Get Support
Recently active
As we migrated to the new Jamf Nation Community, you may have experienced a change in the badges associated with your profile. Please enter your information on this form to have your badges reassigned to your profile. Note: We do check our internal records to ensure the correct badges are allocated to your account.
Hello, community I have a faulty MDM configuration on one of our MacBooks. The enrollment was performed via the following command: sudo profiles renew -type enrollmentThe profiles have been created, but a message comes with:Registration with the management server failed.The update to an MDM profile contains different server URL. We have never received this message so far, nothing had changed. In the dashboard of Jamf pro, however, no management is possible for this device.the profile seems to be broken. In the administration, the points MDM remove or similar are not available. How can we remove MDM management via CLI and run the management again? We have already tried the following without success, the message remains the same and no administration is possible: Sudo jamf removeMDMProfile. — The profiles remained in place, a new enrollment resulted in the same error. A reset of the MacBook is out of the question. Greets
Hello all, I'm looking for the monthly enterprise channel for Office. We're updating our Office config profile and I can't seem to find the keypair. I suppose it may not exist... but I want to confirm that. :P Thanks!
So right now, I use dsconfigad to tell if a computer is bound to our AD, and while that works beautifully, it is not complete. For example, I can have ```dsconfigad -showtell me I am bound, but if the computer account has been deleted in AD, from the AD-side of things, -show will still tell me I am bound, though I will not be able toid $adUserName``` Does anybody have a better scripting process or workflow that gives me a truer idea of whether or not I am bound and fully functioning from a directory services standpoint to our AD?
I saw this on a blog this morning, posting here to raise visability.Much has already been written about the new monthly screen recording prompt in macOS 15 Sequoia. After a bit of research, there is a way to get rid of the prompts; kinda tacky, but does work.The good news is that there's a way to stop the prompts foreverdefaults read ~/Library/Group\\ Containers/group.com.apple.replayd/ScreenCaptureApprovals.plistThis file is protected by TCC, so to access it you'll need to grant Full Disk Access to Terminal app.{ "/Applications/Shottr.app/Contents/MacOS/Shottr" = "2024-09-21 12:40:36 +0000"; }In the plist file, the keys are the paths of the executable files with screen recording permission, and the values are dates. I'm using the Shottr screenshot tool as an example.To stop the prompts forever—for the rest of your life, anyway—set the date to far in the future, for example, the year 3024 instead of 2024.defaults write ~/Library/Group\\ Containers/group.com.apple.replayd/ScreenCaptu
For those who get logged out of Jamf School frequently I believe I have a solution for you. For anyone that has access to Safari for web browsing, I have found a way to quasi circumnavigate getting logged out randomly during the day/overnight with Jamf School. With Safari, load your Jamf School instance and sign in, be sure you're on the dashboard. Make the main page an "app" by going to File > Add to Dock or Share > Add to Dock. If anyone isn't aware, this will make essentially the Mac equivelant of a web clib from iPadOS and place it right in your dock, only to access your Jamf School instance. I have found that after not using for a couple days, I am still logged in and may only need to click on a sidebar item to "reload" Jamf School. During the day, usually I find I can navigate anywhere at anytime without being prompted for login credentials, and again, most I need to do is click on a sidebar option to reload Jamf. Been working without failure for the past coupl
Hi All, I'm deploying Logic Pro X in a multi user environment (AD bound Macs) for the first time, and am wondering how to make the experience as smooth as possible when a new user logs in for the first time. I think I'm fine deploying the additional content, but for each new user Logic prompts them to download it again on first run. If they press no then it finds the existing content just fine, but this is a student environment so I know at least some will just press yes and waste space (and time) downloading another copy of all the content for their account. Is there an easy way to skip this dialog on first run? If anyone has set up Logic in such a way before and has some pointers, it'd be very much appreciated. There are a couple of other things we'd like to achieve if possible, such as skipping the scan for audio units on first run, and the process of indexing apple loops on first run. Are these indices stored in specific files I could load in to the user template, thus skipping
Bonjour, L'option de restrictions des mises à jours aux administrateurs uniquement semble uniquement fonctionner pour les mises à jours mineurs (ex: 15.1 >15.2) mais pas pour les mises à jours OS (ex: sonoma > sequoia) est-ce normal ? Sachant que le but étant d'empêcher les utilisateurs de mettre à jour eux-mêmes vers les dernières versions de macOS sans notre autorisation, afin d'éviter les bugs possibles avec les nouvelles versions.
I've created a set of compliance rules based on CIS Level 1 for Sequoia, I've created guidance, and saved the settings. But the "Jamf Pro Upload" button remains greyed out. I've uploaded before with a similar workflow, but I can't get the button to become clickable. The guide doesn't mention what criteria is required to make the button usable. When creating guidance I've tried the viewing project button, and the upload button is still greyed out. And saving settings, and the upload button is still greyed out. Tips? Tricks? Suggestions? I /could/ manually upload everything... but why when there's a button to do it for me (supposedly).
We tried this and several other approaches to no avail, are there any currently-working solutions to change the keyboard input language programatically? #!/bin/bash # Script to set the default keyboard layout to British # Set the keyboard layout to British/usr/bin/defaults write com.apple.HIToolbox AppleCurrentKeyboardLayoutInputSourceID -string "com.apple.keylayout.British" # Clear the keyboard layout cache/usr/bin/defaults delete com.apple.HIToolbox AppleEnabledInputSources # Add the British keyboard layout to the list of enabled input sources/usr/bin/defaults write com.apple.HIToolbox AppleEnabledInputSources -array-add '<dict><key>InputSourceKind</key><string>Keyboard Layout</string><key>KeyboardLayout ID</key><integer>2</integer><key>KeyboardLayout Name</key><string>British</string></dict>' # Restart the HIToolbox process to apply changes/usr/bin/killall -HUP SystemUIServer echo "Default keyboard l
How do I generate an mdm profile to populate mdmProfileData for a return to service API call?https://learn.jamf.com/en-US/bundle/technical-articles/page/Return_to_Service.html#ariaid-title3
We are trying to change the MacOS Date & Time setting "24-hour time" on 15.2 via a script. There is nothing recent / working anywhere on the web. Is it impossible?
I have set up Cache Server 1 in City A, where I added the subnets of this location in the "content cache for" section. For my local network, I used the "custom public IPs" option and added a TXT record to the local DNS. This configuration is working as expected. Now, I am setting up Cache Server 2 in City B. The configuration is the same as in City A, ensuring that the subnets in City B fetch cached content from Server 2. I have also configured them as peers, with no parent settings in place, and both City DNS servers are synchronized with each other. Q1: How is data served to clients in City B if Cache Server 1 already has the same files? Q2: What changes should be made so that, in the event one server goes down, devices at both locations can still retrieve data from the other server? Additionally, while both servers are available, how can we ensure that devices access their respective server to minimize latency? Q3: How do peers work in this setup? If Server 1 has a file, does
I want to share a useful link,Jamf Youtube Channel has published,how to troubleshoot Configuration Profiles in Jamf Promake sure the Configuration profile you created is correct, sent to the Mac, and processed until complete, if not, you can find where the process stopped/failed.here is the link ( https://www.youtube.com/watch?v=c0r_fz4Kod8 )
We are trying to write a script to output all the active wifi and ethernet connections, if any, and turn off the wifi if there is an active ethernet connection. This is not working at all, because ifconfig is not returning the names of the connections (which may or may not be ethernet). networksetup -listallhardwareports is better as it displays the name of the "hardware port" but doesn't list the status. This seems promising but we haven't been able to use it in a script https://developer.apple.com/documentation/systemconfiguration/1517371-scnetworkinterfacegetinterfacety?language=objc #!/bin/bash # Define the names of the interfacesWI_FI_INTERFACE="Wi-Fi"ETHERNET_INTERFACE="Ethernet" # Check if the Ethernet interface is activeethernet_status=$(ifconfig "$ETHERNET_INTERFACE" | grep "status: active") if [ -n "$ethernet_status" ]; thenecho "Ethernet is active. Turning off Wi-Fi..."networksetup -setairportpower "$WI_FI_INTERFACE" offelseecho "Ethernet is not active. Turn
We have SSO policy that runs at every network change to reestablish the key, with documentation from Apple. This was setup prior to me supporting. The problems is, that it runs and reestablishes the SSO, but in the logs, it shows a network error. When that happens, it prevents any other policy from running other then self service policies until the user restarts their mac. It doesn't happen on all devices, it's pretty sporadic. We only find out when we notice updates not installing. When you go to the device, the only policy that runs over and over is out SSO Policy. Here is the script that runs in the policy. #!/bin/bash killall AppSSOAgent sleep 10 app-sso -a "oursite" -R -q exit 0 Here is our Config Profile.
We work in an area where users do not have admin rights, so I put together this script that allows them to remove apps from the main /Applications folder. You can control which required apps cannot be removed: Link to my Repo: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/AppDelete #!/bin/zsh # # App Delete # # Written: Aug 3, 2022 # Last updated: Dec 21, 2024 ###################################################################################################### # # Gobal "Common" variables # ###################################################################################################### LOGGED_IN_USER=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) USER_DIR=$( dscl . -read /Users/${LOGGED_IN_USER} NFSHomeDirectory | awk '{ print $2 }' ) SW_DIALOG="/usr/local/bin/dialog" SUPPORT_DIR="/Library/Application Support/GiantEagle" SD_BANNER_IMAGE="${SUPPORT_DIR}/SupportFiles/GE_SD_BannerImage.p
Hello everyone,After looking around for a little bit, borrowing from a few forums to make a script that adds exceptions to the popup portion of Safari's settings. I thought I would include this for anyone who would want to add it. Keep in mind this particular script is made to run on check-in. During my testing i was running through self service or a custom trigger via terminal and i came across errors trying to get terminal to call the custom trigger. Custom triggers + this policy will not work unless you grant terminal Full disk access. #!/bin/zsh # Quit Safari to ensure the database is not lockedkillall Safari # Add or update site entries in Safari's PerSitePreferences.dbaddOrUpdateSiteEntries() {for site in "${PUsites[@]}"; do# Check if the site already exists in the databaseexistingEntry=$(sudo -u "$loggedInUser" sqlite3 "$db" "SELECT preference_value FROM preference_values WHERE domain='${site}' AND preference='PerSitePreferencesPopUpWindow';")if [[ -n "$existingEntry" ]]; then#
I have been trying to get Barracuda Device Manager installed from JAMF on our companies macbooks. In order to install it manually you have run a script that Barracuda provides. I have no issues doing the manual install but I want to automate it now. I have tried just uploading the pkg I downloaded from Barracuda but that doesn't work. I tried to run the script manually before I installed from JAMF and it doesn't work. I uploaded the script and installed from JAMF that doesn't work. I have tried adding the script to the pkg when creating the software policy that doesn't work. I also used JAMF composer to create the pkg and tried all of the steps I mentioned before. I did check the logs I found this: Installing at base path / installer: The install failed. The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. So right now I am thinking of a couple of things that maybe happening it may be something on my end w
Our iPads do not automatically join one of our Wi-Fi networks because they require the user to select the Wi-Fi and then trust the cert. They are initially setup at Head Office then are sent to a store. But they do not join the Store Wi-Fi automatically on arrival, the user has to go to Wi-Fi settings, click on the SSID under "My networks" then press trust on the certificate. We have a self-signed root, an intermediate and a Wi-Fi cert. All of which I have pulled directly from ClearPass our Wi-Fi authentication application. I have put all of these certs into a Config Profile and pushed to the iPads, I have tried in separate profiles and also in the Wi-Fi payload profile but none of these work. Does anyone have an idea what I am doing wrong here?
To add the proxy configurations automatically, we can deploy a profile with the Content Filter payload configured. First, we need the app Identifier and Code/Designated Requirement information, PPPC Utility is a great tool to read that directly from the Apps. In the screenshot, the identifier is "com.forcepoint.ne-app" and the code is "identifier "com.forcepoint.ne-app" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = C489D5E8E8". Then, create a new profile or edit the exsited PPPC/KEXT profile, configure the Content Filter payload, and deploy to the client: Now, a new proxy setting will be added and enabled by force, and no pop-up window again during the installation.
Hi all, When attempting to create a custom SSL configuration for the GlobalProtect VPN, I am unable to assign a specific certificate that was previously uploaded. The "Identity Certificate" field does not appear at all, so I cannot select the specific certificate. Furthermore, when trying to deploy the configuration to an iPad without this setup, it unfortunately results in a failure. The configuration was performed according to the PA article: Configure a User-Initiated Remote Access VPN Configuration for iOS Endpoints Using Jamf Pro. https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/mobile-endpoint-management/manage-the-globalprotect-app-using-jamf/manage-the-globalprotect-app-for-ios-using-jamf-pro/configure-ios-endpoints-using-jamf-configuration-profiles/configure-a-user-initiated-remote-access-vpn-configuration-for-ios-endpoints-using-jamf-pro
Hello everyone!Has anyone ever had a Mac not automatically check-in (and therefore also inventory updates) but only when the user carries out some operation via self-service?It appears as if the incoming connection from Jamf is blocked/filtered, but is only available for outgoing.It happens to me on 3 colleagues, on one I identified the problem, the OnVue software for online certifications, but for the other 2 I can't understand what type of troubleshooting I could do. Tried redeploying the jamf binary, no luck.Has anything like this or something similar ever happened to you?
Has anyone ever tried preventing the MFA requirement each time your user's log into Self Service with their corporate account? We as techs usually set up laptops for users to a certain extent and its been kind of a pain to have the user verify for us every time. In our environment MFA is required every hour or so with the self service app.We have conditional access policies in place and use plists for such applications like chrome to surpress these MFA prompts but was wondering if we could do the same for Self Service. Thank you
Content backfill required
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!