Get Support
Recently active
Hi all,I have not found anything on the below on the interwebs, anywhere, and am pulling my remaining two follicles of hair out!As of last Thursday, new users on our Macs now can't log into Office for Mac, we're using the latest version of Office (this is the only change).We use JAMF Connect and a custom script to deploy the logged in users email address to OfficeActivationEmailAddress in com.microsoft.office which has been working perfectly up until last week.I've done some testing and tried removing the script from login and just using a PLIST with two entries in:OfficeActivationEmailAddress is set to a manual entry of a test users email addressand <key>OfficeAutoSignIn</key> <true/>With these two set we get the email address prepopulated, as expected but are told we can ONLY use PERSONAL accounts, remove the email address but leave OfficeAutoSignIn set to true and we don't get the email address prepopulated but can manually enter it and all is well in the
Update 11 November 2024: Standard cloud upgrades are scheduled for the weekend of 15–16 November (details below). We appreciate your patience. Today we are releasing Jamf Pro 11.11. Highlights include: Managed Device Attestation Using MDM RequestsJamf Pro now supports Apple's DeviceInformation attestation, a Managed Device Attestation method that verifies the computers and mobile devices in your fleet are legitimate Apple devices. Computer and Mobile Device Inventory Reporting EnhancementsNew inventory information for Battery Health and FileVault 2 enablement are gathered by declarative status reports. Support for New Mobile Device RestrictionsUsing mobile device configuration profiles, you can now restrict the use of RCS messaging, block the transfer of an eSIM to a different device, and preserve the eSIM on an erased device due to too many failed password attempts or the Erase All Content and Settings option. For additional information on what's included in thi
Is it possible to enable non-admin users access to "system preferences > date & time > date & time"? Subpoints of system preferences > date & time are: -date & time-time zone-clock We want to allow (non-admin) users only to change the "time zone", nothing else. Is this possible or do we really need to open the complete "date & time" preferences for non-admins? Thx! Note: macOS 10.12.x
Fairly new to JAMF Pro and looking for a way to stop Self Service from launching automatically when a Mac logs in for the first time (after its enrolled via pre stage enrolment). Is it possible to stop the auto-launch but still be able to use Self Service when necessary?
is this the corrent place to report these items? Adobe Creative Cloud desktop app missing v6.4.0.361 released on 09/16/2024
Hey all, We have a 1-to-1 iPad program for our elementary and middle school students and I've noticed that students have found that signing out of their Google Chrome profiles allows them to browse freely with the added bonus of deleting their browsing data. We have tons of browsing restrictions in place already, but kids are kids. I'm wondering now if there's a way to lock them into their Google Chrome profiles so that they're not able to sign out, kind of like restricting account modification for their Apple Accounts. This seems to be the only way to ensure that they're unable to delete their browsing history, and it also seems that the specific restriction in Jamf only applies to Safari, unless I'm missing something. Any thoughts?
I have made a script, with help from other scripts found online, that will take user input and then update user information on JAMF Pro. All working apart from where you enter the staff/students full name for example "John Smith", script is only reading the first word on the input and updating JAMF = John. Been on this for a few hours trying anything that I can find and now I am at a loss of what I can try to sort this. Any help on this would be very welcome :) JAMF_FULLNAME=`/usr/bin/osascript << EOTtell application "System Events"activate set JAMF_FULLNAME to text returned of (display dialog "Please enter fullname " default answer "")end tellEOT` #Store input full nameecho $JAMF_FULLNAME ------------------------------------------------------------------------------------------------------- Complete script for information: #!/bin/sh echo ""#1. Get user input for usernameJAMF_USERNAME=`/usr/bin/osascript << EOTtell application "System Event
I've got an exemption group set for a handful of machines to allow them to use Screen Sharing. But when the compliance script run's its remediation it appears to be disabling Screen Sharing.The logs show that the rule failure being identified... Tue Nov 5 14:14:09 UTC 2024 system_settings_screen_sharing_disable passed (Result: 0, Expected: "{'integer': 1}") ...and then where the fix should be skipped because of the exemption... Tue Nov 5 14:15:16 UTC 2024 system_settings_screen_sharing_disable has an exemption, remediation skipped (Reason: Exception - Remote-ScreenShare) And yet Screen Sharing is being disabled as soon as the remediation is finished. I haven't modified the script. And there are no configuration profiles or other policies running to re-disable Screen Sharing.
The last post I can find relating to this is from 2017; There isn't a solution there and I've tried almost everything previously listed.We've been using JAMF for a few years mostly without issue - this is the first time we're seeing this error. There's a similar error "connecting to jamf server" which can be resolved by simply uninstalling and allowing JAMF to reinstall Self Service. No luck on this one. also tested:computer restart, trying from an IT account (removes any variables from the users startup items), refreshing the MDM, clean uninstall and reinstall of the JAMF Framework.I did find the list of ports, but we aren't seeing any blocked ports (on machine, router, or via ISP). Issue is present both on and off VPN (so that is irrelevant).Currently this is only affecting the one machine but as I don't have a fix there's trouble if it spreads. The Mac still has access to jamf controls via terminal, still receiving profiles and policies, still reporting in all information to the ser
I am about to scream. After several hours on the phone with ASM and JAMF, and after being moved up the chain about three times, the issue is not resolved. All my info in ASM is correct and synced, the 5 students show up in all their classes as offline, and their ipads DO NOT show an EDU profile, even though I have checked User ID and location, I have verified it matches in ASM, I have verified I have the right ipad, the right person, the right Apple ID, and done blank push and update inventory and everything else you could think of. Still no dice. The one thing I discovered is that on all the messed-up ipads, the roster info did not sync over. I put it in manually, but still no dice. ANYONE have this issue? I am mega frustrated.
We have deployed Kerberos SSO extension to all mac devices so that we can access SMB shares from file server. When we enroll new mac device, for the first time JAMF asks Kerberos credentials and user needs to manually enter the username and password. Once user provided credentials, it receives Kerberos token and token renews automatically. Issue which I am reporting here is why user needs to enter Kerberos credentials for newly enrolled mac, why it can’t be automated. JAMF connect menu bar plist: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" http://www.apple.com/DTDs/PropertyList-1.0.dtd> <plist version="1.0"> <dict> <key>Appearance</key> <dict> &nbs
I have deployed Sophos Intercept X to our mac and ipad fleet. running great on the Mac, but on the iPads the app has to be opened before the device is enrolled into Sophos Central to pickup the policies. It's unfeasible to get all our students to manually open the app so I'm racking my brain to figure out how to do this. Initially I setup a config profile to deploy a single app mode payload which opens the app, and then had a smart group (with criteria of having the single app mode config profile installed) in the scoped exclusions to disable the single app mode once it was pushed out. but this created a loop. I'm wondering if anyone had any suggestions on how to get this sorted by either being able to open an app without single app mode. or another criteria i could try with the smart group.
Hi, I'm running into an Enrollment issue where the jamf connect okta screen is getting bypassed if the computer is idle and goes to sleep. For example, the user will go through the setup assistant options and reach the jamf connect screen. The mac goes idle/to sleep and once the mac is turned back on, it prompts for a local account login instead of the jamf connect login and you do not get an option to switch to the jamf connect screen anymore. How could I keep the computer display awake when new users get to the jamf connect screen stage? If a computer goes idle and prompts for local account login, is there anything I can do to revert back to jamf connect screen? For one case, I wiped the computer and reinstalled macOS, went through setup stage and it still prompted for local login instead of jamf connect screen
Good morning, We have a problem with shared iPads and students that have to change the Apple School password.After select the name on the list and before begin the password change process, appear the setup assistant about the language and country, I just now create a profile removing all the setup assistant steps from shared iPads and it stil appearing.The problem are the students don't be patience and the iPad get hang during the language process if you didn't wait to select and continue with the password change process. Thank you very much and Merry Christmas.
So we have an ipad that I enabled lost mode, due to the fact it was overdue and the one who checked it out did not return it. So then I locked it and put a message on the screen. It was returned so I disabled lost mode, does the system take a while before it unlocks it? I can see that the command is pending 12 minutes ago, along with other commands that are still pending since 7-2-24 after I locked it. But what I am not sure is if this iPad has active internet connection so that it can receive the command. How can I connect this ipad when it is locked and I do not think there is an active internet connection to it? Will the factory reset method work and when I am asked to join a network connect it and then the commands will process?
Ho do I remove Wallpaper from one iPad? I set it with a picture in Device Management, now I can only upload a new image, I can't remove the one already uploaded? Thank you
When I try updating IntelliJ IDEA (Ultimate edition, i.e., the licensed version) using the Jamf App Catalog, I'm getting an error message. I installed older versions of the application on a couple test devices. I get notified that the app needs to close to update. I close the app, the update begins, and then I get an error message containing the following info: Cannot start the IDECannot set current directory to ‘/Library/Application Support/JamfAppInstallers/com.jetbrains.intellij/scripts’Caused by:No such file or directory (os error 2)Please try to reinstall the IDE. I’ve verified the directory noted in the error message does not exist. Has anyone else experienced this or anything similar? Some additional background info: Our end users currently install the app from the vendor’s website; we don’t currently offer it through Self Service. I’m not a user myself, so I’m unfamiliar with the app. I do have a license and activated it after installing the app. To set things up
This is great did some initial testing with S.U.P.E.R.M.A.N | Jamf Pro on a couple of Intel devices one running Big Sur and one with Monterey both are now fully patched thanks to Kevin M White and @HCSTechnology post on it.https://github.com/Macjutsu/super has anyone else tried it out yet and what do you think of it?
So I have around 360 devices that haven't checked into Jamf for at least 60 days. Thats a lot of licenses being used for no reason. Around 300 of those haven't checked in for 90 days, and maybe half of those haven't checked in for at least a year.My fear is, we have devices all over the world, and managers that like to hold onto returned devices in a drawer for their next employee. If I move these devices into unmanaged, then i'll have to be notified that the device is going to be used again to move it into managed or the device won't get updates or any management tasks when, not if, the manager just turns it back on and hands it to their new employee and says "here, get to work". If I delete the device from jamf so its not taking a license anymore, then I have the same problem, but the only resolution is a full re-jamf. I have a feature request in for some time for some kind of Archived mode (similar to what Filewave has/had) that we could put a device in (call it Quiet or Stored mode
Is there a way to remove web clips that have been created by users via an mdm command/profile? My issue is we have locked our student iPads so that they cannot remove apps from their devices, primarily so that they can't delete our filtering app. However, they still have the ability to create web clips, so some of our students have cluttered their iPads with web clips that now cannot be removed, since the profile treats web clips like apps. I know I could just hide the web clips, so that they couldn't be seen by the students, but then this would hide any of the web clips that we have specifically pushed out. I would really like to be able to send a command to remove web clips from a device, then have our district web clips just be resent to the device. Also, is there a way to restrict web clips being created on the device? Remove the "Send to Home Screen" option"
I am working on creating a good way to track Macs that are not communicating over MDM properly. I have several Macs that are not getting profiles installed, profile changes, and are generally not working properly with MDM communications. One way I have tracked them down in the past is to create a profile, scope it to all computers and then wait to see which Macs don't get the profile. This works, but I wanted to dig a bit deeper. I have been trying to use this command to find out if Macs are reliably working with MDM: log show --info --debug --predicate 'subsystem == "com.apple.ManagedClient"' --last 1h The time can be changed to what ever I want. It seems that this command is only gathering activity from the Mac, not incoming MDM activity. That's what I need. Running the command above will result in a lot of information so I have used grep to make the output more focused. So far, I haven't been able to identify communication coming from APNS. Just running the command from a Mac
On Saturday, November 23rd, 2024, Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time ap-southeast-2 November 22 1300 UTC 1700 UTC ap-northeast-1 November 22 1500 UTC 1900 UTC eu-central-1 November 22 2300 UTC 0300 UTC eu-west-2 November 23 0000 UTC 0400 UTC us-east-1/2 November 23 0500 UTC 0900 UTC us-west-2 November 23 0800 UTC 1200 UTC Jamf Cloud Hosted Data Region Information
I'm trying to have OneDrive function on our company devices so that when they login and Onedrive prompts their login for Onedrive specifically it will automatically start backing up the local documents and desktop to Onedrive. I've tried a lot of variations and done a lot of searching through these forums but nothing's working. I have a Config Profile - > Apps + Custom Settings -> Upload -> com.microsoft.OneDrive. and below is the plist . Is there anything clearly wrong here, I'm stumped.<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>DisablePersonalSync</key> <true/> <key>DisableTutorial</key> <true/> <key>AutomaticUploadBandwidthPercentage</key> <integer>30</integer> <key>FilesOnDemandEnabled</key> <true/> <key>BlockExternalSync</key&
Today we released Jamf Connect 2.41.0. This release includes the following changes and improvements: Upcoming Support Removal for macOS 12.xSupport for macOS 12.x will be removed from Jamf Connect in a future release. Jamf recommends updating to macOS 13.x or later to ensure continued support. Other Changes and ImprovementsYou can now configure offline multifactor authentication (MFA) without integrating Jamf Connect with a cloud identity provider (IdP). This allows users to have an accessible MFA solution, increasing device security without the immediate need for an IdP integration. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hi all, New to Jamf and I'm not seeing the connection on getting Free apps deployed. I followed the steps in the Jamf 100 Course but im getting "Pending - All licenses are in use or the license is not assigned yet". So I went to Apple Business manager and added 1 licenses for the application (im testing this). Made sure the VPP was configured inside of Jamf. What am I missing??This is a 100% free app... why/where do I need assign a license?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!