Get Support
Recently active
Is there a way to remove web clips that have been created by users via an mdm command/profile? My issue is we have locked our student iPads so that they cannot remove apps from their devices, primarily so that they can't delete our filtering app. However, they still have the ability to create web clips, so some of our students have cluttered their iPads with web clips that now cannot be removed, since the profile treats web clips like apps. I know I could just hide the web clips, so that they couldn't be seen by the students, but then this would hide any of the web clips that we have specifically pushed out. I would really like to be able to send a command to remove web clips from a device, then have our district web clips just be resent to the device. Also, is there a way to restrict web clips being created on the device? Remove the "Send to Home Screen" option"
I am working on creating a good way to track Macs that are not communicating over MDM properly. I have several Macs that are not getting profiles installed, profile changes, and are generally not working properly with MDM communications. One way I have tracked them down in the past is to create a profile, scope it to all computers and then wait to see which Macs don't get the profile. This works, but I wanted to dig a bit deeper. I have been trying to use this command to find out if Macs are reliably working with MDM: log show --info --debug --predicate 'subsystem == "com.apple.ManagedClient"' --last 1h The time can be changed to what ever I want. It seems that this command is only gathering activity from the Mac, not incoming MDM activity. That's what I need. Running the command above will result in a lot of information so I have used grep to make the output more focused. So far, I haven't been able to identify communication coming from APNS. Just running the command from a Mac
On Saturday, November 23rd, 2024, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time ap-southeast-2 November 22 1300 UTC 1700 UTC ap-northeast-1 November 22 1500 UTC 1900 UTC eu-central-1 November 22 2300 UTC 0300 UTC eu-west-2 November 23 0000 UTC 0400 UTC us-east-1/2 November 23 0500 UTC 0900 UTC us-west-2 November 23 0800 UTC 1200 UTC Jamf Cloud Hosted Data Region Information
I'm trying to have OneDrive function on our company devices so that when they login and Onedrive prompts their login for Onedrive specifically it will automatically start backing up the local documents and desktop to Onedrive. I've tried a lot of variations and done a lot of searching through these forums but nothing's working. I have a Config Profile - > Apps + Custom Settings -> Upload -> com.microsoft.OneDrive. and below is the plist . Is there anything clearly wrong here, I'm stumped.<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>DisablePersonalSync</key> <true/> <key>DisableTutorial</key> <true/> <key>AutomaticUploadBandwidthPercentage</key> <integer>30</integer> <key>FilesOnDemandEnabled</key> <true/> <key>BlockExternalSync</key&
Today we released Jamf Connect 2.41.0. This release includes the following changes and improvements: Upcoming Support Removal for macOS 12.xSupport for macOS 12.x will be removed from Jamf Connect in a future release. Jamf recommends updating to macOS 13.x or later to ensure continued support. Other Changes and ImprovementsYou can now configure offline multifactor authentication (MFA) without integrating Jamf Connect with a cloud identity provider (IdP). This allows users to have an accessible MFA solution, increasing device security without the immediate need for an IdP integration. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hi all, New to Jamf and I'm not seeing the connection on getting Free apps deployed. I followed the steps in the Jamf 100 Course but im getting "Pending - All licenses are in use or the license is not assigned yet". So I went to Apple Business manager and added 1 licenses for the application (im testing this). Made sure the VPP was configured inside of Jamf. What am I missing??This is a 100% free app... why/where do I need assign a license?
I've been using a policy executing a straight up restart option bound to a SCG that gathers every Macbook that hasn't been turned off for more then 10 days but I find the policy to be too invasive since it doesn't allow deferral as far as I know.I've been searching if there is a way to just send a notification if somebody enters a SCG on their Macbook but I can't find anything of the sort and I'm not very good at scripting either.Do you have any tips about it?Thank you
I see a lot of threads on how to show some information about installed profiles using the profiles command. Anybody know how I can use bash to read specific values from a profile? I want to use it to get a configured server URL that is only easily available via configuration profile on a freshly deployed system.
I have a workflow to rebuild a Mac that is working pretty well for our purposes, and I'm not really looking to change it. The workflow is initiated via Self Service, and it starts with a simple "softwareupdate" command that downloads the installer and then does an eraseinstall. My issue is that since Sonoma, after clicking Install (or Reinstall) in Self Service, and the workflow starts, but it gives the appearance of stopping. The blue spinning circle stops and the button goes back to Reinstall, even though the workflow continues. It has caused some confusion if there is more than one hand in the pot. Is there a way to shift the focus off Self Service and bring forward the Apple Software Update window, or a terminal window that shows the progress of the download so the users know there is activity going on? Thanks, Gus
We are experiencing some connectivity issues with our managed Apple TVs. Since the beginning of the school year, we have been experiencing slow connecting times and choppy video. We made some changes to our network to move the network the Apple TVs are on to its own VLAN in hopes this would help (hoping to force a peer-to-peer connection). The teachers connect to the Apple TV through a managed Macbook or iPad. Since making this change the Macbook/iPad will not connect at all, we have done some problem-solving and found that removing the Apple TV from management solves the problem or removing the WiFi profile also allows the device to connect (this forces the peer-to-peer connection). There is something in the managed Apple TV that prevents devices from connecting. Is anyone else experiencing this and what have you found solves the problem?
Anybody got this to work. When I set it up my Apple TVs fail to take the profile with "The field “Identifier” contains an invalid value." as an errorIn the configuration profile I have to populate the Bundle ID manually which I find strange.
I have a test group setup of 6 devices that I am using to test managing software updates. All of the devices in the group are loaded via ADE and Jamf has full control of them. I pushed out a minor OS update to the devices in this group and even though they are all online and running 14.6.1 which is updatable only one device received a notification about an enforced update. I guess my first question is going to be is this feature reliable or am I wasting my time? Second any ideas where I should start in regards to troubleshooting as from what I can see there are no pending or failed management commands.
It has been six months since my company went into insolvency with a court order. There is no admin to remove the Jamf. I am not alone. Many people are suffering from this problem. How can we solve the problem.Best
I'm trying to find a way , policy/config profile/etc , to set up a sync with Onedrive on our devices. We've given up basically on having Onedrive auto-logged-in but once they do log in we want specific folders to backup automatically to Onedrive. I'm having a hard time figuring this one out. We can do this on our current PC's via a group policy in Intune but I can't find the equivalent in Jamf.
While attemtping to test some changes I made to our ZTP process, I performed erase all content and settings on one of my test Macs, deleted it from Jamf Pro, and then enrolled it through PreStage. Everything worked exactly as it should. The Mac auto-enrolled, got some profiles installed, and all appeared to be good. When the enrollment policy that handles ZTP did not launch, the first thing I did was to look for the Jamf log to see if there were any errors. There was no Jamf log. Next, I checked to make sure that my Mac had indeed successfully enrolled. I saw that the MDM profile along with all the other profiles that this Mac is in scope for were there. I then went to /usr/local and noticed that there was no Jamf binary installed. After 10-11 minutes after enrollment the Jamf binary finally got installed, and the zero touch provisioning process kicked off with an enrollment trigger. I have never seen it take this long for the Jamf binary to get installed. In most cases, the user gets
I am currently running JAMF 10.8.0-t1539715549 and I cannot for the life of me, get any EDU profiles to download to our Macs for teacher use of Apple Classroom. We have been using Apple Classroom with iPads since it was launched and we really want the teachers to be able to use the Mac version. Has anyone had any luck with this? Note, we are manually adding the classes to JAMF and are not using Apple School Manager for the classes. I don't think that should have any effect considering the iPad app works just fine.
Has anyone had luck with setting up background services. Deploy and configure the OneDrive sync app for Mac - SharePoint in Microsoft 365 | Microsoft Learn Does the background services need to be added to the com.microsoft.OneDrive plist? If so it doesnt seem to work.
Anyone know how to manage Improve Siri & Dictation and Share iCloud Analytics here? Can't seem to find the right plist for them.
We have 12 Patch Reporting smart groups set up using “Less Than” and the version we’re deploying. We deploy to 4 groups on different days: Alpha, Beta, UAT, Wave 1, and Wave 2 (Execs/Traders). One Deployment Day, I update each smart groups by adding the next test group using parentheses and the “or” option. We use AutoPkgr for package downloads but can’t use autopkg jamfuploaders due to DLP restrictions. We currently can’t have apps autoupdate and have to manage the updates on a monthly basis. Modifying the 12 groups takes about 15 minutes to do, but I’m looking for a more efficient solution. This is how our smart groups being setup. Using Chrome as an example. Application Smart GroupsName: Monthly Patching - Google Chrome UpdateCriteria: Patch Reporting Application nameOperator: Less thanValue: The current version we’re deploying. We have to manually change this each month. Main Smart Group this list all 12 Patch reporting smart groups. Use an open/closed pa
Is there a way to do an inventory search of computers that are currently locked via the Management Commands -> "Lock Computer" option? I don't see it as an available search criteria or display option when creating an advanced computer search.... I'd like to delete a batch of old computers from our JSS, but want to make sure none of them have a computer lock PIN applied before deleting the entries.
Hello, we are currently experiencing issues with our Apple TVs and tvOS 18: connecting to the Apple TV for screen mirroring is not working properly, teachers have to repeat the process multiple times for it to work. We want to be sure that the problem is coming from tvOS 18 and not from our network. Is anyone also encountering this problem?Thank you
I work in a High School where we are currently moving to a full Mac platform for both staff and students. We are installing Apple TVs in every classroom as well for teachers to wirelessly project more easily. The issue we are having is students in or out of the classroom will attempt to connect to the Apple TV during class which brings up the pin code. The teacher is then stuck waiting for the code to time out before they can move on. Just to note I have require passcode on for every connection to prevent previously connected students form highjacking the Apple TV as well.So I guess my question is, does JAMF Pro provide a way to prevent connections to an Apple TV if it is in use? We are using JAMF 10.42.1 if that matters. We are also using 4th gen Apple TVs
Forgive me if this has been posted and I've missed it. I've found similar issues but all were a few years old. I'm on Jamf Pro 10.25.1-t1602899070. We have seemingly lost our ability to name mobile devices. Specifically Apple TV's in this case though when I checked on an iPad that didn't work either. We still have access to the same steps. Inventory Tab - General - Edit - Enforce Mobile Device Name - change name - Save. All of that goes normally, however if we then look at the history tab we don't see the name change command in pending, completed, or failed. It's like it just disappeared. All other management commands are working normally. I've confirmed with my administrator (whom seems to be the only one that still can name them) that none of our team's rights have been changed. We first noticed it after going to the version we are on now but we don't know for sure if that's ultimately related or not. Any ideas?
So I think I have found a bug which affects Jamf Connect Login products from at least 2.29 and above. It seems that when the disable button for the Wifi is used on the Login screen it doesn't actually disable the Wifi. The icon still shows blue and we have issues with users logging in as we have it set to only fallback to local for users when there is no network connection. However, this doesn't turn off the Wifi and the user is stuck when attached to open Wifi points that require things like captive portals and such (not pure password logins.). So if they reboot at some location like an airport or hotel where they have been using the wifi but not authenticated to pass traffic it will just hang and not validate with our IdP nor locally. We would like to keep policy so that when an active Wifi is there but also have the ability for users to turn off wifi completely if they have to authenticate locally. Anyone else seeing this problem too?
Hello,Not sure if anyone is experiencing the same issue as I but I am having inconsistent results when attempting to change a devices name, being the S/N when enrolled, to a more suitable "Room Name" - Inventory > General > Mobile Device Name. The Asset Tag seems to be the only name that sticks consistently. Some ways we have found to force the name change is to manually reset the device (a few times) and or push a remote reset, this option rarely works. However, I would say 70% of the time, neither option works. Just curious if this is a bug or if there is a sure way to have the name change stick.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!