Get Support
Recently active
Any MacOS device that's released into our production environment has location services enabled in the operating system. However, there has been a request to enable location services in Apps such as Chrome and Siri, which require admin privileges to unlock the Privacy settings. Is there any way this can be done via configuration profile or script? If this has already been answered, I apologize. I can't find anything on doing this on a per app basis though.
I'm distributing a configuration profile to users with rules for their password and I'm seeing a "Cancelled" status on some of them, about 7%. At first, I thought that it was something similar to the alternative status "Pending" and among the list of those with such a status are devices that have access to the Internet. After that, I tried to redistribute the profile again and one of the devices instantly got the "Cancelled" status, even though it doesn't have internet access at the time of getting that status.What does it mean? is there any way i can fix this?
Seeing this message on an old iPad Air so I'm not sure if that's the problem. User installed some kind of update but it's stuck at the Remote Management screen when connecting to JAMF. The error message continues "The configuration is not available". Reading through a lot of the other posts with a similar message when enrolling. I've so far tried removing it from pre-stage and adding back then waiting, I renewed the token from ASM as well as uploaded a new token from JAMF back into ASM. Our pre-stages don't have any certificates with them that would need updated like what fixed some others. I also erased it completely with a restore and update but still get stuck. Is this iPad too old? Maybe it's a different issue? I haven't seen this before but none of our other iPads are having problems.
Hi, i am locking my device to a specific app over time, but when the lock time expires the device is still locked to that app without exiting that app. Does anyone in the group have this problem, can you tell me how to handle it?
I am trying to follow the HCS guide to allowing Jamf Pro to send notifications for Slack, but under the channel, there is no "send emails to channel" under the integrations tab. Is there something that needs to be set up first? I have the Pro plan; does it have to be a higher plan?HCS Guide
I recently took a full-time position with a company for whom I used to consult on their Jamf instance. It had been a little over a year since I was on the system and in the meantime there had been a few other people with their hands inside it though it was mostly perceived as stable and left alone.But I recently discovered that in the intervening year, the APNS cert had expired. A new certificate was created (with a different AppleID) and the handful of iOS devices were re-enrolled. Since the Macs were still checking in, it was assumed that nothing needed to be done.I managed to find the original AppleID and found the cert under that login had been renewed at the same time. But it was the cert with the new login was uploaded to Jamf instead.I have both certs downloaded and I created an extension attribute to determine which computers have which cert topic. Of the computers that have reported in, it's almost 50/50!So I have a large number of computers that are still checking in but not
I have a script that worked before OS15. After updating to OS15, the script became abnormal. Even if it connected to the allowed SSID and obtained the IP address, it would turn off and on WIFI infinitely. The following is the script. Thank you for your help~~我有一个在OS15之前运行正常的脚本。在升级到OS15之后,脚本变得异常。即使连接到允许的SSID并获取了IP地址,它也会无限循环地开启和关闭WiFi。以下是该脚本。谢谢您的帮助~~我有一个在OS15之前运行正常的脚本。在升级到OS15之后,脚本变得异常。即使连接到允许的SSID并获取了IP地址,它也会无限循环地开启和关闭WiFi。以下是该脚本。谢谢您的帮助~~我有一个在OS15之前运行正常的脚本。在升级到OS15之后,脚本变得异常。即使连接到允许的SSID并获取了IP地址,它也会无限循环地开启和关闭WiFi。以下是该脚本。谢谢您的帮助~~ #!/bin/bash #!/bin/bash #!/bin/bash #!/bin/bash #!/bin/bash#!`/bin/bash` 文件内容: ```bash #!/bin/bash #!/bin/bash #!/bin/bash #!/bin/bash ```#!`/bin/bash` 文件内容: ```bash #!/bin/bash #!/bin/bash #!/bin/bash #!/bin/bash ```#!`/bin/bash` 文件内容: ```bash #!/bin/bash #!/bin/bash #!/bin/bash #!/bin/bash ``` # set the allowed SSID GUEST-VIP设置允许连接的SSID为“GUEST-VIP”。设置允许连接的SSID为“GUEST-VIP”。设置允许连接的SSID为“GUEST-VIP”。  
Hey, guys. Started testing Jamf Sync app, since Admin is going away (gone?). I was checking out the documentation and the latest bug fixes list that the upload timeout was changed to an hour to accommodate large uploads, but does not solve issue with files larger than 5GB on a JCDS2 distribution point. This concerns me as my most frequent uploads are Adobe apps and they typically are larger than 5GB. I have not had much success with the web upload of these installers in the past, which is why I continued to use Admin. I am attempting an upload now using Jamf Sync, but I suspect it may just fail as package is larger than 5GB. Progress bar isn't doing much either. What have your experiences been?Bug fixes• Changed the timeout for uploads to an hour to solve an issue with large uploads. This does not solve the issue with files > 5 GB that are uploaded to a JCDS2 DP.
Hi EveryoneI hope this document will help everyone who use Cortex in their environment for mac and manage via JAMF Pro. You can deploy cortex via Jamf. It is pretty simple and straight forward. All you need to follow PaloAlto Networks document: https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-7/cortex-xdr-agent-admin/cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-for-macos. Here you will find they have already pre-configure MDM profile for Cortex one for M1 and another one for non M1. you will get all those here: https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-7/cortex-xdr-agent-admin/cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac-using-unified-configuration-profile#id945ae538-41d5-4b65-ad37-233fd665e992. After download unsigned one upload to your Jamf pro and make some changes as required and follow the document if needed. After upload profile scope your machine to have them on endpoint before corte
Hello, We just started to implement Jamf and we want to configure Jamf integration with Intune. All the policies are in place and we are using company portal to make the enrollment. The issue here is that, after we run the Microsoft Intune Integration from Self Service, we have to login in company portal, after finishing the Company portal the user is prompted with this:If you click continue, you will have to make one more Azure sign in, but the login screen will get stuck after entering your password. My guess is that it get stuck due to system asking you if you want to save the password. The only workaround I found is to close the screen, sign in to Jamf and redeploy the integration script. This time, the enrollment will be done because you are no longer prompted to save the credentials. My question is: Is there something we do wrong or can this be solved? Regards,Traian
Environment WSS Agent, SEP/SES Web and Cloud Access, Symantec Enterprise Agent (with the Web Gateway capability) Cisco AnyConnect Client VPN Curious, has anyone encountered issues where proxied websites are blocked from loading when using SES web and Cloud Access together with cisco anyconnect in their environments? Scenarios: SES web and Cloud Access is enabled on the mac client and OFF VPN , and in office: Proxied Websites load fine SES web and Cloud Access is enabled + Cisco Anyconnect Client is connected :proxied websites do NOT load In office, everything is fine.. Windows clients work while connect to VPN
127.0.0.1:631/printers I set the defaults I want for the printer Works great, but just on my computer. I would like to use the file that is modified and push that out to other computers so they also get the defaults for printing. What file is modified?
Anyone have ideas on how to get the client to consistently present the computer name during the authentication attempt? My understanding is that the 'Use Directory Authentication' option in the profile configuration should be forcing this. I thought I came across an article from back in the 10.10 days where this was discovered as a bug and fixed in 10.11, did it come back?Problem Statement: Corporate managed macOS devices are intermittently failing wired and wireless authentication against the Aruba ClearPass policy. The issue appears to be that sometimes the Mac is sending the logged in user’s username for authentication rather than the Mac Computername which is what is expected. Additional Problem Statement context:When a Mac authenticates the authentication attempt is passed to the ClearPass policy manager. The ClearPass policy is expecting the Mac to pass along its Computername in the 'Username' field. It then validates that this Computername is in the Macs OU in Active D
Hi All, Has anyone got any information on how to create an app for the self service portal that allow a user run Jam policy script ? sudo jamf policy
Hi there, i had a message that our push-certificat will run out in 1 month. I probably made a mistake while renewing this cert. I generated a complete new one and now i cannot push to existing computers anymore. sudo profiles renew -type enrollment Registration with the administration server has failed.The update to an MDM profile contains another push topic What can i do? Frank
It would be nice to have a "notes" section in static device groups so I could add info like classroom locations and current teachers (i.e. these 20 ipads are spread across 5 classrooms 4 ipad each room). I could make individual static groups per room, but that seems like a lot of hassle with teachers/classrooms changing and moving. How do you guys keep track of ipad locations?
Does anyone have a script to use an EA to report on the Expiration date of the JAMF connect license or where this can be viewed on the device?
I am trying to create an API Role that has full access. Is there a way to do this without having to click every single privilege in the list? Am I missing something? Thank you for your help!
I'm wanting to enable the "Defer Updates of software updates" to block Sonoma when it comes out, but we don't have an outstanding Restrictions profile in place.So take this screenshot from below. This is some of the default things ticked/unticked etc in a Restrictions profile.So. if i JUST want to have the restrictions for defering software updates.....should i leave the existing options enabled....or....untick them all?I just don't want to push out a restrictions profile, and then block a load of things that perviously were allowed.Thanks
Hello all,We want to host caching servers in each site, and we've run into a few roadblocks in this area.The main one, is we want to tell the computers to only use the cache on the servers, and not cache locally. We could not find such an option.Another issue, we think we solved, was the fact the actual server had to be excluded from the policy that distributes the caching profile in order to configure it differently. Can anyone share their experience with caching servers? We just want all macs under the same public IP to reach the server that's on that site.
Is there a way to get a list of all installed software from the JSS? What I am looking for is a list of every installed application in our environment.
During integration of Jamf Pro with Entra, a Global Administrator account is needed and this account must exist on the Entra tenant. Often, we use the same account to set up the app registrations for Jamf Connect and to create the various changes for conditional access exemptions, etc. Once these are set up, can this Global Administrator account be safely removed from Entra without affecting any of the integrations or applications created?
Well I am not sure this is even possible to do, but here goes...Update Macs to OSX 12.3, and Google Meet screensharing has broken.I have a PPPC configuration set up to allow non admins to be able to authorise screensharing, all they have to do is go there and click the tickbox.The fix for the issue is...Uninstall google Chrome.Remove Google Chrome from the list in the System Preferences>Privacy>ScreenSharing.Reinstall Google ChromeAdd Google chrome back in to the list for ScreenSharing. Ok I can script finding all of the Chrome stuff and remove that. But how on earth do I go about removing it from the ScreenSharing list.I have around 400 Macs with possibly 2000 different accounts spread across multiple campuses, up to 80 miles apart. So the manual method of going to each mac in turn is not going to happen. Does removing it as the Administrator on each Mac, remove it for all users on each Mac? If so is there any way possible to script that? Any help will be greatly
Random question, but is it possible or are there any scripts out there that could report on Hardware issues? * Display issues/cracked screens (number of nits) * Overheating * Fan Issues etc
I'm attempting to create a configuration profile for GlobalProtect so that users don't have to enter the vpn server address. When testing the following which was added to a configuration profile in Jamf, it still prompts. Any ideas? And, yes, I have our real address in the one I'm using. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Palo Alto Networks</key> <dict> <key>GlobalProtect</key> <dict> <key>PanSetup</key> <dict> <key>Portal</key> <string>vpn.server.edu</string> <key>Prelogon</key> <string>0</string> </dict> </dict>
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!