Get Support
Recently active
There is a lot of information about custom macOS screen savers and how to implement, but it took me a long time to sort through everything and find answers, so i am posting my findings here. I am going to try to keep it simple. Task: Deploy a custom screen saver built by an in house developer using xcode in .saver format. Set the screen saver for the login window and the logged in user. Solution:Part 1 - According to an Apple KB article, you cannot set a "Custom" screen saver at the login window. The article publish date is a bit stale, but after working with Jamf Support and my own testing, this still holds true up to macOS 10.15.2 (also tested on macOS 10.14.6). https://support.apple.com/en-us/HT202223 Part 2 - You can however set a screen saver for a logged in user. Package up your custom screen saver, install it at the /Library/Screen Savers/ path. Add the script below to Jamf Pro. This script was provided to me by Jamf Support. Create a policy, set it for check-in once per co
Hi there Nation! Recently my employer asked to track what employees do on their MDM managed laptop. For example, They want to track every little thing that the employee does on their laptop whether said employee is watching Netflix, Downloading documentation, working on personal projects instead of work related projects. Is there feature on JAMF that allows this? I wouldn't like to source out a 3rd party for this, but if not possible in JAMF then I could do that. I know we have logs but it's not detailed enough for them. Please and thank you!
Hey everyone, at the moment we're testing a new WiFi network. Some of our students iPads have been assigned a profile for that WiFi network, so they can log in while supervised with their teachers. The profile is set to not automaticly log into the wifi network, so the iPads don't just yet rely on that network. Now I tried to update that setting so that the iPads SHOULD automatically log into the wifi network, but the setting on the iPads themselves does not update, even tough the profile has been updated in Jamf School. The other way around (iPads connect automaticly and the profile is updated so they don't do that) the setting updates as intended. Is this a bug? Does anyone have an idea how to get around this issue without making the iPads forget the WiFi completly?
I have a "few" laptops that users have "forgotten" to return when they have left the company. What is the best way to disable the user from Logging in to the laptop using Jamf. I would like to just disable all non admin logins MAybe popup a banner saying Please return to xxxx.. I know I can wipe it if needed. Thanks S
Curious if anyone has used Jamf to install the ServiceNow Agent Client Connector for macOS.Per this document, there are 2 installation methods:https://docs.servicenow.com/bundle/tokyo-it-operations-management/page/product/agent-client-collector/concept/acc-install-mac-os.htmlOne is a simple command line install that references back to the SN Server (notably, the SN "mid-server") to get the installation packages and such.The other is a more manual install that requires downloading packages and configuring connections. Has anyone done this? If so, which method did you use? Any gotcha's to look out for? Background here is that we are currently using the ServiceNow Service Graph Connector to get data from Jamf to the ServiceNow CMDB, however SGC has been getting more unreliable. It appears ServiceNow is applying fewer resources to SGC than in the past and the product is not keeping up with Jamf or even other SN products. ThanksPhil
Jamf pro is down from 10 hours and there is no ETA, I hope we will be getting RCA from Jamf otherwise it would be very difficult to make management understand about this blunder. PS: The employee who did this probably getting a new job soon, I am not sure about me :( and my colleagues @tanuj
Hello Everyone, I am looking for some assistance with an issue that I am wondering if anyone else has ran into. I have JAMF as our MDM for MacOS. I am moving towards MS Intune for our Windows endpoints. Currently I have JAMF setup as a Proxy to deploy SCEP certs to our Macs. This was done using Entra ID App Proxy with a Private Network connector. This works great. Now for the problem... I want to setup Intune to deploy certs to our Windows endpoints but it fails unless the "PFX Certificate Connector" is installed. When that gets installed, it highjacks the SCEP URL and blocks everything not coming from Intune. Essentially I can only have one or the other. JAMF or Intune. Has anyone got both of these working at the same time? Thanks in Advance for any help.
On Saturday, May 24, 2025, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time ap-southeast-2 May 23 1400 UTC 1800 UTC ap-northeast-1 May 23 1500 UTC 1900 UTC eu-central-1 May 23 2200 UTC 0200 UTC eu-west-2 May 23 2300 UTC 0300 UTC us-east-1/2 May 24 0400 UTC 0800 UTC us-west-2 May 24 0700 UTC 1200 UTC Jamf Cloud Hosted Data Region Information
Hello, I am sorry to bother everyone on this matter, but I have been working on an issue for a week and I haven't been able to find a solution to my problem.I can feel I am not far, but there is one last thing in my way which prevent me from moving forward. To make it short, we are about to push Sierra upgrade on all Mac using LANDesk (Ivanti). So far everything works well. I was able to write a script to bypass FV2, I also wrote a script which force quit all the Application in order to prevent a restart. But the last scenario that I am working on and which I am struggling is to Force log out any active user in a Mac except the current user. Using the command line sudo kill <pid> With this command, I was able to force logout an active user of a test Mac, but to do so, I had to find the PID.Now the difficulty is that in my company, we have many users, and I can't find the PID for each user on each computer manually.So I need to write a script which will find the PID of all
Our company is moving to Freshservice. Working on a policy to push the Freshservice agent to all our Macs. The Agnet is a pkg file and that installs fine but I can't figure out how to make it reference the json file for the registration key and account info. I tried using Composer to create a custom pkg but it flat out doesn't work. Any assistance would be appreciated.
I thought I disabled update notifications from Apple via config profile by unchecking "Allow software update notifications" in the Restrictions > Applications section, yet I still get these:Did I miss something?Thanks.
Hi, We use Jamf to auto update Microsoft apps like Word, Excel and Powerpoint. Recently all our users are now seeing this message when Jamf updates the apps. Has this happened to anyone else and is there a fix for it?
<3 to all the people at Jamf working to fix things. In them time, shout out to #jamfnation
Our original Jamf Pro URL is mdm.dpmhome.com, but now it's failed to use. BTW, I have to use dpmhome.jamfcloud.com for access after your cloud service going back recovered, please let us know how can I use back mdm.dpmhome.com, thank you
It's strange that I've been dealing with this for the last 10 hours, and it's been completely unprofessional
Curious as to what happens to paid app licenses when you wipe a device. Seems to me that we are losing licenses if we wipe an iPad. Some of these apps are expensive. I wiped an iPad this morning and 2 paid app licenses were not available to scope, even though they were on the device before. It appears that the device is no longer scoped, but the license is no longer available. Any thoughts on this?
Hi all, I am currently trying to enable LAPS for our computers and after reading through documentation and watching videos on the topic, I disabled the creation of the local MDM admin account in PreStage and only enabled the UIE admin account. New problem that arose with that: The account created by the user during setup is now an admin. But I don't want that. Does anyone have an easy solution for that?
Hi, new Jamf admin and not very knowledgeable about the inner workings of SSO. I have configured SSO to our Entra ID domain and the web log into Jamf Pro and Account and no issues with log in with my account or a test account. I have been able to have devices enrolled successfully when the device (iOS only) is in ABM and have moved on to set up User Self Enrollment. When the test user account, goes to register, at: domain.jamfcloud.com/enroll, the user is directed to the Microsoft log in. After the credential are entered the process fails with the error : "Sorry, but we're having trouble signing you in" message with the AADSTS650056 error. I've found a few suggestions here on JamfNation, but they haven't resolved the issue. SSO Azure AD - Misconfigured application Cloud Identity providers has been set up and tested successfully redid the MS Application set up ensured: Jamf Pro > Settings > System > Single Sign On > Enable Singl
IS there an ETA on the USA hosted outage. I’m unable to apply settings or enroll a single device.
This one is for all of those wanting to issue the .p12 certificate to computers via Jamf Pro for Google LDAP Authentication with Jamf Connect. I've recently performed an integration for a customer with Jamf Connect and their G-Suite tenant following the article provided here: https://learn.jamf.com/bundle/jamf-connect-documentation-current/page/Integrating_with_Google_Identity.html and found that when attempting to issue the certificate via a configuration profile, I would get the error "the certificate could not be verified (authentication error)" I ended up going down a long rabbit hole of troubleshooting that ended with having me attempt to install the certificate manually, which lead me to find that the password I created wasn't being accepted within keychain access.This lead me to the following article going over an open issue with OpenSSL 3.x and it's deciphering issues:https://stackoverflow.com/questions/70431528/mac-verification-failed-during-pkcs12-import-w
Hi All, Does anybody know how to default the edge browser and also add bookmarks within Jamf Pro? Thanks in advance
Hi All, Does anyone know how to remove the configuration profile for the passcode policy deployed during prestage enrollment? In Prestage Enrollment settings, we have set the Passcode requirement, and now we want to deploy a new requirement, but I can't see the option to remove the existing profile. Thank you all in advance.
I noticed that there are 2 Managed Local Administrator Accounts listed in the Inventory > General page of our computers. All our computers and devices are all under Apple School Manager and are automatically enrolled via PreStage Enrollment (so I am thinking that User-Initiated Enrollment never happens for us). My questions are: 1. Under Settings > Global > User-initiated enrollment > Computers, do we need to check the box for "Enable user-initiated enrollment for computers"? And if yes, do we need to check the box for "Create managed local administrator account" (everything else is unchecked) given that each PreStage Enrollment also creates a managed local administrator account? 2. Under Settings > Global > User-initiated enrollment > Devices, do we need to check the box for "Enable for institutionally owned devices" (everything else is unchecked)? 3. If we disable User-Initiated Enrollment, will the currently enrolled devices be affected?
How do I toggle this feature off or prevent it from being toggled on? I went to reset the users password via Recovery Setup Options, user had logged into personal Apple ID when MacBook was issued but didn't remember the password. FileVault is enabled an we escrow those PRK's, but it wasn't until after the user reset their Apple ID password and logged in with it on the recovery side before the system would even allow me to put in the escrow'd PRK. We don't manage Apple IDs, I really don't see the point in them if they can't purchase anything through them. Yes I've had a VPP setup for yrs, but there are those few who like to connect their watches and such. Any advice would be welcomed.VickiH
We want to block Apple Intelligence while not signed in to ChatGPT, but allow it to be linked to ChatGPT with a specific workspace ID. This is because we recognize that Apple Intelligence while not linked to ChatGPT is a learning target. Do you know anything about this control?I know that sign-in can be managed by specifying a workspace id.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!