r/jamf

▲ 19 r/jamf+1 crossposts

Coming from Intune, how hard is it to ramp up on Jamf?

My current environment is Windows only and managed in Intune. Leadership wants to start supporting MacBooks and is planning to use Jamf. I have experience bringing Macs into Intune, but I have never used Jamf. They also mentioned possibly Kandji. How hard is it to ramp up on Jamf Pro if you are already coming from an Intune background?

reddit.com
u/SeanTechGuy — 1 day ago
▲ 30 r/jamf+2 crossposts

Jamf vs Mosyle vs Intune-only for a 28-Mac consulting firm — genuinely stuck, would love real-world input

We're a small ERP/SAP consulting firm — 43 total devices (28 Mac, 15 Windows). All Apple Silicon (M1 through M5), all running macOS 26.5.2. Microsoft 365 Business Premium with Intune. Entra ID joined, Conditional Access enforced with MFA. Leadership is leaning toward Windows standardization long-term, but no final decision has been made on the Mac fleet We're committing to roughly a 1-year Mac MDM investment while we evaluate the long-term direction. No new Mac purchases in the interim, but we're not forcing replacements either.

I've spent the last several weeks doing a genuine hands-on evaluation of all three options — not just demos, actually building out each platform and hitting real walls. Here's what I found.

What's working fine in Intune for Mac:

  • ADE/zero-touch enrollment
  • PPPC profiles, Defender, compliance policies
  • Conditional Access feeding correctly from Intune compliance status
  • FileVault key escrow
  • Await final configuration

The real problems I hit with Intune on Mac — all firsthand, not theoretical:

1. Platform SSO / one-password login is broken under MFA Password mode completely fails when MFA is enforced — which it is in our environment. Tested this extensively across multiple wipes. Secure Enclave mode works with MFA but gives you Touch ID-first, not "type your Microsoft password." Users end up with two passwords that drift out of sync. When the M365 password changes, the Mac local password doesn't update reliably.

2. Local admin password (LAPS) desync on Apple Silicon The admin password Intune shows and the password actually on the device go out of sync randomly. This has happened on multiple machines. Root cause appears to be the Secure Token limitation, Intune's managed admin account doesn't hold a Secure Token, so password rotation can break. Causes "admin password not working" support tickets that take real time to resolve.

3. No automatic third-party app patching Chrome, Claude Desktop, and any non-Microsoft app requires manual repackaging to update. Users get admin prompts for updates and call IT. This was the original trigger for the whole evaluation.

4. No privilege elevation on Mac EPM is Windows-only. Confirmed with Microsoft documentation, the June 2026 EPM updates did NOT add macOS support despite what some sources claim. Standard users needing to install or update certain apps require IT involvement every time.

5. No scheduled recurring restarts No native UI, requires custom shell scripts checking uptime. Manageable but not clean.

Given what I have had issues with thusfar, which MDM would you recommend. Ive stood up instances on quite a few platforms, Mosyle, Jamf, Intune and IRU. Iru is out of budget for 30 Mac devices with EDR and Vulnerability protections since they have a 50 device minimum (although it was my pick). What would you recommend I chose?

My specific questions for the community:

  1. For those running Jamf or Mosyle alongside Intune for a mixed fleet: is the operational overhead of two MDMs actually a problem at this scale, or is it manageable?
  2. Has anyone gotten Platform SSO with Microsoft Entra to work reliably on Apple Silicon with MFA enforced? Which authentication method and which MDM? This is my biggest unsolved problem.
  3. Anyone using Mosyle specifically, does their App Catalog actually solve the third-party patching problem cleanly, or does it still require manual intervention?
  4. Has the LAPS/Secure Token desync issue on Apple Silicon been resolved in any MDM, or is it a fundamental Apple limitation regardless of platform?
  5. For those with compliance obligations (SOC2 specifically) how are you handling vulnerability management and EDR on Mac? Is anyone using Jamf Protect or Mosyle Fuse for this and how does it compare to Defender for Endpoint on Windows in terms of visibility and remediation depth?

Happy to answer any questions about our setup. Genuinely trying to make the right call here rather than just go with the vendor who showed up most persistently.

reddit.com
u/jaylenabc — 2 days ago
▲ 3 r/jamf

App installation stuck in pending status

On Friday, we deployed a little over 100 iPad to students.
The iPads have been assigned three different apps via a group membership. For some students, some apps are stuck in pending status. For the most part that that is good notes, for some, it might be a different or an additional app.

We have enough licenses, so that should not be an issue. The iPads have been connected to different Wi-Fi networks over the weekend, so that should not be the cause.

I don’t know what the cause of the issue is and since there is no button for me to re-deploy the app, like it is the case when an installation fails, I am not sure what the right way to go forward is.
Un assign the app and then reassign it?

Has anyone had this issue before?

reddit.com
u/No-Complaint-8475 — 3 days ago
▲ 6 r/jamf+1 crossposts

Transitioning from Windows to macOS Packaging? Here’s everything you need to know about .app, .pkg, and TCC

Hey everyone,

​If you are coming from a Windows administration background and starting to manage or package software for macOS, the shift in architecture can be confusing. Concepts like the Windows Registry, .msi installers, and PowerShell don't translate 1:1 to macOS .app bundles, Property Lists (.plist), and Zsh scripting.

​I put together a video breaking down the core architectural differences between Windows and macOS application packaging in simple, high-level terms.

​Key Topics Covered:

​Installers & Bundles: .msi / .exe vs .app directory structures and .pkg flat installers.

​Configurations: How macOS replaces the Windows Registry with Property Lists (.plist).

​File System Layouts: Program Files & AppData vs /Applications and ~/Library.

​Scripting: Moving from PowerShell/VBScript to native Zsh and Bash scripts (preinstall / postinstall).

​Security Layer: Overview of Code Signing, Notarization, Gatekeeper, and TCC/PPPC permissions.

​Whether you're deploying via Jamf Pro, Microsoft Intune, or Kandji, understanding these fundamentals makes packaging much cleaner.

​Would love to hear how you all handled the transition from Windows to Mac management! What Mac app gave you the most trouble when you first started packaging? Drop your requests below if there's a specific app you'd like to see packaged in a future guide.

youtu.be
u/Weary_Bumblebee_4286 — 4 days ago
▲ 3 r/jamf

Packaging and Deploying Photoshop 27.9.1

Photoshop has been failing to deploy and I’m not sure why. The raw installer works and I get it directly from Adobe Console but after running it through composer the output package fails to install. Has anyone had similar issues or were able to fix through shell?

reddit.com
u/SEK23_ — 7 days ago
▲ 2 r/jamf

Experience with JAMF VPN

IT manager here. Our team is proposing we use Jamf's VPN offering...and we've been struggling to get it running (suspected network config issues).

Any folks on here using Jamf VPN?

Any good stories/results?

I can't seem to find anyone talking about direct experience with it.

reddit.com
u/Stpstpstp — 6 days ago
▲ 4 r/jamf

Static Groups Vs Smart Groups

Do you use static groups or smart groups? Is there best practice for this? In our Jamf instance there are multiple admins and one prefers static groups over the other and vice versa so as you can imagine there are groups everywhere. Any tips on how to standardize usage so we can clean up this mess? Lol

reddit.com
u/Pitiful-Worry4156 — 8 days ago
▲ 1 r/jamf

Inventory Preload

Hey y'all, anyone use inventory preload here or are there better alternatives? What's your process in adding new computers and device? TIA

reddit.com
u/Pitiful-Worry4156 — 8 days ago
▲ 6 r/jamf

Preparing iPads using Apple Configurator 2

Hello all. Hope someone can maybe sanity check or assist me here. Ill tryyy to keep it short.

Goal: Set up iPads already in Apple School Manager and assigned MDM using Apple Configurator 2. Just need them to enroll to JAMF, skip steps.

Issue: I am using a Wi-Fi profile I created specifically for enrollment so it can activate and enroll to JAMF. In JAMF I have profiles scoped to apply automatically upon enrollment. Problem is in AC2 when I apply my Automatic blueprint it gives me and error that the MDM profile exists and if I want to skip or cancel. I hit skip and all the configs go through but it doesnt skip all the setup windows and then an error saying Erase and Start over or Partial setup. Ive been making due with these errors and it pulls all the configs.

How can I avoid this error? Does anyone have experience using the shared internet option via USB-C? Thats my next try to avoid a profile conflicting upon enrollment. I use a MacMini to enroll FYI.

Any help or guidance on this portion just the wifi profile.

Ah I also forgot the wifi the iPads use is a cert based wifi that obviously is applied once enrolled so I dont need the enrollment wifi I made anymore after.

reddit.com
u/sohk81 — 8 days ago
▲ 4 r/jamf

Advice on garage band

How can I work around garage band prompting for admin user and password when users are attempting to install loops / sounds. Anyone deal with this ?

reddit.com
u/Signal_Beach — 8 days ago
▲ 6 r/jamf

JAMF 200 Requirements

Hi,

I'm about to take the Jamf 200 course and in the requirements an iPad is needed. Since all my iPads are in ABM, I was wondering if an iPhone was enough for the course ?

Thanks

reddit.com
u/Substantial-Motor-21 — 10 days ago
▲ 6 r/jamf

Icloud Login

Hi everyone, I work for a school who use jamf school on ipad 10th gens and I apologise for any incorrect terminology as I was not the the one who installed the management software.

We've had barely any problems however a student recently reached out to me saying he had accidentally managed to log in to his own personal icloud however he still has all the same ipad restrictions as though he was still logged into the icloud we had originally set up on the ipads. I was wondering if he could do anything or bypass the management if so how and what we could do to stop it?

And if it is necessary to try and log him out of his own personal icloud and try to log into the original icloud we logged into.

Thanks in advance

reddit.com
u/Most_Passenger2800 — 10 days ago
▲ 0 r/jamf

Need help with few of the configurations in Jamf pro.

  1. I need help with best and easy way to make pkg from dmg / app Or installed app in a laptop. Any guid Or kb works for me. ..

  2. is there any way to control browsers( safari, firefox, brave) from jamf?

  3. is there any way to force user data backup in one drive or google drive using authorized email domain.

Here is few things I want to share: our set up is Mac users use entra id as I AM for jamf login and we are using jamf connect for that. So if we can block all other login domain s in jamf in onedrive. And force user to auto backup all system other than os, then IT will have a headache free solution or so i thought.

In fact it would be great of we can use jamf connect login to authenticate the one drive, that would be best.

Thanks in advance, it's a concept project that I am thinking of. If possible or if I can fond any out line or if some one already implemented some thing similar and share a roadmap or ideas , it will be great.

Thanks in advance, 🙏

reddit.com
u/goglusifer — 9 days ago
▲ 6 r/jamf

Deploy latest version at enrollment, but manage updates ourselves after that, how are people doing this?

We deploy an app via a Jamf Policy (pkg) that runs once a computer enrolls. Problem: the app updates constantly, so our uploaded package goes stale fast, and re-uploading a new pkg every release isn't sustainable.

Jamf's auto-patching (App Installers) would keep it current, but it also auto-updates the app across our whole fleet, which we don't want. We want to control update timing ourselves.

What we need:

  1. At enrollment, always install whatever's currently the latest version, no manually maintained package.
  2. After that, no self-updating in the background. We push updates ourselves, on our own schedule.

We've tried pointing installs at the vendor's "always current" download URL, disabling the built-in auto-updater via a config profile, and scripting our own update-push (mixed reliability so far, now looking at Installomator for that part).

Is this the standard approach or is there a cleaner way orgs handle this in Jamf?

reddit.com
u/Kcamyo — 14 days ago
▲ 10 r/jamf

Device registers in Entra via PSSO/WPJ, but never flips Compliant

Hey everyone. Having a head scratcher with M365 Conditional Access device compliance for our Macs, and looking to see if anyone has run into this specific behavior or found a fix.

The Issue
When registering a Mac for M365 Conditional Access, whether using legacy Workplace Join (WPJ) or the new Platform SSO with Secure Enclave, the registration completes and the device object appears in Entra. However, Entra never flips the device to Compliant. Users are stuck at the "Set up your device to get access" prompt on their device.
I was able to replicate the issue on my test Mac, so it's not endpoint specific.

Environment & Setup
MDM: JAMF Pro

Integration: Partner Device Management / JAMF Device Compliance (Cloud Connector)

Directory / Auth: Okta LDAP

Auth Methods Tested: Platform SSO (Secure Enclave) & Legacy WPJ (Company Portal)

OS: macOS 26.x

SSO Extension: Single Sign-On Extension payload (com.microsoft.CompanyPortalMac.ssoextension) deployed via JAMF

Compliance Criteria (Verified Met on Device)
1. CrowdStrike Falcon: Installed & running
2. FileVault: Enabled
3 JAMF Check-In: Active & checked in within 30 days (device shows compliant in JAMF Pro)

What We've Tested / Verified So Far
1. Fresh Build Testing: Provisioned a brand new device build via JAMF Setup Manager, but immediately hit the exact same issue upon initial enrollment and M365 registration
2. Intune Partner Connector: Checked Intune Admin Center > Partner compliance management. The JAMF Device Compliance connector status shows Active. The "Last successful sync" timestamp was stuck earlier today 8:30a, but eventually refreshed at 4:30p, yet the devices still won't flip to compliant in Entra

Questions / Where I'm Stuck

  1. Has anyone seen an issue where the JAMF to Intune Cloud Connector reports Active and updates its sync timestamp, but fails to push/map individual device compliance states
  2. Short of disconnecting/re-saving the Intune Integration settings in JAMF Pro (trying to avoid impacting production if possible), is there a way to force JAMF to re-evaluate and push the compliance payload for a specific device?

Appreciate any insights or troubleshooting ideas.

Thank you

*** EDIT / RESOLVED: Root Cause Found ***

Huge thanks to everyone who chimed in with ideas and troubleshooting steps

Turns out the issue wasn't a JAMF sync failure or a PSSO bug, it was triggered by a recent Microsoft Entra change rolling out (Message Center Post MC1326253)

What Happened:
Starting in June, Microsoft rolled out an enforcement change where Conditional Access policies scoped to the "Register security information" user action now evaluate during macOS Platform SSO registration (and Windows Hello for Business enrollment)

In our tenant, we had a CA policy targeting Register security information with a Grant control requiring "Device must be marked as compliant."

This created a Catch-22:
The user attempts to register Platform SSO to establish device identity and compliance.
Entra evaluates the Conditional Access policy during PSSO setup.
Because the device isn't compliant yet, Entra blocks the PSSO registration flow.
PSSO fails to finish registering, JAMF never receives the completion signal to push the attestation payload, and the Mac stays stuck as non-compliant in Entra

The Fix:
Met with JAMF support and they shared the following support articles

https://learn.jamf.com/r/en-US/jamf-connect-documentation-current/Creating\_a\_Jamf\_Connect\_Configuration\_with\_Conditional\_Access

https://developer.jamf.com/jamf-pro/reference/get\_v1-conditional-access-device-compliance-information-computer-deviceid

If anyone else runs into sudden PSSO/WPJ registration blocks on new builds or user re-registrations, definitely check your Conditional Access policies targeting Register security information

:Microsoft Reference Articles
https://techcommunity.microsoft.com/blog/microsoft-entra-blog/upcoming-conditional-access-change-improved-enforcement-for-policies-with-resour/4488925

https://admin.cloud.microsoft/?#/MessageCenter/:/messages/MC1326253

https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1448379

reddit.com
u/keynoto — 13 days ago