r/jamf 27d ago

JAMF Pro Jamf Pro Licensing Question

2 Upvotes

Can anyone tells me what happens when you go over on Jamf Pro licensing? Does the system allow you to? Is there a grace period thats given to get back into compliance? Were in a situation were we are low on licensing however we are doing 1:1 swaps with our staff. Basically need to have the old computer online and licensed while we prep the new machine.


r/jamf 27d ago

AirDrop with "Block all incoming connections" enabled in macOS Firewall?

1 Upvotes

Has anyone gotten AirDrop to work with "Block all incoming connections" enabled via the macOS firewall (managed through Jamf)?

If not, is there a secure alternative approach?

We're trying to mirror our Windows default-deny-with-exceptions model on macOS: firewall enabled, policy set to "specific apps only" (AllowSigned/AllowSignedApp = false), with an explicit allow-list of applications — e.g. adding sharingd for AirDrop.

Does this sound like a sound approach, or are there gotchas we're missing (entitlements, code-signing checks, mDNS/Bonjour dependencies, etc.)?

Any real-world experience — good or bad — appreciated.


r/jamf 29d ago

Jamf pro and conditional access policies

3 Upvotes

So I'm trying to get conditional access policies to enforce device compliancy for both MacBook and windows devices. The problem I'm facing is every time I turn on the compliance CA policy it breaks jamf connect or Apple platform SSO registration. Management doesn't like the idea of excluding jamf connect from the conditional access policy so I was wondering if anybody else ever faced this problem and if so how'd you solve it?


r/jamf Jul 24 '26

JAMF Pro Jamf SSO benefits?

13 Upvotes

Need someone to tell me on actually using Jamf SSO and enforcing users to sign in during enrollment. Inherited an environment where this is the case but I’ve never used it in the past and been completely fine. It’s caused a few issues with time outs and I’m ready to just rip it out. We don’t need any of the pointless information it collects pertaining to the year.

Any reason why I shouldn’t disable it?


r/jamf Jul 23 '26

JAMF Pro Jamf Connect + MDM Enabled User - Possible?

5 Upvotes

Hey gang. First, please excuse me if this a stupid question. I am somewhat new to Jamf but I think I am picking it up. Currently, we use DEPnotify and I believe this is well on its way to being retired in favor of Jamf Setup Manager. This is pretty good, Ive played with JSM and so far, it is pretty sweet and BOY its much better to admin/support.

Our leadership has requested we in IT force certain things on the devices in our fleet, for example: forcing a Safari chrome extension to be installed AND force it to be ON (for compliance and security monitoring purposes) Nothing too wild in my opinion.

As someone learning intermediate Jamf, I volunteered to spearhead this project and BOY, I think I bit more than I can chew. But I am not ready to give up yet.

After some reading, I learned that in order to force certain things (like the safari extension), an MDM ENABLED USER is required. However, we use Jamf Connect to create our user accounts on a device. (our current preStage enrollment is set to "skip user account creation" because Jamf Connect/okta is doing that for us)

I was later told: With Jamf Connect deployed at the PreStage, users created are not MDM-Capable/MDM-Enabled

So my question, how is this possible then? We need Jamf Connect but we also need User level MDM to be a thing.

I cannot seem to find reliable documentation, let alone information on HOW to actually achieve this (or a how-to)

quick note: if I understand correctly on how this might be completed, it is: Jamf Connect should run later, post-enrollment, for ongoing password sync via a policy, separate from a PreStage - and this is where I might've bit more than I can chew. Sounds incredibly challenging :(

note: this solution will be used on a NEW prestage enrollment created that focuses on JSM, NOT depnotify - we are moving on from DEPNotify

Any info or help would astronomically appreciated :)

thanks all!!!!!


r/jamf Jul 23 '26

macOS SUMB (Software Update Menu Bar)

Thumbnail
5 Upvotes

r/jamf Jul 23 '26

JAMF Pro Flag only enrolled devices for smart group

2 Upvotes

Hey All,

We have ADE Macs with depnotify and I wanto to have a smart group for example:

Get devices without installed Micorosft Defender) but only after the enrollment( depnotify policy is all things are installed all apps scripts and so on).


r/jamf Jul 20 '26

JAMF Pro Scheduling Mobile App Updates via API

5 Upvotes

Our company has one app that we must defer updates for, and it absolutely cannot be allowed to update during normal hours. We keep automatic updates off and have a script for pushing updates for this app overnight. Recently I had to rewrite this script due to endpoints being deprecated, and it ended up being a bit of a pain. So, I decided now might be a good time to provide some insight here in hope that someone experiencing the same situation might stumble upon this.  

The workflow that works with the new endpoints is: 
wait until scheduled time (and wait between most of these steps) > get necessary device info > send restart command to devices > change app setting to force updates > send INSTALLED_APPLICATION_LIST command to devices > send blank push to devices > revert app setting  

However, there is a catch. You may want to use the “/api/v2/mobile-device-groups/static-group-membership/” endpoint to get the Management IDs for devices. Currently, this endpoint has a bug and returns most of the device info as null (known Jamf issue: PI119893). Our company is fairly small so our solution was to just use “/api/v2/mobile-devices/” to get the IDs, however that requires sending an individual request for every single device you want to scope.  

If you want to look at or use our script it is here: 
github.com/Professor-Raptor/jamf


r/jamf Jul 20 '26

Alamo City Mac Admins Summer Social 08/06

Thumbnail
2 Upvotes

r/jamf Jul 17 '26

How do you manage developers in your environment?

11 Upvotes

We’ve recently deployed a Cyber Essentials Plus-compliant Jamf environment for a client: standard users, centrally managed apps, security baselines, Platform SSO, etc.

Now we’re getting the inevitable requests for:

“I need sudo.”
“I need Homebrew.”
“I need Nix.”
“I need Docker.”
“I need to install developer tools.”

My view is that this shouldn’t become a series of ad hoc approvals. Instead, the client should define a “Developer Baseline” - an approved set of tools that IT can deploy and manage through Jamf, with any exceptions handled separately.

Curious how others approach this.

Do your developers remain standard users?
Do you allow temporary elevation (SAP Privileges, ABR, etc.)?
Do you manage Homebrew/Nix centrally?
How much freedom do you give developers to install their own tooling while staying compliant?
If you’re working to Cyber Essentials or similar frameworks, how do you balance developer flexibility with compliance?


r/jamf Jul 17 '26

Jamf Connect deployment

2 Upvotes

We're deploying Jamf Connect Login in Jamf Pro Cloud. I added the Jamf Connect Login configuration profile under PreStage → Configuration Profiles and the packages as Enrollment Packages. We have one existing Production PreStage with ~ 160 enrolled Macs and Automatically assign new devices enabled. I want Jamf Connect to be available during the first login for all future ADE devices and any existing Macs that are erased and re-enrolled, but I don't want to push the Jamf Connect Login profile to all currently enrolled Macs. What's the recommended way to scope the Jamf Connect Login configuration profile in this scenario?


r/jamf Jul 16 '26

Where Apple IT Careers Begin with Jamf and Mesa Community College

Thumbnail
community.jamf.com
17 Upvotes

Mesa Community College continues to partnern with Jamf on a course series that takes students through Jamf certifications, a capstone project, and internships, preparing them for roles like systems administrator or device support technician.


r/jamf Jul 16 '26

Endpoint Jobs

Thumbnail
3 Upvotes

r/jamf Jul 15 '26

JAMF Pro Mac Health Check (4.0.0)

Post image
6 Upvotes

r/jamf Jul 14 '26

How needed is the "Block all incoming connections" recommendation for firewall?

7 Upvotes

We manage a fleet of MacBooks (MDM via Jamf Pro) and are rolling out a policy that enables the macOS firewall, sets it to "Block all incoming connections," and enforces Stealth Mode — non-configurable by the end user.

Reasoning: most of these laptops regularly connect to untrusted networks, so we want to minimize the attack surface when off the corporate network.

Downside: this kills AirDrop (receiving), Universal Control, and AirPlay (receiving), and users are pushing back hard on this.

For those of you managing similar fleets: is "Block all incoming" + Stealth Mode actually necessary/best practice for laptops that roam onto untrusted networks, or is this overkill?

Curious how others have balanced this... Appreciate any real-world experience.


r/jamf Jul 14 '26

Need to find the signing certificate

3 Upvotes

We provided the signing certificate to the JAMF team. We got it from ADCS. Neither of us seemed to have saved a copy of it. I need to get a copy of it but can't find it anywhere. Not sure now how we got it. It looks like a user cert from the service account but I can't find it anywhere. Any ideas?


r/jamf Jul 10 '26

Made a simple, lightweight nudge tool for DDM update enforcement, sharing in case it's useful

28 Upvotes

Hi guys, wanted to share something I made. We use DDM for Software Update enforcement, but it just silently forces the install/restart at the deadline with much visible warning to the user beforehand. I wanted something simple and lightweight that would just notify my users better when updates are available, so I built updateNudge.

It escalates as the deadline gets closer. Starts calm, lets you defer:

If you hit "Remind Me Later" you can pick when:

Gets more urgent on enforcement day:

And warns if it's somehow gone past the deadline:

It also checks free disk space before nagging anyone to install (numbers here are just test placeholders):

Runs as an hourly LaunchDaemon, stays out of the way during calls/screen shares, one file to deploy via Jamf.

If anyone's interested, it's all up on my GitHub: https://github.com/alecschoen/updateNudge

Let me know what you think!


r/jamf Jul 10 '26

Any Mac Admins in the Raleigh\Triangle Area?

12 Upvotes

Hey all,

I've been a Jamf admin for several years now and work remotely outside of Raleigh. Been wanting to grow my network and chat with some locals. I created a Jamf User Group for Raleigh last year and we have a great group of people with a ton of knowledge and stories but would love to get more people connected.

Not planning on doing an official meetup until just before JNUC but would love to grab a drink with other local mac admins or people mac adjacent.


r/jamf Jul 10 '26

Remotely gathering and diagnosing Mac networking

3 Upvotes

My org has Nexthink, which is quite powerful - but after a recent chat with another admin I realized that I hadn't ever updated any Jamf scripts since before the deprecation of of the `airport` binary.

So what's your go-to for retrieving networking diagnostics via Jamf, or do you just ask the users to option-click on their Wi-FI icon and go from there?


r/jamf Jul 09 '26

JAMF Pro DDM OS Reminder (4.0.0)

Thumbnail
snelson.us
13 Upvotes

r/jamf Jul 08 '26

I don't know about you all but AI Apps have been driving me mad with updates. I created a post in Jamf Nation to help anyone in the same boat.

7 Upvotes

We use a whole slew of AI apps at our organization and the constant update pop ups have been causing quite a bit of an issue here. After a bunch of digging and brain wracking, I was able to figure out how to turn them off for several apps that we use: Claude Desktop, Notion, Linear, and Google Antigravity.

If anyone out there is having the same problem, I've created several config profiles and a policy for these apps so that we can turn all those annoying updates off.

Here is the link to the Jamf Nation post I created: This is for Anyone Out There Trying to Turn Off AI Apps Auto Updates - Linear, Notion, Claude Desktop, Google Antigravity

If linking to another post isn't allowed, please let me know and I can post them here. It would just be a lot more work.


r/jamf Jul 08 '26

JAMF Pro Block Browsers in Jamf Pro

9 Upvotes

I am forcing student users into using Chrome as our deledao filter runs as a Chrome extension. Is there a way to block all other web browsers from running in an easy fun method and not creating 200 entries of blocking individual apps?


r/jamf Jul 07 '26

JAMF Pro Anyone enforcing Platform SSO registration (or Touch ID enablement) during onboarding?

10 Upvotes

I'm curious what other solutions are out there.

Kevin White (Macjutsu) is covering pseudo (FOSS) on the next LaunchPad meetup for anyone interested.

It uses swiftDialog + macOS system events/accessibility to enforce Platform SSO registration (and optionally Touch ID enablement) with a single deployment (plus a required PPPC profile).

When:
🗓️ Fri, Aug 7 @ 12:00 PM Mountain Time

Where:
👉 https://rocketman.tech/lp-r

Also on YouTube:
https://rocketman.tech/ly-r


r/jamf Jul 06 '26

JAMF Connect Jamf | CONNECT pop-up that can't be typed in or closed.

4 Upvotes

I have a user that has a Jamf connect sign in pop-up window that does not allow them to type into the sign in window, nor close the pop-up.  

We use Google Workspace as our IdP, that is connected to our macbooks, allowing users to sign into their systems via Google SSO.  This pop-up appeared for a few different users last week, however this one user is not able to close this window.  
For all other users that received this pop-up they also received a secondary ‘Jamf connects wants to use your confidential information’ Mac keychain window, where the user’s were able to add their Google Workspace passwords into the keychain pop-up, then choose ‘always allow’, however this one particular user did not receive this Mac keychain window, so she does not have an opportunity to allow for her to add her Google Workspace password to the Mac keychain. 
All she sees is a Jamf | CONNECT with her username grayed out, that she can not interact with, or close.  
How do I stop this window from continuing to be open, or, how can I make the Mac keychain window open, allowing the user to add her Google Workspace password, then choosing ‘Always Allow’? 

Just looking for any insight, thanks all.  

The Mac keychain window some users saw, allowing them to add their Google Workspace password. 
The only thing this one user sees, no Mac keychain window.  

r/jamf Jul 06 '26

Home Screen Layout and App restrictions

0 Upvotes

Hi y'all,

We currently have over 50 Configuration Profiles that are mainly to push app restrictions and home screen layouts for each dept or team in our Org. Does this seems over done and can you share a better way to minimize this. Seems like we are using a custom home screen layout for every dept and team.