Get Support
Recently active
Some apps supposedly have built-in functions which are supposed to report whether the app itself believes it has full disk access and will then either indicate this or go straight to a process of requesting the user grant such access.The main app I am having an issue with is called Scribe and is an app which automates installing updated corporate email signatures for Apple Mail on a Mac.I have previously created a PPPC Configuration Profile in Jamf Pro and verified this has been successfully pushed out to my Mac. System Preferences → Privacy & Security does show an entry saying this has been configured via a Profile and is enabled, i.e. is clicked to the right and is ‘blue’.It should be noted that my own experience is that the TCC database if queried, only lists apps that have been enabled locally and not apps enabled via a Configuration Profile. In this case Scribe is listed in the TCC database and whilst I cannot remember for certain, it is highly likely I did enable it manually
Hi folks!Here’s a nice little quality-of-life improvement released just yesterday.If you’re a Jamf Cloud customer and want to change the 20-minute timeout period for Jamf Pro, now you can manage it by integrating with Jamf Account — using just a Jamf ID (identity provider not required). You can extend the timeout up to 24 hours.Basic instructions:Log in to Jamf Account with a Jamf ID associated with your organization. The organization must have a Jamf Pro instance.Click Profile. Click Security. Adjust the settings for Inactivity timeout (up to 1440 minutes or 24 hours) Jamf Account > Profile > Security > Session Options Log in to Jamf Pro and click Settings. Click Single sign-on. Enable SSO Authentication and save. Copy your failover URL, and keep it available. Jamf Pro > Settings > Single sign-on Ensure you have a Jamf Pro account whose email matches your Jamf ID. Jamf Pro > Settings > User accounts and groups Open a private browser window or a different web
Hi guys, I’m the IT guy in my school and have been encountering this issue that happens to 2 of my IT Colleagues. Their classes disappear in JamF Teacher from time to time. However on my Teacher account that I am using for testing, it stays. Not too sure what is the cause of this. I have been retagging them back to their classes and this has put a hold for us to integrate in our School. Anyone else has encountered this before and has a solution?
So I have a strange notifications that only pop up If you start the SS.app This is standard but when you start the SS.app then the error appear in Notifications. Clear dont work also the old sudo rm -R ~/Library/Application\ Support/com.jamfsoftware.selfservice.mac/Dont work. When you close the App the number 1 in the dock also disappear. If I login with another user there is no error so seems account related, Anyone idea how to fix this?thanks
Hello again. I'm seeing a lot of older posts about this that are not relevant to Sonoma; most posts are from years ago. This is a 2 part question: I want to upload a Corporate image to be used for Desktop Wallpaper. I'll need this to be built into the "image" we use for MacBooks.2nd question, once picture is installed in the right folder, all I need to do is use the the "Lock Desktop Picture" setting in Restrictions and add the file path, correct? Any help is greatly appreciated. JAMF ProSonoma 14.4.1MacBook Pro
My device is stuck at DeviceConfigured. I have been having this problem more often. Everything on the back end in JAMF looks fine, but on the front end it just says "Awaiting final configuration”. This problem will persist for a long time. Does this happen to anyone else? Anyone have any ideas on how to fix this? It does not have any network issues. I tried pushing this command through using update inventory. I wiped it and restarted it multiple times.
Hi,I really hope that someone here can help me with this. We have had this error for a few weeks now and I am getting a little desperate here. Jamf and Apple support have not been able to provide a solution either.Some of our Macs are getting the “Enrolling with management server failed. An unexpected error has occurred <HTTPStatus:502>”. I know that usually means communication issues, but with those Macs that cannot be the case because I can enroll different Macs under the exact same circumstances without any problems. Same time, same cable, same server, everything is the same. On the other hand those Macs always have that problem and it wont go away no matter what I do. I have already tried enrolling via a different network, moving them to a different site, enrolling them via a different PreStage enrollment and much more. Nothing worked. And really bad part is that this issue is spreading. At first only a hand full of my Macs were affected, but now almost 50% of the Macs I try
Hey Jamf Nation! 👋 🎤 Free live workshop: Keynote tips and tricks for your best presentation yet.👉🏼 May 27. Register now → https://jamf.it/JamfNationEvents Here's the deal. 👇Whether you just found out you're speaking at JNUC (congratulations!) or you simply want to level up your slide game, this one's for you. Better slides are useful everywhere - all-hands, team meetings, client calls, that side project you keep meaning to polish up. We're bringing in Rob Potvin (@rob_potvin) for 45 minutes of practical, no-fluff Keynote technique. The kind of session where you leave with things you can use the same day. You'll walk away knowing:• How to shape your slides so they're clear and compelling - not just full of content• How to draw the audience's eye exactly where you want it• How to use Keynote tricks like Magic Move so your transitions feel intentional, not showy• Where to source icons and imagery that look polished without a design budget• How fonts, spacing and contrast affect wheth
I am suddenly having an issue with JAMF deployed apps. I’m only seeing the issue happening on 3 apps that are paid for. The apps deploy properly to the iPads but are now prompting the user to sign in to an Apple Account whenever the app is opened on the iPad. If they hit cancel it allows them to use the app but when they close out of it again, it will prompt the sign in again.Our VPP token in JAMF is not expired, the location is correct, Managed distribution for the app hasn’t changed since it previously been setup and working and we have enough licenses and this issue only suddenly started happening. I’m not seeing it on the free apps. Any feedback or direction would be great, thanks!
I’m curious to know how other organizations are handling OS updates. Not so much in terms of applying them but more so in terms of testing. How long do you typically defer updates in your environment? What is your testing methodology and criteria for deployment?
Hey folks! I am looking for some real-world architecture advice from people managing more segmented Jamf environments.In previous companies, my Jamf setup was relatively straightforward:- one main device type,- mostly shared configurations,- common app stack,- unified policies and profiles.Now I’m building a more segmented environment and trying to design it the “right” way before things scale too much.We’ll likely have multiple categories of macOS devices with different requirements, for example:- standard daily-use employee Macs,- security/guard team devices,- travel/restricted devices,- possibly more specialized fleets later.Each category may require:- different app sets,- different restrictions,- different onboarding flows,- different compliance/security baselines,- different Self Service experiences.I’m currently building around:- PreStage Enrollment,- Jamf Setup Manager,- smart groups,- scoped policies/profiles,The thing I’m trying to figure out is the long-term architecture stra
Running into these messages when trying to log into Self Service+ 2.21.0. No changes have been made in Okta or in Jamf. Its also saying my password isn out of sync when no changes have been made there either. Wondering if this is a bug considering 2.21 was just released 3 days ago and we just discovered it today.
Hi All, Is anyone else having issues with enrolling MacBooks in their Jamf Pro environments? Every time we've tried to enroll a new MacBook Pro this week we're getting hit with "Enrolling with management server failed. Unexpected error (MDMResponseStatus:502)". Jamf Support had me try a few things like trying a different Prestage Enrollment Profile or even removing some packages from Prestage but no luck. Any help would be appreciated. Thanks
Hello there, Im a bit rusty so any help would be appreciated.Im writing a script in jamf pro which uses the computers-inventory API to grab info on a specific computer. So far I have thiscomputerID=$(sudo jamf recon | grep computer_id | cut -f2 -d '>' | cut -f1 -d'<')computerInventory=$(curl -s "${apiURL}/api/v3/computers-inventory/${computerID}" -H "Accept: application/json" -H "Authorization: Bearer ${apiBearerToken}" -X GET)#EXTRACT managementID out of computerInventoryI have no idea how to extract the managementID field out of computerInventory. Im trying to avoid jq cause I dont want to deploy that to all the macs in the fleet.Any help would be amazing.
I'm looking for a way to send the 'wipe computer' command in bulk to our Labs so that they can be refreshed at the end of semester.I gather this will require use of an API client and secret.I'm wondering if anyone has come across a script that can do this?
There are hundreds if not thousands of Terraform examples and walk throughs on the internet today. Most of them start in a clean environment. They assume a brand new account. No history. No surprises.But that’s rarely the situation most of us inherit.More often, we’re working on something that’s been evolving for years:Resources created manually in a GUI Naming conventions that shifted over time Temporary fixes that became permanent Configurations that “just work,” but nobody is entirely sure whyApplying Infrastructure as Code (IaC) using Terraform in an existing, already-provisioned environment is often called Brownfield Terraform.You’re not building from scratch.You’re (very carefully) translating the current reality into code. What Does Success Actually Look Like?Before getting into mechanics, it helps to define the goal. In a brownfield migration, success is not:Rebuilding everything Refactoring immediately “Cleaning it up” on day oneSuccess is simpler. You run: terraform planAnd T
Everytime I try to delete an old smart group or static group that happens to be in scope of multiple policies I then have to go to each policy and remove it from scope first and then I'm able to delete it.There's gotta be a better way to do this.Is there a feature request or something that will allow me to delete it without having to remove it from a bunch of policies first?It's a big waste of time. Add a checkbox for the user to select to allow removal from any policy the group is in.
• iOS - 50+ CVEs patched• macOS - 60+ CVEs patched• link: https://support.apple.com/en-us/100100
Can't seem to find an answer to this so I suspect that there isn't (a satisfactory) one...Security and Privacy best practice says to disable iOS notification previews, especially when a device is locked. This is what I want to set using Jamf Pro.I know I can set Notification preferences per app, but the setting in the screenshot is global and can be set on the device, but is there a way to configure this device-wide setting with Jamf Pro?There is a specific Jamf article on this, from the UK NCSC (National Cyber Security Centre), which refers to this specifically, but does not reveal how to achieve this exactly.https://www.jamf.com/blog/updated-device-security-guidance-from-the-uks-national-cyber-security-centre/This is the relevant paragraph: Hopefully I'm just missing something 🙏
Hello,I’m currently using Lost Mode in Jamf Pro to disable iPads / iPhones that are not returned to the IT Helpdesk.Occasionally, when these devices are returned, they have either run out of battery or have been restarted while still in Lost Mode. After rebooting, the devices are locked down; No WiFi, Ethernet (with working adaptor) or not connecting to Mac via Apple Configurator.Because the device is still in Lost Mode, the passcode cannot be entered, and the device is unable to check in with Jamf to receive the “Disable Lost Mode” command.This leaves the device stuck in Lost Mode unless it is restored via Recovery Mode.Has anyone found a way to:Ensure devices reconnect to a network after reboot while in Lost Mode, or Remove Lost Mode without requiring a full restore?For context:Devices are supervised and managed via Jamf Pro Enrolled via Automated Device Enrolment No cellular connectivity for iPads (Wi-Fi only devices)Any advice or best practices would be greatly appreciated.Thanks i
Hello, For software updates and the type of install action, does “Download and Install” reboot the computer automatically or will it allow the user to restart on their own to complete the installation?If it does reboot automatically, how is it different from the option to “Download, Install, Restart”?
I have a script to lock a Mac via API. No issues with that. It works very reliably.I would like to use this script it to lock a Mac system when it has not updated inventory in over X days. Think of a Mac that has been shoved in a desk drawer for a while. This would force the user to contact the help desk to get it unlocked and explain why it has not bee online.This is an easy enough policy and smart group to build. Last Inventory Update more than x days ago.But testing is a pain in the butt. I have to wait 24 hours for “Last Inventory Update” to get to at least 1 day effectively test the policy.Anyone know of a way to change “Last Inventory Update”?
Looking for some guidance with Jamf Pro - PreStage Enrollment and FileVault.The issue: In PreStage, we pre-create and hide a local admin account. During setup, the workflow prompts for end-user account creation. FileVault is enabled immediately after the user account is created and the user logs in for the first time. As a result, only the end user is added to FileVault , the local admin account is left out of the FileVault enabled users list. I haven’t found a way to ensure the local admin is automatically included in FV2 during enrollment.Should this be configured differently in PreStage, or would scripting the local admin addition after FileVault is enabled be the right approach?
Up until Sonoma I was using this script https://community.jamf.com/t5/jamf-pro/wifi-switching-script/m-p/139275/highlight/true#M128353 But now I can no longer find something that will work. This was handy because it only worked when the school SSIDs were available.Does anyone have something they use in a school environment? Thanks in AdvanceMatt
All,We just signed up for Jamf pro and I am in the naming instance area during set up. Does it matter what I name this such as the company name? I am new to the setup area so just making sure as its not changeable afterwards.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!