Get Support
Recently active
Hi there my iphone xr is stuck in recovery mode after udate of ios 13.6.I hav reset my iphone to give it to my brother but it stucked in recovery mode i hav tried every thing but cant fix it done restore with i tunes but no result plzzz tell me how to fix it i am very stressed
What I want to achieve: Enroll AppleTV 4ks (with only HDMI port) in Jamf School and add them to ASM via Configurator 2. My Steps so far: Followed the Apple documentation: https://support.apple.com/en-au/guide/apple-configurator-2/cada1ba9dab1/mac Renamed my Phone Hotspot to "Apple Store" (no Password) and the Apple TV and my Mac with Configurator are both connected to the network (both devices connected with some data traffic) AppleTV does not show under paired devices This AppleTV is new and has never been configured (Thats why I used the free "Apple Store" Wifi Trick) Other devices, including other Apple TVs with USB Port show under Paired devices in the same Wifi Additional Question: Is it even possible to enroll an AppleTV without a USB Port to ASM + Jamf School.I rechieved a Tipp, that it is only possible when the AppleTV has never been configured. The Wifi Pairing with the older A.TVs only worked, because I went to the settings of the "Test-AppleTVs" and entered a code.
The issue of iPad usage in schools focuses on restrictions to minimize distractions during lessons and breaks. Our school uses Jamf Teacher software but faces two main challenges: Restrictions During Breaks: Students use iPads during breaks, even though this is not allowed. Teachers often forget to activate the necessary restrictions, leading to distractions. Activation of Restrictions: There is a discussion about the idea of heavily restricting iPads from the start, allowing only the apps needed for lessons to be unlocked. Time profiles could help automatically activate restrictions at specific times. One proposal is to use "iBeacon regions" to automatically lock the iPads when students enter or leave the school grounds. However, this requires students to consent to location services, complicating implementation. The central challenge we currently face is that while the dynamic profiles that activate restrictions work well, the iPads become unusable outside the school premise
Hi,so in a couple of weeks Google will shut down basic auth for gmail SMTP (Transition from less secure apps to OAuth ).As this is how we (and probably many other Jamf Pro customers) set up our Jamf Pro in the cloud to send us notification mails, we are now strugeling to find a way for the future.Has anyone (without an other mail server besides Google) found a solution jet?Or has anyone heard of OAuth support for Jamf Pro smtp settings?Kind regards, Matthias
Originally Posted to Patch Notes and Progress I work within a highly regulated enterprise environment, and so, maintaining visibility into the macOS update workflow is critical. Whether for compliance reporting, proactive remediation, or general fleet health, knowing exactly what’s happening during an update—on every device—is a necessity, not a luxury. Many organizations like my own make use of super, an amazing tool designed and maintained by Kevin White (aka Macjutsu). I’ve previously written about various ways organizations can develop a configuration strategyfor super depending on the industry and need. A significant change in the 5.1.0 release is the introduction of a new, condensed audit log file, located at: /Library/Management/super/logs/super-audit.log This file now contains only the most important status events—installation events, workflow target changes, deadline adjustments, successful workflow completions, and any other event that dramatically alters the SUPERMAN workflo
Hey guys. Bare with me, I have taken oven my company's JAMF environment and have now faced some issues. When logging in to the computer they type in their company email + password then authenticate with MFA. When this is done they face this window "Verify your Azure_V2 password:" and they type in their password and log in. This usually works. But now we have faced issues with user not coming through this step, they are "bounced" back to 365 log in window. This is something pretty new, maybe something changed in azure - but not sure how to remove this step. We have "Passtrouh authentication with Jamf Connect"
On Prem JSS 10.26.1macOS 11.1 I am creating my first set of macOS Big Sur Deployments on non-M1 iMacs. I am noticing a strange behavior of iMacs dropping ALL of the Scoped Configuration Profiles listed in System Preferences --> Profiles, EXCEPT FOR the MDM Profile. Performing a recon will restore the Profiles. This is happening on random iMacs from a Lab of 38 devices. Configuration Profile Settings are: Level: Computer Level; Distribution Method: Install Automatically; Profile Payload does not matter. I do see a lot of CP Known Bugs for 10.26.1, but nothing along these lines. Has anyone else come across this? Cheryl
Description: 1/2 the time that I need a user to Self enroll, due to having a non pre-stage enrolled computer, or failling to enroll properly before assignment, I'll have them self enroll, and then they'll show up in Jamf, but without much of the usual data: Check in, inventory, Policies, OS. This is mostly a case with some of my most difficult users, a team of devs I have overseas and somehow it's turned out to be the hardest ones to get responses or help from - but I've self enrolled a computer many times before and it's not like it asks you for permissions that someone could decline or anything. It just installs the profile. So why do some self installed enrollment profiles give me full enrollment and accept application deployments and policies, but some do not? I've tried to have a few of these people do a Jamf Recon before, a Jamf Check, but nothing fixes it except a full computer reset. Is this the only way to correct this? Is there something I can do to prepare an already-deploye
I'm looking for a way to detect and automatically repair (if possible) for the 3 following scenarios:- A computer that does check in but does not receive MDM commands- A computer that does not check in but does receive MDM commands- A computer that does not check in and does not receive MDM commands Does anyone here know of such a solution or have tips for me where to do some more research?
We have a little under 200 Departments in Azure AD. I would like a bulk way of adding these to Jamf under Settings - Network - Departments. Don't tell me I have to add them manually, It is unacceptable in this day and age that you have to add a field one by one. Is this something Jamf Support can import on the back end? I can't believe there isn't an import button after using Jamf for 6 years now... I see an export button, gee thanks! Jamf is great but this was just forgotten for some reason :-(
Hello We are gearing up to roleout macOS 15 across our Mac estate. We using super for the update and it seems fine. I have started seeing on some devices once the Mac has been updated to MacOS 15 while you can login you get a black screen and its doesnt seem to reach desktop.I have update other devices and they been fine.Anyone else come across this?Devices are been updated from 14.7.5 in most cases ThanksTom
I have certain users who need to run a Java based application that is started from a JNLP file. The issue is that when they click on it, the built in malware scanner in MacOS Catalina blocks it. Normally they would go to System Preferences --> Security & Privacy --> General and then select to allow it to run. However, this is not available to them. Is there a way for me to set a preference or change a setting to allow this file to run, without me having to visit each machine and without the user having to do anything?
Greetings all, The advisory group for IT at our university (Notre Dame, northern Indiana, United States) suggested that we develop a "peer group" of other universities using Jamf Pro to manage their Mac fleets. While I know that we can post conversations here, "ours is not to reason why"... :-) At any rate, if other higher education institutions would like to connect with us (and us with them) on a casual basis, please contact me (mild obfuscation here to hopefully avoid scraping, user bcarter at local domain nd top level domain edu). We have just moved to the cloud product from on-prem and are particularly interested in talking to peer institutions about best practices and so forth. Thank you for your consideration. Bruce Carter, Senior System Engineer, University of Notre Dame
Hello everyone,We've been experiencing this problem on rare occasion however it seems like its gotten progressively worse and figured I should ask for support as I cannot figure out for the life of me. I have an ongoing ticket with support but i figured why not ask the community as well.Workflow using ENTRAID:Mac boots up, user selects language, region, wifi, remote management screen appears, they sign in using their credentials, jamf connect window appears for them to reenter credentials again, account gets created and users now at the desktop.The problem occurs remote management screen>sign in using their credentials>black screen>reboots to the user language section>reboots>user language selection>repeatMy first thought is our jamf connect configuration even tho is placed inside of our prestage enrollments, and is scoped to all users and all computers will sometimes not be received by the macs. Now i only say that because if i remove the same configuration profile,
Good afternoon,I need to deploy Blender to a couple of computer labs. Since its a drag and drop application, how do I prep this for deployment without a package?
Has anyone worked out how to actually use this new feature? I'm particularly interested to see whether this feature could pass the onpremisessamaccountname into jamf connect using a variable finally without having to add any optional claims. In short I want to pass the onpremisessamaccount name to jamf connect so that it creates a local account using the shortname that i also want to use for kerberos authentication (both of these desires at the moment require significant hoops to jump through). I was expecting there would be additional fields available on the Entra Identity Provider Page in Jamf Pro under 'mappings' however it still looks the same to me. Second to that has anyone actually figured out how to actually pass these onPremisesExtensionAttributes into Jamf Pro yet? I'm so glad that Jamf Pro is providing some additional features that will help us blend on premises envirotnments more easily. Now I just need to figure out how to use them :) Any h
Hey everyone Since a couple of Sequoia releases the version of Safari is not being updated on our Macbooks ! As example this morning I've updated my (enrolled) machine to Sequoia 18.4 but my Safari remains on version 18.2 (19620.1.16.111.6, 19620). Of 88 devices (all up to date with macOS -> 15.3.2) 77 devices only have Safari in version 18.2 ! softwareupdate -l doesn't show any available updates. Does anyone else have seen this behavior ?
My organization has opted to index the /Users/ directory for various reasons. This hasn't been a big deal until I got a request to patch an application where the dev reused their app name and bundleID on the macOS and iOS versions. As a result, searching for either the Application Name or BundleID catches machines with it in /Applications/ and machines that have a placeholder in ~/Library/Daemon Containers/<device info>/Data/Library/Caches/Placeholders-v2.noindex. I'm kinda stumped on the best way to scope a smart group to include installs in /Applications/ or ~/Applications but exclude that placeholder directory. Usually, the devs have slightly different bundle IDs we can use to make things more targeted. Does anyone here have any recommendations for the best way to scope a group so that it doesn't catch those placeholders locations?
Has anyone else had issues with a very slow to load dashboard with Jamf Pro 11, nothing I seem to do improves the load time as well as information that was present before, like build number etc... are all missing, which is fine, but it does make it give you less information and with slow load times it's just very cumbersome to use now.Any potential fixes for this, cleared cache, incognito, different browsers, no hardware acceleration, different OS, nothing seems to work on load times.
Any idea what this means? OSUpdateStatus - The software update request for this process was denied as another process is currently performing an operation. Please try again later.
Hello! At the school where I work we are planning to convert the mobile user accounts (connected to AD) to local user accounts, and make them admins.I saw the fantastic script on rtrouton's GitHub. I tested it on a test machine and works like a charm, though the issue I have is that it asks for user input, and trying to push it via policy in Jamf, it simply waits. So the question is: is there a way for me to achieve this via Jamf Pro, without the use of Jamf Connect (we currently don't have it)? Thank you
I swear I stumbled upon the ability to do this once but cannot for the life of me remember where or how I did it. So... can you re-order the search categories as seen in the screenshot below? For instance, is it possible to set it so that "Name" comes up first, then "Serial Number" then "Building" instead of how it shows up now (Name, Device Phone Number, Lost Mode Enabled)? It's nitpicky, but I was almost sure it could be done to re-order these categories.
Doing testing in my office and pushing out several commands and profiles to a device. The device is connected to WIFI and has 5 bars signal strength. Everything works great until the screenlock kicks in, at which point, all progress comes to a complete halt. Any commands not executed going into pending with the status message "Device was busy. Will try again".Seriously, if a device has a good WIFI signal and connection, we should be able to send updates to it. This is clearly related to the screenlock kicking in. Question is, why? Is there some helper service that stops responding if the screenlock is on? Or does the WIFI stop transferring data if the screenlock is on?What if we tell our people to leave their devices plugged in over night to do a bunch of updates? Will they be pending all night long and then basically make the device useless in the morning when they unlock the screen and want to get to work?
I created a script that prompts users to run the latest macOS update. The script works perfectly when run through a policy, so there are no issues with the overal functionality of the script. The policy is scoped only to Macs that are not yet running macOS 15.4. We have not decided to allow updates to 15.4.1 just yet. I noticed that the policy ran on a Mac running macOS 15.4. It's likely that this Mac had not yet ran a current inventory that would have put it in the macOS 15.4 smart group, which would have excluded it from running the policy. I decided to add a function to the script to check the current installed macOS and then compare it to the required macOS version. If the Mac is already running 15.4 or higher, I want the script to exit without doing anything. The idea is to run this function before doing anything else. If I fill in "15" for "reqosMajor" and "4" for "reqosMinor", this works perfectly. I put this function into a script by itself to test. Each time the function runs
This was specific to our environment but I could see other environments might run into this or something similar. Running nightly updates and reboots we ran into an issue with Intel devices that would would boot into recovery mode after updates. We did a bit of troubleshooting and realized it won't happen when you run command line softwareupdate --iaR. We couldn't have full OS updates run on these devices so we had to build a script to do that cleanly. Built a script out that looks for the macOS full installers then does a compare and skips any with the full OS update titles. #!/bin/bash echo "Checking for updates..." # Get list of full macOS installers (e.g., macOS 14.x, Sonoma, etc.)full_os_install=$(softwareupdate --list-full-installers 2>/dev/null | awk -F': ' '/^ *Title: / {print $2}') # List available updatesavailable_updates=$(softwareupdate --list 2>&1) # Exit if no updatesif echo "$available_updates" | grep -q "No new software available."; thenecho "No u
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!