Get Support
Recently active
Hi All, I'm implementing Jamf Connect with One Login and have bumped into a pretty weird issue. For Jamf Connect Login, I get prompted for user pass and MFA. the MFA defaults to a push notification to One Login Protect on my phone which , if I accept it if logs in just fine. Issue is that if instead of using the push I actually type the 6 digit OTP code in the same app on the phone, Jamf connect login fails with a 401 err... In a browser , OTP works, when testing the OICD setup in the Jamf Connect Configuration App that also works with OTP.... Trying with another auth app like Google auth produces the same result. Of course I raised it with Jamf Support too and will write the result but was just wondering if anyone bumped into something similar before
Hi there, Try to install IGV app (https://igv.org/doc/desktop/#DownloadPage/) with Installomator but get a error. So downloaded the App and use Composer (and build an pkg) but after installing this app and open it the app give an error. "The application "IGV_2.19.1" cant be opened" If I just drag the app to the applications folder it just work. any idea?
Hi everyone, In a nutshell, here’s how device enrollment is done at my company: In Apple Business Manager, the computer is assigned to Jamf's MDM. Jamf is set with a prestage enrollment named "Google" (because we use Google Workspace to enroll devices). During the first enrollment, Macs recognize that they belong to our company and open a Google login window to initiate the enrollment process. Afterward, the devices appear in Jamf, and I can manage them. Just after the 3rd step, many configuration profiles are applied, such as FileVault and Preferences Restrictions. There’s also a policy that runs—let’s call it "Enrollment Company." "Enrollment Company" is triggered by the enrollment and executes a script that configures system settings and manages user accounts during device setup. This includes functions to ensure network availability, verify the type of enrollment, manage user creation and login, and handle system configurations through launchd tasks to ensure devices are correctl
Good Afternoon All, We are using the Google Chrome Master Preferences file for deployment but has anyone had any luck disabling QUIC via this method or mdm profile? chrome://flags/ Experimental QUIC protocol
My write-up under the Tech Thoughts blog ... Give Yourself a Holiday Gift with Jamf Setup Manager
So the open option we use from photos stopped working once our devices were updated to iOS 18, I been looking through our configuration to see if there were any settings that might control this and I am currently stumped. Any suggestions would be appreciated.
It is good to be able to configure security in various aspects of MacOS using Jamf.However, one unfortunate part is how to solve DLP. There are several products for endpoint DLP or network DLP, but I want to implement DLP in a Jamf-friendly way and at minimal cost. The DLP I want is not to block file transfers unconditionally, but to examine the text in the document to determine allow/block. I also want to scan it when it is pasted into a web page. Is there a case where you use Jamf Security Cloud and Network DLP together? How do you implement it? How do you configure and operate it?We need your creativity.
Dumb question I have completed the migration to Device Compliance for Jamf and the migration script is working with no issues. However; how I can't seem to get it enrolled when it's a new device. What am I missing?
Hello, I've been looking through the documentation to determine if Jamf Protect scans downloaded files for viruses before allowing them to open and I can't seem to find a definitive answer. I know Jamf Protect focuses on providing comprehensive security for macOS devices, including real-time monitoring and threat detection. However, specific features like scanning downloaded files for viruses before allowing them to open are typically associated with traditional or next-generation antivirus solutions. Does anyone know the answer to this? Thanks!Matt
I have seen a few posts about getting a list of Chrome extensions installed but have not had any luck. Does anyone know of a way to generate a report of installed Chrome extensions?
Is there any way to block file sharing from mac to remote system via microsoft RDP?
Hi ! We are going to pilot TouchID in our environment icm with Managed Mobile Accounts, so currently all our macOS devices have an configuration profile where TouchID pane is disabled and also the features to unlock the mac. On my own machine i have removed that profile, and allowed TouchID.What happens is, the syspref pane got accessible again and all checkboxes also.When i configure a vingerprint and check the box and i am leaving the syspref pane and went back to TouchID the "Unlocking your mac" got unchecked again. Already done all basics like;- rebooting- re-enrolling into JSS- Verified the correct configuration profiles are deployed and no other one is also disallowing. Configured TouchID Went back to TouchID Syspref pane, and box unchecked Anyone ran into the same issue?
Hello! I used Jamf Compliance Editor to make a config policy to disable AutoOpenSafeDownloads, as part of implementing CIS lvl 1 benchmarks. I know Jamf Compliance Editor isn't supported, no worries, my question is more about conflicting config profiles! The result is a file named `com.apple.Safari.plist`. This file is very short, with only 1 option. However, `com.apple.Safari.plist` is a file that already exists - you can view the default settings with `defaults read com.apple.Safari`. My concern is: will having two config profiles with the same name cause issues? If I upload my new `com.apple.Safari.plist` to Jamf, and push it to a Mac, will it overwrite the settings specified in the `com.apple.Safari.plist` that already exists? Can macOS apply the settings from both policies of the same name, if one is applied through JAMF and the other is already on the machine? Thank you!! Helpful Info:In my `~/Library/Preferences/` directory, there is no `com.apple.Safari.plist`, but there is man
Hi all, I want to create a series of Smart Groups for the purposes of testing new software releases. I'm looking for about 3-4 groups. I'd like the groups to be made up of machines that don't all have a core attribute in common (such as OS version, model or processor type) - so a 'random' assortment if you will. Any ideas how I can go about creating a 'random' assortment of machines? - I tried using 'matches regex' to filter out serial-numbers with '1' in etc but didn't have much luck. I could separate into static groups easy enough, but was hoping the dynamic nature of smart groups would save me having to go back and update them as machines come in and out of our environment. Thanks for your time! Steve.
Hey everyone, I wanted to know what could be happening when a computer is getting turned on for the first time and it goes through prestage enrollment, and the login screen always comes up grey with the sign in at the bottom. We use Jamf Connect and with Jamf Connect 2.42 and 2.43 we have been getting a grey login screen, Jamf Connect 2.41 works fine but I am not sure why we are getting a grey login screen on the other JC versions.
Hi everyone, just exploring this and i just need to confirm a few things , if anyone knows that would be a massive help. I will get my hands on a device soon but i need to hit the ground running. So for vision OS 2 we do not need managed apple IDs anymore and it will work fine without for a prestage enrollment? Will i be able to hide bits and pieces from the set-up assistant? Lets say i don't want users to login to their personal apple IDs. The Prestage does not make any mentions of visionOS Can this be set-up as a shared device or is it not supported for VisionPro? Will enrollment customisation work ? Will i need any custom configuration profiles or will they just work from : Mobile Devices -> Configuration Profiles. I cant see what applies to visionOS only. Do i need Jamf Trust and Jamf Security cloud to keep these devices secure? I mean what is the best practice in terms of AV/EDR? Those who have implemented it, what has your experience been? Thanks
Does anyone have any experience with the Jamf Pro API and logging the movement of app licenses? My organization deals a lot with mobile device apps, and we are trying to find a solution to track the daily movement of licenses when they are checked in or out so we can cost them properly. The daily transactions are high, and we have a lot of apps. It's too much for one person to track so we need a robot.
Hi Chaps, Trying to create a DMG file to deploy that will install a safari shortcut to everyones desktop. Or possibly in the Applications folder, when I open composer and drag the Icon from my desktop in, it creates the folder Users>Simon>Desktop>GreyConnect.webloc Obviously not everyone will have a "Simon" user folder and I want it to go to theres, is there something like $username or something that will work and edit the folder named Simon? Thanks
Hello. I can get these commands and scripts to work just fine when running them locally on my Mac, but they seem to fail when getting pushed from Jamf.Scripts.1: #!/bin/sh defaults write NSGlobalDomain "AppleShowAllExtensions" -int "1" && killall Finder 2: #!/bin/sh defaults write NSGlobalDomain "AppleShowAllExtensions" YES && killall Finder Both work fine, surprisingly. Whether I run the scripts from Terminal, or I run the commands themselves directly from Terminal, it works both ways. But if I run either of the two scripts via a policy through Jamf, it doesn't work. The script runs and I see Finder quit/restart, but the setting for 'Show all filename extensions' does not change.I was going to try a Configuration Profile instead, but cannot figure that out. I had started something like this:Preference Domain: com.apple.finder <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://
I'm trying to get Jamf Protect offline client/policy talking from Mac to SIEM. It appears that protectctl is only useful with the full cloud product, or else my clients are broken. If protectctl needs cloud version, why is it installed on my Macs? And how do you debug without it. The files in the db folder are totally opaque for debugging. It appears that protectctl diagnose is also useless without cloud. Ideas?
Hello everyone, I would like to implement Installomator to manage the installation and updates of the applications I use, in order to streamline the process and avoid the repetitive task of manually searching for each package for every application. I watched the Patch That App Up (By Using Installomator) session presented at JNUC 2023. In the video, it is recommended to create a smart group based on the "Patch Reporting" criterion to identify devices running a version older than the latest available. Additionally, it is advised to create a second group containing the members of the first one, as Jamf does not allow targeting a group directly based on the "latest version" criterion. Is this still the best method today? Do you have alternative approaches to suggest?
Hello everyone, I'm looking for advice on how to integrate SwiftDialog with Installomator. When I update an application, it closes automatically without notifying the user, which can lead to the loss of their current work. Should I configure specific parameters when adding the script to the rule ? Modify the Installomator script directly ? Or use SwiftDialog to notify the user beforehand ? Thank you in advance for your help!
Getting back to testing OneDrive since we're moving to it this year. For the most part it looks like it's working, but one issue I'm having is, when launching OneDrive, it's not populating the email address on the first step. The below is what we have setup. We're trying to match with Windows settings are going to be, but it looks like some settings are available on the Mac side like, Continue syncing on metered networks Continue syncing when devices have battery saver mode turned on <dict> <key>DisablePersonalSync</key> <true/> <key>DisableTutorial</key> <true/> <key>DefaultFolder</key> <dict> <key>Path</key> <string>~/OneDrive - CompanyName</string> <key>TenantID</key> <string>ourtenantID</string> </dict> <key>AutomaticUploadBandwidthPercentage</key> <integer>30</integer> <key>Fil
Today we released an upgrade to Mac Endpoint Telemetry. The new version of telemetry primarily uses the macOS Endpoint Security API and includes updates for new and existing endpoint logging. The telemetry configuration page has been redesigned and now offers multiple event categories to choose from, allowing for more granularity and customization when choosing events. New telemetry configurations now automatically include both admin-level and user-level activity. This new version of telemetry provides unprecedented visibility into macOS systems, with a few examples being: User elevations Authentication Persistence creation System operations To learn more about Jamf Protect’s endpoint telemetry for macOS, visit our blog.
Hey there, I was wondering if there is an easy way to remove user-added web clips from the home screen, or preventing them from being added in the first place. I see that someone had asked this question a few years ago but there was no accepted solution from what I could tell. At my district we have 1:1 iPads in K-2 and it helps to have the layout configured so that our managed apps and web clips are where our teachers/student expect them to be. Sometimes a web clip will get added by a student/teacher and the teacher will want it removed, but they lack the permissions to edit the layout themselves. Jamf school does not have any way to view/remove user-added web clips to my knowledge. Is disabling the profile with the managed layout or wiping the device the only ways to circumvent this? Thank you! Ben
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!