Get Support
Recently active
Hi Jamf Nation, we are using conditional access policies in EntraID to prevent users from using private mobile devices to access our M365 Services. However I need to Exclude Microsoft Authenticator App from this Policy but im not able to select this app in CA Policy Config. I tried to use a filter for a device condition "device.mdmAppId -eq "4813382a-8fa7-425e-ab75-3b753aab3abb"" But i guess this attribute is not available to EntraID since Devices are not Intune but Jamf managed. In the Device Sign In Log im able to see the block based on the Application ID for Microsoft Authenticator. Do any of you have any ideas on how to do this?
Hi Everyone I'm wondering if anyone knows how I can prevent students from changing the colour of their apps? I have looked around in the profile settings but can't seem to find a setting to disable that function.
Hi We are just adding Jamf Connect using Cyberark; we are getting the following issue once the user has logged into the SSO client its double asking for the local password, would like to remove this. We have the setting set in the xml <key>OIDCUsePassthroughAuth</key> <true/> Does anyone have any other suggestions we can try? thanks.
Hi All, Our District is aiming to use Macbook Air for our next laptop refresh. We have Jamf Pro and on our way to get a subscription on Jamf Connect. Anyhow, when I created a script under Policies, the name is not changing. The naming convention that I wanted to use for all the M1's should be M1-"Serial Number". The script that I've created is below;#!/bin/bash$ sudo jamf setComputerName -name $M1-$serialNumberscutil --set ComputerName $M1-$serialNumberscutil --set LocalHostName $M1-$serialNumberscutil --set HostName $M1-$serialNumberexit Please help?Thank you and have a great one!Sincerely,Cesar
Seems like the root path of when the script is run automatically is different.I have changed the path resolution to this now - currentUser=$(stat -f%Su /dev/console) userHome=$(dscl . -read /Users/$currentUser NFSHomeDirectory | awk '{print $2}') Will this solve my issue since i am looking up for some specific files in each computer?I am trying to confirm if it works on automated runs since it does on the manual ones (jamf recon) - but how do i trigger the policy for all computers using the jamf dashboard?
Hello, we have configured an 802.1X network profile with a scep profile that generates a machine certificate per computer. When connecting to the network we are forced to select the certificate. Isn't there a way to make the selection automatic?
Anyone have a good way to deploy this? Yes, we know it isn't supported except for individual installs - but seriously, when you are a school district and have over 100 Mac Labs - you have to find a better way. Need a little help on this one - we keep getting the Message: Secure Browser may be running from the original file download location.Any help on this one would be appreciated!
Hello,I am having trouble setting up device compliance in Jamf Pro. I followed the instructions found here: https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Device_Compliance.html but when I got to the part where I was redirected to the Microsoft Intune webpage, nothing happened. The Microsoft login window appears; I enter my email address and am then brought back to Jamf Pro with a "Registration Request" error and another warning below that states it is "Establishing connection" with directions to "Open consent URL." I click on the open consent URL, get to the Microsft login window, enter my Azure email address, and am then brought back to the Jamf Pro screen with these same two messages. I have Azure GA rights and have tried two different browsers (Safari and Edge) with no success. Has anyone else come across this issue? I figured that I'd try here before submitting a ticket with Jamf. Here is the error and warning messages Registr
What to expect:• Apple will announce four new iPhones, including an ultra-thin model iPhone 17iPhone 17 AiriPhone 17 ProiPhone 17 Pro MaxApple Watch Series 11Apple Watch Ultra 3https://www.apple.com
We have a script to disable the macOS randomization, it’s been working prior to macOS 15.6. Since 15.6 it has not worked, it also does not work on the beta of Tahoe. The script would hard code the MAC randomization to OFF, and set the default for all new networks to “NOT SET” which then becomes “OFF”.Has anyone else experienced issues with MAC randomization on 15.6 or the Tahoe beta?
Is there a way to get set up a search to show any user without a device (iPad) assigned to them? I am trying to clean out our user database.
Hello,We are evaluating ways to enhance our IT support workflows and are particularly interested in leveraging customer support automation software alongside Jamf Pro. Our goal is to streamline tasks such as ticket creation, device status updates, and end-user communication without compromising service quality.Has anyone successfully implemented such integrations within a Jamf-managed environment? What challenges did you encounter and what measurable benefits such as efficiency gains or improved user satisfaction did you observe?Any recommendations for best practices or compatible tools would be greatly appreciated.
I have several iPads that need unenrolled from our Jamf Pro MDM. Unfortunately, they have expired device identity certificates and recently expired signing certificates. Is there an efficient way to simply unenroll them? I’m a novice at this, so please ask me the necessary questions.
Sometimes when an app or profile is scoped to devices, they get stuck in a pending status indefinitely, but a blank push command will "wake up" the process and it will complete. I'd like a way to send a blank push to all devices if a major profile or app gets deployed to speed up distribution.I can pull up a smart group of managed devices, go into the action menu and send commands to the group, but sending a blank push is not an option as a remote command using this method. And I'm not interested in doing it on an individual device basis from the management menu.Is there a way to send a blank push remote command to all devices or a group of devices?Thanks,Rob
Hello world. Mike here. I wanted to let you know that MUT v6.2.0 was released today! The biggest change you're probably excited for is that MUT now uses bearer tokens for all authentication of all API calls, which means it is fully ready for the deprecation of Basic Auth for the Classic API. There's also a new settings menu. You can access it from MUT > Settings. All existing settings (Allow untrusted SSL, delimiter selection, etc.) have moved to this new menu, and you'll notice a few new options as well. Of note, there is now an option to select a log level, so you can cut down on the chatter and only get errors if you're looking to troubleshoot an issue. Additionally, credentials are now stored in Keychain by default, as opposed to user defaults that they were stored in before. If you'd rather use the legacy method, it's available in the new settings menu--but know that (as always) password storage is not available in user defaults. If you choose to store credentials
I have one user who cannot log in through the LDAPS login at initial setup. No other user has this issue. Their username can be queried through the LDAPS search test and each field populates correctly. They have no issues with other platforms that use LDAPS. I have changed their password and it has made no difference. Are there restrictions that can be placed on a user that I am missing?
We've got a profile that blocks the social media category on iPads as per school policy. However, on some devices (not all) it's blocking Duolingo and Picsart as well. Duolingo is categorised as Education and Picsart Photo & Video. There's no other restrictions blocking apps.I've tried removing the user from Jamf and resyncing with ASM/reassigning to the device but it didn't work.Has anyone else seen this?
Having a strange issue with JAMF Connect computers. We use Google SSO at the login in screen and it works normally, however, when the user logs out you are not able to click in the email box to sign in again. A restart will fix it but wondering if anyone has seen this.
Hello jamfnation, I have a question. I try to rename some user accounts to match the company pattern. We want to do this process as smooth as possible for the user and admins. Therefore I've written a script which checks values and asks the user several questions which in the end creates a plist with some variables. After that the script reboots the computer and uses Rich Troutons "First Boot Package Install" (script almost completely rewritten) to show a log to the user what is happening. At that window the script, which is started by a LaunchDaemon, uses dscl to change the homefolder, uses mv to move the homefolder and again uses dscl to change the username. Now my problem:In order for dscl or mv to be able to change the homefolder it needs access to it (PPPC). My script is signed and stays signed, and a PPPCP is in place to allow for my script to access Admin Files and/or All Files. I also tried the unsecure way and allowed /bin/bash access to AdminFiles/AllFiles.However it is not
We are trying to figure out why most of our Macs updated to macOS 15.6.1 after I used Software Update in Jamf Pro to enforce getting Macs updated to macOS 15.6. When I set the update to go out, I specifically selected 15.6, not 15.6.1. I always check a few Macs in the group I selected to update to verify that they received the correct scheduled update. I confirmed that they had received the scheduled update for 15.6. Right after pushing out another update command, I saw that my own Mac already runnning 15.6 displayed an alert that it would update to 15.6.1 at the scheduled time. We have a profile installed that defers updates for 21 days. I confirmed that it is working using Macs not yet updated to 15.6. They all show 15.6 in Software Update. Macs running 15.6 do not show updates available. I wonder if the enforced update is responsible for this. I was very careful to specifially select 15.6 as the update we wanted to run. Has anyone else seen this behavior?
We upgraded some of our iPads to ios 7 and are unable to disable iMessage and Game Center. We do not use Apple Configurator as we are a Windows school. The iMessage option IS disabled in the restrictions for this profile group but still shows up on the individual iPads. We deleted the profiles on the iPad and it still came back.
Jamf is showing as disconnected after changing the user group membership (Version 11.19.1-t1754574720728).We are getting the following alert:"Exception_Group is actively targeted in the scope of the objects listed below. Changes to this group membership may require more time to deploy than usual due to the increased network traffic associated with redeploying certain content. Jamf Pro may be unusable or unstable during this time."After this message, if we save the assignment changes, the user device gets disconnected and does not accept any sudo commands.
Did someone have the problem logging in from a computer and this window appear? Some computers on our system do throw this if our trainees are trying to log in. They are on the same network as other devices and this appears on multiple browsers.
Hi, I’m trying to manage our recurring license limit in Jamf School since we’ve just renewed a couple days ago. I’ve already released the devices from our organization and they don’t even show up in the Inventory > Devices menu anymore. When I select them under the License Assignment menu, I only get the option to “Assign a Perpetual License” and there’s no option to remove a recurring license: Thank you in advance.
To prevent user from syncing Chrome data with their personal google account, a custom setting for Google Chrome can be set and deployed by Jamf Pro. Preference Domain: com.google.ChromePlist file content: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>RestrictSigninToPattern</key> <string>(?:.*@domain1.com|.*@domain2.com)</string> </dict> </plist> let's check the managed chrome policy status and the sync result.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!