Get Support
Recently active
I created the Cisco Secure Client package (version 5.1.2.42) using the Cisco documentation . It was working fine, but now I am seeing the error "No connection to VPN service. Reattachment failed" (Screenshot attached). I don't know what could be the root cause. Any help would be appreciated. https://support.umbrella.com/hc/en-us/articles/23515921165844-How-to-deploy-Cisco-Secure-Client-via-JAMF-MacOS
Hi everyone, I set a code every afternoon on the iPad of my daughter to set screen time limits. The iPad also has Jamf School to restrict the usage of applications while children are in the school. Every time I check in family, the code enforcement is gone.Either my daughter knows how to hack it, or Jamf is interfering with family. I would like to ask you, if you have experience something similar? Best regards, Paul
Is there a way to disable Password Manager in Settings? I don't want users to be able to view passwords nor add a password to the password manager for iPad/iOS devices.
Hi, I want to migrate my on prem installation of Jamf Pro to a clustered environment. What are the best resources on how to proceed. Until now I dont have any knowledge on clustering, so a complete overview on what to do would be appreciated. Kind regards
Hey everyone, We're currently in a situation where we have users mixing their corporate/managed and personal/unmanaged apps on our devices (please don't ask why, it's a long story). Unfortunately, this leads to some of them being unable to back up personal data into their iCloud, as the app is seen as a managed app, and iCloud backups aren't allowed for managed apps.It seems to me the most straightforward solution would be to convert the apps from managed to unmanaged. But I can only find information going from unmanaged to managed. Does anyone know if it's possible to convert an app back to unmanaged once it's been managed and how to do that? Cheers,Phil
Just wanted to give a quick issue-resolution I came across; our Jamf School instance (set up by someone else) has an issue with apps for macOS lingering in the "Pending" status. I am new to MDM, but my initial thought was that it was due to multiple device groups calling on Google Chrome to be installed, we have an "All Mac's" group and a "Student Group" both having Chrome and multiple other apps scoped to them simultaneously. I had a machine I was erasing for a student and I found no apps were getting past "Pending", so I decided to attempt to manually place another app on there not typically given to students, and boom, all the apps started installing. I have gotten most of them down, but there are still a few apps that are lingering now on "Installing", could that be due to those apps attempting to install themselves from multiple groups?
Just wondering if I missed something ... Could it be that Apps from the Mac App Store do not work with Smart Groups in Jamf Pro 11.11 ? Since changing the target for some MS Office Apps to a Smart Group, those Apps do not receive any Updates on the Macs in the scope of the Smart Group. The MDM Management history looks like this:
Can you also send the invoice for ‘Jamf 170 course Certification’?
I'm deploying the following PLIST config to Macs but users can still sign into other OneDrive Business accounts and they can still disable folder backup. Is there anything wrong with the below config? <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>AllowTenantList</key><array><string>482a4ef9-66e4-4e76-9f24-6da09a713ee5</string></array><key>BlockExternalSync</key><true/><key>DisablePersonalSync</key><true/><key>DisableTutorial</key><true/><key> KFMBlockOptOut</key><true/><key>KFMSilentOptIn</key><string>482a4ef9-66e4-4e76-9f24-6da09a713e5</string></dict></plist>
Dear all, on our Jamf Pro installation, an upgrade from 11.7.1 to 11.9 fails: 1. We first try to follow the instructions here to migrate from Java 11 to Java 21 which is required for Jamf 11.9: Jamf Lernzentrum -> We are not able to stop Tomcat ("failed to stop. exit status 5"). Nevertheless, the uninstallation of Java 11 works, also the installation of Java 21. 2. The installation of JAMF 11.9 also works with no errors. 3. Out Jamf instace https://jss.<domain>:8443/ is not available after the upgrade. Any ideas?
Hi Jamf Community, I’m working on setting up an Extension Attribute (EA) to automatically detect devices with stuck MDM commands (e.g., commands that are pending or failed for an extended period). The goal is to use this EA as a trigger for a self-healing policy that runs once daily for affected devices. Here’s what I’ve considered so far: 1. API Approach: • I explored the Jamf API but haven’t found an endpoint that provides detailed or reliable information about stuck commands. • If there’s a way to identify such commands via the API, I’d love some pointers or examples! 2. Local Machine Logs Approach: • This seems like the most promising path. My idea is to check logs on the local machine for the last executed MDM command and flag devices where no command has been executed in the past 24 hours (or based on statuses). • Are there specific logs or methods Can I extract this information programmatically? If anyone has experience implementing a similar solution or insights into l
Hey, We have multiple sites in our Jamf pro because we are a group of companies. Now we want to assign sites during the prestage enrollment. So, when the user will connect a new laptop with the internet, then it should pop up an option with site names so the user can select which site he/she belongs. Based on that, he will receive the enrollment customizations and policies made for that specific sites. It is working fine with user initiated enrollment but I can't figure out how to do that with prestage enrollment. Can anyone help? Thanks
HiWe have one student whose iPad is locked down. Obviously we have to allow access to certain apps so that the student can work, however we discovered today that even though the student has his web browser restricted they are still able to open it when accessing a link from the gmail application.Has anybody come across this before? Thanks in advance!
This week of the Mac Admins Podcast, we spoke with Jamf's VP of Product & Solutions Engineering Matt Vlasach to talk about Network Relays, and how they can be used to secure network traffic. Relays are different from -- and newer than -- a VPN in a lot of ways, and they're not as well understood. Matt joins hosts Marcus (Jamf SE) and Tom (JumpCloud Product Director) to talk about what makes Relays new and special for Mac Admins. Relays are a complicated technology behind the scenes, but Matt breaks it down into some key components for Mac Admins to understand. The [MASQUE protocol](https://datatracker.ietf.org/wg/masque/about/) that drives Relays is highly secure and private, and the client is built directly into the operating system, all you need to turn it on is an MDM Profile, and if necessary, a per-app VPN. Matt talks at length about Relays are a "yes, and" technology that can go hand in hand with your regular VPN client, allowing you to ensure that key comp
Hi All, I am trying to get the user and location details auto populated in Jamf Pro for each user after enrollment, has anyone got a Script for auto populating user information after or during enrollment with Entra ID? Thanks
Just a quick question. I have a problem where I cannot login with a Pre-Stage Enrolled admin account any longer. I was at first but not now. https://community.jamf.com/t5/jamf-pro/cannot-login-with-local-admin/m-p/332899#M281166 I was in Zoom call with a Jamf tech and I am able to login with a Standard Student account. He had me run a command in Terminal and Secure token is enabled for both my Admin account and Student account. He asked for the logs on the mac but I can't navigate to /Var/Logs because we found out that a Standard User doesn't see "Go to Folder..." in the Finder Go. To help him out does anyone know a way around this? He escalated the call to an engineer.I could also create a new policy to create an admin but I thought I would ask her first before I do so. Thanks!
We have discovered a large number of Macs in our fleet that appear to no longer have the Jamf agent installed on them. This may be because users used the "jamf removeFramework" command on them. I have been working on figuring out how we can get these systems re-enrolled. For years I have used the command "sudo profiles renew -type enrollment" command to re-enroll Macs that are in Apple Business Manager. Running this command requires me to interact with the Mac to complete the enrollment process. I tested this a few days ago on my test Mac to take note of everything that happens after the profiles command is ran. We would like to do this in the background silently. We have an agent called Aternity installed on all of these Macs. We know they're in use and active. They're just not connecting to Jamf Pro. Aternity can send scripts to the Mac, and my thought was that we could run the profiles renew command in a script pushed out to these Macs. Are there any options that can be used with th
I'm currently testing JamfConnect in preparation for deploying across my organisation (approx 50 devices). I'm having issues with the privilege escalation component in particular. User starts the workflow as a Standard (non admin) user. User cannot execute sudo jamf recon, receives the error message "Sorry, user test.x.user is not allowed to execute '/usr/local/bin/jamf recon' as root on <hostname>". This is expected as user is still a standard non-admin user User requests privilege elevation via Jamf Connect menu bar. User authenticates with Jamf Connect, provides a justification/rationale for elevation. User is now an Admin user in System Settings > Users and Groups, and menu bar shows that the user has 10 mins of elevated privileges User attempts again to execute sudo jamf recon, but still receives the same error message as if they have no administrator privileges User ends the privilege elevation session, they are then bumped back down to a Standard User accord
My school wants to change our own school Wifi by making it public by changing it from an WPA 3 to WPA Enterprise with username and etc is there a way to link it with IPads and other Devices so that it would be possible to see what each student does instead of just seeing the IP address and device name maybe even deactivate the private Wifi address setting on iOS?
Before I go through the pain myself, I like to take the lazy route.... Anyone ??? Thanks
Because of CIS we have disabled Bluetooth Sharing using a configuration profile. However we found out that it is still possible to send data from a Mac to an Android device using the Bluetooth File Exchange app.Data exchange between macOS and iOS is being blocked as expected.Have you come across this as well? What have you done to remediate (other than adding the Bluetooth File Exchange app to restricted software)?
"Leave Remote Management" feature remains active on iOS devices and user can remove MDM profile with passcode. What could be causing this issue, and how can it be resolved to ensure that users cannot remove MDM profile.Device enrolled by Pre-stage Enrollment. Below settings have been done in prestage enrollment profile.
I was recently tasked with enabling DLC on 10.11 El Capitan iMacs in lieu of connecting them via Fiber. Since I found very little information about how to do this from JAMF, Quantum, or Apple, I thought I would share my solution. Distributed LAN Client (DLC) is basically a Fiber over ethernet connection Xsan can use. It doesn't have the same level of throughput, but it is an excellent solution for users who historically have needed Xsan access but who aren't doing real-time rendering. Reference Material:- Quantum | StorNext 5 Link: Here- Apple Xsan Reference: Here Benefit of using JSS:Without a JSS the setup is more difficult. Quantum server can provide a Configuration Profile (unsigned). If you manually load the unsigned profile, Apple's SIP security blocks it from running, and if you turn off SIP (which I don't recommend) you still have to work out a script to map the drive if it doesn't initially map at login. If the profile is pushed via JSS the profile i
Jamfsters, am trying to setup an extension Attribute that will tell me if proofpoint is running on the system. After looking at the activity monitor is under logger (4599) I am new to scritpts can someone point me in the right direction?
I have a script that I run on machines to get them to do macOS updates and upgrades. Since the "Update plans" came out of beta I have modified my script to use plans when it is enabled. I have noticed that on macOS 15, if the script runs while a user is logged in and I set a plan via the following: curl --request POST \\ --silent \\ --url $JAMFServer/api/v1/managed-software-updates/plans \\ --header "Authorization: Bearer ${authToken}" \\ --header 'Accept: application/json' \\ --header 'Content-Type: application/json' \\ --data ' { "devices":[ { "deviceId": "'${ClientID}'", "objectType":"COMPUTER" } ], "config":{ "updateAction": "DOWNLOAD_INSTALL_RESTART", "versionType":"SPECIFIC_VERSION", "specificVersion": "'${UpdateVersion}'" } That the macOS 15 machines will pop-up a dialog informing the user of a need to restart and it gives them the option to 'do later". Under the previous setup, when the command was sent: curl --request POST \\ --silent \\ --url $JAMFServer/
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!