Get Support
Recently active
Hey everyone,I’ve set up Jamf Connect with Google IdP following the documentation and tested it; everything seems to run fine. However, I've run into issues during PreStage Enrollment deployment in Jamf Pro. I can’t seem to launch Jamf Connect properly for local account creation to show the Google login screen. Right after the Setup Assistant, it only shows a black login screen with empty fields for user and password. According to troubleshooting, it might be due to the permissions in the package, but since I’m using the official Jamf Connect 2.42.0 package and distributing it through Cloud Distribution Point (Jamf Cloud), I don’t think there should be an issue.Has anyone had a similar experience and found a solution? Here is my configuration excluding secrets: <key>AllowNetworkSelection</key> <true/> <key>CreateJamfConnectPassword</key> <true/> <key>CreateNewUserHide</key> <true/> <key>DenyLocal</key&g
Hi all,Having an issue with Filevault and our local admins getting secure token access. So I have a config profile set to enforce Filevault enablement. The user logs in, they enable filevault, all good to go. Problem is that the local admin we create does not have a secure token in this instance, and it's necessary the local admin has one.What I could do is login with the local admin first, enable filevault, but then I'd have to give the user local admin creds to login to the device prior to JamfConnect screen. That is undesirable.How can I ensure the local admin gets a secure token without actually logging in as the local admin? I know that the sysadminctl command can do it, but that would require someone with a secure token to authorize it (that's not feasible for obvious reasons).
Testing BeyondTrust deployment on Mac OS Sequoia. I also tested this on Sonoma, and ran into the same problem. I'm using the install script from BeyondTrust, and their recommended PPPC Configuration Profile. The installer appears to run successfully, but I am getting a pop-up asking for permission to copy the .app file to the Applications folder. Is there a change I can make or a security setting I can adjust to allow this app to copy to the applications folder without the user needing to click allow?
I'm surly missing something simple. I am trying to update the Adobe CC and Adobe Acrobat (with CC) packages in JAMF. They keep failing with the response being to contact the vendor, and the install log is saying there was an error with executing the packages scripts. Downloading the downloader for a managed package from the Adobe Admin CenterDoing all the random steps to download the package with the adobe package downloader app that comes in the .dmgUploading the install.pgk to JAMF (JAMF auto zips the file when uploading)Putting the install.pkg.zip in a policyTrigger the policy and fails every time.If I run the package locally on the device it works like a charm. Before I break down and put the installer pkg in a pkg and run it with a script, does anyone have any idea what I missed?
Any one notice if you install Self Service+, it re-triggers enrollment complete / first time login policies?
We are pushing a configuration profile to users. So far 1800 machines have completed but there are 450 that still show pending. In this list there are some machines that show pending but when I go to management history for a few of the pending machines it shows that the configuration profile completed but it does not show up in completed. Is there a way to fix this so that we can have a more accurate reading on machines that are actually pending/completed.
Hi, I have been asked to disable the telemetry on Rancher Desktop for deployment in our fleet, and was hoping someone might have done this, or had some insight as to what would be the right way to do it. you can pull the settings and i can see the flag i need to change, but my json skills are not my strongpoint... I know this needs to be changed to False "telemetry": { "enabled": true } https://docs.rancherdesktop.io/references/rdctl-command-reference/#rdctl-or-rdctl-help Any suggestions would be welcome
I've spent some time researching where these options are actually stored, and found them in all locked away in /private/var/root/Library/Preferences/com.apple.CoreBrightness.plist This file is editable by all users, as it simply stores the current display tone and brightness settings. The only trick is, this file is only read at startup, so editing it does require a restart afterwards. For our computers labs and classrooms, we simply run this script at every login. That does mean, however, that if someone changes the display settings, it takes two restarts to get them to go back to our desired default settings (if someone can figure out what service or process to restart to force the preferences to update, that would be great, but for now, this solution is working for us). Update: I have discovered that in order for this to work, you also need to have opened and closed System Settings. I will be working on finding a way around that. For the time being, we
I am using the Make Me an Admin : https://github.com/jamf/MakeMeAnAdmin I'm having 3 questions/concerns:• It is not reliably creating a log?• Is there a way to get the log to me or at least a notification that the policy was run?• Is there a way to block them from creating additional admin accounts while they are an admin? Thanks!
IBM normalized their installation namespaces on Mac/Windows, and changed where they store the license server settings inside a file called "/Applications/IBM SPSS Statistics/Resources/Activation/commutelicense.ini". I wrote a script to update this - its similar to the spssprod.inf file. On launch however I get this popup: Clicking "apply existing license" goes right into the app and checks out a license. The warning doesn't come back. I found that some setting (where I'm not sure) is stored in a file called "com.ibm.spss.plist" in the user profile preferences folder. I can't of course just copy this over to an existing profile because it has many hard coded paths to my user profile inside it. Anyone else run into this issue? I'll likely bounce the issue off IBM support, but I thought I'd ask here as well.
Has any one had the issue where Jamf Compliance editor is not creating the PDF in the Project folder? Not sure if there is something I'm doing wrong, but after taking my course, I was creating a plan for my current organization. After creating the CIS LVL 1 benchmark, the PDF is missing within the build folder. Not sure if there is a way to get that report as it would be pretty useful. Thanks for any insight.
Hello everyone! Something strange happened about 32 hours ago - a main instance has disappeared from my Jamf account. I can't log in to <myinstance>.jamfcloud.com Does anyone of you had such case? It's really frustrating, because it stops all the work in our company - we can't do onboarding (Enrollments), help employees to solve their Jamf-related problems and so on... Jamf support replied about 13 hours ago. I have immediately answered their questions and since then, there is a silence from Jamf people's side. Is there any way to see, if this instance was deleted by someone, or not?
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server: Security Issues Jamf provides the CVE-ID for security issues with high or critical severity when possible. [PI126232] Updated a third-party library to resolve a known vulnerability. (CVE-2025-24970) Jamf Pro Server [PI125880] Jamf Pro users who migrated from an on-premise environment to a Jamf Standard Cloud-hosted or Premium Cloud-hosted environment using a custom URL and port 8443 will no longer experience authentication errors while using SSO through Jamf Account. [PI126314] Jamf Pro successfully populates data in the mdm_client database table, resolving an issue that prevented computers from receiving user-level commands and configuration profiles. [PI133965] Jamf Pro users in on-premise environments will no longer see reminders to enable single sign-on (SSO) through Jamf Account, which is only available in cloud-hosted environments. Jamf Pro System Req
Hi all,Im looking for a simple and easy buy user friendly way to restart a mac .. I know there is many options out there .. script .. jamf policy , DEP Notify . .. but have always had feedback from business saying that there are not very user friendly. I have been tasked to see if i can find a friendly way to restart with less user interaction or at least a deferral ..Any idea is much welcomed..rk
I have a number systems where the Jamf Policy with user interaction messages are configured but only 1 of the systems with the policy assigned is not receiving the message. Has anyone seen this before? I have confirmed the policy is applied to the target Mac.
We set up policy using the user interaction tool allowing the user to defer the policy. Is there a way we can brand the notification with our icon? Is it possible to include weblinks in the notification as well? I poked around Jamf and Jamf Nation and wasn't able to figure this out. Thanks,
I am trying to create a policy that applies software updates for end users. I want a message to be displayed to users only if a reboot is going to be required. I assume this would be done in the user interaction field, under the "Restart Message" field. The issue that I am confronted with is that I want the rest of the policy to be silent, the user does not need to know the task is running, or that software updates are being applied.Is it possible to simply leave the Start and Complete message fields blank, so no message is displayed? Or will this cause an empty dialog box to be displayed?
Hi team,Can we use the below setting to perform Force update of patches after 15 days? Basically if the users don’t install the patches from self service, we don’t, Jamf to perform force update.
Is there a UI fix for Jamf Pro coming up? When my multiple tabs all get timed out and I log back into Jamf Pro all my tabs revert to the main dashboard. This is highly annoying, some I can click the the back button to get to the previous page, but this doesn't always work. Is anyone else having issues with this?
Hello,we like to configure Goodnotes for students without the AI-features. We also activated the auto-back-up-reminder and pre-configured a webdav-url.Can anyone help me with deactivating the AI-features? What do we need to add to make the AI-features configurable?This is our working Code:<plist><dict><key>LicenseKey</key><string>LICENSE CODE</string><key>GoodnotesVersion</key><integer>6</integer><key>ConfigurableFeatures</key><dict><key>ReminderToEnableAutoBackup</key><true/><key>WebDAVHostURL</key><string>WEBDAV DOMAIN</string></dict></dict> </plist>
@AJPinto also know as Anthony James Pinto, is Jamf Nation’s number one community contributor. With some all-star stats like providing 289 accepted solutions, 2,607 posts and 1,145 kudos, it's likely that you’ve seen his name splashed around the community. Jamf Nation, the world’s largest Apple Admins community, relies on the smarts and dedication of members to help advance and maintain this space as a valuable asset of learning and connection. People like Anthony make communities like Jamf Nation function in their highest level. Let's take a peak inside Anthony’s brain and learn more about the man behind the avatar, shall we? Tell us about yourself, Anthony I am from LA and have lived all over the US. I settled down in central Alabama for reasons beyond me, met my wife and just sorta stayed here. My wonder lust never went away, and I love to travel and experience new places and new things. My preferred travel locations are places far a
Hello, here is the scenario: We are pushing out a new version of a in-house app soon but we want to make sure that the end users don't use the old version of that app once the new version is deployed. This is more of a failsafe as the app should auto update for everyone but in the event it doesn't update for someone, we could block the user from opening that specific old version of the app. My plan was to restrict the app in a config profile then scope it to a smart group of users who have the old version. When the app updates to the new version, they would be removed from that smart group and would be able to use the app. My problem is the smart group criteria, it doesn't seem to work. The results always show 0 devices. It should show around 200 devices. This is what I'm trying: I even tried changing the "App Name" to "App Identifier" but I get the same results. Let me know what I could be doing wrong or if there is a better solution for this scenario. It's possible my plan here
Hello Guys, We are using Jamf Pro as an on prem. Tomcat ssl certificate's expires very soon.I did renew the ssl new certificate than restart tomcat service. But users were not able to connect to self service. Actually I deploy the new certificate to clients via config. profile. I can see the current new Certificate in the keychain. For testing, test device was connected to self service when I set the new certificate to always trust.
I've just added a new app to my Apple School Manager and have assigned 200 licenses. When I push this app out to an iPad it gets stuck on Waiting for Licenses despite there being more than enough available. Checking the status of the app says "Waiting for the volume purchasing licenses to be assigned. Install the app again." Doing this just results in it staying on Waiting for licenses again. This is the result of quereying the status of the app: Apple School Manager has assigned the license but still Jamf doesn't complete the install. Any ideas how I fix this? [edit] I've just tried pushing a different app to this particular iPad and have the same issue. The iPad is online and checked in with Jamf and working for everything else. Just can't push apps to it.
Hey all, I've been stuck on this for quite a few weeks. Our JSS servers were moved from one location to another. Since then we've had to redo numerous things. The last being TomCat. The boxes used to be behind a load balancer, now they are not. Anytime we navigate to our jss site, it says it is not secure over https and another issue is any policies with packages trying to push, fail due to it not being secure and not being able to make the connection. If I go into TomCat and "Change the SSL certificate used for HTTPS" -> Next -> I've tried "Generate a certificate from the JSS's built-in CA. Restarted the box. No different " Same steps as above, only this time, "Upload an existing SSL Certificate" -> our network guy pulled the cert we use for other servers. Anytime I try to upload, the second part where it asks for the password, it does not go through. This password works on everything else. Tried redownloading it from the s
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!