Get Support
Recently active
I am helping setup a JAMF solution with a SCEP server. We have everything setup, seemingly, but the assignment of the certificate fails from the SCEP server with the 400.0.64 error code. I was wondering if the fact that the MACs are not in DNS is causing this issue. I ask because I know certificate servers normally need to see the device in DNS that they are giving a certificate to. Could that be it?
Despite having a deferal or Sequoia, we have just seen a few dozen Intel based Mac's upgrade themselves to from sonoma to Sequoia 15.1 today. Has anyone else seen anything like this happen?
Hey guys, This past summer I updated a couple computer labs from Monterey to Sonoma and I was able to login with it. I tried to login to one of the MacBook Airs this week and it's not accepting my password. I grabbed another laptop from the lab and same thing. This has never been an issue in the past and I know I am entering the correct password. The account is created in the PreStage Enrollment. I did some looking into this to see if anyone else is having this issue. It sounds to me like it could be a LAPS issue. I watched a couple of JNUC videos about LAPS and read a post about "How to Securely Manage Local Admin Passwords with Jamf Pro and LAPS". I never turned it on and I checked my Computer Management->Security settings and my jamfinstance/API and it looks like it's still off. Anyone else have this issue or have any ideas? Thanks!
Hello, I have recently set up a device compliance connection between Jamf Pro and Intune. I was able to successfully register my test devices without issue so I pushed it out to a handful of IT users. When they try to register, they are receiving an error that states: "Helpdesk support required Your organization needs to enable partner device management for you before you can enroll. Please contact your helpdesk" Our legacy conditional access policy is currently terminated and was never scoped out to any users, so I am unsure why this message appears. Any advice?
Hi, I've currently got an extension attribute for "Brand" for our retail company and am wondering if there is anyway to have our iPads display a drop down during the enrollment stage to select the brand they belong to for the corresponding configurations to apply correctly? I've seen how I can add text to the enrollment page but unsure how to link the extension attribute Any help would be greatly appreciated. Regards, Danyon
Trying to deploy extensions via DMG, but everytime I deploy it and I launch Chrome, the extension simply disappears from the folder... anyone have any idea why?
We are looking to set up a content cache server in a network that has more than two public IP addresses, with devices connected through GlobalProtect VPN. Could someone please guide me on how to configure the custom Public IP address section to ensure that devices can access the cache, whether they are connected via GlobalProtect or directly to the local network? All devices are enrolled at Jamf.
Hi All, does anyone know/have extension attributes to find installed extension in Safari browser?
Need help to block file sharing via SMB in Mac only allowed Mac need to copy file in same network.also want to block FTP/SFTP file share and allow only particular ip.
Forgive by ignorance, but is jamf able to reset passwords if the user is not logged into a local account? I am seeing the option in policies, but I am unsure of how to trigger it before the user logs in. I attempted to set the trigger to startup and change in network state, but both remain pending when restarting the device to the login screen. Also, I am not seeing a network symbol on the login screen for any device and am thinking I need to adjust configuration profile so network access/settings can be accessed before logging in? If so, where do I access this? I am reviewing the restrictions on the devices and I am not seeing them.Also, is this ill-advised? I can see how doing this sort of thing would be unwise from a security perspective.
I have been fighting with this issue for several years with a variety of Apple TV devices - all newer ones without the USB port built in. The issue occurs because of two things:Through JAMF, we have placed the Apple TV in Conference Mode.The Apple TV has been turned off long enough to no longer have a valid certificate for JAMF.The end result is that the Apple TV is stuck in conference mode, but since it is no longer communicating with JAMF it cannot be taken out of conference mode. The only option is to factory reset, which then leads to a NEW problem - when I get to the factory reset screen, the remote no longer works to actually select the "Reset" option. Here is the general process I do:Boot the Apple TV that needs a resetPair a remote to the Apple TVBoot into recovery mode (power cycle multiple times, interrupting the boot each time, until the recovery mode screen appears)Attempt (usually unsuccessfully) to use the remote to select the Reset option and reset
This seems promising but I know nothing about it. I wonder what kind of performance impact we can expect by implementing this (in a clustered environment.)
I am seeing an issue where suddenly my App Installers that I have setup for automatic updates are no longer functioning, but Self Service app installs work fine. Seems to have started when 11.10 was released. I have tried recreating policies from scratch but issues remain the same. No App Installers set to automatic function, everything stuck in progress but no signs the update command is ever sent. When I look at the deployment status, none of the scoped machines are visible, but if I look at a Self Service policy, they are there. Is anyone seeing anything like this and any idea how to resolve it? I do have a case open with JAMF but so far we haven't got it figured out.
Hello everyone, We use Jamf Pro Cloud 10.42.1 and we have an issue with macOS Ventura. When we prepare a Mac with our prestage enrollment, we have a message : You do not have permission to use the application "SafariSupport". We use exactly the same configuration profiles for Big Sur and Monterey and we never had this message. You can see screenshots of our Restrictions Configuration Profile. Applications folder is in Allow folders so we don't understand why we have this message.And if we add Safari in Allow Apps, Safari opens but we have the dialog box again.Anyone had this issue or understand what is wrong with our Restrictions Configuration Profile ?
I've been trying to get a config profile for a screensaver to work in Somona (14.6) and have had no luck. For those of you that have had success, what path did you use in the field for 'Use Screen Saver Module At Path'? It can be any basic built in screen saver, nothing custom.
Hello all, We would like to deploy our Macs with a set of standard applications in the dock, but not disallow the end user to move and resize the dock. Is there a way to insert or set apps with the dock without locking out the user entirely? Thanks much -
Hi, I've recently setup 30 mac minis to be used for directory displays around my institution. I was looking for a config profile...or policy to block all notifications from popping up. I've already set DND to run 24-hours a day, everyday. Thoughts? Thanks, Danny
Hi All, I have an Zoom screen sharing issue within Configuration Profile, the Policy for Zoom is not working after an App, Do anyone have any information on how to resolve this issue, once there Zoom app update?
Hi y'all, We are trying to deploy the HP printer app that is necessary for connecting and using our HP printers on our new Macs. However, we don't allow App Store access to our devices. For the most part that hasn't been an issue but it looks like HP's app is only downloadable through the App Store. Is there a way through this? I don't think there's a workaround that lets you download the app from HP itself etc , but maybe there's a way to deploy it through the Mac Apps etc that gets it from the App Store but doesn't require a login to it?
Hi,I've installed the Ripple Tool extension on several devices, but I'm having trouble getting it to turn on automatically. Whenever a user logs in and opens Safari, they get a pop-up asking if they want to enable the "Ripple Tool" extension.I’ve tried using a script to automate this, but it keeps failing because it can’t find the com.apple.Safari.Extensions.plist file in preferences. The Ripple Tool was downloaded and installed from the Apple Store.I also tried using a configuration profile to enable the extension, but that approach didn’t work either. #!/bin/bash# Define the extension's bundle IDEXTENSION_BUNDLE_ID="com.ripple.tool"# Safari’s extension preferences filePREFERENCES_FILE="/Users/$USER/Library/Preferences/com.apple.Safari.extensions.plist"# Check if the plist file existsif [ -f "$PREFERENCES_FILE" ]; then# Add the extension to the plist (this approach might vary depending on Safari version)/usr/bin/defaults write "$PREFERENCES_FILE" "ExtensionsInstalled" -array-add
The Jamf Pro 11.12.0 Beta Release features new restrictions including support for bypass screen capture alert, the ability to restrict Apple Intelligence features and more! How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions. The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
for a device which has jafm Manuel enrollment payroll MdM, would the administrator be able to see if a file was airdropped from said device to another device? I’ve seen conflicting information as some stuff says that airdrop is encrypted and not allowed because of apple’s privacy, but also seen other stuff. in any case, would there be a log of the file that was sent and the device it was sent to?
Hello, Jamf is running on my MacBook although its not part of any MDM system. I also don't have any profiles installed. How do I get rid of Jamf altogether? Removing it from Applications/LaunchAgents/LaunchDaemons doesn't help, it just reinstalls itself and starts up again. I can see that there is something when I run `sudo protectctl info` but I don't know what that is? Can this be a left over from migrating from an old mac that had a MDM running? Any help is greatly appreciated as the jamf security extension is using all the network bandwidth which is extremely annoying when tethering. Thanks and cheers, Karsten
So, with new Opt-In to Beta versions on iOS and iPadOS 16.4, how do you disable this option on your managed iPhones & iPads?
Hi Team, I'm working on deploying EndNote 21.4 to multiple devices, along with configuring the "Find Full Text" feature via script. My approach involves modifying the $HOME/Library/Preferences/com.ThomsonResearchSoft.EndNote.plistfile to include the required settings. However, when I deploy the script and launch the EndNote app, it doesn’t appear to recognize or pick up these configured values. For context, I’m setting up the "Find Full Text" preferences as described in the following guide: weblink: https://guides.library.uq.edu.au/referencing/endnote/find-full-textThis includes: Enabling checkboxes for Web of Science, DOI, PubMed, and OpenURL Setting the OpenURL Path to xyx.com Leaving the "Authenticate with URL" field blank Could you advise on why the app might not be picking up these settings from the plist file, or if there’s a recommended alternative approach to automate the setup of these preferences?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!