was using first the visual studio code installer from jamf mac apps. The problem with this, is that i cant add some configuratio (for example creating a symlink for this app) within the jamf mac app installer config. So at the moment i am using a normal policy with a pkg for vscode. Everything until here is working fine. When an update is released for vscode, the user (without admin right) can't install it. The first window which pops up is for the helper tool (updater) for visual studio code So i was searching for a solution and found this page here, which explains this problem: https://github.com/microsoft/vscode/issues/115805 I am able to do all this changes for the group and ownership for the logged in user but the problem still persist. My script #!/bin/bash set -x # Get the current user's home directory loggedInUser=$(stat -f "%Su" /
Grace and peace to all,We currently have Sel-Service+ enabled in our QA environment. It is blocking access to corporate resources when the Mac is connected to a VPN. We use Zscaler. I cannot find any documentation on Sel-Service+ configuration. It is using our JAMF Connect license and profile. Do we need to register Self-Service+ as an application in Entra?
I need to force install a Chrome Extension.I have looked in Jamf Nation for solution but latest ones were in 2017 and they currently do not work (from my testing).Has anyone got them to work with Monterey?
I'm integrating with JAMF MDM to get mobile devices. I have a standard JAMF pro user created and assigned Auditor privileges(grant all read). I'm able to get device info with the following info under the security object."security": { "dataProtected": , "blockLevelEncryptionCapable": true, "fileLevelEncryptionCapable": true, "passcodePresent": true, "passcodeCompliant": true, "passcodeCompliantWithProfile": true, "hardwareEncryption": , "activationLockEnabled": true, "jailBreakDetected": false },I have to capture the compliance info as well when I try to access compliance info using the following API callBaseURL/api/v2/conditional-access/device-compliance-information/mobile/{deviceid}it is showing null results. Please advise how can get the compliance status of the device. Do I need to get more privileges or can we capture from a security object?Thanks.mythdhr
Hello everyone,Some time ago we’ve moved from eDirectory to Entra and everything has just been work great. But yesterday I stumbled on a problem, error with calculating profiles in scope and same with apps.Has anybody else run into this?
Hi,I have a question haw can I setup on managed device via Jamf Pro (and Protect) configuration that restrict local account from some features, apps, internet, usb mount but on another account - admin account user can use all this features. Local restricted account enroled by Jamf, admin account added after enrolment manually. When the device will be login to the local restricted account should lost the connection with the internet, block some sharing features like bluetooth, airdrop, blok mount external usb devices/disks, block apps not needed or give only 2-3 apps what is needed. Tried wit configuration profiles with Restriction but working with all local account, trying some script on login but not working as it should. Could be a workaround solution…. but to get secure when restricted user use the device. Please give me some advice. Thanks!
Hi everyone,Apparently there is a loophole to leak data according to our cybersecurity team on the MacOS Outlook client using the “Share to Teams” feature I am trying to disable the function for “Share to Teams” via a configuration profile on JAMF with the following configurationsApplication & Custom Settings > UploadPreference Domain: com.microsoft.OutlookPLIST:<plist version="1.0"><dict> <key>com.microsoft.Outlook</key> <dict> <key>DisableShareToTeams</key> <true/> </dict></dict></plist>I am wondering if anyone have any insights about thisThanks in advance!!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!