Get Support
Recently active
Hey, since last week we can not remove the Restriction Software settings from Mac Clients. We run Jamf Pro Version 11.13, most Clients are on macOS 15.3.1 Removing Clients from the Scope does not remove the Restriction Setting from the Clients. New Clients enrolled to the Site formerly in Scope of the Restriction get the Restriction Setting ... Should I delete the Restriction Rule to remove it from the Clients? Thanks in advance!
HiI can't find any documentation on the new "Autonomous Single App Mode apps" restriction in the iOS Profiles. Can someone explain me what it does? Thanks in advance!
Basically the title, does pushing the same config profile with different settings applied cause conflicts? Here is a very specific example: Security and Privacy One profile has the firewall turned on and another has the firewall off (not checked). Basically, which wins? Do they fight? We had some weird behavior happen when pushing the same payload multiple times with different settings. Any advise or guidance is appreciated.
We are using Jamf Pro and need a way to restrict students from changing the Wifi settings on iOS devices such as iPads. I have looked through all configuration profile settings/restrictions and do not see any that would achieve this result. Does anyone have a script or know how to accomplish this? Any help would be appreciated.
I was prompted about being able to enable the Apps Inventory (Beta) this morning. I activated it. There's a seperate option to use the current or beta version after that. It seems to be similar to the current Inventory page. It promised that the new appearance woudl be faster. That aside it doesn't seem to have any functionality. When I select apps I can't take any action. Beta: Current: Am I missing something? I did try in Firefox and Google Chrome.
I have a 2019 iMac running Sequoia that keeps losing the Jamf Connect (2.44) window at login. We use the "authchanger -reset -jamfconnect" command to fix it and it works when we log out after fixing it. But when we reboot, it goes right back to this. I have photos of the output from "authchanger -print" if anyone can interpret them. Thanks!
Well, the idea of Jamf Remote was wonderful... it's not reliable in any manner. We have a number of small businesses we support. Teamviewer is for our enterprise clients but the cost is a bit much for many SMBs. What do you use for your SMB clients when you have to balance cost vs features? I know the options, just looking to see why you use what you do [Jamf shop for most clients. ] Zoho Assist? Tailscale with Screen Sharing? Anydesk? Splashtop? LogMeIn?
We're excited to announce a powerful new feature in Jamf Security Cloud that enhances your organization's security posture through advanced vulnerability management capabilities. This new functionality enables real-time visibility into Apple device vulnerabilities and streamlines your security operations.Key Features and Benefits Comprehensive CVE Monitoring: Track both system and application vulnerabilities across your Apple device fleet Real-time SIEM Integration: Stream vulnerability data directly to your preferred SIEM solution Enhanced Security Visibility: Gain deeper insights into your security landscape through consolidated vulnerability reporting Automated Response Capabilities: Enable faster threat detection and streamlined remediation workflows Supported PlatformsThe vulnerability data stream integrates seamlessly with leading SIEM platforms, including: Microsoft Sentinel Splunk Datadog Google Security Operations Easy SetupGetting started with vulnerability data streaming
We have been trying to manually enroll few Macs and since last week, we are getting the attached error message. These Mac were enrolled to a different JAMF server, and we remove the old profiles before starting our own enrollment process. We are not facing any issues while manually enrolling any other devices apart from those specific ones. I have confirmed that MDM certificate and all profiles are fine. Any idea what might be causing this? Thanks
I have a smart group with users that have not shutdown/restarted over 30+ days. (one user 467 days) What kind of policy can I do to force a reboot, I've noticed some things have changed in Jamf Pro. A reboot with a timer and message?
Hi All,Any else having issues with setting up manage login items for Xerox Workplace Cloud Client..I have added the TEAMID but still getting the prompt when installed on Ventura..Here is what i have...Rob
TLDR: If Jamf Connect's password countdown isn't updating or Kerberos tickets aren't being received, turn off iCloud+ Private Relay. We recently solved a puzzling issue affecting a small number of users. After password changes, their Jamf Connect Menu Bar wouldn't refresh the expiration countdown (even showing negative numbers) and they weren't receiving Kerberos tickets, despite the new passwords working correctly in Entra and AD. After hours of investigation - trying different Jamf Connect versions, reinstalls, profile changes, and terminal commands like klist and kinit - we discovered the culprit: iCloud Private Relay was rerouting traffic, preventing proper domain resolution needed for Kerberos tickets. The simple fix: turn off iCloud Private Relay and restart Jamf Connect. Both issues resolved instantly!
Can we enable an button for user to view the password when login ?
I am working on deploying Platform SSO using Microsoft Entra ID. I have followed the steps outlined here: https://learn.jamf.com/en-US/bundle/technical-articles/page/Platform_SSO_for_Microsoft_Entra_ID.html#concept-7900 This seems to be working really well. I created a guide for my users to educate them about the steps that are needed to get registered to use Platform SSO. My current SSO implementation uses Kerberos. The URLS for our current SSO are our internal AD servers that also sync with Entra ID. When it is time for users to reset their password (90 days), they are notified 2 weeks in advance and notified again later. When they are ready to change their password, they can do so using the menubar icon. We are also syncing the user's local Mac password with their AD account password. When the user changes their AD password, the local Mac password is also changed to match. It's a very simple process to follow. I have been trying to find out what the user experience is for
Is there a way to configure TvOS to update automatically? I looked in the configuration profiles and I'm not seeing it.
Hi, I setup everything like documented here: https://github.com/Installomator/Installomator/tree/main/MDM/Jamf I'm trying to install Microsoft 365. The swiftdialog opens, the progress is completing (All MS packages installed) but swiftdialog never closes (stuck at "Finishing…"). /var/tmp/dialog.log last message is “Finishing…”/vag/log/Installomator.log states: "Installed MicrosoftOffice365, version blabla… All done!, exit code 0" I also tried to change the priority of zz_Quit, but this doesn't change anything.If I run the content from the zz_Quit Script from a terminal, the window get's closed. Any hint? Thanks, Stefan
Hi All, I am having a problem getting an iPad app installed from the Self-Service. Sparta Scan is available in the Mac App catalog and we have acquired the appropriate number of VPP licenses from ABM - even renewed our VPP token. When attempting to install via Self-Service, the app completes the installation, but when looking for it on the iPad, we are not seeing anything installed. In the Jamf Pro device management log for that device, I do see that Sparta Scan installed. We've deployed a handful of other apps in similar fashion, but it only seems to be this app. iPad: 10th gen 18.3.1 Jamf Pro: 11.14.0 App: Sparta Scan 3.32.1 Any insight is appreciated. Thank you!
We deploy a number of security products that require specific privacy preferences be set so that users don't block them from working. A couple recent deployments I've witnessed a new privacy pop-up for local network devices. I'm using JAMF Pro 11.9.0, but do not see any privacy preference options for this new Sequoia option. Anyone else seeing this or perhaps I'm looking in the wrong place. Just wanted to confirm with the community before raising it to support.
With Jamf School, we use Azure to authenticate our iPads as part of enrollment (Automated Device Enrolment). We've never normally had a problem, but we're now hitting an issue where, after successfully bringing up the Azure login screen and accepting the credentials, it will then display 'Redirecting you for authentication' on a loop for a few minutes. This will then fail and say 'We couldn't sign you in. Please try again.' I would be grateful for any ideas on how we might be able to troubleshoot this!
Im looking for ways to check the UK macs in our jss for icloud users that have enabled Advanced Data Protection and would like feedback on what people have done.
Hey Jamf Nation! We're excited to announce with Jamf Pro 11.15.0 Beta Blueprints is open for testing in Jamf Pro. We're also continuing Compliance Benchmarks in beta along with Icon Redesign and a lot more! How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hi all,New to this sub so I thought I would make a start with an interesting one.I've got jamf pro and jamf connect setup with Azure AD and working for the most part.Apart from the actual connect dialogue box closes instantly and doesn't actually log in. After some digging, I found that it's failing with the error...Kerberos Authentication Failed with error: KerbErrorHelpful and awfully generic, I know.I can confirm that not ticket is present after logging in by running "klist".If I run "kinit" it'll prompt me for passwords and then everything works as expected, firewall auth, smbs connect without prompting for credentials (When the account in use has permissions).I've got a ticket open with Jamf, they've not been too helpful as the ticket has been open for 8 days without a response from them! They've even tried closing the ticket.I'm at a loss, I want to get this project wrapped up by August and this is the final step, getting kerberos working and auto mapping of user drives...Thanks
I am curious to know what everyone is using for your SUPERMAN deployment script (of those of you who do use SUPERMAN). Here is my script: https://github.com/ScottEKendall/JAMF-Pro-System-Scripts/blob/main/Superman%20Script.sh I am pretty sure it is working, but I am curious if I missed something critical or some "fine tuning" might be in order...the docs on his website can be "daunting"... Please let me know your thoughts / suggestions...
We allow our employees to use the spotify app. Most of them are standard users meaning they get prompted for admin credentials for the update helper. What we want to do is kill automatic updates and then they can update via either self service or we automatically manage updates when our autopkg/jss importer runs. There are a few scripts on git to do this but none have really been proven to work. Does anyone have a surefire solution for Big Sur?
Hi everyone, Does anyone have a solution to the following: Automatically applying computer names to macOS devices that enroll via DEP? Thanks!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!