Get Support
Recently active
iPads that sit on lock screen for a few hours, go to partial sleep mode which disconnects from WiFi. The only way to connect them to WiFi is to wake it up and go to home screen. If an iPad is locked with passcode and not connected to WiFi, how will it complete the "Clear passcode" command through Jamf? There is literally no way to connect back to the internet using the same WiFi, Ethernet or Internet Sharing. In the past, people claimed that Ethernet to lightning adapters worked, but since iOS 11.4.1, USB restricted mode disabled the use of dongles at the lock screen. We have a lot of iPads for staff that are simply added to Jamf without any configuration policies applied to them. I know there is an option to enable/disable USB restricted mode under configuration policies, but the problem is that we are not applying any policies to these iPads. So by default, USB restricted mode is Enabled which prevents use of dongles while at the lock screen. The only way to solve this matter is
We’ve been running into a persistent issue with Jamf Connect (v2.45.1) on devices running macOS 14 Sequoia, where login via Okta intermittently fails after a few reboots. The error we consistently see on the login window is:An error occurred. Contact your IT administrator. The operation couldn’t be completed. (JamfConnectLogin.JCAuthProviderFactory.FactoryError error 0)This happens after the machine has been rebooted 2–3 times, even if it initially works fine after provisioning. Some users can click the network icon and select their username to log in using local credentials, but others get stuck at the login screen completely. We’ve verified the machine is connected to the internet when this occurs.Additionally, the macOS native Microsoft Entra ID login option (added in Sequoia) sometimes appears despite us not using Entra ID at all, which we believe is causing interference or confusion with Jamf Connect.⸻Environment:• Jamf Connect: 2.45.1• macOS: 14.0 (Sequoia) on Apple Silicon Macs•
Good Morning. I am a new Jamf Administrator. We have managed to get everything up and running for the most part. The only thing I am seeing is that when Jamf Protect is installed it does not appear to have been granted full disk access in the Privacy and Security menu. The policy is self configured from Jamf Protect and signed so that it cannot be edited. But it appears to be correct.
We recently tested a scenario with Jamf Connect and Active Directory where we enabled the "Change password at next login" flag on the AD user account. Here's what happened: I was logout of Jamf Connect and on the Self Service+ UI, I noticed the status said: “Password out of sync” and “Sign in to your Identity Provider”. On the next login attempt via Jamf Connect, I expected a prompt to change the password. Instead, Jamf Connect displayed an error saying that the password is expired, with no option to change it directly from the login window. This raises a few questions: Shouldn't Jamf Connect handle the password change flow directly when AD requires it? What are the recommended access limitations when a user is not signed into Jamf Connect? Currently, I can still request admin access via Jamf Connect even if I'm not signed in. However, if I log out and log back in, the system prompts me for the current password as expected. How do you structure access policies arou
We're rolling out a couple of iPads in Single App Mode with a kiosk app and that's working well. However, we need to manage OS updates as well. Does anyone have a workflow that allows for automatic OS updates for devices in Single App Mode? I would also be fine with a process that be scheduled for an overnight maintenance window.
I recently installed Jamf Safe Internet on my device, I seem to be facing an issue that I'm hoping someone could help me with. I've been having trouble accessing certain websites. It's not all websites, but there's a handful that just won't load anymore. I've double-checked my internet connection, cleared my browser cache, and even restarted my device a couple of times, but the problem persists. Has anyone else experienced a similar issue after installing Jamf Safe Internet?
Is it possible to enroll macOS, but to not install SelfService app? For example, I want for some devices install only Jamf Protect app without any configuration profiles and apps. Additionally, I see there is SelfService+ App, it is the same that default installed?
I've been following the directions as per https://school.jamfcloud.com/api/docs/#api-Devices-Assign_owner and PUT to https://{yourDomain}.jamfcloud.com/api/devices/:udid/owner with all the relevant information but no matter how I send the request with the user parameter, it returns a code of 400 with the message "UserRequired".I've spent a whole day trying every variation of submission and multiple programs and methods and the result is the same. Has anyone got any pointers?
I have a computer that we created the user account with Jamf Connect. Once in the user account, we can't open self service. I removed self service and reinstalled it with Jamf policy command. It still won't open. To clarify what I mean but not opening, I click to open it from the applications folder in finder. It shows in the dock then goes away. I get the report option. So it is crashing at launch. I deleted the user account and created it through system settings and still have the same issue with self service. I can open self service in the admin account. I'm not sure what else to try.
We have noticed that on some of our Macs the computer's name is getting added to /etc/hosts. This isn't having any negative effect on the operation of the Mac, but it does cause an issue with Tanium which queries the computer name as part of its data gathering tasks. These Macs display in Tanium as "localhost", not the name that is actually set for the Mac. We use the Mac's serial number for computer names. During initial setup, a policy runs "jamf setComputerName -useSerialNumber" I created an extension attribute that reads the contents of the hosts file and reports if the computer name is present. There have only been about 30 out of 1500. I created a script to remove the computer name, but on some of the Macs, the computer name has reappeared in the hosts file. Since this doesn't happen on all Macs, I'm not sure what could be doing this. Does anyone have ideas on what might be doing this?
I like Jamf Self Service+. It's a clean interface. Currently I don't see a way to rename it like the current version of Self Service. We rename Self Service to Software Center to make it familiar to those that go between Windows and MacOS. Also, while Self Service+ is nice, it doesn't seem to offer any current major advantages over Self Service at this time so we haven't been deploying it. I don't really want to have two versions of Self Service to confuse our users. Is there any plans to make Self Service+ as an automated install like the current version of Self Service? And will we be able to change the name of the app like we can do with Self Service? I'm also failing to understand what makes Self Service+ any better than Self Service other than the UI overhaul. A recent email I received said it has identity management capabilities but you can also log into Self Service. I understand Self Service will be sunset at some point so would I be co
Hello We recently updated our Mac estate to MacsOS 15.I have noticed issues with taking screenshotsWe deploy two base profiles one for staff devices one for shared lab devices.Both have Allow screenshots and screen recording (macOS 10.14.4 or later) set under Functionality.The shortcut key just does't seem to do anything but works fine on staff devices using the same setting.I dont belive Im blocking it elsewhere.Any idea Thanks Capture a portion of the screen Press Shift-Command-4, then move the crosshair pointer to where you want to start the screenshot. Press the mouse or trackpad button, drag over the area you want to capture, then release the mouse or trackpad button.
Is this blog still accurate for version 16.3? Any changes or modifications needed for the newer version?Deploying Xcode on managed devicesConfigure Xcode post installation script with SDK download for Xcode 14 and 15 · GitHub
How can I enable two-factor authentication (such as SMS or email verification) after entering username and password on the Jamf Pro login screen?
After upgrading to macOS 15, all devices are unable to install offline configuration files (.mobileconfig or .profile). The system displays the error: "Could not install 'FileProvider' payload. Configuration profiles must be installed via a Mobile Device Management (MDM) server." Has anyone else encountered this issue? Any solutions would be greatly appreciated. Thank you very much!
Hi All, I'm working with a vendor to deploy their PLM software plugins to our Mac users. The vendor says they can't create a better way to deploy their plugin because their clients "use different methods" to deploy and, essentially, they can't be bothered with it. Since upgrading to Sequoia, I've noticed that their custom .app's don't open without manual interaction in Privacy & Security settings. Does anyone have suggestions/advice whether a silent install is even possible? Thanks, R
I was able to get the Jamf Return to Service app working on an iPad, perhaps a bit too well... Once the iPad reboots, it self-enrolls fine, but it loses all Static groups it was in. I then have to manually re-assign the iPad to the Static groups it needs for proper configuration and app access. Is there a way to make Return to Service work so that it wipes the iPad, but then puts it back into the Static groups it was in? I noticed the wipe and repair option with Apple Configurator does not have this issue (keeps static groups after resetting).
Since we upgraded to sequoia, we had to update our Nexthink version, because the install was failing on enrollments. After changing it and enrollig a sonoma device, it works and shows in nexthink. When we enroll a mac on sequoia, it looks like it installs on the device, but never shows in nexthink.
Hello :) because I'm still struggling with Jamf Connect for testing Onelogin. I'm using the latest version of Jamf Configurator (2.9.0) Please note, for my test instance, I didn't configure MFA for Onelogin. I don't know if it's the OIDCTenant or something else why it's not working but I tested already these things for OIDCTenant. Error message from Jamf Configurator: " Unable to load Identity Provider "Error message from Onelogin: "OIDC authorization code for Jamf Connect FAILED" Onelogin-Client ID<companyname><companyname><companyname>.onelogin.comlogin.<companyname>.onelogin.com/Client-ID <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>CreateJamfConnectPassword</key><true/><key>OIDCClientID</key><string>Onelogin-Client-ID</string&g
I have been busy at work lately with some more scripts! This one is a dual purpose app. If you pass the word "info" in the 4th parameter of the script it will inform the users of their laptop battery status, if you pass the word "fail" in the 4th parameter it will let them know that their capacity is below 'x' amount (You determine failure by a smartgroup) #!/bin/zsh # # Written by: Scott E. Kendall # Created: 2025-01-15 # Last Modified: 2025-01-15 # # Prompt user if battery needs service # ###################################################################################################### # # Gobal "Common" variables # ###################################################################################################### export PATH=/usr/bin:/bin:/usr/sbin:/sbin JAMF_LOGGED_IN_USER=$3 BATTERY_CONDITION="${4:-"info"}" LOGGED_IN_USER=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) USER_DIR=$( dscl . -read /User
iPads generally do not go home with students so there is not a need for the Jamf Parent app. I want to see if there is an easier option for teachers to have their students assign themselves iPads for better tracking and management. We use most iPads for K-1 only. I'm curious if there is something like this, similar to Clever where students scan their badge to access the app, but in this case, they scan the iPad to assign it to themself and the data is synced into Jamf School and goes away if iPad is wiped, etc. This would also help with our asset management API. Thank you
Hello there....We're migrating all our clients, windows and mac to microsoft defender for endpoint. For the mac clients id like to use the policies in the microsoft defender portal to keep them in the same place as the windows clients, which will hopefully make support a bit simpler.I've followed the instructions in the link below, the mac I'm testing on shows up in the defender portal and I've created a mac endpoint security policy assigned to a group to apply. The problem is I cant add the mac to the group in intune as it doesn't exist.I'm sure I've missed something, i can see there are ways to connect jamf and intune but I'm not sure what is the recommended way, does anyone have any info that might point me in the right direction?Any help would be much appreciated Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro - Microsoft Defender for Endpoint | Microsoft Learn
Dear All, First of all would like to thank in advance any help or advise regarding this. To put you all in a little bit of context on our environment we are using a Configuration Profile including "AD Certificate" Payload and Network Payload to configure the connection via TLS Auth. We have been working for a while with this type of configuration without the need of binding our Mac fleet to AD , and indeed we are using Enterprise Connect (yes, I know this is kinda deprecated and we should be using like Kerberos SSO), so far this allowed us to get the AD Certificate (User Level Certificate) Payload in the past without any issue. So far since like 1 week ago it suddenly stopped working, So still figuring out what changed or if there was a change that I didn't get informed on our Infrastructure. We want to avoid any open external traffic like going through workarounds as SCEP > or any AD CS Connector... Would now to request your assistance , if at any point you have configured s
Hi everyone, I'm currently working on aligning our macOS fleet with the CIS Level 1 benchmarks using Jamf Protect and Jamf Pro. I have CIS18 compliance reporting enabled in Jamf Protect, and while it’s very helpful, I’m running into a significant challenge. I’m seeing up to 25 FAIL results in the Compliance report. I’d like to remediate these via configuration profiles in Jamf Pro, but here’s where things get tricky: The CIS18 report in Jamf Protect doesn't clearly state what exactly needs to be configured to fix each FAIL. I’ve referred to the official CIS macOS benchmark PDF, but there are many settings that can’t be implemented via configuration profiles or are labeled differently in Jamf. There’s no consistent ID or reference number in Jamf Protect's report that I can use to match it back to the CIS benchmark document it which makes it very hard to find the right section and remediation. Has anyone dealt with this mapping issue before?How did you go about creating your
Hi I have some issues to get the upload to Jamf working from autopkg Does any one have a general upload template for Autopkg? thnx in advance
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!