Get Support
Recently active
As a follow-up to a recent email all Jamf Pro customers should have received, some IP address have been added and removed from the Inbound/Outbound traffic from Jamf Cloud list. For a complete list, please see the “Permitting Inbound/Outbound Traffic with Jamf Cloud” document located here:Permitting Inbound/Outbound Traffic with Jamf Cloud - Technical Articles | Jamf For a list of only the updates, please see here:IP Address and Domain Changelog for Inbound/Outbound Traffic with Jamf CloudIn order to provide ample time to make these changes, we are requesting these updates be made by August 20, 2025.
Hi I'm trying to make a Smart User Group that takes all Managed Apple Account that ends on our primary domain. I'm using the following Criteria "Managed Apple ID - matches regex - .*aau\\.dk$", but for some reason it only takes 92 out of the 129 users we have with a Managed Apple Account. For example I have a user with the following information in the Roster tab that's not added to that Smart User Group: I have also tried just using "Managed Apple ID - Like - aau.dk" and that still does not add all the users. Any ideas? //Kenneth
Hey all,I am using the script below to install Maya 2024 and activate it using a network license. This is the script we used for the past 3 years. I've made the necessary changes to the script (product key, year, server), double checked things a few times and still can't figure this out: #!/bin/sh#Instructions for next time#Copy installer app to /tmp using Composer package#Modify values below as necessary (Usually: year pKey and serial)#Make sure to check pkgPath1-10 match latest installer#Set variablesyear="2024"pkgPath1="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Licensing/AdskLicensing-13.3.1.9694-mac-installer.pkg"pkgPath2="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Licensing/adskflexnetserverIPV6.pkg"pkgPath3="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Maya/Maya_AdLMconf2024.pkg"pkgPath4="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Maya/LookdevX.pkg"pkgPath5="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Maya/MayaUSD.pkg"pkgPath6="/t
Join us for the first ever South Florida Mac Admins meetup including dinner, drinks, and bowling. This is a casual event for folks who manage and support Apple Devices in enterprise and education to network and get to know one another.https://www.eventbrite.com/e/mac-admins-south-florida-kick-off-tickets-597257101067
We're testing Platform SSO with Entra, we can get the Intune machine to login & create new accounts, but it seems to be removing admin rights on the accounts if they were previously enabled (like our local admin account). I recall jamf mentioned something about this being a potential issue - but I haven't found much on how to change the behavior. Does anybody have any recommendations?
Hello,I have been searching online and through forums but I cannot find any useful information on if anyone has gotten the desktop/folder automatic syncing to work for Mac devices via Jamf? The Plist configurations I am pushing is not working. All the previous posts concerning this topic have gone cold. Has anyone been able to successfully implement this configuration and if so, can you guide me on how to complete this process?
So with the below permission, if we disable it like the below photo will we still have access to Blueprints and Compliance benchmarks? If so what are the negatives in doing so? An Enable authentication with Jamf ID setting has been added to Settings > Single sign-on > OIDC IdP integration, and is enabled by default in environments integrated with OIDC-based SSO in Jamf Account. You can disable this option to force users to use their SSO credentials to log in to Jamf Pro.
Hi We are transitioning to enabling FileVault by Configuration Profile once Mac is enrolled via DEP. All is well, except we cannot add other authorized users to fileVault using the FileVault System Preferences --> Enable Users button. I just click the "Enable Users" button and it does nothing. Any ideas??? What is best practice for getting an end user and a local admin account enabled for FileVault. We are testing with Mojave 10.14.6
Hi, Since 18.4 on iPads at least they now automatically reboot after 3 days of being idle. This is annoying as it drops them from the Wi-Fi preventing them receiving any MDM commands until they are unlocked. Typically, in the holidays we clear the passcodes on our iPads that are kept in school and schedule the update to the latest iPadOS version however as they've been idle over the bank holiday weekend, they are now all disconnected and unable to receive commands. According to Apples MDM Commands page there is a 'Allow Idle Reboot' command, but I can't find any documentation about it at all. ChatGPT came up with a .mobileconfig file but I've no idea where it pulled it from as there's only one result on Google for "Allow Idle Reboot" and it's the above webpage! I've deployed the .mobileconfig file to a test iPad (it shows up as 'unknown payload' but I've got to leave it 3 days before I know if it worked so I was curious if anyone else has had these issues? Thanks
It seems that on or about 6 May 25, and for whatever reason, endpoints seem to have stopped communicating with our cloud instance. After pulling logs, and running analytics, I found references to "JWT Null Key error" pertaining to "MDMActionFactory," which seems to mean our cloud instance couldn't sign--well, anything. Didn't catch it sooner because, and "song as old as time, tale as old as rhyme," ours is very much a Windows-first enterprise--meaning we're forced to install a number of agents upon our managed Mac endpoints--because InfoSec says... So we thought it was that...Turns out it was both.This past Friday evening our push proxy cert was renewed, and we pulled the trigger on the 11.17 upgrade... Now, a scripted DDM sync against all managed endpoints runs to completion (it wasn't before these referenced changes), as does a scripted command to cancel all failed commands...Despite this all policies still indicated a "pending" status... There shouldn't be anything in the way any lo
Can anyone advise what would happen if a policy name was changed? For example, if I needed to rename "10-Install Chrome" to "210-Install Chrome", would it remove the package that was installed by the first policy and reinstall the same package under the 2nd policy? And am I correct in assuming that removing a policy does NOT remove the installed app? We're renaming them so that we can properly sequence the policies (e.g. anything with 0XX are pre-app installations, anything with 1XX are required app installations, anything with 2XX are for specific labs, etc).
Hello, I keep encountering the problem that when I register iPads in our Jamf School environment, they install apps for a while and then freeze. (App status is "waiting") At that point, you can no longer control the device via Jamf School (e.g., refresh or restart). The devices were manually registered in Apple School using Configurator 2. Is this phenomenon known to you, or can someone help with this? Best regards
As this is already working correctly again, it's not really a super urgent issue and I mostly found it a minor annoyance that required a trip across town to my office from the site I was working at. Here's the scenario: I was working on a couple of iPads that for reasons I won't get into needed a physical touch. After wiping them through Jamf I noticed that Self Service and all the apps scoped to the smart group it was in were taking their sweet time installing. I looked up the device records in Jamf and saw that the apps wouldn't install because there were no licenses. I thought, "that's weird, there should be plenty," and checked in VPP, only to discover that *gasp* all our app licenses were zeroed out. Everything in the Content tab under all categories, just showed "0" for Total, In-Use, and Reported.Panicking slightly, I headed across town to my office and called Apple Support first while I got logged into ASM. The licenses were all there. So why aren't they being seen in Jamf
I noticed for our Shared iPads that screen recording is not available in the Control Center. I don't seem to be able to change anything in Control Center either. I have been trying to find if there's a restriction profile selection that is enabled that is stopping this but I'm coming up empty. Maybe I'm missing something. Has anyone else had this issue?
Hi all, I have a new interesting development where Self Service fails to load on some student worker profiles on multi-use macbooks. It happens on newly imaged devices and new profiles that were created as well. But it is random. We do not have a special configuration for student worker profiles nor any restrictions in place for them. Self Service as an app is generally available to all users and they should be able to at least load it.We are on macOS Sequoia 15.0-15.5 Is there anything else I can try besides clearing the Self Service cache? /Users/[username]/Library/Caches/com.jamfsoftware.selfservice
Jamf Connect appears to run ldapsearch with a hardcoded nettimeout=1, which is causing delays or failures when trying to update the menu bar with user state after a successful Kerberos authentication. I’ve attempted to increase the timeout by setting NETWORK_TIME 60 in the /etc/openldap/ldap.conf file, but Jamf continues to use the same nettimeout=1 argument, ignoring the config file. Has anyone found a way to override this default or increase the timeout value used by Jamf Connect during the LDAP query?
Have 290 new iPads. The time zone is wrong on all. How to correct this?
Hi allI've inherited a Jamf School environment where users have been manually imported, some with email address but alot without. I'd like to enable Entra ID authentication method moving forward but what would happen to the manually import local users? Thanks in advance
Hi, We have been testing out the Software Update feature the in the last few macOS updates and have run into a few problems with it not triggering on some devices. We are using the "Download and schedule to install" but we can see in the "Operating System History" that around 200 out of 650 Macs running Sequoia has a failed entry in the history. One of the errors we have not been able to find anything about is "Error reasons: SpecificVersionUnavailable" on a device running 15.1.0 and 15.1.1 is available in Software Update on the device. We are using "Latest minor version" when trying to push the install. Anyone seen that error before and have a solution or reason for why that would happen?
Hello Everyone, Just wondering how you guys perform your Mac hardware refreshes currently? We have filevault enabled for all of our end users, but the difficulty we are facing right now is that when an offboarded employee returns their computer. We need to use the recovery key to get past the filevault screen, otherwise there is no way to wipe the computer. Another option we are exploring is to create a new local standard account that can be used to bypass the filevault screen, but enabling filevault for this account via JAMF Pro seems quite complicated to do. Any insights would be greatly appreciated. Thank you.
Hi there, How can I tune Web Protection for not being blocking our company resources? I understand that Web Protection deploy it custom macOS configuration profile and it replace our corporate DNS and users can't access internal company resources. How can I fix it? Where I can add our company DNS servers to Web Protection configuration profiles?
Hello, I currently have a GPO that displays a legal notice on logon for Windows machines. For linux, I have a motd with the same text. Is there a Jamf/macOS equivalent?
In the Restrictions section of Profiles, I see an option for "Allow creation of VPN configurations". I have disabled this as I don't want our users to be able to add VPNs. Is there also an option to disable deletion of VPN configurations? Likewise, is there any way to prevent a user from just toggling the VPN off. Or perhaps automatically re-enabling the VPN if they do turn it off?
I work for a university- they are requiring that we have rotating admin passwords throughout all devices, both mac and windows. We know that Jamf offers LAPS but it looks like from thats setting that it must be scoped to all computers, and we want to simply test it on a few to make sure it works the way we want to before deploying to the entire university. Is this possible? I have also read that FileVault will be affected once this is turned on, which is a requirement that it stays enabled. Is this accurate, and if so, how do I ensure that both LAPS & FV stay intact and working the way it should? Thanks!
Hello everyone! Has anyone configured the AD CS Connector Inbound? We are currently looking at the documentation for the configuration. Does it contain all the information or did you notice anything during the installation that might have been worth knowing? Thank you!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!