Get Support
Recently active
Came across an issue with Get Add-ins being greyed out and all the add-ins removed. This is happening on different OS and Office versions. I don't think it's affecting that many people just curious if anybody else has seen this. We use "Report Phishing" add and some users didn't have it and the "Get Add-Ins" was greyed out. If you go to Outlook settings>Privacy and uncheck/check "Turn on optional connected experiences" the add-ins come back. Our Add-ins are handled by 365 and our exchange admins confirmed it's not something on the backend.
Hi all,I've had a search through previous posts about this and I can see the question has been asked before a long time ago (4-5 years) with no resolution. I'm hoping someone can tell me whether this is possible or not.I want to deploy an SSID using EAP-TLS and have client devices use a machine certificate to authentictae when a user is not signed in, then, when a user does sign in, to have a user certifcate used for authentication.Ideally the flow would be:No one signed in - device uses machine cert to authenticate to wi-fi, can receive updatesUser A signs in - new authentication occurs using userA certUser A signs out - new authentication using machine cert againUser B sings in - new authentication occurs using userB certetcThis is to support network level access control.The previous posts i've read have mentioned issues with one profile overriding another or the client device sticking to just one profile.Has anyone ever got this working? Annoyingly it's straight forward to do on Win
Hey Jamf Nation! I have a short script set to run once per computer at recurring check in. I am also about tell Jamf to update macOS from 14.7 to macOS 15. I believe individual Macs check for macOS updates as part of the recurring check in (very easily could be wrong!). My question is, which happens first? If a Mac contacts Jamf as part of a recurring check in, and finds out it is due for both a script to run and a macOS update, which does it do first? Thank you all!
I don't know if my subject made sense, but here goes... Most of the software installs we deploy go through a two-step process: cache the installers, then run the installers. I'm testing different ways to run the Adobe CS6 installation (at logout, in the background, at startup, etc.), but to save cooking time, I'd like to be able to cache the hefty-sized CS6 .pkg file from a Mac that has a local distribution point, over either a Firewire or Thunderbolt connection instead of letting it cache from our JSS server. Occasionally we'll push out cached .pkg files through Casper Remote, but it doesn't appear to interact with the local distribution point the same way that Casper Imaging can. Am I missing something or is this not possible through the standard Casper suite? Thanks! JSS 8.62, etc, etc.
I previously used a PLIST for managing Chrome and Edge including pushing 2 extensions for all users. This worked, it pushed them in an active state, no problems. Seeing you can now get nice JSON config files that let you toggle any setting within Jamf I switched to that but when push the 2 extensions they are both loaded, locked but disabled. Its my understanding that you can add keys in an additional plist to configure extension settings, including if its enabled or disabled but so far not been able to find how. Anyone know?
Does anyone know if it is still possible to prevent the removal of management profiles on Jamf Pro for iPads?I believe there used to be a iPad restriction to do this. I can't seem to find it now.Any help would be most appreciated.
Hi everyone, i'm currently trying to create an advanced search that will show me all devices that didn't manage to install our webclips configuration profile. We are using devices in a shared iPad, temporary Session only mode, so the configuration profile has to be installed every time a guest user is being logged in. The profile then stays on the device, even after the user logged out and only if a new guest user is being logged in the "old" profile gets removed and reinstalled or at least that is how it appears to be working. I didn't find any other criteria than "Profile Name" that would let me search devices for installed configuration profiles and it seems to be the correct criteria, but it looks like its either not working correctly or its not meant for what i am trying to achieve, although Jamf lists every configuration profile as possible value. If i use the criteria like this: "Profile Name [Operator] has [Value] BIZ_PROD_Webclips" i only find 2 devices which do have the profi
Hi, I am trying to create the Nexthink package in jamf pro need to deploy 200+ MacBooks and am unable to create the yet not found any steps related to this. I got only a profile from the Nexthink sitecan anyone guide or share the step for Nexthink collector deployment? Thanks
Hello After the autoupdate to Skype 8.60, i have users getting an prompt to imput local admin credentials whenever they start Skype.After some investigation, i concluded that skype wants access to a private key in the SYSTEM keychain, and the problem goes away if you just add it manually. Does anyoane have any ideeas regardng how to solve this? I guess i will have a few hundred people having this problem and i have no clue how to solve it for everybody at once, and user by user is quite out of the question.
I have iPads that I have enrolled in Casper with DEP, but after activationsetup there is a re-occuring prompt to "Sign in to iTunes to allow Casper to manage and install apps. With the ability now to deploy apps without an Apple ID, I have no reason to log these iPads in to the App Store but I can't find what is causing this prompt or how to stop it.
I circulate iPads using Jamf and Apple Configurator. A recent OS update has started prompting this error message:App InstallationSign in to iTunes to allow "<my JAMF server URL>" to manage and install apps.Has anyone found a way to suppress this error? I have turned off the App store in my configuration profile, but still seeing this error pop up on these iPads.
While testing a Self Service policy to install Adobe Creative Cloud Master Collection 2015, I was greeted by a Finder dialog box informing me I was nearly out of disk space. The following script leverages JSS Parameter 4 and verifies there is enough available disk space before continuing with the policy. If there is not enough free disk space, a message is displayed to the end-user and Self Service is forcibly quit. (Is there a way to just simply stop the policy and leave Self Service running?) #!/bin/sh #################################################################################################### # # ABOUT # # Check Free Space: Leverages JSS Parameter 4 to verify there is enough available disk space before continuing with the policy. If there is not enough free disk space, a message is displayed to the end-user and Self Service is forcibly quit. # #################################################################################################### # # HISTORY # # Version
We are trying to find a way to disable Bluetooth File Sharing and prevent re-activation by clients. I've successfully disabled it several different ways via scripts but the issue is preventing the re-enabling by the clients. User Level MCX or Configuration Profiles will disable it at login but then the client is able to re-enable it again until they logout or restart; same goes for running the scripts as part of a policy at login. I could run a policy on the every15 but that still leaves security holes and is a less than ideal approach. The Sharing pane in System Preferences doesn't require Admin rights to access and as far as I can find, there isn't a way to grey out the Bluetooth File Sharing box inside of it. Any suggestions are appreciated!
Background Like most organizations, we want the best — most secure — experience for our users. So, naturally, we’ve investigated leveraging Managed Apple IDs. While Managed Apple IDs come with some significant limitations, my personal favorite has to be: Allows browsing but not purchasing, paid or free in: App Store However, the promise of a Shared iPad is quite alluring. The Rub I also suspect “the rub” for most organizations who wish to federate their domain is Apple’s unwillingness to inform the enterprise which of the enterprise’s users will be impacted before federation is enabled: … but you can’t see their actual personal Apple ID. Get notified about federated authentication user name conflicts, Item No. 7 Script The following Domain Apple IDs Jamf Pro Computer Extension Attribute will inspect the current (or previous) logged-in user’s MobileMeAccounts.plist for Apple IDs associated with domains included in the domainsT
Our Admin team would love to be able to log into JAMF School at the beginning of the morning and get a "quick report" of the battery life across the campus to see who is not bringing their devices fully charged. I could envision it like the current circle graphs that you make with buckets: 90% and above - 80% -89% - 70% -79% - 60% -69% and anything below 60%. Ideally this would require a special "check in" command to happen every day a specified time as well. (So all devices check in around 7am) or allow us to assign that special check in time based on device group so we can stagger the timing. But we only have 1000 devices.
How do you guys have your road warriors login to Jamf Connect from public wifi with captive portals?I only have a few users that do this but wonder what the Jamf Connect config setup is like.
I attended JNUC in both 2023 and 2024 and finally have got around to implementing Installomator as per https://www.youtube.com/watch?v=p2J6fTQXIwU. Lots of people were talking about it and in 2024 was convinced to at least try it. The implmentation in the video uses two Smart groups. Smart group targetting "Patch Reporting" for the targetted application. For example, the criteria would be Patch Reporting: Google Chrome is less than Latest Version. Smart group targetting the above group because you can't target policies using Patch Reporting directly as per the video. The first group using Patch Reporting updates just fine. My issue is the 2nd group does not update correctly. When I initially save it the numbers match but after testing by updating an app the 2nd group will not update to reflect the number of the 1st group. The only way to update it is to go in and edit and resave the group. Then it will update correctly until the next time it
This one of the new MacOS DDM management features we were most looking forward to. Why is Jamf locking this to the cloud?
Hello everyone, For the Chrome browser, I've created a PLIST for installing the extension and a second one for configuring the extension, and it works perfectly. That's why I'd like to do the same for Firefox. The PLIST for installation works. But for the extension configuration PLIST I don't know how to do it? I can't find any information about this if it's possible. Here's what I did for Chrome : Preference domain : com.google.Chrome.extensions.IDextension <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>ConfigJson</key> <string> { "backend_servers": [ { "title": "Exemple title", "url": "https://exemple.com" } ], "base_url": "https://exemple.com", "allow_custom_server": false, "allow_registration": tru
We have all our managed iOS devices in Jamf Pro. We have most of these also in Jamf Security Cloud but need to remove some of them from there. What is the proper order to remove them from Security Cloud so the device is still usuable for the end user without any interaction on their part? We have the Jamf Trust app pushed out through Jamf Pro as well as a configuration profile containing the certificate, JamfSecurityCA.crt, and content filters and DNS settings are specified for Security Cloud and I can easily remove that app and configuration profile from the device, but I don't think that will remove the content filtering or data usage policies from the device that are setup in Security Cloud.
We've got a few devices that the Student app is giving a generic error on. We have enough licenses of it, wiped these iPads, tested other working ones. Any other ideas of what to check?
I'm trying to install Nexthink by using the script that was provided that has all the information in it. I'm issues getting it to run. In the path BASE_PATH="/Library/NexthinkInstall" should this be where I'm mounting the .dmg file? For instance, I created a composer pkg to add the Nexthink.dmg file to /private/tmp/Nexthink and then tried adding the completed postinstall script. #!/bin/bash# v5i - nxt_collector_installer.sh## Nexthink Collector Installation script for macOS## This script makes the following assumptions:# 1) The 'csi.app' folder from the Collector DMG is deployed to the endpoint. The installation# only needs that folder and not the full DMG.# 2) The deployment directory is configured below as 'BASE_PATH'# 3) This script is located in the same directory as the csi.app folder from assumption 1.# # Instructions: # 1) Modify the Nexthink Instance Settings in the section below# COLLECTOR_ADDRESS - The data collection address from the welcome email# CUSTOMER
We are running Jamf Pro v11.7.1I have setup devices in single app mode to Safari to grant access to select MS Forms.Staff you like to be able to adjust the brightness however Control Centre will drop down in Single App Mode.I have modified the Restrictions to allow Control Centre. This only shows the Control Centre bar on the Locked but it doesn't function, the bar disappears when Safari startsAm I missing an option or does single app mode kill Control Centre
Here's one out of left field, from my security group... We have a number of computers (Macs, windows, etc) reporting in CrowdStrike, Axonius, and other services. Not all of the Macs are enrolled in Jamf, for reasons good and bad, and we need to get them enrolled. The security team is looking for ways to deploy Jamf without needing to visit the computer (identifying user and location can be a challenge). I know nothing about whatever process CrowdStrike might use for this. I do know that installing MDM software on Windows computers can be done via Active Directory, and apparently CrowdStrike uses a some kind of method for deploying MSI or exe installers to Windows computers. I also know at one time Jamf had a quick add package that could, maybe, have been deployed from CrowdStrike or other tool that can support macOS pkg files, but today Jamf deployment depends on having the user, at the computer, download and install, with authentication, the Cert and MDM files.  
At one of the JNUC sessions, I could swear that a presenter commented that you could restrict access to the web console to specific IP ranges. This would be a good workaround for us to limit access to our 2FA jump host IPs rather than building a limited access JSS for this purpose. Am I taking crazy pills and made this up, or does anyone know how to configure such access, maybe via Tomcat settings?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!