Get Support
Recently active
Welcome to Self Service+ 1.0.0! Self Service+ is Jamf’s new end user portal that helps organizations develop an autonomous and security-aware workforce. With Self Service+, employees are empowered to request, download, and update apps for their Macs, view the security of their endpoints, manage all notifications in one place, and learn how their data is handled with respect to privacy, all in one central, intuitive portal. Downloading Self Service+ is available on Jamf Account. Thank you.
Has anyone found a way to do IKEv2 VPN on built in Mac without using User-Level configuration profiles? Unfortunately, it is too crazy to unenroll all of our user computers and reenroll them to get mdm-enabled users, so I was wondering if anyone has found a work around for it?I tried Cisco IPSec built-in, but I can't seem to get it to reach our remote server. If I do the IKEv2 manually, it works perfectly.
Hi All. Our security team wants to implement a "Catch All"-Conditional Access Rule which requires a known device. Jamf Connect does not send this Device ID to Entra when syncing passwords. For Entra this request would've been sent from an unknown device. See screenshot: No Device ID. :( There seems to be a workaround here: https://learn.jamf.com/en-US/bundle/jamf-connect-documentation-current/page/Jamf_Connect_and_Microsoft_Conditional_Access.html But I'm curious, isn't there any other way to allow Jamf Connect to use the Device ID? I mean it's on the computer, isn't it?
Hello everyone,Recently we set up a solution that deploys certificates (ADCS Connector) that automatically connects the device to a specific Wi-Fi, without the need to enter a username and password.It works great. But now we have encountered a problem, if someone chooses to forget the network for some reason, it is not possible to reconnect. The connection is not automatically re-established, if you choose to connect to the SSID in question, you are asked to enter a username and password.Does anyone know what to do, if there is a simple or good solution to the problem?
Hello all,We are deploying out Microsoft Defender for Endpoint. Everything is going well except for setting up Device Control.I have everything configured using the custom schema at mdatp-xplat/schema.json at master · microsoft/mdatp-xplat (github.com) , which is linked from Microsoft's documentation. I have played around with trying to get JSON into the line for device control and had no luck.ProfileManifestsMirror/com.microsoft.wdav.json at main · Jamf-Custom-Profile-Schemas/ProfileManifestsMirror (github.com) I have tried to use the custom schema from the Profile Manifests Mirror above and none of the settings deployed at all.I also tried iMazing Profile Editor, with both signed and unsigned, and had the same issue as the Profile Manifests Mirror (which isn't surprising since they are linked I believe).Has anyone had any luck with developing and formatting the JSON string to use in Microsoft's schema to enable device control?Thanks!
How are you all auto-populating the user, location, department, etc. fields for your systems in Jamf?
Hello, We frequently encounter situations where Zoom updates in the background, but users don’t restart the application to apply the updates. I know Zoom updates automatically in the background, but how can I force a restart or ensure that the update is fully applied without needing the user to manually restart it? Is there a way to automate this process or ensure the app relaunches after an update? What steps should I be taking to address this? Best Regard, Jojes
Hi Nation, I am facing a weird issue. I just added the policy in Jamf to remove two dock items(mail and Safari). I tried with multiple triggers but it seems when a new user is trying to logged in via prestage enrollment, it is not working. I have Jamf Setup Manager installed, tried to use that with a custom event trigger for the policy. The policy runs, user logs in, dock reloads but still the items are there. This is the log screenshot: Point to be noted, when I am running the policy from self service, it's working fine. Any idea what I am doing wrong or how to fix that? Any suggestion is much appreciated. Thanks
I want to delete any computer (or device) from Jamf if they have not checked in for over 365 days. 'Action/Delete Computers' seems like it will do this job. Is there a way I could automate this process? It's not a huge amount of work to keep going back to this report and hitting 'delete computers' but I like to save time wherever I can :-)
I would like to stop spotlight from indexing certain locations across all my Macs. I need it to stop indexing the mounted network shares. Is there a way to do that? I could not find a setting regarding that in Jamf Pro.
Would there be any issues with using the same ABM account to manage volume purchasing across multiple Jamf Pro servers/instances? Any particular reason you would want to avoid doing this? I tried searching for similar questions here and information in the docs, but didn't find anything relevant. Thank you.https://docs.jamf.com/10.26.0/jamf-pro/administrator-guide/Integrating_with_Volume_Purchasing.html
Hi,Does JAMF Pro support importing users from Apple Business Manager?If not, then how would shared iPads be supported? ThanksSteven
Hi folks Has someone found a solution to disable the auto update check function in deepl.app?I tried already with preference domain: com.linguee.DeepLCopyTranslator <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>autoUpdateEnabled</key> <false/> </dict> </plist> and searched also for some other plists but had no luck to disable this function. The problem is all releases which are published to the user via app directly do not correspond with the main releases which are published directly from the developer.And our user without admin rights cant update it.Privilege Access via jamf connect is not an option for this :) I cant use also Installomator for it, because the URL is the one for the main releases. THank you in advance J
Effectively managing devices is essential for IT administrators in today's rapidly changing digital environments. While tools like Jamf offer powerful capabilities for managing Apple devices, a truly optimized IT strategy involves more than just top-down policy creation. Incorporating user feedback loops into your Jamf-managed environment can transform device management from a purely administrative task into a dynamic, user-centric process. By conducting surveys, analyzing self-service usage metrics, and adjusting policies based on user behavior, IT teams can ensure their strategies align with the needs of employees or students. This approach enhances device utilization and promotes greater satisfaction and productivity. Why User Feedback Matters in Device Management Device management policies often stem from IT goals such as ensuring security, minimizing downtime, and maintaining compliance. However, the end users—employees, educators, or students—interact with t
I'm checking if there is some configuration profile that can help to automatically add the username (generally the email or upn) during the sign-in process when you start your computer and Jamf Connect.
We have disabled the camera app in our system due to abuse from users with patients/HIPPA.Our users still need to be able to scan QR codes for various surveys etc.I can easily put a 3rd party app on the devices however they all look suspicious or have adsHas anyone had any luck with being able to keep users from taking photos with the camera app while still using the QR scanner?
My end user noticed the option to type part of a URL or term doesn't function after I configured Chrome as she requested. Either I'm enforcing something that disables it or I have to enable a key, but can't find what it's called in the Enterprise documentation. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>AutofillAddressEnabled</key> <false/> <key>AutofillCreditCardEnabled</key> <false/> <key>BrowserAddPersonEnabled</key> <false/> <key>BrowserSignin</key> <integer>0</integer> <key>DefaultBrowserSettingEnabled</key> <true/> <key>DefaultSearchProviderEnabled</key> <false/> <key>DefaultSearchProviderName</key> <string>Google Search</string> <key>DefaultSearchPr
Hi Team, Want to Know is Any Way around the Change the Preferred Language on the Macbook with the Help of jamf. i want to change the Preferred Language from English to English U.S.
I'm trying to restrict access to the UIE page "/enroll" to an EntraID Group. From what I'm reading and have been told this is not possible. Has anyone else encountered this issue, and if so how did you resolve? Turning off UIE isn't an option as we still wish to use Pre-Stage
I keep seeing the error message: "The Jamf Pro built-in certificate authority will expire soon." However, the certificate has already been renewed and doesn’t expire until 2034.When I check the Built-in Certificate Authority section, I see a list of certificates that are due to expire this week, but I’m not sure what they relate to. This system was originally set up by someone else, and I can’t figure out why the error is still appearing even after renewal.Any ideas on how to fix this? and TIA
I am looking to change all of my users System preferences --> General --> set 'Show scroll bars' to 'Always'. I didnt see it in "managed Preferences" so I am wondering how to set this in jamf for my users.
Hi I have been having a slight issue with the management accounts, when i have a management account in user initiated and an account in prestage, the device using the prestage end up being unmanaged, if i only use the one in the prestage enrollment it works fine but then the user initiated dosnt have one is it best now to solely use the one i the user initiated thanks
Hello, I am extremely new to Jamf and barely know how to use the console but was given the task to automate some things. I watched this really cool video: https://www.jamf.com/resources/videos/github-as-the-source-of-truth-for-configuration-in-jamf-pro/ where this dude Hiroshi walks through how to use Github Actions to automate the create/update of scripts in Jamf Pro. I read this blog at https://blog.pirox.dev/2021/03/19/231112 and he actually does a really good job at explaining everything and everything works. However, this doesn't seem very scalable at all because the main deploy.sh file is hard coded and it seems like he is just creating/updating one single script. Has anyone used this similar approach to scaled hundreds of scripts? Just wondering how everyone else is leveraging Github Actions or some sort of automation tool and updating/creating/deleting jamf scripts without hard coding things. I sort of have an idea where this could work if yo
Hello, I am new to JAMF Pro. We set up a test iPad and they seem to be unable to move the apps around on their homescreen as they please. User is also reporting that they can't join their home network. Any idea what could be causing this? Thanks in advance. Thomas
We have been working with Jamf Pro / Jamf Connect for a while now. Jamf Connect is set up with our Azure instance and works perfectly well. Now we also have a separate Google Workspace and we are trying to configure Jamf Connect for it. I have downloaded the latest version of Jamf Connect which i'm pushing to the devices which will need to log in with their google credentials. However, upon installing Jamf Connect and restarting the device, the apple logo appears and the loading bar gets stuck mid way. After some time, the logo and bar dissapear and I can see the mouse, however the rest of the screen is black. When I click on the keyboard I can hear sounds. Anyone else encountered this issue and managed to solve it? Or maybe someone can assist me with what I can troubleshoot? The Jamf Connect Package is being deployed via Jamf Pro policies. Mac OS versions tested on Sonoma and Ventura (both same result)
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!