Get Support
Recently active
Hello All,Please help me with a solution where we can hide or remove the unwanted tunnels list in the CISCO AnyConnect VPN Window.I would like to remove/hide Web Security, System scan or AMP etc.
May be a silly post but I thought I post here for some ideas if any. So i been tasked to create a green colored folder on users desktop that contains "X file". I can get this working on my local system but when I package it and deploy it to another system when the folder installs on the new system the color reverts back to default. Basically it seems like the custom folder color settings don't carry over. I've tried installing the folder in a shared location then creating a colored alias still no go. I've also tried creating a custom green icon folder and trying to redirect that icon to the shared folder location but even that is proving to be challenging. has anybody ever had to tackle a silly task like this? I've been at it for a few days already maybe I'm overthinking?
Now that Jamf Pro Admin is no longer available, is there a way in Jamf Pro web portal to upload a new .pkg file that replaces a current .pkg in an existing package? I don't see any way to do this. This was relatively straightforward task in Admin, but it seems like you have to create a new package every time you need to update a (non-Apple or non-Jamf App Store) package? I have multi-package install policies which include a dozen or more packages, which all would need to be modified every time a new package name gets added/removed? In the past, when the package name could remain unchanged and you could just update the underlying .pkg file, there was no need to worry. Am I missing something? TIA,Jim
Is anyone else seeing this problem? I can't edit the Mac app descriptions any more under Self Service. iOS still works fine... I confirmed this on multiple JAMF instances.
Hi everyone, Does anyone have experience switching Apple accounts when renewing a VPP Server token? What is the impact on applications? Can we have more than one Apple account for the VPP Server token? Thank you.
Hi all, can someone confirm this for me, (those who use sandbox) Does this have it's own JCDS?? so, if i connect via the sanbox, it's not conecting to our live cloud jcds?? TIA
I'm trying to block a specific extension in Firefox. It works if I block all extension, but not when I reference the specific extension ID. I confirmed that the extension ID is correct. Any suggestions? <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>EnterprisePoliciesEnabled</key> <true/> <key>ExtensionSettings</key> <dict> <key>{87677a2c52b84ad3a151a4a72f5bd3c4@jetpack}</key> <dict> <key>blocked_install_message</key> <string>Extension blocked by Security Policy.</string> <key>installation_mode</key> <string>blocked</string> </dict> </dict> </dict> </plist>
Our environment runs JAMF and azure to pick up device compliance, JAMF connect status was "terminated" in Entra ID this has been fixed just wanted to know what could cause this?We followed these steps to fix: https://learn.jamf.com/en-US/bundle/technical-paper-microsoft-intune-current/page/Migrating_from_macOS_Conditional_Access_to_macOS_Device_Compliance.html
In Apple's macOS Sequoia 15.0 release notes the following is mentioned: "Executables, scripts, and launchd configuration files can be installed using MDM and stored in a secure and tamper-resistant location." How does this work in Jamf? I have searched but could not come up with the answer. Has anyone been using this and if so how do I configure a tamper resistant location?
Last week I set up the conditional access integration with Jamf, 2 test machines were added successfully, JamfAAD popup appeared and I was able to go through the authorization process in the keychain, then I registered another 10 machines, this time of other employees, but as I assume due to the fact that their main browser was not Safari, they did not receive a JamfAAD window during registration.I thought that if they do it later (when logging in, for example, to office.com, mac asks for a certificate) there will be no problem, but today, after the weekend, I noticed that the machines do not report their status in Intune, as shown in the screenshots, the first one is my test Mac which I managed to add successfully, the second is another employee who does not report the status, does anyone know how can I fix it? Today I decide to make some test with some custom settings for SSO Extention & JamfAAD, but as you can guess popup window still did not show up. My mac
So I’m sure you folks are familiar with typical Safari behavior on iOS. You can put in a search query on the same place as the URL bar. A student puts in an inappropriate query and taps Go. Google lists safe searches but isn’t always perfect. When it is not our web filter catches it. You tap on an unsafe one of them and our web filter blocks the page. The problem comes with image results and their previews in the search results. if I tap on one of those results that is inappropriate, our web filter blocks it. However, you can still see the thumbnail preview. Today that occurred for a child whose mother happened to be somebody important. Mother was very angry ‘at what her child was exposed to,” pointed out that our district has very strong filtering in her classroom and why is her kid able to see such things. She plans on asking this question of district school officials. Between the network guy and myself, We traced it down to these image previews. Network guy trou
Greetings admins! I wrote a custom migration script that reads several aspects of the users home folder and backs them up to a user specified destination. That part seems to be working OK, but when I go to write this data back to the same locations on the user's new system, it needs full disk access to work. My idea was to have the script run directly from Self service (Policy > script execute), but in order to do so, Self service needs full disk access to be able to write back to the users Library folder. What PPPC do I need to create to allow Self service to have full disk access?
Hi Encountered an weird case on some devices, after enabling internet sharing, the hotspot is unsecured even if i did set up a password for it. Does anyone have any ideea on what i could try? I'm not even sure where is that password, or the internet sharing config is usually stored.
signed inn this morning after my upgrade and saw this warning Duplicate email addresses found Jamf Pro detected one or more accounts using the same email address. Jamf Pro will start blocking SSO access for accounts using duplicated emails when Jamf Pro is configured to use email as Jamf Pro User Mapping. To ensure all accounts can sign in, check that no accounts are using the same email address in User accounts and groups not sure i like this at ALL
As the title implies, When setting an app inside of the App Installers to "on-demand installation", I am not seeing them in the JAMF Kiosk on a device. I have a user assigned, and I am seeing other "in house" applications, but App Installers are missing. If anyone else seeing this?
Hello,I am looking to see if anyone has a way to have Responsdous Lockdown Browser to be able to install and auto-update when a new version is released. This would be used for the schoology and college board (AP) versions of the application. This app would be managed on MacBooks to where the end user (student's) are standard users. I have looked at installomator but unable to find where someone has added a script for respondous lockdown browser. Thank you for your help.
People ask me all the time what the most significant difference is between supporting an MDM for Macs and supporting Windows. I’ve thought about the answer a lot, and it comes down to the collaborative nature of the Apple support community. One underrated community aspect is the sheer number of open-source tools available. The sheer number of tools freely available by the community for the community is amazing! As admins, we strive to make endpoints more secure and streamlined. This often requires acquiring new products and services. Still, it often comes down to Finance signing off on the expense and information Security, ensuring it doesn’t do anything improper with the data. Management approving the implementation of a new tool, not to mention your time making a Proof of Concept (in non-production of course!). This often comes alongside dealing with account representatives, solution engineers, and a slew of other hurdles they are concerned with. Enter open source! I used
Has anyone else run into this issue? It seems to be happening more and more to the point where most apps aren't installing. The weird thing is, this doesn't happen on all iPads, they will be the same type and the same iOS. Also, it's not the same apps that have the issue. I tried wiping them, connecting to a different network, renewing the VPP token (it was almost expired), updating the iOS, and creating a new policy. There are plenty of licenses available. I'm fairly new to JAMF with only the 200 experience so I'm sure it's something dumb that's causing it, I just can't figure it out.Any help would be greatly appreciated!
I am trying to get the Macro Security windows to look the picture below, currently it is fully greyed out and cannot select "Disable All macros without notifications" This is on office 365 for Mac Ventura. I have tried the command lines using JAMF with the line below but still no help. Any ideas to how to get the pop up your macros are disabled every time the user opens a word document would help. Thanks. defaults write com.microsoft.office VisualBasicMacroExecutionState -string DisabledWithoutWarnings
Hi, We have an iPhone 6 that is registered with MDM through JAMF. Unfortunately the passcode is currently unknown and at the same time the device is not connected to any wifi or mobile data connection. This means, we cannot reset the passcode via the MDM and the iPhone is completely stuck. To add to the fun, the phone has been taken to a different geographic location so cannot be connected to the computer with the JAMF to reset that way. There is nothing important on this iPhone so a complete reset would be fine with us, if it allows the passcode to be reset and the phone to be connected to wifi. Will erasing it using recovery mode using iTunes on a different computer do this trick? The device is not set up with an apple ID so that shouldn't be an issue. It is just the passcode on the lockscreen. Any other ideas of how to unlock this iPhone or get it connected to the internet so we can push commands through the MDM? Many thanks for any help!! Ronja
I am looking to identify shared computers by creating a smart group that detects more than 4 local user accounts. It is not a sure fire way to know if they are shared but that works for us. My idea is that the smart computer group criteria is "computers with more than 4 local user accounts" Is this possible?
Hello, I am creating a new configuration profile to apply a new hidden SSID to student iOS devices (ipad 10th gen) in which we plan on utilizing. The SSID is hidden and not broadcasting, and has been tested with several clients without the profile applied. Clients alone don't have an issue connecting after manual entering the hidden network information. After creating the wifi payload configuration profile with the correct scope, devices receive the "managed network" payload but it does not show as a selectable wifi name under the wifi network settings on the ipad. Hidden network and Auto Join have been selected within the wifi payload configuration on JAMF's end. Am I missing something? I am not sure why the ssid is not a selectable option on the ipad, but still shows as a managed network when you head to edit the device wifi networks. Any help would be appreciated, thank you very much!
Just thought I'd loop you guys on a nice tool. If you're here, you're running an MDM with probably a high amount of Apple devices. Your enterprise is then too probably running macOS caching servers to save on bandwidth etc. Currently there's a couple widely used tools for monitoring your caching servers like ErikNG's Cacher (https://github.com/erikng/Cacher) and krypted's precache (https://github.com/krypted/precache). Just wanted to let you guys know about one more that I found particularly helpful. Netdata (https://github.com/firehol/netdata) by ktsaou at Firehol is a free/great tool for monitoring all types of Linux/Unix type devices. It also can monitor some more basic functions of macOS machines. Recently he assisted me with writing a plugin to also help with monitoring the caching function on our caching servers. (https://github.com/firehol/netdata/issues/2766) This in conjunction with prometheus and grafana, has allowed me to monitor historicals, create alerts when something
Hello everyone, We want to put the shortcut for screen recording in the notification center on our managed iPads. It works on some, but you can't customize the Notification Center on most of them. They all have the same profile with the same restrictions, but I can't find an option to allow the customization of the Notification Center. The iPads are all personalized and not shared iPads. I've done some research, and currently, there seems to be no way to manage the control center settings with Jamf School. Is there another way to enable screen recording for our students without a third-party app? If not, can you recommend a free & easy screen recording app without the need to log in or register? Thank you for your help!
I've setup an API role to Read Smart Computer Groups + Read Static Computer Groups but when I try the script (at bottom) following I get this result:- Access token obtained successfully. { "httpStatus" : 401, "errors" : [ ] } I'm fairly new to the API side of things so might be the script is inaccurate. My Questions are:- 1) If I go to JAMF_PRO_URL/Api what do I put for username and password (screenshot below)? Is this an account that has access to the Jamf Pro instance or should this be client id / secret or something else? 2) What privileges do you need as a user in Jamf Pro to be able to run these API calls? 3) Is there something wrong with the script below? If I do echo "$access_token" should it show details or would it be normal to get a response like "Could not extract value..." For the script below I changed JAMF_PRO_URL to URL for Jamf Pro instance and CLIENT_ID + SECRET to details of the API Client. #
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!