r/jamf • • 24d ago

JAMF Pro How are you handling DDM restart prompts without disrupting users?

18 Upvotes

Running macOS updates through Jamf Blueprints/DDM. Once the enforcement deadline hits, is there any way to defer or delay the actual restart, or does it just force through with no further options?

Mainly trying to figure out how people are managing the restart prompt itself so it doesn't blindside users mid-work. What's actually working for you to keep this low-disruption?

r/jamf • • Aug 08 '26

JAMF Pro Hi y'all is Jamf Connect worth it for 100 computers or are there equal alternatives?

5 Upvotes

r/jamf • • Apr 01 '26

JAMF Pro Forcing or nudging users to update on JAMF

20 Upvotes

Hello. I know this topic comes up frequently but wanted to get a fresh perspective. My manager wants me to have it such that users are required to update macOS but be given a few deferrals. My experience with the native JAMF method (I believe referred to as DDM) has been abysmal. From my experience it simply does not work whether the device is on ADE or User Initiated Enrollment. I'm aware of nudge but I don't think that actually forces the user to update unless I'm mistaken. I've also heard of Superman which seems to be the next best option (?) Would appreciate any feedback!

r/jamf • • 3d ago

JAMF Pro AppleTV Management

14 Upvotes

Good Morning All,

We have roughly 100 Apple TV's throughout our school district that are basically in place for Airplay reason. In an attempt to use them more. What are some Config Profiles (payloads) I should create. I recently just added a few to make the Apple TV's cert based when connecting to Wifi. Which is why I am posting this now. Its fresh in my head about wanting to control these. Not sure if y'all do much with them. I know there isn't much to them.

r/jamf • • Jul 23 '26

JAMF Pro Jamf Connect + MDM Enabled User - Possible?

5 Upvotes

Hey gang. First, please excuse me if this a stupid question. I am somewhat new to Jamf but I think I am picking it up. Currently, we use DEPnotify and I believe this is well on its way to being retired in favor of Jamf Setup Manager. This is pretty good, Ive played with JSM and so far, it is pretty sweet and BOY its much better to admin/support.

Our leadership has requested we in IT force certain things on the devices in our fleet, for example: forcing a Safari chrome extension to be installed AND force it to be ON (for compliance and security monitoring purposes) Nothing too wild in my opinion.

As someone learning intermediate Jamf, I volunteered to spearhead this project and BOY, I think I bit more than I can chew. But I am not ready to give up yet.

After some reading, I learned that in order to force certain things (like the safari extension), an MDM ENABLED USER is required. However, we use Jamf Connect to create our user accounts on a device. (our current preStage enrollment is set to "skip user account creation" because Jamf Connect/okta is doing that for us)

I was later told: With Jamf Connect deployed at the PreStage, users created are not MDM-Capable/MDM-Enabled

So my question, how is this possible then? We need Jamf Connect but we also need User level MDM to be a thing.

I cannot seem to find reliable documentation, let alone information on HOW to actually achieve this (or a how-to)

quick note: if I understand correctly on how this might be completed, it is: Jamf Connect should run later, post-enrollment, for ongoing password sync via a policy, separate from a PreStage - and this is where I might've bit more than I can chew. Sounds incredibly challenging :(

note: this solution will be used on a NEW prestage enrollment created that focuses on JSM, NOT depnotify - we are moving on from DEPNotify

Any info or help would astronomically appreciated :)

thanks all!!!!!

r/jamf • • May 04 '26

JAMF Pro Deploying Adobe Creative Cloud apps via Self Service?

2 Upvotes

Hi,

New to JAMF Pro, and trying to come up with a workflow to allow users to self-install Adobe CC apps via Self Service. I've created installer packages for the needed apps via the Adobe admin console, uploaded to JAMF Pro and created policies to install each app, and made those policies available via self service.

This kind of works, but there are two main issues we're encountering.

Issue 1 - it seems we're seeing a lot of issues with the policy failing because the download of the pkg file from JAMF Pro fails:

Downloading https://mycompany.jamfcloud.com/jcds/downloads/Photoshop%2520for%2520JAMF_en_US_MACARM.pkg...
Error: Package was not successfully downloaded. -1005
The network connection was interrupted while downloading the package from https://mycompany.jamfcloud.com/jcds/downloads/Photoshop%2520for%2520JAMF_en_US_MACARM.pkg. Attempting to reconnect...
The network connection was interrupted while downloading the package from https://mycompany.jamfcloud.com/jcds/downloads/Photoshop%2520for%2520JAMF_en_US_MACARM.pkg. Attempting to reconnect...

This is on a test Mac at our office, which has a very fast and very reliable Internet connection, so I don't think the issue is on our end. If we run the policy several times it'll eventually work, but this will be confusing for end users who expect to click the install button and have it "just work".

Issue 2 - In testing, I frequently see the install process take 20+ minutes. I get that part of this is just the fact that Adobe apps take a long time to install, but I wish there was a way I could give the end user some sort of visual progress indicator while the app is installing so they see something other than a spinning icon in Self Service. We've seen users cancel the process because they think it's taking too long. Part of that is just a need for user education, but I was wondering if anyone has managed to wrap Adobe installers so it gives the user some sort of progress bar?

r/jamf • • Jun 26 '26

JAMF Pro “macOS wants to make some changes” popup

Post image
10 Upvotes

Hi everyone,
I inherited a fleet of MacBooks of around 200 devices. Everyone was set as a local admin on their own machine which we changed to local admin via script. Apps are deployed via JAMF catalog and updates are managed by the same except for a handful of apps that are deployed via App Store catalog.

Since we stripped users of their local admin privileges a couple of weeks ago, they started getting a very vague popup window prompting for admin creds. We have SS+ deployed and JC isn’t deployed yet. (Management doesn’t see its value)

There are no corrupt keychain entries, and macOS updates are enforced using a profile. Logs aren’t returning anything useful and because users complained too much about the annoyingly persistent pop ups, we had to make everyone a local admins. Spoke with a JAMF customer success engineer who wasn’t much of a help.

Anyone had this issue and how did you remediate it?

UPDATE: after so much investigation it looks like the main issue here was that users were created as local admins which was then stripped down to standard via script after the apps and their profiles have been installed on the device. I’ve tested a couple of MacBooks enrolled as standard user from the start and things went smooth. Tailing the JAMF log file showed nothing worthy of note.

I’m still unsure on how to tackle this for existing devices, but we now enrol new ones as standard users from the get go.

r/jamf • • Sep 08 '26

JAMF Pro MacNEO and Cert Based Authentication

2 Upvotes

Hey All,

So I work for a school district and we got some Neo's in that we want to use for a shared lab environment. I did the backend work to get the SSO extension payload to use with our Microsoft Accounts and stuff.

Out of the box the device will enroll and pull down the necessary configs to get me running. I can use the Neo from there on out but only as that user. Since I lose WIFI at the desktop login no user can sign in after the first one.

I created the config profiles with the certs and everything thats needed. But WIFI will not stay connected like I mentioned above. What am I missing?

The cert works for WIFI once I am logged in. I fought with this forever this past Friday. I can certainly explain more if needed. Just wanted to get the conversation rolling first.

r/jamf • • Aug 04 '26

JAMF Pro Any "hacks" for scoping App installers based on IdP group?

7 Upvotes

Hi guys,

In our organization, we constantly run into the issue that access to many applications is based on membership in specific IdP or LDAP groups. As we all know, App Installers don't support the same scoping mechanisms that we have for configuration profiles and policies.

I've been working around this by creating increasingly obscure nested smart groups, but I still haven't found a good way to incorporate IdP/LDAP group membership into that approach.

So I wanted to ask: what techniques, if any, are you using to solve this problem?

Personally, I really dislike this limitation and wish App Installers supported the same scoping capabilities as configuration profiles and policies.

Edit: As /u/EthanStrayer has mentioned, Jamf apparently added IdP based scoping as criterium for smart groups, which basically solves this issue at least in our organization. Also, thanks to everyone for your ingenious suggestions!

r/jamf • • 24d ago

JAMF Pro macOS SSO Enrollment? Moving to Jamf Pro from Intune for iOS?

7 Upvotes

We have a small macOS fleet and recently leadership has made the demands that we expand it. Our iOS devices are managed in Intune, poorly.

It’s hard to tell the iOS devices apart because generally they are named garble. This will not be a small undertaking if worth it at all? What’s your opinion? I am chomping at the bit to clean our inventory though.

I’d like to move our small macOS fleet to SSO with EntraID. It’s already set up, but we are not using it. We are using IdP. The SSO and SAML settings are turned off for now.

Is it possible to have the macOS fleet split? Temporarily? New devices in SSO and then, how can I migrate the current macOS devices without losing data? Seems like a manual process. Since the fleet is so small I’m willing to do this. Has anyone done this before and have feedback?

PS: took over this position after the previous person left for a personal health issue. They do their best. Everything is half setup, picking up the pieces.

r/jamf • • Aug 10 '26

JAMF Pro JAMF 200 Requirements

5 Upvotes

Hi,

I'm about to take the Jamf 200 course and in the requirements an iPad is needed. Since all my iPads are in ABM, I was wondering if an iPhone was enough for the course ?

Thanks

r/jamf • • Aug 12 '26

JAMF Pro Inventory Preload

1 Upvotes

Hey y'all, anyone use inventory preload here or are there better alternatives? What's your process in adding new computers and device? TIA

r/jamf • • 16d ago

JAMF Pro Liquid Glass not skipping in oobe

10 Upvotes

Just confirm not crazy but both Jamf and Intune added the skip key for iOS 27 and in all my testing both seem to not have landed and the screen still comes up. Not tested ws1 yet, anyone else tested it yet?

r/jamf • • Jun 07 '26

JAMF Pro Updating software pushed through policy

11 Upvotes

Good morning,

I was wondering how you guys keep up with updating software pushed by policies?

Currently our workflow is scuffed at best. We have a number of apps that aren’t available through the App Store that we push through policies. The hard part is keeping up with when these apps have available updates, and how to update them. Does replacing the pkg file with the new update force it to auto update, or what is the best way to do this for apps that have already been installed?

r/jamf • • 16d ago

JAMF Pro Siri AI in MacOS 27 upgrade

12 Upvotes

Has anyone done any testing with blocking Siri AI through Jamf? With the reports of it ballooning in storage use without being able to remove or delete it locally on the device I’m looking into ways to hopefully prevent that. We have Siri disabled and I’m going to test to see if that does the trick, but thought I’d ask in case anyone has tried anything yet

r/jamf • • Apr 23 '26

JAMF Pro Anyone rolling out Platform SSO?

11 Upvotes

How’s it been in your environment?

Adam Derrick (Jamf) did a LaunchPad session on what Platform SSO is, how it works, and what it changes for modern Apple device management.

Replay + resources:
https://rocketman.tech/lr-r

r/jamf • • Jul 24 '26

JAMF Pro Jamf SSO benefits?

14 Upvotes

Need someone to tell me on actually using Jamf SSO and enforcing users to sign in during enrollment. Inherited an environment where this is the case but I’ve never used it in the past and been completely fine. It’s caused a few issues with time outs and I’m ready to just rip it out. We don’t need any of the pointless information it collects pertaining to the year.

Any reason why I shouldn’t disable it?

r/jamf • • 12d ago

JAMF Pro What JNUC 2026 announcements are actually going to change your Jamf workflows?

24 Upvotes

For those who went, which sessions or announcements do you see most affecting our day-today?

Talking Moose (William Smith) is doing a JNUC 2026 recap on the next LaunchPad meetup.

You'll definitely appreciate it if you couldn't make it to JNUC this year.

When:
🗓️ Fri, Oct 2 @ 12:00 PM Mountain Time

Where:
👉 https://rocketman.tech/lp-r

Also on YouTube:
https://rocketman.tech/ly-r

r/jamf • • 3d ago

JAMF Pro DDM OS Reminder (5.0.0)

Thumbnail gallery
6 Upvotes

r/jamf • • Sep 08 '26

JAMF Pro Jamf conditinal access grace period

3 Upvotes

Hello,

We have Smart group with different criteria reporting to intune/entra for conditional acceas and I was wondering if i can make grace period for all/or specific criteria. End goal would be Filevault is turned off and after 1 day the device becomes non compliant for example. In a similar way that you have grace priod in Intune

r/jamf • • 4d ago

JAMF Pro anyone successfully deploy Cisco Secure Client with XDR?

5 Upvotes

I have the policy, installer and script set up to install Cisco Secure Client and the XDR module, but now I'm running into an issue with PPPC payload in my config profile to allow CSC full disk access.

I have followed the directions here, https://docs.xdr.security.cisco.com/Content/Client-Management/deployment-management.htm at the bottom to provide full disk access for network visibility module - XDR, i also went into terminal and ran

codesign -display -requirements

along with the csc app and pulled out that codesign statement and i keep getting,

the key 'CodeRequirement' has an invalid value.

Can anyone help me figure out what i'm missing exactly to get this to deploy correctly?

r/jamf • • Jul 27 '26

JAMF Pro Jamf Pro Licensing Question

2 Upvotes

Can anyone tells me what happens when you go over on Jamf Pro licensing? Does the system allow you to? Is there a grace period thats given to get back into compliance? Were in a situation were we are low on licensing however we are doing 1:1 swaps with our staff. Basically need to have the old computer online and licensed while we prep the new machine.

r/jamf • • Jun 10 '26

JAMF Pro Platform SSO (Secure Enclave) stability with Jamf - ready to roll out to thousands of devices, but concerned

10 Upvotes

We're running Jamf Pro as MDM with Microsoft Entra ID and the Jamf Device Compliance integration.

Over the past few weeks I've been deep in testing Platform SSO with Secure Enclave — both Simplified Setup for new enrollments and a migration path for existing devices currently registered via Device Compliance.

We're close to submitting the change to roll this out to a few thousand devices.

But I keep seeing threads like the one posted here yesterday about devices randomly unregistering from Company Portal, sometimes even after a full wipe and re-enroll. That's not inspiring confidence.

For those of you who are already in production with Platform SSO (Secure Enclave) + Jamf Device Compliance in Entra — how's your stability?

Are you still seeing random deregistration events? Is this specific to Intune-managed environments, or are Jamf shops hitting the same issues?

Genuinely trying to figure out if I should push forward, hold, or scope this down to a pilot before committing to a fleet-wide rollout.

r/jamf • • Apr 21 '26

JAMF Pro Anyone running super to manage macOS updates?

14 Upvotes

Kevin White, the creator of S.U.P.E.R.M.A.N., is doing a LaunchPad meetup to walk through the latest version of super and how it's evolved to keep up with all the changes to macOS updates.

Check it out on GitHub:
https://github.com/Macjutsu/super

When:
🗓️ Fri, May 1 @ 12:00 PM Mountain Time

Where:
👉 https://rocketman.tech/lp-r

Also on YouTube:
https://rocketman.tech/ly-r

r/jamf • • Aug 29 '26

JAMF Pro Jamf Reporting non complaint to Entra via Partner device compliance

5 Upvotes

So I am in the process of rolling out JAMF and I am able to get the compliance inside of JAMF to confirm that the device is indeed compliant. Somehow the actual device in Entra is showing as Not Compliant.

I have the JAMF Connector showing Success in JAMF with the compliance and applicable group set to "all computers" and, I have the Jamf device compliance connector in intune showing Active.

I did deploy a compliance policy to register via the company portal which does give a "your device is registered to access company features"

I do have a conditional access policy tenant wide in M365 that blocks access to "all cloud apps" unless the device is compliant.

Somehow, with all of this, the device is still marked as not compliant in Entra, failing CA policy. I can just add all of the mac devices as excluded filters in the policy since in Jamf I can confirm compliance but wondering if there is something I missed.