Get Support
Recently active
Is anyone able to get Groups working for privileges in Jamf Pro? I can add a group, search it via our Entra integration, but once its added, i still get access denied with the associated user im logging in with. The only way SSO will work is if i manually add each user. Jamf Support told me add the group as a standard group, matching the name 100%, which obviously still didnt work. Before i go back to support, curious if anyone here has run into something like this?
Hi all, We have a strange issue that i am hoping you can help with. We have had around 10-15 instances where 802.1x WiFi and LAN profiles disappear from a users device. To give some context, its a single profile with LAN and Wifi 802.1x networks with a single SCEP profile, the issue happens on all kinds of devices on different versions of Sonoma and Sequoia. The profile shows as installed on Jamf and the device however the SSID is missing from known networks. The fix is to exclude the device from the profile and then remove the exclusion and the profile reinstalls and all is good. We've logged a ticket with support and they have ruled out Jamf and said its an Apple issue and to log it with them. Has anyone else come across this and been able to resolve it? Its so frustrating as its so sporadic and we cannot reproduce the issue on demand so its proving difficult to resolve. Thanks in advance.
I'm trying to deploy Jamf Connect as part of a PreStage enrollment, and this should now be possible from an on-prem https: DP with no user authentication. I'm obviously not going to replicate my entire package portfolio onto an un-authenticated DP, so I must populate it manually (selective replication is only available for cloud). I've created manifest plists as per documentation and added these to Jamf Pro via the Settings - Packages page, and staged my packages and manifests on the enrollment DP, but cannot get them to deploy in PreStage. Mgt History reports them as being installed, but there are clearly not. Any ideas how to manually manage an enrollment Distribution Point?
Another script that grew out of necessity. Trying to "encourage" users to restart their Macs at least once every 30 days to help with overall system performance, make sure all policies are installed, fix network related issues, etc. so I can with with this super simple Dialog notification that shows up once a week if they are in the "over 30 day uptime" smartgroup. Users don't have to restart, but if they do, you can set a custom timer to do an automatic restart for them. I used the AppleScript method of doing a restart so it will prompt the user to save their docs before a restart. Script can be found here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/UpTime Regex I used to calculate 30+ days And the script parameters...you can control the uptime days and timer value.
I have deployed some printers using the profiles and now we need to remove them and add new ones. How can this be achieved with Jamf School as there is no remove option. Removing the profile does not uninstall the printer from the system pane on the users computer.
Hi everyone, I’m in the process of setting up Jamf Connect in our environment and would really appreciate some guidance on best practices for configuring the login window, especially when integrating with cloud identity providers (like Entra ID). There are a lot of options and functionalities in Jamf Connect, and I want to make sure I cover the most important ones - the "must-have" configurations for a solid and reliable user experience. If you could share: Your go-to plist keys or config profiles Example scenarios you've addressed What has worked (or failed!) in your setup …it would be extremely helpful 🙏 Thanks in advance! Looking forward to learning from the community.
Hi all, I'm trying to properly configure Jamf Connect with Microsoft Entra ID (Azure AD) for a passwordless login experience using Microsoft Authenticator push notifications. Right now, when a user logs into their Mac using Entra ID with passwordless push approval (without entering a password), Jamf Connect always prompts them to set or enter a local password after the identity is verified. My goal is to avoid this step entirely — i.e., users authenticate via Authenticator app and immediately get logged in to the local macOS account, without being asked for a local password. Thanks in advance for any clarification or guidance!
Bonjour, Avec Jamf Composer, nous avons le bug suivant : L'espace disque demandé pour un paquet est de 107 Go alors que le paquet à une taille de 155 Mo. Le paquet à été fait avec Jamf Composer 11.15.0 sur macOS 15.4.1.
Apologies if this is a basic question — I'm new to MDM administration. During the initial rollout at a new school location, the iPads get stuck after connecting to Wi-Fi and attempt to load the profile. The error message appears to be something like: "Timeout while reaching for profile" (translated from a different language). Troubleshooting so far: I spoke with the Wi-Fi administrator to ensure that the necessary ports are open, and the firewall shouldn't be blocking anything. I also tested with a different Wi-Fi network, but that didn't resolve the issue. I un- and reassigned the ADE profiles. The profiles are relatively small compared to those at other locations, so size shouldn't be the issue. Any suggestions for potential solutions or next steps would be greatly appreciated.
We allow our users from management level up to download apps as they need and we do not worry about controlling their backgrounds or layouts on their devices. If you restore from backup on a phone that was never in JAMF it will not show up in JAMF. If you restore from backup on a phone that was in JAMF after a restore it no longer actively communicates. Is there a way for these users to restore from backup and keep their new phones similar to the old?
With the new changes in the US, we would like to know how the EU manages third-party app stores within Jamf, as they have had the feature for a little while. Specifically, is there a way to automatically install an app from one of the third-party app stores?
Hey everyone,Having an issue with jamf app catalog installations. Some machines just seem to randomly not want to install the app. These machines are very similar, it's a computer lab, but one machine will install successfully and its neighbor will fail.My question is how do I investigate this further plus all I see in the console is that it failed with no real information and also has anyone else experienced this and was able to fix it.
I’ve set up Jamf Connect, but the current login process feels too complicated for users. Right now, they need to: Then authenticate with their Entra ID password, And finally enter a local admin password to sync the network and local accounts. I don't understand what I configured wrong and why this is happening. As far as I understood from the forums and documentation, this should happen at the beginning when you need to synchronize the password, or when the password has not been synchronized.So it's most likely that the password is not synchronized? How can I troubleshoot it?
Hi everyone! I’m a few months into using Jamf Pro and loving it — but my list of configuration profiles is growing faster than my caffeine intake on patch Tuesdays. Categories definitely help a bit, but honestly... my Config Profiles page is starting to look like a teenager's bedroom: stuff everywhere, no clear idea what belongs where, and a growing sense of fear every time I open the list. I’m curious — what’s your "best practice" for keeping things clean, understandable, and future-you-friendly? Do you: Create broader profiles (e.g., one config for all things Microsoft Edge),OR Break it down into smaller, highly specific profiles (e.g., one profile just for Edge homepage settings, another for extensions, another for updates)? Would love to hear how you actually organise it day-to-day. Bonus points if your method also stops your future self from screaming into the void six months from now. 😅 Thanks legends!
I have an employee who reset his passcode on his laptop and then immediately forgot it. I don't have the option to reset his passcode (in the management section where you would typically lock it). It's managed by jamfusermanagement and we generated that 1 hour passcode to log in and that didn't work. FileVault says it's off one place and on in another. But it's managed by jamf. I can see that. Shouldn't I be able to help him??
Greetings! We use FileVault through Jamf Pro and we also have a mixed bag of Intel and Apple Silicon laptops. As far as our Jamf Protect Complaince report, ALL of the Apple Silicon machines show as "Pass" and ALL of the Intel machines show as "Fail". I've been poking around online trying to figure that one out, but can't seem to find anything. Has anyone else experienced this phenomenon and found a fix? Thank you
Here is another goodie! As everyone knows (or maybe it is just me), that the Adobe apps are a real pain to deal with, and I have come up with a script that will facilitate the removal of any Adobe apps that are discovered on a user's system. The script will go thru and import a directory listing all of the adobe apps that it can find and determine the highest "year" that is installed, and when the user is presented with the removal options, it will NOT allow them to remove the the highest year versions, but will allow them to remove previous versions. I will also remove any CS6 and older files, outdated Adobe reader apps, outdated Acrobat apps & Safari flash plugin You can also pass the year when a new version becomes available and it will (optionally) present the user with a message stating that there is a newer version available if they don't already have it installed. There are two critical functions for this process noted here: extract_version_code(): (This h
I've been tasked wtih trying to rightsize our Mac fleet's SSD that we purchase for the devices. I've been tried doing an EA script that is generating some info and I tried creating an advanced computer search looking at "Boot Volume % full". The Comp search one seems to give inconsistent data when I click into a machine record it vary's wildly from the column the report spits out. I was thinking that once I get consistent data out, I could use smart groups to dump the machines that are 25% full go into one group, 26-50% to another, and so on. But I'm also open to other suggestions. thank you!
Hi Friends! Today is the FINAL day to apply to be a Jamf Hero! A few things to note: Heroes is for ANY Jamf customer. (It doesn't matter if you're new to Apple management or have loads of experience!) Even if you were in the program before, you still need to apply. Applications won't open again until next spring. THIS is your chance to get in amazing community! Learn more from this previous post. Or apply directly HERE! Reach out to jamfnation@jamf.com with any questions.
I have been trying to scope a policy to an Azure directory group however im not having any luck. In the settings JAMF thinks the user is a member of the directory group so that part all seems ok. In the policy i scoped it to all managed devices with a limitation of the directory group but it doesnt seems to run at all. I have tried both a Self-Service policy and a policy that runs on check-in but neither seems to work. When i remove the group limitation the policy works fine. Is there anything else i need to do to get the group limitation working?
Hi, I'm looking for a script or uninstaller for removing all Jamf components. My company made a decision to move to Intune, and we took the non-best practice route of manually moving devices (best practice is to completely reimage). Because of this the devices have Jamf residuals on them. We're simply looking to clean up after and remove any unlicensed elements as part of good due diligence. I did find one post suggesting use of a third-party uninstaller. Perhaps this is best over trying to come up with a script?
So I was having a hard time removing TV.app from the dock. Now before we start I know I could've used dockutil (which I've used in the past before) to make my life easier. However I didn't want to push any more 3rd apps unless I really needed to. I decided to use the built-in tools JAMF has to keep our deployment lean. I read a lot of post and found nothing relating to the TV.app itself.Some Applications are found in /Applications (Music, Numbers) while other like TV.app is found in /System/Applications (Launchpad, Photos). So I kept on trying /System/Applications/TV.app and nothing happen, it didn't remove itself. I tried every thing I can think of and nada, it was putting up a hell of a fight. So I decide to dig into the app itself. I finally came across something interesting. If you open up this file: /System/Applications/TV.app/Contents/version.plistYou will find:<string>TVDesktop</string>. Now I haven't seen any mention of this any where before. I was like hmmmmmm
Using Configuration Profiles option in JAMF i had setup HTTP/HTTPS Proxies.Distribution method was "Install Automatically". In Scope had added the target machine to which these Proxies should be applied In Proxies option enabled "Enable Web Proxy (HTTP)" and " provided Hostname or IP address and port number for web proxy.In Proxies option enabled "Enable Secure Web Proxy (HTTPS)" and providedHostname or IP address and port number for secure web proxy.After this saved the Proxies.Checked and verified in logs and found that the Proxies was pushed automatically. As per JAMF logs Proxies values were pushed successfully and automatically to target machine.In target machine went to Network--->Advanced--->Proxies to check if the values were pushed or not.Values were not being reflected there. Can some please provide some thoughts and inputs on this.The Proxies section under Network--->Advanced should show the updated values which have been pushed.Nothing was sho
In any organisation some of the applications are licensed and which need to be scoped to individual machine or through static group collection.But when we check the JAMF App Catalog which are limited to scope “Smart Computer Groups” only.Could you please enhance this JAMF App catalog scope feature to the individual machines or static group.Thanks.
My team has been tasked with changing some settings for Safari and Chrome. We have to have the homepage set and then a second tab that's blank. We are able to successfully push these changes with a config profile, but of course this locks down the settings. Has anyone had any experience with pushing settings like this and the user still being able to change the settings back if they want? I tried scripting the changes and pushing to me device, but neither browser seems to care about the changes. Any advice would be much appreciated. Thank you
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!