Get Support
Recently active
I finally got around to getting my repo created of all of my JAMF stuff. So far, I have all of the SwiftDialog scripts that I have been posting here up on my repo. Will be adding more, and also posting my EAs as well.. I am new to the git repo world, so please be patient with me as this quite a learning experience! https://github.com/ScottEKendall/JAMF-Pro-Scripts
On Saturday, February 15, 2025, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time us-gov-west-1 February 15 0800 CT 1200 CT
Good morning, simple question about Jamf Connect Deploy & Updates integration in Jamf Pro. Currently my configuration is: deploying Jamf Connect not in the prestage via .pkg (only launch agent) but via the integrated functionality of Jamf Connect combined with the Jamf Connect Login Configuration Profile, as shown in the screenshot. It works. Two questions. 1) In your experience is it a stable configuration? Up to now it has never given me problems, but I would like to update to 2.44 (I'm stuck on 2.39) and since the profile is in scope on All Managed Clients I'm wondering if it's stable and the best option. 2) If I remove this integration in the configuration profile, nothing would happen to existing clients, right?That way I could simply deploy the update via policy and reinsert the Connect .pkg in the Prestage, just to have more control. What do you suggest? If the integration works well in your experience i could simply choose the new version and keep this configuration :)Tha
Hello, We are a school district and are facing a potential problem with the deep integration of Apple Intelligence in iOS 18.1+. All students use iPads and they are starting to update to 18.1 and above. This is likely going to be a major problem once it's testing season and I'm not the only one worried about this. According to Jamf Support there is currently no way to restrict this "feature" on an MDM level. The problems: 1. In Notes you type an equation and the solution will automatically fill in. 2. Typing math problems in other apps will show a solution in the keyboard suggestions. What I've tried: 1. Disabling AI settings currently available for config profiles (not applicable) 2. Restricting: spell-check, auto-correction, predictive keyboard, auto-suggestions -- only affects words/grammar, not math. 3. Blocking AI related hosts: https://support.apple.com/en-us/101555 4. Disabling com.apple.calculator There is a potential option but current
Hello,please vote for the following request. Link: Network autojoin - always on option | Jamf Nation Ideas I requested:Make it possible that autojoin can't be changed by a user. It should be possible to leave it always on. The problem without it:In our school we use iPads with WIFI always on. Our network profile includes our school network with an "automatically join the network" on.We also use specific profiles which are activated at 7:45 til 13:00 with some restrictions while being in school. We block specific gaming and social media websites and we configured a whitelist there make only necessary app while beeing in school available.The problem is that a lot of users now found out, that it's possible to turn autojoin for the school network off before arriving in school. They do this because they won't the restrictions beeing activated from 7:45 til 13:00. This causes also other problems like always catching the students which are not connected on purpose and not visible in clas
Has anyone run into this issue:-MacBooks are bound to AD-User changes password.-Restarts/locks computer can't sign back in again. States account is locked out for "15 minutes"-Log in as the local Administrator account and log back out, user can then sign in without issue.-Change user's password and they can log in but when they restart/shutdown, won't let them back in until we sign in as local admin account.
Hello everyone, since the major tvOS 18 update, I guess, there are additional screensavers displaying in the Apple TV than the usual skyline (ocean, aerial view of an airport etc.). We use them in conference room mode in schools and even though the screensavers look nice on a 4K display, the distraction of the students especially in elemantary schools is an issue. Is there a way to stop the screensavers from showing up, I couldn't find a matching setting in Jamf. If not, maybe this should be considered becoming a payload? Thank you in advance Benjamin
What I would LOVE to see implemented in Jamf is a report containing all of the apps currently existing in the App table and a list of what groups that apps are scoped to. FWIW, we have over 900 unique apps listed in "Mobile Device Apps" Right now if we look at the Apps table we see a list of all the apps but for the scoping, we see something akin to "3 mobile device groups, 2 mobile device groups excluded". I understand we can't see it all in the GUI necessarily, but if we could get a PDF report or a txt file generated that shows what those groups are, we could mark it up and know which apps we need to make changes on scoping each summer. Right now, we have to look at each app and go to the scope tab for it and decide and then keep going 899 more times. Very tedious process. Having some sort of report or spreadsheet we could markup would be wonderful so we only have to make scoping changes to the 10 apps or so we care about. It would also help because we could socialize the big list wi
Dear all, I am trying to deploy Cisco Secure Endpoint Connector v 1.24 via JAMF. I try to deploy a configuration profile to give the app full disk permission, install the kernel extension and something else. I tried to use this documentation for that: < Approval of the Mac Connector macOS Extensions with MDM > and < Approval of Full Disk Access for the Connector with MDM >. Unfortunately it is the documentation for version 1.18 and from 2022. But there is no newer documentation available. After trying to deploy the profile to a Mac with Sequoia 15.3 I get the feedback from JAMF: "The current system configuration does not allow the requested operation". (Die aktuelle Systemkonfiguration erlaubt den angeforderten Vorgang nicht). The MacBook is an Apple M1 hardware. Can someone help me to find my issue?
Back at again with another script that has been useful in our company. Before I took over as Mac admin, the users were creating their IDs with their employee# vs their first.last name. As such we have a mixture of systems with incorrect UserID, so I borrowed this script (author unknown) from a very very old JAMF post and thought I would make it more user friendly by adding some Swift Dialog "flare" to it. The user that you are wanting to change cannot be logged in for this, so what I do is scope it to an admin ID that is present on all of the computers, and I walk the user through how to login to the admin ID (the password changes after they login using LAPS, so no worries there) and then I instruct them on how to run the script. It only takes a few seconds to run, and will restart the computer once it is done. Here is the script #!/bin/zsh ###################################################################################################### # # Gobal "C
I've been doing some testing of the "Lock Computer" function (from the Inventory/Management screen) and it does not work as I would hope. I want to know if it's working "as expected" or if I'm doing something wrong or if there might be a bug which I should report somehow. While my test machine (M1/Sonoma 14.7.2) is offline, I send the "Lock Computer" command. Of course I don't expect it to be effective until the machine is awake/networked; Jamf shows it as Pending. Pretending I'm a computer thief & don't have the password, I wipe the machine, keeping it offline. But in order to install MacOS, I need to connect to the network and get past that pesky activation screen. Surprisingly, no problem: your Mac is activated! And installation of OS proceeds. As installation proceeds, I check Jamf: the Lock command is still Pending. After OS installation completes, but before creating an account, the Lock command disappears from Pending, but it doesn't show under Management History at all (Com
Hello everyone, We use Jamf School in our school to manage iPad that are borrowed to our pupils. I have set a mail profile for every single one of them. Since september i encounter an issue that i did not have before. The students password is automatically written in "Incoming Mail Server" but not in "Outgoing Mail Server". We can manually put the password but i want the password to be automatically to earn some precious time. Is there a way to do it? Thanks
Hey Guys,Is there any way to block the ability to set parental control passwords on an AppleTV? People have been setting passcodes on the devices and it is really annoying to wipe them every time to reset the code. Cant seem to find any info about this. Thanks
Hi, due to an Audit finding we are to enable the native macOS Firewall in our Mac estate consisting of about 150+ machines. I've created the config profile with the Firewall payload and it deploys and works with no issue, but we donot want stealth mode to block the ICMP protocol, as we need Ping and other network troubleshooting utilities that it provides. Also dont want screensharing blocked, as well as Airdrop. Any advice how to accomplish this please?
We don't use DHCP, we manually assign each network connected device a static IP. It is possible to do this for our iPads from within Jamf Now rather than on each individual iPad?
Work for a public school district, use MacBook Airs for students, and of course Jamf Pro to manage them. Students keep finding ways to play Roblox. We've restricted every variation of the word "Roblox" and all the installers in Restricted Software. Seems like all they need to do is rename the app (for instance, to "easy" or "easy.app" or even just a letter, "g" or "g.app") and it is able to open. Any ideas?
Good Afternoon, I work at a school that uses Jamf Pro to manage our 2300ish Macbook Airs. All are 2020 M1s currently running on Sonoma. I'm having a lot of trouble finding a way to "wipe" multiple devices at one time and I have zero experience in using the Jamf API or even how to start using it. Everything is in prestage though and Apple School Manager.So far I've tried scripting it but haven't had any luck. My guess is the only way I'll be able to do this is through the API as "wipe" device doesn't seem to be an option for one of the Action commands. I really don't want to have to reset over 2k macbooks this summer by hand. Anyone who has any advice would be greatly appreciated. Thank you,
Hello everyone We're currently running into an issue. We've recently activated the LAPS for PreStage accounts. Seems that now after just one wrong try on the login screen the account gets locked for 1 minute. It happens to the LAPS, aswell as the local accounts. Is there any way to disable or set a higher number of wrong password-tries? We've tried it with a Passcode Config Profile, but this did not help. Even if you set the number to 11, it still locks down after 1 try. This is pretty annoying, also considering the fact, that those LAPS passwords can be quite easy to mistype one letter. Kind regards, Dario
I've tried deploying Mohs Surgery iOS app(https://apps.apple.com/us/app/mohs-surgery-appropriate-use-criteria/id692790649) to managed Macs through Jamf Pro w/o success. I've made sure to match the short version, bundle ID, and app link. I can deploy this to iOS devices just not Macs.I've confirmed on a vanilla M1 unmanaged Mac that it works through App Store.Through self-service it attempts to install but spins infinitely.Through automatic install it shows 1 license used but never shows up in /Applications.Included below are the configs for Mac and iOS:
Hi,I'm developing a container application that has 2 system extensions.During uninstall on customer environment, the extensions are fail to get deactivated. The customer is working with JAMF environment, and the only way that resolve this problem is to install a profile that allows the extensions automatically (bypass manual extension approval) and than revoke the profile.In addition, even with no dedicated profile for my application, the user need to manually approve the extensions, and deactivating the extensions from the container app fails.Here's the deactivation code from my application : self.deactivationRequest = OSSystemExtensionRequest.deactivationRequest(forExtensionWithIdentifier: extensionIdentifier, queue: DispatchQueue.global(qos: .default)) self.deactivationRequest!.delegate = self OSSystemExtensionManager.shared.submitRequest(self.deactivationRequest!) I don't have full visibility of the customer profiles environment, but perhaps you can tell me if there'
anyone had an issue at some point where users would get locked out of their accounts even though the password is correct, i've been investigating this for quite some time now and even though the user is a standard Account not mobile it still get's locked out at certain point, right now i have a user whose getting locked out every other day, i tried reading the logs but nothing helpful there. we are using Kerberos Extension for password Syncs, Default passcode policy, Filvault without institutional key , i read online that it's an issue with FV but i can't replicate the lock, because most of the time the lock happens after a restart or shutdown (sometimes it happens after a device is locked) anyone with a similar exp?
Very recently we've had some users who have upgraded their version of macOS beyond Monterey up to Ventura or Sonoma (I know, we need to get away from it ASAP, but we're stuck a bit longer because of the Microsoft/Adobe SMB hidden file issue).Our staff are all standard users and do not have admin access to their computers. In the past, any attempt to upgrade macOS to a new version would not be possible without entering admin credentials.Why is this suddenly being allowed to happen and what is the best practice using Jamf to prevent it?
After updating, the "block popups" setting on our iPads always revert back to the default of being enabled. There is no way to permanently disable this setting within Jamf, but is there a way to stop the setting from going back to enabled after every update?
This script automates the configuration of display settings on macOS by checking the system architecture, downloading and installing the correct version of `displayplacer`, and setting up display mirroring with specified parameters. It ensures compatibility with ARM64 and Intel systems while optimizing display settings such as resolution, refresh rate, color depth, and scaling. The script uses JAMF parameters to adjust these settings dynamically.Feel free to adjust the description if you have any specific points you'd like to highlight!DisplayPlacer: https://github.com/jakehilborn/displayplacer #!/bin/bash # ----------------------------------------------------------------------------- # Script Name: DisplayPlacer.sh # Author: [Muhammad Hasib] # Created: 25Jul2024 # Last Modified: 25Jul2024 # Description: This script checks the system architecture, downloads and # installs the appropriate version of displayplacer, and #
Hello,does anyone know how to fix this? In the companyname placeholder is the entry {{companyname}} displayed. But we entered the name of our school in the right field. We also use the payload variable %companyname% for beeing displayed on the lock screen and the school name is displayed there correctly. I also was contacting the jamf support two years ago because of this and they said, that this is a known bug. Greetings
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!