Get Support
Recently active
I'm following this page and trying to get the MDM commands, but when I use a JSS account on myaccount.jamfcloud.com/api/doc/#/mdm/get_v2_mdm_commands I get a 400 returned, and when I use an API account I get a 401 returned. The full URL for CURL/Postman is: https://{myaccount}.jamfcloud.com/api/v2/mdm/commands?page=0&page-size=100&sort=dateSent%3Aasc *EDIT* I realized I missed the "filter" field and it's working now.
In a recent deployment of the SecureConnector, we are discovering a large number of systems generating errors after the SecureConnector deployment. It is suspected the process is being spawned twice. Our install policy is very generic without any custom configurations. Has anyone experienced similar behavior or found a resolution? 6/29/15 9:16:46.339 PM sshd[22462]: error: Bind to port 2201 on 127.0.0.1 failed: Address already in use.6/29/15 9:16:46.340 PM sshd[22462]: fatal: Cannot bind any address.
Hello! I am a student at a school, so I'm not sure how much help the Jamf community will give me but my school laptop's Jamf sometimes will stop blocking apps that are meant to be blocked, e.g. Terminal, Activity Monitor, App Store, Messages and Facetime. I am not sure why it seemingly at random sometimes stops blocking apps. My school had an issue similar to this 2 years ago where after a few days without a restart or shutdown, it would stop restricting apps but that was fixed. It seems something similar happened 2 days ago to me. Late yesterday my jamf was finally fixed via a periodic MDM profile refresh. I am not asking for a way to do this as I do not plan to do this as I follow the rules that are set but I am intrigued by how my school's IT could fix it and if it is fixable so I can forward them the issue and the fix for it.
Hello Jamf Nation, Seeking for advice from people using cloud instance of Jamf Pro with Google Could Identity Provider. We are moving from local LDAP server to Cloud IdPs (Google). We've configured Google LDAPS connection in Jamf Pro settings - everything seems to be OK so far. The question is - how users, after they imported into Jamf from Google during enrolment, will be updated? If they change department or position in Google LDAPS - I believe Jamf will not sync them automatically. Previously we could access our database directly, but now it's also going to the cloud (we migrating from on-premises as well). Is the only option - updating them via API calls? Thanks!
Hey all. getting ready to move LAPS into our system. what are the best steps to incorporate with already managed macs?
Is there an updated script to install Google Drive? I have been trying to deploy Google Drive via Self Service using the package installer. 9/10 times it fails, whereas installing Google Chrome with a script works every time. I would like to do this with Google Drive. I have seen a few scripts out there, but they are many years old.
Please clarify the doubt. Let's say I'm managing 50 mac devices manually. Then my organization wants to manage those mac devices through Intune and organization don't want to do Factory reset. So, solution would be Account driven enrollment. In these 50 mac devices, end users using their personal iCloud id's.If they initiate the account driven enrollment, will they get a prompt to sign out from iCloud account and login with managed apple id's? Or what's the process of it. Kindly explain. Thanks.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server: Security Issues Jamf provides the CVE-ID for security issues with high or critical severity when possible. [PI119913] Updated a third-party library to resolve a known vulnerability (CVE-2023-45857). [PI121204] Resolved a "Credentials Management Error" for some SMTP server configurations. Jamf Pro Server [PI121197] Jamf Pro upgrades no longer fail due to issues during the font migration process if a database table contains null values. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 11.10.1 based on your hosted d
For several years now, Apple has highlighted the important role that partners and Admins play in testing beta versions of their upcoming operating systems and submitting feedback for any issues that can (and do, particularly in the early versions) appear. They also provide some great tools that make it easy for this to be done, but those tools are only half of the story. The other half is an effective testing strategy that, when executed properly, will both provide Apple’s engineers with invaluable data for resolving unforeseen issues prior to public release and also give you ample opportunity to ensure your readiness (and confidence!) to deploy the latest OS version upon public release. This benefits your organisation and users alike by offering the latest software features to enhance workflows and maintaining security standards across your Apple fleet. This post aims to provide an overview of the tools Apple provides to Admins for beta testing at scale, as well as highlighting best p
Hello - My district uses Jamf Pro and we use Jamf Teacher within this. It seems that Jamf Teacher has updated recently and since then Jamf has been a mess! When trying to create a lesson and allow apps, an app shows multiple times and most apps are not even available. Has anyone else had this issue and if so, do we know if it is being worked on? Thanks!
Hi everyone, During our testing, we've encountered an alarming issue with Jamf Protect on BYOD devices. Even though we've configured the Jamf Trust app to route only specific domains through the Jamf Protect gateway, it's logging all web activity—regardless of whether it matches the routing policy or not. This presents a serious privacy concern, as it feels like an unnecessary overreach into user browsing data. While there is an option to anonymize user details, this feels more like a workaround than a solution. Ideally, we should be able to implement split-tunneling, where traffic that doesn’t match the company’s routing policy is treated as regular traffic and exits through the device’s standard WiFi interface (iOS/Android). Has anyone else experienced this or found a better way to manage this?
I've run into this issue a few times on different machines, where i let a user upgrade to the next macos version and after downloading the update it prompts admin credentials to install. Neither the local admin or the user's secondary admin accounts work and the only way to upgrade the macos is to sign out of the standard user, sign in as one of the admin accounts and run the update there. Is anyone else running into this issue too or found any solutions? It isnt bad when they are in the office, but remote users without access to admin accounts are unable to upgrade their os. And yes, jamf has the software update ability, but ive yet to see that succeed in working for major updates.
Hello All,On a Standard Account, when user tries to upgrade to MacOS Ventura it's asks to enter admin credentials.On the Same machine when it's asks for Monterey 12.6.1 Update, user can update it wit out any admin rights. Trying to find out what could be the issue and how can we mitigate it.Thank you.
I would like to know a single platform for upgrading and updating macOS with standard user permissions. Does anyone use a single platform for M1/M2 & Intel Mac in their environment?
Hello, This is a bit long so please bare with me here, thanks! I was wondering if anyone could guide me on how I can set this up? I was at JNUC and got a relatively good idea of what it can do when I was at the session. I was told that switching to Jamf School could be done. I will be scheduling something with an engineer in my region, but if I could get a hand on doing this to test on an iPad first, that would be great if I gather more questions and info for the meeting. What can I do to set this up best? Majority of our iPads are already on Jamf School. I just want to know the best way I can prepare for this in the future with maybe the last several hundred iPads still in Jamf Pro left. We will begin retiring older iPads and removing them from Jamf and Apple School Manager altogether, so at least that I don't have to worry about. I was looking at the Jamf Migrator tool on Github. Skimming through it it looks like something to setup transferring the whole serve
Hello everyone and I hope you are doing well!Was just curious if there is a Timeout Function for the Jamf Setup App that is currently being used for shared iPads. For example, if there is a shared iPad that is currently logged into using Jamf Setup and it hasn't been used in 20-30 minutes. Is there a way for a timeout to kick in and so the system would notice and execute "This iPad hasn't been used in 30 minutes, so we are going to auto logout the currently signed in user since they are most likely not using this device anymore." Let me know if there's any other details I can provide.Thank you so much and I hope you have a nice day!
Any orgs out there leveraging WiFi only iPhones that are shared between on-campus staff and ALSO trying to implement device level PIN (unique per user) enforcement in tandem with Jamf Setup + Jamf Reset (Soft reset) Wanted to try to see if other organizations have anything similar and what experiences you all have with this. We are moving away from Imprivata Ground Control (Mobile Access Mgr) to due the sheer cost and inconsistencies with reliance on phone cases + docks + host machines. Aiming to have all workflows handled OTA (Over The Air).We have noticed that if staff forget to soft reset a phone using Jamf Reset that it puts a rather large burden on other clinical staff and/or IT Support staff to wipe / reprovision and setup the devices again.Appreciate your time and shared experiences! We are looking at Jamf Return to Service as a replacement to Jamf Reset, but that requires all devices to be iOS 17+ compatible, which we aren't quite there yet. This still wouldn't solve for the is
Hi Everyone,Currently, I am having issues with printing to Ricoh printers in our schools with macs running on both Big Sur and Monterey. Whenever certain students or staff print, they get the following error:ERROR : invalidfont OFFENDING COMMAND : show STACK: (!)I have managed to find a workaround with a change to the Rasterizer in the PPD files of the print drivers, by running the below script:#!/bin/sh cd /etc/cups/ppd find ./ -type f -exec sed -i '' -e "s/TTRasterizer: Type42/TTRasterizer: None/" {} ;However, any mac that I run it on throws the following error:find: -exec: no terminating ";" or "+"If anyone has any input on this, I would appreciate it! If you have any other questions, please let me know!
If the Apple Silicon Mac computers can not be enrolled through PreStage Enrollment, the Recovery Lock can only be set from remote command, here's how to do it in Jamf API. 1. First, we need to know the managementId of the target computer. we can copy it from computer‘s inventory. (Jamf Pro Server 10.50.0 and above) 2. Open the Jamf Pro Server API page (https://yourInstance.jamfcloud.com/api, or https://yourjss.domain.com:8443/api) , and choose Jamf Pro API PRODUCTION View. 3. Navigate to "MDM", and choose "POST /v2/mdm/commands", then click "Try it now". 4. Modify the request json body. Input the managementId and the recovery lock password. Set to empty ("") will remove the recovery lock password, set to a different one from previous can RESET the existed recovery lock passcode directly. (PS: Firmware/EFI passcode cannot be reset, must be removed and then set a new passcode.) (copy paste and modify it) { "clientData": [ { "managementId": "6c1c6fd
Hello everyone,I'm a new Mac JAMF admin at my organization and first time poster here. First off want to say thanks to the community here, as I've already received lots of help here already perusing the forums with other questions I've had (that have previously been covered). I do have a question as it pertains to firmware / recovery locks as it pertains to M1 Macs.Currently managing a fleet of around 700 Macs. I'll just state what our organization is wanting to have happen and maybe some of you have suggestions that I haven't thought of or found. I have orders from up top to try to lock down MacOS, so employees are unable to wipe it and bypass JAMF. There was some sort of an incident, which has prompted this request. Ultimately if a user is having a problem with their MacOS device, we would like them to bring it to IT for a reimage to ensure the JAMF MDM profile is present. It was my understanding a Firmware password was previously used on Intel Macs but this feature is not pres
Forgive me if this is answered in another discussion - I have seen similar posts, but nothing that gets to the root of what I am trying to accomplish. I am also, unfortunately not versed in BASH scripting, hence the reason for reaching out... I am trying to put together a policy that includes a script to completely remove any installed versions of Oracle JAVA - including multiple JDK versions if found. I am familiar with the official method published here: https://www.java.com/en/download/help/mac_uninstall_java.xml However, if a machine has multiple JDK versions installed, I need a way to detect those and loop through an uninstall command to remove each. Does anyone have a script that will accomplish this? Thanks for any insight that can be provided... Brian
Guys,Since Jamf introduced Compliance Benchmarks which helps admin to manage and report security compliance on macOS. If that's the case, then Intune integration is mainly for conditional access and no need to check for compliance status as Jamf itself let us know the device compliance status. Is my understanding being correct?
Newbie here so sorry if this has been asked ( i already search the forums beforehand and found nothing) We want to create a report in Jamf to detect all versions of Java or any Java App installed. I know other applications it's app name +.app for the value when I create an Application title search, but that didn't work. Assuming since java is added mostly as an extension ( i think). Any help or other links to how it's done would be appreciated! Thanks
After Google announced they would not be allowing basic credentials for SMTP, we are struggling to get the Google OAuth to work. We have followed the steps below and still not have had any luck. It keeps giving us this error but we have tried multiple URLs for the failover and it is not working. Any suggestions?References: SMTP Server IntegrationsPreparing a Google Workspace for Jamf Pro Jamf Pro SMTP Walkthrough
Hello Jamf Nation! The Jamf Pro 11.11.0 Beta Release features Managed Device Attestation, updated Computer and Mobile Device Inventory Reporting and lots more. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions. The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!