Get Support
Recently active
I'm currently testing JamfConnect in preparation for deploying across my organisation (approx 50 devices). I'm having issues with the privilege escalation component in particular. User starts the workflow as a Standard (non admin) user. User cannot execute sudo jamf recon, receives the error message "Sorry, user test.x.user is not allowed to execute '/usr/local/bin/jamf recon' as root on <hostname>". This is expected as user is still a standard non-admin user User requests privilege elevation via Jamf Connect menu bar. User authenticates with Jamf Connect, provides a justification/rationale for elevation. User is now an Admin user in System Settings > Users and Groups, and menu bar shows that the user has 10 mins of elevated privileges User attempts again to execute sudo jamf recon, but still receives the same error message as if they have no administrator privileges User ends the privilege elevation session, they are then bumped back down to a Standard User accord
My school wants to change our own school Wifi by making it public by changing it from an WPA 3 to WPA Enterprise with username and etc is there a way to link it with IPads and other Devices so that it would be possible to see what each student does instead of just seeing the IP address and device name maybe even deactivate the private Wifi address setting on iOS?
Before I go through the pain myself, I like to take the lazy route.... Anyone ??? Thanks
Because of CIS we have disabled Bluetooth Sharing using a configuration profile. However we found out that it is still possible to send data from a Mac to an Android device using the Bluetooth File Exchange app.Data exchange between macOS and iOS is being blocked as expected.Have you come across this as well? What have you done to remediate (other than adding the Bluetooth File Exchange app to restricted software)?
"Leave Remote Management" feature remains active on iOS devices and user can remove MDM profile with passcode. What could be causing this issue, and how can it be resolved to ensure that users cannot remove MDM profile.Device enrolled by Pre-stage Enrollment. Below settings have been done in prestage enrollment profile.
I was recently tasked with enabling DLC on 10.11 El Capitan iMacs in lieu of connecting them via Fiber. Since I found very little information about how to do this from JAMF, Quantum, or Apple, I thought I would share my solution. Distributed LAN Client (DLC) is basically a Fiber over ethernet connection Xsan can use. It doesn't have the same level of throughput, but it is an excellent solution for users who historically have needed Xsan access but who aren't doing real-time rendering. Reference Material:- Quantum | StorNext 5 Link: Here- Apple Xsan Reference: Here Benefit of using JSS:Without a JSS the setup is more difficult. Quantum server can provide a Configuration Profile (unsigned). If you manually load the unsigned profile, Apple's SIP security blocks it from running, and if you turn off SIP (which I don't recommend) you still have to work out a script to map the drive if it doesn't initially map at login. If the profile is pushed via JSS the profile i
Jamfsters, am trying to setup an extension Attribute that will tell me if proofpoint is running on the system. After looking at the activity monitor is under logger (4599) I am new to scritpts can someone point me in the right direction?
I have a script that I run on machines to get them to do macOS updates and upgrades. Since the "Update plans" came out of beta I have modified my script to use plans when it is enabled. I have noticed that on macOS 15, if the script runs while a user is logged in and I set a plan via the following: curl --request POST \\ --silent \\ --url $JAMFServer/api/v1/managed-software-updates/plans \\ --header "Authorization: Bearer ${authToken}" \\ --header 'Accept: application/json' \\ --header 'Content-Type: application/json' \\ --data ' { "devices":[ { "deviceId": "'${ClientID}'", "objectType":"COMPUTER" } ], "config":{ "updateAction": "DOWNLOAD_INSTALL_RESTART", "versionType":"SPECIFIC_VERSION", "specificVersion": "'${UpdateVersion}'" } That the macOS 15 machines will pop-up a dialog informing the user of a need to restart and it gives them the option to 'do later". Under the previous setup, when the command was sent: curl --request POST \\ --silent \\ --url $JAMFServer/
Hi, A little while ago I noticed the Remove Sophos Endpoint.app had appeared on my Mac. After checking other machines I can see it's installed on everything. Not cool. I ran a script to remove it from all the Macs and manually deleted it from mine. However, it reappears in /Applications the next day. I've been running a daily script to remove it from all Macs but now it's getting to me. I can match up a Sophos update in the logs to the same time the app was created last night so it appears to be pulling it down when Sophos updates. Although I 'think' it's only doing this once a day. Most logs show Sophos Anti-Virus is up to date but the one that i think is downloading shows as Sophos Anti-Virus was updated. Update is pointing at Sophos as the primary locations (no secondary) and if i force an update the app doesn't install. Has anyone else seen this behaviour? (I don't want to have to open a ticket with them as previous experience
How do i go about removing apps from an iPad. It is setup that pupils cannot delete an app from the iPads. I have went into Jamf self service to see if it gives me the option to uninstall but it doesnt.Thanks
Hi folks, i try to force a device (macbook pro) to update to the latest MacOS. I created a testgroup which contains this computer. Then i go to software updates, choose this group and then i choose a specific version or latest possible (makes no difference). Install option is "download and install with referrals (2)" In Jamf Pro computer management it shows this job....but nothing happens. On this computer every user is an admin....so it can´t be an AppStore setting. Any idea? Greetings Frank
Hi, Whether updating through Jamf Pro or manually running the pkg to update Zoom, I've been getting this message since Zoom 6.1.11. "Your Zoom application is being managed by your IT administrator. Please contact your IT administrator to request an update." I do have a configuration profile in place to only allow the screencapture settings for Zoom. That has been working fine for years. Anyone have this same issue or know what's wrong? TYIA
Dear All Let me first start by apologising as I am new to APIs and getting them working, also fairly new to scripting. I have checked on the forums and I keep going around in circles. I have spent a lot of the weekend trying to get this to work and even trying to get chatgpt to assist (But its a bit useless). I am trying to build out an asset system on Google Sheets where I pull in inventory data in one (Live) tab and then use a lookup formula to pull in the relevant data from the LIVE tab into another TAB. WHAT I WANT TO ACHIEVE I want to be able to build a Google Script that pulls inventory data from JAMF into a tab called LiveInventory on my Google sheet.I have created an api user and defined clients/roles/privileges in JAMF. I've also setup an advanced search for the api user.What I have is so far from following some instructions are- USER CREDENTIALS- CLIENT ID- CLIENT SECRET- JAMF URLI tried copying a script from years ago but to no avail. Please help and my ap
Came across an issue with Get Add-ins being greyed out and all the add-ins removed. This is happening on different OS and Office versions. I don't think it's affecting that many people just curious if anybody else has seen this. We use "Report Phishing" add and some users didn't have it and the "Get Add-Ins" was greyed out. If you go to Outlook settings>Privacy and uncheck/check "Turn on optional connected experiences" the add-ins come back. Our Add-ins are handled by 365 and our exchange admins confirmed it's not something on the backend.
Hi all,I've had a search through previous posts about this and I can see the question has been asked before a long time ago (4-5 years) with no resolution. I'm hoping someone can tell me whether this is possible or not.I want to deploy an SSID using EAP-TLS and have client devices use a machine certificate to authentictae when a user is not signed in, then, when a user does sign in, to have a user certifcate used for authentication.Ideally the flow would be:No one signed in - device uses machine cert to authenticate to wi-fi, can receive updatesUser A signs in - new authentication occurs using userA certUser A signs out - new authentication using machine cert againUser B sings in - new authentication occurs using userB certetcThis is to support network level access control.The previous posts i've read have mentioned issues with one profile overriding another or the client device sticking to just one profile.Has anyone ever got this working? Annoyingly it's straight forward to do on Win
Hey Jamf Nation! I have a short script set to run once per computer at recurring check in. I am also about tell Jamf to update macOS from 14.7 to macOS 15. I believe individual Macs check for macOS updates as part of the recurring check in (very easily could be wrong!). My question is, which happens first? If a Mac contacts Jamf as part of a recurring check in, and finds out it is due for both a script to run and a macOS update, which does it do first? Thank you all!
I don't know if my subject made sense, but here goes... Most of the software installs we deploy go through a two-step process: cache the installers, then run the installers. I'm testing different ways to run the Adobe CS6 installation (at logout, in the background, at startup, etc.), but to save cooking time, I'd like to be able to cache the hefty-sized CS6 .pkg file from a Mac that has a local distribution point, over either a Firewire or Thunderbolt connection instead of letting it cache from our JSS server. Occasionally we'll push out cached .pkg files through Casper Remote, but it doesn't appear to interact with the local distribution point the same way that Casper Imaging can. Am I missing something or is this not possible through the standard Casper suite? Thanks! JSS 8.62, etc, etc.
I previously used a PLIST for managing Chrome and Edge including pushing 2 extensions for all users. This worked, it pushed them in an active state, no problems. Seeing you can now get nice JSON config files that let you toggle any setting within Jamf I switched to that but when push the 2 extensions they are both loaded, locked but disabled. Its my understanding that you can add keys in an additional plist to configure extension settings, including if its enabled or disabled but so far not been able to find how. Anyone know?
Does anyone know if it is still possible to prevent the removal of management profiles on Jamf Pro for iPads?I believe there used to be a iPad restriction to do this. I can't seem to find it now.Any help would be most appreciated.
Hi everyone, i'm currently trying to create an advanced search that will show me all devices that didn't manage to install our webclips configuration profile. We are using devices in a shared iPad, temporary Session only mode, so the configuration profile has to be installed every time a guest user is being logged in. The profile then stays on the device, even after the user logged out and only if a new guest user is being logged in the "old" profile gets removed and reinstalled or at least that is how it appears to be working. I didn't find any other criteria than "Profile Name" that would let me search devices for installed configuration profiles and it seems to be the correct criteria, but it looks like its either not working correctly or its not meant for what i am trying to achieve, although Jamf lists every configuration profile as possible value. If i use the criteria like this: "Profile Name [Operator] has [Value] BIZ_PROD_Webclips" i only find 2 devices which do have the profi
Hi, I am trying to create the Nexthink package in jamf pro need to deploy 200+ MacBooks and am unable to create the yet not found any steps related to this. I got only a profile from the Nexthink sitecan anyone guide or share the step for Nexthink collector deployment? Thanks
Hello After the autoupdate to Skype 8.60, i have users getting an prompt to imput local admin credentials whenever they start Skype.After some investigation, i concluded that skype wants access to a private key in the SYSTEM keychain, and the problem goes away if you just add it manually. Does anyoane have any ideeas regardng how to solve this? I guess i will have a few hundred people having this problem and i have no clue how to solve it for everybody at once, and user by user is quite out of the question.
I have iPads that I have enrolled in Casper with DEP, but after activationsetup there is a re-occuring prompt to "Sign in to iTunes to allow Casper to manage and install apps. With the ability now to deploy apps without an Apple ID, I have no reason to log these iPads in to the App Store but I can't find what is causing this prompt or how to stop it.
I circulate iPads using Jamf and Apple Configurator. A recent OS update has started prompting this error message:App InstallationSign in to iTunes to allow "<my JAMF server URL>" to manage and install apps.Has anyone found a way to suppress this error? I have turned off the App store in my configuration profile, but still seeing this error pop up on these iPads.
While testing a Self Service policy to install Adobe Creative Cloud Master Collection 2015, I was greeted by a Finder dialog box informing me I was nearly out of disk space. The following script leverages JSS Parameter 4 and verifies there is enough available disk space before continuing with the policy. If there is not enough free disk space, a message is displayed to the end-user and Self Service is forcibly quit. (Is there a way to just simply stop the policy and leave Self Service running?) #!/bin/sh #################################################################################################### # # ABOUT # # Check Free Space: Leverages JSS Parameter 4 to verify there is enough available disk space before continuing with the policy. If there is not enough free disk space, a message is displayed to the end-user and Self Service is forcibly quit. # #################################################################################################### # # HISTORY # # Version
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!