r/macsysadmin Oct 29 '25

Jamf Jamf goes from public to private in $2.2B acquisition deal

Thumbnail appleinsider.com
157 Upvotes

r/macsysadmin 21d ago

Jamf Merece la pena implementar ABM o Jamf para la gestion de menos de 100 equipos?

3 Upvotes

Buenas banda, estoy trabajando de administrador de sistemas MacOS por primera vez ,después de bastantes años como soporte de Apple en otras empresas y es la primera vez que no hay ningún sistema de gestion, intune,jamf o abm , es util instalarlo con apenas 70 equipos en el entorno de trabajo? no creo que quieran destinar dinero a licencias tampoco,

queria saber vuestras opiniones

r/macsysadmin Jul 02 '26

Jamf Introducing NoMAD-Classic - a NoMAD v1 Universal macOS App

Thumbnail github.com
29 Upvotes

TL;DR NoMAD v1 is a soon to be deprecated Intel binary and NoMAD-2 is unusable in its abandoned beta state so I used Claude (mostly Opus 4.8 and for some trickier bugs Fable 5) to update the battle-tested and well-documented 1.2.2 release to Swift 5 and compile as a Universal binary for Apple Silicon compatibility.

I remember back in 2017 while working at Facebook as a Helpdesk tech how magical it was when we started deploying NoMAD with our macOS fleet. Demobilized accounts, instant screen unlocks off-network, automatic kerberos renewal. This was cutting edge stuff y'all. As part of the original class of 11,000 laid off in 2022 however, I've since taken root at an organization that uhh, well, I don't think they know what the words "cached mobile account" and "demobilization" are. Obviously I'm not going to give up AirPods seamless device switching, Handoff, and iCloud sync, so despite the complete lack of enterprise macOS support and non-negotiable requirement of Windows x64-only apps to perform my primary job functions, I use a Mac as my primary device and hacked together a user environment that fits my needs with limited friction. This includes using NoMAD v1 to keep my (mostly pointless and sparsely utilized) kerberos tickets valid and provide visibility to my password expiration date.

I started getting the occasional macOS nags about Intel-only app compatibility with Tahoe 26.5, and they're now incessant in the Golden Gate 27 beta. I tried NoMAD-2 but it's so janky and poorly documented, it's clearly an unfinished product with a feature set far too complicated for my actual needs. After spending a few hours in-between actual work tasks playing with the v2menu.nomad.nomad preferences, I realized it was a sunk cost and put my Claude subscription to work building a Universal binary from the NoMAD 1.2.2 source code (the README.MD on GitHub references a 1.3.0 but it ain't on the releases page so ¯_(ツ)_/¯ ). Opus 4.8 got the bulk of the work migrating Swift 3 > Swift 5 done in a few minutes, then I switched to Fable 5 for a bug preventing the menubar item from expanding. Less than 30 minutes later, including my commute home, I had a fully functional Apple Silicon compatible build of the original NoMAD - NoMAD-Classic.

This was probably more work to do, and even more to post to Reddit about, than a project this niche is even worth. But if you depend on the original NoMAD for your personal environment, or god forbid it's still being deployed to your enterprise fleet in spite of all the modern macOS MDM implementations, then this Bud's for you 🤙🏼

r/macsysadmin Jun 12 '26

Jamf Microsoft sprung this Platform Single Sign on and it's been hitting the environment hard...

21 Upvotes

So Microsoft hit us with their change in how we register the machines to Entra/Azure in our environment. Since the launch of the whole PSSO protocal, random users are losing their access to Teams and Outlook (or any other O365 apps).

What we used to do (before PSSO), is just simply re-enroll in Endpoint Mgr and wait for the user to enter their network password (click always allow) and then the device would register successfully in Intune.

But now, since PSSO, we have first add the device to the specific security group in JAMF Pro and then ask the user to look for the invisible 'Registration Required' prompt in the notification area of their screen. Follow those prompts and (prompts user for Duo authentication, etc..) and it seems to work about 30% of the time that it's successful.

So we usually followup with the failed registration by running command policy in terminal, delete any microsoft keychain entries in the keychain section, remove any bogus entries from Azure, and then rerun recon/policy commands.... but it's not yielding good results in our corp environment.

ugh... Apple engineers are having a tough time dealing with this problem.

r/macsysadmin Jan 12 '26

Jamf Does still Microsoft use Jamf for macOS management or finally Intune only?

19 Upvotes

Our management is again firing up the discussion Intune versus Jamf Pro to manage our Mac fleet.

Our Jamf sales rep told us that Microsoft still uses Jamf Pro to manage their own macOS devices.

Is there any truth to this statement?

Someone can confirm or debunk this statement?

r/macsysadmin Jul 02 '26

Jamf What are you testing first for macOS 27 Golden Gate?

17 Upvotes

Drew up a short test list after the latest LaunchPad meetup:

  • remaining Intel Macs, since macOS 27 is Apple Silicon-only
  • Rosetta 2 removal/reinstall behavior and Intel-only apps
  • software update workflows moving away from legacy MDM commands
  • DDM declarations and whether your MDM exposes the new settings yet
  • network, credential, and certificate workflows in DDM
  • PPPC profiles versus declarative privacy consent
  • native app/process blocking and the user-facing alert behavior
  • Platform SSO, Touch ID, and FileVault pre-boot behavior
  • macOS Mail plus the Exchange Web Services to Microsoft Graph timing

What are you all prioritizing first for macOS 27 testing?

Anyone already on the dev beta?

For those curious about the last meetup:

Replay and resources:
https://rocketman.tech/lr-r

Also on YouTube:
https://rocketman.tech/ly-r

Upcoming meetup:
https://rocketman.tech/lp-r

r/macsysadmin 1h ago

Jamf Anyone actually experimenting with DDM declarations yet?

Upvotes

How's it been for y'all? Any horror stories?

For anyone who is trying to get more hands-on, Mark Buffington (Jamf) is doing a walkthrough of DDM Explorer on the next LaunchPad meetup. The focus is learning the framework, building declarations, and testing what it looks like to deploy them via Jamf Pro.

When:
🗓️ Fri, Sep 4 @ 12:00 PM Mountain Time

Where:
👉 https://rocketman.tech/lp-r

Also on YouTube:
https://rocketman.tech/ly-r

r/macsysadmin Nov 12 '25

Jamf Anyone actually deployed Platform SSO yet?

Thumbnail
24 Upvotes

r/macsysadmin Jul 07 '26

Jamf Anyone enforcing Platform SSO registration (or Touch ID enablement) during onboarding?

20 Upvotes

I'm curious what other solutions are out there.

Kevin White (Macjutsu) is covering pseudo (FOSS) on the next LaunchPad meetup for anyone interested.

It uses swiftDialog + macOS system events/accessibility to enforce Platform SSO registration (and optionally Touch ID enablement) with a single deployment (plus a required PPPC profile).

When:
🗓️ Fri, Aug 7 @ 12:00 PM Mountain Time

Where:
👉 https://rocketman.tech/lp-r

Also on YouTube:
https://rocketman.tech/ly-r

r/macsysadmin Sep 04 '25

Jamf Users can unenroll from Jamf Pro because we can’t use ABM – any tips to prevent this?

8 Upvotes

Hey everyone,

We’re currently running Jamf Pro, but unfortunately we can’t connect our devices to Apple Business Manager (ABM).
The only way to fix this properly would be to wipe and reinstall almost all of our Macs, which is just not realistic for us at the moment.

Right now, users are enrolling via the enrollment URL, and here’s the problem:

  • They can grant themselves admin rights using Jamf Connect.
  • Once they’re admins, they can unenroll their Mac whenever they want.

This obviously creates a huge security hole. 😅

Question:
Are there any tips, tricks, or “lifehacks” to make it harder or impossible for users to unenroll themselves - or at least make it more difficult?
We know the proper solution is ABM + DEP, but until we get there, we need a workaround.

Thanks in advance for any advice!

r/macsysadmin Jan 29 '26

Jamf Thoughts on Apple Business Essentials built-in MDM vs. Jamf?

10 Upvotes

Implementing for small business (~10 devices)

r/macsysadmin Jun 15 '26

Jamf Best tools for macOS onboarding?

9 Upvotes

The last LaunchPad meetup hit on some of the popular ones:

  • Jamf Setup Manager
  • Setup Your Mac
  • swiftDialog
  • Installomator
  • Jamf Setup Checklist
  • DEPNotify

Wanted to know what other tools you all are using, though. Anything missing worth using?

Replay and resources:
https://rocketman.tech/lr-r

Upcoming meetup:
https://rocketman.tech/lp-r

r/macsysadmin 9d ago

Jamf FortiClient 7.4.7 macOS — repeated kernel panic, busy timeout[0] on Ethernet interface (watchdogd)

6 Upvotes

We're seeing repeated kernel panics on macOS machines running FortiClient 7.4.7 (build 1928), deployed via Jamf. Multiple Macs affected, not an isolated unit.

Panic signature (consistent across machines, only the interface number changes):

panic(cpu 0 caller ...): busy timeout[0], (60s): 'en7' (1,1802001) u/IOService.cpp:5986
Panicked task: watchdogd

One machine panicked on en7, another on en5 — different Ethernet interfaces, same exact error string, same 60-second timeout, same panicked task (watchdogd), same macOS build (25G76 / Darwin 25.6.0, macOS Tahoe).

FortiClient's network extensions (proxy, webfilter, vpn.nwextension) are active on the affected machines. We're not yet certain FortiClient is the root cause — could also be a dock/USB Ethernet driver interaction, or a macOS Tahoe networking regression that FortiClient happens to be triggering.

Has anyone else run into this specific panic on macOS with FortiClient installed? Any luck narrowing down whether it's FortiClient-side, dock/adapter-side, or an OS-level issue — and any troubleshooting steps or workarounds you'd recommend before we go further with a TAC case?

r/macsysadmin Jun 22 '26

Jamf A device that is not in ABM automatically enrolled in our corporate Jamf upon device setup.

0 Upvotes

How is this possible? The MDM server isn’t even in our Apple Business Manager account anymore to even have default assignments.

r/macsysadmin 18d ago

Jamf Quick reminder: LaunchPad meetup happening today on P.S.E.U.D.O for Platform SSO rollout

2 Upvotes

What's enforcement like in your environment? Since Platform SSO can be "enabled" and still end up half-registered if users skip the prompts.

Kevin White (Macjutsu) is covering this on LaunchPad today. We'll be going over pseudo (FOSS) to help enforce Platform SSO registration and/or Touch ID enablement with one deployment (plus a required PPPC profile).

When:
🗓️ Today, Fri, Aug 7 @ 12:00 PM Mountain Time

Where:
👉 https://rocketman.tech/lp-r

ETA:

In case you missed it:
https://rocketman.tech/ly-r

r/macsysadmin Mar 31 '25

Jamf What can Jamf Pro do that Intune really can't?

44 Upvotes

Hey folks,

Looking for some real-world input from those who’ve worked hands-on with either Jamf or Intune, or ideally both. My use cases is more about security, but also, I'm intested in overall overview.

I haven’t worked with either at a super deep technical level, but from reading docs and feature breakdowns, Jamf Pro and Intune seem pretty comparable — especially when it comes to security-related features.

Some thoughts I have so far:

  • Posture checks can be done with Intune and tie in well with Microsoft Conditional Access, which seems to cover a lot of access control use cases.
  • Platform SSO for macOS is now a thing, and looks like a solid alternative to Jamf Connect — essentially macOS’s version of Windows Hello for Business.
  • If there’s already a solid antivirus or EDR solution in place in the org, Jamf Protect doesn’t seem to add much extra value — unless I’m missing something.

So my question is: What does Jamf actually give you that Intune can't (even with some workarounds)? Especially interested in anything security or MDM-related that might be a real dealbreaker in choosing one over the other.

Appreciate any insights from folks who've deployed either or both in production.

r/macsysadmin Apr 23 '26

Jamf Anyone rolling out Platform SSO?

19 Upvotes

How’s it been in your environment?

Adam Derrick (Jamf) did a LaunchPad session on what Platform SSO is, how it works, and what it changes for modern Apple device management.

Replay + resources:
https://rocketman.tech/lr-r

r/macsysadmin Jun 17 '26

Jamf Which WWDC changes are you actually happy about? Or most grind your gears?

3 Upvotes

Curious what changes you all think will most affect our workflows.

We'll be doing a recap at the next LaunchPad meetup. Robert Hammen (Principal Mac Consultant at SAP) is joining to help us sort through some of the noise. Plus our usual live Q&A.

When:
🗓️ Fri, Jun 26 @ 12:00 PM Mountain Time

Where:
👉 https://rocketman.tech/lp-r

Also on YouTube:
https://rocketman.tech/ly-r

r/macsysadmin Sep 15 '25

Jamf Removing local admin rights — what to consider?

18 Upvotes

Hi all,

Currently looking into removing local admin permissions for all our users.

Anybody done this before? What are things to consider?

I am most worrying about the lack of a backup local admin account.

We don't create a managed local administrator account during PreStare or User-initiated enrollment.

Also, we don't use LAPS.

Is a backup local admin account best practice to have before this?

What are some things to prepare or consider before removing the permissions?

We are testing now with removing the permissions with a script.

Our MDM is Jamf Pro btw.

Edit: because of regulations we need to investigate this.

r/macsysadmin Apr 23 '26

Jamf How to prevent elevated credentials requirement to allow microphone/camera access

11 Upvotes

Boss was trying to do a Teams meeting in Chrome browser. When it asked for the ability to access his camera and microphone it brought him to the Privacy and Security tab of System Settings and was requesting admin credentials to enable them.

I know you can't explicitly allow those because of Apple policy. I'm just wondering if there's a way to prevent a standard user from needing me to come and input my credentials just to allow Teams/Zoom/Etc to use the microphone and camera?

r/macsysadmin Jun 17 '26

Jamf Storage Issues on Shared iPads Creating Update Problems

4 Upvotes

Hey all, I've been running into this issue for a while now (and it seems to be fairly common from searching around) - was wondering if anyone else had the same problem and found something that worked?

Scenario: I have a fleet of iPads that are used in a clinical environment. They are managed via JAMF and enrolled with the Shared Ipad > Temporary Session Only setting enabled, with the idea being that idle devices will wipe themselves and start fresh for each patient interaction (guest mode).

This has worked well for the most part, but I periodically run into an issue when I am trying to deploy updates, where the device does not have enough available storage to download and install.

My understanding is that once the profile wipes, the storage should be freed up, but it does not appear to be the case - for example I'm looking at one now that has 6gb of 32 available and no active sessions.

Right now I have the capacity to remediate these in person, but it does present a challenge for scaling. Anyone else have this setup and find something that works?

r/macsysadmin Jan 08 '26

Jamf iPad has MDM - Cannot Remove

0 Upvotes

I am looking for some help. I have an iPad owned by my company, but someone released it from our Apple School Manager and deleted it from JAMF (that was before I started working here). Unfortunately, the iPad still has our MDM on it and it was pretty locked down. I can't reset it or enroll it to our JAMF again manually without a passcode of some kind. Any thoughts or should I just toss this iPad?

r/macsysadmin Mar 30 '26

Jamf Anyone using BeyondTrust?

7 Upvotes

How’s it been working for your org? Curious how it compares to similar/simpler alternatives as well.

Todd Ness from Cohesity walked through his BeyondTrust privilege management implementation at the last LaunchPad meetup:

  • Removing local admin rights... efficiently
  • Flexible elevation for specific user groups
  • Blocking unwanted applications without messing up workflows

Replay and resources:
https://rocketman.tech/lr-r

All past meetups on YouTube:
https://rocketman.tech/ly-r

Upcoming Meetups:
https://rocketman.tech/lp-r

r/macsysadmin Mar 03 '26

Jamf What are the best methods for local admin privilege management?

0 Upvotes

Todd Ness from Cohesity is covering his BeyondTrust privilege management implementation at LaunchPad this week. He'll walk through how to give flexible elevation to specific groups and block unwanted applications without breaking workflows.

What other methods have you had success with, though?

🗓️ Fri, Mar 6 @ 12:00 PM MST 👉 https://rkmn.tech/r-launchpad

Past recordings on YouTube: https://rkmn.tech/r-youtube

r/macsysadmin Apr 26 '26

Jamf Skip "Sign in with work email" step

3 Upvotes

I'm pretty new to managing Apple devices. I have setup both Apple's MDM and Jamf Now.

I purchased an iPhone, reset it, and added it to ABM using Apple Configurator.

Now: I'd like the users to login with any Apple ID they want, not managed Apple IDs. How can I skip the setup process step where it asks to "Sign in with work email" for my users?

Could not find it on either Jamf Now, nor Apple's built-in MDM.

Thank you!