Get Support
Recently active
Disabling an Existing Local Account for FileVaultLog in to the JSS with a web browser.Click Computers at the top of the page.Click Policies.On a smartphone, this option is in the pop-up menu.Click New images/download/thumbnails/5832871/New_icon.png .In the General payload, enter a display name for the policy. For example, “Disable Local Account for FileVault“.images/download/attachments/12979842/DEC_Policy.pngSelect a trigger and execution frequency.Select the Local Accounts payload and click Configure.Choose “Disable User for FileVault 2” from the Action pop-up menu.images/download/attachments/12979842/LocalAccounts_DisableforFV2.pngEnter the username of the user you want to disable for FileVault.(Optional) Select the Maintenance payload and then select the Update Inventory checkbox so that the FileVault-enabled status for the local account is updated in inventory immediately when the policy runs.Click the Scope tab and configure the scope of the policy.Note: If applicable, you can us
Hi everyone, I have an JAMF managed I-pad that we use for testing. I need to connect it to my Macbook pro to run debugging. When I connect it to the Macbook the Ipad does not show the Trust this computer pop up. Is there anything I can do to be able to see this alert in JAMF?
Hello everyone,With the release of macOS Sequoia, I’ve run into an issue with our podium iMacs that are connected to projectors. By default, they no longer mirror the display to the projector screen, even when using scripts or third-party tools from GitHub.Currently, I have to manually adjust the display settings to enable mirroring for each instructor who logs in.Has anyone encountered this and found a reliable solution or workaround?Thank you in advance for any suggestions!
I’m getting Jamf Self Service error loading content when accessing self-service to download apps.
If you haven’t read part 1, then click here and go back and read it. The next portion of Apple Intelligence is now shipping with macOS 15.2 and iOS/iPadOS 18.2. We now have Image Wand, Image Playground, Genmojis, ChatGPT integration, and a little more. To soothe all concerns quickly, Apple Intelligence is NOT powered by ChatGPT. It will never send data off to ChatGPT without first asking permission and that integration must also be enabled. Ok, now that that’s out of the way.Apple Intelligence now features image playground, Genmoji and moreWhat’s great is that all of these features have a way to be blocked. Apple has provided the following configuration profile keys for the preference domain com.apple.applicationaccessallowImagePlayground allowImageWand allowGenmojiAnd new as of Dot 2 releaseallowExternalIntelligenceIntegrations allowExternalIntelligenceIntegrationsSignInThe two new keys, as of the Dot 2 releases, must be deployed on the Dot 2 releases and higher versions. They may not
Name and information link Available for Release date iOS 18.6.2 and iPadOS 18.6.2 iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later 20 Aug 2025 iPadOS 17.7.10 iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation 20 Aug 2025 macOS Sequoia 15.6.1 macOS Sequoia 20 Aug 2025 macOS Sonoma 14.7.8 macOS Sonoma 20 Aug 2025 macOS Ventura 13.7.8 macOS Ventura 20 Aug 2025 CVE patched ...https://support.apple.com/en-us/100100
Outlook Search is Broken Problem: When you search in Outlook, you get "No Results," even when you know the email is there. Solution: Force the Mac to rebuild its search index for Outlook. Quit Outlook . Go to System Settings and navigate to Siri & Spotlight . Click the Spotlight Privacy button. In a new Finder window, click Go → Go to Folder, from the menu bar. Paste this path and press Enter: ~/Library/Group Containers/UBF8T346G9.Office/Outlook/Outlook 15 Profiles Drag the "Outlook 15 Profiles" folder into the Spotlight Privacy list. Wait about a minute, then click on the folder you just added and click the minus button to remove it. Mac will start re-indexing in the background. It might take a few hours, but search will work again when it's done. Mac is Slow After Update Problem: Mac feels sluggish and shows the spinning beachball a lot after updating to Sequoia Solution: This is often temporary. Here are the main things to check. Wait it Out: Af
I recently had to rebuild a device because it would not install any updates, so I started from scratch. I got Sequoia installed and when I attempted to use Jamf.OUR.COMPANY/enroll, it did not download the normal MDM & CA profiles, but the QuickAdd.pkg. Even with enabling all pkgs via “sudo spctl --master-disable” and “-allowUntrusted” when using “sudo installer” the package still continues to fail because it is untrusted. Is there any way to manually download the MDM & CA from jamf pro since the /enroll will not download it? Or just another workaround in general? Thank you!~G
We recently implemented Content Filtering and saw that the “Clear All” button for safari is now disabled. In providing support to our users, we often tell them to clear their cookies and cache when they are having issues loading a website. Now that content filtering is enabled, this is no longer an option.How have you overcome this? Any recommendations?
Hi,I noticed that rather many of my Mac clients are not FileVault encrypted even though I have configured a configuration that should take care of that. Now I wanted to ask what is the best practice to enable FileVault on all my Macs. As far as I know there is an option to enable it via Policy and one via Configuration Profiles. What is the difference there and what is recommended?
Hi , I tried all the topics on jamf and internet , but didn’t work , and it seems there is a missed step related to PList i think. the steps i did are as per below:1- from computers , select configuration profiles , add new2- scope = add computer you want, level is computer level.3- Application & custom Settings : add External Application and name it, application domain is com.microsoft.Egde , Edit Schema and add the JSON as below [ { "toplevel_name": "Managed Favourites" }, { "url": " https://keepersecurity.eu/vault/ ", "name": "Keeper" }]that didn’t take effect , but it has been applied according to JAMF logs.there is something missed ,specially i noticed the Plist preview didn’t change with JSON added as above
End User Experience Reference: https://learn.microsoft.com/en-us/mem/intune/configuration/use-enterprise-sso-plug-in-macos-with-intune?tabs=prereq-jamf-pro%2Ccreate-profile-jamf-pro#end-user-experience Secure Enclave After the configuration profile for PSSOe and the companion application for PSSOe are installed on the device, macOS will prompt the user to register. The message can be customized with the configuration profile value of “Display Account Name”. In this example, the Display Account Name was set to “Jamfse.io Entra ID”. The user is then prompted for their local macOS UNIX account password. This is used to determine the user is present and actively using the device. The next step requires the user enter a strong credential like a security key or Passkey enabled on another device. Other methods also include push with number challenge. Upon completion, the user is shown instructions to set up the device as a Passkey provider for
Posting this for anyone that works with an organization that wants to disable Microsoft AutoUpdate with a Jamf Pro configuration profile. Preference Domain: com.microsoft.autoupdate2 <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>ChannelName</key> <string>Custom</string> <key>EnableCheckForUpdatesButton</key> <false/> <key>HowToCheck</key> <string>Manual</string> <key>StartDaemonOnAppLaunch</key> <false/> </dict> </plist>
Any ideas what causing this issue, ive checked ABM and each app got enough licences so not sure what causing it.
Hello,I've enrolled new iPads in Jamf Pro. They are correctly configuring them. However, when downloading the apps, we get the following message: kCFErrorDomainCFNetwork error -1202.Any idea why this error is occurring?Possibly some pending configuration? Syncing between ABM works correctly and has available licenses for the app. The iPad is also connected to an unblocked network.
We have a smaller environment and some flexibility on our update schedule. There is an MDM profile we push out with a software update payload where everything is checked except “Restrict software updates to administrator users only”. It has been like this for years and usually it means after a few weeks some folks have updated and others need a little reminder. The recent 15.5 to 15.6 update appears to be different for us. This time it pushed out to everyone on either 8/5 or 8/6. Has anyone noticed a change in how the built-in software update runs in Sequoia with that kind of set it and forget it MDM payload? There are only 10 computers running Sequoia in our environment with another few dozen running a mixture of Sonoma and Ventura, so it might be sampling/anecdotal. The other releases are in their usual state of lag two weeks after the update and all of them are using the same payload. This all came to attention because the one Sequoia user who hadn’t updated reached out complaining
We've recently updated our Dev Jamf instance to 11.5, introducing the new DDM functionality, known as the BluePrint. I'm particularly interested in Password Policy and its implementation. Currently, we deploy the passcode policy via a Configuration profile, installing it during the Prestage to ensure that restrictions are applied during the initial account creation. I'm seeking insights on how to ensure that the Blueprint passcode policy is applied during the prestage. Any hints or tips on this would be greatly appreciated.
Hello,With the new version of Jamf Connect 2.45, I noticed an issue with the login window.The login banner takes up the full width of the screen.Is there a way to reduce it to the size of the EntraID login window?
Hi Team, Can you provide detailed steps to configure in jamf Pro in terms of configuration profile and also for Policy since Rapid7 agent install is not working on Mac & intel chips? https://docs.rapid7.com/insight-agent/mac-installation/
is anyone familiar with the incident ID: DD02DC66 while using company portal to enroll into intune
Hello everyone, For some time now, we have been going over all of our Apple TVs (ATV 4 and 4K) and making sure they are included in Jamf. We manage to add many devices with Apple Confiurator (those with USB-C) via Apple School Manager, while some do not. For those that do not succeed, we order DEP for them through our supplier. Once DEP is activated against Jamf and we reset them and restart them, the activation problem occurs.Does anyone know why this happens and if there is a way to solve it?Ordering new Apple TVs with DEP works immediately.
We got an email advising us to update our IP Addresses by August 20th, but the last change in the changelog is dated July 31, 2025Are the dates in the changelog referring to the date when the changes are announced or the date when they are live? If the latter, where can I find the changes done for August 20?
We’ve recently noticed that some new devices enrolled via Prestage are showing the unenrollment option in the MDM profile on Sequoia OS. I reached out to the Jamf Support team, but unfortunately, I didn’t receive a satisfactory response. They did share the article linked below, but I don’t believe this was the case previously. In our environment, we add devices to ABM using Apple Configurator and then assign the server for Prestage enrollment. I’m looking for a better understanding of this issue from the group. https://support.apple.com/en-gb/guide/apple-business-manager/axm200a54d59/web
Hi Everyone, Just curious if anyone else has found a solution to this issue below. In our environment, we have 89 users on MacBook Pros enrolled in JAMF Pro and bound to Active Directory (AD). Our password policy requires users to change their AD passwords every 90 days. However, after users change their passwords, their secure tokens appear to become corrupted, and the Mac no longer accepts their new passwords. The only workaround we’ve found is to disable and re-enable the secure token via Terminal, which resolves the issue temporarily. We’d like to prevent this from happening in the first place.
Hello, I am trying to figure out what the API call is to update a computer group with the “Patch Reporting Software Title” Criteria. a scripting beginner trying to automatically update a bunch of smart groups and for our Patching.the way we patch has us manually updating a bunch of smart groups to handle what applications need to be updated. we are not in a space to auto update with app installers so we have to manually (installomator/autopgk) apps for deployment.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!