Get Support
Recently active
It would be great if there was some sort of flag to let Admins know which parents had associated their children devices with the Jamf Parent app.
We want to block external USB-C access on all our Mac devices using Jamf Pro. While we are aware that Jamf Protect offers functionality to block USB access, we do not currently have Protect and would like to achieve this using Jamf Pro alone. I attempted to configure restrictions in a Configuration Profile under Media (even though it is marked as deprecated). This approach worked on Intel-based Macs running macOS 15.2 (Sequoia), but it does not seem to work on Apple Silicon devices. Is there a way to consistently block USB access across all Mac devices (both Intel and Apple Silicon) using Jamf Pro? Any advice or guidance would be greatly appreciated.
Jamf is updating the Hosted Services Availability Commitment (“HSAC”), effective June 10, 2025. In addition to other updates, it will now be called the Jamf Service Level Agreement, and as set forth in the HSAC, we are providing 30 days notice of the updates. Please read the updated version, which can be found on Jamf’s Trust Center. We have also posted an FAQ about the updates on that page.
Earlier this year we introduced a new App Installers binary which provided a number of new capabilities, one of the most significant being the ability to download trusted installation media directly from a vendor and then performing the installation whereas previously the installation media had to be hosted on Jamf’s cloud infrastructure.As I described in my previous post, we planned to utilise this external URL method to enable us to add titles that we were previously unable to offer such as VLC and iTerm, now both available in App Installers.We recently introduced a new App Installers capability in Jamf Pro 11.16 that allowed admins to influence the flow rate of MDM commands that App Installers sent to managed Macs in their environment to help address network congestion/capacity issues. This is controlled by the new Deployment settings option in the App Installers section of the Jamf Pro settings page.As the volume of updates for software titles continues to increase we will continue
I've recently taken over JAMF duties at my company and have been asked to enable Strict Enforcement on our Zscaler Version 4.3.1 Currently the Zscaler app is deployed and asks for a password to quit the app or to sign out but lets users browse the internet when not signed in which is what we want to remove. - Looking at JAMF I only see a configuration policy for an expired zscaler certificate - I attempted to push a configuration policy of com.zscaler.installparams that I found in the Zscaler documentation but when I reinstalled Zscaler from scratch nothing changed - I attempted a com.zscaler.zscaler plist configuration policy push as well - Tunnel version says 1.0 inside the app - If you think of something even if it is obvious please let me know I am looking to learn How do you enforce this at your company and is a socket filter policy needed as well? I saw that mentioned / possibly some settings on the cloud admin portal.
We have a file share on a windows server with over 300k video and picture files. Mounting the drive and trying to navigate through the file structure or searching for files is painfully slow. Are there any tips for using Macs to access a windows server file share?? Settings to tweak or check?
Hi everyone, We're an EDU and I have the WiFi Configuration profile scoped to devices to ensure that we have the correct cert. I don't have any configuration profiles (to my knowledge) that would lock down settings in Network WiFi to where you cannot forget the network. However, I'm seeing on all my devices that it is greyed out and says "this option is not available because this network was joined via a managed profile". I have tried several different ways to remove it. The only one that worked was this command via terminal using an elevated admin account networksetup -removepreferredwirelessnetwork en0 GOODBYE_NETWORK_NAME I am probably missing something so I would appreciate any hints as to where to look to manage this and apply to all one to one macs in my environment. Thank you!
I'm seeing a repeated entry in the jamf.log on client machines."no container info found for disk with id disk2s1"I have wiped the disk and then reinstalled the OS - maybe the cause?Anyone shed any light on this?
Hello. Does anybody have a script that disables ipv6 over ethernet connections that works. Thanks D
We have a specific case where an App update is coming soon that we need to temporarily stop from happening on iOS devices. Currently, the app is set in JAMF Pro to install automatically for the iOS tablets, with "Schedule Jamf Pro to automatically check the App Store for app updates" set to on and "Automatically force app updates" set to on. All iOS devices are put into Single App mode running this specific app. What is the expected impact on the existing install base, if any, when we set the "Schedule Jamf Pro to automatically check the App Store for app updates" set to off and "Automatically force app updates" set to off. And additionally will that in fact stop the app from updating on all devices in the install base?
Hi everyone, I’d like to raise a question and share some real-world challenges we’ve encountered regarding user switching on macOS devices enrolled via Jamf Pro and managed with Jamf Connect + Entra ID integration. Scenario: A Mac is enrolled in Jamf under one user (e.g., during setup), but then another user logs in and becomes the primary user of the device. This scenario is quite common in cases of device handoff, testing, or human error during deployment. Observed Issues: Incomplete Deployment of Policies and Apps: After re-enrollment (even with full device removal from Jamf Pro and Entra ID), not all policies or apps are being deployed properly. Device Registration & Compliance in Entra ID: Devices sometimes fail to register properly in Entra ID. Even if the device appears registered (sometimes duplicated 2–3 times), the "Compliance" status is either missing or errors out. After several re-enroll attempts and manually removing the device from all platforms (Jamf,
I Have updated my instance to 11.16 and here are some quick hits that are bugging me. theres an option of monitor, and monitor and enforce. However there is no switch available to go from 1 to the other, you need to create a whole new set of rules, make your changes, then send it out. this needs to be looked at. once the monitor has been set (I didnt enforce quite yet) you get the results, how many machines pass or fail, there is NO WAY to see what machines fail, OR WHY they failed certain standards, this too needs to be looked at. using the advanced search fails to yield any results as there is no way to point to these standards in the search function when using JCE, profiles were added in the device management tab, using Jamf's CE, I dont have a CLUE where they're stored at the documentation contains NONE of the items i've listed above
Hello.Can anyone advise steps for SCIM Renewal please?I have looked over https://community.jamf.com/t5/jamf-pro/how-to-renew-scim-token-in-apple-business-manager/m-p/291373#M259451 and these steps don't match the options I see in ABM.I only see preferences, not settings and I don't see any integration tab. I am set with the Administrator role in our ABM so believe this should show me all tokens.D
Hi everyone,I’m currently reviewing the different methods for syncing Recovery Keys and I’m a bit unclear on the distinction. Could someone help clarify the differences between: Recovery Key stored via iCloud, and Recovery Key escrowed to the Jamf Pro Server? Specifically, I’d like to understand how each method works, the user experience, and any implications for security or recovery workflows. Thanks in advance for your guidance!
We are receiving this error from one of our policies that runs during enrollment. I am a little confused as to why we are receiving this error when a local admin is created during pre-stage. Has anyone else experienced this or has found a way to resolve this?
We have Jamf Pro 10.34 hosted on-premises. We have a single server and a single SMB share, running on Windows Server.We have some files that cannot be downloaded. In Self Service, it says the file cannot be found, but it is there when we check the share and check Jamf Admin. Other files work fine. If we open a browser and just simply put in the URL to files in the share, most work but some do not. On ones that do not download via Self Service, we get this in the logs: Error: Package was not successfully downloaded. -1005Any help would be appreciated. Thanks.
I have recently secured some unused iPads in our environment previously enrolled in JamfNow and wondering if it is worth enrolling them in JamfPro or just getting new devices (9th Gen or newer). Does anyone know when support or ADE will not be available for 5th and 6th generation iPads with JamfPro? Thanks!
Is anyone able to get Groups working for privileges in Jamf Pro? I can add a group, search it via our Entra integration, but once its added, i still get access denied with the associated user im logging in with. The only way SSO will work is if i manually add each user. Jamf Support told me add the group as a standard group, matching the name 100%, which obviously still didnt work. Before i go back to support, curious if anyone here has run into something like this?
Hi all, We have a strange issue that i am hoping you can help with. We have had around 10-15 instances where 802.1x WiFi and LAN profiles disappear from a users device. To give some context, its a single profile with LAN and Wifi 802.1x networks with a single SCEP profile, the issue happens on all kinds of devices on different versions of Sonoma and Sequoia. The profile shows as installed on Jamf and the device however the SSID is missing from known networks. The fix is to exclude the device from the profile and then remove the exclusion and the profile reinstalls and all is good. We've logged a ticket with support and they have ruled out Jamf and said its an Apple issue and to log it with them. Has anyone else come across this and been able to resolve it? Its so frustrating as its so sporadic and we cannot reproduce the issue on demand so its proving difficult to resolve. Thanks in advance.
I'm trying to deploy Jamf Connect as part of a PreStage enrollment, and this should now be possible from an on-prem https: DP with no user authentication. I'm obviously not going to replicate my entire package portfolio onto an un-authenticated DP, so I must populate it manually (selective replication is only available for cloud). I've created manifest plists as per documentation and added these to Jamf Pro via the Settings - Packages page, and staged my packages and manifests on the enrollment DP, but cannot get them to deploy in PreStage. Mgt History reports them as being installed, but there are clearly not. Any ideas how to manually manage an enrollment Distribution Point?
Another script that grew out of necessity. Trying to "encourage" users to restart their Macs at least once every 30 days to help with overall system performance, make sure all policies are installed, fix network related issues, etc. so I can with with this super simple Dialog notification that shows up once a week if they are in the "over 30 day uptime" smartgroup. Users don't have to restart, but if they do, you can set a custom timer to do an automatic restart for them. I used the AppleScript method of doing a restart so it will prompt the user to save their docs before a restart. Script can be found here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/UpTime Regex I used to calculate 30+ days And the script parameters...you can control the uptime days and timer value.
I have deployed some printers using the profiles and now we need to remove them and add new ones. How can this be achieved with Jamf School as there is no remove option. Removing the profile does not uninstall the printer from the system pane on the users computer.
Hi everyone, I’m in the process of setting up Jamf Connect in our environment and would really appreciate some guidance on best practices for configuring the login window, especially when integrating with cloud identity providers (like Entra ID). There are a lot of options and functionalities in Jamf Connect, and I want to make sure I cover the most important ones - the "must-have" configurations for a solid and reliable user experience. If you could share: Your go-to plist keys or config profiles Example scenarios you've addressed What has worked (or failed!) in your setup …it would be extremely helpful 🙏 Thanks in advance! Looking forward to learning from the community.
Hi all, I'm trying to properly configure Jamf Connect with Microsoft Entra ID (Azure AD) for a passwordless login experience using Microsoft Authenticator push notifications. Right now, when a user logs into their Mac using Entra ID with passwordless push approval (without entering a password), Jamf Connect always prompts them to set or enter a local password after the identity is verified. My goal is to avoid this step entirely — i.e., users authenticate via Authenticator app and immediately get logged in to the local macOS account, without being asked for a local password. Thanks in advance for any clarification or guidance!
Bonjour, Avec Jamf Composer, nous avons le bug suivant : L'espace disque demandé pour un paquet est de 107 Go alors que le paquet à une taille de 155 Mo. Le paquet à été fait avec Jamf Composer 11.15.0 sur macOS 15.4.1.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!