Get Support
Recently active
Just noticed in Automated Device Enrollment that Asset Tag information loaded in the Placeholder is not showing up in the Device Inventory Details after enrollment. This has worked in the past but was wondering if anyone else has experienced this lately in Jamf School?
I am looking for a way to manage the settings to allow accessory (USB/Thunderbold). In the System Preferences are these settings available: Ask every time Ask for new accessories Automatically when unlocked Always But I didnt find any setting options in the following MDM command: https://support.apple.com/guide/deployment/manage-accessory-access-depf8a4cb051/1/web/1.0 Is there a different way to set this option to "Ask every time" ?
On March 20th, 2025, the NYC Jamf User Group (NYC JUG or “the JUG”) celebrated its 11th anniversary—a milestone that reflects the remarkable growth and resilience of the Apple Admin community. What began as a small gathering of 20 admins in Jamf’s old NYC office has flourished into a thriving network, now meeting at Apple’s 11 Penn Plaza location, with over 80 attendees regularly.A Look Back: From Humble Beginnings to a Thriving CommunityFounded in 2014, the NYC JUG was created to bring Apple admins together to share real-world Jamf experiences outside of official events. With early encouragement from Jamf supporters, including Henry Patel and Jonah Klevesahl (now at Apple), the group held its first meeting on February 18, 2014, after a few weeks of promotion on Jamf Nation.What started with 20 admins quickly grew through word of mouth. By the third meeting, the group had outgrown Jamf’s office, prompting Apple to offer their 100 Fifth
Through necessity, a need arose to enable users to be able to install Tableau Desktop on their Macs via Self Service. But with the app not currently being available in the Jamf App Catalog, a scripted process was devised to enable the installation of Tableau Desktop on a Mac, whilst ensuring the correct variant for CPU architecture (i.e arm64 on Apple Silicon or x86_64 in Intel based Macs) was deployed. After putting time into curating the script, I felt it would be good to share this with the community for anyone else who may need to deploy this within their environment: #!/bin/bash cd "/Library/Application Support/JAMF/tmp" # Update variables. These shouldn't need to change for each update dmgname="TableauDesktop.dmg" pkgname="Tableau Desktop.pkg" apptoreplacerunningname="Tableau" # Determine CPU architecture for download arch=$(/usr/bin/arch) if [ "$arch" == "arm64" ]; then dmglink="https://www.tableau.com/downloads/desktop/mac-arm64" echo "Running process to download arm
Hello! Our school uses Jamf School. Now I got an advice from a student that the students have the opportunity to lock themselves in an app in the morning before our restrictions become active and thus make our restrictions on their iPad ineffective. That sounds very much like "single app mode" to me. A review of the activity protocol in Jamf School also revealed that an iPad rejected restrictive profiles because it was in "single-app mode," which was certainly not activated by the school admin (me). Questions: Is there a way to disable user-triggered single-app mode? Or, if this is already running on an iPad: Is there a way to end a student-activated single-app mode through Jamf Teacher or by the admin in Jamf School? I can't find anything about it at the moment. But that would really be an important function?
Hey everyone! Long time reader, first time poster. I am trying to configure a custom analytic in Jamf Protect, that will create an alert, similar to the default analytics, in the "Alert's" pane. This one is a little too robust, in terms of what its creating alerts on. Basically, we are trying to create an analytic that can be used to audit against installed .app software on endpoints, as a way to maintain and ensure compliance with the software allow list. The predicate doesn't need to do anything other than alert when an application is installed. We want it to ONLY alert on the primary .app, and not a bunch of child folders or .apps associated with it. Any ideas on the best way to modify that predicate? $event.type == 7 AND $event.isNewDirectory == 1 AND $event.path ENDSWITH[cd] ".app" AND NOT ($event.path CONTAINS ".Trash" OR $event.path BEGINSWITH "/Library/InstallerSandboxes/.PKInstallSandboxManager")
I am working on creating some installer packages to run on some Macs that are not yet enrolled in my Jamf Pro server. For reasons outside my control, we need to install several apps on these Macs using the processes that would have ran had they been enrolled in Jamf Pro. The installer packages deploy all the install components, then they use a post install script to finish the install process. The post install scripts feed in tokens and licensing information. I am using a valid Apple Developer ID installer certificate. If I launch any of these packages, I can see that the certificate is there. I can also open them in Suspicious Package. It shows that the certificate is there and trusted. When I launch these packages on a Mac that is not the one I used to create them, I see this error: "Apple could not verify “NameOfMyPackage.pkg” is free of malware that may harm your Mac or compromise your privacy." I can run "sudo xattr -r -d com.apple.quarantine" followed by the path to the package.
Would love to hear some success stories.
I'm trying to utilize a script that will upload a file as an attachment to a computer. I'm trying to figure out the minimum necessary permissions to accomplish this. I used an admin account and was able to upload fine, but when I try to use a lower-privileged account, I get an HTTP 502 response code from the CURL command. Some of the permissions I think might be related already are:- Allowed File Extensions (Read)- API Integrations (Read)- Computers (Read, Update)- File Attachments (Create, Read, Update, Delete) I can't find anything in the admin guide or on the API page
borrowed the script from @bwoods and put some nice Swift Dialog UI on it. Gives user notification of what is about to happen and notifications along the way. #!/bin/zsh ###################################################################################################### # # Gobal "Common" variables (do not change these!) # ###################################################################################################### export PATH=/usr/bin:/bin:/usr/sbin:/sbin LOGGED_IN_USER=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) USER_DIR=$( dscl . -read /Users/${LOGGED_IN_USER} NFSHomeDirectory | awk '{ print $2 }' ) OS_PLATFORM=$(/usr/bin/uname -p) [[ "$OS_PLATFORM" == 'i386' ]] && HWtype="SPHardwareDataType.0.cpu_type" || HWtype="SPHardwareDataType.0.chip_type" SYSTEM_PROFILER_BLOB=$( /usr/sbin/system_profiler -json 'SPHardwareDataType') MAC_SERIAL_NUMBER=$( echo $SYSTEM_PROFILER_BLOB
Hello All, We want to use superman to update our MacBook fleet but our higher ups want to make sure that this device is not malicious. Has anyone run into this before and point me to any confirmation that this software is not malicious. I know that many people use this to update MacBook fleet as Jamf built in software updates does not work on OS under 13 and asking users to update their devices never works.
Hi there A quick question, hopefully. We have a new config that has been pushed to some users to test new APs and a new SSID. A couple of them have not connected automatically to the new SSID, despite valid certs etc in the payload and having successfully appeared in the keychain. In the config, there is a "trusted certificate" area, under the Trust section in 802.1x settings So a couple of questions- Any idea why some users didn't connect automatically despite the profile being there, and some people connected just fine? Can someone please explain what the "trusted certificates" does? If the user tries to connect manually to the SSID, they choose the cert to connect with, and then they have the pop up from Apple to say to confirm trust etc. The certs in the wifi part of the network config are ticked, so I would have thought there would be nothing to do- but some users are still being requested for manual authentication / connection.
Hi! Is there any way to allow an app DLP to capture the screen on macos without user involvement or notification?
Hi,we recently acquired a Jamf Pro license and wanted to build a update ring for certain softwares.Since Cisco Anyconnect is not available in Patch Management i thought i'll make a feature request.
Hi there, I hope this message finds you well. I purchased a few apps from Apple School Manager earlier today. I can see the number of available apps was increased in manage licenses. I also received an email from the Apple Store that mentions Your recent VPP purchase is available. When I go back to mobile device apps on Jamf Pro, the number of apps in managed distribution did not increase. I checked, and no certificate was expired. Every certificate is still active. Please kindly advise on this case. Many Thanks, Jonathan
Hi , Im able to read members of a AD group with command dscl "/Active Directory/domainname/All Domains" -read /Groups/ADgroupName | grep -Eo 'CN=[^,]+' | sed 's/CN=//' | sort -V . How can I add a computer to same group ?
So I am trying to figure out if its possible to use the Jamf Splunk Add-On to see if our team can use it view logs for one of our policies, where certain groups can gain temp-admin priv.From reading the documentation, you can use Splunk to spew out data from an Advanced Computer Searches, which can't cover that need. Or doing a Custom API call referencing from Jamf's classic API documentationHowever, haven't been able to find something that will fit the request. Was wondering if anyone knows way to use Splunk to spew out a certain policy log.
Hi guys, We have quite a few users who seem to download applications and run them from their desktop, Spotify and Chrome being the biggest culprits. I'm looking for a way to remove the application from users desktop folders. We have a couple of users (read: myself and a few other IT people) that have these installed on their machines in their Applications folder, and we don't want to touch those. Our users have local homes on our iMacs, and we run an AD environment. What's the best/tidiest way that people have used to remove apps from multiple users desktop folders?
Hey Jamf Nation!Since we announced Self Service+ at JNUC 2024, it has continued to evolve with features focused on content discovery, branding, and usability. Today, we’re excited to introduce the next major milestone: identity management in Self Service+. We're moving Jamf Connect's desktop app capabilities into Self Service+, which brings key functionality: synchronizing macOS accounts with cloud-based credentials, and privilege elevation for just-in-time admin rights on Mac. Jamf Connect's login window plugin remains separate application and is not included in this preview of Self Service+, ensuring continuity for account provisioning and local multi-factor authentication.How to join the beta:Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum in your email, click "Join this group Hub" to gain access.Email beta@jamf.com with questions. The beta program is covered by the Jamf no
Hello all, I've had an issue since upgrading to Jamf Pro v10. On some client Macs, the Self Service app constantly crashes. In some cases it crashes as soon as it tries to launch. In other cases it crashes as soon as you click anywhere in the app window. In a few other cases, the app will be working fine, but as soon as you click on the 'History' or 'Updates' button at the top, the app crashes and continues to do so each time your open it. It has mostly happened on 10.11.6 clients, but we have one Mac running 10.12.6 that is now having the same issue. I had logged support call with Jamf about it. They said it was a bug with 10.0 and to update to 10.1. Did that, confirmed that the clients had the newest version of the app, but no change. Removing the frameworks from the client and re-enrolling it worked once on one client, but as soon as I clicked something in the app window, boom, crashed. Jamf did a remote session into my server, made sure everything look
Jamf Nation,We have big news for you today. I’m thrilled to share that we have announced our intent to join forces with Identity Automation, a company known for its innovative solutions, with capabilities that span identity lifecycle management, access management, and governance to help organizations secure their environments without hindering the user experience. This joining of forces is a natural fit, allowing us to enhance the way we support schools and other organizations that rely on desk-less workflows. We have a history of partnership with Identity Automation and RapidIdentity - sharing many customers who have benefitted from our shared technology and integrations. By further integrating Identity Automation’s technology with our own, we’ll be able to provide even more powerful solutions to help organizations enhance security, improve standard workflows and provide flexibility for shared devices. Our priority remains delivering the best possible experience for you, o
Content backfill required
Hi all,We are trying to determine if we can use Jamf to audit which users are actively using Apple Intelligence.Our hunch is that Apple doesn't log gen AI actions but I was wondering if anyone here might have some specific advice that could help.Thanks in advance!
Hi folks - working with a new jamf cloud and I've run into a problem trying to have a user follow the steps to make their device Entra compliant. When they log into the Company Portal app (after starting the registration from Self-Service) the login screen for Entra pops up, accepts their username and password, then goes to a blank window. We know authentication is happening because the MFA for the user kicks off but the login window is blank and does not show the numbers. Has anyone seen this before? I was able to do this on a different machine two days ago. The OS on this machine is 15.0
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server [PI126319] Jamf Pro now pushes a new single sign-on extension (SSOe) profile to devices that have been either re-enrolled without being marked as unmanaged in Jamf Pro or scoped for device compliance for shared devices and had the SSOe profile removed. [PI131971] Performance is improved in environments where a large number of computers belonging to a site update their inventory simultaneously. [PI134534] A 404 error no longer occurs when navigating between a smart group that is scoped to a blueprint and the blueprints interface. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, inc
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!