Get Support
Recently active
Hi all, I am a Jamf reseller in South Korea. We support a lot of Jamf customers, but there are problems with license renewal these days.I've purchased licenses for several customers from Jamf, but each time it takes a long time for a new activation code to come out, and I'm worried that it might even come out over time.In the past, there was time for licenses to come out in advance and prepare for the renewal of Jamf Pro or Connect.This is because after the activation code period, there may be problems with the behavior of all products, including Jamf Pro. So I think it is necessary to improve Jamf's license issuance system.Doesn't everyone have this problem? I'd love to know what you guys think.
Hello everyone,I've configured some new extension attributes connected to eDirectory. In this case it tells if the computer or devices is connected to a student or an employee. Since we haven't had the information in Jamf before, it seems like it has to go through all devices and users again for the information to be searchable. We have over 1000 computers and 2500 mobile devices. I made two smart groups yesterday afternoon, one for computers and one for mobile devices. This morning it has gone through about 80 computers and 60 mobile devices. Is it normal for it to take this long or is there a way to speed it up?
We have the Microsoft SSO plug-in Configure and deployed to all managed clients, upon initial sign-in or after sometime, signing into Microsoft Teams is blocked and end users are unable to sign-in to Teams, when we unstop the configuration profile from the affected devices users are then able to sign-into Teams, please note the SSO plug-in works with all other MS and 3rd Party apps that use Entra Authentication.Please advise if anyone has this issue and if there are any solutions. Teams sign-in gets stuck here when selecting your account nothings happens no errors, no prompts.
Hello,We would like to start utilizing the return to service app however I am unsure how to scope our deployment network. Our network is cert. based so we have a temp network we use to get the devices online to get their configs and then we manually forget that network. I have return to service configured up to the point of getting that deployment network. What would be a scope I could use for these to have them only have the network loaded after return to service has ran? I did find the plist key to set a time for it to forget the network, just not sure on the scope for enrollment. Thanks in advance!Dan
Hello, I'm trying to deploy Harmony Check Point to our clients. Our security team gave me Endpoint_Security_Installer.zip How can i deploy this? I tried many things but all is failed. Zip File: Endpoint_security_Installer.zip in Zip File : /87.60/Endpoint Security Installer.app I tried to copy zip to client then unzip it. But how can i run installer with quite mode? Maybe I'm on the wrong way. Please help me :)
Trying to deploy a Fortinet VPN config profile for macOS Sequoia and Sonoma, but the profile fails to install. If I change the Connection Type to L2TP the profile installs. Has anyone run into this issue? Settings: Connection Name: VPNTunnel Identifier: com.fortinet.forticlient.macos.vpn Server: locahost Provider Bundle Identifier: com.fortinet.forticlient.macos.vpn.nwextension Provider Designated Requirement: identifier "com.fortinet.forticlient.macos.vpn.nwextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = AH4XFXJ7DK
I didn't see a solution here and really don't want to package it every time, which defeats the purpose of the App Store... We are trying to install FileMaker via the Jamf App Store but include the license file and activate it. I can deploy the app fine and deploy the cert to a folder, but then the end user needs to activate manually after installation. Does anyone have a trick to getting the license activated automatically when deploying via the Jamf App Store? Thanks
Hi everyone! I've been slowly building out our self service with software from VPP, scripts for updating and some help desk tools. I was hoping you all could share some of the scripts and other tools you use for your users. There have been some older threads showing off their tools but they are a little sparse on how to make them work. One great one I saw, but have no idea how to get it to work, was an emergency backup to Google Drive. I would love to see some scripts for updating Adobe CC and some other nifty scripts for helpdesk. Attached is what I have so far. Cheers everyone! :)
Is there a way in self service to update spotify automatically. Or at the very least package/script the policy to always pull and install the latest version?
Dear jamf nation, please add the ability for us to block certain members
Has anyone managed to get around the "403 - INVALID_PRIVLEDGE" error when trying to use the API? I created several API roles that basically give read privilege to every single thing that Jamf Pro allows you to assign read access to, then I assigned those roles to an API user. I'm able to create the token from oath2 and use it to hit various endpoints, so I know that this user's credentials and my basic setup are correct. The API does return 200 OK codes and I get data back. However, when I try to hit any version of the computer_prestages endpoint (v1, v2, v3) I get { "httpStatus": 403, "errors": [ { "code": "INVALID_PRIVILEGE", "description": "Forbidden", "id": "0", "field": null } ] } What is an invalid privilege? It seems different than insufficient privleges.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server [PI122416] When creating or modifying a configuration profile with a VPN payload that uses "Password" for the User Authentication type, Jamf Pro now correctly creates the profile with a valid AuthenticationMethod key. [PI123933] Jamf Pro no longer fails to display the scope for newly created deployable objects and saves scoping changes for existing objects as expected. [PI124225] Upgrading Jamf Pro no longer unexpectedly alters the required privileges for the Jamf Parent and Jamf Teacher apps to function. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox e
In our efforts to demonstrate our commitment to transparency and the safeguarding of personal information, we are providing you with the following important update around the use of AI within Jamf. We’ve updated our Privacy Notice to clarify to customers how we use the information you share with us to inform our AI product features. Performance and usage data may be used to support AI features, such as knowledge-based insights and advanced query results, however, we do not use any personal data to train our AI models. This change is effective December 19, 2024. If you have any questions or concerns, don’t hesitate to contact our Privacy team at https://www.jamf.com/trust-center/privacy/ or privacy@jamf.com
My school district has Apple TV's in classrooms, and we're trying to prevent our managed student iPads from being able to AirPlay to them. On the student device profile, we have AirPlay restricted to only known AirPlay destinations, and we left the destinations empty so that they have none available. This isn't preventing them from being able to AirPlay to the Apple TV's. They can still AirPlay with the code that appears on the AppleTV. Is there another setting we're missing? We need to keep our student and teacher iPads on the same WiFi network for Apple Classroom, so using a different network for the student devices isn't an option for us. We'd also like to avoid putting passcodes/passwords on the AppleTV's because we have many teachers who travel to different schools and classrooms. We could possibly start configuring Apple TV passwords with a similar convention, but sometimes when we do that, we just find it publicly posted in class
We're excited to announce with Jamf Pro 11.13.0 Beta the compliance benchmarks capability is available for testing. A full version of compliance benchmarks will be available in a future release of Jamf Pro. The Jamf Pro 11.13.0 Beta also features Jamf SSO, outbound communication for AD CS integration, a new collapsible sidebar and more! How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hello My Beta server is still on Version11.12.0-b.1.t1731093179Can some push it to 11.13? Beta Region us-east-2 Version 11.12.0
Does anyone have experience with this product from ManageEngine? https://www.manageengine.com/products/self-service-password/mac-os-x-login-agent.html They offer a Login Agent that allows AD password resets from the login screen. I have some concerns about FileVault (won't work with FV2 enabled) and compatibility (it will break every time OS X is released) but otherwise it seems reasonable. Anyone using this?
Hi all,Jumping into this can of worms. I run MacOS classroom environments in higher-ed with around 100 computers. So far each year the fall release of a new major MacOS comes with challenges and feature breaking in our rather "custom" setup. Looking into the coming Fall 2024 releases, I'm most concerned about the ability to disable and manage features with the beta Apple Intelligence. AI/LLM feature sets are cool, but they are still a wild-wild-west hazard in education environments.I figured I'd post here and see whether anyone has some inside information on whether these features will be immediately configurable by admins. Anything obvious I've missed so far? Has this information just not been released?Thanks!
Hi Jamf Nation, We are a group of companies and I have configured multiple sites for each company. Now I want to enable SSO for users so that they can use that to enroll their device (user initiated enrollment). While enabling SSO, I noticed that I am able to enable SSO for only one domain. How I can configure multiple domains for SSO in Jamf Pro? I am a newbie, so pardon me if I asked a silly question. Thanks in Advance
Hi All, This worked for me...Hence I am sharing this to all the admins out there who is looking for a permanent solution of never ending AD Password Sync Issue with FileVault..First let's spit the scenarios..Scenario 1 (Mac User who is aware of his/her old AD password) FV2 EnabledScenario 2(Mac User who is not aware of his/her old AD password) FV2 Enabled Scenario 1:-(Mac User who is aware of his/her old AD password) FV2 enabled Step 1 - Check the Securetoken status of the AD Mobile Account sysadminctl -secureTokenStatus username_goes_hereIf it's disabled follow this article to enable the secure token https://derflounder.wordpress.com/2018/01/20/secure-token-and-filevault-on-apple-file-system/By any chance if you receive any Operation not permitted error while enabling securetoken. Simply go to system preferences>Security & privacy > Unlock using admin credentials > Select Filevault > You will notice the following Alert "Some users are not able to unlock the disk |E
Unfortunately, we didn't catch the new iCloud preference pane in time, allowing some users to sign in despite us not wanting them to. I have tried deleting MobileMePreferences.plist as well as anything in ~/Library/Preferences/com.apple.[anything iCloud related] as well as ~/Library/Caches/com.apple[anything iCloud related], perform a killall cfprefsd and killall finder, and unfortunately, these methods no longer work in Catalina. I have looked through a number of posts on here, however, there isn't a thread modern enough that addresses this issue in Catalina. How can we force a log out of iCloud in Catalina remotely? We are already able to address the System Preferences issue.
We keep getting the 'Server session invalidated' error on most commands sent out to this specific iPad. Has anyone seen this before or know how to fix it?
We have a restriction on icloud and Siri for our Mac laptops... Some users are consistently getting a message similar to- "You do not have access for Siri permissions, contact the person who created your computer." How can we turn off notifications?
Hi All Does anyone have updated version of loopdown script by carlashley. Not conviced Im using the right one from github. Thanks
Might anyone have any tips on how to better handle some of our popular apps like MSFT Authenticator, Outlook, and Teams that were deployed with the Remove on Unenroll restriction set to on? With a migration coming up we would want these apps to remain on the device through a soft MDM wipe. We may be looking at a complete removal/uninstall/reauthentication of the applications which is not a fun user experience. I will be testing a few more scenarios but want to make sure I’m not missing something. Thanks in advance.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!