Get Support
Recently active
At the moment it seems that JAMF is unable to turn off private wifi addresses via configuration policy even though they have an option for "Disable MAC Address Randomization (macOS 15 or later)". After testing with JAMF and confirming this function does not work in setting this to OFF (there currently are no granular settings in the MDM framework for this), they recommended I raise a developer case with Apple for this. Shouldn't JAMF be doing this to allow this functionality in their MDM instead of us as a user?? Our vendor is incredibly upset and recommending we drop JAMF as a product due to their response on this.
Lots of posts about return to service, but nothing I have found about the Wi-Fi profile used in the Prestage Enrolment.As this profile cannot have anything except the Wi-FI payload (why??) There’s a workaround for Enterprise networks which have such things as a certificate payload.The workaround is to add the certificates to the profile after you have added the profile to the Prestage Enrolment. But when you go to save the modified profile, you are given a choice between sending to all devices or only devices without the profile.Well none of the devices have the profile yet, and if it’s a clone of your normal enterprise Wi-Fi profile, what will happen if you go ahead? Will you end up with two profiles with the same Wi-FI payload? I am reluctant to go ahead as changing WI-Fi profiles midstream is fraught...
I'm setting up automation for a COW of iPads. These are (mostly) DEP enrolled devices. I'm using cfgutil to restore/pair/prepare and then the last step is to load a configuration profile that is used to add the devices to a smart group based on what they're going to be used for. It all works fairly well, but i always get the error: "cfgutil: error: User interaction on the device is required to install this profile.(Domain: ConfigurationUtilityKit.error Code: 625)" the profile even gets installed if I load it before prepare, but i always get the error. Is there something i could do to remove the need for user interaction?
Apple releases security updates to macOS Tahoe, Sequoia, and Sonoma The release build for each system is:• macOS Sonoma 14.8.9 (23J631)• macOS Sequoia 15.7.9 (24G830)• macOS Tahoe 26.6.1 (25G76)Link Here
I've worked in IT for over 20 years, and I've seen plenty of changes. But AI is the biggest shift I've faced yet. Like any new technology, it brings real benefits and real challenges. That's especially true in training. Most of the students I work with are already using AI, and the rest plan to start soon. It's making them faster and more efficient. But it's also introducing a new risk, the quality of the answers their AI tools hand back. This is where I think Jamf has gotten something right. Their own AI Assistant, built into Jamf Pro, takes a different approach than the general AI tools my students reach for. AI Assistant can read, analyse, explain, and surface information from your Jamf environment. But it can't modify configurations, push policies, enrol devices, or take any action that changes your fleet's state. It's built to help you understand, not to act on your behalf. What makes it useful is where its answers come from. When you ask it a question, it pulls from two places b
In JAMF Protect i have devices incorrectly showing as failing compliance on Bluetooth Sharing Disabled. I have a Configuration Profile created using JAMF Compliance Editor for this and shows on the devices as being disabled and controlled by a configuration profile yet JAMF Protect still reports the devices as failed complianceIs there a detection method i am missing that JAMF Protect is using ?I have also tried setting up a Blueprint for this also and JAMF Protect still shows the device as not compliant
Hello everyone, IDK if anyone is using the great add on to Macs, but if you are can you help me get 4 Tiles to work? Tile #1 - Submit a Service Desk Ticket - the link is mailto:#servicedesk@mycompany.com. Nothing happens. Tile #2 - Battery - can't get it to display the battery level. Tile #3 - Storage - can't get the amount of storage to display. Tile #4 - Privacy and Security - can't figure put how to open this one. We want end users to be able to open Privacy & Security directly without going through SystemSettings>Privacy and Security. Other than that, it is a great addition to our JAMF program. If you haven't tried it - check it out. https://github.com/root3nl/SupportApp JNUC 2021 release with training: https://www.youtube.com/watch?v=LijCmR6gQAM
Hi there - I’m new here so if I’m somehow off-target with this post, please let me know! I looked around for a Welcome message with guidelines, but had no luck. Sorry if I misunderstand anything. Here is what I’ve come to ask:What is the simplest effective way to properly secure 1-3 Macbooks? The scale is small but security requirements happen to be high (imagine a law firm, for example). I need both a professional configuration, which I’ll tweak for our purposes, and a deployment tool, but an entire MDM solution is way too much. Some background: I’m an experienced admin on other platforms, I’ve lightly used and helped out people with Macs for a long time but I’m new to actual, professional Mac adminsitration. Now I have just a few Macbooks, one to start. To narrow scope, I’m not worried about configuring or locking down user behavior, productivty, or updates and management (for this purpose). I need to lock down system and network behavior, including protecting identity (so no iCloud,
Where I work two different teams manage the MacOS and iOS devices. It would be nice to limit the iOS team to only devices and MacOS team to only computers. I know you can do this by creating a site but it seems like a lot of work to move all our iOS stuff to a new site.
What’s the best way to add an app to Restricted Software that has a number (e.g. App Name 3.app, App Name 4.app, etc) Activity monitor shows the process name with the number as well? Do I just need to create a separate entry for each version?
Hi all,I'm running 2 macOS VMs on a bare-metal Mac (host is also macOS). I'm seeing inconsistent iMessage sign-in behavior depending on the Apple ID type and whether it's bare metal or virtualized:Managed Apple ID (ABM-issued): signs into iMessage fine on the bare-metal host.Same Managed Apple ID: fails to sign into iMessage inside the VM on the same physical machine.Personal/basic Apple ID: signs in fine in the VM without issue.Has anyone run into this specific combination — MAID working on bare metal but not inside a VM, while a personal ID works fine in both?
I’m using a Jamf Pro Policy to remove dock items from student laptops. Process works slick, except for the Apple TV app, which stubbornly hangs in there, in spite of my efforts. Anyone else experience this problem, and perhaps found a solution? I’ve read about the dockutil, and will probably fool around with it when I have time, but the JAMF GUI would be my preferred solution, if it would work. Please share ideas. Thanks
Hi,so I just noticed that the configuration profile payload that defers macOS Updates up to 90 days is deprecated. So I was wondering how you are supposed stop your users from updating to the next macOS Version, once this is removed. Does anyone know? Kind regards
Hi All, Does anyone has a method after User has action SSO on the system that Jamf Pro will extract all there details from Entra ID included there department to the User and Location information for there system in Jamf ProThanks in Advance
Hi, anyone know how I can suppress this notification, what should one configure in the configuration profile? I think it might have something to do with the management action app, based on the icon. I’ve configured a Management Action profile with a notifications payload a coupla months back but looks like it don’t work. I’m concerned users are going to start logging tickets for this
Trying to offboard a business org user who is keeping their laptop but it has to be wiped. However it is not accepting the activation unlock code.Steps taken: 1 - device was locked from jamf now2 - device was erased by sending “Erase device” command from jamf now.3 - Unlock code was provided to user to unlock. It failed. 4 - Tried to use activation unlock from Apple Business Manager. ABM now says the activation lock disabled, but device still shows activation lock screen. What else can I try as the MDM admin/ABM contact?
Hi team,We are looking to strengthen our change management and security controls within Jamf Pro. Specifically, we're exploring ways to implement a peer review workflow for high-risk payloads like Config profiles, policies and scripts.Currently, any admin with edit permissions can save and deploy those changes immediately. For us, having a single admin able to make immediate, wide-reaching changes introduces significant risk—whether from accidental misconfiguration or compromised admin credentials.We’ve considered reducing the permission scope of admins and granting limited time admin elevations, but we’re mostly interested in payload-level security here which we think is best to solve the problem.Curious to hear if you’ve thought of this, or if there’s any non-native way to solve it.I tried searching through the this forum and the mac-admins slack but couldn’t find any previous discussions on it. Feel free to point me to one if it already exist.Thanks!
Hey So Im looking to turn the hadware history of inventory into an extension attriubute that udaptes when the OS changes. I mnot sure if this is the right way to go however I made a script that runs during invetnory check in however its only pulling in with the OS was downloaded to install. Any suggetions on how to get this set up so other techs can use the extension t oassist with troubleshooting?
Hi everyone,I've been working through a deployment of Platform SSO Simplified Setup on macOS 26 using Microsoft Company Portal 5.2604.1 (5.2604.0 or newer is required per documentation), and I've hit a wall with username/account name mapping that I wanted to share in case others are running into the same thing and could potentially provide some alternative options.---Our Setup- Jamf Pro 11.28.1- macOS 26- Microsoft Company Portal 5.2604.1 (deployed as a PreStage package)- Microsoft Entra ID- PSSO profile with Simplified Setup enabled (EnableCreateFirstUserDuringSetup + EnableCreateNewUserAtLogin both true)- Authentication method: Password- Associated Domains payload included in the same profile---The ProblemEverything works end-to-end — Simplified Setup fires during the Setup Assistant, the user signs in with their Entra credentials, and a local account gets created. However, the local account short name is being set to the full preferred_username value (e.g. John.Smith@company.com), w
Anyone having some users upgrade to macOS 26.6 and now after they login with username password they are then greeted with a black screen. They can’t do anything else. We use Jamf Connect, users didn’t have any issues until they upgraded to macOS 26.6.
Anyone else having this issue?Jamf School’s app installers don’t seem to be installing apps onto my Macs properly. I have a list of apps in a device group that is sourced in the app installers - and upon a Mac joining said device group the apps stay stuck on “Installing” and they stay that way indefinitely. When I click on the stalled app to “Retry app stuck on installing” and refresh, the installation fails and I have to retry or it says “App installation timed out. Try again.”. This is really slowing down my zero-touch deployment process.
Is there an option like “Clear Activation Lock” for MacOS devices but for the API?There seems to be for Mobile Devices but I can’t find anything about doing this for MacOS. If there is not currently, do we know if this option will be available down the pipeline?
getting a few of these, has anyone figured a way to disable them completely?
Hi, in I recently discovered a bug in Jamf Pro that appeared just this week. After enrollment, profile/policy execution "stops" and is "waked up" by these commands: sudo jamf recon
My goal is to block FaceTime from opening, and removal from the dock would be a plus. I’ve looked at other threads on this same issue and consulted AI. I am doing what has been suggested but FaceTime still opens up and allows me to log in; user are not able to sign into their appleid’s. I am running version 11.30.1 of JAMF Pro. Does anyone have a current setup that is successfully blocking FaceTime. I’m just wondering what I am missing. Screen shots would be appreciated. Thanks.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!