Get Support
Recently active
Hi, we are trying to find a solution to prevent the device name from changing after an iOS device is reset. With the PreStage Enrollment method "List of Names", each enrolled device receives a name from the predefined list (e.g., Device0001, Device0002...). However, when we reset and re-enroll the device, it gets a new name from the list instead of keeping the original one. We plan to label the devices with stickers showing their assigned names, so the current behavior is not ideal for us. Is there a way for Jamf to assign the device name as it does now, but without changing it after a new enrollment? Thanks in advance! Currently we have this workaround: We show the hostname on the lockscreen.
After upgrading to iOS 18, students are seeing trusted certificates being removed from their iPads. In our case, they are root certificates that get pushed via Jamf Pro during enrolment - one for wifi access, one is the JSS built in certificate. (click on settings, about, certificate trust settings to see the certificates that get pushed)Is anyone else seeing this please? We are seeing this sitewide, as the OS update rolls out.No fix at the moment other than wipe the device and enrol all over again to get the certificates back - not feasible when you have over 1000 iPads!
Hey Gang, I have gotten 1 computer out of 300 that refuses to finish a jamf recon (either at login or on demand). I am pretty sure that my EAs are OK as the collection works perfectly fine on all of the other Macs. I did try "jamf recon -verbose" and it did provide me a detailed listing, but that didn't tell me much info on where to start troubleshooting... Could it be a particular app or corruption that could be causing this? I am looking for some ideas on what to try next...
Hello everyone, I want to force the Microsoft login windows when the user enrolls a device. I already archviced:Settings -> System -> Cloud identity providers -> Entra ID (Mappings test works) Settings -> System -> Single sign-on with SAML Settings -> System -> User accounts and groups -> Jamf Pro User Groups - > I got two Directory Service Groups for Jamf Pro Administrator access and Enrollment The only thing that's left is the Error HTTPStatus:500 when I want to register a Mac. I don't want the whole bunch of extras of Jamf Connect with local/mobile account creation on the Mac etc.. Just the extra step as login to verify the user is an active member of the company. Thanks a lot.
Does anyone know of a way to modify the built-in extension attribute for a Patch Management title? The issue I'm seeing is that the one for Jamf Protect is pointing to /Library/Application Support but the application is installed in /Applications, meaning the extension attribute is turning up as blank for all the machines. If there's no way to modify, is there at least a way to point the Patch Management version collection to a different place? Any help is appreciated!
I've been asked to deploy some apps as managed on all our iPads - but some people seem to have the app with their own apple ID. Does the 'convert unmanaged to managed' option fix that? Or is my only option to ask them to remove the one they installed?
I've been looking for a way to silently uninstall the zoom outlook plugin but everything I see is just running the uninstall.app. Is that the only viable option (remote connect and uninstall) or is there a better way to do it?
How are you updating your users to the latest version of Safari (17)? Mac Apps does not have Safari available and you can't add Safari to VPP, so I tried creating a package using composer and adding it to a Patch Management policy and pushing it that way, but that is not working. I also tried just creating a regular Jamf policy and adding the package there and pushing it out, but no dice even though the logs show it was installed successfully, but when the machine runs recon it still shows the old version of Safari, not Safari 17. I have Software Updates (System Settings>General>Software Updates) disabled because Restricted Software was not restricting users from going to macOS Sonoma, so this may have something to do with why I'm not able to update these devices to the latest version of Safari, but at this point It's just a guess. Any help is greatly appreciated!
When I was asked to write my thoughts down for a blog to celebrate International Women’s Day, my first reaction was, What the heck?! Advice, from me? More specifically, advice on professional development. Ha! I don’t even RTFM! Then, I had a flashback to 2019 when Jamf asked me to be on their first Women in Tech panel at JNUC. I’ll admit—I needed some encouragement from other admins, my leadership, and my team. I may or may not have gone into hiding when first asked to be on a panel. In the end, I wound up co-presenting with a fellow woman Mac admin on leadership, and it turned out to be a positive experience. After this quick montage in my head, I cast my doubts aside and realized, Okay, maybe I do have something to share. I can talk about a few key things in my career that I think could be helpful to other women out there. The 2025 UN International Women’s Day (IWD) theme is “For ALL Women and Girls: Rights. Equality. Empowerment.” This theme focuses on empowering the next gener
I am relatively new and not very knowledgeable when it comes to certificates. About a year ago I successfully created our company's push certificate for JAMF Pro (cloud version), and it is about to expire in a couple weeks. In attempting to renew our push certificate for another year I get the following message after I upload the new .pem file I downloaded from Apple. "WarningExisting devices that are enrolled with Jamf Pro will no longer respond to push notifications." What does this mean? What will happen if I complete the process as-is? Will I need to re-enroll my devices? Will they stop responding to JAMF? Should I wait until the actual expiration date to create a new push certificate? I believe I am using the same Apple ID, but is there a way to check or verify this? Any help would be appreciated. Mark BishopCommunity Action, Inc. of Central Texas
Hello, in our company, we automatically synchronize some SharePoint/Teams folders on certain Windows devices. Is there a similar solution for Jamf? Or does anyone have any ideas on how I could implement it best? Thank you in advance!
Hello everyone we have a major performance issue with Jamf Teacher (Jamf over jamfcloud.com). In a class of 20 students, it sometimes takes over 10 minutes for the last iPad to receive the profile. Since there are also such problems with other online services, but the speed of the Internet connection is about the same everywhere in the building (measured), I think it could be due to the configuration of our network. Has anyone here perhaps had similar experiences and found a solution?
Hello,I'm trying to find out if Jamf Pro has a audit log of users that log into Jamf Pro for administration and the actions they preformed? Looking for a audit log to trigger alerts in Splunk for when a new "Standard User" is created or etc...
Hello Hoping someone can point in the right direction.Im in the process of updating our secuirty base lines we settled on using Level 2 CIS.Things are going well so far with no major issues.I noticed our updated firewall config as cut of the ablity to screenshare using vnc I think I just need add allow com.apple.ScreenSharing under this section. Does anyone have the bundle ID for com.apple.ScreenSharing or now how to find it.I would normal run something simliar to this https://www.hexnode.com/mobile-device-management/help/how-to-find-the-bundle-id-of-an-application-on-mac/ but only seem to work for apps. I dont think it would work as its not an app. Thanks
Hi, Calling all jamf script superheroes... I am a newbie to scripting, I want to make a script to enroll computers to JamfPro and then add the computer to a specific static group. Could any one please share/help if you have a working script handy? I managed to make one but I am stuck with downloading the CA and enrollment profile config files. If I managed to download those two config files, I have to install it manually by clicking them and then the script continues and moves the computer to a specific static group, then a binding profile is pushed and the computer get binded to local AD. @greatkemo Is this a piece of cake for you? Thanks
Does anyone have a configuration file for macOS and iOS for locking Teams down so that only a specified user domain can login? Attempting to prevent our students from logging in with personal accounts.
We are testing enrolling Macs in to Microsoft Partner Compliance to enforce Conditional Access policy. For the most part, the process is smooth to enroll and we have not seen too many issues. However the one issue, that will be a user concern, is when a user goes to a Microsoft site (like Outlook on the web), they are prompted by macOS to allow Google Chrome to use the Microsoft Workplace Join Key from the Keychain. Edge and Safari use this key automatically, which makes sense being Apple & Microsoft. I tried adding com.google. to my SSO extension, like i have for Apple, Microsoft, and Jamf, but that doesn't seem to work. (See Below) Is there anyway that I can automatically allow Chrome to use this WJK? <?xml version="1.0" encoding="UTF-8"?> <plist version="1.0"> <dict> <key>AppPrefixAllowList</key> <string>com.microsoft.,com.apple.,com.jamf.,com.jamfsoftware.,com.google.</string> <key>browser_s
Hey,What is the recommended way of handling compliance with the upcoming Sequioa release? I have used the Jamf Compliance Editor to create config profiles for Sonoma, which was very convenient, since the JCE let's you upload perfectly name config profiles for Sonoma and its predecessors.If I am not mistaken, the JCE does not currently support Sequoia, yet. For now, I have set major OS updates to be deferred by 90 days, so I can sort this out.How do you guys handle this?When is the JCE likely to be updated? Thank you for your help.Toby
Want to earn Jamf Rewards Points and a shiny new badge? Get an article published in the Tech Thoughts blog, and (if enrolled) you'll be rewarded with bytes and this sweet badge 👇 If you have information that you'd like to contribute to the community, we want to hear from you! Tech Thoughts blog posts should be 400-600 words covering relevant Apple Admin topics. There's no pressure to write something epic or profound– articles are meant to read like a long-form Jamf Nation post. Interested? Please reach out to me on Slack @Joanna buchmeyer with your submissions or questions. Happy writing!
Hi Everyone, There are Aruba Access Points in my environment. We connect to the WIFI broadcast of these APs via Aruba Clearpass. Authentication is done through this. Then certificates and a Profile are downloaded to the MacOS device. After doing these, we can connect to the company WIFI network. This is a long and tiring process for the user and the technical support teams. We want to do this process automatically, without user participation as much as possible. For this, we decided to use the policies on Jamf Pro. However, we have not been successful so far. The configuration policies we have prepared remain in the "pending" state. We first made the SCEP configuration within the configuration policies and tried it. However, this does not work as it should. We configured this profile by using various documents. Of course, we first installed a Windows SCEP Server and configured it as it should. We activated the NDES service. We saw that we could reach the links we wanted via IIS for the
Following this weekend's update, I decided to start testing out the "Available in Self Service" option for App Installers. This works great for machines that do not have the application installed already. The problem is that App Installers that are set to Available in Self Service do not adopt previous installations of those applications unless the user goes to Self Service and re-installs the application using the App Installer route.Has anyone found a good method to get apps previously deployed by policies transferred to App Installers (Available) without forcing the end users to go into Self Service and re-install the program?
Hey everyone, I wanted to share a Bash script that allows standard users to temporarily gain admin rights for 15 minutes via Self Service in Jamf Pro. This script ensures users can perform admin-required tasks while maintaining security, compliance, and auditability. What This Script Does 1.Checks if the user is already an admin and notifies them if they don’t need elevation. 2. Prompts the user for a valid ServiceNow Request Number before granting admin access. 3.Logs the ServiceNow Request Number along with the username for auditing purposes. 4.Grants admin privileges to the user and creates a flag file for tracking. 5.Deploys a LaunchDaemon that ensures admin access is revoked after 15 minutes, regardless of reboots or logouts. 6.Starts logging all user activity for the duration of admin access, capturing executed commands for review. 7. At the end of 15 minutes, the script automatically revokes admin rights, stops logging, and collects logs for audit purposes. Key Features • E
Hello everyone,Now when we have left our old eDirectory and are up en running with our Entra en AD I put together some Apple Scripts for mounting network volumes - home and shared. The scripts work okej but I think it would work even better if you made them as bash script instead. But I'm not good att bash at all. Maybe someone's willing to help me out? One of the scripts I've done look like follows: set userName to short user name of (system info) set Share_Path to "smb://" & userName & "@our_server_address/home$/" & userName tell application "Finder" mount volume Share_Path open userName end tell Thanks in advance,Jonas
We're having issues trying to install Unreal Engine in our lab of 25 Macs. I've been searching for a solution but have come up empty handed. I found an unanswered question from someone with the same problem in the Epic Games Launcher community, and I've borrowed his description of the problem, as he explained it better than I could: We've installed Epic Games Launcher and Unreal Engine 5.2.1 on all of the Macs. When any other user logs in to use Epic Games Launcher and Unreal Engine, in the Unreal Engine section it asks to install Unreal Engine again, not recognizing that there is already a version installed. When you click Install it tries to install it to the exact same place and throws a ‘Directory must be empty’ error. (Obviously the directory isn’t empty because it already contains Unreal Engine)Unreal Engine is installed to the default /Users/Shared location, and permissions on the /Users/Shared/Epic Games and /Users/Shared/Unreal Engine folders (and their contents) ar
Has anyone been able to script/package beA Client Security? This is a requirement for our German offices, and would like to be able to streamline this if possible.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!