Get Support
Recently active
So with the below permission, if we disable it like the below photo will we still have access to Blueprints and Compliance benchmarks? If so what are the negatives in doing so? An Enable authentication with Jamf ID setting has been added to Settings > Single sign-on > OIDC IdP integration, and is enabled by default in environments integrated with OIDC-based SSO in Jamf Account. You can disable this option to force users to use their SSO credentials to log in to Jamf Pro.
Hi We are transitioning to enabling FileVault by Configuration Profile once Mac is enrolled via DEP. All is well, except we cannot add other authorized users to fileVault using the FileVault System Preferences --> Enable Users button. I just click the "Enable Users" button and it does nothing. Any ideas??? What is best practice for getting an end user and a local admin account enabled for FileVault. We are testing with Mojave 10.14.6
Hi, Since 18.4 on iPads at least they now automatically reboot after 3 days of being idle. This is annoying as it drops them from the Wi-Fi preventing them receiving any MDM commands until they are unlocked. Typically, in the holidays we clear the passcodes on our iPads that are kept in school and schedule the update to the latest iPadOS version however as they've been idle over the bank holiday weekend, they are now all disconnected and unable to receive commands. According to Apples MDM Commands page there is a 'Allow Idle Reboot' command, but I can't find any documentation about it at all. ChatGPT came up with a .mobileconfig file but I've no idea where it pulled it from as there's only one result on Google for "Allow Idle Reboot" and it's the above webpage! I've deployed the .mobileconfig file to a test iPad (it shows up as 'unknown payload' but I've got to leave it 3 days before I know if it worked so I was curious if anyone else has had these issues? Thanks
It seems that on or about 6 May 25, and for whatever reason, endpoints seem to have stopped communicating with our cloud instance. After pulling logs, and running analytics, I found references to "JWT Null Key error" pertaining to "MDMActionFactory," which seems to mean our cloud instance couldn't sign--well, anything. Didn't catch it sooner because, and "song as old as time, tale as old as rhyme," ours is very much a Windows-first enterprise--meaning we're forced to install a number of agents upon our managed Mac endpoints--because InfoSec says... So we thought it was that...Turns out it was both.This past Friday evening our push proxy cert was renewed, and we pulled the trigger on the 11.17 upgrade... Now, a scripted DDM sync against all managed endpoints runs to completion (it wasn't before these referenced changes), as does a scripted command to cancel all failed commands...Despite this all policies still indicated a "pending" status... There shouldn't be anything in the way any lo
Can anyone advise what would happen if a policy name was changed? For example, if I needed to rename "10-Install Chrome" to "210-Install Chrome", would it remove the package that was installed by the first policy and reinstall the same package under the 2nd policy? And am I correct in assuming that removing a policy does NOT remove the installed app? We're renaming them so that we can properly sequence the policies (e.g. anything with 0XX are pre-app installations, anything with 1XX are required app installations, anything with 2XX are for specific labs, etc).
Hello, I keep encountering the problem that when I register iPads in our Jamf School environment, they install apps for a while and then freeze. (App status is "waiting") At that point, you can no longer control the device via Jamf School (e.g., refresh or restart). The devices were manually registered in Apple School using Configurator 2. Is this phenomenon known to you, or can someone help with this? Best regards
As this is already working correctly again, it's not really a super urgent issue and I mostly found it a minor annoyance that required a trip across town to my office from the site I was working at. Here's the scenario: I was working on a couple of iPads that for reasons I won't get into needed a physical touch. After wiping them through Jamf I noticed that Self Service and all the apps scoped to the smart group it was in were taking their sweet time installing. I looked up the device records in Jamf and saw that the apps wouldn't install because there were no licenses. I thought, "that's weird, there should be plenty," and checked in VPP, only to discover that *gasp* all our app licenses were zeroed out. Everything in the Content tab under all categories, just showed "0" for Total, In-Use, and Reported.Panicking slightly, I headed across town to my office and called Apple Support first while I got logged into ASM. The licenses were all there. So why aren't they being seen in Jamf
I noticed for our Shared iPads that screen recording is not available in the Control Center. I don't seem to be able to change anything in Control Center either. I have been trying to find if there's a restriction profile selection that is enabled that is stopping this but I'm coming up empty. Maybe I'm missing something. Has anyone else had this issue?
Hi all, I have a new interesting development where Self Service fails to load on some student worker profiles on multi-use macbooks. It happens on newly imaged devices and new profiles that were created as well. But it is random. We do not have a special configuration for student worker profiles nor any restrictions in place for them. Self Service as an app is generally available to all users and they should be able to at least load it.We are on macOS Sequoia 15.0-15.5 Is there anything else I can try besides clearing the Self Service cache? /Users/[username]/Library/Caches/com.jamfsoftware.selfservice
Jamf Connect appears to run ldapsearch with a hardcoded nettimeout=1, which is causing delays or failures when trying to update the menu bar with user state after a successful Kerberos authentication. I’ve attempted to increase the timeout by setting NETWORK_TIME 60 in the /etc/openldap/ldap.conf file, but Jamf continues to use the same nettimeout=1 argument, ignoring the config file. Has anyone found a way to override this default or increase the timeout value used by Jamf Connect during the LDAP query?
Have 290 new iPads. The time zone is wrong on all. How to correct this?
Hi allI've inherited a Jamf School environment where users have been manually imported, some with email address but alot without. I'd like to enable Entra ID authentication method moving forward but what would happen to the manually import local users? Thanks in advance
Hi, We have been testing out the Software Update feature the in the last few macOS updates and have run into a few problems with it not triggering on some devices. We are using the "Download and schedule to install" but we can see in the "Operating System History" that around 200 out of 650 Macs running Sequoia has a failed entry in the history. One of the errors we have not been able to find anything about is "Error reasons: SpecificVersionUnavailable" on a device running 15.1.0 and 15.1.1 is available in Software Update on the device. We are using "Latest minor version" when trying to push the install. Anyone seen that error before and have a solution or reason for why that would happen?
Hello Everyone, Just wondering how you guys perform your Mac hardware refreshes currently? We have filevault enabled for all of our end users, but the difficulty we are facing right now is that when an offboarded employee returns their computer. We need to use the recovery key to get past the filevault screen, otherwise there is no way to wipe the computer. Another option we are exploring is to create a new local standard account that can be used to bypass the filevault screen, but enabling filevault for this account via JAMF Pro seems quite complicated to do. Any insights would be greatly appreciated. Thank you.
Hi there, How can I tune Web Protection for not being blocking our company resources? I understand that Web Protection deploy it custom macOS configuration profile and it replace our corporate DNS and users can't access internal company resources. How can I fix it? Where I can add our company DNS servers to Web Protection configuration profiles?
Hello, I currently have a GPO that displays a legal notice on logon for Windows machines. For linux, I have a motd with the same text. Is there a Jamf/macOS equivalent?
In the Restrictions section of Profiles, I see an option for "Allow creation of VPN configurations". I have disabled this as I don't want our users to be able to add VPNs. Is there also an option to disable deletion of VPN configurations? Likewise, is there any way to prevent a user from just toggling the VPN off. Or perhaps automatically re-enabling the VPN if they do turn it off?
I work for a university- they are requiring that we have rotating admin passwords throughout all devices, both mac and windows. We know that Jamf offers LAPS but it looks like from thats setting that it must be scoped to all computers, and we want to simply test it on a few to make sure it works the way we want to before deploying to the entire university. Is this possible? I have also read that FileVault will be affected once this is turned on, which is a requirement that it stays enabled. Is this accurate, and if so, how do I ensure that both LAPS & FV stay intact and working the way it should? Thanks!
Hello everyone! Has anyone configured the AD CS Connector Inbound? We are currently looking at the documentation for the configuration. Does it contain all the information or did you notice anything during the installation that might have been worth knowing? Thank you!
Hi All, I'm working on a solution where customer managing MacBooks using Jamf Pro and having Zendesk ticketing tool. Upon reviewing the environment, found that traditional way of software request or installation is happening. I would like to understand that is that possible that can we integrate Jamf self-service with Zendesk, so that whenever user need of an application then user can request from self-service, and an application requires an approval Zendesk will raise a request on behalf of user and forward to concern member. If approval is not required, then application gets installed automatically from Jamf self-service.
Jamf is offering an incredible opportunity to attend the 16th Annual Jamf Nation User Conference (JNUC) in Denver, Colorado, from October 7–9, 2025. Through the JNUC Diversity Sponsorship program, 10 individuals from underrepresented backgrounds in tech will receive: Full conference registration to JNUC 2025 $500 stipend to assist with travel expenses Exclusive networking events, including meet-and-greets with Jamf leaders Access to expert-led sessions and community-building opportunities Now in its ninth year, this initiative reflects Jamf's commitment to fostering diversity and inclusion within the tech industry. Whether you're an Apple admin, InfoSec professional, or aspiring tech leader, this is your chance to connect, learn, and grow. 🗓️️ Application Deadline: June 30, 2025, at 5:00 p.m. CST📩 Apply Now: https://www.jamf.com/blog/jnuc-diversity-sponsorship/Jamf Don't miss this opportunity to be part of a vibrant community and advance your career in
With Jamf Pro 11.17, use the new app switcher to quickly access other Jamf products, integrate DigiCert ONE Trust Lifecycle Manager to issue certificates, and gain support for IPv6 addresses in inventory reporting! Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements. Thank you for your continued support and feedback! https://learn.jamf.com/en-US/bundle/jamf-pro-release-notes-videos
We've been seeing a weird issue with some of our macbooks that have been sitting on our shelves for a while. These macbooks have been sitting for a couple months now, when we turn them on, go through the basic setup steps country region keyboard wifi. We get to the remote management screen just fine, enter our company creds, sometimes we get to our entraID signin page (jamf connect), or it'l go into a bootloop. Or sometimes we get to the desktop but the macbook becomes an unmanaged device and self service doesnt install and no ability to run any sudo jamf commands as jamf cant be found. (so the MDM doesnt fully install?)To resolve this we have remove our mdm and reinstall the mdm, but sometimes its easier to reimage the macbook as we have the MDM as nonremovable.Any else having this issue?
We are doing a POC for Linewize and running into some issues with access to the VPN System Preference Pane. Test user is a local administrator, as will the production users, no getting around that. I can restrict access to the network preference pane: but then VPN & Filters pane is still available I don't see anywhere that I can restrict the VPN & Filters pane, am I missing something?Ideally I would love to be able to leave access to Network open and restrict VPN & Filters in 2 locations:
Hi All Hoping someone can help.Have found a script for collecting log files using jamf pro API thanks @Travid @david_maestre for updating the script to work with Jamf pro API I belive its based on this https://github.com/kc9wwh/logCollection which no longer seems to work. I belive due to changes in the API.Im getting the below errror is there anyway to make it work without needing Xcode, seems to be using some tools which are part of Xcode. My coding skills arent up to much so struggling to find whats bits of Xcode its using as dont appear to be reference in the script. no developer tools were found at '/Applications/Xcode.app', and no install could be requested (perhaps no UI is present), please install manually from 'developer.apple.com'. Failed to retrieve Jamf Pro Computer ID. #!/bin/bash ## User Variables jamfProURL="$4" jamfProUser="$5" jamfProPass="$6" logFiles="$7" ## System Variables mySerial=$(system_profiler SPHardwareDataType | a
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!