Get Support
Recently active
I’m struggling, we’ve got a policy that disables uninstalling apps and system apps, and we have a policy that enables uninstalling apps and system apps.I’ve confirmed the Disable policy was removed from the device and the Enable policy was installed. I’ve confirmed no other applied policies are affecting those toggles (“remove apps” and “remove system apps”)For some reason, the device still won’t let us uninstall apps. What am I missing? We’ve restarted the devices and still no luck.
Hi all!We have been having a very strange problem for a while, the iphones without touching the buttons or starting the recovery mode are formatted from the factory. It does not happen to us in all the iphones devices that we have in Jamf but we have reported more than 15 cases with this problem, we reviewed the configuration and we did not find anything strange. We have configured the installation of updates if the user has not applied the update after 90 days, but these cases occur with all the updates made.Do you know what could be due?Thanks!
Hey Jamf Nation,Happy WWDC week 🎉!The festivities kicked off yesterday with Apple’s Keynote and Platform State of the Union.So let’s dive in…What are you most excited about so far? Either professionally or personally!
Anyone running into an issue with the Shared Device SSOe profile failing to install on shared iOS devices? I set up the Intune integration with Jamf Pro for both shared devices and standard iOS devices. Standard iOS devices register with Microsoft just fine, but don’t actually perform SSO with the Microsoft apps but they do show as compliant in Entra. I had the Shared Devices registering for about two days and now after wipe, The “Install Device Compliance Shared Device Profile” command fails every time even with a different device. Previous Entra records have been removed. Any ideas of what I could try to fix it or where I can find more detailed logs? History of failed commands had nothing.
Hi Jamf Nation,Big news at Jamf. I'm thrilled to share that our Board of Directors has named Beth Tschida as Jamf's new CEO. Many of you already know Beth. She's been with Jamf for eight years, most recently as our CTO, and has served as Interim CEO since March.Beth has been at the heart of so much of what you rely on from Jamf: our cloud platform, our security portfolio, and our eight-year streak of same-day support for new Apple operating systems. She knows this community, she knows your work, and she knows that everything we build has to earn your trust.A quick word of thanks to John Strosahl, who led Jamf through our transition to private ownership earlier this year. John has been a great partner to this community, and we're grateful for everything he's done to set us up for what's next.Also important is what hasn't changed: our commitment to you. Managing and securing Apple at work is what we do, and with Beth leading the way, especially as AI reshapes how we need to think about w
Jamf Icon Uploader is a utility that streamlines the bulk upload of icons to Jamf Pro, eliminating the tedious process of uploading them one at a time. This app was built to solve a common pain point: hosting app icons on Jamf Pro for use with Setup Manager. Instead of manually uploading each icon through the Jamf Pro interface, you can now upload an entire collection in a single operation. • Link: https://hcsonline.com/support/resources/apps/jamf-icon-uploader?ref=macadmins.news
I understand that it’s expected behavior, but when using the “Preserved Apps” option with the Return To Service feature, OS updates can’t be installed.Has anyone found a way to work around this limitation?
Taking a swing at the regex. How is this?iOS/iPadOS 27 (Regex Devices Can't upgrade)^(iPhone(12|13|14|15|16|17|18|19),\d|iPad(8,(9|10|11|12)|12,\d|13,(1|2|1[6789])|14,(1|2|[89]|1[01])|15,\d|16,\d|17,\d))$
What’s new in managing Apple devicesDiscover the latest updates to declarative device management, Apple Business, and Apple School Manager. Explore how these advancements help you streamline deployment, strengthen security, and improve the experience for people using your managed devices. Whether you're building device management solutions or managing enterprise fleets, you'll learn practical ways to take advantage of these new capabilities. https://developer.apple.com/videos/play/wwdc2026/206/
I have trouble under this device ID 116, because It’s failed to delete or looking details in Jamf Pro
We have a few iMacs running Sequoia 15.5 and Jamf Connect that are going to black screens after you log in. Both local user accounts and IdP accounts are affected, but I can see the user folder is being created when we log in against our IdP, I get the account creation message but it just hangs on the black screen. Local admin account is having the same problem. I’ve tried uninstalling, restarting, and reinstalling Jamf Connect, but the problem persists. Uninstalling and logging in as a local admin user causes a beach ball to spin, but it sits there and doesn’t not progress. I’ve checked the config profiles and license and they’re all valid, and this isn’t happening fleet wide, just randomly.if I create a new user through Jamf, the user will create, but I can’t log into that account, it immediately dumps me back to the JC login window without any feedback. I can see the new user’s account by running dscl . -list /Users UniqueID but it still hangs. Resetting authchanger doesn’t help eit
How to bulk lost mode a smart group of ipads in Jamf Pro?I have a smart group but lost mode is not one of the available remote commands?Suggestions?
I am trying to configure Baseline. I can’t seem to get the Global Status Icons to work. For example: Global Status Icon - Fail:SF=xmark.circle.fillGlobal Status Icon - Success:SF=arrow.down.circle.fillGlobal Status Icon - Wait:SF=progress.indicator They don’t show up at all when deploying packages.
Standalone rostering tools sync class lists and stop there. They don't connect to your identity system, SSO, or governance policies, which means gaps, lingering access, and manual cleanup for IT. RapidIdentity handles rostering natively within your IAM platform. When a student enrolls, their identity, access, and rostered apps are all provisioned in one workflow. When they leave, it all unwinds automatically. No reconciliation. No disconnected tools.Identity and rostering working as one system means students get access on day one, and IT stays in control throughout the lifecycle. Want to go deeper?We have new RapidIdentity Studio Academy courses that cover IAM-integrated rostering in detail. A great next step if you want to see how this works in practice. Drop your questions in the comments or share how your district is handling rostering today.
Hello,Currently, the date of the day is displayed at the top of the message, but the subsequent messages do not have a specific timestamp. For better organization and a clearer follow-up of discussions, I suggest adding a precise timestamp (time) to each message. This would help us keep track of conversations more effectively, especially for instructions or immediate feedback.Thank you!
We recently laid off 14 people and were going to gift them their M1 Laptops after they were off-boarded. I issued Lock Computer commands from JAMF Pro to each machine and, to my surprise, found that only 3 of the 14 had actually locked out the user. Luckily, these folks were all friends of the company (sad) and they did not do anything malicious, but I was able to use my TeamViewer link to the machine to go in and ‘removeFramework’ and re-enroll. After that, I was able to wipe the machines normally. Is there a way to get the rest of my machines back into compliance without removing the framework and re-enrolling them, one by one? Will a ‘renewDeviceCert’ work? Thanks.
Last year, I had the extraordinary privilege of travelling to Zimbabwe to meet and teach some of the most driven, curious students I've ever encountered — the cohort at the MATTER Career Readiness Institute (MCRI). If you're not familiar with MCRI, let me explain why it matters. You may already know the Matter Innovation Hubs (MIH): tech-forward, student-centred environments designed to foster active learning and creativity for children who often lack access to critical educational resources. MCRI takes that mission further. It's a post-secondary workforce training program with a bold goal — equip young Zimbabwean students with the skills needed to become software engineers and secure remote employment with Western companies. In an environment where opportunity can be rare, MCRI is opening doors that were once closed, helping students turn potential into power. How the program worksStudents apply from local secondary schools, go through a rigorous selection process, and dive into a cu
I’m just wondering if anyone has got this to work via Jamf Pro on-prem?I’ve created a package deployment of the latest Company Portal, configured the SSO extension profile as explained in the Jamf guide for Entra, and setup the pre-stage enrolment but when I go through the setup on my test MacBook Neo it doesn’t work.It takes over 15 minutes to try and install the Company Portal and then just moves on to the ‘create user’ step. If I restart the MacBook Neo it may eventually pick up the Company Portal and SSO extensions but then after signing in via Entra it shows a “Sign in to your organisation” screen with a box for username and a box for password, which will not accept any kind of credential.I can access the package URL and download the pkg file in seconds via a browser. I’ve reloaded Tahoe on the MacBook Neo and deleted and recreated the SSO extensions, still nothing.Thanks
Hello everyone, IDK if anyone is using the great add on to Macs, but if you are can you help me get 4 Tiles to work? Tile #1 - Submit a Service Desk Ticket - the link is mailto:#servicedesk@mycompany.com. Nothing happens. Tile #2 - Battery - can't get it to display the battery level. Tile #3 - Storage - can't get the amount of storage to display. Tile #4 - Privacy and Security - can't figure put how to open this one. We want end users to be able to open Privacy & Security directly without going through SystemSettings>Privacy and Security. Other than that, it is a great addition to our JAMF program. If you haven't tried it - check it out. https://github.com/root3nl/SupportApp JNUC 2021 release with training: https://www.youtube.com/watch?v=LijCmR6gQAM
Does anyone have any insight to when (or if) Jamf Security Cloud will be available on MacOS and Windows?I see the options as not yet supported, but wondering if there is a timeline on that.
*Trying to get ahead of OS27 and the devices that can’t update*We have a requirement that all Apple mobile devices can support the latest OS update. Based on early reports, we will have 100+ iPads that won’t support OS27. I need to be able to block those devices completely. We have departments that will attempt to keep them, but I need to make sure they can’t use them.Current setup is Jamf Pro for MDM and Entra for compliance. We currently use Smart Device Groups and Entra Conditional Access to block Microsoft apps from devices that don’t meet criteria to be in our compliance smart group. I wasn’t sure if there is a way to completely block in Entra Conditional Access or if there is a way to wipe and ban the device in Jamf Pro. If not, is there a way to block all apps or put it into a kiosk mode if it isn’t eligible for OS27?Any suggestions will be greatly appreciated!
I am gradually learning how to work with blueprints. I have had success managing software updates with blueprints, so I decided to try out restricting external drives to read-only access. I want to stop controlling this using Proofpoint DLP (which I think is crapware) and start controlling it with blueprints.After configuring the blueprint, I deployed it to one of my Macs, then connected two USB drives. Neither drive appeared on my desktop. I opened Disk Utility and found both there. When I clicked to mount each of them, they would not mount. I saw no errors. They just won’t mount. As part of my testing, I uninstalled Proofpoint DLP, which is being used currently to make external drives mount as read-only. Before scoping the blueprint to my Mac, I confirmed that I could mount drives and write to them. I just recreated this on a second Mac. It’s the same issue. Proofpoint DLP is removed. The blueprint is installed. A PLIST was created at /private/var/db/ManagedConfigurationFiles/DiskMan
I have JAMF pro cloud instance and when I enroll new device using PreStage Enrollment, all my 12 application installations show ''background items added" notification on the right side of mac devices. can we mute these notifications?
I am trying to install sophos through JAMF School and used their script.The script it working fine when running it on the mac as sudo, but when i try pushing it through JAMF, nothing happens.This makes me wonder if i am missing something, i seem to be unable to make the app run as an administrator/sudo user.Can anyone help?
Hello,I'm trying to understand the recommended workflow for a school using both Microsoft Entra ID federation and Apple School Manager / Jamf School synchronization.Current setup:Apple School Manager is already federated with Microsoft Entra ID. All Managed Apple IDs have already been created successfully. We currently have only one ASM location (the original/default location). Jamf School is already connected to ASM and synchronized with that location. Our goal is simply to create and synchronize classes/rosters for Apple Classroom and Jamf School.The issue:If I manually create my classes in Apple School Manager and assign students and teachers to them, everything works correctly after the synchronization between Jamf School and ASM.However, how should this be handled when using a OneRoster/SFTP import into Apple School Manager?When I enable SFTP / OneRoster synchronization from Jamf School to Apple School Manager, ASM creates a new location instead of associating the imported classes
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!