Get Support
Recently active
Hi. Does anybody has used Splunk or another tool so far to display the progress of Smart Group memberships over a certain period of time for data analytics? Thanks,Maik
Having a big issue here with one of my user's mac devices. So, it keeps coming up on my CTO's laptop where every time he tries to access an O365 product it wants a password. Problem is none of the passwords work for this. He just got this device and ran it through Jamf from OOBE and everything else is accessible. We even installed Edge and it works through there, but the preferred browser is Chrome. I implemented the SSO extension, and it is working fine for others.From his device he is getting the below: All users also have the Windows Accounts extension for Chrome enforced on the devices.Anyone else faced or facing this issue?
Hi all, Having a bit of a struggle figuring out how to package and send out an application without having user have to sign in to an apple account. See image attached. Is there anyway in composer to bypass signing with an apple account to open the app?
Hello,We currently have an environment that has some computers with the standard release of Firefox and some with the ESR release. I'm looking to standardize this to the ESR version, but am looking for suggestions on how best to achieve this? I currently have the latest ESR setup with patch management and most systems have installed that update now. Would checking the box in patch management for "patch unknown versions" achieve the change? I have a script in place for the extension attribute for standard vs ESR, but I don't see the ability to make a smart group from that like I originally expected.Thanks for any ideas you can offer!
As enterprises grow increasingly and rely on technology, finding efficient ways to provide employees with access to digital tools is important. While iPads are often the device of choice for many organization, a one-to-one deployment may not always be feasible. Apple’s Shared iPad functionality, combined with Jamf Pro, offers a powerful solution for enterprises looking to provide secure and personalized access on shared devices without compromising user experience or data security. What is Shared iPad in Enterprise? Shared iPad is a feature designed to enable multiple users to share a single iPad while maintaining a secure, personalized experience for each individual. Each user logs into the device with their Managed Apple Account or a temporary session, accessing their unique apps, settings, and data. When users log out, their data is stored securely and becomes inaccessible to others.&nbs
Hi Can someone please help me with the nudge custom launchagent? I am trying to run Nudge in every 3 hours instead of default 30 mins. So far, I tried to edit the .plist file in /library/Launchagents and repackage Nudge from Composer and deploy from JAMF, but no luck so far. Got the error saying unable to move files in final destination while running policy.
Background information: I need to mass remove all devices from all groups via api I've been reading through all the API Calls available from jamfs /api page, i've come to the conclusion if it would be anywhere, it would be here [https://ENTERJSS.URLHERE] :8443/api/#!/mobiledevicecommands/createMobileDeviceCommandURL_post but via "Delete" (assuming a Remove From Groups Option is an available command) instead of "Post" but "Post" is all that's available. Am I missing something? Does anyone know of a way to remove an iOS Device from all static groups via API Call? Thank you
We have a number of machines that don't have the bootstrap token escrowed. I'm trying to provide a self-service option by having someone run the script from Self-Service. My understanding is that the scripts would run as root, but I'm getting the error:Script result: Enter the admin user name:Error: Missing user name.profiles: Unable to authenticate user information.Do scripts run in a policy not run with root access?
Hello everyone, I hope you are well and can answer my questions. We are currently on-boarding a new client and they are using MaaS360 at the moment with another MSP. I have everything just about finished up in JAMF, except Auto-Enrollment which requires connecting to the Apple Business Manager Server. Once I do, that is usually what bring in the devices (If I remember correctly). If the devices are currently already setup with a MDM profile on them with another MDM service provider, would that be interfered with if I would setup the connection between ABM and JAMF? I am wanting to make this transition seamless and have zero down time as the customer works 24/7 and needs access to these devices. I have only done setup of new users to JAMF and not migrated from another MDM Provider. Any insight would be helpful. My Plan was to have the users setup and tie that to Groups and profiles so that when he sees the users account it downloads the appropriate profile and
We are a young company and have been on Jamf Pro for less than a year. We were not able to start our operations with Apple Business Manager (ABM) so we will need to bring our existing inventory (all purchased direct from Apple) into ABM. I have been reading about the process here and I am concerned about the part that says:If you want to add a Mac that’s currently configured, you must first erase all content and settings.Important: All your data will be erased. Make sure you have an up-to-date backup of your data because it will all be erased.We have more than 100 active computers in Jamf. Is there a way to bring them into ABM without erasing everything? I can't see how that is going to go over well with one user, let alone 100+.Needless to say I am looking for some guidance (and hopefully some reassurance) that there is a better way.
I have a MacBook Pro (14-inch, M2 Pro, 2023) in our test environment on macOS 14.4. When i set the prestage to enforce the latest macOS based on device eligibility i get an error: System Update could not be installed, even though the machine should force it up to 15.2. Has anyone else seen this?
Welcome to Self Service+ 1.0.0! Self Service+ is Jamf’s new end user portal that helps organizations develop an autonomous and security-aware workforce. With Self Service+, employees are empowered to request, download, and update apps for their Macs, view the security of their endpoints, manage all notifications in one place, and learn how their data is handled with respect to privacy, all in one central, intuitive portal. Downloading Self Service+ is available on Jamf Account. Thank you.
Has anyone found a way to do IKEv2 VPN on built in Mac without using User-Level configuration profiles? Unfortunately, it is too crazy to unenroll all of our user computers and reenroll them to get mdm-enabled users, so I was wondering if anyone has found a work around for it?I tried Cisco IPSec built-in, but I can't seem to get it to reach our remote server. If I do the IKEv2 manually, it works perfectly.
Hi All. Our security team wants to implement a "Catch All"-Conditional Access Rule which requires a known device. Jamf Connect does not send this Device ID to Entra when syncing passwords. For Entra this request would've been sent from an unknown device. See screenshot: No Device ID. :( There seems to be a workaround here: https://learn.jamf.com/en-US/bundle/jamf-connect-documentation-current/page/Jamf_Connect_and_Microsoft_Conditional_Access.html But I'm curious, isn't there any other way to allow Jamf Connect to use the Device ID? I mean it's on the computer, isn't it?
Hello everyone,Recently we set up a solution that deploys certificates (ADCS Connector) that automatically connects the device to a specific Wi-Fi, without the need to enter a username and password.It works great. But now we have encountered a problem, if someone chooses to forget the network for some reason, it is not possible to reconnect. The connection is not automatically re-established, if you choose to connect to the SSID in question, you are asked to enter a username and password.Does anyone know what to do, if there is a simple or good solution to the problem?
Hello all,We are deploying out Microsoft Defender for Endpoint. Everything is going well except for setting up Device Control.I have everything configured using the custom schema at mdatp-xplat/schema.json at master · microsoft/mdatp-xplat (github.com) , which is linked from Microsoft's documentation. I have played around with trying to get JSON into the line for device control and had no luck.ProfileManifestsMirror/com.microsoft.wdav.json at main · Jamf-Custom-Profile-Schemas/ProfileManifestsMirror (github.com) I have tried to use the custom schema from the Profile Manifests Mirror above and none of the settings deployed at all.I also tried iMazing Profile Editor, with both signed and unsigned, and had the same issue as the Profile Manifests Mirror (which isn't surprising since they are linked I believe).Has anyone had any luck with developing and formatting the JSON string to use in Microsoft's schema to enable device control?Thanks!
How are you all auto-populating the user, location, department, etc. fields for your systems in Jamf?
Hello, We frequently encounter situations where Zoom updates in the background, but users don’t restart the application to apply the updates. I know Zoom updates automatically in the background, but how can I force a restart or ensure that the update is fully applied without needing the user to manually restart it? Is there a way to automate this process or ensure the app relaunches after an update? What steps should I be taking to address this? Best Regard, Jojes
Hi Nation, I am facing a weird issue. I just added the policy in Jamf to remove two dock items(mail and Safari). I tried with multiple triggers but it seems when a new user is trying to logged in via prestage enrollment, it is not working. I have Jamf Setup Manager installed, tried to use that with a custom event trigger for the policy. The policy runs, user logs in, dock reloads but still the items are there. This is the log screenshot: Point to be noted, when I am running the policy from self service, it's working fine. Any idea what I am doing wrong or how to fix that? Any suggestion is much appreciated. Thanks
I want to delete any computer (or device) from Jamf if they have not checked in for over 365 days. 'Action/Delete Computers' seems like it will do this job. Is there a way I could automate this process? It's not a huge amount of work to keep going back to this report and hitting 'delete computers' but I like to save time wherever I can :-)
I would like to stop spotlight from indexing certain locations across all my Macs. I need it to stop indexing the mounted network shares. Is there a way to do that? I could not find a setting regarding that in Jamf Pro.
Would there be any issues with using the same ABM account to manage volume purchasing across multiple Jamf Pro servers/instances? Any particular reason you would want to avoid doing this? I tried searching for similar questions here and information in the docs, but didn't find anything relevant. Thank you.https://docs.jamf.com/10.26.0/jamf-pro/administrator-guide/Integrating_with_Volume_Purchasing.html
Hi,Does JAMF Pro support importing users from Apple Business Manager?If not, then how would shared iPads be supported? ThanksSteven
Hi folks Has someone found a solution to disable the auto update check function in deepl.app?I tried already with preference domain: com.linguee.DeepLCopyTranslator <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>autoUpdateEnabled</key> <false/> </dict> </plist> and searched also for some other plists but had no luck to disable this function. The problem is all releases which are published to the user via app directly do not correspond with the main releases which are published directly from the developer.And our user without admin rights cant update it.Privilege Access via jamf connect is not an option for this :) I cant use also Installomator for it, because the URL is the one for the main releases. THank you in advance J
Effectively managing devices is essential for IT administrators in today's rapidly changing digital environments. While tools like Jamf offer powerful capabilities for managing Apple devices, a truly optimized IT strategy involves more than just top-down policy creation. Incorporating user feedback loops into your Jamf-managed environment can transform device management from a purely administrative task into a dynamic, user-centric process. By conducting surveys, analyzing self-service usage metrics, and adjusting policies based on user behavior, IT teams can ensure their strategies align with the needs of employees or students. This approach enhances device utilization and promotes greater satisfaction and productivity. Why User Feedback Matters in Device Management Device management policies often stem from IT goals such as ensuring security, minimizing downtime, and maintaining compliance. However, the end users—employees, educators, or students—interact with t
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!