Get Support
Recently active
Experiencing issues with the JAMF Remote Assist feature! It was effective for a few months, but now, I'm unable to access any devices remotely. Even after trying the troubleshooting methods recommended by JAMF Support, the problem persists. I've learned there's an ongoing product issue. Is anyone else encountering similar challenges?
Hi Jamf Nation Community, I’m reaching out to get some advice on using Jamf Pro to manage macOS devices for an upcoming event I’m organizing. I’m hosting a viewing party for the Masters Tournament 2025 (happening from April 10 to April 13 at Augusta National) for my team, and we’ll be streaming the event live on multiple MacBook Airs and iMacs in our office. I’m relatively new to Jamf Pro, and I want to ensure everything runs smoothly during the event. I’d really appreciate your insights on a few challenges I’m facing! Here’s the context: We have about 15 macOS devices (mostly running macOS Ventura and a few on macOS Sonoma) that we’ll be using to stream the Masters 2025 via FuboTV. I’ve already set up a guide for my team on how to stream the event, which I found helpful for planning (you can check it out here if you’re a golf fan: How to Watch the Masters Tournament 2025 Live on FuboTV on my blog at masterstournament2025.wordpress.com). However, I’m running into a few issues with Jamf
Hi, I see there is a configuration Profile that enables FileVault and a Policy that does the same. Can someone tell me what the difference between those two is? Do I need both? Do I only one? Do they have different use cases? Kind regards
Hello There, Can someone give me a suggestion for below configuration profiles and policies. 1- Lock screen wallpaper (screensaver after 5 minutes idle time) 2- MS teams background image 3- A custom PowerPoint templates 4- Custom Outlook Signature 5- Deploy a custom font and set as a default
My company sent me a MacBook to do some application testing on, but I initially couldn't login to it. I had to reset the device and let it re-enroll in our Jamf cloud before I could login to it.I can login as a standard user now. These are not domain joined and there is no local admin account right now.I am a Jamf administrator, but I've never used it. I went and created a new policy that targets only my computer that was supposed to create a new local account with administrator privileges, but it doesn't appear to have worked.Any suggestions?
After a recent patch we have had LIS files recently start requiring admin privilege's to open in TextEdit. Is there a way in Jamf Pro to allow for this without admin creds?
Hi All, Long time reader, first time poster! I was wondering whether anyone has successfully implemented Platform SSO with password auth whilst using Entra ID & Jamf Pro? We are currently working with this in testing. Initial UPN sign-ins are successful, but subsequent sign-ins with the user's UPN following a password change do not work. The user can however sign in successfully with their new password by either using their display name or UPN without the "@", suggesting it may be the user mapping that's at fault rather than the IdP connection. Has anyone experienced this? Any help would be greatly appreciated! Cheers!
Hi Folks,I'm putting this here to try to be a little helpful. We just moved from v5 to v6 for GlobalProtect, and basically, the setup that we had that, installed the stock pkg from paloalto and relied on a config profile to set our default portal stopped working. I also couldn't get the app to stop an endless "connecting" loop. So for anyone who is having the same issue, I hope this is helpful. Long story short, you need to package an XML file that installs the system extension with the app pkg and then run a script to install both.The GP release notes for 6.0.1 speak of a new Simplified and Seamless macOS GP app deployment Using Jamf MDM integration feature. The documentation is helpful but not comprehensive so I'll put it together here. Sources: https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/mobile-endpoint-management/manage-the-globalprotect-app-using-jamf/deploy-the-globalprotect-mobile-app-using-jamfhttps://docs.paloaltonetworks.com/globalp
I have a user on an M1 MacBook Air who has suddenly been getting the following message - credential verification failed because account is temporarily locked. We authenticate via 365 using JAMF Connect. I have checked on Azure (or whatever its new name is!) and the account isn't locked, I have sent a command via Unlock user account but no success -- any ideas ??thanks in advanceLenny
Trying to get an understanding of what some scripts do that were written by a previous Jamf admin. We have a device in our fleet that keeps racking up Pending management commands. The MacBook in question is up to date in terms of OS and software updates, but it never seems to process any management commands. I tried clearing them then sending a blank push, but that didn't do anything. A bit of online searching uncovered the recommendation to run the following command: sudo profiles renew -type enrollment I ran that on one of my test devices (actually ran it from Self Service because the script is a payload to a Policy) and am trying to understand what the script actually does, or how I can tell that it ran successfully. I can see in jamf.log where the script began to execute, but there's no other info in jamf.log or install.log. I checked the system logs by running the following Terminal command: log show --predicate 'process == "mdmclient"' --info That returned a ton of information, a
Hey Nation, Recently we deployed user initiated enrollment for all users in the company. But after that, a large group of developers are having issues with VPN connection. We are using OpenVPN. The VPN gets disconnected after every 2-3 hours and developers need to reconnect it. It is happening with GitLab, ChatGPT and some other webpages. It is affecting their daily workflow since they always need to push-pull repositories. Any idea what can be a reason behind this? Please note, we didn't put any networking restrictions on Jamf side. But WiFi profile was deployed from configuration profile. I am clueless here as a newbie. Thanks in advance.
I saw during one of the demo's at JNUC this year someone had added custom logo's to their JSS icons (not necessarily self service). Was that something they did manually or is there a way to brand my JSS that I'm unaware of?
Good morning, We recently upgraded our MacBook fleet to MacBook M1 Apple Silicon. Our old scripts that allowed us to force bluetooth back on does not work anymore do the restrictions of Apple Silicon. I was checking if any found a to turn bluetooth on using terminal? I found the /usr/sbin/bluetoolctl in terminal but it only shows if the power is on for bluetooth but nothing else.
Provide your users a “heads-up display” of critical computer compliance information via swiftDialog Background More than six years ago, William Smith (@talkingmoose) published "Build a Computer Information script for your Help Desk"; we implemented a customized version in the fall of that same year. Last week, during a conversation with one of our rock-star TSRs — whom I’ll refer to as “John” — we decided it was time for swiftDialog-ized reboot. Features The following compliance checks and information reporting are included in version 0.0.2. Compliance Checks Compliant OS Version Last Reboot Free Disk Space MDM Check-in MDM Inventory FileVault Encryption BeyondTrust Privilege Management Cisco Umbrella CrowdStrike Falcon Palo Alto GlobalProtect Network Quality Test Time Machine Information Reporting IT Support Telephone Email Website Knowledge Base Article User Information Full Name User Name User ID Kerberos Single Sign-on Extension Platform Single Sign-on Extension Computer
Hi https://learn.jamf.com/en-US/bundle/jamf-account-documentation/page/Jamf_SSO_with_Jamf_Account.htmlUse this guide to configure your Microsoft Entra IDI'm in the process of doing something and it says it's connected, but I can't see the IDP redirection page. Can you share any success stories?
Hello All, Can someone please guide me on this? I have two images one that I want to set as the wallpaper and the other as the lock screen. What are the possible ways to achieve this?
Whenever i try to change the Timezone via the device details page on the bottom it just changes for a second, loads, and then goes back to the old Timezone. This is only happening on a few iPads we have, the other ones are working just fine and they have the exact same profiles and are in the same device groups. The devices location is just as always in germany, but the time is US/Pacific. This is extremly annoying for our employes, because thats like a 9 hour difference between Timezones, so i would appreciate some help on that topic.
I'm seeing some strange behaviour with the login window on devices in one Jamf environment but not in another. All machines have the CIS L1 baseline and some additional lockdown restrictions on them. They should be asking for the username and password at the login window on startup and after a logout. This works fine for devices in one environment but in the other I get the user account(s) listed on startup and only the password is required. It works as expected if you log out though. I wondered if it was something relating to FileVault but, again, the configs between both Jamf environments should be the same. The only difference I can see is that one Mac is Intel (T2) and the other is M1. Here are some examples of what happens on the Mac that isn't working as expected:- Startup: After logout: Some of the settings applied:
I found another excellent script from Karthikeyan Marappan on his GitHub site for setting or clearing the recovery lock on a system. I took his script and put a nice GUI frontend on it. I believe this only works on Apple Silicon Macs at this time. Initial Welcome screen Succesfull clear message Successful set message No Device found JAMF Script parameters to pass GitHub Repo: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/RecoveryLock
As someone who’s been part of the Apple admin community for a few years now, I’ve had the privilege of helping out the amazing team with MacAD.UK, both as an attendee and behind the scenes. In my day-to-day role as a Technical Lead for Workplace Solutions, I spend my time working with all aspects of our business with everything Apple and development, collaborating with fellow admins, sharing knowledge and supporting customers adopt Apple technology whenever I can. MacAD.UK is a community-driven, session-led Apple-focused conference, has been a staple in Brighton for eight years. Bringing together world-class speakers, leading exhibitors, and top technical professionals from around the globe. Whether you're an experienced admin or just starting your journey, MacAD.UK is where the community comes together to learn, collaborate, and push the boundaries of what’s possible. Why Attend MacAD.UK? First and foremost, the ducks! (Ok, maybe not the ducks. More on
I'm rolling out a 10.9 lab, and my workflow works fine.My machines deploy and configure as expected.Bind to AD works great.The AD bind has "force local home directory" and "Use UNC path..." enabled.I can log in with LDAP/AD users, and profiles/policies work fine.The users get a local home forced. They DON'T show up in the local user list or via a command like: "dscl . list /Users UniqueID"These sorts of users used to automatically show up in 10.7.Since this is my first wide installation of 10.9, I'm not sure where to look to diagnose - any help?
We are a school where every student has an ipad. we use apple classroom to control the use of ipads during lessons. however, it is enough for the student to disable bluetooth to no longer be viewable in apple classroom.Is it possible that on jamf there is no possibility to insert in the profile the possibility to always leave the bluetooth active? the lack of this feature is very limiting. is it expected in the next updates? I saw from the forum that it has been talked about since 2016
Hi All, I have configured the Gateway access followed by the linkhttps://learn.jamf.com/en-US/bundle/jamf-connect-documentation-current/page/Creating_a_Quick_Connect_Gateway.html Connection was established between Linux and Radar portal but when I try to access Subnets through ZTNA it is not accessible. I have configured the Access policy with direct IP and subnets as well but no luck. I'm able to access Direct IP address application but subnets hosted apps are not accessible, please let us know if anyone come across this issue. Thanks
Does the return to service app actually reinstall ipad os? The documentation uses words like "wipe" but isn't definitely clear on if the OS on a ipad is erased and installed clean.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!