Get Support
Recently active
We need to view usage statistics on each of the Adobe apps we use. I can't figure out how to report the usage in the last 90 days per user. I don't even seem to get very close. Below is essentially what I'm looking for. ComputerName, UserName, ApplicationName, Usage laptop12, jdoe@company.com, Adobe Acrobat Pro, 23 hours If I look at each of roughly 800 computers I can see the pretty charts that claim to show usage. Some level of data is there, but I see no way to export it to make it useful.
Struggling to set this up. The script seems to 'work'. I don't see any erorrs during install. ButI my configuration profile policy is still Pending and nothing seems to be getting pushed. I don't see any particular errors anywhere. Is there a log on the client end that i can check to see what's going on under the hood? If I go to PKI Certificates in Jamf Cloud - I see : "Outbound mode status check The Jamf AD CS Connector last contacted Jamf Pro for pending certificate requests on 03/09/2025 08:12 AM"So I'm assuming there is some sort of connection happening? And at what interval does the outbound AD CS instance check for certificate requests? Is there a way to modify the interval for polling?Any help would be appreciated.
I set a Restrictions configuration profile to disable Find My Mac. I ensured that I'm part of the scope and that the config profile actually installed on my machine. My machine is checking in with no problem. However, I'm still able to turn on/off Find My Mac after the Restrictions profile is installed Anyone having this issue or recommend a better way of disabling? What scares me the most is a user being able to remote wipe their Mac without IT's consent.
Update 08 May 2025: Standard Cloud upgrades are scheduled for the weekend of 16-17 May (details below). We appreciate your patience with the delayed schedule. Today we are releasing Jamf Pro 11.16; highlights include: Compliance BenchmarksBuilt on the macOS Security Compliance Project (mSCP) framework, compliance benchmarks enables you to automatically implement security standards across Mac devices. Compliance benchmarks supports industry-standard frameworks and automatically generates necessary management settings to enforce security controls. When enabled, compliance benchmarks create and maintain device security baselines through a combination of policies, configuration profiles, scripts, extension attributes, and smart groups, eliminating the need to manually configure individual security controls.Important: This capability requires logging in to Jamf Pro using Jamf Account (OIDC) single sign-on (SSO). This OIDC-based SSO integration allows you to log in to Jamf Pro with your J
We’re encountering recurring issues related to password resets and access across our company’s managed MacBooks, and I’d appreciate any insights from others dealing with a similar stack. Our Setup User Management: All users are created in Google Workspace. Device Enrollment: These users are synced into Apple Business Manager (ABM). Device Management: ABM is connected to Jamf, which is used to manage our company-issued laptops. Team Structure: We are a remotely distributed team across 10 countries. Security: FileVault and storage encryption are enabled by default via MDM. Issue Summary Several teammates have experienced repeated lockouts after password resets, leading to data access issues. While some users successfully regain access via the “Recover Account” option on the macOS login screen, others require the FileVault recovery key to decrypt and access their data. In my most recent case: One was able to reset the password using iCloud, which allowed them to log in. Ho
Hey all - is there an easy way to remove this from our macs. Have tried a few scripts which are failing to resolve the issue:
There will probably come a point in a Jamf Pro admin’s duties when they find themselves with the need to provide a mechanism for users to add or exclude their Mac to the scope of a Configuration Profile or Policy via Self Service. An example would be so users could add themselves to a group teasing macOS Beta releases. Using the Jamf Pro API to add a Mac to a Static Computer Group might seem like the obvious way to do this, but per recommendations made in the Jamf Pro certification courses calling the API from arbitrary endpoints is not recommended. This article will describe an alternative mechanism to allow user initiated scope changes without using the Jamf Pro API. The core part of this approach is what’s known as a flag file, and its existence on a Mac can be used to add the Mac to a Smart Computer Group which can be used a Scope Target or Exclusion. To create the flag file we’ll use a script to be called via a Script payload in a Self Service initiated Policy. To det
How can I join the mac admins slack? I tried Sign up for a new account | Slack but I don't have an email address in the macadmins.org domain. Can anyone here please invite me? I'm a relatively newer mac sysadmin, working on migrating from Intune to JAMF for my org. Would love to be a part of the community!
It would be great if there was some sort of flag to let Admins know which parents had associated their children devices with the Jamf Parent app.
We want to block external USB-C access on all our Mac devices using Jamf Pro. While we are aware that Jamf Protect offers functionality to block USB access, we do not currently have Protect and would like to achieve this using Jamf Pro alone. I attempted to configure restrictions in a Configuration Profile under Media (even though it is marked as deprecated). This approach worked on Intel-based Macs running macOS 15.2 (Sequoia), but it does not seem to work on Apple Silicon devices. Is there a way to consistently block USB access across all Mac devices (both Intel and Apple Silicon) using Jamf Pro? Any advice or guidance would be greatly appreciated.
Jamf is updating the Hosted Services Availability Commitment (“HSAC”), effective June 10, 2025. In addition to other updates, it will now be called the Jamf Service Level Agreement, and as set forth in the HSAC, we are providing 30 days notice of the updates. Please read the updated version, which can be found on Jamf’s Trust Center. We have also posted an FAQ about the updates on that page.
Earlier this year we introduced a new App Installers binary which provided a number of new capabilities, one of the most significant being the ability to download trusted installation media directly from a vendor and then performing the installation whereas previously the installation media had to be hosted on Jamf’s cloud infrastructure.As I described in my previous post, we planned to utilise this external URL method to enable us to add titles that we were previously unable to offer such as VLC and iTerm, now both available in App Installers.We recently introduced a new App Installers capability in Jamf Pro 11.16 that allowed admins to influence the flow rate of MDM commands that App Installers sent to managed Macs in their environment to help address network congestion/capacity issues. This is controlled by the new Deployment settings option in the App Installers section of the Jamf Pro settings page.As the volume of updates for software titles continues to increase we will continue
I've recently taken over JAMF duties at my company and have been asked to enable Strict Enforcement on our Zscaler Version 4.3.1 Currently the Zscaler app is deployed and asks for a password to quit the app or to sign out but lets users browse the internet when not signed in which is what we want to remove. - Looking at JAMF I only see a configuration policy for an expired zscaler certificate - I attempted to push a configuration policy of com.zscaler.installparams that I found in the Zscaler documentation but when I reinstalled Zscaler from scratch nothing changed - I attempted a com.zscaler.zscaler plist configuration policy push as well - Tunnel version says 1.0 inside the app - If you think of something even if it is obvious please let me know I am looking to learn How do you enforce this at your company and is a socket filter policy needed as well? I saw that mentioned / possibly some settings on the cloud admin portal.
We have a file share on a windows server with over 300k video and picture files. Mounting the drive and trying to navigate through the file structure or searching for files is painfully slow. Are there any tips for using Macs to access a windows server file share?? Settings to tweak or check?
Hi everyone, We're an EDU and I have the WiFi Configuration profile scoped to devices to ensure that we have the correct cert. I don't have any configuration profiles (to my knowledge) that would lock down settings in Network WiFi to where you cannot forget the network. However, I'm seeing on all my devices that it is greyed out and says "this option is not available because this network was joined via a managed profile". I have tried several different ways to remove it. The only one that worked was this command via terminal using an elevated admin account networksetup -removepreferredwirelessnetwork en0 GOODBYE_NETWORK_NAME I am probably missing something so I would appreciate any hints as to where to look to manage this and apply to all one to one macs in my environment. Thank you!
I'm seeing a repeated entry in the jamf.log on client machines."no container info found for disk with id disk2s1"I have wiped the disk and then reinstalled the OS - maybe the cause?Anyone shed any light on this?
Hello. Does anybody have a script that disables ipv6 over ethernet connections that works. Thanks D
We have a specific case where an App update is coming soon that we need to temporarily stop from happening on iOS devices. Currently, the app is set in JAMF Pro to install automatically for the iOS tablets, with "Schedule Jamf Pro to automatically check the App Store for app updates" set to on and "Automatically force app updates" set to on. All iOS devices are put into Single App mode running this specific app. What is the expected impact on the existing install base, if any, when we set the "Schedule Jamf Pro to automatically check the App Store for app updates" set to off and "Automatically force app updates" set to off. And additionally will that in fact stop the app from updating on all devices in the install base?
Hi everyone, I’d like to raise a question and share some real-world challenges we’ve encountered regarding user switching on macOS devices enrolled via Jamf Pro and managed with Jamf Connect + Entra ID integration. Scenario: A Mac is enrolled in Jamf under one user (e.g., during setup), but then another user logs in and becomes the primary user of the device. This scenario is quite common in cases of device handoff, testing, or human error during deployment. Observed Issues: Incomplete Deployment of Policies and Apps: After re-enrollment (even with full device removal from Jamf Pro and Entra ID), not all policies or apps are being deployed properly. Device Registration & Compliance in Entra ID: Devices sometimes fail to register properly in Entra ID. Even if the device appears registered (sometimes duplicated 2–3 times), the "Compliance" status is either missing or errors out. After several re-enroll attempts and manually removing the device from all platforms (Jamf,
I Have updated my instance to 11.16 and here are some quick hits that are bugging me. theres an option of monitor, and monitor and enforce. However there is no switch available to go from 1 to the other, you need to create a whole new set of rules, make your changes, then send it out. this needs to be looked at. once the monitor has been set (I didnt enforce quite yet) you get the results, how many machines pass or fail, there is NO WAY to see what machines fail, OR WHY they failed certain standards, this too needs to be looked at. using the advanced search fails to yield any results as there is no way to point to these standards in the search function when using JCE, profiles were added in the device management tab, using Jamf's CE, I dont have a CLUE where they're stored at the documentation contains NONE of the items i've listed above
Hello.Can anyone advise steps for SCIM Renewal please?I have looked over https://community.jamf.com/t5/jamf-pro/how-to-renew-scim-token-in-apple-business-manager/m-p/291373#M259451 and these steps don't match the options I see in ABM.I only see preferences, not settings and I don't see any integration tab. I am set with the Administrator role in our ABM so believe this should show me all tokens.D
Hi everyone,I’m currently reviewing the different methods for syncing Recovery Keys and I’m a bit unclear on the distinction. Could someone help clarify the differences between: Recovery Key stored via iCloud, and Recovery Key escrowed to the Jamf Pro Server? Specifically, I’d like to understand how each method works, the user experience, and any implications for security or recovery workflows. Thanks in advance for your guidance!
We are receiving this error from one of our policies that runs during enrollment. I am a little confused as to why we are receiving this error when a local admin is created during pre-stage. Has anyone else experienced this or has found a way to resolve this?
We have Jamf Pro 10.34 hosted on-premises. We have a single server and a single SMB share, running on Windows Server.We have some files that cannot be downloaded. In Self Service, it says the file cannot be found, but it is there when we check the share and check Jamf Admin. Other files work fine. If we open a browser and just simply put in the URL to files in the share, most work but some do not. On ones that do not download via Self Service, we get this in the logs: Error: Package was not successfully downloaded. -1005Any help would be appreciated. Thanks.
I have recently secured some unused iPads in our environment previously enrolled in JamfNow and wondering if it is worth enrolling them in JamfPro or just getting new devices (9th Gen or newer). Does anyone know when support or ADE will not be available for 5th and 6th generation iPads with JamfPro? Thanks!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!