Get Support
Recently active
In Apple's macOS Sequoia 15.0 release notes the following is mentioned: "Executables, scripts, and launchd configuration files can be installed using MDM and stored in a secure and tamper-resistant location." How does this work in Jamf? I have searched but could not come up with the answer. Has anyone been using this and if so how do I configure a tamper resistant location?
Last week I set up the conditional access integration with Jamf, 2 test machines were added successfully, JamfAAD popup appeared and I was able to go through the authorization process in the keychain, then I registered another 10 machines, this time of other employees, but as I assume due to the fact that their main browser was not Safari, they did not receive a JamfAAD window during registration.I thought that if they do it later (when logging in, for example, to office.com, mac asks for a certificate) there will be no problem, but today, after the weekend, I noticed that the machines do not report their status in Intune, as shown in the screenshots, the first one is my test Mac which I managed to add successfully, the second is another employee who does not report the status, does anyone know how can I fix it? Today I decide to make some test with some custom settings for SSO Extention & JamfAAD, but as you can guess popup window still did not show up. My mac
So I’m sure you folks are familiar with typical Safari behavior on iOS. You can put in a search query on the same place as the URL bar. A student puts in an inappropriate query and taps Go. Google lists safe searches but isn’t always perfect. When it is not our web filter catches it. You tap on an unsafe one of them and our web filter blocks the page. The problem comes with image results and their previews in the search results. if I tap on one of those results that is inappropriate, our web filter blocks it. However, you can still see the thumbnail preview. Today that occurred for a child whose mother happened to be somebody important. Mother was very angry ‘at what her child was exposed to,” pointed out that our district has very strong filtering in her classroom and why is her kid able to see such things. She plans on asking this question of district school officials. Between the network guy and myself, We traced it down to these image previews. Network guy trou
Greetings admins! I wrote a custom migration script that reads several aspects of the users home folder and backs them up to a user specified destination. That part seems to be working OK, but when I go to write this data back to the same locations on the user's new system, it needs full disk access to work. My idea was to have the script run directly from Self service (Policy > script execute), but in order to do so, Self service needs full disk access to be able to write back to the users Library folder. What PPPC do I need to create to allow Self service to have full disk access?
Hi Encountered an weird case on some devices, after enabling internet sharing, the hotspot is unsecured even if i did set up a password for it. Does anyone have any ideea on what i could try? I'm not even sure where is that password, or the internet sharing config is usually stored.
signed inn this morning after my upgrade and saw this warning Duplicate email addresses found Jamf Pro detected one or more accounts using the same email address. Jamf Pro will start blocking SSO access for accounts using duplicated emails when Jamf Pro is configured to use email as Jamf Pro User Mapping. To ensure all accounts can sign in, check that no accounts are using the same email address in User accounts and groups not sure i like this at ALL
As the title implies, When setting an app inside of the App Installers to "on-demand installation", I am not seeing them in the JAMF Kiosk on a device. I have a user assigned, and I am seeing other "in house" applications, but App Installers are missing. If anyone else seeing this?
Hello,I am looking to see if anyone has a way to have Responsdous Lockdown Browser to be able to install and auto-update when a new version is released. This would be used for the schoology and college board (AP) versions of the application. This app would be managed on MacBooks to where the end user (student's) are standard users. I have looked at installomator but unable to find where someone has added a script for respondous lockdown browser. Thank you for your help.
People ask me all the time what the most significant difference is between supporting an MDM for Macs and supporting Windows. I’ve thought about the answer a lot, and it comes down to the collaborative nature of the Apple support community. One underrated community aspect is the sheer number of open-source tools available. The sheer number of tools freely available by the community for the community is amazing! As admins, we strive to make endpoints more secure and streamlined. This often requires acquiring new products and services. Still, it often comes down to Finance signing off on the expense and information Security, ensuring it doesn’t do anything improper with the data. Management approving the implementation of a new tool, not to mention your time making a Proof of Concept (in non-production of course!). This often comes alongside dealing with account representatives, solution engineers, and a slew of other hurdles they are concerned with. Enter open source! I used
Has anyone else run into this issue? It seems to be happening more and more to the point where most apps aren't installing. The weird thing is, this doesn't happen on all iPads, they will be the same type and the same iOS. Also, it's not the same apps that have the issue. I tried wiping them, connecting to a different network, renewing the VPP token (it was almost expired), updating the iOS, and creating a new policy. There are plenty of licenses available. I'm fairly new to JAMF with only the 200 experience so I'm sure it's something dumb that's causing it, I just can't figure it out.Any help would be greatly appreciated!
I am trying to get the Macro Security windows to look the picture below, currently it is fully greyed out and cannot select "Disable All macros without notifications" This is on office 365 for Mac Ventura. I have tried the command lines using JAMF with the line below but still no help. Any ideas to how to get the pop up your macros are disabled every time the user opens a word document would help. Thanks. defaults write com.microsoft.office VisualBasicMacroExecutionState -string DisabledWithoutWarnings
Hi, We have an iPhone 6 that is registered with MDM through JAMF. Unfortunately the passcode is currently unknown and at the same time the device is not connected to any wifi or mobile data connection. This means, we cannot reset the passcode via the MDM and the iPhone is completely stuck. To add to the fun, the phone has been taken to a different geographic location so cannot be connected to the computer with the JAMF to reset that way. There is nothing important on this iPhone so a complete reset would be fine with us, if it allows the passcode to be reset and the phone to be connected to wifi. Will erasing it using recovery mode using iTunes on a different computer do this trick? The device is not set up with an apple ID so that shouldn't be an issue. It is just the passcode on the lockscreen. Any other ideas of how to unlock this iPhone or get it connected to the internet so we can push commands through the MDM? Many thanks for any help!! Ronja
I am looking to identify shared computers by creating a smart group that detects more than 4 local user accounts. It is not a sure fire way to know if they are shared but that works for us. My idea is that the smart computer group criteria is "computers with more than 4 local user accounts" Is this possible?
Hello, I am creating a new configuration profile to apply a new hidden SSID to student iOS devices (ipad 10th gen) in which we plan on utilizing. The SSID is hidden and not broadcasting, and has been tested with several clients without the profile applied. Clients alone don't have an issue connecting after manual entering the hidden network information. After creating the wifi payload configuration profile with the correct scope, devices receive the "managed network" payload but it does not show as a selectable wifi name under the wifi network settings on the ipad. Hidden network and Auto Join have been selected within the wifi payload configuration on JAMF's end. Am I missing something? I am not sure why the ssid is not a selectable option on the ipad, but still shows as a managed network when you head to edit the device wifi networks. Any help would be appreciated, thank you very much!
Just thought I'd loop you guys on a nice tool. If you're here, you're running an MDM with probably a high amount of Apple devices. Your enterprise is then too probably running macOS caching servers to save on bandwidth etc. Currently there's a couple widely used tools for monitoring your caching servers like ErikNG's Cacher (https://github.com/erikng/Cacher) and krypted's precache (https://github.com/krypted/precache). Just wanted to let you guys know about one more that I found particularly helpful. Netdata (https://github.com/firehol/netdata) by ktsaou at Firehol is a free/great tool for monitoring all types of Linux/Unix type devices. It also can monitor some more basic functions of macOS machines. Recently he assisted me with writing a plugin to also help with monitoring the caching function on our caching servers. (https://github.com/firehol/netdata/issues/2766) This in conjunction with prometheus and grafana, has allowed me to monitor historicals, create alerts when something
Hello everyone, We want to put the shortcut for screen recording in the notification center on our managed iPads. It works on some, but you can't customize the Notification Center on most of them. They all have the same profile with the same restrictions, but I can't find an option to allow the customization of the Notification Center. The iPads are all personalized and not shared iPads. I've done some research, and currently, there seems to be no way to manage the control center settings with Jamf School. Is there another way to enable screen recording for our students without a third-party app? If not, can you recommend a free & easy screen recording app without the need to log in or register? Thank you for your help!
I've setup an API role to Read Smart Computer Groups + Read Static Computer Groups but when I try the script (at bottom) following I get this result:- Access token obtained successfully. { "httpStatus" : 401, "errors" : [ ] } I'm fairly new to the API side of things so might be the script is inaccurate. My Questions are:- 1) If I go to JAMF_PRO_URL/Api what do I put for username and password (screenshot below)? Is this an account that has access to the Jamf Pro instance or should this be client id / secret or something else? 2) What privileges do you need as a user in Jamf Pro to be able to run these API calls? 3) Is there something wrong with the script below? If I do echo "$access_token" should it show details or would it be normal to get a response like "Could not extract value..." For the script below I changed JAMF_PRO_URL to URL for Jamf Pro instance and CLIENT_ID + SECRET to details of the API Client. #
I know there are more questions about this, but there is no clear answer and every now an then i guess any Jamf admin will run into it. Can someone point me in the right direction when command like removing config profles or assigning them to a macbook are just stuck at pending. The device seems to report in with inventory and check ins as expected, but i feel something is just waiting for failure. Any help or experience would be helpfull Thanks!
At Jamf, we’re passionate about helping our customers succeed. That's why we’re thrilled to announce Jamf Nation Rewards – a new program that (you guessed it!) rewards our you for engaging with Jamf, and your fellow community members. And it’s super simple to join! Step 1: Log into Jamf Account (computer)Step 2: Click Enroll on Jamf Nation RewardsStep 3: There is no step 3! 😉 Step 1: Log into Jamf Account (mobile device)Step 2: Navigate to the drop down menu (top right hand side)Step 3: Click ProfileStep 4: Click Rewards and follow the steps to enroll! Once in the program, you’ll earn points for a variety of interactions – both in and outside of Jamf Nation. The more points you earn, the more rewards you can claim. And yes, you can rank up! Earn more points, climb to a higher level. You may even reach Yottabyte! Learn more about the program here. Have a blast! And as always, thank you for being a valued member of our great Jamf Nation! *Please note – This program is for existing custo
I have been testing this Configuration Profile for PrinterLogic Chrome Extension. It does install and grays out the toggle so the end user cannot remove. The issue I am having is if I remove the device from the Configuration Profile it will remove from the profiles section but the extension still shows in the Google Chrome Extensions. It is also still grayed out. I have restarted Chrome and the device. Removed Chrome and reinstalled. Anyone have any ideas? <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>ExtensionInstallForcelist</key> <array> <string>bfgjjammlemhdcocpejaompfoojnjjfn;https://clients2.google.com/service/update2/crx</string> </array> </dict> </plist>
Hello there. I just started using Jamf and I love it. Historically we have made all users a local admin on their machine. Now that we have Jamf in place, we want to remove those rights. But there are some dev users who will still need local admins so we set up a second log in for those users. On the windows side of things, I created a GPO that checks an OU for a security group "computername_Admin" with a single user in that group which grants local admin rights on that one machine. Is there a way to do that same thing with Jamf? Since all users are created as mobile users, the other idea was to create a script (which I am horrible at), that revokes admin rights from all mobile accounts, unless the account name has a ".la" at the end of it.
What is Sovereign Cloud in the Setting > Global > Device Compliant used for?Is it just a text box that we enter anything or leave blank or the connection setting to ITunes
Guys, In my environment I got 85 devices enrolled in Jamf using User initiated Enrollment because my organization did not have ABM and that's why user initiated enrollment did for those 85 devices. Now my organization going to bring rest 30 - 40 devices unmanaged devices to jamf through ABM by enrolling through ADE. In case If I bring those 85 devices to ABM and assign the ADE profile to those 85 devices, shall I run the reenroll command to enroll through ADE or I've to do the factory reset and initiate the ADE. Kindly advice
Jamf Connect has been working in our environment for a few weeks, but we've run into some issues with MFA with security keys.On a computer undergoing prestage enrollment, an SSO window appears prior to configuration. MFA works without issue. After prestage completes, the SSO window appears again. At this point, it should be creating the local account, and connecting to AzureAD. However, if the account is authorized to use a FIDO2 security key, the MFA page will hang.Following this guide, I was able to get MFA working successfully for most logins without issue even with a security key authentication available except when logging into the computer. For all other logins, I don't run into any errors on MFA unless it's when I actively choose Windows Hello/Security Key.
Hello everyone, Has anyone had any luck setting up Global Project for iOS ? After an exhaustive search of PA Networks support documentation I have been unable to locate any documentation that is specific to installing and configuring Global Protect for iOS using Jamf. MDM software. The only relevant documentation that PA Networks provides is specific to Airwatch and inTune , however there is nothing specific to Jamf and I'm beginning to think that perhaps Jamf is not supported based on PA Networks MDM support page, included as a reference. https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/mobile-endpoint-management/set-up-a-mobile-endpoint-management-system/manage-the-globalprotect-app-using-a-third-party-mdm/always-on-vpn-configurations/configure-an-always-on-vpn-configuration-using-airwatch/configure-an-always-on-vpn-configuration-for-ios-endpoints-using-airwatch
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!