Get Support
Recently active
Hello! About a month ago, we started receiving messages from a few of our users that when they try to go to "Users & Groups" in System Preferences to change their password, they see a message saying "Users & Groups" settings are not available. These settings are controlled by a profile." However, we have no profile in place that would completely lock the users out of that preference pane. This has only happened on a handful of Macs, and we've been unable to determine a cause. All of the machines in question are getting the same set of Configuration Profiles. We've seen it on Macs running both macOS Sonoma and Sequoia. The even stranger thing is that on at least one of the Macs, it just disappeared one day and the "Users and Groups" pane went back to working normally. If anyone has an idea why this might be happening and what we can do to fix it, we'd love to hear about it. Thank you!
I got a macbook from my school, went into MDM profiles and saw the name Jamf like 4 times. I hope this is the right forum! So basically our school isnt that restricted when it comes to macbooks, they let us create our own apple accounts or login on already existing apple accounts, they heavily recommended that we logged in into our daily basis icloud accounts so i dont think they look into data on our macbooks so much because its literally our own account or i hope so. We can literally download almost everything on our macbook, and can play around on the settings how much we want. I ofcourse disabled the Screen time data on settings. But my question is if they can see our screen time on our macbooks and how much we been using it, ive been using the laptop very very very much, got so many hours on it. I just wanna see if the school can see that, even if they did, is it easy accesible or do they have to contact JAMF for SCREENTIME DATA? ( I DONT KNOW WHICH PRODUCT I SHO
We track Macbooks by name in Jamf but students are easily able to rename their Macbooks by going to System Settings - General - About, and then just clicking and typing over the name that we set. When I look in restrictions, there's an option to restrict the entire General section but we don't want to do that. I just want to restrict the About section in General to prevent them from renaming the Mac.
I got a macbook from my school, went into MDM profiles and saw the name Jamf like 4 times. I hope this is the right forum! So basically our school isnt that restricted when it comes to macbooks, they let us create our own apple accounts or login on already existing apple accounts, they heavily recommended that we logged in into our daily basis icloud accounts so i dont think they look into data on our macbooks so much because its literally our own account or i hope so. We can literally download almost everything on our macbook, and can play around on the settings how much we want. I ofcourse disabled the Screen time data on settings. But my question is if they can see our screen time on our macbooks and how much we been using it, ive been using the laptop very very very much, got so many hours on it. I just wanna see if the school can see that, even if they did, is it easy accesible or do they have to contact JAMF for SCREENTIME DATA?
Hello everyone. I saw a few discussions about this one but nothing really stood out to help me.I want to give out FileVault key to the user that forgets his password. But I want to reissue that as it has been seen/captured.I'm working on Jamf Cloud, not on premise.I was thinking of Extension Attribute but found nothing helpful.Nothing either in Criterias (Smart Groups). Have an idea? Feature request? Truly,Danny P.
our users have to authenticate about 3 times during enrollment. 1st to authenticate / start enrollment 2nd time to create local account 3rd time to authenticate to Zscaler We use Entra as our iDP and everything is setup fine in JAMF Connect as existing users are able to authenticate to Azure without issue. Is there a way to have the Mac store the SSO credentials so it can be passed to other apps during enrollment? We are using Device Compliance...finally got rid of Conditional access..TIA
Hi everyone,I have just started my Jamf adventure and I've been working on disabling Chrome auto updating.We used a script which was removing a KeystoneRegistration.framework file and as far as I know, it worked well since the update, when Google changed/removed that file? I did some tests and check logs, and our policy which was using the above mentioned script stopped working 1,5 years ago, nobody must have noticed it. Anyway, I wanted to fix that but I have no clue, what else should I do.I tried to figure out, which option/file is responsible for the software update option and I found it's a Google Keystone file, I tried to create a profile with com.google.keystone where I used "updates are never applied" but nothing works here. Once Chrome is installed and I go to the chrome://settings/help, updates are being installed, no matter what.Any ideas how to stop it?I use a Enterprise Google Chrome downloaded from this site
As we migrated to the new Jamf Nation Community, you may have experienced a change in the badges associated with your profile. Please enter your information on this form to have your badges reassigned to your profile. Note: We do check our internal records to ensure the correct badges are allocated to your account.
Hello, community I have a faulty MDM configuration on one of our MacBooks. The enrollment was performed via the following command: sudo profiles renew -type enrollmentThe profiles have been created, but a message comes with:Registration with the management server failed.The update to an MDM profile contains different server URL. We have never received this message so far, nothing had changed. In the dashboard of Jamf pro, however, no management is possible for this device.the profile seems to be broken. In the administration, the points MDM remove or similar are not available. How can we remove MDM management via CLI and run the management again? We have already tried the following without success, the message remains the same and no administration is possible: Sudo jamf removeMDMProfile. — The profiles remained in place, a new enrollment resulted in the same error. A reset of the MacBook is out of the question. Greets
Hello all, I'm looking for the monthly enterprise channel for Office. We're updating our Office config profile and I can't seem to find the keypair. I suppose it may not exist... but I want to confirm that. :P Thanks!
So right now, I use dsconfigad to tell if a computer is bound to our AD, and while that works beautifully, it is not complete. For example, I can have ```dsconfigad -showtell me I am bound, but if the computer account has been deleted in AD, from the AD-side of things, -show will still tell me I am bound, though I will not be able toid $adUserName``` Does anybody have a better scripting process or workflow that gives me a truer idea of whether or not I am bound and fully functioning from a directory services standpoint to our AD?
I saw this on a blog this morning, posting here to raise visability.Much has already been written about the new monthly screen recording prompt in macOS 15 Sequoia. After a bit of research, there is a way to get rid of the prompts; kinda tacky, but does work.The good news is that there's a way to stop the prompts foreverdefaults read ~/Library/Group\\ Containers/group.com.apple.replayd/ScreenCaptureApprovals.plistThis file is protected by TCC, so to access it you'll need to grant Full Disk Access to Terminal app.{ "/Applications/Shottr.app/Contents/MacOS/Shottr" = "2024-09-21 12:40:36 +0000"; }In the plist file, the keys are the paths of the executable files with screen recording permission, and the values are dates. I'm using the Shottr screenshot tool as an example.To stop the prompts forever—for the rest of your life, anyway—set the date to far in the future, for example, the year 3024 instead of 2024.defaults write ~/Library/Group\\ Containers/group.com.apple.replayd/ScreenCaptu
For those who get logged out of Jamf School frequently I believe I have a solution for you. For anyone that has access to Safari for web browsing, I have found a way to quasi circumnavigate getting logged out randomly during the day/overnight with Jamf School. With Safari, load your Jamf School instance and sign in, be sure you're on the dashboard. Make the main page an "app" by going to File > Add to Dock or Share > Add to Dock. If anyone isn't aware, this will make essentially the Mac equivelant of a web clib from iPadOS and place it right in your dock, only to access your Jamf School instance. I have found that after not using for a couple days, I am still logged in and may only need to click on a sidebar item to "reload" Jamf School. During the day, usually I find I can navigate anywhere at anytime without being prompted for login credentials, and again, most I need to do is click on a sidebar option to reload Jamf. Been working without failure for the past coupl
Hi All, I'm deploying Logic Pro X in a multi user environment (AD bound Macs) for the first time, and am wondering how to make the experience as smooth as possible when a new user logs in for the first time. I think I'm fine deploying the additional content, but for each new user Logic prompts them to download it again on first run. If they press no then it finds the existing content just fine, but this is a student environment so I know at least some will just press yes and waste space (and time) downloading another copy of all the content for their account. Is there an easy way to skip this dialog on first run? If anyone has set up Logic in such a way before and has some pointers, it'd be very much appreciated. There are a couple of other things we'd like to achieve if possible, such as skipping the scan for audio units on first run, and the process of indexing apple loops on first run. Are these indices stored in specific files I could load in to the user template, thus skipping
Bonjour, L'option de restrictions des mises à jours aux administrateurs uniquement semble uniquement fonctionner pour les mises à jours mineurs (ex: 15.1 >15.2) mais pas pour les mises à jours OS (ex: sonoma > sequoia) est-ce normal ? Sachant que le but étant d'empêcher les utilisateurs de mettre à jour eux-mêmes vers les dernières versions de macOS sans notre autorisation, afin d'éviter les bugs possibles avec les nouvelles versions.
I've created a set of compliance rules based on CIS Level 1 for Sequoia, I've created guidance, and saved the settings. But the "Jamf Pro Upload" button remains greyed out. I've uploaded before with a similar workflow, but I can't get the button to become clickable. The guide doesn't mention what criteria is required to make the button usable. When creating guidance I've tried the viewing project button, and the upload button is still greyed out. And saving settings, and the upload button is still greyed out. Tips? Tricks? Suggestions? I /could/ manually upload everything... but why when there's a button to do it for me (supposedly).
We tried this and several other approaches to no avail, are there any currently-working solutions to change the keyboard input language programatically? #!/bin/bash # Script to set the default keyboard layout to British # Set the keyboard layout to British/usr/bin/defaults write com.apple.HIToolbox AppleCurrentKeyboardLayoutInputSourceID -string "com.apple.keylayout.British" # Clear the keyboard layout cache/usr/bin/defaults delete com.apple.HIToolbox AppleEnabledInputSources # Add the British keyboard layout to the list of enabled input sources/usr/bin/defaults write com.apple.HIToolbox AppleEnabledInputSources -array-add '<dict><key>InputSourceKind</key><string>Keyboard Layout</string><key>KeyboardLayout ID</key><integer>2</integer><key>KeyboardLayout Name</key><string>British</string></dict>' # Restart the HIToolbox process to apply changes/usr/bin/killall -HUP SystemUIServer echo "Default keyboard l
How do I generate an mdm profile to populate mdmProfileData for a return to service API call?https://learn.jamf.com/en-US/bundle/technical-articles/page/Return_to_Service.html#ariaid-title3
We are trying to change the MacOS Date & Time setting "24-hour time" on 15.2 via a script. There is nothing recent / working anywhere on the web. Is it impossible?
I have set up Cache Server 1 in City A, where I added the subnets of this location in the "content cache for" section. For my local network, I used the "custom public IPs" option and added a TXT record to the local DNS. This configuration is working as expected. Now, I am setting up Cache Server 2 in City B. The configuration is the same as in City A, ensuring that the subnets in City B fetch cached content from Server 2. I have also configured them as peers, with no parent settings in place, and both City DNS servers are synchronized with each other. Q1: How is data served to clients in City B if Cache Server 1 already has the same files? Q2: What changes should be made so that, in the event one server goes down, devices at both locations can still retrieve data from the other server? Additionally, while both servers are available, how can we ensure that devices access their respective server to minimize latency? Q3: How do peers work in this setup? If Server 1 has a file, does
I want to share a useful link,Jamf Youtube Channel has published,how to troubleshoot Configuration Profiles in Jamf Promake sure the Configuration profile you created is correct, sent to the Mac, and processed until complete, if not, you can find where the process stopped/failed.here is the link ( https://www.youtube.com/watch?v=c0r_fz4Kod8 )
We are trying to write a script to output all the active wifi and ethernet connections, if any, and turn off the wifi if there is an active ethernet connection. This is not working at all, because ifconfig is not returning the names of the connections (which may or may not be ethernet). networksetup -listallhardwareports is better as it displays the name of the "hardware port" but doesn't list the status. This seems promising but we haven't been able to use it in a script https://developer.apple.com/documentation/systemconfiguration/1517371-scnetworkinterfacegetinterfacety?language=objc #!/bin/bash # Define the names of the interfacesWI_FI_INTERFACE="Wi-Fi"ETHERNET_INTERFACE="Ethernet" # Check if the Ethernet interface is activeethernet_status=$(ifconfig "$ETHERNET_INTERFACE" | grep "status: active") if [ -n "$ethernet_status" ]; thenecho "Ethernet is active. Turning off Wi-Fi..."networksetup -setairportpower "$WI_FI_INTERFACE" offelseecho "Ethernet is not active. Turn
We have SSO policy that runs at every network change to reestablish the key, with documentation from Apple. This was setup prior to me supporting. The problems is, that it runs and reestablishes the SSO, but in the logs, it shows a network error. When that happens, it prevents any other policy from running other then self service policies until the user restarts their mac. It doesn't happen on all devices, it's pretty sporadic. We only find out when we notice updates not installing. When you go to the device, the only policy that runs over and over is out SSO Policy. Here is the script that runs in the policy. #!/bin/bash killall AppSSOAgent sleep 10 app-sso -a "oursite" -R -q exit 0 Here is our Config Profile.
We work in an area where users do not have admin rights, so I put together this script that allows them to remove apps from the main /Applications folder. You can control which required apps cannot be removed: Link to my Repo: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/AppDelete #!/bin/zsh # # App Delete # # Written: Aug 3, 2022 # Last updated: Dec 21, 2024 ###################################################################################################### # # Gobal "Common" variables # ###################################################################################################### LOGGED_IN_USER=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) USER_DIR=$( dscl . -read /Users/${LOGGED_IN_USER} NFSHomeDirectory | awk '{ print $2 }' ) SW_DIALOG="/usr/local/bin/dialog" SUPPORT_DIR="/Library/Application Support/GiantEagle" SD_BANNER_IMAGE="${SUPPORT_DIR}/SupportFiles/GE_SD_BannerImage.p
Hello everyone,After looking around for a little bit, borrowing from a few forums to make a script that adds exceptions to the popup portion of Safari's settings. I thought I would include this for anyone who would want to add it. Keep in mind this particular script is made to run on check-in. During my testing i was running through self service or a custom trigger via terminal and i came across errors trying to get terminal to call the custom trigger. Custom triggers + this policy will not work unless you grant terminal Full disk access. #!/bin/zsh # Quit Safari to ensure the database is not lockedkillall Safari # Add or update site entries in Safari's PerSitePreferences.dbaddOrUpdateSiteEntries() {for site in "${PUsites[@]}"; do# Check if the site already exists in the databaseexistingEntry=$(sudo -u "$loggedInUser" sqlite3 "$db" "SELECT preference_value FROM preference_values WHERE domain='${site}' AND preference='PerSitePreferencesPopUpWindow';")if [[ -n "$existingEntry" ]]; then#
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!