Get Support
Recently active
Configuring single sign-on through Jamf Account for administrator authentication to the Jamf platform now supports Microsoft's admin consent flow for Entra ID connections.From Organization > SSO > New Connection, choose Entra, then select "Use Microsoft's admin consent flow for multi tenant applications." Click Connect with Microsoft and approve the screen. If you're not the Entra Global Admin, copy the link and send it to them instead. Once they approve, Jamf configures the connection. Manual configuration is still available as an option.New Entra connections request GroupMember.Read.All and User.Read instead of Directory.Read.All. Existing connections on the old scope can switch to the new scope using the "Entra Scopes" selector, which preserves existing group mappings.If your organization's domain is already verified in Microsoft Entra ID, Jamf inherits that verification automatically. Domain verification in Jamf Account is skipped for that connection.Full setup steps: Setting
I’m not sure if anyone else was struggling with some of these apps as much as I was for the past few weeks but we’ve got quite a few that we use in our environment: Linear, Notion, Claude Desktop, Google Antigravity (just to name a few).If so, I was able to create a few configuration profiles that will stop them from auto updating and stop all those annoying prompts users keep getting.I’ll leave a comment with each config profile\policy and the setup and hopefully it’ll save someone out there some time and headaches.
Hey Everyone, I have been battling this issue for quite some time and have done rigorous testing but have sincerely hit a wall with this issue. My organization is prepping to remove Administrator access from all users on our macOS systems, this requires them all to be converted to a Standard user. (We have a "MakeMeAnAdmin" script in place in JSS we plan to utilize) MacOS: 14.3.1Jamf Connect: 2.32.0 We use Jamf Connect with Azure/EntraID so users can authenticate on login, we have the app roles setup for the app registration in Azure with two groups, MacUserAdmin-Entra & MacUserStandard-Entra with the correct roles tied to each (Administrator & Standard) The Problem:Whenever a user is moved into the group tied to the STANDARD role in Azure and attempts to login to Jamf Connect on one of our Macs they can enter the O365 email, PW, verify 2FA, but then hit a "Yellow Exclamation Point" box with simply an "Okay" button. Once you click "Okay" you are kicked back
With Apple recently expanding access to the ABM/ASM API, I set out to recreate the GSX experience. By leveraging Jamf’s new MCP feature, Claude Code, and MUT, I believe I’ve come very close. Additional details are outlined below.Please visit the following Github repo for the latest version of Warranty Wrangler: https://github.com/brndnwds6/Warranty-Wrangler/tree/main Warranty Wrangler — Setup & Usage GuideThis guide walks through everything needed to run warranty_wrangler.zsh, a script that pulls warranty and AppleCare+ coverage data from Apple Business Manager (ABM) or Apple School Manager (ASM) and produces CSV files ready for import into the Mass Update Tool (MUT).PrerequisitesA Mac running macOS Administrator access to Apple Business Manager or Apple School Manager jq installed — if you don't have it, install it with Homebrew: brew install jq openssl, curl, and xxd — all included with macOS by defaultStep 1 — Create a Working DirectoryCreate a dedicated folder to store the scr
Is anyone experiencing issue with the lock desktop wallpaper configuration with macbook neos in Tahoe 26? I can get the configuration profile to block the “change the wallpaper” section in System Settings; however, users can still download a picture and right click to “Set Desktop Picture.” I have a policy to downloads and sets the wallpaper, which works, but users can now download any image and set the wallpaper. I am uncertain if this is a OS bug with Tahoe
Hey Community,From now until Sep 26th, you’ll earn 20 BYTES in Jamf Nation Rewards just for subscribing to our Jamf Nation General Discussions!How? Easy:Head to the page linked above! Click the big blue Subscribe button. Stay in the loop on all things Jamf + Apple - and get rewarded for it!⭐️ BONUS TIME ⭐️For a limited time, get 50% off the bytes needed to redeem some of our newest swag. Imagine rocking that gear at JNUC!Not part of Jamf Nation Rewards yet? If you’re a Jamf customer, sign up through your Jamf Account (details here).Your swag is waiting…⏰Please note: You may not see your new points reflected in your Jamf Nation Rewards Account right away. We are currently in the process of reconnecting our updated Jamf Nation with Jamf Account. We appreciate your patience while we reconnect these programs.
Hi. Im working with the new platform API, but i cannot access the Integrations tab on our company Jamf Account, and every time need to ask my colleague. My colleague has exactly same permissions as meand yet he can access Integrations tabs just fine, creating and modifying integrations, while all am seeing is two errors:Has anyone had a similar problem and managed to resolve it? Our accounts are provisioned from Duo IdP
Hello, Looking for a way to configure the Global HTTP proxy via Jamf Pro for macOS. The "Global HTTP Proxy" payload is only available for 'Devices' in JamfPro. We previously pushed a proxy pac URL setting that restricts browsing if not signed in to VPN via a script from macmule that uses the networksetup command. We found that this method doesn't restrict Safari and only restricts Chrome. After a chat with Apple Support, it appears that we need to use the Global HTTP proxy method for it to apply to Safari. Has anyone deployed a "global HTTP proxy" configuration to macOS devices via Jamf Pro? Thank you! Thank you
Anyone able to update to Google Chrome to version 150+? I’m stuck at 149. It won’t flip for me. And I tried creating a new title too.
Has anyone else noticed that custom Self Service branding no longer applies to App Installer / Notification Center notifications?Environment:Jamf Pro (current version) Self Service 11.28.1 macOS Tahoe 26.5.1What I’m seeing:Self Service branding is configured correctly in Jamf Pro. The custom icon appears correctly in the Self Service UI and as the application icon. However, macOS Notification Center notifications (e.g. App Installer update notifications) show the generic Jamf icon instead of our branded icon.Some investigation:Notifications appear under Management Action in System Settings > Notifications. CFBundleIconFile for Self Service points to AppIcon. AppIcon.icns appears to contain the generic Jamf icon. Running selfservice branding brand --icon <path> changes the Dock/Finder icon but does not affect notification icons. The behavior appears to be specific to notifications delivered via Management Action, which is how they appear in System Settings > Notifications.I
Many organizations recommend or prescribe a specific web browser for their users. The user can change the setting in the user interface, even though it is not really obvious where to look. Many MacAdmins would like to pre-set this browser and the default during enrollment. However, there are several challenges associated with this in macOS. It would be really nice if Apple provided some means to manage this with a configuration profile. If you agree, please file feedback with your AppleSeed for IT account. While we wait for that, what can we do? Use the browsers Most third party browsers have a built-in command option to set themselves as the default browser. Most Chromium based browsers (Google Chrome, MS Edge, etc.) can be launched with the --make-default-browser option: open -a "Google Chrome" --new --args --make-default-browser open -a "Microsoft Edge" --new --args --make-default-browser For Firefox, the options are different: open -a "Firefox" --new --args -silent -nosplas
Hi, Has anyone been able to deploy Crowdstrike Falcon via jamf? We need to deploy this to 180+ machines and don't want to manually install every device.
Has anyone had luck getting Accessibility to "allow" or "let standard user approve"?Similar to the post here https://community.jamf.com/t5/jamf-pro/enabling-privacy-accessibility-setting-for-ms-teams/m-p/245576#M230198 we've used the PPPC Utility to "let standard users approve" Screen Recording but does not seem to work for accessibility. We have a handful of apps that needs Accessibility to "allow" or "let standard user approve" for non-admins but cannot get it to work. Apps like MS Teams, Logitech Logi Options will not work for the "Accessibility" section. I've attempted to use the PPPC utility and though the other options work it's "Accessibility" that will just not work.
Today we are releasing a maintenance version of Jamf Pro to address the following product issue:Jamf Pro Server[PI-1431] Fixed: Advanced searches and smart group calculations that include User Group or Mobile Device Group criteria may cause performance degradation. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud UpgradesNote: Jamf Pro 11.29.2 will not be mass deployed to Standard Cloud environments. To upgrade manually: Log in to Jamf Account, click View details on the Jamf Pro tile, and then click Upgrade on the appropriate instance. Note: This capability is not available for GovCloud environments and is disabled for all instances one day prior to when the scheduled standard upgrades begin.
We’re truly excited about MCP and can’t wait to explore its potential. The idea of using the MCP (Model Context Protocol) connected to Claude for managing enterprise devices through simple chats is incredibly appealing to us. If we were able to achieve similar functionality with JamfPro’s MCP, it would certainly be a fantastic solution.
I have a user that has a Jamf connect sign in pop-up window that does not allow them to type into the sign in window, nor close the pop-up. We use Google Workspace as our IdP, that is connected to our macbooks, allowing users to sign into their systems via Google SSO. This pop-up appeared for a few different users last week, however this one user is not able to close this window. For all other users that received this pop-up they also received a secondary ‘Jamf connects wants to use your confidential information’ Mac keychain window, where the user’s were able to add their Google Workspace passwords into the keychain pop-up, then choose ‘always allow’, however this one particular user did not receive this Mac keychain window, so she does not have an opportunity to allow for her to add her Google Workspace password to the Mac keychain. All she sees is a Jamf | CONNECT with her username grayed out, that she can not interact with, or close. How do I stop this window from continuing to
Hey all!Just wondering if anyone has had a similar issue where they've deployed CIS benchmarking specifically CIS lvl1 (passwordpolicy) in JAMF for devices on Tahoe, and when users are upgrade to Tahoe from Seqouia they are locked out and are unable to login? this was advised to be implemented by our sec team whilst also having jamf connectthey are jus locked out on the default mac log in screen, we have a work around of going into recovery and resetting password but do not get why they are locked out as if it was the policy i was advised it should ask the user to reset their password if does not align with the cis password policy
A Jamf ID gets you into your admin experience, support, and Jamf Account, and it also satisfies the platform authentication requirement for capabilities like blueprints, compliance benchmarks, and AI Governance. One passkey strengthens all of that at once, since Jamf Pro, Jamf Security Cloud, Jamf Protect, and Jamf Account all draw on the same credential.Authentication is moving past the password industry-wide. According to Okta's 2025 Secure Sign-in Trends Report, workforce MFA adoption is now at 70%, with phishing-resistant authenticator adoption up 63% in a single year, as organizations replace older sign-in methods rather than just add to them. That shift makes sense once you look at what a password actually is. It's the same value every time, regardless of who enters it or where, and that's what makes it risky. The moment it's exposed anywhere, in a breach at an unrelated service, that same value still works everywhere else it's been used. A passkey removes that risk entirely. Th
I am installing AdobeUninstaller and I am getting the following message because I have me Gatekeeper set to Allow apps downloaded from: "Mac App Store and Identified developers" How can I whitelist the AdobeUninstaller App? I have tryed to create a PPPC Payload but that is not working. "AdobeUninstaller" Not Opened Apple could not verify "AdobeUninstaller" is free of Malware that may harm your Mac or compromise your privacy.
We have the policies to install the following Office 2024 components in order during our prestage deployment:2024 Volume SerializerMicrosoft Excel 2024Microsoft PowerPoint 2024Microsoft Word 2024For the past couple of years, this has worked exactly as intended. The volume serializer is installed to activate the license, then the individual apps are installed one by one. After deployment these have also opened and been activated. However, over the last week or so, the activation is no longer applying. I’ve tried everything I can to try and deactivate the license/reactivate it from self service etc, but the only fix appears to be completely removing all office components, and reinstalling them - only then does the volume serializer work. I thought this might be as a result of the latest Office apps, so I reverted to using older versions of the pkg files but the problem remains. I even tried using the whole Office suite pkg but the same thing is happening. Anyone else seen this before?
We cannot update our ipad 8 from ios to ios 26.5.2 because there is not enough memory available. There are 11,31 GB free. Only around 1 GB is used by apps. Only a few kb of photos and music. The huge part is iPadOS (2,88 GB reserved for updates, 12,11 GB iPadOS) and System files (4,63 GB).We are using jamf Now.Settings - General - Software updates says: More memory needed. … minimum 13,35 GB needed…How can I trigger this update? Can jamfnow helpl to free system mememory (cache etc)?
Hi everyone,ContextI’ve encountered several machines where multiple Teams accounts (professional, personal, etc.) were registered, and removing them from the system proved to be quite difficult.I looked into various solutions, but many of the recommended methods didn’t work in my case. Every time I opened Microsoft Teams, the accounts would reappear.Here are some of the resources I consulted: https://support.microsoft.com/en-us/office/sign-out-or-remove-an-account-from-microsoft-teams-a6d76e69-e1dd-4bc4-8e5f-04ba48384487 https://learn.microsoft.com/en-us/answers/questions/2202933/how-do-i-delete-an-old-teams-account-on-mac etc. What actually worked for meI manually removed the following items from Keychain Access: OneAuthAccount login.windows.net authority_mapAnother effective solution was using a script that I adapted to fit my needs.Hopefully, this can help someone.#!/bin/zsh# Original by PAUL BOWDEN - Completely remove Microsoft Office# Change to remove credent
If you are an admin that has access to the Adobe Admin Console, you can control what services and apps are available to users via the Creative Cloud desktop app. The following Adobe support articles document what customization options are availablehttps://helpx.adobe.com/enterprise/using/customize-creative-cloud-app.html The settings are controlled on the end user machine by the ServiceConfig.xml file that is installed alongside the Adobe application withing the following location /Library/Application Support/Adobe/OOBE/Configs/Since the launch of App Installers in Jamf Pro 10.37, the ServiceConfig.xml that App Installers installed alongside any Adobe deployments had the following settings configured: Adobe Admin Console optionAdobe Admin Console valueServiceConfig.xml keyServiceConfig.xml valueEnable self-service installNoAppsPanelfalseAllow non-admins to update and install appsNoSelfServeInstallsfalseDisable auto-update for end-usersYesAppsAutoUpdatefalseEnable self-se
We are deploying beyond trust jump clients on all of our macs and following the instructions by setting up a configuration profile to enable all screen sharing, disk sharing other settings on the backend through jamf without users being notifiied however still some of the users are presented with this which is annoying for the user as well as IT team . what could have been missing in the configuration profile . any help would be greatly appreciated
Today we released Jamf Connect 3.11.0; highlights include: Changes and ImprovementsThe Jamf Connect login window now includes Simplified Chinese and Italian as supported languages. Resolved Issues[PI-1193] Fixed: The Jamf Connect login window presents the following error during authentication with Microsoft Entra ID when Use Passthrough Authentication (OIDCUsePassthroughAuth) is enabled: Password verification unsuccessful: invalid password. Contact your IT administrator. [PI-1239] Fixed: MacBook Neo computers fail to connect to Wi-Fi after a restart, preventing the Jamf Connect login window from connecting to the identity provider. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!