Get Support
Recently active
It is good to be able to configure security in various aspects of MacOS using Jamf.However, one unfortunate part is how to solve DLP. There are several products for endpoint DLP or network DLP, but I want to implement DLP in a Jamf-friendly way and at minimal cost. The DLP I want is not to block file transfers unconditionally, but to examine the text in the document to determine allow/block. I also want to scan it when it is pasted into a web page. Is there a case where you use Jamf Security Cloud and Network DLP together? How do you implement it? How do you configure and operate it?We need your creativity.
Dumb question I have completed the migration to Device Compliance for Jamf and the migration script is working with no issues. However; how I can't seem to get it enrolled when it's a new device. What am I missing?
Hello, I've been looking through the documentation to determine if Jamf Protect scans downloaded files for viruses before allowing them to open and I can't seem to find a definitive answer. I know Jamf Protect focuses on providing comprehensive security for macOS devices, including real-time monitoring and threat detection. However, specific features like scanning downloaded files for viruses before allowing them to open are typically associated with traditional or next-generation antivirus solutions. Does anyone know the answer to this? Thanks!Matt
I have seen a few posts about getting a list of Chrome extensions installed but have not had any luck. Does anyone know of a way to generate a report of installed Chrome extensions?
Is there any way to block file sharing from mac to remote system via microsoft RDP?
Hi ! We are going to pilot TouchID in our environment icm with Managed Mobile Accounts, so currently all our macOS devices have an configuration profile where TouchID pane is disabled and also the features to unlock the mac. On my own machine i have removed that profile, and allowed TouchID.What happens is, the syspref pane got accessible again and all checkboxes also.When i configure a vingerprint and check the box and i am leaving the syspref pane and went back to TouchID the "Unlocking your mac" got unchecked again. Already done all basics like;- rebooting- re-enrolling into JSS- Verified the correct configuration profiles are deployed and no other one is also disallowing. Configured TouchID Went back to TouchID Syspref pane, and box unchecked Anyone ran into the same issue?
Hello! I used Jamf Compliance Editor to make a config policy to disable AutoOpenSafeDownloads, as part of implementing CIS lvl 1 benchmarks. I know Jamf Compliance Editor isn't supported, no worries, my question is more about conflicting config profiles! The result is a file named `com.apple.Safari.plist`. This file is very short, with only 1 option. However, `com.apple.Safari.plist` is a file that already exists - you can view the default settings with `defaults read com.apple.Safari`. My concern is: will having two config profiles with the same name cause issues? If I upload my new `com.apple.Safari.plist` to Jamf, and push it to a Mac, will it overwrite the settings specified in the `com.apple.Safari.plist` that already exists? Can macOS apply the settings from both policies of the same name, if one is applied through JAMF and the other is already on the machine? Thank you!! Helpful Info:In my `~/Library/Preferences/` directory, there is no `com.apple.Safari.plist`, but there is man
Hi all, I want to create a series of Smart Groups for the purposes of testing new software releases. I'm looking for about 3-4 groups. I'd like the groups to be made up of machines that don't all have a core attribute in common (such as OS version, model or processor type) - so a 'random' assortment if you will. Any ideas how I can go about creating a 'random' assortment of machines? - I tried using 'matches regex' to filter out serial-numbers with '1' in etc but didn't have much luck. I could separate into static groups easy enough, but was hoping the dynamic nature of smart groups would save me having to go back and update them as machines come in and out of our environment. Thanks for your time! Steve.
Hey everyone, I wanted to know what could be happening when a computer is getting turned on for the first time and it goes through prestage enrollment, and the login screen always comes up grey with the sign in at the bottom. We use Jamf Connect and with Jamf Connect 2.42 and 2.43 we have been getting a grey login screen, Jamf Connect 2.41 works fine but I am not sure why we are getting a grey login screen on the other JC versions.
Hi everyone, just exploring this and i just need to confirm a few things , if anyone knows that would be a massive help. I will get my hands on a device soon but i need to hit the ground running. So for vision OS 2 we do not need managed apple IDs anymore and it will work fine without for a prestage enrollment? Will i be able to hide bits and pieces from the set-up assistant? Lets say i don't want users to login to their personal apple IDs. The Prestage does not make any mentions of visionOS Can this be set-up as a shared device or is it not supported for VisionPro? Will enrollment customisation work ? Will i need any custom configuration profiles or will they just work from : Mobile Devices -> Configuration Profiles. I cant see what applies to visionOS only. Do i need Jamf Trust and Jamf Security cloud to keep these devices secure? I mean what is the best practice in terms of AV/EDR? Those who have implemented it, what has your experience been? Thanks
Does anyone have any experience with the Jamf Pro API and logging the movement of app licenses? My organization deals a lot with mobile device apps, and we are trying to find a solution to track the daily movement of licenses when they are checked in or out so we can cost them properly. The daily transactions are high, and we have a lot of apps. It's too much for one person to track so we need a robot.
Hi Chaps, Trying to create a DMG file to deploy that will install a safari shortcut to everyones desktop. Or possibly in the Applications folder, when I open composer and drag the Icon from my desktop in, it creates the folder Users>Simon>Desktop>GreyConnect.webloc Obviously not everyone will have a "Simon" user folder and I want it to go to theres, is there something like $username or something that will work and edit the folder named Simon? Thanks
Hello. I can get these commands and scripts to work just fine when running them locally on my Mac, but they seem to fail when getting pushed from Jamf.Scripts.1: #!/bin/sh defaults write NSGlobalDomain "AppleShowAllExtensions" -int "1" && killall Finder 2: #!/bin/sh defaults write NSGlobalDomain "AppleShowAllExtensions" YES && killall Finder Both work fine, surprisingly. Whether I run the scripts from Terminal, or I run the commands themselves directly from Terminal, it works both ways. But if I run either of the two scripts via a policy through Jamf, it doesn't work. The script runs and I see Finder quit/restart, but the setting for 'Show all filename extensions' does not change.I was going to try a Configuration Profile instead, but cannot figure that out. I had started something like this:Preference Domain: com.apple.finder <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://
I'm trying to get Jamf Protect offline client/policy talking from Mac to SIEM. It appears that protectctl is only useful with the full cloud product, or else my clients are broken. If protectctl needs cloud version, why is it installed on my Macs? And how do you debug without it. The files in the db folder are totally opaque for debugging. It appears that protectctl diagnose is also useless without cloud. Ideas?
Hello everyone, I would like to implement Installomator to manage the installation and updates of the applications I use, in order to streamline the process and avoid the repetitive task of manually searching for each package for every application. I watched the Patch That App Up (By Using Installomator) session presented at JNUC 2023. In the video, it is recommended to create a smart group based on the "Patch Reporting" criterion to identify devices running a version older than the latest available. Additionally, it is advised to create a second group containing the members of the first one, as Jamf does not allow targeting a group directly based on the "latest version" criterion. Is this still the best method today? Do you have alternative approaches to suggest?
Hello everyone, I'm looking for advice on how to integrate SwiftDialog with Installomator. When I update an application, it closes automatically without notifying the user, which can lead to the loss of their current work. Should I configure specific parameters when adding the script to the rule ? Modify the Installomator script directly ? Or use SwiftDialog to notify the user beforehand ? Thank you in advance for your help!
Getting back to testing OneDrive since we're moving to it this year. For the most part it looks like it's working, but one issue I'm having is, when launching OneDrive, it's not populating the email address on the first step. The below is what we have setup. We're trying to match with Windows settings are going to be, but it looks like some settings are available on the Mac side like, Continue syncing on metered networks Continue syncing when devices have battery saver mode turned on <dict> <key>DisablePersonalSync</key> <true/> <key>DisableTutorial</key> <true/> <key>DefaultFolder</key> <dict> <key>Path</key> <string>~/OneDrive - CompanyName</string> <key>TenantID</key> <string>ourtenantID</string> </dict> <key>AutomaticUploadBandwidthPercentage</key> <integer>30</integer> <key>Fil
Today we released an upgrade to Mac Endpoint Telemetry. The new version of telemetry primarily uses the macOS Endpoint Security API and includes updates for new and existing endpoint logging. The telemetry configuration page has been redesigned and now offers multiple event categories to choose from, allowing for more granularity and customization when choosing events. New telemetry configurations now automatically include both admin-level and user-level activity. This new version of telemetry provides unprecedented visibility into macOS systems, with a few examples being: User elevations Authentication Persistence creation System operations To learn more about Jamf Protect’s endpoint telemetry for macOS, visit our blog.
Hey there, I was wondering if there is an easy way to remove user-added web clips from the home screen, or preventing them from being added in the first place. I see that someone had asked this question a few years ago but there was no accepted solution from what I could tell. At my district we have 1:1 iPads in K-2 and it helps to have the layout configured so that our managed apps and web clips are where our teachers/student expect them to be. Sometimes a web clip will get added by a student/teacher and the teacher will want it removed, but they lack the permissions to edit the layout themselves. Jamf school does not have any way to view/remove user-added web clips to my knowledge. Is disabling the profile with the managed layout or wiping the device the only ways to circumvent this? Thank you! Ben
I haven't seen any documentation so I'm not sure if this is possible but I'd like to show days until password expiration on Jamf Connect Menu Bar. Does anyone have any info on how to do this if it is possible?
I am setting up Zscaler for my Org and this requires adding several processes to the MacOS native firewall. We are hoping to use Jamf for this however we seem to be limited by Zscaler not knowing the bundle ID of their products as well as the format not meshing well with the Jamf Firewall allowlist. Has anyone configured this in the past?I'm looking to allow the following: (from https://help.zscaler.com/client-connector/zscaler-client-connector-processes-allowlist)Zscaler: InboundZscaler: OutboundZscalerService: InboundZscalerService: OutboundZscalerTunnel: InboundZscalerTunnel: OutboundZscalerUpdater: OutboundUPMServiceController: InboundUPMServiceController: Outbound/Applications/Zscaler/.Updater/autoupdate-osx.app/Contents/MacOS/ZscalerUpdater: Inbound/Applications/Zscaler/.Updater/autoupdate-osx.app/Contents/MacOS/ZscalerUpdater: Outbound/Library/Application Support/Zscaler/ZDP/bin/zdpd: Outbound/Library/Application Support/Zscaler/ZDP: Inbound/Library/Application Support/Zsca
Today we released Jamf Connect 2.43.0; this release includes minor bug fixes and improvements. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hello Community, I am trying to install wazuh agents in our organisation's computers in an effective way, and i wanted to use jamf pro for this. Any one have an idea on how to do this? or any alternative way?
I've setup the "Device Compliance" in Jamf as well as the "Partners Compliance Management" in Entra ID successfully and syncs daily with Jamf. However, it appears that after a macOS device has registered in Entra ID, a day later it's no longer compliant and "MDM" is no longer reporting as "Microsoft Intune" but as "N/A". In Intune, all macOS devices are also not reporting any compliance status. Any suggestions?
Is anyone currently using Platform SSO, specifically with Microsoft as the IdP? I’m impressed with its capabilities so far, but I’m not entirely confident about deploying it just yet, as it still feels like an early-stage product. Initial testing has been positive—Kerberos tickets authenticate to all resources seamlessly, and much of what we rely on Jamf Connect and NoMAD for is covered. One issue I’ve noticed, though, is that Microsoft Teams prompts users to reauthenticate almost daily when using SSO—something that doesn’t occur without it. Has anyone else run into this Teams reauthentication issue, or have feedback on the overall stability of Platform SSO?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!