Get Support
Recently active
Hi Everyone,After upgrading the operating system to Sonoma, I noticed that I could not see the Profiles section. I see the message in the screenshot below. Has anyone encountered this situation? Does anyone know the solution?
Afternoon All So Im going through a process of removing a reduant local admin account from our fleet.It most cases I have been able to pass the secure token from one admin account to another admin account which I know the password for. This has worked in most cases.I assume there isnt a way to remove the secure token from that admin account only which then would alllow me to remove the admin account.I confused by most of these machines have another secure token user however they are not admin. Just trying to get my head around why I cant remove the admin account if another account also has a secure token. Machine in some cases have Filevault turn on and we do us jamf connect.Thanks
Hey, Macos 15 (and IOS 18) add support for controlling Safari extensions enablement using DDM - https://developer.apple.com/documentation/devicemanagement/safariextensionsettingsIs it supported on jamf already? didn't see anything about it in the recent release notes. If not, any plan to add jamf support for this configuration anytime soon?
We deploy our updates monthly and use autopkgr or installomator to install the updates. It seems we always have issues with Adobe Products updating. There is always a handful of devices that it fails to install on. I was using a script to check it was open and then close it and that seemed to help a little. These devices are getting other 3rd party updates just fine. When I go to the policy log, it shows the below. Executing Policy Update Adobe Acrobat Downloading Adobe Acrobat DC-24.005.20320.pkg... Downloading https://xxx.jamfcloud.com/jcds/downloads/Adobe%20Acrobat%20DC-24.005.20320.pkg... Verifying package integrity... Installing Adobe Acrobat DC-24.005.20320.pkg... Installation failed. The installer reported: installer: Package name is Adobe Acrobat (24.005.20320) installer: Upgrading at base path / installer: The upgrade failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurr
Our infrastructure is team is doing a bunch of upgrades to our PKI infrastructure. They are setting it up to have redundancy with different hosting sites. They are exploring putting Multiple the NDES severs behind a VIP but we are not sure if we will run into any issues. My thought is as long as the various NDES servers provide valid certs it should be accepted by our NAC ClearPass. Has anyone tried this or have experience with it?
When I try and remove Cisco AMP version 1.14.0 or newer the way I would with pre 1.14.0 version by running the uninstaller package in /Applications/Cisco AMP (now moved to /Applications/Cisco AMP for Endpoints) the user gets prompted for admin credentials. I've even tried running as root on the command line like I did before: /usr/sbin/installer -verbose -pkg /Applications/Cisco AMP for Endpoints/Uninstall AMP for Endpoints Connector.pkg -target / but it still prompts. I've also looked at the steps listed here https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/216232-manual-uninstall-procedure-for-amp-for-e.html to manually uninstall but again there are some steps which produce the prompts: /Applications/Cisco AMP for Endpoints/AMP for Endpoints Service.app/Contents/MacOS/AMP for Endpoints Service deactivate endpoint_security Enter password when prompted. For macOS versions 10.15.5 and newer: /Applications/Cisco AMP for Endpoints/AMP for Endpoints S
We have a requirement where users need to enable/disable the Automatic Proxy Configuration without requiring admin credentials. From the developer documentation, I found the "object NetworkProxyConfiguration.Proxies," but I am unable to modify it via a script. Could you please guide me on any alternative methods, such as using a configuration profile, to achieve this?
We have created Sites in our Jamf instance and are now planning to delete all of them. Before proceeding, I would like to ensure that none of the sites are currently being used by any policies, groups, or configuration profiles. Could you suggest the best way to gather detailed information on their associations?
Is anyone having issues packaging the additional content for Logic Pro X 11?I've tried twice, and my normal method isn't playing ball.In short, 'Composer' a whole installation, Also move related receipts to /Library/Receipts and add that to Composer. Build the PKG, PKGchunk up the 60-80GB file, upload and test deploy.If I remember correctly, the Logic Pro X 10 receipts used to appear in the users library and had to be moved. Now they're arriving in /Library/Apple/System/Library/Receipts - this seems to be a protected location. Any sudo ditto commands to that location result in 'Operation not permitted'.Anyone had any success getting Logic to register all the installed content?
Hi,I'm wondering if iBeacons are still a thing as they don't appear to have any effect on devices, no matter what policy is set.Documentation refers to Location Services and the Self Service app but the Jamf Self Service app doesn't appear to have any hooks in to Location Services and permissions can't be set for it.Were iBeacons something that Apple created but are now deprecated? Is anyone actually using them in 2024? If so, how did you manage that?!
Hello friends,I have recently deployed Forticlient version 7 through a package and then a policy, however, it is installed on the computers but appears blank. Does anyone have a solution?
Hello, I would like to know if you've encountered the following issue with the (Flat) Adobe packages generated via the Adobe Admin Console. When we generate an Adobe flat package and upload it to the JSS to make it available via self-service, during installation, it shows as "completed" in the self-service, even though it is still being installed. Therefore, if we create a JSS policy with multiple product packages, preferences, and scripts, including Adobe products, it considers the Adobe application installed and moves on to the next item. This poses a problem because often these are Adobe plugins or preferences that need to be installed after the Adobe product. We experience the same behavior if we incorporate the flat pkg into a package generated with Composer, along with a post script to install the flat package. We don't have this issue with non-flat Adobe pkgs, but apparently, it's become mandatory for Sequoia. Additionally, the installation of Adobe flat packages is much slower
Hello,Need to force some extensions on our fleet via MDM. I've already done so with most of our enabled browsers but can't find anything on Safari on how to do that.Is there any way to force them on it?
I remember from the 2024 JNUC, there was commentary about Apple allowing users to continue using their purchased software with their managed Apple IDs, rather than forcing *everything* to personal (for situations in which a user has already purchased company software using their company email address as their Apple ID). Is there any documentation on that somewhere, particularly a timeline on when that's supposed to be implemented? I've been dragging my feet on implementing Managed Apple IDs in the meantime, and leadership wants to know the holdup.
I'm working a customer setting up macOS Onboarding and we had it going, then at the end of the for some reason they started getting this message: " Cannot reach a Jamf MDM Server" after Device Enrolment, when the desktop came up, and SelfService Opens to start installing policies as per onboarding setup. At this point the onboarding froze of course as it cannot connect to mdm... -Jamf Pro is On PRem in this installation: - Only change the local tech made was in the prestage, setup assistant. Originally they left unchecked the location services, so on enrolment the user would select their location... He remove this in setup assistant and then all of sudden this message started coming up.-Server Reboot was done - no change-Ticket has been logged with Jamf - still waiting on resolution -We were able to get it going again by once again removing the check on the setup assistant skip, so no again the user selects the location services.- we also saw once the checkbox was removed, that
I am attempting to set up pre-stage enrollments for Jamf, but am running into some issues:I manually assigned a device to our business manager account for testing purposes. When I sign into the account, everything looks like it works correctly, but the device isn't assigned to any user. Is there a way that it can be automatically assigned?I would love to get Google SSO set up for creating the local user account. Would I need Jamf Connect to accomplish this?Thank you in advance!
A follow-up to this ticket, but different enough I wanted to start anew.Essentially, we're trying to do zero-touch with our next batch of MacBooks, so I've been working on a new Enrollment Profile. We want to primary account information (name and username) to be filled-in and locked during setup. Initially we tried to pull the data via prestage (see prior ticket), but since that isn't working, we tried via Google SSO and Secure LDAP:I followed these directions for the Google SSO:https://docs.jamf.com/technical-articles/Configuring_Single_Sign-On-with_Google_Workspace.htmlAlong with adding the SSO pane to the prestage. The pane seemed to work fine — asked for login, went through two-factor authentication, continued the setup afterword — but it never passed the variables to the Create a Computer Account screen, so the name and the username were still blank. I tried both Custom Details and Device Owner's Details in the Pre-fill Primary Account Information, neither worked.So
Running a long standing (and working) script to do updates on Macs and got this error today with a Jamf cloud client: Install action:Download and schedule to install (2025-01-15T15:00:00) Update action:Specific version (15.2) Current state:PlanFailed Error reasons:SpecificVersionUnavailableForDeviceModel Part of my script verifies that the Jamf Cloud client recognizes the requested version (like sometimes the trailing ".0" is not recognized). So that shouldn't be it. The plan is actually created but is "immediately" rejected:{ "events" : [ { "type" : ".PlanCreatedEvent", "managementUUID" : "e163182f-ea49-440e-967c-b5840bcf0366", "processManagerUUID" : "85980caf-557a-411e-99b9-94a07a478ead", "id" : 2469, "deviceObjectId" : 1, "eventReceivedEpoch" : 1736956458301 }, { "type" : ".PlanRejectedEvent", "managementUUID" : "e163182f-ea49-440e-967c-b5840bcf0366", "processManagerUUID" : "85980caf-557a-411e-99b9-94a07a478ead", "id" : 2470, "deviceObjectId" : 1, "event
Following the use of JAMF Mac Apps to update Chrome, some users have reported an issue where they are unable to access any internet or intranet sites from Chrome. The browser becomes unresponsive, and the issue is resolved only after a device restart. Has anyone else encountered this issue, and are there any insights or suggestions available?
Help! I have been trying to endlessly to get this to work...what am I doing wrong? I know for a fact that the logged in user has the workplace join key in their keychain but for some reason, when trying to run this for an EA it doesn't report correctly. I know the jamf runs with elevated privileges, but should it be able to run this without prompt for user credentials (like root), or is this not going to be possible? #!/bin/zsh currentUser=$( echo "show State:/Users/ConsoleUser" | scutil | awk '/Name :/ { print $3 }' ) uid=$(id -u "$currentUser") haswpjkey="No" wpjkey=$(launchctl asuser "$uid" sudo -iu "$currentUser" security dump-keychain | grep "Workplace Join Key" | xargs) [[ "${wpjkey}" == *"Microsoft Workplace Join Key"* ]] && haswpjkey="Yes" echo "<result>$haswpjkey</result>"
If I wanted to test a script locally on my mac before deploying it out - how would i go about doing it?Do I open my terminal and drag the".sh" file in there?
I'm trying to configure my updates to run via S.U.P.E.R finally, and I keep running into the error: Warning: Inaccurate deferral found for macOS major upgrade 1 of 1 is: DeferredUntil:2025-01-10 00:00:00,Title:macOS Ventura 13.7.2,Build:22H313,Version:13.7.2 I have config profiles setup for Apple Software Updates and SUPER the following: Apple Software Allow installation of macOS beta releases Automatically install macOS updates Automatically install app updates from the App Store Restrict software updates to administrator users only Automatically check for updates Automatically download new updates when available Automatically install configuration data Automatically install system data files and security updates MacJutsu.Super <key>AuthJamfComputerID</key> <string>$JSSID</string> <key>InstallMacOSMajorUpgrades</key> <true/> <key>InstallMacOSMajorVersionTarget</key> <strin
Instead of using the Okta Authentication API, Jamf Connect can also use the Custom identity provider type with an application set up for OIDC/ROPG in the Okta tenant. This allows for granular application of Authentication Policies in the new Okta Identity Engine tenants. Create App Integration in Okta Navigate to the organization Okta administration page. Select Applications → Applications and pick the Create App Integration option. Select the options for OIDC - OpenID Connect and Native Application. Select Next to continue. Select a name for the App integration name. In Grant type, select the options for: Resource Owner Password (this enables ROPG for ongoing password checks) Implicit (hybrid) Scrolling down for more options, remove the default entries with the X option for Sign-in redirect URIs and Sign-out redirect URIs. Enter a new sign-in redirect URI with the value https://127.0.0.1/jamfconnect Optionally, assign users to the Jamf Co
Hello everyone. We recently setup Kerberos SSO and are having some issues with it syncing passwords after a password change. Upon initial setup it works as intended. User logs in with their AD credentials, it asks for their AD password and their Mac password, it then syncs the password to match the AD password. However, when a user changes their password, they are able to log into SSO with their new password, but it never prompts to sync the mismatched passwords, so their computer still uses their old password. Has anyone run into this issue? Password sync is enabled and the system currently running into this issue is running 10.15.2
Hello We have a group of iPads which need to have their time zone moved forward one hour. I'm using Jamf Pro Cloud version 11.11.1-t1731016358 and I have administrator rights. I've checked the configuration profile for this group of iPads and can't find the correct setting to specify the correct time zone. There is only the setting Restrictions - Functionality - Automatic Date and Time setting, which doesn't allow me to set a specific time zone. Can you please tell me how to change the time zone setting in Jamf Pro Cloud interface? Thank you.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!