Get Support
Recently active
I know there are more questions about this, but there is no clear answer and every now an then i guess any Jamf admin will run into it. Can someone point me in the right direction when command like removing config profles or assigning them to a macbook are just stuck at pending. The device seems to report in with inventory and check ins as expected, but i feel something is just waiting for failure. Any help or experience would be helpfull Thanks!
At Jamf, we’re passionate about helping our customers succeed. That's why we’re thrilled to announce Jamf Nation Rewards – a new program that (you guessed it!) rewards our you for engaging with Jamf, and your fellow community members. And it’s super simple to join! Step 1: Log into Jamf Account (computer)Step 2: Click Enroll on Jamf Nation RewardsStep 3: There is no step 3! 😉 Step 1: Log into Jamf Account (mobile device)Step 2: Navigate to the drop down menu (top right hand side)Step 3: Click ProfileStep 4: Click Rewards and follow the steps to enroll! Once in the program, you’ll earn points for a variety of interactions – both in and outside of Jamf Nation. The more points you earn, the more rewards you can claim. And yes, you can rank up! Earn more points, climb to a higher level. You may even reach Yottabyte! Learn more about the program here. Have a blast! And as always, thank you for being a valued member of our great Jamf Nation! *Please note – This program is for existing custo
I have been testing this Configuration Profile for PrinterLogic Chrome Extension. It does install and grays out the toggle so the end user cannot remove. The issue I am having is if I remove the device from the Configuration Profile it will remove from the profiles section but the extension still shows in the Google Chrome Extensions. It is also still grayed out. I have restarted Chrome and the device. Removed Chrome and reinstalled. Anyone have any ideas? <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>ExtensionInstallForcelist</key> <array> <string>bfgjjammlemhdcocpejaompfoojnjjfn;https://clients2.google.com/service/update2/crx</string> </array> </dict> </plist>
Hello there. I just started using Jamf and I love it. Historically we have made all users a local admin on their machine. Now that we have Jamf in place, we want to remove those rights. But there are some dev users who will still need local admins so we set up a second log in for those users. On the windows side of things, I created a GPO that checks an OU for a security group "computername_Admin" with a single user in that group which grants local admin rights on that one machine. Is there a way to do that same thing with Jamf? Since all users are created as mobile users, the other idea was to create a script (which I am horrible at), that revokes admin rights from all mobile accounts, unless the account name has a ".la" at the end of it.
What is Sovereign Cloud in the Setting > Global > Device Compliant used for?Is it just a text box that we enter anything or leave blank or the connection setting to ITunes
Guys, In my environment I got 85 devices enrolled in Jamf using User initiated Enrollment because my organization did not have ABM and that's why user initiated enrollment did for those 85 devices. Now my organization going to bring rest 30 - 40 devices unmanaged devices to jamf through ABM by enrolling through ADE. In case If I bring those 85 devices to ABM and assign the ADE profile to those 85 devices, shall I run the reenroll command to enroll through ADE or I've to do the factory reset and initiate the ADE. Kindly advice
Jamf Connect has been working in our environment for a few weeks, but we've run into some issues with MFA with security keys.On a computer undergoing prestage enrollment, an SSO window appears prior to configuration. MFA works without issue. After prestage completes, the SSO window appears again. At this point, it should be creating the local account, and connecting to AzureAD. However, if the account is authorized to use a FIDO2 security key, the MFA page will hang.Following this guide, I was able to get MFA working successfully for most logins without issue even with a security key authentication available except when logging into the computer. For all other logins, I don't run into any errors on MFA unless it's when I actively choose Windows Hello/Security Key.
Hello everyone, Has anyone had any luck setting up Global Project for iOS ? After an exhaustive search of PA Networks support documentation I have been unable to locate any documentation that is specific to installing and configuring Global Protect for iOS using Jamf. MDM software. The only relevant documentation that PA Networks provides is specific to Airwatch and inTune , however there is nothing specific to Jamf and I'm beginning to think that perhaps Jamf is not supported based on PA Networks MDM support page, included as a reference. https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/mobile-endpoint-management/set-up-a-mobile-endpoint-management-system/manage-the-globalprotect-app-using-a-third-party-mdm/always-on-vpn-configurations/configure-an-always-on-vpn-configuration-using-airwatch/configure-an-always-on-vpn-configuration-for-ios-endpoints-using-airwatch
I'm in the process of getting back to testing OneDrive. If I have the default folder set, does this prevent the user from choosing a different folder? I did create a couple of documents and put them in Desktop and Documents prior to deploying OneDrive and the config profile. I have the below plist set and it pulled down all my files that are currently in OneDrive from all of my other testing. The files I added prior to setting up OneDrive don't have the cloud icon next to it. Does the below plist look ok? <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>DisablePersonalSync</key> <true/> <key>DisableTutorial</key> <true/> <key>DefaultFolder</key> <dict> <key>Path</key> <string>~/OneDrive - Home</string> <key>T
During prestage enrollment, the Macs are bound to AD and members of an AD group, tier2-users, is specified to be administrators. Local accounts are Mobile account enabled. However users of the group, tier2-users are no longer recognized as local administrators. I think this was working fine in Ventura, but Im running Sonoma now and all the local accounts are just recognized as Mobile accounts.
Hello, I work for a large Fintech company and currently we have our macs enrolled in their JAMF with all their security endpoints. The company I work for is splitting off from the larger company. Me and another guy have been building out our JAMF and it's going well, it's looking to go live May 2025 with some of the first actual enrollments as the migration kicks off but obviously will be testing it more thoroughly first. The discussion now is how to create the smoothest transition for the users. One method is to erase all the macs and have them enrolled clean in our JAMF. This is the one we want to do. The second method being pushed by the higher ups is to remove the JAMF framework, get all the security software uninstalled and leave no trace and make sure they all work. The issue with that one is we are not admins in the current company and do not have access to the removal of the security endpoints so we either need to ask for the all the passwords (not likely) or have
We are currently encountering a 500 Internal Server Error on the `/api/v1/computers-inventory` service, and the error is not detailed in the response. This issue is affecting five clients. When we query the endpoint: /api/v1/computers-inventory?section=GENERAL&section=DISK_ENCRYPTION&section=APPLICATIONS&section=USER_AND_LOCATION&section=HARDWARE&section=SECURITY&section=OPERATING_SYSTEM&section=EXTENSION_ATTRIBUTES&page=0&page-size=50 it works as expected. However, when we try to retrieve the next page: /api/v1/computers-inventory?section=GENERAL&section=DISK_ENCRYPTION&section=APPLICATIONS&section=USER_AND_LOCATION&section=HARDWARE&section=SECURITY&section=OPERATING_SYSTEM&section=EXTENSION_ATTRIBUTES&page=1&page-size=50 we are receiving a 500 Internal Server Error. Could you please assist us in resolving this issue?
I am hoping for a bit of guidance. I have used Jamf School in the past for iPad management but this didn't involve any integration with Entra or Platform SSO. I now have a provision that is entirely Apple, I know what I am doing with the iPads but they also have iMacs and we would like to be able to log into the iMacs with our Microsoft 365 accounts with SSO so that all Microsoft services sign in automatically, for example, Office 365, OneDrive etc. I have been recommended Jamf Pro and Connect for this purpose and currently have both on trial. I have an iMac that is enrolled into Apple School Manager and is managed by Jamf Pro. Jamf Connect is installed and successfully logs in using an Microsoft 365 account but does not SSO into portal.office.com, instead Company Portal appears asking for an email address and password. I have followed the following guidance https://learn.jamf.com/en-US/bundle/technical-articles/page/Platform_SSO_for_Microsoft_Entra_ID.html#concept-7900 Am I missing so
I've inherited a JSS from someone else and see steps detailed in link below to set up a JSS - GSX connection but in our case we will be renewing it — 1) are those same steps needed for that? Also 2) can the same GSX certificate once renewed be added to two JSSes? https://www.jamf.com/jamf-nation/articles/26/integrating-with-apple-s-global-service-exchange-gsx Thanks for pointing me in the right direction...
We have several policies, configuration profiles, and other objects assigned to a site. This site serves the same purpose as our 'Full Jamf Pro' and is therefore redundant. We want to reassign all the objects in the site over to our ‘Full Jamf Pro’ (site set to ‘none’). What’s the most efficient way to transfer everything to Full Jamf Pro?
Does any one happen to know how to structure a config profile for plist settings for Microsoft edge https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies The aim at present, is to enforce safe browsing, prevent incognito mode and prevent deleting browsing history. As this helps curb miss use of web browsing as kids realise, they can't hide where they have visited.
Part of our Mac hardening, we have to have the BT icon show on the menu bar. All our Mac's are mostly Ventura with a handful of Sonoma. I don't see anything in to Jamf to allow this. I have a command that when ran locally via terminal, it'll add the icon, but if I create a policy using the Files and Processes>Execute Command, it won't add it, but the according to the log on the device, it was successful. I've also tried using a script, but the script won't add it either.defaults write ~/Library/Preferences/ByHost/com.apple.controlcenter.plist Bluetooth -int 2
Job posting: "... You can write production-quality code for automation in Python, Bash, or similar languages" I've written some scripts, but nothing significant like the open-source projects we all use. I can modify what I need from other sources to get stuff done. What sort of 'production code' have you used or written? Where would I start to write something? Seems everything I can think of exists I'm not nearly experienced enough to contribute to nudge or super, etc. If you have a code repo, where'd you get the experience? I guess I'm having a rough day after being passed on job after job and the only factor I can figure is I don't have the programming experience as a sysadmin
I am having a little brain fart here, but I'm sure it's simple. When I run this jamf policy using the event flag from Terminal, it runs just fine (probably because it prompts for my credentials). But if I try to run it from self service, I get an error that a Terminal is required for the password. Script: #!/bin/bash #Find current logged in user loggedInUser=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) #Runs SysDiagnose as Current User su $loggedInUser -c "sudo /usr/bin/sysdiagnose -u -f ~/Desktop/" Error: I want users to have the capability to run SysDiagnose from Self Service, without it prompting for a password.
Good Afternoon All!I work for a school district, and I've kind of taken on the mantel of apple Sysadmin. We are a windows org, but we do have a chunk of apple devices managed with Jamf Pro/ASM. I am having trouble getting our WiFi payload working the way I want. Our windows devices are on AD, so everything is automatic, but I want our apple devices to be on the WiFi using an AD credential we made for this. That technically works, but whenever you first push that payload out you have to make a "Trust Exception" to connect to the WiFi. At the moment we don't have a clear way of getting these devices on AD, and I'm wondering if there's anything I can do or a Certificate I can upload with it to make the device automatically Trust.I don't have a ton of experience on the networking side of things, and not many of us do, so we're trying to figure this out as we go.I appreciate any helpful tips!
Hey JAMF'ers- Is there a good way to bundle multiple .pkgs into one pkg file using composer? So like say I have a bunch of instrument packs I've downloaded the .pkg files from the vendor and I want to deploy to some of our machines, is there a way to bundle those dozen or so pkgs into one pkg file using composer?
My district currently uses JAMF School and I am pretty familiar with the Teacher app and have several teachers using it consistently. My question is if we were to upgrade to Pro are there added features within the teacher app that would benefit our teachers? We are trying to gather as much information as possible from people actually using the product to make an informed decision on whether an upgrade to Pro would be worth it for our district.
I am a system administrator for a school in Germany. We have received a ton of IPads this Year where the MDM was an old version due to it still allowing the App Store and removal of the MDM.We have already tried many things like resetting it or contacting the City Administration but nothing had worked until now. If you could help me that would be very kind of you
We have a user who wants to run iMovie and Music on an iPad managed by JAMF. They want to make promotional videos with iMovie and use Music to create playlists for events at our on-campus art museum. Both require the user to sign in with an iCloud account to launch the App (correct me if I"m wrong, I'm not a wiz at all this). I don't want to encounter Activation Lock with this iPad so I'm wondering if a Managed Apple ID is the solution or if an email address that we create for the user (and know the password once they use it to create an AppleID and iCloud account) is the correct method. WWW research has not yet revealed this particular situation; can someone wiser than me offer help?
Hey all, got a question for you. We have recently been using Jamf on our clients' Mac devices. However, we have been using ncentral for years now. We love the ncentral agents' ability to monitor device statistics and the alert board for issues. My question; can we install the ncentral agent via Jamf Policy? The research I have done so far has indicated they are competing for products. I am still planning on testing this but wanted to see if anyone else had already gone through the process and can tell me if I am on a doomed quest or not.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!