Get Support
Recently active
Hi, A little while ago I noticed the Remove Sophos Endpoint.app had appeared on my Mac. After checking other machines I can see it's installed on everything. Not cool. I ran a script to remove it from all the Macs and manually deleted it from mine. However, it reappears in /Applications the next day. I've been running a daily script to remove it from all Macs but now it's getting to me. I can match up a Sophos update in the logs to the same time the app was created last night so it appears to be pulling it down when Sophos updates. Although I 'think' it's only doing this once a day. Most logs show Sophos Anti-Virus is up to date but the one that i think is downloading shows as Sophos Anti-Virus was updated. Update is pointing at Sophos as the primary locations (no secondary) and if i force an update the app doesn't install. Has anyone else seen this behaviour? (I don't want to have to open a ticket with them as previous experience
How do i go about removing apps from an iPad. It is setup that pupils cannot delete an app from the iPads. I have went into Jamf self service to see if it gives me the option to uninstall but it doesnt.Thanks
Hi folks, i try to force a device (macbook pro) to update to the latest MacOS. I created a testgroup which contains this computer. Then i go to software updates, choose this group and then i choose a specific version or latest possible (makes no difference). Install option is "download and install with referrals (2)" In Jamf Pro computer management it shows this job....but nothing happens. On this computer every user is an admin....so it can´t be an AppStore setting. Any idea? Greetings Frank
Hi, Whether updating through Jamf Pro or manually running the pkg to update Zoom, I've been getting this message since Zoom 6.1.11. "Your Zoom application is being managed by your IT administrator. Please contact your IT administrator to request an update." I do have a configuration profile in place to only allow the screencapture settings for Zoom. That has been working fine for years. Anyone have this same issue or know what's wrong? TYIA
Dear All Let me first start by apologising as I am new to APIs and getting them working, also fairly new to scripting. I have checked on the forums and I keep going around in circles. I have spent a lot of the weekend trying to get this to work and even trying to get chatgpt to assist (But its a bit useless). I am trying to build out an asset system on Google Sheets where I pull in inventory data in one (Live) tab and then use a lookup formula to pull in the relevant data from the LIVE tab into another TAB. WHAT I WANT TO ACHIEVE I want to be able to build a Google Script that pulls inventory data from JAMF into a tab called LiveInventory on my Google sheet.I have created an api user and defined clients/roles/privileges in JAMF. I've also setup an advanced search for the api user.What I have is so far from following some instructions are- USER CREDENTIALS- CLIENT ID- CLIENT SECRET- JAMF URLI tried copying a script from years ago but to no avail. Please help and my ap
Came across an issue with Get Add-ins being greyed out and all the add-ins removed. This is happening on different OS and Office versions. I don't think it's affecting that many people just curious if anybody else has seen this. We use "Report Phishing" add and some users didn't have it and the "Get Add-Ins" was greyed out. If you go to Outlook settings>Privacy and uncheck/check "Turn on optional connected experiences" the add-ins come back. Our Add-ins are handled by 365 and our exchange admins confirmed it's not something on the backend.
Hi all,I've had a search through previous posts about this and I can see the question has been asked before a long time ago (4-5 years) with no resolution. I'm hoping someone can tell me whether this is possible or not.I want to deploy an SSID using EAP-TLS and have client devices use a machine certificate to authentictae when a user is not signed in, then, when a user does sign in, to have a user certifcate used for authentication.Ideally the flow would be:No one signed in - device uses machine cert to authenticate to wi-fi, can receive updatesUser A signs in - new authentication occurs using userA certUser A signs out - new authentication using machine cert againUser B sings in - new authentication occurs using userB certetcThis is to support network level access control.The previous posts i've read have mentioned issues with one profile overriding another or the client device sticking to just one profile.Has anyone ever got this working? Annoyingly it's straight forward to do on Win
Hey Jamf Nation! I have a short script set to run once per computer at recurring check in. I am also about tell Jamf to update macOS from 14.7 to macOS 15. I believe individual Macs check for macOS updates as part of the recurring check in (very easily could be wrong!). My question is, which happens first? If a Mac contacts Jamf as part of a recurring check in, and finds out it is due for both a script to run and a macOS update, which does it do first? Thank you all!
I don't know if my subject made sense, but here goes... Most of the software installs we deploy go through a two-step process: cache the installers, then run the installers. I'm testing different ways to run the Adobe CS6 installation (at logout, in the background, at startup, etc.), but to save cooking time, I'd like to be able to cache the hefty-sized CS6 .pkg file from a Mac that has a local distribution point, over either a Firewire or Thunderbolt connection instead of letting it cache from our JSS server. Occasionally we'll push out cached .pkg files through Casper Remote, but it doesn't appear to interact with the local distribution point the same way that Casper Imaging can. Am I missing something or is this not possible through the standard Casper suite? Thanks! JSS 8.62, etc, etc.
I previously used a PLIST for managing Chrome and Edge including pushing 2 extensions for all users. This worked, it pushed them in an active state, no problems. Seeing you can now get nice JSON config files that let you toggle any setting within Jamf I switched to that but when push the 2 extensions they are both loaded, locked but disabled. Its my understanding that you can add keys in an additional plist to configure extension settings, including if its enabled or disabled but so far not been able to find how. Anyone know?
Does anyone know if it is still possible to prevent the removal of management profiles on Jamf Pro for iPads?I believe there used to be a iPad restriction to do this. I can't seem to find it now.Any help would be most appreciated.
Hi everyone, i'm currently trying to create an advanced search that will show me all devices that didn't manage to install our webclips configuration profile. We are using devices in a shared iPad, temporary Session only mode, so the configuration profile has to be installed every time a guest user is being logged in. The profile then stays on the device, even after the user logged out and only if a new guest user is being logged in the "old" profile gets removed and reinstalled or at least that is how it appears to be working. I didn't find any other criteria than "Profile Name" that would let me search devices for installed configuration profiles and it seems to be the correct criteria, but it looks like its either not working correctly or its not meant for what i am trying to achieve, although Jamf lists every configuration profile as possible value. If i use the criteria like this: "Profile Name [Operator] has [Value] BIZ_PROD_Webclips" i only find 2 devices which do have the profi
Hi, I am trying to create the Nexthink package in jamf pro need to deploy 200+ MacBooks and am unable to create the yet not found any steps related to this. I got only a profile from the Nexthink sitecan anyone guide or share the step for Nexthink collector deployment? Thanks
Hello After the autoupdate to Skype 8.60, i have users getting an prompt to imput local admin credentials whenever they start Skype.After some investigation, i concluded that skype wants access to a private key in the SYSTEM keychain, and the problem goes away if you just add it manually. Does anyoane have any ideeas regardng how to solve this? I guess i will have a few hundred people having this problem and i have no clue how to solve it for everybody at once, and user by user is quite out of the question.
I have iPads that I have enrolled in Casper with DEP, but after activationsetup there is a re-occuring prompt to "Sign in to iTunes to allow Casper to manage and install apps. With the ability now to deploy apps without an Apple ID, I have no reason to log these iPads in to the App Store but I can't find what is causing this prompt or how to stop it.
I circulate iPads using Jamf and Apple Configurator. A recent OS update has started prompting this error message:App InstallationSign in to iTunes to allow "<my JAMF server URL>" to manage and install apps.Has anyone found a way to suppress this error? I have turned off the App store in my configuration profile, but still seeing this error pop up on these iPads.
While testing a Self Service policy to install Adobe Creative Cloud Master Collection 2015, I was greeted by a Finder dialog box informing me I was nearly out of disk space. The following script leverages JSS Parameter 4 and verifies there is enough available disk space before continuing with the policy. If there is not enough free disk space, a message is displayed to the end-user and Self Service is forcibly quit. (Is there a way to just simply stop the policy and leave Self Service running?) #!/bin/sh #################################################################################################### # # ABOUT # # Check Free Space: Leverages JSS Parameter 4 to verify there is enough available disk space before continuing with the policy. If there is not enough free disk space, a message is displayed to the end-user and Self Service is forcibly quit. # #################################################################################################### # # HISTORY # # Version
We are trying to find a way to disable Bluetooth File Sharing and prevent re-activation by clients. I've successfully disabled it several different ways via scripts but the issue is preventing the re-enabling by the clients. User Level MCX or Configuration Profiles will disable it at login but then the client is able to re-enable it again until they logout or restart; same goes for running the scripts as part of a policy at login. I could run a policy on the every15 but that still leaves security holes and is a less than ideal approach. The Sharing pane in System Preferences doesn't require Admin rights to access and as far as I can find, there isn't a way to grey out the Bluetooth File Sharing box inside of it. Any suggestions are appreciated!
Background Like most organizations, we want the best — most secure — experience for our users. So, naturally, we’ve investigated leveraging Managed Apple IDs. While Managed Apple IDs come with some significant limitations, my personal favorite has to be: Allows browsing but not purchasing, paid or free in: App Store However, the promise of a Shared iPad is quite alluring. The Rub I also suspect “the rub” for most organizations who wish to federate their domain is Apple’s unwillingness to inform the enterprise which of the enterprise’s users will be impacted before federation is enabled: … but you can’t see their actual personal Apple ID. Get notified about federated authentication user name conflicts, Item No. 7 Script The following Domain Apple IDs Jamf Pro Computer Extension Attribute will inspect the current (or previous) logged-in user’s MobileMeAccounts.plist for Apple IDs associated with domains included in the domainsT
Our Admin team would love to be able to log into JAMF School at the beginning of the morning and get a "quick report" of the battery life across the campus to see who is not bringing their devices fully charged. I could envision it like the current circle graphs that you make with buckets: 90% and above - 80% -89% - 70% -79% - 60% -69% and anything below 60%. Ideally this would require a special "check in" command to happen every day a specified time as well. (So all devices check in around 7am) or allow us to assign that special check in time based on device group so we can stagger the timing. But we only have 1000 devices.
How do you guys have your road warriors login to Jamf Connect from public wifi with captive portals?I only have a few users that do this but wonder what the Jamf Connect config setup is like.
I attended JNUC in both 2023 and 2024 and finally have got around to implementing Installomator as per https://www.youtube.com/watch?v=p2J6fTQXIwU. Lots of people were talking about it and in 2024 was convinced to at least try it. The implmentation in the video uses two Smart groups. Smart group targetting "Patch Reporting" for the targetted application. For example, the criteria would be Patch Reporting: Google Chrome is less than Latest Version. Smart group targetting the above group because you can't target policies using Patch Reporting directly as per the video. The first group using Patch Reporting updates just fine. My issue is the 2nd group does not update correctly. When I initially save it the numbers match but after testing by updating an app the 2nd group will not update to reflect the number of the 1st group. The only way to update it is to go in and edit and resave the group. Then it will update correctly until the next time it
This one of the new MacOS DDM management features we were most looking forward to. Why is Jamf locking this to the cloud?
Hello everyone, For the Chrome browser, I've created a PLIST for installing the extension and a second one for configuring the extension, and it works perfectly. That's why I'd like to do the same for Firefox. The PLIST for installation works. But for the extension configuration PLIST I don't know how to do it? I can't find any information about this if it's possible. Here's what I did for Chrome : Preference domain : com.google.Chrome.extensions.IDextension <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>ConfigJson</key> <string> { "backend_servers": [ { "title": "Exemple title", "url": "https://exemple.com" } ], "base_url": "https://exemple.com", "allow_custom_server": false, "allow_registration": tru
We have all our managed iOS devices in Jamf Pro. We have most of these also in Jamf Security Cloud but need to remove some of them from there. What is the proper order to remove them from Security Cloud so the device is still usuable for the end user without any interaction on their part? We have the Jamf Trust app pushed out through Jamf Pro as well as a configuration profile containing the certificate, JamfSecurityCA.crt, and content filters and DNS settings are specified for Security Cloud and I can easily remove that app and configuration profile from the device, but I don't think that will remove the content filtering or data usage policies from the device that are setup in Security Cloud.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!