Get Support
Recently active
Is anyone else experiencing multiple reauthorization prompts per day/week with Platform SSO? I have several users reporting this issue, and it's been ongoing for weeks without a clear cause.
Simply put we are looking for a way to disable the ability to save passwords in the major three browsers (Safari, Firefox, Chrome). Through all of our searching we're unable to find which preference files, or settings we can push out via Jamf to disable this. It seems the modern versions of the browsers make this complicated. Ideally if it was a package we could deploy via a policy that would be perfect, especially if the users themselves couldn't go and manually enabled this option later. Also if it was something we had to run say, once per day, we are probably open to doing that as well. Just seeing if anyone has any ideas or methods they are using.
Is anyone else experiencing an issue where Configuration Profiles are being removed? Every morning, these profiles disappear from over 30 devices, and I can’t work out why. I’ve raised it with Jamf Support, but thought I’d ask here in case anyone else has come across something similar. We’re running Jamf Pro Version 11.14.1, which we upgraded from 11.6 a couple of weeks ago. I’m not sure if the upgrade is the cause, as I didn’t notice this behaviour before the upgrade. I'm seeing this under Management History section.
Hi Jamf Nation,I’m happy to announce that Identity Automation is now officially part of the Jamf family! This exciting milestone represents a significant step forward in our mission to help organizations succeed with Apple. Identity Automation brings industry-leading expertise in identity and access management, and their addition to Jamf strengthens our ability to deliver seamless, secure access for organizations managing a growing number of devices. This partnership is particularly exciting because it combines two crucial elements of modern device management: Jamf’s expertise in device management and Identity Automation’s advanced identity solutions. What does this mean for you? Simplified Access Management: Streamlined user authentication across your ecosystem Enhanced Security: Integration of cutting-edge identity solutions including Single Sign-On (SSO) and Passwordless Authentication (PSSO) Improved Compliance: Stronger identity management and policy settings t
With Jamf Pro 11.15, utilize declarative device management with new Jamf Pro blueprints, get ready for compliance benchmarks, and enforce new restrictions for computers and mobile devices! Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements. Thank you for your continued support and feedback! https://learn.jamf.com/en-US/bundle/jamf-pro-release-notes-videos
Despite documentation that seem to indicate that Bootstrap Tokens are automatically escrowed when using ADE, it still requires an admin to log in for the first time for this to happen. In order to force it, we are using scripts during Enrollment to create and activate a Secure Token for the Managed Local Admin account created during PreStage with a known password. Once it is created, the Bootstrap Token is escrowed by another script also during Enrollment. For both scripts, we pass the known password for the admin account as a parameter. So we've now achieved our requirement to have computer labs' Bootstrap Tokens escrowed during Enrollment without an admin having to physically go to each lab PC and logging in. However, we're concerned about the Managed Local Admin account having a fixed password. If we enable LAPS on the Managed Local Admin account, will there be any potential issues? The way we see it, the known password will just be used twice during Enrollment when th
Hi everyone,Has anyone recently tried using the softwareupdate --fetch-full-installer --full-installer-version 15.4 command—either directly or through a Jamf policy? This applies to any version, not just 15.4. I tried running it earlier today and consistently got the error: “Install failed with error: Update not found.” I’m not sure if Apple has changed something behind the scenes, but it doesn’t seem to work anymore. I came across this recent discussion where someone else ran into the same issue:https://discussions.apple.com/thread/256042015?sortBy=rank
Hey Jamf Nation, I'm currently trying to uninstall Cortex XDR from company devices, but I'm encountering an error that says "Uninstaller not found." The uninstaller is located in the folder '/Library/Application Support/PaloAltoNetworks/Traps/bin/'. Do you have any recommendations or suggestions? Here is my script for the uninstallation: #!/bin/bash # Set your master key here MASTER_KEY="master-key-here" # Path to the uninstaller app UNINSTALLER_APP="/Library/Application\\ Support/PaloAltoNetworks/Traps/bin" # Check if the uninstaller exists if [ ! -d "$UNINSTALLER_APP" ]; then echo "Uninstaller not found at $UNINSTALLER_APP" exit 1 fi # Launch the uninstaller and enter the tamper protection key osascript <<EOF tell application "$UNINSTALLER_APP" activate end tell delay 2 tell application "System Events" tell process "Cortex XDR Uninstaller" repeat until exists window 1 delay 1 end repeat set frontmost to true
Hello, How would I go about allowing Sidecar through the block all incoming connections toggle for MacOS's firewall? I've added the bundle ids com.apple.sidecar-relay and com.apple.sidecar-display-agent to the allow list. This did let Sidecar through but for some reason it's stopped working after a few days. No changes were made during this time. Any help would be appreciated. Thanks!
I have an issue in most of the mac, after enter the password it will stuck by showing loading like below image. This is happening for while restart and login or after un lock the device, to login need to do force restart the MacBooks. Does anyone faced this issue? Any solution for this?
Challenge - Using Computer-Based Certificate Authentication after Microsoft's’s Implementation of Strong Certificate Mapping while leveraging ADCS requires some extra steps to gather Computer Information from Active Directory. As per Jamf Tech Document - Supporting Microsoft Active Directory Strong Certificate Mapping Requirements Microsoft implemented their changes on the 11th February 2025. The existing article provides detailed guidance on how to overcome these changes and adhere to the new requirements from Microsoft. The method provided via an LDAP Extension attribute works great for User-based certificates. The recon information is going to pull the SID for the user and not the computer. We also have no way to query computer records from Entra ID or LDAP connection, as we using Inventory Update LDAP Connection to query user info only When binding a Mac to Active Directory. A computer record is created which will contain the SID that is required to adhere to the new
Hi Teams! Migrating to Self Service Plus and started testing. Created the profiles\\configs and devices are getting the new Self Service Plus portal with no issues. What is proper process to uninstall self service legacy? Do I create smart\\dynamic groups that check for self service + installed then create app block\\uninstall for self service legacy when those devices meet the criteria? Thank you!
There is a lot of information about custom macOS screen savers and how to implement, but it took me a long time to sort through everything and find answers, so i am posting my findings here. I am going to try to keep it simple. Task: Deploy a custom screen saver built by an in house developer using xcode in .saver format. Set the screen saver for the login window and the logged in user. Solution:Part 1 - According to an Apple KB article, you cannot set a "Custom" screen saver at the login window. The article publish date is a bit stale, but after working with Jamf Support and my own testing, this still holds true up to macOS 10.15.2 (also tested on macOS 10.14.6). https://support.apple.com/en-us/HT202223 Part 2 - You can however set a screen saver for a logged in user. Package up your custom screen saver, install it at the /Library/Screen Savers/ path. Add the script below to Jamf Pro. This script was provided to me by Jamf Support. Create a policy, set it for check-in once per co
Hi there Nation! Recently my employer asked to track what employees do on their MDM managed laptop. For example, They want to track every little thing that the employee does on their laptop whether said employee is watching Netflix, Downloading documentation, working on personal projects instead of work related projects. Is there feature on JAMF that allows this? I wouldn't like to source out a 3rd party for this, but if not possible in JAMF then I could do that. I know we have logs but it's not detailed enough for them. Please and thank you!
Hey everyone, at the moment we're testing a new WiFi network. Some of our students iPads have been assigned a profile for that WiFi network, so they can log in while supervised with their teachers. The profile is set to not automaticly log into the wifi network, so the iPads don't just yet rely on that network. Now I tried to update that setting so that the iPads SHOULD automatically log into the wifi network, but the setting on the iPads themselves does not update, even tough the profile has been updated in Jamf School. The other way around (iPads connect automaticly and the profile is updated so they don't do that) the setting updates as intended. Is this a bug? Does anyone have an idea how to get around this issue without making the iPads forget the WiFi completly?
I have a "few" laptops that users have "forgotten" to return when they have left the company. What is the best way to disable the user from Logging in to the laptop using Jamf. I would like to just disable all non admin logins MAybe popup a banner saying Please return to xxxx.. I know I can wipe it if needed. Thanks S
Curious if anyone has used Jamf to install the ServiceNow Agent Client Connector for macOS.Per this document, there are 2 installation methods:https://docs.servicenow.com/bundle/tokyo-it-operations-management/page/product/agent-client-collector/concept/acc-install-mac-os.htmlOne is a simple command line install that references back to the SN Server (notably, the SN "mid-server") to get the installation packages and such.The other is a more manual install that requires downloading packages and configuring connections. Has anyone done this? If so, which method did you use? Any gotcha's to look out for? Background here is that we are currently using the ServiceNow Service Graph Connector to get data from Jamf to the ServiceNow CMDB, however SGC has been getting more unreliable. It appears ServiceNow is applying fewer resources to SGC than in the past and the product is not keeping up with Jamf or even other SN products. ThanksPhil
Jamf pro is down from 10 hours and there is no ETA, I hope we will be getting RCA from Jamf otherwise it would be very difficult to make management understand about this blunder. PS: The employee who did this probably getting a new job soon, I am not sure about me :( and my colleagues @tanuj
Hello Everyone, I am looking for some assistance with an issue that I am wondering if anyone else has ran into. I have JAMF as our MDM for MacOS. I am moving towards MS Intune for our Windows endpoints. Currently I have JAMF setup as a Proxy to deploy SCEP certs to our Macs. This was done using Entra ID App Proxy with a Private Network connector. This works great. Now for the problem... I want to setup Intune to deploy certs to our Windows endpoints but it fails unless the "PFX Certificate Connector" is installed. When that gets installed, it highjacks the SCEP URL and blocks everything not coming from Intune. Essentially I can only have one or the other. JAMF or Intune. Has anyone got both of these working at the same time? Thanks in Advance for any help.
On Saturday, May 24, 2025, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time ap-southeast-2 May 23 1400 UTC 1800 UTC ap-northeast-1 May 23 1500 UTC 1900 UTC eu-central-1 May 23 2200 UTC 0200 UTC eu-west-2 May 23 2300 UTC 0300 UTC us-east-1/2 May 24 0400 UTC 0800 UTC us-west-2 May 24 0700 UTC 1200 UTC Jamf Cloud Hosted Data Region Information
Hello, I am sorry to bother everyone on this matter, but I have been working on an issue for a week and I haven't been able to find a solution to my problem.I can feel I am not far, but there is one last thing in my way which prevent me from moving forward. To make it short, we are about to push Sierra upgrade on all Mac using LANDesk (Ivanti). So far everything works well. I was able to write a script to bypass FV2, I also wrote a script which force quit all the Application in order to prevent a restart. But the last scenario that I am working on and which I am struggling is to Force log out any active user in a Mac except the current user. Using the command line sudo kill <pid> With this command, I was able to force logout an active user of a test Mac, but to do so, I had to find the PID.Now the difficulty is that in my company, we have many users, and I can't find the PID for each user on each computer manually.So I need to write a script which will find the PID of all
Our company is moving to Freshservice. Working on a policy to push the Freshservice agent to all our Macs. The Agnet is a pkg file and that installs fine but I can't figure out how to make it reference the json file for the registration key and account info. I tried using Composer to create a custom pkg but it flat out doesn't work. Any assistance would be appreciated.
I thought I disabled update notifications from Apple via config profile by unchecking "Allow software update notifications" in the Restrictions > Applications section, yet I still get these:Did I miss something?Thanks.
Hi, We use Jamf to auto update Microsoft apps like Word, Excel and Powerpoint. Recently all our users are now seeing this message when Jamf updates the apps. Has this happened to anyone else and is there a fix for it?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!