Get Support
Recently active
We are trying to push out a profile to have our Mac's (in a primarily Microsoft environment) to auto join our 802.1x network. I have setup the Jamf ADCS and am able to push a device cert to the Mac's that I would like to use. I created a policy in NPS to use that cert for authentication that I would like to use but am getting auth failures. Any guidance for how to remediate this?
Hello everyoneMy context: wi-fi authentication based on 802.1x through a Windows Server (NPS). Computer certificates are deployed by Jamf (Configuraton Profile) and through the Jamf ADCS connector.Macs are not bound to the Windows domain but a computer object is created for every laptop (it's mandatory with a NPS server).Everything is working as intended. As you may know, in may 2022 Microsoft published an important security update that changes the way certificates are validated by domain controlers.https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16 A new extension identified by the OID "1.3.6.1.4.1.311.25.2" is now included in certificate templates, but only for the ones that build the subject information from Active Directory.Unfortunately, certificates issued through the Jamf connector are "offline", meaning that the subject information (CN, DNS name) are supp
We use jamf school to reset laptops in classrooms, everything is installed in nl_NL but all Adobe apps stay in english. If we create a dutch package in Adobe admin console and try to upload it in jamf we get a parse xml error. Tried all suggestions from AI but no succes..
Hello everyone, is there an API Call/Endpoint to disown Devices (ADE) in Jamf School?
Hey folks,We migrated from using policies onto using Jamf App Catalog to handle our standardize applications (Google Chrome, Mozilla Firefox, VLC, etc) for auto patching the latest builds and offering the software for workstations without the software to download from Self Service+.We’re looking into configuring Jamf Setup Manager, however since we do not have triggers from policies for software, I’m curious if anyone has found a workaround or best practice for this. I’m interested in hearing your thoughts, workarounds, and recommendations.Thank you,JG
Hey,I am just wondering if anyone else got the same expierence?After installing the latest DisplayLink Update, it turned out that the previous working configuration Profile is broken. Every time I open the Tool from the Apple Menu, the Splash Screen comes up again.This is the Profile in User Level (I tried also Computer Level) which worked fine on the previous version:PLIST file containing key value pairs for settings in the specified domain<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict> <key>AppAutostart</key> <string>1</string> <key>SilentSetup</key> <string>1</string></dict></plist>
I am having an issue that I think is somehow related to Safari and our proxy. We have had several reports of users traveling off-network and having issues with captive portals. The Captive Network Assistant.app window appears but it's blank and says: "The webpage couldn't be loaded". If I open Chrome or Firefox, and go to https://captive.apple.com then the Captive Portal appears and I can do whatever I need to access the WiFi SSID. If open Safari, I am unable to get to https://captive.apple.com. Has anyone run across this issue? I'm assuming the Captive Network Assistant is using Safari to try to show the Captive Portal...
The way JAMF displays my inventory requires me to scroll a lot to the right to find information on an asset. I would like to customize the order the columns are displayed. For example, Asset, serial number, building, and then room. Is it possible to change the order of the inventory display?
How can I make it so after a set amount of time the device goes to a app and the app can not be exited until you fill out a sign in and after the set amount of time it "Signs you out" bringing you back to the form. ThanksIan Nelson
Hello all, I know there have been a couple of topics around this already but I can't seem to find a solid solution for this. We are a university and have both user assigned and public apple computers and laptops. I would like todo one of the following:1. Prevent users from login into their personal apple ID's and lock the devices to only use our ITS apple ID (make sure they can not log out of it).2. Simply block the ability to sign into any apple ID.3. Force sign out users already signed into their personal apple ID's. I have tried to set this up using a configuration profile under Restrictions > Preferences but this does not work (once the profile is applied the section is still visible). I also don't like the restrictions method as this includes many other options I don't want to use (in Applications, Widgets, Media, ect).We are using Jamf PRO and Apple School Manager. Thanks!
Hi all,We have several Mac builds deployed across the University, with the majority of devices using a core “Staff” build within Jamf Pro. When we introduce a new build, we typically create a new PreStage enrolment profile and re-scope existing Macs to that profile. The intention is that if a device is rebuilt or reset at any point during its lifecycle, it will receive the latest build and updated setup experience. I assume this is fairly standard practice, and up until this point, it’s otherwise had no unintended consequences.However, something I’ve noticed this year is that Macs running older builds, but now scoped to a newer enrolment profile, are unexpectedly migrating.I’ve traced this back to the point where the MDM profiles renew on the client. During this process, the value of the following attribute in the computer record appears to be overwritten:Enrollment Method: PreStage enrollment = XXXXWe currently rely on Smart Groups based on this value to scope configuration profiles a
Does anyone have issues when using JRA with the users that have multiple displays?During a session it will swap between displays automatically, even thought I have auto switch monitor turned off.
With Jamf Pro 11.29, administrators can strengthen identity-first enrollment with a new Simplified Setup for Platform SSO workflow, scope devices more reliably using native directory service group criteria in smart groups, and enforce software updates via declarative device management on self-hosted instances.Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
We have a lab environment where we explicitly want the screen saver / display timeout to be a specific time, but we don’t want the user to have to re-enter the password when the display wakes / screen saver exits.When we set a Configuration Profile with a Security and Privacy: General payload, we can successfully set Require Passcode to Unlock Screen to enabled and set to a specific time (Immediately, 5 minutes, 8 hours, etc.), and this works as expected. But when we try setting it to “Never”, the target device updates and reverts to “Immediately”. I’ve also tried setting it to “Immediately” to see if “Never” and “Immediately” were just swapped in the Jamf UI, but that wasn’t it.I’ve also tried using a plist file in a Application & Custom Settings payload with a domain of com.apple.screensaver as detailed from Apple’s documentation.However, this doesn’t seem to work at all, and the settings don’t seem to take effect.<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist P
Taking a swing at the regex. How is this?macOS 27 Golden Gate (Regex Can't upgrade)^Mac(BookPro1(7|8),\d|(1(4,([5679]|10)|5,([36-9]|1[01])|6,[15-8]|7,[2-9]))|(1([56],1[23]|4,(2|15))|BookAir10,1)|(6,[23]|5,[45])|mini9,1|1(6,1[015])|14,(3|12)|1(3,[12]|4,1(3|4)|5,14|6,9)|14,8)$|^iMac21,[12]$
Pretty sure I know the answer, just doing due diligence at this point.We recently modified our local account password policy where we are actually are now enforcing one. For background, we’ve had a local account password policy for years, but never enforced it. Now we are.We’ve had a number of users who have been presented with the password change dialog, and rather than changing the password have clicked Cancel instead, then keep trying to login with their current password, which has resulted in them getting locked out.The field support team has asked if it's possible to modify the text in the PW change dialog in some way to help people understand that the pw change is not really optional.I didn't think there was, and I haven’t found anything to suggest otherwise, but thought I’d check in here to see if anyone has any suggestions.
We purchased some M5 MacBook Airs with Tahoe with 26.2 installed and when we deploy them to a new staff person, they are required run a macOS update despite the fact we have the minimum required macOS version in the prestage set to “no enforcement”. I don’t think this was happening in previous macOS’es.This just prolongs the onboarding process.
I was struggling with targeting a Web Clip in Single App mode for some iPads. I found several articles saying you couldn’t do it until I found a Jamf article saying that it was possible but, only by targeting the specifc bundle ID of the Web Clip.https://support.jamf.com/en/articles/13274571-configuring-single-app-mode-for-web-clips-in-jamf-proThis sounded great and I thought my search was over. However, this didn’t work. It made sense though, targeting the specific payload identifier should work. So, after much testing I discovered the following with regard to targeting a web clip in single app mode:1. There can only be a SINGLE web clip profile with a single web clip payload deployed to the iPad. I chose full screen but, it might not matter.2. The Single App profile MUST use the standard "com.apple.webapp" bundle ID.That's it. If you do those two things, the single web clip will present in Single App mode.Good Luck!
Hey Jamf Nation!We're excited to announce SCIM-based provisioning and lifecycle management of administrator profiles in Jamf Account, now available in Beta.Inbound SCIM lets your identity provider push administrator profiles directly into Jamf Account without requiring those users to sign in first. Once configured, your IdP becomes the source of truth for administrator lifecycle events in Jamf. This beta supports Microsoft Entra ID and Okta as identity providers.Today, SCIM-provisioned profiles appear in Jamf Account, names stay current when updated in your IdP, and you can assign roles and privileges before an administrator's first login. This is the foundation for platform-wide administrator provisioning across Jamf Pro, Jamf Security Cloud, and other Jamf applications. When that work ships, your SCIM configuration carries forward with no changes required.When configuring your SCIM connection, you can also select the groups scope. Groups sync now but do not yet drive role assignments
If not, you really should check out https://github.com/Jamf-Concepts/Jamf-Extender (and take a look at the other repos under Jamf-Concepts while you're there). Versions for Safari, Firefox, and Chrome/Edge are available.I’m not going to list all of the capabilities of the current version, but a few that I’ve found to be _extremely_ useful are:The capabilities of MUT accessible directly from the Jamf Pro console Identify how may times a Smart Group is used as a Target or an Exclusion Convert unused Smart Groups to Advanced Computer Searches A Compare Profiles command to view the scope summary and which payloads are shared or unique (the settings in each payload are not displayed in the comparison however)Other areas where the extension adds capabilities are Blueprints, Jamf Security Cloud, and Jamf ProtectThanks to @Tribruin for calling out this very useful tool in the MacAdmins Slack #jamf-concepts-discussion channel
Introducing the MacAdmins Definitive Resource DirectoryOne of the greatest difficulties I found when I began my career as a Mac Systems Administrator was not learning the technology or the tools, but rather finding out where I should be looking. The MacAdmins community holds a vast amount of information and resources, however, due to the sheer volume and the fact that there is so much spread around the web, it can become quite intimidating, especially for newbies.This is why I decided to create the MacAdmins Definitive Resource Directory: https://github.com/maccy10/definitivemacadmins Reasons for Building This ProjectOf course, there are already other very good, curated collections of links, and it would be unfair not to mention the projects that inspired this one:* Community is Valuable: A List of My Favourite Community Resources: https://community.jamf.com/tech-thoughts-180/community-is-valuable-a-list-of-my-favorite-community-resources-53430* https://github.com/JordyThery/bookmarksJ
Hi,We're starting to see a number of cases being raised internally about some of our Macs (all on macOS 15.1.1) having intermittent login issues. Our devices are bound to AD and our users have been logging on fine for some time but now we're starting to get issues. Sometimes the logins are fine. Sometimes they take ~10 mins and sometimes they appear to stall completely (waited over 2.5 hours in testing) even on the same device. The login screen appears to freeze (the time doesn't change) and you eventually get the spinning beachball. SSH is still working and you can run a "jamf policy" successfully. "Screen Sharing" reports that the user who has attempted to log into the device is the active user when you connect.Can anyone share some tips as to how we would start to investigate this sort of issue let alone resolve it???ThanksStuart
Hi everyone! Looks like Microsoft may have finally released a compatible version of Company Portal for simplified platform SSO to work with JamfPro and Intune :). I’m sure I’m not the only one who’s been keeping an eye out for Microsoft to release a compatible version of Company Portal for Platform SSO during registration, so wanted to share the info with everyone. I noticed late yesterday that Microsoft updated their “What’s new in Intune” page with this little tidbit:What's new in Microsoft Intune - Microsoft Intune | Microsoft Learn They released this blog post in the last couple hours:New Platform SSO with registration during Automated Device Enrollment on macOS | Microsoft Community Hub And here is the direct link to the Microsoft learn article on setup for it:Add Platform SSO policy to ADE Profile on macOS devices - Microsoft Intune | Microsoft Learn Anyone gotten a chance to play with it yet? If so, what are your thoughts? It’ll likely be tomorrow before I get a chance, sad
Hi there,I try to use Jamf Setup Manager to made zero touch installation on my Macs.First question, i don’t have found how to launch JSM after enrollement wouthout let a welcome pane open. If the Mac return back to login screen nothing happens. Is it possible to automatically launch JSM without a pane opened?I also try to change Mac name and sync his identify on Jamf inventory, which are the command i could use in JSM to do this?Thanks for your help
I had a support ticket recently where a user reported that they couldn’t update any packages they had installed in the TeX Live Utility, and I wanted to post here in case anyone was searching around for a solution. The large majority of our users don’t have local administrator rights on their Macs, so I wanted to find a solution where they could update their packages within the program without being prompted for administrator credentials.The solution is to create a Jamf policy to install MacTeX (of which TeX Live Utility is included) via Installomator and make this installable via Self Service.General > Display Name: MacTeX LatestCategory: UtilityTrigger: <Leave Blank>Execution Frequency: OngoingScripts: installomator.sh and Tex Live Utility Script (see below)Scope: As desired, but I elected to make this available to ‘All Computers’Self Service: Choose a Display Name and short Description. I then checked the Utility category.User Interaction > Complete Message: MacTeX has b
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!