Get Support
Recently active
Hello all,Just come to reimage my first computer lab of the year.Figured 'this lab now has M4 Mac mini's in it... that means I can use the Wipe Computer MDM command', as this is essentially doing an 'Erase all content and settings' - something I have previously done manually.8 of the devices wiped, reactivated, then started up just fine.The other 12 have SOS orange blinking lights on the front - apparently in DFU mode because something broke.I don't normally have to do this DFU business, so I'm connecting a USBC, loading Apple Configurator 2... and I'm going through the motions.After downloading and attempting to install, it failed presumably because my Macbook is on Sonoma, and it wants to be on Sequioa - now waiting for macOS to update.What a hassle! Is this a known bug?Hard to imagine I messed something up here. Ya press a button, enter a code... device wipes itself.Anyone been in this situation care to mutually vent frustration with me on the forums?
We are excited to share the most recent updates to our Privacy Policy which were made to enhance transparency around how Jamf collects, uses, and protects personal data, particularly in relation to our responsibilities when acting as a data Controller. We have tailored the language to reflect this and have made improvements to the overall structure and writing style of the policy to make it easier to read and navigate. In line with evolving privacy regulations, we have also added a new section outlining privacy rights for residents of the United States. The language relating to AI-powered features has also been updated to better explain how data is used, while maintaining our commitment to responsible and secure innovation. We have also added to the explanation of our lawful basis for processing personal information. You can access the updated Privacy Policy on the Jamf Trust Center Privacy page. If you have any questions or concerns, you can contact our Privac
Managing macOS devices in a large-scale enterprise environment always need IT expertise. Even with a powerful MDM like Jamf Pro, IT admins often need to dive into the command line to truly get to the root of issues. In this blog, we will walk through real-world command-line troubleshooting techniques for both macOS system issues and Jamf Pro management. Whether you're dealing with failing profiles, app crashes, or failed policies, this post has your back with real commands that work. Getting Started: System Info at Your Fingertips Before troubleshooting, gather critical system details: Get system version: sw_vers List all installed system updates softwareupdate –history Hardware overview system_profiler SPHardwareDataType Check uptime uptime Check disk usage df -h Network Troubleshooting Network issues
This ERB Secure Browser app require Screen Time permission. Our students are standard account. Is there a way to allow Screen Time or any ways to solve it?
Historically, after your jamf pro sign-in timed out, when you returned to the login page, it would sign you in automatically. With the new jamf admin sso integration, every login attempt requires you to type your full email. it only takes a few seconds, but when I have to do it 6 or 7 times a day, it starts to add up.
say i have 10 configuration profiles and 2 of them happen to have ENERGY SAVER settings. Names of the 2 config profiles with energy saver settings are below. Which one of them gets their settings applied to the mac laptop? Gaming Energy Saver. (Battery: sleep 30, display sleep 30) (Adapter: sleep 30, display sleep 1 hour) Action Energy Saver. (Battery: sleep 15, display sleep 10) (Adapter: sleep 15, display sleep 10)
Recently whenever i try to install displaylink manager via Installomator i run into this problem where it always fails at the package verification. Every other Installomator installation works perfectly fine only displaylink manager doesnt.Here is the output of Jamf:ERROR : displaylinkmanager : ERROR: Error verifying DisplayLink Manager.pkg error: DisplayLink Manager.pkg: rejected source=no usable signature 2025-06-16 10:07:02 : REQ : displaylinkmanager : ################## End Installomator, exit code 4Is there a problem with displaylink manager or is it a problem with me?
Hello! I am looking to disable the first "transfer your data" prompt before the enrollment screen on macOS. (Seqouia) When I wiped my device from JAMF PRO management portal after upgrading to Seqouia, I noticed BEFORE the enrollment screen, a "Migration Assistant" - "Transfer your data" prompt. How can I disable this prompt before enrollment? I have PreStage options disabled to NOT show transfer wizard (pictured) - confirmed the device is getting the proper prestage profile. And when enrollment pops up, and I finally enroll, I can confirm the migration assistant\\Transfer your data does not prompt.
Hey everyone! 👋 I wanted to share a project I’ve been working on, now available on GitHub:🔐 Jamf Automatic Admin Password Generator This script is designed to securely rotate the password of a local admin account on macOS devices managed by Jamf Pro. It handles everything from password generation to encryption and inventory reporting, making it ideal for IT admins looking to improve endpoint security without manual effort. ✨ Key Features: Generates strong passwords using two random words + creative suffix Applies leet-style substitutions for complexity Mixed casing and ensures minimum 20-character length Updates the local admin password securely Encrypts the password using AES-256-CBC Saves encrypted password to:/private/var/tmp/encrypted_localadmin_password.txt Triggers jamf recon for inventory update in Jamf Pro 🛠️️ Configuration Highlights: adminUser: The local account to rotate (default: admin) encryptionKey: Your custom AES
(Not Jamf Pro specific but I figure this is the most appropriate channel) If you've been using Microsoft AutoUpdate (MAU) to manage updates to Office for Mac you might have noticed that your Office apps have been stuck on the October 2023 Office 16.78 release (the last release to support an Office 2019 license). This appears to be due MAU's license detection mechanism failing to properly detect a Microsoft 365 Subscription license since MAU 4.65 released in November 2023. If you aren't seeing the post 16.78 Office releases, and your users have Microsoft 365 Subscription licenses, deploy a Configuration Profile with an Application & Custom Settings payload for the com.microsoft.autoupdate2 preferences domain and the .plist: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>AppCustomPref</key> <dict>
Hi all, I've seen various threads on this, some dating back to years ago, and I was hoping to get some concrete suggestions on the most efficient way to go about this. We're wanting to deploy only the VPN, Umbrella, and AMP portions of AnyConnect, along with their respective config files from our organization. I've seen seen mention of using the Packages app, as well as Pacifist, but going that route leads to the com.apple.installer issue. I've tried a myriad of different things, but I can't seem to get it setup without issue. Any insight is greatly appreciated!
Hello, we use Cisco AnyConnect 5 on our Mac systems. The one feature I've been unable to get working so far is our VPN management tunnel. We have the management tunnel configured by an XML file on our Windows systems but I can't find any information on where exactly it should go in MacOS (we're running 13.5.2) or how I can use Jamf to push this profile to make sure the management tunnel connects, even before login if possible.Any suggestions?
Hi Guys, I'm trying to deploy SentinelOne and followed all the steps in the HCSOnline PDF, but I'm still getting an error. I've attached a screenshot of the error. Any advice or help would be really appreciated! Thanks in advance!
I can't see the new setting that was deployed in the 11.17RC unless this was pulled? "Jamf Pro now includes a new page that enables administrators to set Self Service+ as the default application and remove Self Service Classic from managed devices that meet Self Service+ requirements. Self Service Classic remains installed on computers that do not meet Self Service+ requirements. To enable Self Service+ deployment from Jamf Pro, navigate to Apps ⇨ Self Service+, then select "Use Self Service+ as the default end user application."
Hey all, We’re currently testing Jamf Connect Login as part of a move to improve our remote deployment process. We haven’t previously used Jamf Connect at login. Currently, devices enrol via ADE, IT enters the user’s name and password, and setup begins with macOS Onboarding. This then installs the Jamf Connect menu bar app for password syncing, which works well - but we’re aiming for a more seamless experience, especially when sending laptops directly to staff. The goal is to let users authenticate directly with Entra ID (Azure AD) during setup, allowing the account creation process to be automated, reduce mistakes, and speed things up. After that first login, we’d like the Mac to: Revert back to the native macOS login window No longer use Jamf Connect Login Keep the Jamf Connect menu bar app (Self Service+) running for password sync, SSO token refresh, etc. I’ve tested removing the config profile and LaunchAgent, which removes the settings — but the login window still s
Hi everyone, I'm looking for a reliable best practice for a common administrative task: automatically clearing the contents of the Desktop and Downloads folders for our standard (non-admin) student users every time they log in or log out of a MacBook. I attempted to resolve this by deploying a shell script directly through the Jamf School "Scripts" module. However, after pushing the script to the MacBooks, it did not successfully clean the files from the target folders upon user login or logout. Environment: MDM: Jamf School Device Platform: macOS (currently on macOS Sequoia 15.5) Target User Accounts: Standard, non-admin users Here is the script I used: #!/bin/bash target_users=("student_ac" "public_user") current_user=$(/usr/bin/stat -f%Su /dev/console) if [[ " ${target_users[@]} " =~ " ${current_user} " ]]; then find "/Users/${current_user}/Desktop" -mindepth 1 -exec mv {} "/Users/${current_user}/.Trash/" \\; find "/Users/${current_user}/Downloads" -mindepth 1 -exec mv
We like to use Patch Management for whatever we cannot patch with app installers but will use Patch Management for reporting even if there is an entry being used in app installers. Sometime early last week we noticed that Microsoft Teams was listed in patch management as having the latest be 25122.1207.3700.1444. App installers never updated and even this morning it still reports 25107.1606.3643.3915 while patch management says 25151.505.3727.5755 is now the latest. I'll give that a little leeway since it says 17 min ago. It reads to me like patch management has a system in place for Teams that keeps it on top with the latest version but app installers not so much. At any rate it seems a bit strange for patch management and app installers to not be in sync. On a related note Jamf Connect 3.0 was recently released yet patch management says 3.2.0 is the latest and there is no 3.0 listed. Jamf Connect Login is listed as 3.0.0 and so is Jamf Connect Configuration. This confu
Hi, I have the problem that my users often dont comply with some policies, like if they received a new device they have to return their old device within 14 days. Many of them just ignore that and my bosses are of no help here. Is there a way to just annoy them via a pop up or something so that they are more willing to return items borrowed from IT or their old Computers, when they finished migrating to a new one? Or any other way to apply soft pressure?
Hey all, I have an issue where I'm trying to write some automation scripts that cross-reference Mac app restrictions with Mac end users' device app inventories. I can query for the list of 'App Store' Mac apps and also 'Restricted Apps', but not the Jamf Catalogue/Software Catalogue apps that we have added to my company's instance. I've looked into this and apparently the deprecated endpoint "api/v2/patch-software-title-configurations" bears a list of applications that have overlap with the Jamf App Catalogue. Are there any current functions/endpoints or even workarounds that are able to get me this software catalogue?
Hi I've created this script utilizing the jamf API to wipe some 2015 intel MacBook Airs, but it's locking the devices instead of wiping them. I using the existing json format since the classic api's erase command has been deprecated. What am i running into here? ` #!/bin/bash # Define credentialsresponse=$(curl -v -u "GVC4_API_Admin_Migration:Change2025" https://gvc4.jamfcloud.com/api/v1/auth/token -X POST)bearerToken=$(echo "$response" | jq -r '.token') # Device IDscomputerIDs=(2403 2636 2619 2595) for comID in "${computerIDs[@]}"doecho "Sending erase command to computer ID $comID..."#curl -X POST \\#-H "Accept: application/json" -H "Authorization: Bearer ${bearerToken}" \\#"https://gvc4.jamfcloud.com/JSSResource/computercommands/command/EraseDevice/passcode/123456/id/$comID"curl -X 'POST' \\"https://gvc4.jamfcloud.com/api/v1/computer-inventory/$comID/erase" \\-H "Authorization: Bearer $bearerToken" \\-H "Content-Type: application/json" \\-d '{ "pin": "123456" }'done `
Hey everyone, I need to get a list of installed software on our ends users' macs .. the way I know of is by going to computers in Jamf Pro dashboard => Search => Export => I choose the file type => Applications then I get a list of software installed but this one also contains the build-in apps like Weather, Calendar .. etc I can filter it myself but thought to ask and see if there are better ways to get what I want. Thanks in advance
How is everyone handling making sure certain apps are always installed on macOS? For example, we have an emergency notification/management app that every computer has to always have installed. We have done this two different ways and I'm wondering if there's something better. Option 1: Policy to install the app and then do inventory update. Trigger is recurring check-in and frequency is ongoing. Scoped to required groups and an exclusion set to a smart group with criteria that the app is installed. Option 2: Policy to install the app. Trigger is recurring check-in and frequency is ongoing. Scoped to a smart group with criteria the app is not installed. I feel like both ways create a lot of extra overhead on the server and the device with all of the inventory updates and if the app reinstalls itself multiple times before JAMF catches the inventory update, especially with multiple apps that are required on the device. I think option 2 with a frequency ch
Hi Jamf Nation,I’m reaching out to this great community for advice and suggestions as I prepare to launch a Jamf consulting business focused on macOS management, automation, compliance, and security. With over 10 years of experience in Apple IT and recent Jamf 400 certification, I’m looking to turn my expertise into a service that helps organizations streamline and secure their Apple environments. My goal is to support companies in areas such as: Jamf Pro setup and optimizationJamf Protect deployment and alertingJamf Connect integration with identity providersAutomation of routine tasks and workflowsCompliance reporting and endpoint security best practices I’d love to hear from anyone who has started a similar journey. Specifically, I’m looking for: Tips for setting up your consulting structure (freelance vs. LLC, contracts, billing tools)What services clients value the mostLessons learned from your first clients or projectsRecommendations for tools or templates you use (reporting, doc
I’ve implemented Jamf Trust in my test environment and would like to clarify its primary function. Could you confirm whether Jamf Trust is primarily used as an authentication mechanism, or does it serve a different core purpose?
How are y'all tracking and deploying these ever more frequent updates? For point releases we use Nudge, but have not found a way to do so for rapid security responses. Also, the following is not populating. we are on jamf pro release 10.47.0 in a cloud hosted environment. I had thought that this would be reported starting in 10.46 with declarative management (which is enabled).
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!