Get Support
Recently active
I manage several dozen iPads using Jamf Pro. I have a restriction set to only allow OS updates after they are 30 days old. Once the 30 days are up, I manually push out the update using the “Download and schedule to install” option, setting the “Force install date” one week in the future and selecting the specific version I want installed. What I am seeing is that when the “Force install date” comes around, the update is not forced, but the user is allowed to continue using the iPad without updating the OS. I expected them to be “forced” to update when this date happens. Does “force” have a different meaning here? What am I missing? Also, if I choose “Download and install” it does not force the user to update the OS either. Thanks for any insight. I’m new to this world.
Hey all, looking for some help or confirmation here. I’m managing lab Macs (M1/M2, macOS Sequoia) where user accounts are deleted at reboot. I want to stop OneDrive from auto-launching that “Set up OneDrive” window every time a new user logs in — but still allow students to launch it manually if needed. Here’s what I’ve tried so far: Scoped a Jamf Managed Login Items config profile with a rule to block application.com.microsoft.OneDrive(Label Prefix, team ID UBF8T346G9) Also added a rule to block com.microsoft.OneDriveLauncher just in case that agent is still around Tried both Jamf’s GUI approach and uploading a signed com.apple.servicemanagement profile directly with <Authorization>false</Authorization> rules Even layered on launchctl disable + login hook scripts to unload and delete the LaunchAgents But the wizard keeps launching for brand-new users, even when all signs say the login item is blocked. Nothing shows in launchctl list, and the
New releases include:iOS 18.6 iPadOS 18.6 macOS Sequoia 15.6 HomePod 18.6 tvOS 18.6 watchOS 11.6 visionOS 2.6https://support.apple.com/en-us/100100
Have Logic on our recording studio machines (AD bound lab machines), but struggling to capture the plugin cache in Composer in a way that prevents Logic scanning for plugins on every login (We have c.400 plugins so it’s a real time killer). Do chip in with any questions/ suggestions, I'm very much not a Jamf power user, but to me has fallen the task...
That’s right - there are brand-new swag options waiting for you in Jamf Nation Rewards!Check out your Jamf Account to see what’s new and start redeeming those hard-earned bytes.Not a member yet? Learn more and join here.And we’d love to hear - what are you saving your bytes for? Drop it in the thread 🧵!Here’s a sneak peek ⬇️ Explore the full lineup in Jamf Nation Rewards!Your rewards await 😎
Don't miss your chance to secure your 2025 JNUC tickets at the Just In Time rate of $1499 ($1299 for educational organizations). Starting Friday, August 1st, the Standard rate of $1,699 will apply ($1,499 for education).If you need help getting approval to attend, we've prepared a Convince Your Boss Letter to ensure you don't miss out.Have questions or need additional assistance? Visit our JNUC FAQ or email us at jnuchelp@jamf.com.Ready to secure your spot? Register for JNUC 2025! We look forward to seeing you in Denver this October! Kind regards,Jeff
I installed an App from self service. However, after installation, self service now only gives me the button to "Reinstall". There is not a "Uninstall" button for this App. How do I uninstall it ?
I'm trying to apply proxy settings to Macs for use only when they are in the office, connected to corporate Ethernet or WiFi, but I don't want these proxy settings to be applied when the user is at home or anywhere that isn't the office. Is there a way that this can be done?
Some of our primary school students have just used the Jamf Student app to update all the apps on their iPads. The Jamf Student app updated, but now it's asking the students to log into the Student app with a .jamcloud.com account. Our students are 10 years old and do not have any online accounts, how do they now use the Jamf Student app if they aren't allowed a .jamfcloud.com account?
Been having a lot of problems with Filevault over the years. Now I’ve just discovered that you can no longer use the Filevault recovery keys in macOS 15.5. Instead, you are expected to boot to recovery, which is more of a pain. This removal is insane. Like many we use the stored key from Jamf to unlock devices in the event of account passwords not working. Now we have to use Recovery mode. I’d love to know Apple’s reasoning for this. Anyone else aware of this and have any comment?
Hi there, Has anyone managed to successfully get the Jamf Pro Custom API action call card working in Okta?I get a 401 Unauthorized error even though the bearer token is brand new and passed directly to the auth field of the custom API action card. I even tried with API endpoint reference curl command and compared an invalid bearer token to a valid freshly generated one: curl --request POST \ --url https://sandbox.jamfcloud.com/api/v1/ddm/18/sync \ --header 'accept: application/json' \ --header 'authorization: Bearer invalid_token'{ "httpStatus" : 401, "errors" : [ { "code" : "INVALID_TOKEN", "description" : "Unauthorized", "id" : "0", "field" : null } ]}% curl --request POST \ --url https://sandbox.jamfcloud.com/api/v1/ddm/24/sync \ --header 'accept: application/json' \ --header 'authorization: Bearer working_token'{ "htt
Since moving to JAMF Cloud, we’ve noticed that some time appears to be off. For example, I ran an Inventory Update manually on a computer, and the record in JAMF console shows that it was run 1 hour earlier than it actually was.Also, with Apple TVs we have records that say that the Inventory Update occurred up to an hour in the future.I’m not sure that this is causing an actual problem yet, but concerned that it could. Are there time zone settings we should see or anything? All of our client devices are in the same time zone (unless a client goes on a temproary trip or something).
I blocked the extension installation on chrome, with that un approved extension are blcoked but now I want to remove the un approved extension which is installed previously. Is there any way to removed it?I tried to remove the extension ID with script but in Chrome browser it shows corrupted not removing completely.
Hello, I need to create a script to simply turn on the Teamviewer in Security & Privacy > Screen recording. Right now it's a manual process and we're trying to deploy Teamviewer host via Jamf. However the configuration policy that comes with Teamviewer host does not allow us to allow screen sharing. It gives the user the option to allow screen sharing and since we don't want the user to interact with anything, I'm looking for a script that can turn on Teamviewer in Screen recording in Security & privacy:
Does the JIM use Apache Tomcat at all?
Hello all,I created a PPPC config profile to grant OneDrive full disk access. Jamf Pro says the config profile is successfully installed on my test Mac, but when I check Privacy & Security → Full Disk Access it shows that OneDrive does not have full disk access. Is it normal for this change not to reflect in settings or am I missing something/doing something wrong? For clarification I have made the config profile directly in Jamf Pro and using the Jamf PPPC utility and uploading the config profile into Jamf Pro afterwards. Thanks!
New 270 class for those interested ... Jamf 270 CourseJamf Certified Tech - Jamf Protect The Jamf 270 Course offers a core understanding of endpoint and network security for Mac and mobile devices with Jamf Pro and Jamf Protect. Our hands-on, scenario and example-based course environment is the optimal way to begin learning how to secure devices with Jamf.https://account.jamf.com/training-courses/jamf-270-course/available
Hello communityI'm looking for a solution to only allow self-service application installation, even for local admin accounts.I tried blocking the installation process, but unfortunately this also blocks self-service installations.
A practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service Mac Health Check (2.0.0)Overview Mac Health Check provides a practical and user-friendly approach to surfacing Mac health information directly to end-users via Jamf Pro Self Service.Built using the open-source utility swiftDialog, the solution acts as a “heads-up display” presenting real-time system health and policy compliance status in a clear and interactive format.Administrators can customize the user interface using swiftDialog’s visual capabilities, making the experience both informative and approachable.The tool logs results for IT review, while not altering device configuration, making it ideal for visibility without intrusion.Continue reading …
I created this small application to make it easier to retrieve the Bundle ID of a macOS app.Simply drag a .app file onto its icon in the Dock to display the app’s unique identifier and easily copy it to the clipboard.The link below includes both the AppleScript source code and the compiled, ready-to-use application.https://www.dropbox.com/scl/fi/74iqhkbs7cd7nfhi0fsn9/Bundle-ID-Droplet.7z?rlkey=a2kldrolexvix16z6hluvjpar&st=n999z5tv&dl=0Hopefully, this can help someone.
We’ve been getting a lot of feedback that you need to see the compliance status of specific computers to take corrective actions - so here it finally is!Available now in all Jamf Pro 11.18 and newer instances, you are now able to click on each rule of your benchmark to get a list of computers in scope, with their compliance status against this rule, and a link to computer inventory for further investigations.Let us know what you think of this and how it helps you in your workflows. Availability of the data via APIs and exports is the next on our list, so stay tuned!
Hi all,I try to create a user level configuration profile for ethernet (for 802.1x LAN authentication).So basically, the same we already use for WiFi.We currently use a computer lvl profile, which works without issues. But have to change it to user lvl because of the strong auth change Microsoft enforces soon.The settings should work but as soon as I click on save, the network payload vanishes. Without an error or any explanation… As said before, the WiFi profile (also user lvl) works like a charm.Any tips on why this might happen?BR Thomas
A lot of machines recently asked for the update of Slack helper tool.Is there a way to stop it from happening?Thank you!
We’re deploying the CIS L1 baseline to Macs which are using the new Platform SSO with Entra. What’s the best practice in terms of password policy within the CIS baseline? Should we exclude these policies or does using PSSO override them anyway? I don’t want to end up on a situation where the baseline password policies are more restrictive than the company password policy from Entra and have that causing issues with password syncing.
What is the best way to export Management History and the "Inventory Update" log, given that we do not have JAMF Protect yet Instead of having to open each iPad entry and review its log individually, is there a way to export that data?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!