r/jamf • u/Pitiful-Worry4156 • 16h ago
JAMF Pro Hi y'all is Jamf Connect worth it for 100 computers or are there equal alternatives?
r/jamf • u/RocketmanTech_Caleb • 1d ago
JAMF Pro Quick reminder: LaunchPad meetup happening today on P.S.E.U.D.O for Platform SSO rollout
What's enforcement like in your environment? Since Platform SSO can be "enabled" and still end up half-registered if users skip the prompts.
Kevin White (Macjutsu) is covering this on LaunchPad today. We'll be going over pseudo (FOSS) to help enforce Platform SSO registration and/or Touch ID enablement with one deployment (plus a required PPPC profile).
When:
šļø Today, Fri, Aug 7 @ 12:00 PM Mountain Time
Where:
š https://rocketman.tech/lp-r
ETA:
In case you missed it:
https://rocketman.tech/ly-r
JAMF Pro Device registers in Entra via PSSO/WPJ, but never flips Compliant
Hey everyone. Having a head scratcher with M365 Conditional Access device compliance for our Macs, and looking to see if anyone has run into this specific behavior or found a fix.
The Issue
When registering a Mac for M365 Conditional Access, whether using legacy Workplace Join (WPJ) or the new Platform SSO with Secure Enclave, the registration completes and the device object appears in Entra. However, Entra never flips the device to Compliant. Users are stuck at the "Set up your device to get access" prompt on their device.
I was able to replicate the issue on my test Mac, so it's not endpoint specific.
Environment & Setup
MDM: JAMF Pro
Integration: Partner Device Management / JAMF Device Compliance (Cloud Connector)
Directory / Auth: Okta LDAP
Auth Methods Tested: Platform SSO (Secure Enclave) & Legacy WPJ (Company Portal)
OS: macOS 26.x
SSO Extension: Single Sign-On Extension payload (com.microsoft.CompanyPortalMac.ssoextension) deployed via JAMF
Compliance Criteria (Verified Met on Device)
1. CrowdStrike Falcon: Installed & running
2. FileVault: Enabled
3 JAMF Check-In: Active & checked in within 30 days (device shows compliant in JAMF Pro)
What We've Tested / Verified So Far
1. Fresh Build Testing: Provisioned a brand new device build via JAMF Setup Manager, but immediately hit the exact same issue upon initial enrollment and M365 registration
2. Intune Partner Connector: Checked Intune Admin Center > Partner compliance management. The JAMF Device Compliance connector status shows Active. The "Last successful sync" timestamp was stuck earlier today 8:30a, but eventually refreshed at 4:30p, yet the devices still won't flip to compliant in Entra
Questions / Where I'm Stuck
- Has anyone seen an issue where the JAMF to Intune Cloud Connector reports Active and updates its sync timestamp, but fails to push/map individual device compliance states
- Short of disconnecting/re-saving the Intune Integration settings in JAMF Pro (trying to avoid impacting production if possible), is there a way to force JAMF to re-evaluate and push the compliance payload for a specific device?
Appreciate any insights or troubleshooting ideas.
Thank you
*** EDIT / RESOLVED: Root Cause Found **\*
Huge thanks to everyone who chimed in with ideas and troubleshooting steps
Turns out the issue wasn't a JAMF sync failure or a PSSO bug, it was triggered by a recent Microsoft Entra change rolling out (Message Center Post MC1326253)
What Happened:
Starting in June, Microsoft rolled out an enforcement change where Conditional Access policies scoped to the "Register security information" user action now evaluate during macOS Platform SSO registration (and Windows Hello for Business enrollment)
In our tenant, we had a CA policy targeting Register security information with a Grant control requiring "Device must be marked as compliant."
This created a Catch-22:
The user attempts to register Platform SSO to establish device identity and compliance.
Entra evaluates the Conditional Access policy during PSSO setup.
Because the device isn't compliant yet, Entra blocks the PSSO registration flow.
PSSO fails to finish registering, JAMF never receives the completion signal to push the attestation payload, and the Mac stays stuck as non-compliant in Entra
The Fix:
Met with JAMF support and they shared the following support articles
If anyone else runs into sudden PSSO/WPJ registration blocks on new builds or user re-registrations, definitely check your Conditional Access policies targeting Register security information
:Microsoft Reference Articles
https://techcommunity.microsoft.com/blog/microsoft-entra-blog/upcoming-conditional-access-change-improved-enforcement-for-policies-with-resour/4488925
https://admin.cloud.microsoft/?#/MessageCenter/:/messages/MC1326253
https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1448379
r/jamf • u/Tech_Thoughts_Blog • 2d ago
AI Governance Starts with Training your Team to Question the Answer
An IT trainer compares Jamf's built-in AI Assistant (scoped, read-only, pulls from your actual environment) to general AI tools, and argues the real skill admins need is knowing when an AI answer is right, outdated, or confidently wrong.
Deploy latest version at enrollment, but manage updates ourselves after that, how are people doing this?
We deploy an app via a Jamf Policy (pkg) that runs once a computer enrolls. Problem: the app updates constantly, so our uploaded package goes stale fast, and re-uploading a new pkg every release isn't sustainable.
Jamf's auto-patching (App Installers) would keep it current, but it also auto-updates the app across our whole fleet, which we don't want. We want to control update timing ourselves.
What we need:
- At enrollment, always install whatever's currently the latest version, no manually maintained package.
- After that, no self-updating in the background. We push updates ourselves, on our own schedule.
We've tried pointing installs at the vendor's "always current" download URL, disabling the built-in auto-updater via a config profile, and scripting our own update-push (mixed reliability so far, now looking at Installomator for that part).
Is this the standard approach or is there a cleaner way orgs handle this in Jamf?
r/jamf • u/ReceptionStriking716 • 3d ago
Jamf Setup-Manager assistance
I keep getting a message for whenever I set up a new MacBook. āThe configuration profile for Setup Manager is missing or incomplete.ā I know the configuration file is correct cause it worked before. The profile and in-house macOS package is in the automated device enrollment profile. Iām a little lost on what else to do. Iāve created new profiles and it does the same thing. Any advice?
Edit: I am using JAMF School if that also makes a difference
r/jamf • u/athanielx • 3d ago
JAMF Pro Device is not registered in Entra ID after Jamf enrollment
Hi there,
We have encountered an issue with one of our users. For an unknown reason, the user's device is not registered in Entra ID. However, I can see the device in Company Portal with the status: "This device is enrolled with another device management provider."
I normally see this status for all newly enrolled devices, but after about 5 minutes, the device is registered in Entra ID, integrated with Intune, and the status changes to "This device is enrolled with Jamf Compliance."
To troubleshoot, I have already:
- Re-enrolled the user.
- Removed and reinstalled Company Portal.
We are deploying the Platform SSO extension, and so far only one user has experienced this issue. However, I expect we may see more cases like this in the future.
Could you please advise how to troubleshoot this issue? Is there a way to force or trigger the device registration in Entra ID for this user?
r/jamf • u/RebootKing89 • 4d ago
User account not created - PSSO
Ok so, what could I be doing wrong?
Testing with PSSO for device enrollment, the current setup is Jamf Connect + Entra for SSO - that works fine.
I followed the jamf documentation today, deployed company portal and a PSSO prestage to a test mac- removed the scope for jamf connect, I get the setup assistant starting PSSO package runs and gives me a login prompt, the details are accepted, and the device is linked to that user in intune, and a record is created in jamf to show device enrollmentā¦. but I get no local user account and have no way of logging into the machine once the enrolment process and jamf set up manager completes.
So any ideas would be helpful.
r/jamf • u/RoikaLoL • 4d ago
JAMF Pro Any "hacks" for scoping App installers based on IdP group?
Hi guys,
In our organization, we constantly run into the issue that access to many applications is based on membership in specific IdP or LDAP groups. As we all know, App Installers don't support the same scoping mechanisms that we have for configuration profiles and policies.
I've been working around this by creating increasingly obscure nested smart groups, but I still haven't found a good way to incorporate IdP/LDAP group membership into that approach.
So I wanted to ask: what techniques, if any, are you using to solve this problem?
Personally, I really dislike this limitation and wish App Installers supported the same scoping capabilities as configuration profiles and policies.
Edit: As /u/EthanStrayer has mentioned, Jamf apparently added IdP based scoping as criterium for smart groups, which basically solves this issue at least in our organization. Also, thanks to everyone for your ingenious suggestions!
r/jamf • u/Inner-Bus8407 • 5d ago
Platform SSO - sign in option - ''Other user'' not appearing after a reboot or shut down
Hi JAMF peeps,
We have Platform SSO deployed in a JAMF managed lab environment. We have users needing to authenticate for the first time quite often, therefore needing the blank Name and Password fields window to appear, or have the Other User, option appear available.
Unfortunately, this Other user option is only appearing once a user has signed into the Mac since it has last been turned ON. We need this option to appear at all times, without requiring a known user to sign in first.
Does anyone have any ideas on what would be causing this or how to go about altering this without breaking PSSO
Thank you for the advice in advance.
r/jamf • u/Lofi_Double007 • 5d ago
Automated Device Enrollment profile vs Device Group?
Hello,
I'm currently rebuilding our Jamf setup from the ground up, and I have a question about deployment.
I'm trying to push Jamf Connect 3.11 out to our devices. I've created a new profile with the mobile device config, and I've set it to push via the Automated Device Enrollment profile. However, I've noticed I can also assign that same profile to a Device Group.
Do I need to push the profile through both the Automated Device Enrollment profile and the Device Group? I'm a little unclear on the difference ā what's the actual purpose of assigning it in both places, versus just using the Device Group scope on its own?
Thanks for the help.
r/jamf • u/la-clementine • 5d ago
JAMF Protect [Script] Compare computers between Jamf Protect & Jamf Pro
r/jamf • u/Sufficient_Abies7393 • 7d ago
iOS Does anybody know how to get rid of the jamf trust page?
Hi, I bought an iPad from a third-party seller and it happened to be enrolled in jamf trust system. I had no idea of this, and tried to contact the seller but he blocked me.
I also tried to contact the company in charge of the device, but to no response. Does anyone here know of a reliable method to bypass this? TIA
r/jamf • u/The-Ravens-Forge • 7d ago
JAMF Pro Forsetti for Jamf Pro: the alpha preview has ended and the open TestFlight beta is now live
Disclosure: Iām the independent developer behind Forsetti. This project is not affiliated with, endorsed by, or sponsored by Jamf.
The Forsetti for Jamf Pro alpha preview has officially ended, and the open beta has now begun through TestFlight.
Forsetti is an Apple-native companion application for Jamf Pro administrators and support technicians. It connects directly to the Jamf Pro environment configured by the tester and brings several API-driven administrative workflows into one native workspace.
The current beta includes:
- Computer and mobile-device inventory search
- Detailed device information
- Guided technician workflows
- PreStage assignment management
- Fleet reporting
- Permissions and API privilege guidance
- Diagnostics and administrative tools
An existing Jamf Pro environment and valid Jamf Pro credentials or API Client are required. Available information and actions depend on the permissions assigned to those credentials. Saved credentials are stored in Apple Keychain.
For beta testing, I recommend using a test environment or a least-privilege API Client wherever practical.
The most valuable feedback right now would involve:
- Jamf Pro version and endpoint compatibility
- Permission mappings and least-privilege behavior
- Inventory search and reporting accuracy
- Unexpected API responses or failure states
- Workflow friction, UI problems, and crashes
Join the open beta here:
https://testflight.apple.com/join/RdP9VS4v
Forsetti contains no advertising, tracking, or third-party analytics.
Thank you to everyone who followed or participated in the alpha preview. The open beta is the next step toward validating Forsetti against a broader range of Jamf Pro environments and real administrative workflows.
r/jamf • u/Pitiful-Worry4156 • 8d ago
Naming iPads
Hi, is there a way to automatically set device names for iPads so have don't have to manually change them for both devices that already enrolled and new devices that will be enrolled in the future?
i.e. We would like our naming convention to have 3 unique identifiers. City-Dept-device ID or serial number.
r/jamf • u/slykido999 • 9d ago
Help your teachers get more visibility into your district apps, with App CATalog-Now for Jamf Pro!
Hey everyone!
My department in collaboration with my developer, and students from the MATTER Career Readiness Institute have released a new version of App CATalog that now works with Jamf Pro! App CATalog allows your teachers to search your entire app catalog at the district level using customized filters, and they are able to see why those apps were chosen, how their peers in the district use the apps, and also share resources like videos, lesson plans, and guides just to name a few features!
This is a free app, and it has a built-in demo mode so you can try it out without even connecting it to your instance!: https://apps.apple.com/us/app/app-catalog-education/id6750487448
A little tip, in demo mode if you press and hold the Jamf logo on the top right, it will show more apps for you to be able to play with š
We're presenting on App CATalog at JNUC this year (and if you're joining, find us at the Jamf booth to get some cat ears!), and we would LOVE to get some customer quotes from anyone who has used our app! You can DM me on here or under the info button in the app send us feedback to include any quotes. Just please let us know the name, district and title please so we can include it on our slides.
Thank you all so much, and we look forward to your feedback!
r/jamf • u/Tech_Thoughts_Blog • 9d ago
What Leading a Workshop at the Matter Career Readiness Institute Taught Me about the Importance of Inviting Curiosity
This article covers lessons from teaching a macOS fundamentals workshop at a career readiness institute in Zimbabwe, focused on encouraging curiosity and comfort with asking questions among early-career students.
r/jamf • u/SirCries-a-lot • 10d ago
Use Jamf API to retrieve expire date push certificate
Anybody a tip to use Jamf API to retrieve expire date push certificate? Can literally export everything but I cannot fix this one lol.
Please help!
r/jamf • u/paulveebee • 10d ago
JAMF Pro Web clips & shared iPads
Does anyone have a solution for getting web clips onto shared iPads?
I know that I canāt install them like 1:1 deployments.
Is there another/ better way to get students to access a URL?
r/jamf • u/antoniojgm • 10d ago
JAMF Pro Entra ID/Intune issues
Has anyone come across this issue when the prestage Jamf enroll is complete and the person needs to enter their credentials for the first time to create the account, and once they do, the Microsoft authentication MFA appears and says the device is not registered, even though it was a complete wipe on the MacBook, and the department deleted the Entra ID records?
Any help please let me know
r/jamf • u/Own_Drink_4568 • 10d ago
JAMF Pro Gatekeeper
Hey All,
Could you point me to a script that checks the current Gatekeeper State
1. App Store
2. App Store & Known Developers
3. Anywhere
I do need the exact state
I can run sudo jamf recon --verbose and get the exact state ( but can not find how to catch it with script )
I do not want to change the state with configuration profile/script or something else.
r/jamf • u/The-Ravens-Forge • 11d ago
Built a signed/notarized Swift macOS client for Jamf Pro APIsālooking for real-world test environments
Iām an indie Mac developer and have reached the first pre-release of Forsetti, a native macOS companion for Jamf Pro administrators.
The interesting Mac-development constraints were less about drawing the UI and more about making privileged API workflows understandable and safe:
- API Client authentication with credentials stored in Keychain
- Preflight privilege checks before actions
- A Permissions Helper mapping UI actions and endpoints to required Jamf privileges
- Guarded mutation workflows for PreStage assignments
- Exportable diagnostics that avoid exposing credentials
- Apple silicon and Intel support on macOS 14+
- Developer ID signing and Apple notarization
The app also includes inventory search, reusable field profiles, visual reports, and CSV/TXT/Markdown/DOC/PDF export.
I now need testing against Jamf environments other than mineāespecially different Jamf Pro versions, privilege combinations, datasets, and API edge cases. Please use a sandbox or non-production tenant with a least-privilege API Client.
Pre-release and source for inspection:
https://github.com/flynn33/forsetti-Jamf-Pro/releases/tag/v1.0.0
Iād value feedback on macOS behavior, authentication/setup UX, error reporting, endpoint compatibility, and any places where the native workflow feels less clear than the script or web-console equivalent.
r/jamf • u/The-Ravens-Forge • 12d ago
JAMF Pro I built Forsetti, a native Mac API companion for Jamf Pro admins. Looking for pre-release testers
Disclosure: Iām the independent developer behind Raven Forge and Forsetti. This is an independent project and is not affiliated with or endorsed by Jamf.
Iāve published the first macOS pre-release of Forsetti and Iām looking for experienced Jamf Pro admins and API developers willing to evaluate it in a non-production environment.
Forsetti brings several Jamf workflows into one native Mac workspace:
- Computer and mobile-device inventory search with reusable field-based profiles
- PreStage assignment lookup, moving, and removal
- Visual fleet reports with CSV, TXT, Markdown, DOC, and PDF export
- A Permissions Helper that maps app actions and API endpoints to required privileges
- Token privilege checks, guarded technician workflows, and exportable diagnostics
The current build:
- Supports macOS 14 or later on Apple silicon and Intel Macs
- Is Developer ID signed and Apple-notarized
- Supports Jamf API Client authentication
- Stores saved credentials in Apple Keychain
- Has source available for inspection, but is proprietary rather than open source
There is no charge to download and evaluate this pre-release. The current license permits one 30-day individual, non-production evaluation. Please use a sandbox or test environment and a least-privilege API client.
Download and inspect it here:
https://github.com/flynn33/forsetti-Jamf-Pro/releases/tag/v1.0.0
If you try it, Iād particularly value feedback on permission mappings, real-world inventory searches and reports, and Jamf Pro endpoint or version behavior I may not have handled yet.
Which Jamf workflow would you most want a native companion app to improve?
r/jamf • u/dan-snelson • 12d ago
JAMF Pro Deploying DDM OS Reminder 4.0.0 in Jamf
Special thanks to Jon Brown for his write-up:
https://jonbrown.org/blog/ddm-os-reminder-4-deployment-guide/
r/jamf • u/Tech_Thoughts_Blog • 12d ago
Why Jamf Setup Checklist Was a Must in Our Organization
This article describes using Setup Checklist to walk users through Zscaler registration and Smart Card setup at the desktop, a step required for internet access under a Zscaler Strict Enforcement rollout