Get Support
Recently active
Hi everyone. Recently onboarded new MacBook Pro devices to JAMF School through Apple School Manager (added using Configurator 2). In the ADE profile, the option to allow the user to remove the MDM profile is unchecked but somehow students are still finding a way to delete the profile.Can anyone point me in the right direction to solve this? Not sure if there is another setting I'm missing somewhere. Thank you!
On Saturday, August 16, 2025, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below.Hosted Data Region Date Start Time End Time us-gov-west-1 August 16, 2025 0800 AM CT 1200 PM CT
With Jamf Pro 11.19, prevent potential scope errors with impact alert notifications, add descriptions to smart groups, and deploy Self Service+ automatically!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!Jamf Learning Hub - Release Notes Videos: https://learn.jamf.com/bundle/jamf-pro-release-notes-videos
We are used to deploying apps by choosing an app in the App Inventory, assigning a scope and picking some options. One of the options is on-demand installation, as opposed to automatic installation. On-demand installations allow a user to choose an app from 'My resources' in the Jamf Teacher or Jamf Student app on an iPad or on a Mac. So far, so good.Recently, Jamf School added the extra option of 'App Installers' to install apps on macOS. Here also, you can choose between on-demand and automatic installation. Choosing the latter, the app installs correctly and as expected. Choosing the former: where can a user find the list of installable apps?
Hello, What do you guys use to track your iPads or MacBook Airs that have been lost or stolen? Just wondering what some of you have done to meet that requirement in your environment or school district. Thanks, as always, for your input.
Hi all,I'm hoping someone with experience around LAPS-managed local accounts and Declarative Device Management (DDM) can weigh in on this.Scenario 1:When applying the "Change passcode on next authentication" payload via DDM, I’ve observed that this flag applies to all local accounts on the device — including the one managed by LAPS. My question is:If LAPS rotates the password while that account is flagged for password change on next login, what happens?Will the password change flag be satisfied automatically by the rotation, or is there a risk of the user being prompted unexpectedly or getting locked out?Scenario 2:If the same DDM payload is in place, and the passcode for the affected LAPS-managed account is manually changed (e.g., by an admin or user), then when LAPS next attempts to rotate the password — it will likely operate with an outdated expectation of the current password.Will this mismatch disrupt LAPS password cycling?Does LAPS handle this edge case gracefully or will it fai
Hi All, how to triggar configuration profile from App in self service portal? Thank in Advance
is there anyway I recover Apple Devices Warranty in Jamf pro as Mass load without a GSX Account? Thank in Advances
Good day all, What is everybody’s current/past solutions for PKI and SCEP for Apple. Specifically for EAP-TLS. If you are a mixed enviorment, please also share! Currently using step-ca for everything Apple with JAMF Pro aswell as ChromeOS and Intune devices. Moved away from AD CS and NDES. However, currently on the hunt for a hosted Cloud solution. Share your thoughts, solutions and challenges.
Hi,I need to delete all classes in Jamf pro imported by ASM. Does anybody have a working sh. script?I have used this one below but getting in terminal this error "-:1: parser error : Document is empty" #!/bin/bashjssUser="xxx"jssPass="xxx"jssURL="https://xxxx:8443"echo "Downloading list of class IDs..."ids+=($(curl -X GET -s -k -u "$jssUser:$jssPass" "$jssURL/JSSResource/classes" | xmllint --format - | awk -F'>|<' '/<id>/{print $3}' | sort -n))for n in "${ids[@]}"; docurl -kvu $jssUser:$jssPass ${jssURL}JSSResource/classes/id/$n -X DELETEdone
Hey, I’m curious if anyone has come up with a way to build a smart group that can report specifically on apps located in ~/Applications, since /Applications currently only shows system-level applications.
I have always used JSSConduit to purge old classes to learn JAMF no longer accepts basic authentication. Support sends me the below script to run without explanation. I am a network guy who also manages Jamf, and par for the course Jamf Support falls short. As I stated, I am not a JAMF scripting expert so I am only looking for a detailed procedure on how to delete the classes which typically took me 5 minutes has now lingered for 3 weeks. Any expert advice / instructions would be appreciated. Script below:#!/bin/bash #################################################################################################### # # THIS SCRIPT IS NOT AN OFFICIAL PRODUCT OF JAMF # AS SUCH IT IS PROVIDED WITHOUT WARRANTY OR SUPPORT # # BY USING THIS SCRIPT, YOU AGREE THAT JAMF # IS UNDER NO OBLIGATION TO SUPPORT, DEBUG, OR OTHERWISE # MAINTAIN THIS SCRIPT # #################################################################################################### # # DESCRIPTION # T
Hello, I’m Radhika Sharma, and I manage an online textile business specializing in Jaipuri Print Fabric and Discharge Hand Block Printed Fabric. I’m exploring ways to manage both inventory and Apple devices (like iPads and Macs) used in my business operations using Jamf Pro.Specifically, I need help with: Device Management – Setting up Macs/iPads for employees handling stock and orders. Inventory Management Solutions – Integrating Jamf with inventory software or systems for better tracking and automation. Any advice on how to effectively use Jamf Pro in a retail or business setting would be greatly appreciated!Thanks in advance!
Hello every one,Trying to make a bash script for adding a printer via Self Service. Some things is easier to solve and others not. :)In this case I’m trying to fill out the following string to complete a command for a script.lpadmin -p <destination> -E -D <destination> -v <device_uri> -m everywhereThe problem for me is what to set within all the < >, the printer in question is named followme and is a papercut-printer/que (follow me).I’ve already run a command in my terminal that lists alot of parameters for the printer in question but I get rather unsure what to put where. Anybody able to help med out a bit? :)
Join Chris Schasse (you know, the guy steering the Rocketman Tech ship 🚀) for this month’s LaunchPad on Friday, Aug 8 @ noon MDT. We’re talking Blueprints, Compliance, Jamf’s new AI stuff—and why it’s all locked behind Jamf ID.Expect honest takes, a few laughs, and time for live Q&A.🔗 Sign up free: https://rkmn.tech/m-launchpad
I was wondering if it was possible to make the footnote under "Lock Screen Message" (section for the configuration profiles) bigger as we have users who cannot read text as small as it is.Alternatively is it possible to in some way (maybe a script) push a lock-screen/pop-up notification with a message if a user enters their pass code wrong too many times and gets locked out? Thanks!
Hi All,Windows admin here, thrust into a mixed environment consisting mainly of Mac’s. I’ve worked with Intune for a few years now, but Jamf/managing macOS is totally new to me. Looking forward to learning a lot, but I was wondering what everyone wishes they knew at the beginning of their Jamf journey?
Today we released Jamf Connect 3.2.0; this release includes the following changes and improvements:Identity Provider Support for RapidIdentityJamf's RapidIdentity is now available as an officially supported cloud identity provider (IdP) for the Jamf Connect login window and Jamf Connect Configuration. For more information about configuring RapidIdentity as your cloud IdP, see Integrating RapidIdentity's Identity Automation with Jamf Connect. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hey Jamf Nation!Jamf Pro 11.20.0 features new keys and updates for Apple’s new Operating Systems coming this fall. There are also great updates to SSO features and functionality, updates to new APIs, and more!How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher.Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hi,We are working on implementing Managed Blocking of Macros in Office365. My task was to to have every user (not computer) have the Macro Security locked to "Disable all macros without notification" There was also to be an exclusion group for users who would not be controlled by the above lock. For the exclusion group, we wanted if possible for them to be locked instead to "Disable all macros with notification" as that setting allows a user to enable macros on a document by document useI also had to make this work with Entra or our On Premises Active Directory (to which the Mac's are bound). As there's no linkage yet with Entra I've focused on Active Directory (AD)I found that the settings for this in the Configuration Profile only work on a "Computer Level" even though they seem to be User settingsMy Configuration Profile looks like this:This works but generally takes a few minutes for the machine to pick up a change in the group from ADIf I try and make a second Config Profile an
Hey everyone!I'm reaching out for guidance on a complex issue I've encountered with integrating Jamf Pro and Microsoft Entra ID for SSO, specifically regarding user attribute mappings and device enrollment processes. Despite a successful setup of Single Sign-On and Cloud Identity Providers for new macOS device enrollments with corporate credentials, I've hit a stumbling block with more detailed configurations.Core Issues:User Attribute Mappings: My goal is to map the User Name attribute to the onPremisesSamAccountName (essentially, the UPN without @domain.com) for a more intuitive username representation. Additionally, I aim to map Phone attributes to mobilePhone and Position to jobTitle, enhancing user profile completeness within our system.Device Enrollment Customization: During the Setup Assistant phase of Automatic Device Enrollment (via ABM), I intend to pre-fill the primary account information with the device owner's details. However, the system defaults to using the UPN/email fo
I am attempting to use SSO Enrollment through Enrollment Customization, but having issues with getting the desired Full name and Account name (Home folder).The Account name is always the user’s full email address.I am NOT using Jamf Connect. Using Entra ID as IDP. I am using pre-fill from Pre-Stage Enrollment for the user account.johnsmith@email.comThe goal is for Full Name to be John Smith. And Account Name to be johnsmith.I’ve tried checking and unchecking pass through Jamf Pro to Jamf Connect with different attributes. (I know I’m not using Connect, but I’ve been running out of ideas). This always places the proper Full Name and always the the email for the Account Name.I adjust the IDP attribute mapping to change the username to mailnickname. This tests properly and the username appears as johnsmith. It pulls User & Location from my directory properly when I do a search by just the nickname. When I go through enrollment customization though, it still places the full email as th
We’re Trying to force OneDrive to sync Desktop and Documents on our Macs using Jamf. machines aren’t domain-joined. They’re already signed into Outlook/Teams with their work accounts.Here’s what I’m trying to do: Auto sign users into OneDrive Turn on Known Folder Move (KFM) for Desktop/Documents Avoid macOS prompts asking for folder access What I’ve done so far: PPPC profile – I used the correct code signature from the OneDrive app (verified with codesign). Gave access to Desktop, Documents, and Downloads. But the profile fails to apply in Jamf with a status of “Failed”. Script – I’ve got a script that reads the signed-in email from Office apps and uses the odopen:// URL to trigger OneDrive login. It runs, but OneDrive either doesn’t sign in or doesn’t start syncing unless the user manually clicks through prompts. Where I'm stuck: PPPC profile won’t install, even though the code signature looks right. Even if OneDrive opens, syncing doesn’t start unless the user allows folder a
I’ve got a weird issue with MS Defender Configuration Profiles applying/Un-applying intermittently. As part of our enrollment process we install MS Defender and apply Configuration Profiles. This has been working fine for close to 12months.Now for some reason even though the Configuration Profiles are still applying (You can see them in Device Management). The configuration doesn’t always apply even when it does apply the settings can stop taking affect shortly afterwards.Device Management still has the Configuration Policies applied.I’ve tried downloading fresh configurations, onboarding etc. from Microsoft with exactly the same result. Has anyone else seen this?
Suggestions needed for this query...
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!