Get Support
Recently active
Hey Jamf Nation!We're excited to announce SCIM-based provisioning and lifecycle management of administrator profiles in Jamf Account, now available in Beta.Inbound SCIM lets your identity provider push administrator profiles directly into Jamf Account without requiring those users to sign in first. Once configured, your IdP becomes the source of truth for administrator lifecycle events in Jamf. This beta supports Microsoft Entra ID and Okta as identity providers.Today, SCIM-provisioned profiles appear in Jamf Account, names stay current when updated in your IdP, and you can assign roles and privileges before an administrator's first login. This is the foundation for platform-wide administrator provisioning across Jamf Pro, Jamf Security Cloud, and other Jamf applications. When that work ships, your SCIM configuration carries forward with no changes required.When configuring your SCIM connection, you can also select the groups scope. Groups sync now but do not yet drive role assignments
Hello Jamf Nation!We’ve released Jamf Pro 11.32.0 beta. This release includes Inventory enhancements, a new UUID column for advanced searches and more! For full details, check out the release notes after enrollment.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Click “Join Community” to join the beta forum once enrolled. If you encounter an error on Jamf Nation joining the beta forum, please log into Jamf Nation and then click “Join Community” again. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this pr
iOS 26.6.1• Fixes 20+ security patcheshttps://support.apple.com/en-us/148282
AI is being used for work every day, whether you've planned for it or not. This workshop is your chance to get in front of it instead of reacting to it.You'll learn how to see what AI apps are actually running across your Mac fleet, control them with the policy builder and Blueprints, and prove they're governed when someone asks with a PDF report. Jamf subject matter experts will walk you through it directly, and by the end, you'll have built and deployed an AI Governance policy yourself.It's free, it's 90 minutes, and it's hands-on; you're not just watching a demo, you're doing the work.Register now and pick a date and time once you're logged in with your Jamf ID.This workshop is for current Jamf customers with access to AI Governance. Not sure if that's you? Your account team can confirm — reach out anytime.Can't make this one, or want to explore more first?Watch the Jamf Short Read the AI Governance documentation Read the launch blog post Join our Product Office Hours each week wher
Hey Jamf Nation,We’ve just added our Jamf 100, 140 & 170 exam voucher codes to Jamf Nation Rewards. You could earn a free certification in the comfort of your home! The Jamf 140 course is our latest offering, launched in April this year 🎉.Check out your Jamf Account to see what’s new and start redeeming those hard-earned bytes.Not a member yet? Learn more and join here.Who’s going to be first to redeem their free exam code 👀
will their ever be a possibility that jamf adds Custom ODIC For Jamf Now, I love using jamf now in my little 1 device homelab and it would be fun if I can setup my Authentik as jamf now
Cisco Secure Client (CSC): Version 5.1.12.146MacOS: Tahoe 26.5Current issue we are facing is that when enrolling new MacBooks into our environment we are seeing that Cisco Secure Client is no longer passing through deviceID to azure to pass through conditional access policies. Previously our environment was running JAMF conditional access, and our devices were enrolling without a problem. All applications were passing deviceID and going through conditional access policies (CAPs) without any blockers. Recently we have shifted over to platform SSO as per many people’s recommendation as the old method was being deprecated. Since then, we have noticed that most applications are still working without issues, but unfortunately Cisco Secure Client is failing to pass deviceID and is now being blocked by our Azure CAPs. The main difference that I'm seeing is that the previously enrolled devices also received a WJP certificate, while the new enrollment method no longer utilizes this check. We or
Hi, I want to ask something about this issue. I’ll describe the test I’m performing.I have a macBook Pro enrolled with in Jamf Pro with Jamf connect. Authentication is done through MS Entra/Azure.The first user, user A, that logins gets a prompt to enable Filevault. User A is now a filevault enabled user.When restarting user A has to unlock the disk as expected.User A is logging out and user B logs in. Now this user is also able to unlock the filevault encrypted disk.User B is logging out and user A logs in again. User A shuts downs the macBook.And now comes the issue I’m facing. When restarting the macBook user B needs to unlock the disk. The name of user B is pre-filled and you have to enter B’s password. When pressing ‘option + enter’ you can choose for another user.So I thought, maybe because user B is the last user that was enabled for Filevault this user shows up. Still strange but let’s give it a try with user C. So after user A or B logs in and logs out again I log in with user
With Jamf Pro 11.31, use app management status as criteria in smart groups and advanced searches, group blueprint components into component blocks, and control the layout of Self Service+. Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
Running RSA MFA Agent on macOS Tahoe in a Jamf-managed fleet. At the screensaver unlock, a legacy `SFAuthenticationController` "macOS wants to make changes" dialog appears before RSA's own OTP prompt. RSA has pointed us at Apple and Jamf, with no clear next step yet.While isolating it, one test stood out. Writing a stock right to `system.login.screensaver`:```sudo security authorizationdb write system.login.screensaver authenticate-session-owner-or-admin```gives the modern unlock UI (wallpaper + password) on a managed Mac, but the legacy black-screen unlock prompt on an unmanaged one — same right, same OS, only variable is management. So the legacy unlock path still exists in Tahoe; something on the managed side is suppressing it.Anyone seen this, or know what MDM-side setting (profile, restriction, DDM) would cause it? Trying to work out whether this is an Apple thing or a Jamf thing before going back to either vendor.
It would be a useful feature in ‘Classes’ if, when adding members by specifying a group, that user group were synchronised.Currently, if you add teachers and enter a complete group at the top of the selection window (‘Member of group’), only the current status of that user group is recorded. Annoyingly, it is not updated or synchronised when new teachers are added.
Need to identify and generate a report of Intel-based applications installed on Mac devices.As this is required to know application compatibility and identify software that still relies on Intel architecture, especially in preparation for future macOS 28.0 releases and Apple's ongoing transition away from Intel-based technologies such as Rosetta 2.
Happy Monday! So I just came across this issue. When a user tries to change their password using Jamf Connect, they get this Kereberos error 4.So they go into Okta and change it there. Later Jamf prompts them that the Local Password and Network password don’t match. They are able to enter the old and new passwords and get the local mac password changed to match. But Jamf still shows “password expires in 0 days”.I didn’t do the Jamf Connect setup, it was here when I joined the company, so I’m not sure exactly how to start fixing this. I’m hoping you have some tips, maybe someone has seen this before, really anything. I’ll keep doing my research, but It’s always nice to get some expert advice.-Pat
JNUC 2026 is coming to Kansas City, September 23–25*.Jamf CEO Beth Tschida sits down with Jen Kaplan to unpack this year's theme, *Power Up, and what's ahead for Apple device management.In this fireside chat, Beth explains why Kansas City's Power & Light District is the right metaphor for where Jamf is headed, how shadow AI is reshaping the work of Mac admins and CISOs, and gives a preview of one keynote moment: a workflow where the device tells you something is wrong before a frustrated user files a ticket.What's inside?What the JNUC 2026 theme "Power Up" means and why Jamf chose it for this yearHow Jamf is connecting Apple device management and endpoint security, and layering AI on topWhy shadow AI has become a day-to-day problem for IT and security teamsA preview of a JNUC 2026 keynote workflow: proactive device health before the support ticketHow to govern AI on an Apple fleetWhat the Jamf Nation Global Foundation is doing at JNUC 2026,CHAPTERS:0:00 Introduction: Jamf CEO Beth
Jamf Pro 11.30.2 (Jamf Cloud),SYMPTOMAn App Installer deployment stays IN_PROGRESS forever after the install hasalready completed successfully on the Mac. Once stuck, Jamf never issues anotherInstallEnterpriseApplication for that (Mac, title) pair. retryable is false, andper the docs "Retry all failed" does not cover in-progress deployments, so thereis no way back other than toggling the deployment off/on (a PUT to the deploymentre-dispatches it within minutes).WHAT MAKES THIS DIFFERENT FROM THE USUAL "STUCK IN PROGRESS" THREADSWe can point at a trigger. From /var/log/install.log on an affected Mac: until 2026-07-12: Will start wait for 1 apps to close with timeout: -1.0 from 2026-07-13: Will start wait for 1 apps to close with timeout: 172799July 13 is the day we set a global update deadline of 48h (previously: nodeadline, so timeout -1 = wait forever). Every stuck deployment we have datesfrom after that change. With no deadline, the install only ever happened whenthe user closed
Today we released Jamf Connect 3.12.0; highlights include: Changes and ImprovementsThe Jamf Connect login window now displays the time remaining before you can attempt to log in after an authentication lockout. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
We’re seeing an issue on multiple (more than 10 Macs, multiple hardware specs) Sonoma (14.8.8) devices which have attempted the 14.8.9 update in the last week. The OS update seems to fail, and the machine reboots, but afterwards no users are able to login (login window shakes as if incorrect password was entered, for all accounts).Booting to recovery we can use the existing user accounts to unlock the disk without any issue, so doesn’t seem to be a SecureToken issue. Using the resetpassword option from Recovery doesn’t fix the issue either, the users are all still unable to login after rebooting to the normal drive. Safe mode doesn’t help either. We can thankfully backup the users’ files (via the terminal in recovery) to an external drive, but the system itself seems to be completely hosed, and has to be erased and have a fresh OS installed.Any ideas what might be causing this sort of issue? I’ve never come across something like this before.
So as we approach the inevitable coming of Self Service + we have noticed something that would be great to remove if possible to bypass some potential issues.In the Mac menu bar the Self Service + icon does not go away no matter what at the moment, and it also has a “Get software” option in the menu that does not apply to us. So I have the following questions:1: Is there a way to automatically hide or disable the icon from showing up?or2: Is there a way to customize what menu options the icon has so that it is more applicable to different use cases where optional software deployed through self service is not a thing?
Thanks again, @boberito! https://github.com/boberito/sc_menu
https://community.jamf.com/p/jamf-heroes
Running into this for iOS and macOS? Vote if interested.Be nice if admins could customize the verbiage for users that fall out of compliance in your organization. Will give the customer a better workflow and user experience. Less calls to the “IT administrator.” Link: https://ideas.jamf.com/ideas/JPRO-I-1479
Hey Jamf Nation, We're opening the doors on something new: Product Office Hours, a live weekly space on Jamf Nation where you get direct access to the people building the product.Each Thursday, members of our Product and Leadership teams sit down with the community for a new theme. Think behind-the-scenes looks at Jamf, product how-tos or big-picture thinking. Submit (and upvote) questions, and get them answered live. No fluff, no script - just real conversation with the people behind the product. 📅 Starts: Thursday, August 13🕒 Time: 3 p.m. BST / 10 a.m. EDT / 9 a.m. CT / 4 p.m. CEST⏱ Length: 45 minutesFirst session: AI Governance: What is it and what can we do with it?Want to see what's coming up, or get a question in early? Head to the Product Office Hours hub. That's where we'll post the theme for each upcoming session, and it's the place to drop your questions before, during, or after any call. REGISTER HERE for upcoming sessions. See you there!Lysette
Anyone else getting errors when working with devices in ASM today? I’ve had two Windows users report it to me, one on Chrome and the other on Edge… then I just got it in Safari on my Mac. Apple status lights are all green right now.
Issue: Mobile Devices on iOS and iPadOS 26 or later Booting are occasionally booting into Recovery Mode. Standard expected workflow: We have Microsoft Entra ID SSO extension configured with the Jamf Setup and Jamf Reset apps. When a user signs out using Jamf Reset three different configuration profiles are removed:Profile with a Passcode payload Profile with a Restrictions payload Profile with a Lock Screen Message payload When the above profiles are removed, two profiles are installed:Profile with a Restrictions payload Profile with a Lock Screen Message payload The issue appears to occur during Jamf Reset sign out as one configuration profile is removed (confirmed by completed command logs) and can vary between the Passcode payload profile or the Restrictions payload profile while the other two commands are left pending.Example pending commands that occur at the time of issue:Clear PasscodeEnable App StoreProfile ListCertificate List I have not been able to reproduce the issue on tes
Hello !Since Tahoe, my profile for the login window doesn’t work anymore as expected.We use Fast User Switching and everything worked fine. I use a profile to enable it and a script to configure it as needed (Full user’s name). But since macOS Tahoe, even if the profile has the checkbox marked, every Mac computer has the user’s full name greyed out instead of white and I can’t switch users. If I remove the profile, everything is fine and the user’s name is white. No matter if the checkbox is marked or not.Is it a bug ? Is there a solution ? I need the Login Window profile for some configs, but maybe that I could script this instead of using a profile ?Any help is welcome !
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!