Get Support
Recently active
Hi everyone,Is there a possibility to set a configuration on Macs that allows AirDrop transfers, but only to other macOS (or iOS) devices, and not to others?Thanks!
User wants to turn off Assistive Access on an iPad but forgot the passcode. He didn't set the recovery Apple ID so the Forgot Assistive Access passcode option is not appearing. The soltion to disable Guided Access does not work with Assistive Access. Is there a way to disable it without wiping the iPad? Thanks.
I can't remember how but how do i see the file in the office2024.pkg showing what get's installed? I can't seem to get the microsoft teams to NOT install. Here is my .plist that i use with -applychoicechanges Am I naming the <string>com.microsoft.teams</string>. correctly? or is it something else? is it com.microsoft.teams2 I added the 'defender' entry but not sure if that is correct/necessary/needed. (defender didn't get installed) <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><array><dict><key>attributeSetting</key><integer>0</integer><key>choiceAttribute</key><string>selected</string><key>choiceIdentifier</key><string>com.microsoft.OneDrive</string></dict><dict><key>attributeSetting</key><integer>0</integer><
Seeing inconsistent deployment of a Config Profile that is required for use of CISCO Secure Client. "the current system configuration does not allow the requested operation" My device it installed fine (15.1) on another device (15.1), it gets the above message in the JAMF device record. The config profile does have one kernel extension being deployed Kernel Extension Bundle ID com.cisco.kext.acsock
I have an in-house Automator app I need to distribute to my teacher fleet of laptops. There used to be an in-house app upload space (a while ago) that I no longer see. This is the first time I have needed to distribute a non App Store app. How are folks handling uploading and distribution of non App Store apps?
Is there any way of configuring JAMF to send out login credentials for the Google Apps so students are not required to sign into each Google App? Currently, they need to sign into Google Docs, then Google Drive, then Google Sheets, then Google Slides, etc This is time consuming with younger grades. Hoping there is a AppConfig way of auto signing into each of those apps based on username and email address fields.
The Autoactivationlink is not passing through to the application. The mobileconfig provided is for Intune, the vendor does not have a Jamf version. I am also having trouble getting it to pull the USERNAME and DEVICE_NAME from the system, I tried the original palceholders {{Username}} {{Devicename}} and the ones you see now.. I have obscured the link as it is unique to our license. <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><!-- This profile contains all CIRA DNS Firewall specific settingsFor detailed information on these options, please see the MDM specification"--><plist version="1.0"><dict><key>PayloadContent</key><array><dict><key>PayloadContent</key><dict><key>ca.cira.secure.remote</key><dict><key>Forced</key><array><dict><key>mcx_preference_settings&
Hello,I continue to get this message when I am on JAMF Pro Cloud ... Poor network connection strength.Changes may not be saved. I have tested our network - and speed is fine. We do not have any other problems on any other sites. I have checked out firewall. Everything fine. Any suggestions? Nikole
I have set up an API Role, and Client. When I go to retrieve the token, I am seeing an error on my PC, but not on my Mac. When I go to retrieve the token, on my PC I get this error: curl: (35) schannel: next InitializeSecurityContext failed: CRYPT_E_NO_REVOCATION_CHECK (0x80092012) - The revocation function was unable to check revocation for the certificate. If I add "--ssl-no-revoke" to the curl command, it works fine. My Mac is managed by Jamf, and it has a couple of Jamf specific certs installed. I am assuming I need a certificate on my PC. Any help on how to get this going would be appreciated. Dave
Hey all,Does anyone have a solution to automatically install apps upon enrolment from the mac apps app store and then make them available in self service as well?Appreciate any help or advice, Thank you!
So I've created a new package using Jamf Pro web GUI, pointed it to a newly uploaded file on repository, and tried to deploy, but all installs are failing because the "package could not be verified". Never had this issue with Jamf Admin...just sayin' Jim
If you're like me, you wear many hats at your organization, and if your organization is like mine (higher education) your staffing is lean. You may think, as I once did, that you don't have time to start enforcing macOS security compliance, or even see why you should. But in today's climate of evolving threats, increasing regulation, and high-profile settlements, it's likely that you'll need to get started sooner than you think. First of all, if you're new to security compliance, you might want to check out my presentation from PSU MacAdmins 2024, where I went into detail about how the macOS Security Compliance Project (mSCP) works together with Jamf Compliance Editor (JCE) to help you build a framework you can use to: set a compliance baseline, check your fleet to see what's compliant and what's not, report on those findings, and fix non-compliant devices. There are plenty of great resources on how to use mSCP and JCE, so what I'll concentrate on is the planning and staging.&nbs
Looking at setting up single app mode for a Mac and it is failing (The “Assessment Mode” payload contains an improperly formatted key: “AllowedApplications”.)The one thing I know I'm missing is the Team identifier for the app. My test app, Chess, doesn't have it.I'm using com.Apple.Chess as the bundle identifier.I can only guess as to what is actually breaking it.
I haven't had to do much with extension attributes yet, looking for an easy way to determine if something is installed and the version number, and if it isn't installed, to also note that. So the command I run on a local machine is: sysctl cs.version That will return the version number of the Falcon Host installed, something like: cs.version: 2.27.4809.0 If the application isn't installed it returns: sysctl: unknown oid 'cs.version' Ultimately I will use a smart group to make sure Falcon Host is installed, and if it is not installed, to flag it for installation. The version number is just nice to know. Is there an easy way to do this that anyone would know? If it works, I'm happy to submit it to the EA list as well.
I am helping setup a JAMF solution with a SCEP server. We have everything setup, seemingly, but the assignment of the certificate fails from the SCEP server with the 400.0.64 error code. I was wondering if the fact that the MACs are not in DNS is causing this issue. I ask because I know certificate servers normally need to see the device in DNS that they are giving a certificate to. Could that be it?
Despite having a deferal or Sequoia, we have just seen a few dozen Intel based Mac's upgrade themselves to from sonoma to Sequoia 15.1 today. Has anyone else seen anything like this happen?
Hey guys, This past summer I updated a couple computer labs from Monterey to Sonoma and I was able to login with it. I tried to login to one of the MacBook Airs this week and it's not accepting my password. I grabbed another laptop from the lab and same thing. This has never been an issue in the past and I know I am entering the correct password. The account is created in the PreStage Enrollment. I did some looking into this to see if anyone else is having this issue. It sounds to me like it could be a LAPS issue. I watched a couple of JNUC videos about LAPS and read a post about "How to Securely Manage Local Admin Passwords with Jamf Pro and LAPS". I never turned it on and I checked my Computer Management->Security settings and my jamfinstance/API and it looks like it's still off. Anyone else have this issue or have any ideas? Thanks!
Hello, I have recently set up a device compliance connection between Jamf Pro and Intune. I was able to successfully register my test devices without issue so I pushed it out to a handful of IT users. When they try to register, they are receiving an error that states: "Helpdesk support required Your organization needs to enable partner device management for you before you can enroll. Please contact your helpdesk" Our legacy conditional access policy is currently terminated and was never scoped out to any users, so I am unsure why this message appears. Any advice?
Hi, I've currently got an extension attribute for "Brand" for our retail company and am wondering if there is anyway to have our iPads display a drop down during the enrollment stage to select the brand they belong to for the corresponding configurations to apply correctly? I've seen how I can add text to the enrollment page but unsure how to link the extension attribute Any help would be greatly appreciated. Regards, Danyon
Trying to deploy extensions via DMG, but everytime I deploy it and I launch Chrome, the extension simply disappears from the folder... anyone have any idea why?
We are looking to set up a content cache server in a network that has more than two public IP addresses, with devices connected through GlobalProtect VPN. Could someone please guide me on how to configure the custom Public IP address section to ensure that devices can access the cache, whether they are connected via GlobalProtect or directly to the local network? All devices are enrolled at Jamf.
Hi All, does anyone know/have extension attributes to find installed extension in Safari browser?
Need help to block file sharing via SMB in Mac only allowed Mac need to copy file in same network.also want to block FTP/SFTP file share and allow only particular ip.
Forgive by ignorance, but is jamf able to reset passwords if the user is not logged into a local account? I am seeing the option in policies, but I am unsure of how to trigger it before the user logs in. I attempted to set the trigger to startup and change in network state, but both remain pending when restarting the device to the login screen. Also, I am not seeing a network symbol on the login screen for any device and am thinking I need to adjust configuration profile so network access/settings can be accessed before logging in? If so, where do I access this? I am reviewing the restrictions on the devices and I am not seeing them.Also, is this ill-advised? I can see how doing this sort of thing would be unwise from a security perspective.
I have been fighting with this issue for several years with a variety of Apple TV devices - all newer ones without the USB port built in. The issue occurs because of two things:Through JAMF, we have placed the Apple TV in Conference Mode.The Apple TV has been turned off long enough to no longer have a valid certificate for JAMF.The end result is that the Apple TV is stuck in conference mode, but since it is no longer communicating with JAMF it cannot be taken out of conference mode. The only option is to factory reset, which then leads to a NEW problem - when I get to the factory reset screen, the remote no longer works to actually select the "Reset" option. Here is the general process I do:Boot the Apple TV that needs a resetPair a remote to the Apple TVBoot into recovery mode (power cycle multiple times, interrupting the boot each time, until the recovery mode screen appears)Attempt (usually unsuccessfully) to use the remote to select the Reset option and reset
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!