Get Support
Recently active
Hi all,I’ve been unable to find the answer to this one so I’m hoping the experts here will know the answer.I accidentally scoped a policy to all computers with the recurring check-in box ticked rather than just the enrollment complete option. I realised my mistake and rectified it, but now there are multiple pending commands in the policy log. How can I cancel these? Thanks
Hi everyone,I’m in the process of cleaning up a previous school system’s JAMF instance, which unfortunately lacked proper patch management. As a result, there are still devices running macOS Catalina and newer versions.I’m looking for advice or best practices on automating OS upgrades. While I’ll address the specifics of communication with my new manager separately, I’d really appreciate hearing from anyone who has dealt with a similar situation—particularly those without a dedicated team to handle the task.Thank you in advance!
We were configuring our new devices in Jamf pro and it was working fine till August 4th. After that there were no communication between the devices and the server. Any idea why this happened and how to fix?
I use IBM Notifier for most of the popup and notification messages for my user base. Has anyone had any luck using IBM Notifier with a progress bar from a script? I’d like to use a progress bar in a few of my longer running scripts. Would AppleScript be a better option? I’ve used CocoaDialog back in the day but that’s not an option right now.
I've been tasked with finding a way to prevent users from running applications out of unapproved locations such as their Desktop and Downloads folders. I found a nearly 10 year old thread talking about doing exactly that, and it doesn't seem like much has changed in the years since. That said, any decade old device management thread is going to be really out of date. Are there any major gotchas I should be aware of while building out the test Restrictions here? Things like needing to whitelist unexpected directories for Microsoft or Google products? Should I hold off until the Restrictions payload gets updated to match the modern Jamf payload setup?
I have a script that worked before OS15.5. After updating to OS15.6, the script became abnormal. Even if it connected to the allowed SSID and obtained the IP address, it would turn off and on WIFI infinitely. The following is the script. Thank you for your help~~
Basically we have disabled the screenshot feature for a certain group in my organization via JAMF Configuration Profiles, but recently we have found a loophole for users to take screenshots via enabling the “Show features for web developers” and then on Safari, going to Develop tab and “Show Web Inspector” > Elements tab and right click the html to show the option to “capture screenshot” and it will allow you to save the screenshot. We are trying to remediate this loophole by disabling the option to enable the web developers option. Anyone have any ideas? I have tried using Configuration Profile and using the Application & Custom Settings option, but could not get it to work using the plist I found online.https://www.geeksforgeeks.org/techtips/how-to-take-screenshot-apple-safari/
Has anyone found a way to configure the Canvas app with your schools site? One issue we see a lot of is our users entering in the wrong address when trying to access Canvas. I cannot find any information about configuring it from Canvas so I figured I would see if anyone else found out how.
I'm currently traveling around the globe and using VPN to have a static IP address. Is JAMF going to report my location either by detecting nearby WiFis and matching them to a location or by GPS?I understand that a script can always be pushed to do just that, but I'm asking about the more common default setups.Thank you!
To deploy Platform Single Sign-On (SSO) for macOS integrated with Microsoft Entra ID, especially using the Secure Enclave key method, here’s a comprehensive step-by-step guide based on Microsoft & Jamf✅ OverviewPlatform SSO allows macOS users to authenticate using:Microsoft Entra ID credentials Smart cards Secure Enclave-backed keys (recommended for phishing-resistant MFA)In Secure Enclave mode, the local account password remains unchanged, and knowledge of it satisfies MFA requirements for Conditional Access.🔧 Deployment StepsStep 1: Determine Authentication MethodChoose one of the following:Secure Enclave (Recommended) Smart Card Password SyncFor Secure Enclave:Works on macOS 13+ (full support on macOS 14+) Uses hardware-bound cryptographic keys Leaves local account credentials unchanged Supports phishing-resistant MFA https://learn.jamf.com/en-US/bundle/technical-articles/page/Platform_SSO_for_Microsoft_Entra_ID.html
I'm seeing a number of Macs reporting that FileVault 2 is not enabled, despite the encryption state being displayed as Encrypted. I've also seen this sometimes change to show Enabled before reverting back to Not Enabled again. Is this a known issue? The machines appear to be completely fine and encryption seems to be on.
We have our network setup with ADCS connector to get the certificates for the computer. The profile is working and the certificate is in the keychains. In the admin user, I am able to connect to the wifi without any issues. In the user’s account, it won’t connect and doesn’t prompt to choose the certificate. It should prompt for the certificate. I have removed the plist in the user’s library preference folder that had anything to do with network. I still can’t get it to work. I had already cleared out everything in the /Library/Preferences/SystemConfiguration folder. I’m at a loss on what else to delete.
Hi everyone. Recently onboarded new MacBook Pro devices to JAMF School through Apple School Manager (added using Configurator 2). In the ADE profile, the option to allow the user to remove the MDM profile is unchecked but somehow students are still finding a way to delete the profile.Can anyone point me in the right direction to solve this? Not sure if there is another setting I'm missing somewhere. Thank you!
On Saturday, August 16, 2025, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below.Hosted Data Region Date Start Time End Time us-gov-west-1 August 16, 2025 0800 AM CT 1200 PM CT
With Jamf Pro 11.19, prevent potential scope errors with impact alert notifications, add descriptions to smart groups, and deploy Self Service+ automatically!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!Jamf Learning Hub - Release Notes Videos: https://learn.jamf.com/bundle/jamf-pro-release-notes-videos
We are used to deploying apps by choosing an app in the App Inventory, assigning a scope and picking some options. One of the options is on-demand installation, as opposed to automatic installation. On-demand installations allow a user to choose an app from 'My resources' in the Jamf Teacher or Jamf Student app on an iPad or on a Mac. So far, so good.Recently, Jamf School added the extra option of 'App Installers' to install apps on macOS. Here also, you can choose between on-demand and automatic installation. Choosing the latter, the app installs correctly and as expected. Choosing the former: where can a user find the list of installable apps?
Hello, What do you guys use to track your iPads or MacBook Airs that have been lost or stolen? Just wondering what some of you have done to meet that requirement in your environment or school district. Thanks, as always, for your input.
Hi all,I'm hoping someone with experience around LAPS-managed local accounts and Declarative Device Management (DDM) can weigh in on this.Scenario 1:When applying the "Change passcode on next authentication" payload via DDM, I’ve observed that this flag applies to all local accounts on the device — including the one managed by LAPS. My question is:If LAPS rotates the password while that account is flagged for password change on next login, what happens?Will the password change flag be satisfied automatically by the rotation, or is there a risk of the user being prompted unexpectedly or getting locked out?Scenario 2:If the same DDM payload is in place, and the passcode for the affected LAPS-managed account is manually changed (e.g., by an admin or user), then when LAPS next attempts to rotate the password — it will likely operate with an outdated expectation of the current password.Will this mismatch disrupt LAPS password cycling?Does LAPS handle this edge case gracefully or will it fai
Hi All, how to triggar configuration profile from App in self service portal? Thank in Advance
is there anyway I recover Apple Devices Warranty in Jamf pro as Mass load without a GSX Account? Thank in Advances
Good day all, What is everybody’s current/past solutions for PKI and SCEP for Apple. Specifically for EAP-TLS. If you are a mixed enviorment, please also share! Currently using step-ca for everything Apple with JAMF Pro aswell as ChromeOS and Intune devices. Moved away from AD CS and NDES. However, currently on the hunt for a hosted Cloud solution. Share your thoughts, solutions and challenges.
Hi,I need to delete all classes in Jamf pro imported by ASM. Does anybody have a working sh. script?I have used this one below but getting in terminal this error "-:1: parser error : Document is empty" #!/bin/bashjssUser="xxx"jssPass="xxx"jssURL="https://xxxx:8443"echo "Downloading list of class IDs..."ids+=($(curl -X GET -s -k -u "$jssUser:$jssPass" "$jssURL/JSSResource/classes" | xmllint --format - | awk -F'>|<' '/<id>/{print $3}' | sort -n))for n in "${ids[@]}"; docurl -kvu $jssUser:$jssPass ${jssURL}JSSResource/classes/id/$n -X DELETEdone
Hey, I’m curious if anyone has come up with a way to build a smart group that can report specifically on apps located in ~/Applications, since /Applications currently only shows system-level applications.
I have always used JSSConduit to purge old classes to learn JAMF no longer accepts basic authentication. Support sends me the below script to run without explanation. I am a network guy who also manages Jamf, and par for the course Jamf Support falls short. As I stated, I am not a JAMF scripting expert so I am only looking for a detailed procedure on how to delete the classes which typically took me 5 minutes has now lingered for 3 weeks. Any expert advice / instructions would be appreciated. Script below:#!/bin/bash #################################################################################################### # # THIS SCRIPT IS NOT AN OFFICIAL PRODUCT OF JAMF # AS SUCH IT IS PROVIDED WITHOUT WARRANTY OR SUPPORT # # BY USING THIS SCRIPT, YOU AGREE THAT JAMF # IS UNDER NO OBLIGATION TO SUPPORT, DEBUG, OR OTHERWISE # MAINTAIN THIS SCRIPT # #################################################################################################### # # DESCRIPTION # T
Hello, I’m Radhika Sharma, and I manage an online textile business specializing in Jaipuri Print Fabric and Discharge Hand Block Printed Fabric. I’m exploring ways to manage both inventory and Apple devices (like iPads and Macs) used in my business operations using Jamf Pro.Specifically, I need help with: Device Management – Setting up Macs/iPads for employees handling stock and orders. Inventory Management Solutions – Integrating Jamf with inventory software or systems for better tracking and automation. Any advice on how to effectively use Jamf Pro in a retail or business setting would be greatly appreciated!Thanks in advance!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!