Get Support
Recently active
Hi folks We are trying to configure Jamf Pro as a SCEP proxy for our Microsoft CA which is hosted in our company network.So far we have set up the NDES role on one of our servers and the website shows the challenge passwords can be obtained from the mscpe_admin webpage. We have verified that the connection between jamf pro and the SCEP / NDES server is allowed on our firewall. I can see inbound traffic from the jamf pro network ranges (Data Region eu-central-1). In the logs of the SCEP configuration profile, I always get an error that the server could not be found, which I weird since I see the traffic coming in on the firewall. I tried both ways of configuring SCEP, in the configuration profile and in "Settings/PKI Certificates/Management Certificate Template), it shows the same issues. Now what's really the icing on top is that sometimes we get an error that the certificate could not be verified, which I see only in the jamf pro server logs(but I might be reading that w
Hello, we have the following problem: Nobody can change their AD password via NoMAD. This error shows up: "Unable to change password: Configuration file does not specify default realm" I found out as soon as I go to the nomad app container and execute the unix file, another NoMAD instance is opening and showing an icon in the menu bar, where I can successfully change my AD password: In Jamf we deliver nomad and the launch agent as a policy and a Plist as a configuration profile. This comes from the past, I dont know if this is enough and correct in this time: The weird thing is that it is working with the unix file inside the nomad.app which is on all our Macs. Thank you for your help in advance!
I'm rather suddenly having an issue with Mac Apps and it not installing Google Chrome from the Jamf App Catalog. Before, if I wiped a device and got it set back up, within a few minutes Chrome would auto-install like it should. But over the last two days I've had 400+ devices stuck in the 'In Progress' stage including devices I've recently wiped. Version deployed is the latest version of Chrome Target Group: All Managed Clients Update Method: Automatic Initial Distribution: Install automatically I tried switching it from Install Automatically to making it available in Self Service, but when I opened Self Service, there wasn't an option to install, only Open or Reinstall but it would error each time I selected either option. Any ideas?
Hi, is there a way to add network shares to finder favorites via the command line? I could not find anything by googling.
Greetings. I need to be able to ingest Security related log data from JAMF Pro api. Does anyone have suggestions on the API endpoints that I should focus on? ThanksFrank
Hi Everyone, Am trying to Packaging Homebrew-4.4.0.pkg using Jamf composer When i install Homebrew-4.4.0.pkg on clean Mac machine it will install without issue it shows Homebrew 4.4.0 when checked on terminal with brew -v but When i package it using jamf composer and install the packaged Homebrew on other Mac machine it will show Homebrew 4.3.0 on terminal with brew -v. Can someone please help me with this, packaging Homebrew 4.4.0 is not right?
So I know this was requested and asked about a couple years ago based on searches but have not seen anything recently. With the addition of screen time tracking having been added to iPads in general is this something that JAMF now tracks or are we still out of luck? I have several users requesting new iPads because there are "We use them to much and there aren't enough for all of us" but in reality I think its they do not want to share.
Hello everyone, I'd like to know if it's possible to have a configuration profile for each of my Chrome extensions when deploying them on the same target? I currently use a single configuration profile for all my extensions, because when I tried to create several configuration profiles and applied them to my target, only one of them applied. Current configuration : <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>ExtensionSettings</key> <dict> <key>eljmjmgjkbmpmfljlmklcfineebidmlo</key> <dict> <key>installation_mode</key> <string>normal_installed</string> <key>update_url</key> <string>https://clients2.google.com/service/update2/crx</string> <key>toolbar_pin</key> <string>force_pinned</string> </dict> <key>cjpalh
Hello Gurus, I am fairly new to JAMF, so I'm still learning. I would like to use Azure groups to assign configuration profiles. I was able to connect to our Entra ID environment from Settings > Cloud identity providers. I can query and find our Azure groups from Settings > User accounts and groups. The problem I'm facing is that these Azure groups are not showing up under Scope when I am setting up Computers > Configuration Profiles or even Policies. The reason for this is to set up different applications/policies for users in different departments. Since we already have different security groups set up for departments, I'd like to utilize what we already have in Azure. We'd also want to avoid LDAP and stick with Cloud only. What am I missing here? Thanks!
Hi there. I am fairly new to Jamf and have been handed control of a school who is already setup. I have a teacher who wants students to take a photo on the ipad and then be able to open gallery, select the photo and email it to themselves. But there is no email listed when they try to share the photo. Does anyone know where to allow this in the dashboard? Thanks.
Just wondering if there is a way to enable the Safari Homepage button so that it's visible. I would like to do this on the command line so that I can have Jamf do it
Hi there,Looking for instructions on how to install the Veeam Agent for Mac. Veeam doesn't have any instructions they just say to "refer to the documentation of your MDM solution.". Obviously there's nothing in the documentation for how to install the Veeam agent using Jamf.Can anyone help me out here? Thanks!Sincerely,
We use iPads for our Electronic Flight Bags, and one of the applications on these devices utilizes the native iPadOS Mail app to send emails. We operate in a Microsoft Exchange Online environment and have successfully pushed email accounts assigned to user devices with OAuth, where they enter their password and 2FA. However, we also use backup devices assigned to planes or loaners, which are user-agnostic. We are trying to push a centrally managed service account for these devices, as the pilots wouldn’t know the password for this email account. Modern Auth is disabled for this account, so a username and password should suffice. Despite this, when setting up the configuration profile, it still prompts for a password on the device when the profile syncs. Does anyone have any ideas or suggestions on how to resolve this issue?
I've installed Zoom via VPP on several iPad's. Recently got a call that the customer stated they were required to update Zoom. When they went to the App Store to update they got this message: "Zoom cannot be updated because it was refunded or purchased with a different Apple ID". This customer was not signed into a Apple ID. I was under the impression that since it was "purchased" via VPP, that it wouldn't need an Apple ID associated in order to update.How does everyone else update non-Apple apps on iPad's that were installed via VPP?Thanks for any help in advance.
I've an idea up at https://ideas.jamf.com/ideas/JPRO-I-778 that I'm honestly kinda jazzed about! Don't know if it will work--still workshopping.The 36,000 ft fly-by is:1) Eliminate Cloud Standard for the SLG space, making Cloud Premium the entry point.2) Bundle training at least up through 200 with the product; offer this "free" for 6mos - 1year. For an org not convinced there's an exit clause with a Jamf-determined fee.3) Admins both go through training before their own onboard, and must participate in at least one peer org's onboard before their own. The notion is pay it forward and/or servant leadership.4) At the end of the introductory period, org's agree to sign on for no less than 3-5 years.5) Orgs that go above and beyond in assisting with onboards maybe get to host a JNUC (a little friendly competition). Where not prohibited by law, policy, etc, perhaps entities may negotiate a waiver of fees pertaining to
Hi all, We are running the latest production ring version of OneDrive (23.153.0724.0003) and setup known folder move via the official Microsoft documentation, has anyone been able to get this working on the production ring? Deploy and configure the OneDrive sync app for Mac - SharePoint in Microsoft 365 | Microsoft LearnI found an article that suggested it was a known issue with Microsoft on the production ring but that was from 2022 so i assumed it would've been fixed by now.Has anyone been able to setup KFM move for Desktop and Documents to OneDrive?
Hey guys, I need to deploy VSCode & Jetbrain Snyk extension via Jamf. VScode is in format .vsix and Jetbrain is looking like a simple folder with one Library and .jar files inside this folder.Have any of you had to deal with such an installation?Thank you in advance.Regards
I setup Platform SSO (enclave) and it works... okay. Outlook and OneDrive both still require me to enter the email address to begin. It's better than nothing, but deeper integration to capture username prompts would be great. And, it would be ideal if we didn't need Company Portal to broker this login. Jamf Connect is already connected to Entra. So, it would be great if it can broker platform SSO, and autofill usernames in apps with the app prefixes defined in the profile.
We have Jamf School in use and now we need to reassign the push certificates to a central Apple-account since before we used to renew them with the personal ones. In Jamf i have the option to change the Apple-Account to which the certificate is assigned but will it affect in any way our MDM and will the devices be still available ? Thanks in advance
Hi all,I hope I'm posting this in the right place, but I am experiencing an issue with my jamf school shared iPad deployment regarding display names.From the list of selectable users, most users have their first name listed, but for a very select few users, their accounts are listed with their last name instead of their first name. This has become confusing for the younger students here at the school I manage. Hope that makes sense.I don't know why this is, their first names only range between four to six characters, and there aren't any users who share the same first or last name as the affected users in the system. If I could list their entire name that would be ideal, but I'm willing to take any advice or solutions to this problem.My users are provisioned through SFTP sync and uploaded to ASM. I have checked their users through Jamf and it looks like the first and last name are being populated correctly.Thanks!- sammy
Greetings, My grad school is starting a new project to look at how to get user account data (Mac Home folder) transferred from a users old computer to a new computer when the user and the computers are fully remote. We currently provision all computers on-site, and then ship them to the remote user. The user is then responsible for the transfer of data from the old computer to the new one. This results in a fairly heavy lift for the user and support staff. We're moving towards a low-touch process where the user can initiative the provisioning out of the box, so we're investigating ways to reduce the data transfer load as well. Apple Migration Assistant is somewhat less than ideal; it's sort of all or nothing (well, not exactly, but it's not great) and we've had many bad experiences with it on managed devices. We use CrashPlan for home folder backup, but it's very slow at restoring folders over a couple gigs in size. Suggestions? Are there home grown soluti
Afternoon All Hopefully someone has seen this before. I have recently patched VLC media player the install media is DMG so used Repackage https://bitbucket.org/twocanoes/repackage/src/master/?ref=steemhunt application to create a PKG for deployment. I have noticed that some devices don't unmout the sparsebundle within pkg package. I though this might have been some issues with creation of the pkg. So I delete the current version and recreated it.Testing the new package created in same way this doesnt seem to happen.I though removing the orginal pkg from DP would stop it being mounted seems not. So I have created a policy forcely remove it on login. /usr/sbin/diskutil unmount force /Volumes/1010139C-84D6-4178-A17F-D3DD4F424C8C.This seems to be working fine if the machine is rebooted, I think this should sort itself out overtime as the machines are powered off daily. On restarting a device which has just run the above command it doesnt get mounted on login.I have two ques
I'm trying to use Jamf Sync from the command line to keep a local backup of our jamfcloud packages. It works great from the GUI (so everything is in my keychain), but in the CLI I can't get it to connect to the server. The issue is with the formatting of the source I think. With the "Name" for my source in the GUI set as "JamfCloud" (for my JCDS), and the local directory named "JamfcloudBackup" I've tried... -s JamfCloud -d JamfcloudBackup -p-s JCDS:JamfCloud -d JamfcloudBackup -p-s JCDS:xxxxxxxx.jamfcloud.com -d JamfcloudBackup -p-s JCDS:https://xxxxxxxx.jamfcloud.com -d JamfcloudBackup -p-s https://xxxxxxxx.jamfcloud.com -d JamfcloudBackup -p And I get the same response... Loading distribution pointsCouldn't find the source distribution point or folder: The help page says to use "the source name" but is that the name defined in the GUI, or the actual URL in my case?
We have recently purchased Jamf Business and have an Intune backbone for Windows. I know in previous experience that there is a Jamf and Intune connector but upon searching, it looks like that will be deprecated. Is there another way of going about reporting machine info to Intune from Jamf Pro?
How is everyone handling SecureTokens? We are seeing issues with password resets outside of macOS and the SecureToken not working anymore, I am guessing because they aren't getting sync'd up. NoMaD is not allowing users to change their passwords anymore from within macOS even though the password criteria is met.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!