Get Support
Recently active
Is there a way in self service to update spotify automatically. Or at the very least package/script the policy to always pull and install the latest version?
Dear jamf nation, please add the ability for us to block certain members
Has anyone managed to get around the "403 - INVALID_PRIVLEDGE" error when trying to use the API? I created several API roles that basically give read privilege to every single thing that Jamf Pro allows you to assign read access to, then I assigned those roles to an API user. I'm able to create the token from oath2 and use it to hit various endpoints, so I know that this user's credentials and my basic setup are correct. The API does return 200 OK codes and I get data back. However, when I try to hit any version of the computer_prestages endpoint (v1, v2, v3) I get { "httpStatus": 403, "errors": [ { "code": "INVALID_PRIVILEGE", "description": "Forbidden", "id": "0", "field": null } ] } What is an invalid privilege? It seems different than insufficient privleges.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server [PI122416] When creating or modifying a configuration profile with a VPN payload that uses "Password" for the User Authentication type, Jamf Pro now correctly creates the profile with a valid AuthenticationMethod key. [PI123933] Jamf Pro no longer fails to display the scope for newly created deployable objects and saves scoping changes for existing objects as expected. [PI124225] Upgrading Jamf Pro no longer unexpectedly alters the required privileges for the Jamf Parent and Jamf Teacher apps to function. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox e
In our efforts to demonstrate our commitment to transparency and the safeguarding of personal information, we are providing you with the following important update around the use of AI within Jamf. We’ve updated our Privacy Notice to clarify to customers how we use the information you share with us to inform our AI product features. Performance and usage data may be used to support AI features, such as knowledge-based insights and advanced query results, however, we do not use any personal data to train our AI models. This change is effective December 19, 2024. If you have any questions or concerns, don’t hesitate to contact our Privacy team at https://www.jamf.com/trust-center/privacy/ or privacy@jamf.com
My school district has Apple TV's in classrooms, and we're trying to prevent our managed student iPads from being able to AirPlay to them. On the student device profile, we have AirPlay restricted to only known AirPlay destinations, and we left the destinations empty so that they have none available. This isn't preventing them from being able to AirPlay to the Apple TV's. They can still AirPlay with the code that appears on the AppleTV. Is there another setting we're missing? We need to keep our student and teacher iPads on the same WiFi network for Apple Classroom, so using a different network for the student devices isn't an option for us. We'd also like to avoid putting passcodes/passwords on the AppleTV's because we have many teachers who travel to different schools and classrooms. We could possibly start configuring Apple TV passwords with a similar convention, but sometimes when we do that, we just find it publicly posted in class
We're excited to announce with Jamf Pro 11.13.0 Beta the compliance benchmarks capability is available for testing. A full version of compliance benchmarks will be available in a future release of Jamf Pro. The Jamf Pro 11.13.0 Beta also features Jamf SSO, outbound communication for AD CS integration, a new collapsible sidebar and more! How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hello My Beta server is still on Version11.12.0-b.1.t1731093179Can some push it to 11.13? Beta Region us-east-2 Version 11.12.0
Does anyone have experience with this product from ManageEngine? https://www.manageengine.com/products/self-service-password/mac-os-x-login-agent.html They offer a Login Agent that allows AD password resets from the login screen. I have some concerns about FileVault (won't work with FV2 enabled) and compatibility (it will break every time OS X is released) but otherwise it seems reasonable. Anyone using this?
Hi all,Jumping into this can of worms. I run MacOS classroom environments in higher-ed with around 100 computers. So far each year the fall release of a new major MacOS comes with challenges and feature breaking in our rather "custom" setup. Looking into the coming Fall 2024 releases, I'm most concerned about the ability to disable and manage features with the beta Apple Intelligence. AI/LLM feature sets are cool, but they are still a wild-wild-west hazard in education environments.I figured I'd post here and see whether anyone has some inside information on whether these features will be immediately configurable by admins. Anything obvious I've missed so far? Has this information just not been released?Thanks!
Hi Jamf Nation, We are a group of companies and I have configured multiple sites for each company. Now I want to enable SSO for users so that they can use that to enroll their device (user initiated enrollment). While enabling SSO, I noticed that I am able to enable SSO for only one domain. How I can configure multiple domains for SSO in Jamf Pro? I am a newbie, so pardon me if I asked a silly question. Thanks in Advance
Hi All, This worked for me...Hence I am sharing this to all the admins out there who is looking for a permanent solution of never ending AD Password Sync Issue with FileVault..First let's spit the scenarios..Scenario 1 (Mac User who is aware of his/her old AD password) FV2 EnabledScenario 2(Mac User who is not aware of his/her old AD password) FV2 Enabled Scenario 1:-(Mac User who is aware of his/her old AD password) FV2 enabled Step 1 - Check the Securetoken status of the AD Mobile Account sysadminctl -secureTokenStatus username_goes_hereIf it's disabled follow this article to enable the secure token https://derflounder.wordpress.com/2018/01/20/secure-token-and-filevault-on-apple-file-system/By any chance if you receive any Operation not permitted error while enabling securetoken. Simply go to system preferences>Security & privacy > Unlock using admin credentials > Select Filevault > You will notice the following Alert "Some users are not able to unlock the disk |E
Unfortunately, we didn't catch the new iCloud preference pane in time, allowing some users to sign in despite us not wanting them to. I have tried deleting MobileMePreferences.plist as well as anything in ~/Library/Preferences/com.apple.[anything iCloud related] as well as ~/Library/Caches/com.apple[anything iCloud related], perform a killall cfprefsd and killall finder, and unfortunately, these methods no longer work in Catalina. I have looked through a number of posts on here, however, there isn't a thread modern enough that addresses this issue in Catalina. How can we force a log out of iCloud in Catalina remotely? We are already able to address the System Preferences issue.
We keep getting the 'Server session invalidated' error on most commands sent out to this specific iPad. Has anyone seen this before or know how to fix it?
We have a restriction on icloud and Siri for our Mac laptops... Some users are consistently getting a message similar to- "You do not have access for Siri permissions, contact the person who created your computer." How can we turn off notifications?
Hi All Does anyone have updated version of loopdown script by carlashley. Not conviced Im using the right one from github. Thanks
Might anyone have any tips on how to better handle some of our popular apps like MSFT Authenticator, Outlook, and Teams that were deployed with the Remove on Unenroll restriction set to on? With a migration coming up we would want these apps to remain on the device through a soft MDM wipe. We may be looking at a complete removal/uninstall/reauthentication of the applications which is not a fun user experience. I will be testing a few more scenarios but want to make sure I’m not missing something. Thanks in advance.
We seem to have Macs already enrolled being added again into Jamf somehow, but since the entry is already there it overwrites the original hostname and adds a () at the end. These Macs are not being enrolled a second time, this appears to be random duplicate entries. A fellow jamf/mac admin I work with had this happen to his mac today and he had done nothing out of the ordinary to it, so we searched and found several entries shown below. I did a search for (1) - (10) and found multiple for each. XXXXXXXXXXC32P (10) XXXXXXXXXXXJT4 (2) XXXXXXXX647 (2) XXXXXXXXYWP (2) XXXXXXXXXX9VH (2) XXXXXXXXXNL9 (2) XXXXXXXXGH5 (2) XXXXXXXW9QG (2)
I currently have the script to try and uninstall python3 in Homebrew: sudo brew uninstall python3 and keep getting the error "sudo: brew: command not found". I've also tried the command /opt/homebrew/bin/brew uninstall python3 and run into the error "Running Homebrew as root is extremely dangerous and no longer supported.As Homebrew does not drop privileges on installation you would be giving all build scripts full access to your system." I'm certain that Homebrew and python3 (via Homebrew) is installed on the device I'm pushing this script to. Is there another way I should be running uninstall commands for Homebrew?
Hello,I am getting this message when I attempt to uninstall or install Netskope from Jamf, which prompts me to elevate.I have given both the Netskope and the Remove Netskope Client full disk access.I am using the uninstall script for Jamf, provided by Netskope on their download page.I don't know what more I can do to prevent the pop-up. Help?
Just wondering if anyone has some experience with Analog Lab Pro (formerly Analog Lab V). It's for some fancy midi keyboards. (https://www.arturia.com/store/hybrid-synths/keylabessential49mk3) There seems to be a serial number and activation code needed for the software but they want to use them in classrooms so I'm trying to understand how the activation works. If they can all be activated through the same account, then that might work on multiple machines, just not sure. I just don't want to blow a bunch of codes finding out how it works.I have emailed their support too but suspected someone here might have come across this already.
We have Jamf LAPS enabled for a PreStage account and a jamf binary account. For an unknown reason the PreStage account keeps getting locked out and requires a password change. When I run this command: usr/bin/pwpolicy -authentication-allowed -u prestageadminuser I get this return: User <prestageadminuser> is not be allowed to authenticate until password is changed: Credential verification failed because account is temporarily locked. Sometimes I get this return User <prestageadminuser> is not be allowed to authenticate until password is changed: Password change is required by authentication server. I've gotten this result with and without a config profile for passcode. From the terminal sometimes I am able use the command "login prestageadminuser" with theLAPS password and it will prompt me to change the password. Sometimes it does not take the LAPS password at all. I do not have any problems with the jamf binary account LAPS.
Has anyone recently packaged Nvivo 14.I have captured the application and sorted out the license side of things and the PPC config required.Have people come accross this issue NVivo 14” cannot be opened because the developer cannot be verified.Appreciate this can normally be handled by excepting it from Privacy a security window. However this isn’t really workable for a full site deployment. Has anyone found a soultion to this I think it maybe how Im packaging it.ThanksTom
I just wanted to post this as it is an inconsistent issue I have come across. When a user changes their password using Jamf Connect, sometimes the 'New' Outlook for mac does not sync the change. I have found that if you toggle back to the 'Old' Outlook for mac it will restart and prompt Single Sign-On for the users password and then will begin to sync the inbox. You can then switch back to the 'New' Outlook if so desired. Hope this helps.
Hi all, Has anyone attemped to push the ERB Secure Browser to MacBook Airs/Pros. I am using Jamf Pro and have created a PKG through Composer. I have successfully loaded it on to two computers. However, I get an error on other computers. They are all from the Monterey to Sonoma OS. The error is as follows: Attention Required Secure Browser may be running from the original file download location. This prevents certain functions, including automatic updates, from working properly. Move Secure Browser to another location such as the Desktop or the Applications folder. Mind you, this lands in the Applications in Finder. I had a faculty member also attempt to move it to the desktop but received the same error. Thoughts?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!