Get Support
Recently active
Hi EveryoneI hope this document will help everyone who use Cortex in their environment for mac and manage via JAMF Pro. You can deploy cortex via Jamf. It is pretty simple and straight forward. All you need to follow PaloAlto Networks document: https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-7/cortex-xdr-agent-admin/cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-for-macos. Here you will find they have already pre-configure MDM profile for Cortex one for M1 and another one for non M1. you will get all those here: https://docs.paloaltonetworks.com/cortex/cortex-xdr/7-7/cortex-xdr-agent-admin/cortex-xdr-agent-for-mac/install-the-cortex-xdr-agent-for-macos/install-the-cortex-xdr-agent-for-mac-using-unified-configuration-profile#id945ae538-41d5-4b65-ad37-233fd665e992. After download unsigned one upload to your Jamf pro and make some changes as required and follow the document if needed. After upload profile scope your machine to have them on endpoint before corte
Hello, We just started to implement Jamf and we want to configure Jamf integration with Intune. All the policies are in place and we are using company portal to make the enrollment. The issue here is that, after we run the Microsoft Intune Integration from Self Service, we have to login in company portal, after finishing the Company portal the user is prompted with this:If you click continue, you will have to make one more Azure sign in, but the login screen will get stuck after entering your password. My guess is that it get stuck due to system asking you if you want to save the password. The only workaround I found is to close the screen, sign in to Jamf and redeploy the integration script. This time, the enrollment will be done because you are no longer prompted to save the credentials. My question is: Is there something we do wrong or can this be solved? Regards,Traian
Environment WSS Agent, SEP/SES Web and Cloud Access, Symantec Enterprise Agent (with the Web Gateway capability) Cisco AnyConnect Client VPN Curious, has anyone encountered issues where proxied websites are blocked from loading when using SES web and Cloud Access together with cisco anyconnect in their environments? Scenarios: SES web and Cloud Access is enabled on the mac client and OFF VPN , and in office: Proxied Websites load fine SES web and Cloud Access is enabled + Cisco Anyconnect Client is connected :proxied websites do NOT load In office, everything is fine.. Windows clients work while connect to VPN
127.0.0.1:631/printers I set the defaults I want for the printer Works great, but just on my computer. I would like to use the file that is modified and push that out to other computers so they also get the defaults for printing. What file is modified?
Anyone have ideas on how to get the client to consistently present the computer name during the authentication attempt? My understanding is that the 'Use Directory Authentication' option in the profile configuration should be forcing this. I thought I came across an article from back in the 10.10 days where this was discovered as a bug and fixed in 10.11, did it come back?Problem Statement: Corporate managed macOS devices are intermittently failing wired and wireless authentication against the Aruba ClearPass policy. The issue appears to be that sometimes the Mac is sending the logged in user’s username for authentication rather than the Mac Computername which is what is expected. Additional Problem Statement context:When a Mac authenticates the authentication attempt is passed to the ClearPass policy manager. The ClearPass policy is expecting the Mac to pass along its Computername in the 'Username' field. It then validates that this Computername is in the Macs OU in Active D
Hi All, Has anyone got any information on how to create an app for the self service portal that allow a user run Jam policy script ? sudo jamf policy
Hi there, i had a message that our push-certificat will run out in 1 month. I probably made a mistake while renewing this cert. I generated a complete new one and now i cannot push to existing computers anymore. sudo profiles renew -type enrollment Registration with the administration server has failed.The update to an MDM profile contains another push topic What can i do? Frank
It would be nice to have a "notes" section in static device groups so I could add info like classroom locations and current teachers (i.e. these 20 ipads are spread across 5 classrooms 4 ipad each room). I could make individual static groups per room, but that seems like a lot of hassle with teachers/classrooms changing and moving. How do you guys keep track of ipad locations?
Does anyone have a script to use an EA to report on the Expiration date of the JAMF connect license or where this can be viewed on the device?
I am trying to create an API Role that has full access. Is there a way to do this without having to click every single privilege in the list? Am I missing something? Thank you for your help!
I'm wanting to enable the "Defer Updates of software updates" to block Sonoma when it comes out, but we don't have an outstanding Restrictions profile in place.So take this screenshot from below. This is some of the default things ticked/unticked etc in a Restrictions profile.So. if i JUST want to have the restrictions for defering software updates.....should i leave the existing options enabled....or....untick them all?I just don't want to push out a restrictions profile, and then block a load of things that perviously were allowed.Thanks
Hello all,We want to host caching servers in each site, and we've run into a few roadblocks in this area.The main one, is we want to tell the computers to only use the cache on the servers, and not cache locally. We could not find such an option.Another issue, we think we solved, was the fact the actual server had to be excluded from the policy that distributes the caching profile in order to configure it differently. Can anyone share their experience with caching servers? We just want all macs under the same public IP to reach the server that's on that site.
Is there a way to get a list of all installed software from the JSS? What I am looking for is a list of every installed application in our environment.
During integration of Jamf Pro with Entra, a Global Administrator account is needed and this account must exist on the Entra tenant. Often, we use the same account to set up the app registrations for Jamf Connect and to create the various changes for conditional access exemptions, etc. Once these are set up, can this Global Administrator account be safely removed from Entra without affecting any of the integrations or applications created?
Well I am not sure this is even possible to do, but here goes...Update Macs to OSX 12.3, and Google Meet screensharing has broken.I have a PPPC configuration set up to allow non admins to be able to authorise screensharing, all they have to do is go there and click the tickbox.The fix for the issue is...Uninstall google Chrome.Remove Google Chrome from the list in the System Preferences>Privacy>ScreenSharing.Reinstall Google ChromeAdd Google chrome back in to the list for ScreenSharing. Ok I can script finding all of the Chrome stuff and remove that. But how on earth do I go about removing it from the ScreenSharing list.I have around 400 Macs with possibly 2000 different accounts spread across multiple campuses, up to 80 miles apart. So the manual method of going to each mac in turn is not going to happen. Does removing it as the Administrator on each Mac, remove it for all users on each Mac? If so is there any way possible to script that? Any help will be greatly
Random question, but is it possible or are there any scripts out there that could report on Hardware issues? * Display issues/cracked screens (number of nits) * Overheating * Fan Issues etc
I'm attempting to create a configuration profile for GlobalProtect so that users don't have to enter the vpn server address. When testing the following which was added to a configuration profile in Jamf, it still prompts. Any ideas? And, yes, I have our real address in the one I'm using. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Palo Alto Networks</key> <dict> <key>GlobalProtect</key> <dict> <key>PanSetup</key> <dict> <key>Portal</key> <string>vpn.server.edu</string> <key>Prelogon</key> <string>0</string> </dict> </dict>
Hello, I am trying to uninstall iMovie on managed devices. We initially pushed the app through a policy for some reason I do not remember. Since iMovie is asking users to sign into apple id in order to update to the latest version it is not working since we restrict the app store and apple id. We now want to push the iMovie app through the JAMF pro app catalog to make it easier to update. I tried pushing the app through the jamf catalog with the app already installed but it does not seem to download the latest version and remains at the version installed from the policy. What would be the best way to uninstall the app that was pushed through a policy?
I was able to get some phenomenal help from @sdagley and @rayjd1650 on this before, but cannot seem to find any keys for disabling the crash reports. I have dug through the Crash Reporter docs and the policy-templates, but am unable to find a key to disable this feature. If anyone knows a solution, I'd love to read it. Thank you in advance
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issue: Jamf Pro Server [PI121695] Functionality for viewing computer inventory information in the General pane of the Jamf Pro interface and retrieving inventory information for certain endpoints in the Jamf Pro API, including App Installers endpoints, has been restored. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. If you would like to upgrade manually, navigate to https://account.jamf.com/produ
We generally restrict student ipads to not allow Airdrop. We use a Static Device Group exemption to allow it for a select few students who use it to share app data with their teacher. Everything was working well until we started to update the student ipads to iOS17.x. Teacher ipads, even ones on iOS17.x can still Airdrop. Student ipads, once on iOS17, can Airdrop to the teacher ipad, but the teacher ipad can't Airdrop back to the same student ipad. How do I find the setting that needs to be changed?
How would I force install this extension? https://microsoftedge.microsoft.com/addons/detail/jbkfoedolllekgbhcbcoahefnbanhhlh And also set my self-hosted server URL? https://bitwarden.com/help/configure-clients-selfhost/#tab-macos-55MXwgIamulyigoLoAbLMo An example plist would be much appreciated. Thank you in advance.
Has anyone else had their FileVault key rotated since updating to Sequoia?It's happened on 2 test machines we've updated from Sonoma to Sequoia (both ARM).The personal recovery key then doesn't escrow to Jamf and becomes invalid.Checking in to see if anyone else is seeing this before we roll out any further.
We were told that Jamf Connect is basically NoMAD rebranded (sales agent's words not mine) so I assumed it'll work exactly like NoMAD. We used NoMAD in the past to authenticate to local AD and access to file shares was not a problem. With it now becoming unsupported, we decided to look at Jamf Connect. Now, we're trialling Jamf Connect and for the life of me, I can't get it to authenticate to file shares. I suspect that it is passing incorrect credentials (i.e. just the ShortName value) because when I connect using Finder to an SMB share, if I use the default entry, it fails but when I add the AD domain part (@domain.local), it goes through. So now I have 2 problems: 1. Some of our users will have a ShortName value of firstname.lastname (they auth to Entra ID using firstname.lastname@external.domain.com). How can I change this so that it uses the sAMAccountname? I've read that you can pass additional attributes but have not seen an example of how to properly do this
We have two Jamf Pro instances in use; one is a test environment and the other is our production environment.Over the course of the last couple of years both instances might have entries the other one does not have.At the moment I'm preparing a project to overhaul our instances so that our production server resembles our test server (as much as possible).Do you know of any tools/tips to compare both servers? Ideally it generates some sort of report with found differences.Any tips are much appreciated.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!