Get Support
Recently active
Trying to set up a config profile for this new feature set. I have used Jamf's example and Apple's example as starting points, but the radio buttons for the items I have set to be managed are still able to be turned off and do not say they are managed like the Jamf apps are. Has anyone else had success in getting a config profile to work for this yet?
Hi I am looking for a best practice way to move from a MS Office Mac App Store Installation to MS Office PKG Installation. We have currently some Clients with MS Office from the Mac App Store, those Clients shoul get MS Office via PKG Installation in the future. Can we simply remove the MAS MS Office Apps from the Clients and replace them with the PKG MS Office Apps? Thanks in advance.
Great that we've now go the CIS control number references in the title. What's now needed to make this even better is a way to select all of the controls available en masse. Currently if we want to create granular controls, not all of the options selected for each scoping group etc, I have to manually untick each control for each benchmark I want to create. This is tedious, and repetitive. If I could select/de-select all in one click, then add the ones I wish to add to that specific benchmark control, that would make my life a helluva lot easier!
Hello everyone! Since 12/14/25 we have been receiving the message “The VPN client agent was unable to set up monitoring of the VPN profile files” every few seconds. It doesn't matter whether VPN is connected or not. It feels like the message only comes when you open the Finder and then you can't get rid of it. Reinstalling the same version fixes the problem. Since Friday we have activated version 5.1.7.80 for the zero touch deployment. So yesterday I activated version 5.1.6.103 again. When you connect to the VPN for the first time, the app is updated to 5.1.7.80. Today I have the first client installed with version 5.1.6.103. Since it was connected, it also automatically updated to 5.1.7.80. So it can't be my newly created 5.1.7.80 pkg. maybe it's because of macOS 15.3.1? Have you ever seen this?
Hi everyone, I'm currently struggling to create a working PPPC profile for AnyDesk on macOS. My goal is to pre-approve the following permissions for all users: Full Disk Access Accessibility Screen Recording So far, I’ve tried two approaches: A .mobileconfig file generated with the help of AI Manually configuring the payload using Jamf In both cases, the profiles appear as “completed” in Jamf, but they don’t seem to take effect — AnyDesk still prompts for the permissions when launched. These settings need to be valid system-wide, across all users, and I’m currently out of ideas. Has anyone successfully deployed a PPPC for AnyDesk or encountered similar issues? Any advice, tips, or examples would be greatly appreciated! Thanks in advance!
Hey guys, I really struggle on probably something easy. We are partially using the erase tool from github to update some Macs in our fleet. So the easy way is a policy with the package and the command line like /Library/Management/erase-install/erase-install.sh --version=15.4.1 --reinstall --check-power --no-timeout --min-drive-space 20 --no-fs --rebootdelay 300 --power-wait-limit 300 --cleanup-after-use My problem is that this policy, once completed, is showing failed. So it will start again popping up on the users macs. I read about the launcher script, but it failes too. I tried with the package and without, I tried the example script given by Github and the normal version. Hows the process? I would just like to have jamf confirmed that the installation is completed. Thanks!
Hey Everyone, Kinda new on all related stuff for MDM and JAMF, so I'm figuring out how to properly perform tests on mac enviroments without everytime breaking my own laptop and certificate stuff to connect back and pull over everything from the scratch. With that in mind, I've came with the idea of creating VM (Using VirtualBuddy) and enrolling it to jamf server through the jamf enrollment link... so far even everything seems to be good. I´m facing problems with the Self Service app, that it's not connecting. Anyone else that has being tested this? or have any kind of solution to have an appart mac enviroment to break :) without the need of purchasing another macbook hehe :)
New to Jamf School. Handed out new pre enrolled iPads to teachers about two weeks ago and they were all connecting to the school Wifi and working fine. Suddenly about a week ago they stopped connecting to any WiFi network...even outside of school. Any ideas if something within Jamf could be causing this? We do not have Safe School.
Hi there, we are new to JAMF and are currently experiencing an issue with the Classroom app not displaying any classes on our devices. Unfortunately, I have not been able to resolve this on my own, so I am hoping of receiving your support. Initially, the Classroom app on my own testing device successfully showed the groups configured in JAMF. However, when two of my colleagues offered their devices for testing (we are currently in the process of migrating from another MDM solution to JAMF), the app did not work as expected. After installing the app, it prompted for a teacher name and no classes were displayed. I attempted to reproduce the issue by resetting my device, and since then, it also no longer shows the classes—even though it previously did. The devices of the students shows the correct classes in the general preferences of the devices, so I think their devices are working correctly in Apple Classroom. We would greatly appreciate any assistance in resolving this matter so that
Hi All, Does any have any information on how I can deploy License Key for SnagIT 2025? Please don't refer me to the SnagIT Website as there Script on the site doesn't work for me. Thanks in Advance
Hey Folks, we have recently moved with our entire Fleet of iOS and macOS Devices to Jamf Pro. today Apple released iOS18.2 and we wanted to Update our iOS Devices using DDM. We noticed that non of our Devices, macOS or iOS, has DDM enabled. Does anyone know why? thanks!
I am looking to Execute Absolute Full Agent, however the PKG relies on a few other files, how can I accomplish this as it seems to have an error code of 0 - getcwd with my script. #!/bin/sh ## postinstall pathToScript=$0 pathToPackage=$1 targetLocation=$2 targetVolume=$3 if sysctl machdep.cpu.brand_string | grep -w "Intel" ; then sudo -S installer -allowUntrusted -verboseR -pkg "/private/tmp/Absolute5.10.25/AbsoluteFullAgent.pkg" -target / fi rm -rf "/Private/tmp/Absolute5.10.25/" 2>dev/null exit 0 ## Success exit 1 ## Failure
Hi everyone, hoping someone is able to help. We are implementing Jamf Connect (w/ Jamf Pro) using EntraID as OIDC and ROPG. Additionally, I am integrating Kerberos, but I am running into issues (most likely DNS) with devices on VPN (Citrix Secure Private Access). We have a on-prem Citrix NetScaler/ADC and while connected to Citrix ADC I am able to get both kerberos tickets (krbtgt and ldap). However, when connected to Citrix Secure Private Access (cloud), I only get the kgbtgt not the ldap ticket and Jamf Connect says unable to get kerberos ticket, attempting to fetch. I am hard coding the kdc and realms in /etc/krb5.conf (Sequoia 15.4.1).. anyone worked with Kerberos and Citrix appliances before? Any feedback would be awesome, over 24 hours on this issue already I am unable to resolve nslookup -type=srv _kerberos._tcp.REALM-NAME.NET (neither in uppercase or lowercase, in our NetScaler/ADC on-prem works fine. Also when I run scutil --dns I get 182 search domains, one
Hello all. Just for some context, I'm Alex, and I work at a school in the UK. We are currently in the process of setting up JAMF Pro and JAMF connect, and we are running into trouble around DFS shares and Kerberos. Are AD domain is school.local, and are azure AD is school.co.uk, and we are currently not getting Kerberos tickets,. In the JAMF connect logs, I get a kerberos authentication error, OffDomain. So I am wondering if this has anything to do with the domain names not matching and wondering if anyone else has had similar issues and how you've gotten around it? Just to clarify, I can ping the domain from my test Mac, and kinit gives a manual Kerberos ticket. Also, the next question... We have DFS shares for our home folders in AD, and all our other shares are DFS. I'm desperately looking for some way of mounting these shares, based on user groups etc. If certain user is in particular group, mount this share for them, etc. And as well while having home folders mounted over DF
Hi everyone, I am searching for the API which will provide the list of all the applications and its latest version. This will help if the installed app on the computer, is having the latest version or not. I tried this API, but couldn't get the latest version:/JSSResource/macapplications/ I am able to find corresponding API for mobile applications:https://developer.jamf.com/jamf-pro/reference/findmobiledeviceapplications But couldn't find the same for computers. Thanks in advance.
Hello Jamf Community, Not sure whether this has been done or not but I'm looking to see if anyone has any ideas/scripts for creating a sort of universal uninstaller for approved applications. All of our users are standard users and we only want them to uninstall certain applications we deem "approved" for uninstallation. As such, we are looking for something that creates a pop-up window which allow them to select from a predefined list of apps to uninstall. Is anyone aware of something like this that exists? Or have an idea on how to create it? I'm not the best at scripting...
Hi all, I need to create a list of applications that all the devices have installed (only Macbook).Is there any way I can do this? I know I can see the device application Log (Computer>Inventory>Search>Select computer>History>application usage logs)but I need something easier... I don't need to know what each computer has installed but an overall thing. Any help?
We need to view usage statistics on each of the Adobe apps we use. I can't figure out how to report the usage in the last 90 days per user. I don't even seem to get very close. Below is essentially what I'm looking for. ComputerName, UserName, ApplicationName, Usage laptop12, jdoe@company.com, Adobe Acrobat Pro, 23 hours If I look at each of roughly 800 computers I can see the pretty charts that claim to show usage. Some level of data is there, but I see no way to export it to make it useful.
Struggling to set this up. The script seems to 'work'. I don't see any erorrs during install. ButI my configuration profile policy is still Pending and nothing seems to be getting pushed. I don't see any particular errors anywhere. Is there a log on the client end that i can check to see what's going on under the hood? If I go to PKI Certificates in Jamf Cloud - I see : "Outbound mode status check The Jamf AD CS Connector last contacted Jamf Pro for pending certificate requests on 03/09/2025 08:12 AM"So I'm assuming there is some sort of connection happening? And at what interval does the outbound AD CS instance check for certificate requests? Is there a way to modify the interval for polling?Any help would be appreciated.
I set a Restrictions configuration profile to disable Find My Mac. I ensured that I'm part of the scope and that the config profile actually installed on my machine. My machine is checking in with no problem. However, I'm still able to turn on/off Find My Mac after the Restrictions profile is installed Anyone having this issue or recommend a better way of disabling? What scares me the most is a user being able to remote wipe their Mac without IT's consent.
Update 08 May 2025: Standard Cloud upgrades are scheduled for the weekend of 16-17 May (details below). We appreciate your patience with the delayed schedule. Today we are releasing Jamf Pro 11.16; highlights include: Compliance BenchmarksBuilt on the macOS Security Compliance Project (mSCP) framework, compliance benchmarks enables you to automatically implement security standards across Mac devices. Compliance benchmarks supports industry-standard frameworks and automatically generates necessary management settings to enforce security controls. When enabled, compliance benchmarks create and maintain device security baselines through a combination of policies, configuration profiles, scripts, extension attributes, and smart groups, eliminating the need to manually configure individual security controls.Important: This capability requires logging in to Jamf Pro using Jamf Account (OIDC) single sign-on (SSO). This OIDC-based SSO integration allows you to log in to Jamf Pro with your J
We’re encountering recurring issues related to password resets and access across our company’s managed MacBooks, and I’d appreciate any insights from others dealing with a similar stack. Our Setup User Management: All users are created in Google Workspace. Device Enrollment: These users are synced into Apple Business Manager (ABM). Device Management: ABM is connected to Jamf, which is used to manage our company-issued laptops. Team Structure: We are a remotely distributed team across 10 countries. Security: FileVault and storage encryption are enabled by default via MDM. Issue Summary Several teammates have experienced repeated lockouts after password resets, leading to data access issues. While some users successfully regain access via the “Recover Account” option on the macOS login screen, others require the FileVault recovery key to decrypt and access their data. In my most recent case: One was able to reset the password using iCloud, which allowed them to log in. Ho
Hey all - is there an easy way to remove this from our macs. Have tried a few scripts which are failing to resolve the issue:
There will probably come a point in a Jamf Pro admin’s duties when they find themselves with the need to provide a mechanism for users to add or exclude their Mac to the scope of a Configuration Profile or Policy via Self Service. An example would be so users could add themselves to a group teasing macOS Beta releases. Using the Jamf Pro API to add a Mac to a Static Computer Group might seem like the obvious way to do this, but per recommendations made in the Jamf Pro certification courses calling the API from arbitrary endpoints is not recommended. This article will describe an alternative mechanism to allow user initiated scope changes without using the Jamf Pro API. The core part of this approach is what’s known as a flag file, and its existence on a Mac can be used to add the Mac to a Smart Computer Group which can be used a Scope Target or Exclusion. To create the flag file we’ll use a script to be called via a Script payload in a Self Service initiated Policy. To det
How can I join the mac admins slack? I tried Sign up for a new account | Slack but I don't have an email address in the macadmins.org domain. Can anyone here please invite me? I'm a relatively newer mac sysadmin, working on migrating from Intune to JAMF for my org. Would love to be a part of the community!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!