Get Support
Recently active
Since our client is renting an Apple device(Mac), client are using the user-initiated enrollment method to register the device with jamf pro. Also, through Jamf pro, the profile item was disabled to use jamf pro restrict configuration profiles -> restrictions -> preference -> disable profile item. The end-point with Monterey installed is normally graded out, but the profile is not disabled on the end-point with Ventura installed. Are you experiencing any issues like this or have you solved them?If you have one, please share it with us.
Hello everyone, We are currently using Jamf School to manage our devices and would like to automate the process of assigning configuration profiles to specific device groups like Group 4 students. While reviewing the API documentation (https://api.zuludesk.com/docs/), I could not find a dedicated endpoint for this functionality. Could you please confirm if there is an existing API endpoint or method that allows us to: - Assign a configuration profile to a device group. - Remove a configuration profile from a device group. I really appreciate any help you can provide.
I migrated over to S.U.P.E.R.M.A.N. late last year (ok...the company didn't even have any type of policy in place...it was the wild Wild West over here...). I am sure that this script is not perfect in anyway, but it is working for me, so I thought I would share it in case anyone starting out would like a starting point. For you seasoned admins, any feedback on better improvement(s) is greatly appreciated! #!/bin/zsh # Writen by: Scott E. Kendall # Last Revision: 01/10/2025 # # Execute Superman script with passed parameters from JAMF # Options include Allow on minor updates, install major updates (speicific versions) and donwload only # # Parm #4 - Update Type (Major, Minor, Download, Defer, Reset) # Parm #5 - Force OS Version # Parm #6 - Deferral Time (in minutes) # Parm #7 - Deferral Count # Parm #8 - Deadline Date # Parm #9- Icon path # Parm #10- Test Mode On/Off # export PATH=/usr/bin:/bin:/usr/sbin:/sbin:/usr/local/bin LoggedInUser=$(echo "show State:/
Hi Folks,So we use Unity Hub in our classroom, I have always been able to activate for multiuser's by running.https://docs.unity3d.com/Manual/ManagingYourUnityLicense.html /Applications/Unity/Hub/Editor/2022.2.0b4/Unity.app/Contents/MacOS/Unity -quit -batchmode -serial SB-XXXX-XXXX-XXXX-XXXX-XXXX -username 'name@example.com' -password 'XXXXXXXXXXXXX'When I run it, it looks like it works, but when I log in as another user it is not activated.I verified that the path exists, if anyone has any advice id be grateful Unity support has a 30 day wait time for a response (I am not kidding I put in a ticket over 2 weeks ago)
Hi all, I'm the only Jamf admin for my company and have been asked to removed a specific Chrome extension from all our Macs across 9 locations. Is there a way AI can do this without physically going to all locations and removing it one by one? I saw a few posts, but I'm a newbie and don't know where to even start. Thanks in advance!
I am trying to figure out how to completely remove Jamf connect from my machines.I have tried running the uninstaller but it leaves profiles in my profile list of client machines that do not exist in my profiles built and deployed from Jamf Pro. I have looked for these profiles in my list of deployable profiles and they do not exist.I have turned off every profile and policy I believe is related to connect but two profiles still show up in the list on client machines.
Hey! I work in a school district where we have given teachers MacBooks. We have restricted the teachers from adding printers because we would really like to cut down on the insane amount of printing that they were doing. Before we had done this, a lot of the teachers had brought their own personal computers and added our IP base network printers. So we were thinking that they would do the same with their new district issued MacBooks and blocked the addition of printers behind admin credentials. We have given them the option to all print to the district's Xerox machines and that's it. However, a lot of these users would like to add their own personal printers. I was wondering if there was a way to allow the users to add their own personal home printers while still restricting them from adding a IP based network printer? I've seen some scripts that would add the user to a specific group that would allow them to add printers, but I am nervous that this would allow them to start adding
Hi All, I'm implementing Jamf Connect with One Login and have bumped into a pretty weird issue. For Jamf Connect Login, I get prompted for user pass and MFA. the MFA defaults to a push notification to One Login Protect on my phone which , if I accept it if logs in just fine. Issue is that if instead of using the push I actually type the 6 digit OTP code in the same app on the phone, Jamf connect login fails with a 401 err... In a browser , OTP works, when testing the OICD setup in the Jamf Connect Configuration App that also works with OTP.... Trying with another auth app like Google auth produces the same result. Of course I raised it with Jamf Support too and will write the result but was just wondering if anyone bumped into something similar before
Hi there, Try to install IGV app (https://igv.org/doc/desktop/#DownloadPage/) with Installomator but get a error. So downloaded the App and use Composer (and build an pkg) but after installing this app and open it the app give an error. "The application "IGV_2.19.1" cant be opened" If I just drag the app to the applications folder it just work. any idea?
Hi everyone, In a nutshell, here’s how device enrollment is done at my company: In Apple Business Manager, the computer is assigned to Jamf's MDM. Jamf is set with a prestage enrollment named "Google" (because we use Google Workspace to enroll devices). During the first enrollment, Macs recognize that they belong to our company and open a Google login window to initiate the enrollment process. Afterward, the devices appear in Jamf, and I can manage them. Just after the 3rd step, many configuration profiles are applied, such as FileVault and Preferences Restrictions. There’s also a policy that runs—let’s call it "Enrollment Company." "Enrollment Company" is triggered by the enrollment and executes a script that configures system settings and manages user accounts during device setup. This includes functions to ensure network availability, verify the type of enrollment, manage user creation and login, and handle system configurations through launchd tasks to ensure devices are correctl
Good Afternoon All, We are using the Google Chrome Master Preferences file for deployment but has anyone had any luck disabling QUIC via this method or mdm profile? chrome://flags/ Experimental QUIC protocol
My write-up under the Tech Thoughts blog ... Give Yourself a Holiday Gift with Jamf Setup Manager
So the open option we use from photos stopped working once our devices were updated to iOS 18, I been looking through our configuration to see if there were any settings that might control this and I am currently stumped. Any suggestions would be appreciated.
It is good to be able to configure security in various aspects of MacOS using Jamf.However, one unfortunate part is how to solve DLP. There are several products for endpoint DLP or network DLP, but I want to implement DLP in a Jamf-friendly way and at minimal cost. The DLP I want is not to block file transfers unconditionally, but to examine the text in the document to determine allow/block. I also want to scan it when it is pasted into a web page. Is there a case where you use Jamf Security Cloud and Network DLP together? How do you implement it? How do you configure and operate it?We need your creativity.
Dumb question I have completed the migration to Device Compliance for Jamf and the migration script is working with no issues. However; how I can't seem to get it enrolled when it's a new device. What am I missing?
Hello, I've been looking through the documentation to determine if Jamf Protect scans downloaded files for viruses before allowing them to open and I can't seem to find a definitive answer. I know Jamf Protect focuses on providing comprehensive security for macOS devices, including real-time monitoring and threat detection. However, specific features like scanning downloaded files for viruses before allowing them to open are typically associated with traditional or next-generation antivirus solutions. Does anyone know the answer to this? Thanks!Matt
I have seen a few posts about getting a list of Chrome extensions installed but have not had any luck. Does anyone know of a way to generate a report of installed Chrome extensions?
Is there any way to block file sharing from mac to remote system via microsoft RDP?
Hi ! We are going to pilot TouchID in our environment icm with Managed Mobile Accounts, so currently all our macOS devices have an configuration profile where TouchID pane is disabled and also the features to unlock the mac. On my own machine i have removed that profile, and allowed TouchID.What happens is, the syspref pane got accessible again and all checkboxes also.When i configure a vingerprint and check the box and i am leaving the syspref pane and went back to TouchID the "Unlocking your mac" got unchecked again. Already done all basics like;- rebooting- re-enrolling into JSS- Verified the correct configuration profiles are deployed and no other one is also disallowing. Configured TouchID Went back to TouchID Syspref pane, and box unchecked Anyone ran into the same issue?
Hello! I used Jamf Compliance Editor to make a config policy to disable AutoOpenSafeDownloads, as part of implementing CIS lvl 1 benchmarks. I know Jamf Compliance Editor isn't supported, no worries, my question is more about conflicting config profiles! The result is a file named `com.apple.Safari.plist`. This file is very short, with only 1 option. However, `com.apple.Safari.plist` is a file that already exists - you can view the default settings with `defaults read com.apple.Safari`. My concern is: will having two config profiles with the same name cause issues? If I upload my new `com.apple.Safari.plist` to Jamf, and push it to a Mac, will it overwrite the settings specified in the `com.apple.Safari.plist` that already exists? Can macOS apply the settings from both policies of the same name, if one is applied through JAMF and the other is already on the machine? Thank you!! Helpful Info:In my `~/Library/Preferences/` directory, there is no `com.apple.Safari.plist`, but there is man
Hi all, I want to create a series of Smart Groups for the purposes of testing new software releases. I'm looking for about 3-4 groups. I'd like the groups to be made up of machines that don't all have a core attribute in common (such as OS version, model or processor type) - so a 'random' assortment if you will. Any ideas how I can go about creating a 'random' assortment of machines? - I tried using 'matches regex' to filter out serial-numbers with '1' in etc but didn't have much luck. I could separate into static groups easy enough, but was hoping the dynamic nature of smart groups would save me having to go back and update them as machines come in and out of our environment. Thanks for your time! Steve.
Hey everyone, I wanted to know what could be happening when a computer is getting turned on for the first time and it goes through prestage enrollment, and the login screen always comes up grey with the sign in at the bottom. We use Jamf Connect and with Jamf Connect 2.42 and 2.43 we have been getting a grey login screen, Jamf Connect 2.41 works fine but I am not sure why we are getting a grey login screen on the other JC versions.
Hi everyone, just exploring this and i just need to confirm a few things , if anyone knows that would be a massive help. I will get my hands on a device soon but i need to hit the ground running. So for vision OS 2 we do not need managed apple IDs anymore and it will work fine without for a prestage enrollment? Will i be able to hide bits and pieces from the set-up assistant? Lets say i don't want users to login to their personal apple IDs. The Prestage does not make any mentions of visionOS Can this be set-up as a shared device or is it not supported for VisionPro? Will enrollment customisation work ? Will i need any custom configuration profiles or will they just work from : Mobile Devices -> Configuration Profiles. I cant see what applies to visionOS only. Do i need Jamf Trust and Jamf Security cloud to keep these devices secure? I mean what is the best practice in terms of AV/EDR? Those who have implemented it, what has your experience been? Thanks
Does anyone have any experience with the Jamf Pro API and logging the movement of app licenses? My organization deals a lot with mobile device apps, and we are trying to find a solution to track the daily movement of licenses when they are checked in or out so we can cost them properly. The daily transactions are high, and we have a lot of apps. It's too much for one person to track so we need a robot.
Hi Chaps, Trying to create a DMG file to deploy that will install a safari shortcut to everyones desktop. Or possibly in the Applications folder, when I open composer and drag the Icon from my desktop in, it creates the folder Users>Simon>Desktop>GreyConnect.webloc Obviously not everyone will have a "Simon" user folder and I want it to go to theres, is there something like $username or something that will work and edit the folder named Simon? Thanks
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!