Get Support
Recently active
Hello,in our school, students can no longer create an Apple icloud.com account.I tested, with the latest update, without restriction, on two different networks, by changing the date of birth but during the configuration, I always have the same error message "unable to create the account at the moment".Do you have a solution?Do we have to use managed identifiers? Thnks for your help
We've trialled Platform SSO fairly successfully, I'd like to use this more broadly but have a user-friendly workflow which follows enrolment.Using Prestage enrolment with SSO for account creation, only to then follow a separate process with company portal to register the mac in Intune and complete the user integration seems a bit odd, to a degree a duplicate step. Has anyone developed a smooth workflow with platform sso integration and PSE?
Good morning, I'm looking for help on updating or new fleet of Apple Silicon MacBooks. We wrote a script that worked perfectly with our old intel MacBooks, but with the new Silicon MacBooks the scripts get stuck waiting for admin user or an user with secure token to input their credentials. I found that Jamf "Software Update" does not work well for our MacBooks in our environment. I found two scripts that works well with the new Silicon devices, but we still run into the issues with enduser having to type in their information. The scripts I used were S.U.P.E.R and Erase-Install I'm looking for a workflow like this if anyone has one. Prompts the user there is an Update Allow the User to defer if time is not right, but forces them after they reach their limit Checks to make sure MacBook is connected to charger Performs the update without needing users credentials Thank you guys in advance for any help or suggestions
Hey Community, I am facing an issue and need to identify the solution for that. I have couple of enrollment customizations which are working fine with PreStage enrollment. But I wan enrollment customization for user initiated enrollment. For example, I want to guide the users how to install the MDM profile once downloaded. But I can see enrollment customization works only with PreStage Enrollment. Any ways to achieve this for user inititated enrollment? Thanks in advance.
Hi all,So we are using the MakeMeAnAdmin script for almost 3 years without a hitch.Now we are having the first macoS 12.3.1 devices and the MakeMeAnAdmin script does not work anymore. On older macOS versions everything works fine.Anyone else experiencing this issue?
macOS 13.6Connect 2.29Azure/EntraLogging in seems to work fine. Once in, click on the JC icon > change password, box comes up with microsoft asking for our email address, enter and get redirected to our page, then a blank white box. At the bottom is our password change rules and a done button, but no place to change the password.Verified in the menu config that thechangepasswordurl = https://account.activedirectory.windowsazure.com/changepassword.aspxWhen I click on the url, I get to the page. Jamf Connect license is present in its own file.Any suggestions on what might be going on?
Has anyone had any luck getting these to work? or am i just doing something stupid?
Hello!We are using JAMF School, and I wanted to update the logo in DEP. Unfortunately, every time I try to change it in the settings under "Appearance," I receive an error with the following message:"An error occurred while saving - The following error occurred: Our development team is notified about this problem. Problem identification:" The size and format are correct, and the file is quite small. Are there any specific rules?
Hello,I've been testing how to recover a device in the case an employee logged into their iCloud account with their personal credentials on a supervised machine. I was able to successfully boot into recovery mode, erase the machine then after rebooting again use the MDM recovery key in JAMF to regain control over the machine. However, I tried another scenario where I used the personal iCloud account to remotely lock the machine. I was not able to find a procedure to recover the machine in that case.Is there a process for this, or is there a way to disable remote lock via iCloud in Jamf Now?
Hello everyone,We've been using Bitdefender in our organisations in almost five years now without and problems with the distribution/installation through Jamf. But recently it happen after updating the package. We get a result in the process bellow I don't really understand and don't know to solve.I would appreciate it if anyone knows what the problem is and hopefully how to solve it.1. Executing Policy Antivirus - Bitdefender2. Downloading antivirus_for_mac_arm.pkg...3. Downloading https://euc1-jcds.services.jamfcloud.com//download/952aecdf92e54c788e0e69144d29572e/antivirus_for_mac_arm.pkg?token=4937184d5be64b5d96ccb6c40b9d18cbxw42zber37n0ivx90oh2s2vii50bnmfg...4. Verifying package integrity...5. Installing antivirus_for_mac_arm.pkg...6. Installation failed. The installer reported: installer: Package name is Endpoint Security for Macinstaller: Installing at base path /installer: The install failed. (Installeraren stötte på ett fel som förhindrade installationen. Kontakta programv
Hello everyone, If a user restarts her Mac device and the computer does not recognize her computer password does that mean there is a a syncing issue with the local account password and the network credentials? What would be best practice to resolve this sort of issue?
Hello everyone, I wanted to know if there is a terminal command or best practice for dealing with a user receiving the image attached to the post.
Please join us for a Chicago-area Jamf User Group meetup! There will be food, drinks, networking, and great conversation. We plan to share insights into the latest updates going into 2025. Date and time: 4:30 p.m., Jan. 8, 2025 Location: Ditka's Oakbrook, 2 Mid America Plaza Suite 100, Oakbrook Terrace, IL 60181 We hope to see you! Register to reserve your spot now! LINK TO REGISTER: https://www.jamf.com/events/jamf-nation-user-group-event/
Afternoon All For those in education sector, how are people dealing with deploying the extra content for Logic sound loops etc.Packaging it unsurprisingly a none starter due to size. 68GB is way to big.Are there any good script out there? Looking around have only come accross loopdown https://github.com/carlashley/loopdown but loooks like thats been no longer developed.Just wondered if anyone had experience of this and has any tips/tricks to share.Thanks
Edge pin's itself to the dock on macos. I have to manually uncheck where it says keep in dock, however, I never wanted the app to pin itself in the first place. Is there a solution to prevent apps from pinning themselves to dock on their own?
I have a few remote users that do not have the best internet connections and they randomly complain that it has gotten worse. Are there any EAs or scripts that can help troubleshoot what is going on? The steps we start off with Reboot your Mac Reboot your router Clear the cache in the browsers Make sure you are not on the VPN Check to see if other devices in the house are hogging the network. Jamf also verifies updates are complete since they are standard users and not admins on our machines. We have also found disabling IPv6 helps with some sites. We have also disabled zscaler as a test and verified the firewall is not blocking the traffic. Our latest complaint said their internet really slowed down when they got the 14.7.2 update. I am putting together some EAs to see who they use for DNS and making sure we know which primary interface they use (most are wi-fi) in case it is a bum docking station. Any tips would be appreciated!! We are trying to craft
Hi all, I recently took over as the Jamf admin for my institution, and am trying to make sense of some settings that were enabled prior. In regards to this setting in Settings > Global > User-initiated enrollment > Computers:We also have a managed local administrator account created via PreStage. Would this setting enable SSH for both the user-initiated and PreStage managed local administrator accounts, or just the user-initiated only? I tried to find information about this in other Jamf Nation posts but couldn't seem to find anything - please let me know if I missed any helpful posts. I also tried looking at System Settings > General > Sharing > Remote Login while logged into each of the managed local accounts and did not see either of them listed as allowed users, though I understand this may not be visible by design. Thanks in advance!
This is honestly totally baffling me. Dock has been set with dock items using a configuration profile in our environment. To this day, these profiles are still configuring the dock correctly to newly deployed machines, with the dock items we set initially. Today I went to add a dock item only to see NONE of them listed. It's so bizarre. This very configuration profile is still setting dock items in on a test machine - but again, this policy seems to have NO dock items listed. Anyone seen this? See screenshot.
Is anyone using the following?Jamf Connect, Company portal to register devices into Intune, and using Microsoft Entra for the IDP.Using this method can you have devices binded to Local AD?Trying to find the best method to keep Mac user accounts and Entra ID credentials synced.
I got a macbook from my school, went into MDM profiles and saw the name Jamf like 4 times. I hope this is the right forum! So basically our school isnt that restricted when it comes to macbooks, they let us create our own apple accounts or login on already existing apple accounts, they heavily recommended that we logged in into our daily basis icloud accounts so i dont think they look into data on our macbooks so much because its literally our own account or i hope so. We can literally download almost everything on our macbook, and can play around on the settings how much we want. I ofcourse disabled the Screen time data on settings. But my question is if they can see our screen time on our macbooks and how much we been using it, ive been using the laptop very very very much, got so many hours on it. I just wanna see if the school can see that, even if they did, is it easy accesible or do they have to contact JAMF for SCREENTIME DATA? ( I DONT KNOW WHICH PRODUCT I SHO
We track Macbooks by name in Jamf but students are easily able to rename their Macbooks by going to System Settings - General - About, and then just clicking and typing over the name that we set. When I look in restrictions, there's an option to restrict the entire General section but we don't want to do that. I just want to restrict the About section in General to prevent them from renaming the Mac.
I got a macbook from my school, went into MDM profiles and saw the name Jamf like 4 times. I hope this is the right forum! So basically our school isnt that restricted when it comes to macbooks, they let us create our own apple accounts or login on already existing apple accounts, they heavily recommended that we logged in into our daily basis icloud accounts so i dont think they look into data on our macbooks so much because its literally our own account or i hope so. We can literally download almost everything on our macbook, and can play around on the settings how much we want. I ofcourse disabled the Screen time data on settings. But my question is if they can see our screen time on our macbooks and how much we been using it, ive been using the laptop very very very much, got so many hours on it. I just wanna see if the school can see that, even if they did, is it easy accesible or do they have to contact JAMF for SCREENTIME DATA?
Hello everyone. I saw a few discussions about this one but nothing really stood out to help me.I want to give out FileVault key to the user that forgets his password. But I want to reissue that as it has been seen/captured.I'm working on Jamf Cloud, not on premise.I was thinking of Extension Attribute but found nothing helpful.Nothing either in Criterias (Smart Groups). Have an idea? Feature request? Truly,Danny P.
our users have to authenticate about 3 times during enrollment. 1st to authenticate / start enrollment 2nd time to create local account 3rd time to authenticate to Zscaler We use Entra as our iDP and everything is setup fine in JAMF Connect as existing users are able to authenticate to Azure without issue. Is there a way to have the Mac store the SSO credentials so it can be passed to other apps during enrollment? We are using Device Compliance...finally got rid of Conditional access..TIA
Hi everyone,I have just started my Jamf adventure and I've been working on disabling Chrome auto updating.We used a script which was removing a KeystoneRegistration.framework file and as far as I know, it worked well since the update, when Google changed/removed that file? I did some tests and check logs, and our policy which was using the above mentioned script stopped working 1,5 years ago, nobody must have noticed it. Anyway, I wanted to fix that but I have no clue, what else should I do.I tried to figure out, which option/file is responsible for the software update option and I found it's a Google Keystone file, I tried to create a profile with com.google.keystone where I used "updates are never applied" but nothing works here. Once Chrome is installed and I go to the chrome://settings/help, updates are being installed, no matter what.Any ideas how to stop it?I use a Enterprise Google Chrome downloaded from this site
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!