Get Support
Recently active
An org’s network requires non-personal devices (think digital signage, inventory scanners, etc...) to be bound to a set network using MAC address. That then requires “Private Wi-Fi Address” to be disabled on all the iOS devices otherwise the device MAC does not match up to the registered MAC.For these type devices, I have a config set to disable “Private Wi-Fi Address” but that only comes through AFTER the device is enrolled (and gets internet access of course). With a random MAC, the device cannot do the initial out of box activation and eventually times out. I can get around all of that with a USB ethernet dongle, which allows the device to get online, enroll, get wifi config settings etc... but that is time consuming.Does anyone know of a way to disable the private wi-fi address setting when you first connect a device to wifi out of the box?I have tried backing out on the setup screen and holding the wifi name in question to try and bring up options, but so far no
I'm trying to add a video to a customize enrollment. It's a video we are storing in a S3 bucket on AWS. When I try to embed it the video doesn't show. Everything I look about this is about Youtube videos but we don't particularly want to host a video on Youtube.
There's plenty of posts regarding disabling AirPlay Receiver, but we actually want to ENABLE it. Our previous AirPlay solution, AirServer, is not being properly maintained by the dev, doesn't play nice on our network, and we have just about given up on it. I tried reversing @ljcacioppo 's solution for disabling the setting here, but when set to true, it doesn't toggle the setting on; it only allows the user to enable it. This is on Seqouia 15.5. Ideally, we would like the following things set via profile: AirPlay Receiver set to ON Allow AirPlay for Anyone on the Same Network Require password set to OFF (the user must click a popup to allow the connection so this is fine) Does anyone have a working solution for this?
We use ClassLink Single Sign On to manage certain apps on our iOS devices. At first launch, you need to choose the correct school district which can get a little confusing. I was wondering if there was a way using the App Configuration setting to specify the exact URL to open upon launching ClassLink.
I'm transitioning us from Jamf Pro to Jamf School. It can't happen like a flipping a light switch so I have to deal with small amount of lingering devices still in use in Jamf Pro into the coming school year (I have all our student devices but not teacher devices). In Jamf Pro we currently have 8 different Sites each setup with their own content tokens that match our locations in Apple School Manager. As we make the transition I can't completely remove every single license from Jamf Pro's tokens, so in setting up Jamf School I'm wondering.... Should I create this same structure with new locations and new content tokens to transfer the bulk of the licenses to in Apple School Manager for the new Jamf School instance, since I can't clean house and use the existing token? Downsides? Is that what Jamf School expects or is it more tuned to one large pool of apps from one content token even when using multiple locations with Jamf School ("sites"). I suspect creating this parallel world is t
Hello all,Just come to reimage my first computer lab of the year.Figured 'this lab now has M4 Mac mini's in it... that means I can use the Wipe Computer MDM command', as this is essentially doing an 'Erase all content and settings' - something I have previously done manually.8 of the devices wiped, reactivated, then started up just fine.The other 12 have SOS orange blinking lights on the front - apparently in DFU mode because something broke.I don't normally have to do this DFU business, so I'm connecting a USBC, loading Apple Configurator 2... and I'm going through the motions.After downloading and attempting to install, it failed presumably because my Macbook is on Sonoma, and it wants to be on Sequioa - now waiting for macOS to update.What a hassle! Is this a known bug?Hard to imagine I messed something up here. Ya press a button, enter a code... device wipes itself.Anyone been in this situation care to mutually vent frustration with me on the forums?
We are excited to share the most recent updates to our Privacy Policy which were made to enhance transparency around how Jamf collects, uses, and protects personal data, particularly in relation to our responsibilities when acting as a data Controller. We have tailored the language to reflect this and have made improvements to the overall structure and writing style of the policy to make it easier to read and navigate. In line with evolving privacy regulations, we have also added a new section outlining privacy rights for residents of the United States. The language relating to AI-powered features has also been updated to better explain how data is used, while maintaining our commitment to responsible and secure innovation. We have also added to the explanation of our lawful basis for processing personal information. You can access the updated Privacy Policy on the Jamf Trust Center Privacy page. If you have any questions or concerns, you can contact our Privac
Managing macOS devices in a large-scale enterprise environment always need IT expertise. Even with a powerful MDM like Jamf Pro, IT admins often need to dive into the command line to truly get to the root of issues. In this blog, we will walk through real-world command-line troubleshooting techniques for both macOS system issues and Jamf Pro management. Whether you're dealing with failing profiles, app crashes, or failed policies, this post has your back with real commands that work. Getting Started: System Info at Your Fingertips Before troubleshooting, gather critical system details: Get system version: sw_vers List all installed system updates softwareupdate –history Hardware overview system_profiler SPHardwareDataType Check uptime uptime Check disk usage df -h Network Troubleshooting Network issues
This ERB Secure Browser app require Screen Time permission. Our students are standard account. Is there a way to allow Screen Time or any ways to solve it?
Historically, after your jamf pro sign-in timed out, when you returned to the login page, it would sign you in automatically. With the new jamf admin sso integration, every login attempt requires you to type your full email. it only takes a few seconds, but when I have to do it 6 or 7 times a day, it starts to add up.
say i have 10 configuration profiles and 2 of them happen to have ENERGY SAVER settings. Names of the 2 config profiles with energy saver settings are below. Which one of them gets their settings applied to the mac laptop? Gaming Energy Saver. (Battery: sleep 30, display sleep 30) (Adapter: sleep 30, display sleep 1 hour) Action Energy Saver. (Battery: sleep 15, display sleep 10) (Adapter: sleep 15, display sleep 10)
Recently whenever i try to install displaylink manager via Installomator i run into this problem where it always fails at the package verification. Every other Installomator installation works perfectly fine only displaylink manager doesnt.Here is the output of Jamf:ERROR : displaylinkmanager : ERROR: Error verifying DisplayLink Manager.pkg error: DisplayLink Manager.pkg: rejected source=no usable signature 2025-06-16 10:07:02 : REQ : displaylinkmanager : ################## End Installomator, exit code 4Is there a problem with displaylink manager or is it a problem with me?
Hello! I am looking to disable the first "transfer your data" prompt before the enrollment screen on macOS. (Seqouia) When I wiped my device from JAMF PRO management portal after upgrading to Seqouia, I noticed BEFORE the enrollment screen, a "Migration Assistant" - "Transfer your data" prompt. How can I disable this prompt before enrollment? I have PreStage options disabled to NOT show transfer wizard (pictured) - confirmed the device is getting the proper prestage profile. And when enrollment pops up, and I finally enroll, I can confirm the migration assistant\\Transfer your data does not prompt.
Hey everyone! 👋 I wanted to share a project I’ve been working on, now available on GitHub:🔐 Jamf Automatic Admin Password Generator This script is designed to securely rotate the password of a local admin account on macOS devices managed by Jamf Pro. It handles everything from password generation to encryption and inventory reporting, making it ideal for IT admins looking to improve endpoint security without manual effort. ✨ Key Features: Generates strong passwords using two random words + creative suffix Applies leet-style substitutions for complexity Mixed casing and ensures minimum 20-character length Updates the local admin password securely Encrypts the password using AES-256-CBC Saves encrypted password to:/private/var/tmp/encrypted_localadmin_password.txt Triggers jamf recon for inventory update in Jamf Pro 🛠️️ Configuration Highlights: adminUser: The local account to rotate (default: admin) encryptionKey: Your custom AES
(Not Jamf Pro specific but I figure this is the most appropriate channel) If you've been using Microsoft AutoUpdate (MAU) to manage updates to Office for Mac you might have noticed that your Office apps have been stuck on the October 2023 Office 16.78 release (the last release to support an Office 2019 license). This appears to be due MAU's license detection mechanism failing to properly detect a Microsoft 365 Subscription license since MAU 4.65 released in November 2023. If you aren't seeing the post 16.78 Office releases, and your users have Microsoft 365 Subscription licenses, deploy a Configuration Profile with an Application & Custom Settings payload for the com.microsoft.autoupdate2 preferences domain and the .plist: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>AppCustomPref</key> <dict>
Hi all, I've seen various threads on this, some dating back to years ago, and I was hoping to get some concrete suggestions on the most efficient way to go about this. We're wanting to deploy only the VPN, Umbrella, and AMP portions of AnyConnect, along with their respective config files from our organization. I've seen seen mention of using the Packages app, as well as Pacifist, but going that route leads to the com.apple.installer issue. I've tried a myriad of different things, but I can't seem to get it setup without issue. Any insight is greatly appreciated!
Hello, we use Cisco AnyConnect 5 on our Mac systems. The one feature I've been unable to get working so far is our VPN management tunnel. We have the management tunnel configured by an XML file on our Windows systems but I can't find any information on where exactly it should go in MacOS (we're running 13.5.2) or how I can use Jamf to push this profile to make sure the management tunnel connects, even before login if possible.Any suggestions?
Hi Guys, I'm trying to deploy SentinelOne and followed all the steps in the HCSOnline PDF, but I'm still getting an error. I've attached a screenshot of the error. Any advice or help would be really appreciated! Thanks in advance!
I can't see the new setting that was deployed in the 11.17RC unless this was pulled? "Jamf Pro now includes a new page that enables administrators to set Self Service+ as the default application and remove Self Service Classic from managed devices that meet Self Service+ requirements. Self Service Classic remains installed on computers that do not meet Self Service+ requirements. To enable Self Service+ deployment from Jamf Pro, navigate to Apps ⇨ Self Service+, then select "Use Self Service+ as the default end user application."
Hey all, We’re currently testing Jamf Connect Login as part of a move to improve our remote deployment process. We haven’t previously used Jamf Connect at login. Currently, devices enrol via ADE, IT enters the user’s name and password, and setup begins with macOS Onboarding. This then installs the Jamf Connect menu bar app for password syncing, which works well - but we’re aiming for a more seamless experience, especially when sending laptops directly to staff. The goal is to let users authenticate directly with Entra ID (Azure AD) during setup, allowing the account creation process to be automated, reduce mistakes, and speed things up. After that first login, we’d like the Mac to: Revert back to the native macOS login window No longer use Jamf Connect Login Keep the Jamf Connect menu bar app (Self Service+) running for password sync, SSO token refresh, etc. I’ve tested removing the config profile and LaunchAgent, which removes the settings — but the login window still s
Hi everyone, I'm looking for a reliable best practice for a common administrative task: automatically clearing the contents of the Desktop and Downloads folders for our standard (non-admin) student users every time they log in or log out of a MacBook. I attempted to resolve this by deploying a shell script directly through the Jamf School "Scripts" module. However, after pushing the script to the MacBooks, it did not successfully clean the files from the target folders upon user login or logout. Environment: MDM: Jamf School Device Platform: macOS (currently on macOS Sequoia 15.5) Target User Accounts: Standard, non-admin users Here is the script I used: #!/bin/bash target_users=("student_ac" "public_user") current_user=$(/usr/bin/stat -f%Su /dev/console) if [[ " ${target_users[@]} " =~ " ${current_user} " ]]; then find "/Users/${current_user}/Desktop" -mindepth 1 -exec mv {} "/Users/${current_user}/.Trash/" \\; find "/Users/${current_user}/Downloads" -mindepth 1 -exec mv
We like to use Patch Management for whatever we cannot patch with app installers but will use Patch Management for reporting even if there is an entry being used in app installers. Sometime early last week we noticed that Microsoft Teams was listed in patch management as having the latest be 25122.1207.3700.1444. App installers never updated and even this morning it still reports 25107.1606.3643.3915 while patch management says 25151.505.3727.5755 is now the latest. I'll give that a little leeway since it says 17 min ago. It reads to me like patch management has a system in place for Teams that keeps it on top with the latest version but app installers not so much. At any rate it seems a bit strange for patch management and app installers to not be in sync. On a related note Jamf Connect 3.0 was recently released yet patch management says 3.2.0 is the latest and there is no 3.0 listed. Jamf Connect Login is listed as 3.0.0 and so is Jamf Connect Configuration. This confu
Hi, I have the problem that my users often dont comply with some policies, like if they received a new device they have to return their old device within 14 days. Many of them just ignore that and my bosses are of no help here. Is there a way to just annoy them via a pop up or something so that they are more willing to return items borrowed from IT or their old Computers, when they finished migrating to a new one? Or any other way to apply soft pressure?
Hey all, I have an issue where I'm trying to write some automation scripts that cross-reference Mac app restrictions with Mac end users' device app inventories. I can query for the list of 'App Store' Mac apps and also 'Restricted Apps', but not the Jamf Catalogue/Software Catalogue apps that we have added to my company's instance. I've looked into this and apparently the deprecated endpoint "api/v2/patch-software-title-configurations" bears a list of applications that have overlap with the Jamf App Catalogue. Are there any current functions/endpoints or even workarounds that are able to get me this software catalogue?
Hi I've created this script utilizing the jamf API to wipe some 2015 intel MacBook Airs, but it's locking the devices instead of wiping them. I using the existing json format since the classic api's erase command has been deprecated. What am i running into here? ` #!/bin/bash # Define credentialsresponse=$(curl -v -u "GVC4_API_Admin_Migration:Change2025" https://gvc4.jamfcloud.com/api/v1/auth/token -X POST)bearerToken=$(echo "$response" | jq -r '.token') # Device IDscomputerIDs=(2403 2636 2619 2595) for comID in "${computerIDs[@]}"doecho "Sending erase command to computer ID $comID..."#curl -X POST \\#-H "Accept: application/json" -H "Authorization: Bearer ${bearerToken}" \\#"https://gvc4.jamfcloud.com/JSSResource/computercommands/command/EraseDevice/passcode/123456/id/$comID"curl -X 'POST' \\"https://gvc4.jamfcloud.com/api/v1/computer-inventory/$comID/erase" \\-H "Authorization: Bearer $bearerToken" \\-H "Content-Type: application/json" \\-d '{ "pin": "123456" }'done `
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!