Get Support
Recently active
I know this has been asked before, but has anyone been successful using Jamf Pro to accomplish either of the following on managed iPads?Prevent students from deleting their Chrome browsing history. Prevent students from signing into Chrome with personal Google accounts (either allowing only our managed Google Workspace accounts or disabling personal sign-in altogether).If you've gotten this working, would you mind sharing how you configured it? Was it done through a Chrome managed app configuration, Google Workspace policies, Jamf restrictions, or a combination of the three?
Written by Diane Meza The demand for skilled Apple IT professionals isn't slowing down. As more schools and businesses build their operations around macOS and iOS, they need people who know how to manage, secure, and support those devices at scale — and the talent pipeline hasn't kept pace.Mesa Community College is helping close that gap. Through the Maricopa Information Technology Institute (MITI), in partnership with Jamf, the college offers the Enterprise IT Professional Apple Technology course series: a hands-on iniative built to turn students into job-ready Apple IT professionals.Learning by doingUnder instructor Carl Cortez, students get more than lecture time. The initiative combines classroom instruction with real device management experience, covering how to work with macOS and iOS and how to manage them in both business and education environments. Along the way, students earn Jamf 100, Jamf 170, and Jamf 200 certifications, credentials that carry weight with employers already
Launching the inaugural Mac Admins User Group Paris meetup during Apple annual developer conference week was quite a challenge… but a good one, and I must really thank all the Jamf team for helping us to make it happen in such a short time! As a long time Mac user, I loved the energy from Apple Expo in the old days. Since its termination, Paris has long needed a localized hub for Apple IT professionals to connect face-to-face. I worked on different Mac admins events in the past (Command IT, Gete.Net Connect), but I felt that choosing WWDC 2026 as our kickoff theme for this new Paris User Group provided the perfect catalyst, uniting the community around massive technical shifts. WWDC 2026 Highlights for Mac Admins Apple made it absolutely clear this year that Declarative Device Management, aka DDM, is no longer just the future, but the present standard. Hopefully, the message was well sent, and as our favorite management tools have been updated to use DDM properly, and this transition s
I have gotten as far as the OneDrive icon prompts and says “Your IT department wants you to backup your folders” and if they click the botton it does work, but I’d like to have this just forced with no choice. This is what I have setup as far as a policy { "title": "Microsoft OneDrive Folder Backup", "description": "Silently enable OneDrive Folder Backup for Desktop and Documents and prevent users from turning it off.", "type": "object", "properties": { "KFMSilentOptIn": { "title": "Tenant ID", "description": "Microsoft 365 tenant ID used to silently enable OneDrive Folder Backup.", "type": "string", "property_order": 10 }, "KFMSilentOptInDesktop": { "title": "Back up Desktop", "description": "Silently move the user's Desktop folder to OneDrive.", "type": "boolean", "default": true, "property_order": 20 }, "KFMSilentOptInDocuments": { "title": "Back up Documents", "description": "Silently move the user's Document
Hi, We deployed self service + with jamf connect globally to our environment and computers that use local accounts are now showing a self service + login prompt. The prompt will not go away and will display over all other windows. We can log in, yes but these are shared use local accounts and we don’t want users to log in with their credentials to self service +. That would be a security concern. We’ve tried setting up restrictions for self service + and its processes but that has either not worked or the window still pops up momentarily every few seconds.
Greetings,Is there a way to determine the last time a policy was triggered? I’m doing some clean-up in my cloud environment, and have several policies created by other people that I’m reasonably certain haven’t been used in a long while; like months or years. Ultimately its my decision on whether to remove the policy or not, but having evidence to support that decision (and the knowledge of how to get that evidence anytime) is useful to me.
I have a fleet of ipads that run conference room meeting equipment. I’m trying to figure out a way to schedule them to reboot overnight, a couple of times a week. I know this can be done with a policy for macos. I’m hoping i can accomplish something similar on iOS. All the answers i’m getting seem to be related to the computer side of things. Any help would be greatly appreciated.
We have a number of machines that restart when left for awhile. These machines did not do when old MDM, but after am getting a number of complaints. Mine also does this. It is reminiscent of the M5 issue that was fixed in 26.5.1; however, none of the machines that are having this issue are M5-based including my own, which is an M3 Air.Is there a fix for this? Could it be Digital Guardian or SentinelOne.
Hi everyone,I recently built a small native macOS utility called App Signing Inspector to make it easier to inspect applications and create application-execution declarations for the new macOS 27 Declarative Device Management controls.I started working on it while testing the macOS 27 beta because gathering the correct signing information and manually building declaration JSON was becoming repetitive and easy to get wrong.What it doesThe Inspector lets you select a macOS .app bundle and displays information such as:Bundle identifier Application version and build Executable path Signing ID Team ID Signing authorities Complete designated requirement Hardened runtime status Gatekeeper assessment Locally reported notarization status Apple Silicon, Intel, or Universal architecture classificationThe separate Policy Builder lets you combine multiple applications and rules into a complete com.apple.configuration.app.settings declaration.It currently supports:Allow and deny rules Signing ID and
We are a K-12 independent school preparing to implement Jamf Protect. Our immediate, high-priority goal is reigning in the highly creative gaming habits of our middle schoolers and not so much of malware protection. We recently migrated away from Santa and are hoping Protect will be our new line of defense. If you are using Protect as a method similar to this, what are some things you wish you knew when you first implemented it, or what challenges or succeses have you had with it?
So I was looking at deploying the updated Adobe apps using the Mac Apps feature rather than packaging up from the admin console and making a policy. However; Apparently you can only target one group. O.N.E. group for deployment. Since I want to stage the deployment to different labs rather than all at once (by making yet another smart group), I would have to add multiple instances of the app.Blueprints can be deployed to multiple targets, So can software updates. Why can’t Mac Apps do the same? Am I missing something?
With Jamf Pro 11.30, administrators have increased visibility with a new Last Contact field in device inventory and can configure activation conditions for blueprints. Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Today we are releasing Jamf Pro 11.30; highlights include:Inventory Reporting EnhancementA Last Contact field has been added to computer and mobile device inventory records. This attribute displays the date and time a computer last made contact with Jamf Pro using the Jamf binary, MDM, or declarative device management, or the date and time a mobile device last made contact with Jamf Pro using MDM or declarative device management. This attribute can also be used as criteria for smart groups and advanced searches. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Subscribe to Jamf Learning Hub contentWhen logged in to the Learning Hub, click the Subscribe button (bell icon) on the release notes page to receive email when that content is updated (i.e., a new version of Jamf Pro is available). For more information about the Subscribe feature, see Jamf Learning Hub Watchlist. To access new versions of Jamf Pro, log into Jamf A
We are excited to announce the return of the Learning Hub watchlist. To get started, log in to the Learning Hub and click the Subscribe button on any page you would like to watch. You will receive email notifications when that content is updated. By subscribing to "Release Notes" and "Release History" pages, you will be notified when a new version of a Jamf application, portal, or capability is available.Notes: You will receive a separate email from "learn@jamf.com" for each page you have subscribed to. The subject line of each email message will include "search summary". Email notifications will be sent once per day at 11 PM Central Time (UTC-5). To manage your subscriptions, navigate to My Library > saved searches.
Are you familiar with or have you used MacPAR deLuxe?For a long time, it was a go-to tool for creating and using PAR2 files, which can repair corrupted files using parity data. PAR2 files are primarily used on Usenet servers (newsgroups).The problem is that the application was developed solely for Intel-based Macs and appears to have been abandoned since 2018. Furthermore, the announced removal of Rosetta 2 in a future version of macOS effectively rules out its use on Apple Silicon Macs.PAR2Manager can help you solve this problem. Developed natively for Apple Silicon Macs (while remaining compatible with Intel Macs), this open-source application allows you to create, verify, and repair PAR2 file sets.GitHub : https://github.com/chrisbasse/PAR2Manager
This thread is a decent reference to the "feature" on Big Sur, as it's not brought up that much from what I can tell: Solved: Hide "Your screen is being observed" - Jamf Nation Community - 236104Unfortunately the solution was "you can't" and I would not be surprised if that's the same solution here, just want to confirm before I have to break the bad news to the teams that'll be affected by it. Now when you remotely screenshare with ARD/VNC, it makes a very obvious popup from the menu bar with icon stating that "Your screen is being controlled" with the IP that it's coming from:And then on top of that, it says when it stops being observed: I get that it's for security and can help a little bit, with the off chance that someone sees a connection that's not with an expected IP address (for example we'll be asking folks to watch for any non 172.etc addresses), but most end users won't know or retain that information and generate unnecessary noise and change a lot of behavio
Is the API call for the "Overview of Automated Device Enrollment devices" working for anyone? I use Jamf School, and while many endpoints work perfectly, this one doesn't. I am getting a "404 Not Found" error.GEThttps://{yourDomain}.jamfcloud.com/api/dep
I am attempting to roll out Jamf trust for ZTNA. I currently have Crowdstrike falcon installed on all of my fleet. My understanding is a limit of Mac is only one network filter can be active at a time. It seems like Crowdstrike doesn’t play nice with Jamf Trust. Even with the filter disabled I am unable to edit the DNS settings to have default to Jamf. Has anybody successfully deployed both products?
Districts buy a lot of apps. Some get used every day. Others quietly gather dust after the first semester. The problem is that most IT teams don't find out which is which until renewal season, by which point it's too late to make a good decision. That's the gap RapidIdentity Insights is built to close.What Insights actually shows youInsights is the analytics engine built into RapidIdentity. It doesn't just tell you an app is licensed. It shows you how students and teachers are actually using it, down to the individual login. That includes:A full inventory of your SSO applications, including their status, security controls, and who has access to what Usage stats by user type, school, grade level, or location, so you can see exactly which apps are catching on and where Trend analysis and forecasting, so growth or decline in adoption shows up before it becomes a budget surprise Individual application launch events, if you need to drill down that far Engagement tracking, including which us
We have all our Users Synced from ASM. Pupils will bring their own iPads from August. These will not be Supervised but we would like them all to enrol in JAMF.Is there anything that could be done during Enrollment that would automatically associate the device with the correct User so that we can use JAMF Student?
Another year, another Jamf Nation Live London and Berlin in the bag! And this might be bold to say, but I think it was the best one yet. This year, the Community team wanted to approach things differently. Rather than assuming we know what you need from us, we wanted to hear it directly from you, the community members, so we could understand our gaps and figure out how to close them. My "vision" was simple: create an interactive space that got attendees to stop and think about where they are in their Apple admin career, and see other people right there alongside them. We built a wall showcasing the different stages an Apple admin might find themselves in, from just starting out in management and security, all the way through to leading teams and strategy, with plenty of stops in between. Attendees filled in cards with a mix of light-hearted preference questions (light mode vs. dark mode... guess what won? 🌚) and the areas where they'd like more help, like AI integration, career growth
https://ideas.jamf.com/ideas/JPRO-I-2178i think this would be invaluable, please vote on if you agree
Newbie MDM user here. Signed up for Jamf Now and have 6 iPhone 14's being managed for work. The iPhones are not signed into an iCloud account. What is the best/easiest way to push a managed list of contacts to the phones?
What are the best practices for legal name changes for staff when utilizing Google Workspace and JAMF Connect? If you change the Google Workspace account name, JAMF Connect creates a new user on the users Macbook when they log in with that new account. How would I effeciently sync the new google account to the previous user account. I have read the Unmigrating a local Account post, but not sure how that helps with linking the new google account to that unmigrated account now.
Configuring single sign-on through Jamf Account for administrator authentication to the Jamf platform now supports Microsoft's admin consent flow for Entra ID connections.From Organization > SSO > New Connection, choose Entra, then select "Use Microsoft's admin consent flow for multi tenant applications." Click Connect with Microsoft and approve the screen. If you're not the Entra Global Admin, copy the link and send it to them instead. Once they approve, Jamf configures the connection. Manual configuration is still available as an option.New Entra connections request GroupMember.Read.All and User.Read instead of Directory.Read.All. Existing connections on the old scope can switch to the new scope using the "Entra Scopes" selector, which preserves existing group mappings.If your organization's domain is already verified in Microsoft Entra ID, Jamf inherits that verification automatically. Domain verification in Jamf Account is skipped for that connection.Full setup steps: Setting
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!