Get Support
Recently active
Good Day!I am testing Platform SSO out in our environment and so far it is working great! We are pushing out MSCP via the Jamf Mac Apps. We’re using “Password” as our authentication type. Setup with Entra. And we do not currently have any custom config, just out of the box setup. Our machines are NOT Bound to AD, and we use local standard user accounts to start off with. then register and sync passwords. I have 2 major issues that I would love to hear from the hivemind:We are seeing that we can put in many bad passwords at the login screen without any repurcussions. If the machine was compromised, what is stopping someone from brute forcing the correct password? Is there a way to set password attempts? When a user’s password changes they can obviously go re-authenticate and sync their password again, but what if a user just ignores this and never syncs their password? Meaning whatever their password WAS is what they are using to Log In and then use a different password for their AD Ac
I wanted to start a new post due to all the interest in some older posts. We are about to start a closed beta test of an app we built to help address a hole we saw in the digital signage space. We wanted a way to simply connect Google Slideshows to Apple TVs and we couldn't find a solution that fit our needs. So we built our own solution. Our app, Simple Signage, is a easy way to connect Google Slideshows to Apple TVs. You just copy the share link into Jamf, set the intervals for the slides and how often you want the slideshow to refresh. That is it. It has worked so well for us all year, we decided we would share with the community, but first we are hoping a few people will help us tryout and test the app. If you are interested in our app Simple Signage and would be willing to help us beta test it through TestFlight, just respond here and I will message you privately with more information.
I am using Jamf Pro and ran tests to get Microsoft Defender installed on our Macs. However, we’ve now decided to go a different route and I need a way to automate the removal of Defender. It was installed via a PKG and a policy in Jamf Pro. I have tried running a sudo rm etc to remove the app but that returns “operation not permitted”. I am an admin on my device and all our other users with defender are as well. I read that I might need to give Terminal full disk access, so I did. That didn’t work. I also then revoked full disk access from Defender, that didnt’ do anything either. I’m not sure what script I need to be running in Jamf to get this gone.
I have this specific need to keep the Google Drive app version to 77.0 but it keeps updating to version 110.0 (latest).I’ve already removed the device from the Smart CG linked to the GDrive app on the Application section but it still automatically updating.Is there something I can do to solve the issue?Thank you
We have a small yet nice enhancement available as of today - you can now edit the benchmark description after creating the benchmark.This means that only the benchmark name cannot be changed once the benchmark is created (as it is used in all generated objects names). We therefore encourage you to pick a more general benchmark name and use the description (which is also visible on the benchmark card) to better describe the benchmark purpose - e.g. scope or mode.Let us know how this helps you to manage the compliance of your fleet!
Recently, an end user had their laptop stolen, so once notified i was able to apply a lock to the unit from my instance of JamfPro with a 6 digit code and it’s been a week now and it looks like nobody has tried to get the unit online. Long term can anyone suggest what i should do? I don’t expect to ever get the unit back so should i remove it from JamF?? Umberto
Hey Jamf Nation! My name is Taylor Taylor; I’m from Birmingham, Alabama. I am wondering if there are any Jamf Heroes in Alabama or the South. I’m curious to find out and would love to connect.
Would love to connect with you all, share experiences, and maybe even collaborate on some cool stuff. Feel free to drop a message or say hi! 😊Thanks...
Hi all, We have quite a weird recurring issue with 3 mac devices. FileVault is set to enable via a configuration profile from UIE//ADE and this has been working good since we introduced Jamf. We are however having issues where the secure tokens assigned to these users are being removed? I was wondering if this is something that anyone else has seen? The accounts a mobile accounts from AD. All of the mobile accounts on the devices are struggling. The workaround currently is to sign in with the local account that was created for support (has securetoken key) and then log out. Falling short of disabling FileVault for these devices, is there anything else any one can think of? Thanks in advance!
Just be going though the process of updating our Autodesk apps for 2026. its not a script I have written but I have updated for Maya & Mudbox 2026. I found on her somewhere.Thought it was sharing to help other as a starting point. #!/bin/bash#Copy installer app from .dmg to /tmp#Modify values below as necessary (Usually: year and pKey)#Set variablesyear="2026"pkgPath1="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/MayaUSD.pkg"pkgPath2="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/Maya_AdLMconf2026.pkg"#pkgPath3="/private/tmp/InstallMaya2024.app/Contents/Helper/Packages/Licensing/adskflexnetserverIPV6.pkg"pkgPath4="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Licensing/AdskLicensing-15.1.0.12339-mac-installer.pkg"pkgPath5="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/Maya_core2026.pkg"pkgPath6="/private/tmp/InstallMaya2026.app/Contents/Helper/Packages/Maya/bifrost.pkg"pkgPath7="/private/tmp/InstallMaya2026.app/Content
Hello,I know this is probably not the best place to ask that question but as it’s about the beta forums (which are under NDA), I’m asking it in one of the beta forums. With the new Jamf Nation forum, there’s no way to find a link to all the beta forums for which we are a member like we could with the previous version.Do you plan to change this? It makes it hard to find our way back to one of the beta forums because of that. For example, I had some pending topics on the Self Service+ forum before the migration and it’s impossible for me to find them again to check if there has been answers posted.
Hi All,Does anybody know if InTune Cloud PKI integration with JAMF works instead of the legacy setting up NDES on prem?
My Google-Fu is failing me ... How can I enable the preference below from Terminal?
I have been getting requests to provide all managed phones with a contact list. The config page allows me to access a CARDDAV server. I would like some suggestions on how to best set one up, perhaps a cloud solution. Thanks
In case you missed it ... What’s new in Apple device management and identity https://developer.apple.com/videos/play/wwdc2025/258/?utm_campaign=MacAdmins.news&utm_medium=email&utm_source=MacAdmins.news_365
Updated 14SEPT2022 - I moved the GitHub link over to the official Jamf Github - https://github.com/jamf/jamfconnect/tree/main/azure_conditional_access will have the latest until the official Jamf Connect docs get updated.Updated 14JUL2022 - The github link below has been updated with some steps removed for version 2.13 or greater of Jamf Connect, details about custom ROPG scopes in the menu bar, notes on how the login may still show a failure after doing this but that's fine. https://www.jamf.com/blog/how-to-azure-conditional-access-and-jamf-connect/ will supersede instructions currently on the Jamf Blog.Updated 14JAN2022 - The github link below has been updated to simplify the setup of the application registrations in Azure and allows for full testing in Jamf Connect Configuration before deploying to a test machine.https://www.jamf.com/blog/how-to-azure-conditional-access-and-jamf-connect/ - Updated instructions posted to Jamf Blog.UPDATE
Hi folks, I'm looking to create a policy to do the following. Install AWS VPN Client Add Profile with provided .ovpn file. Pushing the AWS VPN Client is easy enough by pushing the .pkg file.Anyone have any experience/ideas for the second part? Thanks!
Hi, We'd like to create an app/script that when run prompts the user to enter an asset tag and then automatically renames the device.I.e. asset tag 12345 renames the device to AG-MAC-12345 so that "AG-MAC-" is already predefined? Is this something that can be done with DEPNotify? TIA.
Our department is rolling out 500 new iPhones and we’ve been asked to provide an “address book” to each phone that will display the caller’s name on the phone receiving the call. These assumes that both the caller and the callee will be using our managed, and supervised, phones. Most of the en users are using Office 365. We also have the option of creating our own address book data entries and hosting them “someplace”. I can see that Casper can push out settings for a CardDAV server, but am not sure if that will do what we need or if there are better approaches. Any ideas appreciated. Thanks. Seth
Hello, So I’m curious about whether we need to have either an LDAP server setup or issue managed AppleIDs in order to utilize user-initiated enrollment.I made a user and user group in JAMF Pro thinking it would allow for enrolling a device and that I could give my end users a single set of credentials to then get the MDM profile and configuration to everyone. However during the enrollment, I get stuck on a page which mentions “Assign to User” with a blue magnifying glass and Enroll button which don’t seem to react, no matter what I enter. Perhaps this is not possible, but it’s what I’m hoping to find out here. Can I use a single JAMF Pro user to log in all my end users for user-initiated device enrollment? Or must we set up an LDAP server/get managed IDs?Context: We are doing a big push for new devices soon, and currently we have no self-enrollment, meaning our IT department would have to manually enroll every phone. We are looking for an alternative solution to avoid that. We do not u
Was upgrading my on prem dev Jamf pro instanace today and was looking into Important notices for the last few releases. I noticed this:11.14.0 Apple announced upcoming changes to the Apple Push Notification service (APNs) Certificate Authority (CA). Organizations using APNs will be required to update their application's trust store to include the new server certificate before 24 February 2025 to prevent communication disruption. For cloud-hosted environments, the root certificate is already trusted and validated. For on-premise environments, you may need to download and install the new SHA-2 Root USERTrust RSA Certification Authority certificate to your server's certificate trust store if it is not already trusted on your hosting infrastructure. For more information, see How to Download & Install Sectigo Intermediate Certificates - RSA documentation from Sectigo per Apple's announcement. Apple has a test server available to allow organizations to send push certificates to v
Hi all,I'm fairly new to Jamf and recently completed the Jamf 100 course. I want to start testing to learn more, and I have a loaner Mac to use but I want to make sure I don’t accidentally affect anything in production.What’s the best way to safely test? Should I ask for a separate test instance from Jamf, or use VMs? Any tips or lessons from those who’ve been in a similar spot would be super helpful.
I have been using docutil for many years at this point (along with BuildADock). It works great. I am building a new lab and it's a weird setup. Not every computer will have the same versions of software installed (mainly Adobe) for some stupid licensing issues. I'm wondering if there is a way to use wildcards in the docutil script? For example, I have three sets of computers that have either Adobe CC 2023, 2024, or 2025. The software installs are the same, but the version year is different. Rather than make different docks for all the variations in the lab, is there a way to use a wildcard so it puts whichever version of Photoshop onto the dock that is installed onto the computer?
Hi everyone,I'm currently facing an issue with AnyDesk deployed via Jamf across our Mac fleet. Initially, I set up an installation policy and a configuration profile for all Macs and users, and everything was working smoothly.However, I've noticed that whenever I add a new PC to AnyDesk and attempt to connect remotely to a Mac, I receive an "Access Denied" message. I understand this isn't the official AnyDesk forum, but I’m hoping someone here might have encountered a similar situation.I’m considering removing and redeploying the configuration profile to see if that resolves the issue—but I’m not entirely sure how to go about it. Would changing the scope to "specific computers" and "specific users" be enough? Could that potentially cause other problems?If anyone has suggestions or has dealt with something similar, I’d really appreciate your input.Thanks in advance for your help!
We need to add a new allowance to our VPN profile that is required for the newest version of our VPN client .I am trying to figure out what exactly happens on macOS when a profile gets updated. Does it remove all the settings the profile sets and reapply, or does it only add/remove changes. I would like it so people do not get kicked off VPN when the profile is updated (The addition to the profile only deals with login items.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!