Get Support
Recently active
We have been working with Jamf Pro / Jamf Connect for a while now. Jamf Connect is set up with our Azure instance and works perfectly well. Now we also have a separate Google Workspace and we are trying to configure Jamf Connect for it. I have downloaded the latest version of Jamf Connect which i'm pushing to the devices which will need to log in with their google credentials. However, upon installing Jamf Connect and restarting the device, the apple logo appears and the loading bar gets stuck mid way. After some time, the logo and bar dissapear and I can see the mouse, however the rest of the screen is black. When I click on the keyboard I can hear sounds. Anyone else encountered this issue and managed to solve it? Or maybe someone can assist me with what I can troubleshoot? The Jamf Connect Package is being deployed via Jamf Pro policies. Mac OS versions tested on Sonoma and Ventura (both same result)
Hello everyone. We are using Jamf Pro and Safe Internet in an effort to block prohibited technologies from the state of Texas DIR website and I wanted to ask a couple of questions on how other organizations are handling this situation if applicable. Here is the link to DIR website for Texas: https://dir.texas.gov/information-security/covered-applications-and-prohibited-technologies The issue: 1. Several of our Mac computers do not meet the system requirement for Safe Internet to be able to block prohibited technologies (macOS 15). Are other organizations buying brand new Mac workstations to meet the system requirement if they can't be upgraded to prohibited technologies? 2. Our IT security team has made Crowdstrike mandatory to be installed on all of our Mac workstations along with Cisco Anyconnect VPN, which we found causes the JSI network filter to be disabled upon those resources being enabled. Are there any workarounds for these issues? We are interested to know what othe
Apologies for the newbie question: How do you reapply a configuration profile: For example: configuration profile to apply WiFi networks to managed Macs. One users goes through System Preferences > Network and deletes the WiFi networks applied in the profile. The profile still exists on the devices but its payload has been removed. How do you either flush that configuration profile has been applied to this Mac or reapply the configuration profile? I see you can Edit the configuration profile in JSS and then reapply to all in scope but is there a way to do this to specific devices? Thanks,Paul
Hi All is there anyway that Email address in entra can be claim on credential for Jamf connect instead of the UPN in entra? or have both? Thanks
Our organization mostly uses iPhones as wifi-only devices. There's a message at the top left near the wifi symbol where the cellular company name used to be. The message alternates between "SOS only" and "No Sim". Often, during troubleshooting with the service desk the users simply see this message and assume this is why the phone is "broken", even though that is the standard message for all our devices. Is there a way to change that message at the top left to anything else? We've searched all over and can't find a way to change that message. Any help appreciated as user education doesn't seem to be helping.
An up-to-date changelog of the Jamf Protect endpoint threat prevention feature is now available on the Jamf Learning Hub. The endpoint threat prevention database for macOS is managed by the Jamf Threat Labs team. Note: This changelog is separate from the Jamf Protect product release notes.
Today we released Jamf Connect 2.44.0; this release addresses the following product issue: [PI123459] Jamf Connect now passes the correct shortname to Kerberos when using the PasswordChangeFlow workflow. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hello everyone!Searched/googled but don’t find any good guide or solution for it. Anybody know anything?We shell uninstall it from abot 1.000 Macs and replace with another anti virus tool.
Hi community,I running into a strange behaviour for Google Meets on our BYOD deployment for iOS devices. I have configured per App VPN as I did for all other BYOD apps in combination with Jamf Trust ZTNA. Whenever I want to join a call, I am not able to join it.When I remove the per-app VPN in the app's configuration then I am able to join.Is there something I am missing or constraints to be considered?Maybe there is a tweak to this?
where getting odd issues with Jamf connect at the start of our build procees not showing our wif network, it cant be seen at login screen but if you login local it leaps into action. Anyone else seen this before. Toggling button seems to make no difference.
Hello Team, What a good new !? Security and Identity teams will certainly appreciate the implementation of an AD CS connector utilizing outbound communication. Excellent ! 🥳 As explained on the release note, the outbound mode requires Jamf AD CS Connector 2.0.0. Could you please make this version available, at least on the feedback program ?
How can we disable or hide the Apple Intelligence and Siri options in System Preferences? I attempted to do this using a configuration profile, but it didn’t work.
Hello all, Would just like to open up a conversation, to see what people are doing around Multi Factor/2 Factor Authentication. I've been tasked with securing all our Mac logins with 2FA. I've had mixed degree's of success, using both SecureAuth and Yubikeys. We FileVault our Mac's, so use with any 2FA is difficult without disabling the automatic FV login, which in my opinion becomes a poor user experience. We also want to be able to use the 2FA for unlocking the lock screen/waking up from sleep which doesn't work with SecureAuth and their SMS/Push Notification 2FA. I have had success with Yubikeys having to be plugged in, so that a user can login, wake from sleep and unlock the Mac. These do seem difficult to deploy on a large scale. This is looking like our only alternative. Was hoping to find a way to use both Touch ID on ours Mac's and the users password, this tho doesn't seem possible at the moment. Our other option is conditional access on applications on the Mac's, ideall
I would like to know if anyone else is experiencing this issue. Unable to log in with any user on the device while writing data to the server, the system will notify and prompt to log in again. We tried logging in again, but the device is still unresponsive. Note: Model: MacBook Pro (13-inch, M1, 2020)Processor: Apple M1FileVault 2 Enabled (System)Personal Key: Yes Preliminary testing steps: Resetting the password and account did not resolve the issue. Checked for the latest macOS update through Recovery Mode. Unable to access Safe Mode on macOS. To verify the accuracy of the information, users can confirm that they successfully accessed the system without needing to enter a password.
I have an IOS application we are about to deploy through JAMF Pro. the app vendor would like for me to force allow permissions that their application prompts for on first use:allow notifications from appallow app to use locationallow app to use Bluetoothallow app to Access Your Motion & Fitness ActivityIs this possible to do through jamf pro?
We are testing the PSSO with the Secure Enclave method. When setting the Account Authorization Type as Standard in the PSSO configuration, we've observed that post-registration, Mac local user accounts with Admin access are downgraded to Standard user accounts. Conversely, when utilizing Account Authorization Type as Admin in the PSSO configuration, we've noted that post-registration, Mac local user accounts with Standard access are elevated to Admin accounts. wherein user accounts are not inadvertently changed from Admin to Standard or vice versa. any hints on this?
Lately I've noticed (this also happened to my coworkers) that when I log into JamfPro I find my dashboard loads for about a split second then disappears. I've tried the following steps to troubleshoot the issue. Clear my cache, restart browser. Try a different browser (Chrome, Safari, Firefox) Removed each item on the dashboard hoping that one item was causing the isssue. Tried added an item that wasn't there before. Had my coworker do the same steps with their account. Has anyone else run into this issue?Anyone have a fix I haven't thought of? Honestly it's not a big deal, but I'm of the mindset...if it's there...it should work.
I have a policy to manage the applications that show on the Dock. In the picture provided it shows the triggers and execution frequency. For some reason the policy executed on the local admin account, but since these laptops are in a 1 too many program we have several local Standard accounts created for students. I am noticing that the policy has trouble executing on the other Standard accounts. In the logs of the policy, the device does not even show up, but i know it has executed on the admin account. Any advice or tips? Picture provided shows the triggers and frequency. Thanks
Hello jamf nation, We have 2 managed local administrator accounts on our Macs. One is the PreStage admin, which is created during the macOS Setup Assistant. This is the PreStage admin "hu", which is LAPS enabled. And we have the jamf management account "ja", which is also LAPS enabled. We have now removed the PreStage admin "hu" from all devices, as we only wanted to have one admin on the devices. Since LAPS, we can now also use the jadmin, if necessary, to enter passwords in exceptional cases. Unfortunately, the PreStage admin remains in the jamf Pro database and is displayed in the computer object. There is also still the option to display the LAPS password. If you display the Laps password, it ends with the Failed mdm command: "SetAutoAdminPassword" - "Unable to find user with GUID '851D63DB-068A-4FCD-B650-709144FE6E20'" Has anyone else removed the PreStage Admin and had the same experience or do you just leave the Admin and have 2 Admins on the devices?
Hi All, Pretty much at the moment I've enable a deny access to the security and privacy tab in system preferences. We have mainly done this to stop the users changing their password. But this however is really annoying if a user needs to grant permission to an app to allow microphone access, camera access and the rest. Is there any work around where I can allow users to this but grey out the change password option under security & privacy > general > change password
Trying out the new Self Service feature added to App Installers. I'm testing using the Google Drive app. I've made the app selection from the Jamf App catalog, configured it for Self Service, and scoped to my targets. Whenever any of the computers/users opens Self Service and clicks to install Google Drive, we get the error: "This application is unavailable. Try again later." from Self Service.Anyone else experiencing this issue?
Hi, We've noticed recently that when users are enrolling iMacs and MacBooks (not iPhones and iPads they seem to work) Jamf isn't collecting user details used to enroll on every occasion they seem to be missing about 75% of the time. This only seems to have become an issue since we moved to Jamf Cloud and Azure for authentication. Has anyone else had similar issues? Matt
I have downloaded and tested the new Self Service+ and it is definitely an improvement over the old Self Service app.I'm wondering if/when it will see better support in Jamf Pro. Currently to deploy it I'd be pushing a .pkg installer via a computer Policy, whereas the old Self Service app has an entire panel in the Jamf Pro settings for automatically deploying and configuring it on endpoints. As we get closer to EOL for the old Self Service will we see similar support for the Self Service+ app added to Jamf Pro?
Wondering if anyone is experiencing this lately... When we schedule a DDM update, the device successfully gets the command from Jamf Pro. The device downloads the update, but it immediately installs the update without honoring the scheduled plan. There isn't a notification, maybe a 5-second ticker, then the device shuts off and updates. Some other details: • Happens to some devices, not all • I set the deadline a few days out • Noticed this around iOS 18.1 - 18.2.1 • Here is a log from sysdisagnose: [DDM] -[SUDDMManager _scanForUpdateForDeclaration:retryIfNecessary:]: Scanning for update for DDM declaration SUCoreDDMDeclaration (DeclarationKey:com.apple.RemoteManagement.SoftwareUpdateExtension/EAD2FADB-1141-44C4-8E49-6E07F462A033:NmQ1ZjVjYTItMzViNS00ZDcxLThkMWQtNGMxZmY3YmJlODYx.NjZmYTA2YzYyZGJjNjFmNzM0OGE1ZGY1YTNhMGU3ODg4ZWQwMjRjNDg5NTcwZDZmZDM4YWQ2M2VjNjc3ZWVkYQ==|EnforcedInstallDate:2025-01-08T22:00:00|VersionString:18.2.1|BuildVersionString:22C161|DetailsU
I am trying to remove and add some Dockitems to our new Users, so far it goes well with the Built in Tool and policies. Just these three Apps don't work. I am using the following path file://localhost/System/Applications/TV.app/file://localhost/System/Applications/Music.app/file://localhost/System/Applications/Launchpad.app/ I'm aware that there are other tools like dockutil and dockmaster, but I would like to use the built-in functions. Am I doing something wrong or is this a known issue?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!