Get Support
Recently active
Content backfill required
So, el capitan has a new binary called sfltool. It has been discussed a few times, and I have incorporated it into my firstrun script to add items to the sidebar. I think many more uses for this will be discovered.Here is my script as an example. #!/bin/bash # Get the Username of the currently logged user loggedInUser=`/bin/ls -l /dev/console | /usr/bin/awk '{ print $3 }'` if [ -e /usr/local/bin/mysides ] then su - "$loggedInUser" -c "/usr/local/bin/mysides remove All My Files file:///System/Library/CoreServices/Finder.app/Contents/Resources/MyLibraries/myDocuments.cannedSearch/" && sleep 2 su - "$loggedInUser" -c "/usr/local/bin/mysides remove iCloud x-apple-finder:icloud" && sleep 2 su - "$loggedInUser" -c "/usr/local/bin/mysides remove domain-AirDrop nwnode://domain-AirDrop" && sleep 2 /usr/bin/sfltool add-item com.apple.LSSharedFileList.FavoriteItems file:///Users/$loggedInUser &&
Hello I am blanking on trying to come up with the answer. My boss has tasked me with a way to remove all of our canon office printers from users Mac os devices. Obviously the first thing I have done is create a script. But my boss is telling me that there is something else that you can do that is native in Jamf Pro. Would anyone know what that would be? I shared with him a link in the Jamf Pro settings that is titled "Printers" and he said that is wrong but I am close. I just do not know what else it can be.
This is an ever growing / changing library of common functions that I have created over the years. Fairly easy to use, just grab the common functions you need when creating your own scripts. Thought I would share with the community. Any feedback is welcome. #!/bin/zsh ###################################################################################################### # # Gobal "Common" variables (do not change these!) # ###################################################################################################### export PATH=/usr/bin:/bin:/usr/sbin:/sbin LOGGED_IN_USER=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) USER_DIR=$( dscl . -read /Users/${LOGGED_IN_USER} NFSHomeDirectory | awk '{ print $2 }' ) OS_PLATFORM=$(/usr/bin/uname -p) [[ "$OS_PLATFORM" == 'i386' ]] && HWtype="SPHardwareDataType.0.cpu_type" || HWtype="SPHardwareDataType.0.chip_type" SYSTEM_PROFILER_BLOB=$(
WIP script to show all relevant IP addresses running on an end users Mac. Good for having the user give you their IP addresses when trying to remote in. Uses Swift Dialog to show info to users...designed to be run from Self Service. #!/bin/zsh ###################################################################################################### # # Gobal "Common" variables # ###################################################################################################### export PATH=/usr/bin:/bin:/usr/sbin:/sbin LOGGED_IN_USER=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) USER_DIR=$( dscl . -read /Users/${LOGGED_IN_USER} NFSHomeDirectory | awk '{ print $2 }' ) SW_DIALOG="/usr/local/bin/dialog" SUPPORT_DIR="/Library/Application Support/GiantEagle" ICON_FILES="/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/" OVERLAY_ICON="${SUPPORT_DIR}/SupportFiles/DiskSpace.png" SD_WINDOW_ICO
Morning All I have been working for sometime on getting our macs compliant with intune. It does seem to work. The process seems extremely clunky with users running through the steps in company portal which seems very user driven. I'm sure I have read somewhere this process has become obsolete, is that right? Is there a better way? Thanks
Dear All,I need a bash script for adding "Favourites Finder Sidebar items" in macOS Monterey or Custom Payload profile. Please advise. Thanks!Raj.
Everyone in my environment gets Office preinstalled on their Macs. Users with Acrobat Pro licenses may install the app through the Creative Cloud Desktop app. When Acrobat Pro users install the app, next time they open Word or PowerPoint, they get an error like this: The only advice I've really seen on Adobe's forums is to go in and delete the addins. Since this issue spans Office 2016 (no longer in my environment), 2019, 2021, 2024, and 365, I've written a script (below and on my GitHub) to take care of that issue on a per-computer basis, but it needs to be re-run whenever Adobe ships an update that replaces the Office addin. Does anyone here have a better solution or should I just work on user training that "when you get Run-time error '53', use this nifty button in Jamf to fix it"? #!/bin/zsh # Written by D3xbot # Setup # Set user/localized dirs userAddinDir="/Users/$3/Library/Group Containers/UBF8T346G9.Office/User Content/Startup/" localizedUserAddinDir="/Users/$
I'm trying to create a Policy to update mac like SUPER can since our organization won't allow it's use. Issue i'm having is when running command I keep getting error messages saying" No such update No updates are available. "Here is Syntax I have hopefully someone can point out my error.sudo -S softwareupdate --install 'macOS Sequoia 15.2-24C101' --restart --force --no-scan --agree-to-license --stdinpass "$4" --user "$5" I've tired "macOS Sequoia 15.2-24C101", "macOS Sequoia 15.2", "15.2"Really appreciate everyone time for reviewing this posting.
Hello Team From my understanding and different tests, Compliance panel is accessible only if OIDC has been enabled on the Jamf Pro Single sign-on configuration. Arg ! Domain verification 🥶 (how to.. request 4 validations process in a day) Skip it, and just use Jamf account without IDP.. not secure but it's beta instance. Is it something you are going to remove after the Beta ? Indeed, i do not understand the use case : security ? I do not think to be the only one, my Jamf Pro console access is secure by an IDP. I cannot explain to my Identity Teams: that we need to connect the IDP to Jamf Account website, to list users that need also to be listed on Jamf Pro, which need to be allowed in the IDP app access...🥴 to allow admins to connect on the Jamf Pro console. the answer will be : we already have a process in place which is secure and works as expected, why do we have to add another party. i cannot explain to my Security Teams: that we are going to us
Hello All, We implemented Platform SSO through JAMF to avoid repetitive username and password prompts again and again when accessing company resources. now the issue is that user is getting the shared account(Which he used before in outlook and now removed from outlook) populated when accessing any company resources, it is happening only after implementing Platform SSO. We clicked on 3 dots and clicked on to remove and forget option but no luck. Any idea to suppress these shared account not to be populated when accessing any company resources?
Hi all, I am a Jamf reseller in South Korea. We support a lot of Jamf customers, but there are problems with license renewal these days.I've purchased licenses for several customers from Jamf, but each time it takes a long time for a new activation code to come out, and I'm worried that it might even come out over time.In the past, there was time for licenses to come out in advance and prepare for the renewal of Jamf Pro or Connect.This is because after the activation code period, there may be problems with the behavior of all products, including Jamf Pro. So I think it is necessary to improve Jamf's license issuance system.Doesn't everyone have this problem? I'd love to know what you guys think.
Hello everyone,I've configured some new extension attributes connected to eDirectory. In this case it tells if the computer or devices is connected to a student or an employee. Since we haven't had the information in Jamf before, it seems like it has to go through all devices and users again for the information to be searchable. We have over 1000 computers and 2500 mobile devices. I made two smart groups yesterday afternoon, one for computers and one for mobile devices. This morning it has gone through about 80 computers and 60 mobile devices. Is it normal for it to take this long or is there a way to speed it up?
We have the Microsoft SSO plug-in Configure and deployed to all managed clients, upon initial sign-in or after sometime, signing into Microsoft Teams is blocked and end users are unable to sign-in to Teams, when we unstop the configuration profile from the affected devices users are then able to sign-into Teams, please note the SSO plug-in works with all other MS and 3rd Party apps that use Entra Authentication.Please advise if anyone has this issue and if there are any solutions. Teams sign-in gets stuck here when selecting your account nothings happens no errors, no prompts.
Hello,We would like to start utilizing the return to service app however I am unsure how to scope our deployment network. Our network is cert. based so we have a temp network we use to get the devices online to get their configs and then we manually forget that network. I have return to service configured up to the point of getting that deployment network. What would be a scope I could use for these to have them only have the network loaded after return to service has ran? I did find the plist key to set a time for it to forget the network, just not sure on the scope for enrollment. Thanks in advance!Dan
Hello, I'm trying to deploy Harmony Check Point to our clients. Our security team gave me Endpoint_Security_Installer.zip How can i deploy this? I tried many things but all is failed. Zip File: Endpoint_security_Installer.zip in Zip File : /87.60/Endpoint Security Installer.app I tried to copy zip to client then unzip it. But how can i run installer with quite mode? Maybe I'm on the wrong way. Please help me :)
Trying to deploy a Fortinet VPN config profile for macOS Sequoia and Sonoma, but the profile fails to install. If I change the Connection Type to L2TP the profile installs. Has anyone run into this issue? Settings: Connection Name: VPNTunnel Identifier: com.fortinet.forticlient.macos.vpn Server: locahost Provider Bundle Identifier: com.fortinet.forticlient.macos.vpn.nwextension Provider Designated Requirement: identifier "com.fortinet.forticlient.macos.vpn.nwextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = AH4XFXJ7DK
I didn't see a solution here and really don't want to package it every time, which defeats the purpose of the App Store... We are trying to install FileMaker via the Jamf App Store but include the license file and activate it. I can deploy the app fine and deploy the cert to a folder, but then the end user needs to activate manually after installation. Does anyone have a trick to getting the license activated automatically when deploying via the Jamf App Store? Thanks
Hi everyone! I've been slowly building out our self service with software from VPP, scripts for updating and some help desk tools. I was hoping you all could share some of the scripts and other tools you use for your users. There have been some older threads showing off their tools but they are a little sparse on how to make them work. One great one I saw, but have no idea how to get it to work, was an emergency backup to Google Drive. I would love to see some scripts for updating Adobe CC and some other nifty scripts for helpdesk. Attached is what I have so far. Cheers everyone! :)
Is there a way in self service to update spotify automatically. Or at the very least package/script the policy to always pull and install the latest version?
Dear jamf nation, please add the ability for us to block certain members
Has anyone managed to get around the "403 - INVALID_PRIVLEDGE" error when trying to use the API? I created several API roles that basically give read privilege to every single thing that Jamf Pro allows you to assign read access to, then I assigned those roles to an API user. I'm able to create the token from oath2 and use it to hit various endpoints, so I know that this user's credentials and my basic setup are correct. The API does return 200 OK codes and I get data back. However, when I try to hit any version of the computer_prestages endpoint (v1, v2, v3) I get { "httpStatus": 403, "errors": [ { "code": "INVALID_PRIVILEGE", "description": "Forbidden", "id": "0", "field": null } ] } What is an invalid privilege? It seems different than insufficient privleges.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server [PI122416] When creating or modifying a configuration profile with a VPN payload that uses "Password" for the User Authentication type, Jamf Pro now correctly creates the profile with a valid AuthenticationMethod key. [PI123933] Jamf Pro no longer fails to display the scope for newly created deployable objects and saves scoping changes for existing objects as expected. [PI124225] Upgrading Jamf Pro no longer unexpectedly alters the required privileges for the Jamf Parent and Jamf Teacher apps to function. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox e
In our efforts to demonstrate our commitment to transparency and the safeguarding of personal information, we are providing you with the following important update around the use of AI within Jamf. We’ve updated our Privacy Notice to clarify to customers how we use the information you share with us to inform our AI product features. Performance and usage data may be used to support AI features, such as knowledge-based insights and advanced query results, however, we do not use any personal data to train our AI models. This change is effective December 19, 2024. If you have any questions or concerns, don’t hesitate to contact our Privacy team at https://www.jamf.com/trust-center/privacy/ or privacy@jamf.com
My school district has Apple TV's in classrooms, and we're trying to prevent our managed student iPads from being able to AirPlay to them. On the student device profile, we have AirPlay restricted to only known AirPlay destinations, and we left the destinations empty so that they have none available. This isn't preventing them from being able to AirPlay to the Apple TV's. They can still AirPlay with the code that appears on the AppleTV. Is there another setting we're missing? We need to keep our student and teacher iPads on the same WiFi network for Apple Classroom, so using a different network for the student devices isn't an option for us. We'd also like to avoid putting passcodes/passwords on the AppleTV's because we have many teachers who travel to different schools and classrooms. We could possibly start configuring Apple TV passwords with a similar convention, but sometimes when we do that, we just find it publicly posted in class
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!