Get Support
Recently active
HiDid anybody try this?How to turn on the "Reminder To Enable Auto Backup" popup for managed devices – Goodnotes SupportI can not get it to work with the provided XML config. When I add the red part of the suggested configuration I get this error:"Unexpected key "" while parsing <dict/>."Adding a "/" before "key" lets me save the file but breaks my working license key config.Any ideas? I find the feature itself to be very useful!
Hi, we need to create a few certificate authenticated wifi profiles to distribute to macs, as the office is mainly windows and the number of macs is 20 or so, there is not much desire to set up an azure app proxy, ndes etc to allow jamf pro to connect to the internal CA through scep to generate certs, but looking through the documentation am not sure if it is possible to access the internal CA through scep when creating a new wifi profile.
Hi I've been searching around for an answer to this but cant find anything that answers it. A) Whats the preferred option, Is using the SCEP Proxy preferred over using the ADCS Connector? B) Is there any functionality difference between the two options once its set up? Or do they perform identical functions Struggling to figure out what the difference is, and why I would go with one over the other. I've got an environment where because of the organisations security requirements we need to use ADCS Connector instead of the SCEP Proxy functionality. I just want to make sure that the ADCS connector will provide the same "end state" functionality as using the SCEP proxy. Any suggestions appreciated. Thanks!Kevin
A new OS in the fall means it's time to review and update EAs. Post your new versions that will support macOS Sequoia (15). I realized that I still had one using `airport` (which is (way) deprecated), so here's my new Current Wi-Fi.sh: #!/bin/bash # 1.3 240808 PWC SSID=$(/usr/bin/wdutil info | awk -F: '/SSID/ { print $NF;exit } ') SSID=${SSID:1} if [[ -z $SSID ]]; then echo "<result>Not Connected</result>" else echo "<result>${SSID}</result>" fi exit 0 Let's f^%#!^ go!
Hello I'm trying deploy EndNote 21 so that End Users can open Word and the Cite While You Write plug-in will be configured. Have tried to use configurater to do this and while everything seems to be in the write place the plugin doesnt load in word.i did come accross this old post https://community.jamf.com/t5/jamf-pro/endnote-x8-w-cite-while-you-write-deployment/m-p/148974#M138024Which I have tried to updated. #!/bin/bash WordMajVersion=`defaults read "/Applications/Microsoft Word.app/Contents/Info" CFBundleShortVersionString | awk -F "." '{print $1}'`WordMinVersion=`defaults read "/Applications/Microsoft Word.app/Contents/Info" CFBundleShortVersionString | awk -F "." '{print $2}'` case $WordMajVersion in15) echo "Word version 15.xx, need to confirm it is above 15.24"if [ ${WordMinVersion} -ge 24 ]; thenrm -dfR /Library/Application Support/Microsoft/Office365/User Content.localized/Startup/Word/EndNote CWYW Word 2016.bundle#Copy the new oneditto "/Applications/EndNote 21/Cit
As one of the maintainers of the Jamf Pro terraform plugin here i'd like to request a new feature to assist with creating Jamf Pro based terraform resources as templates, whereby there would be the ability to export from the gui a template of existing resources into HCL (hashicorp configuration language). The exported template would help admins understand the HCL syntax and properties that deploy admin's resources. The exported template would function as a starting point for new and existing users of the plugin and would act as a basis from which it can be modified for the admin's specific scenario. The exported resource template process would attempt to create a usable template from the off and would be autogenerated, however there would be an understanding that exported templates could still require some modifications before they can be used to deploy Jamf Pro resources. The feature request would enable admin's to pick one or more resources from the gui for exporting to a
The situation:We are using jamf school in conjunction with Azure Entra. This means that users can log in to a 1:1 iPad via SSO. This has worked without any problems so far. The problem:Now we wanted to use some shared iPads. We have created a corresponding DEP profile. When a user now wants to log in to the device, the following happens: Immediately after entering the managed Apple ID, a code prompt appears. The required code is of course not known, as none has been entered yet. You would actually expect a window to open with an MS login screen where you can enter the user password. In the activity log I find an error: “Install/update profile (AzureProfile)” with the content “Profile installation failed / The payload type ‘com.apple.webClip.managed’ may not be installed for the system in multi-user mode.”This profile does not originate from us, but is probably created automatically because of the SSO. There are numerous posts on the subject of webClips, which cannot be easily integra
Hi, I'm wondering if anybody else is having issues with iOS18 and JAMF School? Currently, we've noticed the following: On restrictions, we have 'Allow creation of VPN configurations' turned off. On the new iOS, VPN and device management are now lumped together. Having this setting turned off means you can't see device management at all, so you can't see any certificates or restrictions that are installed. A colleague has informed me that they have had issues with certificates not working properly with in upgrade to the new iOS, but it has worked if factory reset. Another issue I've noticed is Bluetooth. In settings on JAMF School, there's an option for Bluetooth "Enforce Bluetooth on devices with JAMF School Student 6.2.0 or later". I am now able to toggle Bluetooth on iOS 18 which will cause absolute chaos for teachers as we heavily use Apple Classroom. Bluetooth can not be toggled on iOS 17 with this JAMF school setting enabled. Is anybody else having these issues? Does anybody
Hello community, does Jamf plan to make an iOS and iPadOS app for administrators?
Hello people my name is Sanjeev Mansotra from Dubai. I'm new to this community, please help to solve my query. How can Jamf Safe Internet be integrated with existing school networks to ensure compliance with both local data protection regulations (such as GDPR or CIPA) and institutional cybersecurity protocols, while maintaining seamless network performance and minimal latency for students accessing educational resources across a multi-campus setup? Additionally, what strategies can be employed to monitor and enforce safe internet usage without infringing on user privacy, and how can Jamf's threat detection capabilities be customized to address institution-specific vulnerabilities and emerging threats?
First a warm hello to the community and a happy new year to everyone 🙂I am looking for a solution to run a client policy (job) on jamf pro immediately after setting the scope to the policy instead of triggering it with a event like "change networkstate" or "recurring check-in". The reason is, we have to change a configuration file on the client dependent of a server event in our windows domain.I cannot find any article here, so I would be glad, if someone can help me to solve my problem.greetings,Michael
Is there an option to remove a user's ability to perform mass actions in jamf Pro? We recently conducted a risk assessment, and we discovered that anyone can perform a mass action as long as they have permission to use that action on an individual device. Is there a permission or another tool you have used that would remove the jamf users ability to do something like wipe all devices but allow to still wipe one device at a time?
Hello Everybody, Our Macbooks on the domain. So we are deploying AD certificate to our macbooks. I have 2 question for this.1- How this is working? For example, I'm login in a macbook nothing happens.(certificate not installed) But after reboot or log out then login, AD Certificate is installed. Why do i reboot or logout? 2- AD certificate is applying to all users. When we are setting up a macbook, login with local account. So Jamf try to add AD certificate to local account. I dont want it. How do i set exclude for the local accounts? This is a local account and AD certificate always pending.Thank you.
Hello, I'm new to Jamf. Does anyone have suggestions on configuring Cisco VPN to install during the initial startup or right after logging in with my Windows credentials?
Hi I would like to:Defer a major update (from Sonoma to XX) for 90 days & Allow all minor updates (from 11.5.2 to 11.5.3) How i can achieve that.
Is there a way to display a computer group in the Jamf Pro Dashboard based on whether it is Locked in Computer > Management? I tried all the advanced options but could not find anything that seems to work.
Hi, our company has canceled the BYOD option. I have my own mac and two options. Enroll your mac or start working on a company laptop with windows. Honestly, I'd rather stay on a mac, but I'm afraid that if the company blocked my laptop via jamf, I wouldn't be able to use it for my private purposes.I can think of a solution:Bual boot, when I would have 2 systems on the mac (both under the same apple ID), but I would only enroll one, so in case of potential blocking, I could still use the mac on the other system.Does anyone have any experience with this?
Hi, We use 1 Jamf instance for multiple school facilities, sometimes a device needs to be moved to a different location within our Jamf instance. Though since about 2 months ago, we are unable to move devices. This is the error:The device could not be moved because it is not associated with a server token in the main location.Anyone have an idea what's going on?I checked all our certificates, enrollment and purchase all valid
Good morning.We are deploying Jamf on approximately 200 new Macs that we are replacing for our employees; however we have around 60 already in operation, which were added to ABM by the Apple Reseller.To avoid asking employees to use the terminal and type "sudo profiles renew -type enrollment" command, is there a way to make this process automatic?I would like to be able to share a file by email and saying to them "Just launch it and wait until Setup your Mac will start". I tried with Automator without success.Any ideas?
Hello, since a while we get an error message when trying to transfere the configuration Profile to our Ipads.I think it is since we updated to IOS 18 / IOS 18.01, but not sure about that.The error message is: Beim Einstellungsdienst für Netzwerkauslastung ist ein Fehler aufgetreten. / permission deniedAny idea what is causing that problem and how to solve?Udo
https://ideas.jamf.com/ideas/JPRO-I-769 upvote if you agree, i think this would be a great place to add notes for other admins, troubleshooting steps that have been taken in the past, etc.
Historically, I've been using this command to restrict modifying WiFi settings to admins only: /usr/libexec/airportd en0 prefs DisconnectOnLogout=Yes JoinMode=Automatic JoinModeFallback=DoNothing RememberRecentNetworks=No RequireAdminIBSS=Yes RequireAdminNetworkChange=Yes RequireAdminPowerToggle=Yes I've recently realized this no longer works on Sonoma. Does anyone know of an alternative way to enable this on Macs running Sonoma?
Just curious if anybody has run into an issue where you uninstall app, but won't reinstall, but the policy logs show successful reinstall. A while back I was testing a snagit version and used the uninstaller, but after that, I could never get it to reinstall. I went through the Mac and removed every file related to Snagit, went in to the /Jamf folder and removed anything related to snagit. For that I eventually just reimaged it. I just came across the issue again uninstalling cisco secure client. I have a script that uninstalls the old version of AnyConnect and modified it, but it broke something and didn't uninstall. I gave myself admin rights and just ran the uninstallers for both the client and the dart agent. Verified all other files were gone including in the /Jamf folder. Now when I try to install the old version which we use in our current deployment, it doesn't install, but the policy log says it was successful. It does install the /opt/anyconnect folder, but not all the compon
Hello all, I'm puzzled as to why the option to share a note in the Notes app or an image in the Preview app via Messages isn't showing up (see image below). From what I understand, these sharing options can't be disabled on a Mac, so my guess is that something in JAMF may be restricting it. We simply want users to be able to share notes by clicking the box with arrow and selecting Messages. We've checked our restrictions, and there don't appear to be any in place, so it shouldn't be that. Any help would be greatly appreciated.
I have this need.I would like that during the enrollment phase, if a user belongs to a certain list, he is added to a static group.I don't know if there is something similar or a different and simpler approach for my need.Basically I have 100 users with an Office 365 license and I would like that only those entitled to be able to install the available software on self-service.In my imagination the ideal script should do this:an enroll policy that checks whether the email address present in the user & location section is contained in a specific file on Google Sheet.I use something similar to rename Macs, this script actually downloads the .csv file locally (with serial and asset name) and writes it to jamf pro with the -fromfile function (bash).While in my case I should probably use the API to write to the static group.Any suggestions or help would be greatly appreciated. Obviously I also accept different approaches, which however are not manual (at the moment I check each enroll vi
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!