Get Support
Recently active
Was this a feature add that administrators have been clamoring for over other features or is this just another case of everything needs to have AI jammed into it?
Does anyone know how to get rid of this option? I'm not very techy, but my daughter keeps bypassing onto bad websites by using this option. I'm using an image off the Internet as an example but this is exactly what it looks like. Thank you 😊
Hello,New to jamf school, I followed this page to install adobe with our shared device licence https://support.jamf.com/en/articles/12335537-deploying-adobe-applications-with-a-shared-device-license-with-jamf-schoolEverything runs perfectly but there is one major problem : The apps from the jamf “Apps installer” are only in english even if the creative cloud app from the package made with adobe console is in another language (as there is no link between them, except for licence I guess, cause Creative Cloud doesn’t detect the installations made from “Apps installer”) Is there any way to correct this ?
Hello, We are currently working on configuring Jamf Connect to get away from local AD binding. I have the initial login to macOS working (Google SSO Prompt and Duo MFA is working well.) After initial account creation when you’re prompted by Self Service + to sync your Google Account password to your local account, that is where it fails. The error is: “invalid password.” In testing... any account outside or bypassed from Duo can query LDAP successfully. Accounts encompassed by Duo receive the same “invalid password” message via Self Service + or when running the LDAP query manually via terminal. I’ve already spoken with Jamf support. They did some minor config changes, log searching, asked me to speak with Duo and then resolved the ticket. I have a support request into Duo at the moment but haven’t heard back. I’ve looked through both Duo’s policies and in Google Admin and haven’t come up with anything. What am I missing?
Hello everybody !I’ve been looking around, but without finding any real solution. Add to this changes from Apple / Jamf so what worked before may not work anymore, and of course what didn’t worked before may now be fine.I would like what’s the best practice to install minor or major updates of macOS on Apple silicon computers. Actually, I’m working on 2 scripts: one that will download the updates and another one that will install them later. The problem is: users have standard user account and of course, admin credentiales are needed.I’ve read that mdm commands aren’t very reliable, but as the posts are now from months ago, maybe that it’s working as expected now. And about those mdm commands, I don’t know if it downloads / installs only minor updates, or if it will install major ones if available.I was thinking of having the credentials as parameters for the scripts, but is is secure enough ?A last thing to ask: is there a way to install updates at the computer’s boot ? My main goal i
Hi, we would like to add a watermark text in the background to all our prints. The solution should be distributable over Jamf Pro to our workers. Since now I tried to create this watermark with cupsfilter and ghostscript. Unfortanely both ways didn’t get the watermark in the backgrounds. Have anyone another idea? Best regards Korbinian Eigner
I thought I had this right, but I’m not getting correct results…..Processor Type - Like - AppleandArchitecture Type - Is - amr64andOperating System - does not match regex - ^26(\..*)?$Still finding devices running 26. Someone have a better way to write this?Appreciate any nudges in the right direction!
Hi all, I'm trying to upload a specific DMG file to cache to Waiting Room and run a simple script that just installs a PKG that has to be in the same folder as a JSON file. I believe the silent install script I have should work fine, it's just the actual uploading of the DMG file that has me puzzled. I've done this exact same thing with other DMG files that contained items inside (a .app file that I successfully moved to the Applications folder) but this is a PKG file alongside a JSON file which I assume has some kind of configuration it needs. When i upload the DMG in the Packages section, it looks like it uploads, I run the Cached command in the Policy, and I get a corrupted error: [STEP 1 of 5] Executing Policy FireEye Agent [STEP 2 of 5] Caching package Fire Eye Agent 32 30 13... Downloading https://use1-jcds.services.jamfcloud.com//download/012345etc/IMAGEHXAGENTOSX323013.dmg?token=012345etc... Verifying DMG... Error: Could not verify the down
Hi all, I was wondering if I'm the only one no longer able to load the https://macadmins.software/ site that was previously hosted by Microsoft? When I go there now from any device I get a GoDaddy page, so it looks like they didn't renew the site hosting perhaps? I used this site all the time to get the most recent packages for Microsoft software. Is everyone else seeing the same thing as me? If so, has anyone heard anything about this, if this will be coming back or if that's it? I know for a while now while the links all pointed to the most recent versions of software, the version numbers listed on the site were stuck on some old version from many months back, but it was still working to download the most current releases as early as this month.
We're in the process of getting ready to implement JAMF Connect for syncing local accounts with Entra. Our current Wi-Fi is 802.1x PEAP where users sign in with their username and password, which we were told is not compatible. We're looking into certificate based auth using machine certs, but haven't found a clear answer on how to make this work. Our PKI is Microsoft ADCS, so we run up against the strong mapping requirements. We don't have SCEP right now and we are hoping to not open anything for inbound communication as we don't host anything on site anymore and have no real dmz for hosting things. We also don't want to bind to AD as that's pretty terrible. Has anyone gotten this set up in a similar environment? Thanks!
We are trying to push out a profile to have our Mac's (in a primarily Microsoft environment) to auto join our 802.1x network. I have setup the Jamf ADCS and am able to push a device cert to the Mac's that I would like to use. I created a policy in NPS to use that cert for authentication that I would like to use but am getting auth failures. Any guidance for how to remediate this?
Hello everyoneMy context: wi-fi authentication based on 802.1x through a Windows Server (NPS). Computer certificates are deployed by Jamf (Configuraton Profile) and through the Jamf ADCS connector.Macs are not bound to the Windows domain but a computer object is created for every laptop (it's mandatory with a NPS server).Everything is working as intended. As you may know, in may 2022 Microsoft published an important security update that changes the way certificates are validated by domain controlers.https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16 A new extension identified by the OID "1.3.6.1.4.1.311.25.2" is now included in certificate templates, but only for the ones that build the subject information from Active Directory.Unfortunately, certificates issued through the Jamf connector are "offline", meaning that the subject information (CN, DNS name) are supp
We use jamf school to reset laptops in classrooms, everything is installed in nl_NL but all Adobe apps stay in english. If we create a dutch package in Adobe admin console and try to upload it in jamf we get a parse xml error. Tried all suggestions from AI but no succes..
Hello everyone, is there an API Call/Endpoint to disown Devices (ADE) in Jamf School?
Hey folks,We migrated from using policies onto using Jamf App Catalog to handle our standardize applications (Google Chrome, Mozilla Firefox, VLC, etc) for auto patching the latest builds and offering the software for workstations without the software to download from Self Service+.We’re looking into configuring Jamf Setup Manager, however since we do not have triggers from policies for software, I’m curious if anyone has found a workaround or best practice for this. I’m interested in hearing your thoughts, workarounds, and recommendations.Thank you,JG
Hey,I am just wondering if anyone else got the same expierence?After installing the latest DisplayLink Update, it turned out that the previous working configuration Profile is broken. Every time I open the Tool from the Apple Menu, the Splash Screen comes up again.This is the Profile in User Level (I tried also Computer Level) which worked fine on the previous version:PLIST file containing key value pairs for settings in the specified domain<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict> <key>AppAutostart</key> <string>1</string> <key>SilentSetup</key> <string>1</string></dict></plist>
I am having an issue that I think is somehow related to Safari and our proxy. We have had several reports of users traveling off-network and having issues with captive portals. The Captive Network Assistant.app window appears but it's blank and says: "The webpage couldn't be loaded". If I open Chrome or Firefox, and go to https://captive.apple.com then the Captive Portal appears and I can do whatever I need to access the WiFi SSID. If open Safari, I am unable to get to https://captive.apple.com. Has anyone run across this issue? I'm assuming the Captive Network Assistant is using Safari to try to show the Captive Portal...
The way JAMF displays my inventory requires me to scroll a lot to the right to find information on an asset. I would like to customize the order the columns are displayed. For example, Asset, serial number, building, and then room. Is it possible to change the order of the inventory display?
How can I make it so after a set amount of time the device goes to a app and the app can not be exited until you fill out a sign in and after the set amount of time it "Signs you out" bringing you back to the form. ThanksIan Nelson
Hello all, I know there have been a couple of topics around this already but I can't seem to find a solid solution for this. We are a university and have both user assigned and public apple computers and laptops. I would like todo one of the following:1. Prevent users from login into their personal apple ID's and lock the devices to only use our ITS apple ID (make sure they can not log out of it).2. Simply block the ability to sign into any apple ID.3. Force sign out users already signed into their personal apple ID's. I have tried to set this up using a configuration profile under Restrictions > Preferences but this does not work (once the profile is applied the section is still visible). I also don't like the restrictions method as this includes many other options I don't want to use (in Applications, Widgets, Media, ect).We are using Jamf PRO and Apple School Manager. Thanks!
Hi all,We have several Mac builds deployed across the University, with the majority of devices using a core “Staff” build within Jamf Pro. When we introduce a new build, we typically create a new PreStage enrolment profile and re-scope existing Macs to that profile. The intention is that if a device is rebuilt or reset at any point during its lifecycle, it will receive the latest build and updated setup experience. I assume this is fairly standard practice, and up until this point, it’s otherwise had no unintended consequences.However, something I’ve noticed this year is that Macs running older builds, but now scoped to a newer enrolment profile, are unexpectedly migrating.I’ve traced this back to the point where the MDM profiles renew on the client. During this process, the value of the following attribute in the computer record appears to be overwritten:Enrollment Method: PreStage enrollment = XXXXWe currently rely on Smart Groups based on this value to scope configuration profiles a
Does anyone have issues when using JRA with the users that have multiple displays?During a session it will swap between displays automatically, even thought I have auto switch monitor turned off.
With Jamf Pro 11.29, administrators can strengthen identity-first enrollment with a new Simplified Setup for Platform SSO workflow, scope devices more reliably using native directory service group criteria in smart groups, and enforce software updates via declarative device management on self-hosted instances.Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
We have a lab environment where we explicitly want the screen saver / display timeout to be a specific time, but we don’t want the user to have to re-enter the password when the display wakes / screen saver exits.When we set a Configuration Profile with a Security and Privacy: General payload, we can successfully set Require Passcode to Unlock Screen to enabled and set to a specific time (Immediately, 5 minutes, 8 hours, etc.), and this works as expected. But when we try setting it to “Never”, the target device updates and reverts to “Immediately”. I’ve also tried setting it to “Immediately” to see if “Never” and “Immediately” were just swapped in the Jamf UI, but that wasn’t it.I’ve also tried using a plist file in a Application & Custom Settings payload with a domain of com.apple.screensaver as detailed from Apple’s documentation.However, this doesn’t seem to work at all, and the settings don’t seem to take effect.<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist P
Taking a swing at the regex. How is this?macOS 27 Golden Gate (Regex Can't upgrade)^Mac(BookPro1(7|8),\d|(1(4,([5679]|10)|5,([36-9]|1[01])|6,[15-8]|7,[2-9]))|(1([56],1[23]|4,(2|15))|BookAir10,1)|(6,[23]|5,[45])|mini9,1|1(6,1[015])|14,(3|12)|1(3,[12]|4,1(3|4)|5,14|6,9)|14,8)$|^iMac21,[12]$
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!