Get Support
Recently active
We are testing the PSSO with the Secure Enclave method. When setting the Account Authorization Type as Standard in the PSSO configuration, we've observed that post-registration, Mac local user accounts with Admin access are downgraded to Standard user accounts. Conversely, when utilizing Account Authorization Type as Admin in the PSSO configuration, we've noted that post-registration, Mac local user accounts with Standard access are elevated to Admin accounts. wherein user accounts are not inadvertently changed from Admin to Standard or vice versa. any hints on this?
Lately I've noticed (this also happened to my coworkers) that when I log into JamfPro I find my dashboard loads for about a split second then disappears. I've tried the following steps to troubleshoot the issue. Clear my cache, restart browser. Try a different browser (Chrome, Safari, Firefox) Removed each item on the dashboard hoping that one item was causing the isssue. Tried added an item that wasn't there before. Had my coworker do the same steps with their account. Has anyone else run into this issue?Anyone have a fix I haven't thought of? Honestly it's not a big deal, but I'm of the mindset...if it's there...it should work.
I have a policy to manage the applications that show on the Dock. In the picture provided it shows the triggers and execution frequency. For some reason the policy executed on the local admin account, but since these laptops are in a 1 too many program we have several local Standard accounts created for students. I am noticing that the policy has trouble executing on the other Standard accounts. In the logs of the policy, the device does not even show up, but i know it has executed on the admin account. Any advice or tips? Picture provided shows the triggers and frequency. Thanks
Hello jamf nation, We have 2 managed local administrator accounts on our Macs. One is the PreStage admin, which is created during the macOS Setup Assistant. This is the PreStage admin "hu", which is LAPS enabled. And we have the jamf management account "ja", which is also LAPS enabled. We have now removed the PreStage admin "hu" from all devices, as we only wanted to have one admin on the devices. Since LAPS, we can now also use the jadmin, if necessary, to enter passwords in exceptional cases. Unfortunately, the PreStage admin remains in the jamf Pro database and is displayed in the computer object. There is also still the option to display the LAPS password. If you display the Laps password, it ends with the Failed mdm command: "SetAutoAdminPassword" - "Unable to find user with GUID '851D63DB-068A-4FCD-B650-709144FE6E20'" Has anyone else removed the PreStage Admin and had the same experience or do you just leave the Admin and have 2 Admins on the devices?
Hi All, Pretty much at the moment I've enable a deny access to the security and privacy tab in system preferences. We have mainly done this to stop the users changing their password. But this however is really annoying if a user needs to grant permission to an app to allow microphone access, camera access and the rest. Is there any work around where I can allow users to this but grey out the change password option under security & privacy > general > change password
Trying out the new Self Service feature added to App Installers. I'm testing using the Google Drive app. I've made the app selection from the Jamf App catalog, configured it for Self Service, and scoped to my targets. Whenever any of the computers/users opens Self Service and clicks to install Google Drive, we get the error: "This application is unavailable. Try again later." from Self Service.Anyone else experiencing this issue?
Hi, We've noticed recently that when users are enrolling iMacs and MacBooks (not iPhones and iPads they seem to work) Jamf isn't collecting user details used to enroll on every occasion they seem to be missing about 75% of the time. This only seems to have become an issue since we moved to Jamf Cloud and Azure for authentication. Has anyone else had similar issues? Matt
I have downloaded and tested the new Self Service+ and it is definitely an improvement over the old Self Service app.I'm wondering if/when it will see better support in Jamf Pro. Currently to deploy it I'd be pushing a .pkg installer via a computer Policy, whereas the old Self Service app has an entire panel in the Jamf Pro settings for automatically deploying and configuring it on endpoints. As we get closer to EOL for the old Self Service will we see similar support for the Self Service+ app added to Jamf Pro?
Wondering if anyone is experiencing this lately... When we schedule a DDM update, the device successfully gets the command from Jamf Pro. The device downloads the update, but it immediately installs the update without honoring the scheduled plan. There isn't a notification, maybe a 5-second ticker, then the device shuts off and updates. Some other details: • Happens to some devices, not all • I set the deadline a few days out • Noticed this around iOS 18.1 - 18.2.1 • Here is a log from sysdisagnose: [DDM] -[SUDDMManager _scanForUpdateForDeclaration:retryIfNecessary:]: Scanning for update for DDM declaration SUCoreDDMDeclaration (DeclarationKey:com.apple.RemoteManagement.SoftwareUpdateExtension/EAD2FADB-1141-44C4-8E49-6E07F462A033:NmQ1ZjVjYTItMzViNS00ZDcxLThkMWQtNGMxZmY3YmJlODYx.NjZmYTA2YzYyZGJjNjFmNzM0OGE1ZGY1YTNhMGU3ODg4ZWQwMjRjNDg5NTcwZDZmZDM4YWQ2M2VjNjc3ZWVkYQ==|EnforcedInstallDate:2025-01-08T22:00:00|VersionString:18.2.1|BuildVersionString:22C161|DetailsU
I am trying to remove and add some Dockitems to our new Users, so far it goes well with the Built in Tool and policies. Just these three Apps don't work. I am using the following path file://localhost/System/Applications/TV.app/file://localhost/System/Applications/Music.app/file://localhost/System/Applications/Launchpad.app/ I'm aware that there are other tools like dockutil and dockmaster, but I would like to use the built-in functions. Am I doing something wrong or is this a known issue?
Hello, I would like to hide the window that asks whether to send diagnostic data when opening Microsoft Edge. After some research, I found the Edge Policy available in Jamf (com.microsoft.Edge). I added DiagnosticData and configured it. The profile is applied. Unfortunately, it doesn’t work—the window still opens. The other configured settings are applied. Edge version : 132 Edge Policy : The Diagnostic window : Thanks
I've been researching Jamf NOW as a potential MDM solutions for some Mac's we plan to buy but I've found some of the documentation contradictory. In this particular case I'm trying to determine if a device enrolled using Open Enrollment will have the option to use Activation Lock Bypass. The article on Supervision states that the feature requires both supervision and Automated Device Enrollment, but the article on Open Enrollment states that the device will share it's bypass code when Find My is enabled which suggests it also supports the feature. So which is it?
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: [PI124276] In Jamf Pro instances hosted in Microsoft Azure, a port number is no longer incorrectly appended to the end of the IP Address field in a device's inventory record, which previously prevented any changes to the General pane from being saved. [PI125557] The device compliance for shared devices workflow to configure iOS apps no longer causes issues for apps other than Jamf and Microsoft apps. Note: Devices in scope of device compliance for shared devices will have a Single Sign-On Extensions payload deployed to them. If devices in the Applicable Group had a Single Sign-On Extensions payload deployed to them previously, device compliance will not be enforced on those devices until the old Single Sign-On Extensions payload is removed. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new
How would I create an extension attribute that reports back on a mac's last reboot. I know by typing in "last reboot" in terminal, I can get a response with the most recent times a mac was rebooted. I am looking for a nice way to back up claims by users that they "just restarted" when I ask when they did. Any help is appreciated.
Hello, Today, We found out the Jamf Connect login is not working when connected to our corporate WiFI network which is basically EAP/TLS machine level cert auth with auto-join configured through Configuration Profile. Does anyone has any solution for this issue ? OR does anyone come across this issue ? Note: Jamf Connect Login works perfectly fine on home network / mobile hotspot.
How do I bulk add apps to a scope or category? I would envision that I could simply tick a checkbox for the 20 apps I want and go to 'Assign to scope' or 'Assign to category'. I just can't seem to find the screen, manually entering each app is doing my head in. Any help would be greatly appreciated.
Afternoon Where gearing up to rollout Sequoia later this year, does anyone have any config profiles there using to block these from appearing. Is it something that can be blocked? it doesnt seem possible through Jamf own config profile settings.I assume there is some custom xml that could be used possibly.Thanks Tom
I've got a profile added to my prestage to enable FileVault during enrollment, and for random systems, it seems to be failing to turn on FileVault. The profile is installed on the system, but the key is Unknown and FileVault 2 status is Not Enabled. These machines have all been on macOS 14.x (few with 14.1, few with 14.3). The weirdest one of all though, is a system with 13.7.3 enrolled, got the profile deployed, and FileVault enabled and key escrowed to Jamf. I doublechecked and confirmed the documentation states this is for macOS 14.0 or later. Anyone else seeing anything similar? My environment is running 11.12.1. I could rip out that profile from one system and then deploy the previous profile that I was using to enable at first login (I confirmed that both profiles are not on the systems affected). Also of note - users are FileVault2 Enabled, and have SecureToken issued. I also checked the PI's and didnt see anything that sounded similar to this.
Hey Everyone!I have been at this for hours and I am not sure what I am doing wrong. I am trying to make an extention attribute that will display the users current keyboard input type. We have users in the UK and in the US and I have been asked to show if the users mac has a UK Keyboard or a US Keyboard. This is my script, its very simple and I am not sure why its not showing a result in Jamf Pro. Even know it shows a result in terminal and code runner. #!/bin/bash# get the keyboard layout nameresult=$(defaults read com.apple.HIToolbox AppleCurrentKeyboardLayoutInputSourceID)echo "<result>$result</result>" Here is my EA's Attributes I am trying to find out if I need to contact jamf or am I missing something. Any help would be greatly appreciated!
In 11.11 a new attribute for macOS was released - Battery Health. However the only value I see reported for any of my computers over 14.4 is Unknown. Is anyone seeing this work? There is a note stating that this will work for iOS but not iPadOS - but nothing about it not working for macOS.
Once established, it is no longer possible to change any configuration of the compliance set. It would be nice to have the ability to change it.
Hi, I'm fairly new to doing Software Updates via DDM and am having a few issues. One of which is a Mac that requires an update from 14.6 to 14.7.2. I've posted a software update to it, 'Latest Minor Version' with Download, Install and Allow Deferrals (3). While most of the machines in the target group have worked, one user has reported that they haven't received any notifications despite the machine being on and connected for many days. Using the JAMF Api: https://[jamf server]/api/doc/#/managed-software-updates/get_v1_managed_software_updates_update_statuses_computers__id_ I can see that there are 2 other updates that seem to date back to 2023, which are showing DownloadPercentComplete = 0. The 14.7.2 update is in the list too, and says it has 'notified' 4 times but its download percent is also at '0'. My assumption then is that the old updates are stuck for some reason, and the new update is waiting for them to complete before beginning to download.
Good day everyone, I usually setup our VPN, Cisco Secure Client via https://docs.umbrella.com/umbrella-user-guide/docs/customize-macos-installation-of-cisco-secure-client. Simple enough to navigate through if you have all the pieces. I am traversing trying to get this process a hair more automated. The end goal: One Policy that can create the DMG you're looking for. The theory: - Use composer to package your already configured XML file and orginfo json file into a specific directory. - Add the newest version of the pre-deploy DMG to that same directory - Run a script to do any of the steps you need in the url. I've made this script so far where I want to make the file locations variables and make "Version" a user parameter so when the next version is getting prepared all you have to do is update the version number in the Policy Script Parameters. #!/bin/sh #This is to update the Cisco Secure Client #Create the Variables Version=“$4” orgFile=“/private/tmp/org
Created a simple log viewer that the end users can run and optionally email log contents. Nothing fancy, but might come in handy... #!/bin/zsh # # Log Viewer # # Created by: Scott Kendall # Created on: 01/29/25 # Last Modified: 01/29/25 # # Expected Parmaters # # Parm #4 - Full Path of Log to view # Parm #5 - Window Title # Parm #6 - Length of log to display or email (tail -n) ###################################################################################################### # # Gobal "Common" variables (do not change these!) # ###################################################################################################### export PATH=/usr/bin:/bin:/usr/sbin:/sbin LOGGED_IN_USER=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) USER_DIR=$( dscl . -read /Users/${LOGGED_IN_USER} NFSHomeDirectory | awk '{ print $2 }' ) OS_PLATFORM=$(/usr/bin/uname -p) [[ "$OS_PLATFORM" == 'i386' ]] && HWtype="SPHard
I try to add the app screen recorder to in iPad. Tipping on the "+" sign on the screen has no effect. It is not possible to add or delete items. Is there a solution?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!