Get Support
Recently active
When adding apps to Self Service (or even Self Service+) via Mac Apps, the applications descriptions are in German. I’ve ensured that English is set to the preferred language and enabled location service. This is being run on a test VM but I can’t for the life of me figure out why this would be the case?
We wanted to share a few updates about new features in Jamf Account that improve SSO management and troubleshooting, as well as new documentation resources for enabling OIDC authentication for platform services.A new Jamf Account Release History section in our Learning Hub details several improvements:A new "Authorize URL" button for Google Workspace OIDC connections, enabling consistent group support across organization types Login History tab under Profile, allowing you to view authentication history and ID tokens when using an IdP Enhanced error handling with unique reference UUIDs for failed SSO attemptsTo help customers migrate to OIDC, we've published a SAML to OIDC Migration Guide that walks through adopting OIDC-based workflows.The Understanding SSO Authentication Methods guide helps address common questions about IdP choices, OIDC benefits, and authentication options. It includes visual breakdowns of both SAML-based and OIDC-based authentication methods to demonstrate how vari
We recently migrated to Jamf Cloud and using Azure AD as our Cloud Identity Provider and Single Sign-On solution. It works well enough, but we have a weird situation. We're sticking pretty close to Microsoft's documentation on it, which can be found here.By default, the iDP maps userPrincipalName as the username. That's a full email address in our environment, so we want to use onPremisesSamAccountName instead. That works fine in the iDP in both testing and looking up users/accounts.We also need user authentication during the initial device enrollment via DEP. We've gotten that added in by adding an Enrollment Customization that is just the SSO.Here's where it gets dumb. If we now enroll a machine while the User Name mapping is set to onPremisesSamAccountName, the SSO during enrollment registers the device to just the userPrincipalName with no other user data. The Pre-Fill Primary Account Information only puts in the userPrincipalName as the Us
Hello,on macOS 14, With PPPC Utility, i want to create a profil who allow the usage of camera and microphone on an .app. But when i open PCCC Utility or make it across web admin from Jam, there is not “Allow” option available in the select field.I read that the application must be without hardened runtime, but if i remove the hardened runtime, the app can’t be export via “Archive” → “Direct distribution”.Any idea ?
Heya awesome Mac admins! I am still relatively new to this whole Jamf thing and looking into setting up Jamf Setup Manager to install our apps before the user reaches the desktop. I am trying to follow guides and getting hung up quite a bit on step 1 of most them, “package Setup Manager”. This is kind of a loaded step. I have tried several ways of doing this. I have packaged the zip, which didn’t work. I have extracted the .zip to the desktop and then packaged, didn’t work. I have tried putting the extracted zip in different folders, then packaging from there with Composer, didn’t work. How the heck do I package this thing for deployment? The configuration from Jamf Pro is relatively straightforward, I just need some help making sure the actual files are in the proper places.
Question for how/if we have controls to deploy a specific app version to iPads. We have a couple applications we use and work closely with the developer and schedule when we make the update available on our EFB iPads. We use the check boxes ‘Schedule Jamf Pro to automatically check the App Store for app updates’ and ‘Force App Update’ to accomplish this. Today is the first time we noticed a different version was installed than what Jamf Pro is reporting as available.This is what is showing under Mobile Device Apps.Does it always install the newest version of what’s available in the Apple store via Self Service regardless of what Jamf Pro is reporting? When looking at the Inventory for the iPad we see that 10.5.1 was installed.
CIS 1 Allow Touch ID to unlock your mac what needs to be deactivated?Hi Hope you can help, how do we allow users to use Touch ID rather than the full password each time sleep is activated. What needs to be unticked in the list of Managed Rules in compliance?Thanks
Hello there, Is there any way to automatically enable Location Services for non-admin users? I know it is currently not possible to set up a PPPC, so I tried some scripts to enable this feature. For example: #!/bin/bash #set -x ########################################################################################## ## ## Script to enable automatically Location Services on Mac ## ########################################################################################## ## Define variables location_enabled=$(sudo -u "_locationd" defaults -currentHost read "/var/db/locationd/Library/Preferences/ByHost/com.apple.locationd" LocationServicesEnabled) ## Check if location services is enabled. If so, we will terminate this script immediately. Otherwise, we will enable it. echo " $(date) | Checking if this macOS-device has Location Services enabled or not..." if [[ "$location_enabled" = "1" ]]; then echo " $(date) | Location Services are already enabled" exit 0 else ech
We've followed the steps given in this guide (https://www.jamf.com/blog/help-users-activate-microsoft-office-365-and-configure-outlook-in-one-click/) but when we launch Outlook, our email address isn't automatically populated like it is here. Has anyone else experienced this? If so, what was your workaround? Any advice would be much appreciated! Thanks in advance!
Hi folks, I’m trying to find a way to report (at the very least) which of our devices have Jamf Connect enabled in System Prefs>Privacy & Security>Local Network. Based on my investigation, it seems like SIP/Apple blocks this particular preference from being viewed or modified by MDM’s (on macOS 15+). I have seen similar discourse around the weekly system prompts for Camera/Screen recording and some solutions there, but nothing for this. I am preparing to upgrade all of our Macs to Sequoia 15.5, about ~80 computers. My org uses Entra for login + network drives and I’ve found that end-users on Sequoia that don’t have this enabled have issues with password sync and accessing the drives. Grateful for any input or advice!
I have Jamf connect configured with entra ID and requires authentication with their network account at each restart. My users are unable to sign into their macs offline because the account cannot authenticate with microsoft. Is this a setting within jamf connect that I can change to allow a local account to pass through when not connected to internet?
Hi, Jamf Nation! Many of you wear multiple hats and are the glue that holds the technical processes together in your environments. That’s why when something goes wrong, you need us, your Jamf Support team, to be by your side. Today we’re excited to share that the Support service you rely on is getting even better by streamlining your access to Jamfs who can best help you solve your problems at the right time. While all of the details of the enhanced process are in your email inboxes, we’re happy to share the highlights here. Knowledge and support now live together in the Support Portal, which is accessible via Jamf Account or at support.Jamf.com. Customers will see an updated chat experience (with more enhancements to come) The Product Issue process was simplified to enhance the customers’ overall interaction with Support While this work greatly enhanced the support you’ll receive from us, the majority of the changes are on our side (within the Jamf “walls”). Our Support teams w
Good Day!I am testing Platform SSO out in our environment and so far it is working great! We are pushing out MSCP via the Jamf Mac Apps. We’re using “Password” as our authentication type. Setup with Entra. And we do not currently have any custom config, just out of the box setup. Our machines are NOT Bound to AD, and we use local standard user accounts to start off with. then register and sync passwords. I have 2 major issues that I would love to hear from the hivemind:We are seeing that we can put in many bad passwords at the login screen without any repurcussions. If the machine was compromised, what is stopping someone from brute forcing the correct password? Is there a way to set password attempts? When a user’s password changes they can obviously go re-authenticate and sync their password again, but what if a user just ignores this and never syncs their password? Meaning whatever their password WAS is what they are using to Log In and then use a different password for their AD Ac
I wanted to start a new post due to all the interest in some older posts. We are about to start a closed beta test of an app we built to help address a hole we saw in the digital signage space. We wanted a way to simply connect Google Slideshows to Apple TVs and we couldn't find a solution that fit our needs. So we built our own solution. Our app, Simple Signage, is a easy way to connect Google Slideshows to Apple TVs. You just copy the share link into Jamf, set the intervals for the slides and how often you want the slideshow to refresh. That is it. It has worked so well for us all year, we decided we would share with the community, but first we are hoping a few people will help us tryout and test the app. If you are interested in our app Simple Signage and would be willing to help us beta test it through TestFlight, just respond here and I will message you privately with more information.
I am using Jamf Pro and ran tests to get Microsoft Defender installed on our Macs. However, we’ve now decided to go a different route and I need a way to automate the removal of Defender. It was installed via a PKG and a policy in Jamf Pro. I have tried running a sudo rm etc to remove the app but that returns “operation not permitted”. I am an admin on my device and all our other users with defender are as well. I read that I might need to give Terminal full disk access, so I did. That didn’t work. I also then revoked full disk access from Defender, that didnt’ do anything either. I’m not sure what script I need to be running in Jamf to get this gone.
I have this specific need to keep the Google Drive app version to 77.0 but it keeps updating to version 110.0 (latest).I’ve already removed the device from the Smart CG linked to the GDrive app on the Application section but it still automatically updating.Is there something I can do to solve the issue?Thank you
We have a small yet nice enhancement available as of today - you can now edit the benchmark description after creating the benchmark.This means that only the benchmark name cannot be changed once the benchmark is created (as it is used in all generated objects names). We therefore encourage you to pick a more general benchmark name and use the description (which is also visible on the benchmark card) to better describe the benchmark purpose - e.g. scope or mode.Let us know how this helps you to manage the compliance of your fleet!
Recently, an end user had their laptop stolen, so once notified i was able to apply a lock to the unit from my instance of JamfPro with a 6 digit code and it’s been a week now and it looks like nobody has tried to get the unit online. Long term can anyone suggest what i should do? I don’t expect to ever get the unit back so should i remove it from JamF?? Umberto
Hey Jamf Nation! My name is Taylor Taylor; I’m from Birmingham, Alabama. I am wondering if there are any Jamf Heroes in Alabama or the South. I’m curious to find out and would love to connect.
Would love to connect with you all, share experiences, and maybe even collaborate on some cool stuff. Feel free to drop a message or say hi! 😊Thanks...
Hi all, We have quite a weird recurring issue with 3 mac devices. FileVault is set to enable via a configuration profile from UIE//ADE and this has been working good since we introduced Jamf. We are however having issues where the secure tokens assigned to these users are being removed? I was wondering if this is something that anyone else has seen? The accounts a mobile accounts from AD. All of the mobile accounts on the devices are struggling. The workaround currently is to sign in with the local account that was created for support (has securetoken key) and then log out. Falling short of disabling FileVault for these devices, is there anything else any one can think of? Thanks in advance!
Just be going though the process of updating our Autodesk apps for 2026. its not a script I have written but I have updated for Maya & Mudbox 2026. I found on her somewhere.Thought it was sharing to help other as a starting point. #!/bin/bash#Copy installer app from .dmg to /tmp#Modify values below as necessary (Usually: year and pKey)#Set variablesyear="2026"pkgPath1="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/MayaUSD.pkg"pkgPath2="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/Maya_AdLMconf2026.pkg"#pkgPath3="/private/tmp/InstallMaya2024.app/Contents/Helper/Packages/Licensing/adskflexnetserverIPV6.pkg"pkgPath4="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Licensing/AdskLicensing-15.1.0.12339-mac-installer.pkg"pkgPath5="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/Maya_core2026.pkg"pkgPath6="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/bifrost.pkg"pkgPath7="/private/tmp/InstallMaya2026.app/Content
Hello,I know this is probably not the best place to ask that question but as it’s about the beta forums (which are under NDA), I’m asking it in one of the beta forums. With the new Jamf Nation forum, there’s no way to find a link to all the beta forums for which we are a member like we could with the previous version.Do you plan to change this? It makes it hard to find our way back to one of the beta forums because of that. For example, I had some pending topics on the Self Service+ forum before the migration and it’s impossible for me to find them again to check if there has been answers posted.
Hi All,Does anybody know if InTune Cloud PKI integration with JAMF works instead of the legacy setting up NDES on prem?
My Google-Fu is failing me ... How can I enable the preference below from Terminal?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!