Get Support
Recently active
I have jamfpro allow the camera only in specific specific apps, and disable the camera in the browser and others at all.However, Disabling the camera will also prevent third-party apps from using the camera.How do I deal with this?
we are using jamf connect for account creation for our environment and we are populating accounts from okta ldap and okta is idp.I am able to download and enrol my device with user initiated process but for auto enrolment I am not able to proceed after doing authentication with okta.I can provided crews and I can approve okta prompt for authentication successfully but right after successful authentication the login window on the devices remains as it is and password box goes blank.
In my organization, students are often unaware that they need to release devices from their iCloud accounts. Because of this, we experience a fair amount of Activation Lock Errors. Previously, when using the bypass codes provided for each user in JAMF, they worked consistently. Recently (over the past 6 months) I have noticed that there are an increasing number of codes that are not working ot remove Activation Lock from the devices. Currently I am attempting to contact each of the students with directions on how to release the activation lock, however, they are no longer students of the university, so often times, they are not checking their university email, so a better solution is preferable. Has anyone else experienced this? Whether you have or have not had these same issues, can anyone offer a better solution?
Hi,We issued a new ipad to our speech teacher. She has many apps on her old ipad that we only purchased one license for. How do I transfer the paid license to the new ipad? Will she lose all the data from those apps in the old ipad? Both ipads are managed via JAMF Pro. Any help will be greatly appreciated. Thanks.
Estoy buscando ayuda para dar a los usuarios con perfil estándar en macOS la posibilidad de agregar y eliminar redes Wi-Fi sin que el sistema les solicite la contraseña de administrador, pero limitando este permiso solo a la gestión de redes Wi-Fi.Quisiera saber si alguien ha creado o conoce un script que permita otorgar estos permisos, y que pueda enviarse a los dispositivos a través de políticas en Jamf Pro. Agradecería mucho si alguien pudiera compartir una solución o guiarme en el proceso.¡Gracias de antemano!
Hi We've noticed recently that a reliable script to return jamf ext attributes has stopped working in ventura, somona and sequia.oldPass=$(curl -s -f -u $apiUser:$apiPass -H "Accept: application/xml" $apiURL/JSSResource/computers/udid/$udid/subset/extension_attributes | xpath -e "//extension_attribute[name=$extAttName]" 2>&1 | awk -F'<value>|</value>' '{print $2}' | tail -n +1 ) We used to be able to retrieve the value of an ext attribute with the above but it seems to have broken. i see lots online refering to "xmllint xpath" as a fix but doesn't work in our case, just returns an empty value.
We have been seeing several personal IOS devices being prompted to register or sign in with Jamf Pro registration. Our environment uses Intune for MDM, so this creates several issues, including some configuration profiles with applications and such. These are often phones that we are attempting to register in Intune, as well as the users signing in and registering their device with MS Authenticator.
I have a CIS requirement from our security team that will disable an NFS, HTTP, and FTP server and I'm having a difficult time coming across anything on JAMF Nation or Google searches. Is anyone doing anything like this? Thanks!
Hi there, We are using Jamf School and Jamf Pro. Formerly, we had Jamf Pro, but for some select iPads, are still using Jamf Pro. For this particular app, we have 222 purchased licenses, and I removed about 70+ serial numbers off the scope. Jamf Pro is still saying there are 200 in use, with 22 remaining. I have some pushed to Jamf School MDM iPads. Apple School Manager says the same. There are "22" remaining. It's been that number whether I take off or add. There are more problems I have, but for this question, I am curious why the "In use" amount doesn't change. I tried to transfer some licenses over (because we had a volume purchasing problem). When I tried pushing the app, it would ask me to sign in with an iTunes account so I just put most of the licenses back into the other MDM that works with volume purchasing. Hopefully this makes sense! I took over from our previous Jamf admin so I'm still learning a lot of things and uncovering stuff. Thank
Hello Mac Admins!Not a shell script expert!! But still managed to achieve this comprehensive script. Give it a shot and let me know how it performs in your environment. As always, feedback is welcome!I’m excited to share a robust, advanced macOS Sequoia upgrade automation script tailored for enterprise environments. This script ensures a seamless upgrade experience by performing pre-upgrade checks, deferral management, Secure Token validation, and notifying users at every step to keep them informed. It has been designed to address common challenges in macOS upgrades and provides full automation with error handling to reduce user friction and IT overhead.This solution leverages JAMF Pro to manage the upgrade workflow and works well for both JAMF Self Service policies and automated deployments#!/bin/bashLOGFILE="/var/log/com.scb.sequoia_update.log"DEFERRAL_FILE="/Library/Preferences/com.scb.sequoia_update_deferral.plist"MAX_DEFERRAL_DAYS=1CURRENT_DATE=$(date +%Y-%m-%d)CURRENT_EPOCH=
I am reaching out to seek your assistance regarding a customized requirement for taking snapshots on Jamf, involving multiple applications bundled as a single package. I would greatly appreciate your guidance and expertise in achieving this.I have been exploring the functionalities of Jamf and its ability to capture snapshots, which I find extremely useful for managing software deployments. However, I have encountered a specific scenario where I would like to create a custom snapshot that includes multiple applications within a single package.Could you please provide me with step-by-step instructions or guidance on how to achieve this? Here are some specific details regarding my requirements:Snapshot Purpose: I would like to capture a snapshot of a specific software configuration that includes multiple applications installed on a macOS device.Multiple Applications: The package I want to create should include several applications, each with its own specific settings and configurations.C
Hi teamI think I already know the answer to this one (cheers Apple for that brick wall) but asking anyway as there are smarter brains at work here than I :)Using Display Link for dock drivers and keen to know if System settings to enable Display Link Manager (And Jamf Remote Assist for that matter) can be scripted as part of the app policy in Jamf Pro?
Hi Jamf community!Wanted to share this with the community and possibly get some input on how else I can block JDK from getting installed. The problem is, JDK uses "Installer" process which makes it really difficult to block that as I dont want to block any other app from being installed. Below are some other methods I've tried so far with the outcomes. 2 things to note:1. All our users are local admins (yes, i know!)2. I do not have Jamf Protect.Code Signature Verification:I attempted to block Oracle JDK installations using code signature verification, focusing on the Team Identifier VB5E2TV963 from a previously installed JDK.Also tried using hash values for both the dmg and the pkg within it. The closest ive come is that it does detect the installer but does nothing to block it. Outcome: I successfully identified the Team Identifier, but my current implementation isn't effectively blocking installations across different paths.Script Development:I created a script located at
For safety and sanity, we'd like to be able to disable this feature on in our fleet. I couldn't find any documentation on a configuration profile payload or policy setting or even a homebrew script to disable this feature. A config profile would obviously be best as it would prevent the users from re-enabling. An ongoing policy that uses either a script or an actual policy payload would be... fine I guess, but less preferred as between recurring checkins the user could do whatever they wanted. Does anyone have any resources on this?
Hi everyone, I'm just putting out feelers to see if anyone knows of any alternatives to Carousel digital signage that are reliable, and bonus points if they use apple tvs as the players. We've been happy with carousel for a few years, but them eliminating the on-prem product while charging SO much more for the cloud product has me thinking about alternatives.
Hello everyone. I am testing Privilege Escalation for the first time with JC; 2.39.0. I want to do a very basic any user can escalate for 30 minutes with no password needed, just need to select a reason. The profile is deploying to the test workstation however the Request escalation is not appearing. Here are the necessary snippets. Any assistance you can give will be greatly appreciated. <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>Appearance</key><dict><key>AlternateBranding</key><true/><key>MenubarIcon</key><string>/usr/local/jamfconnect/cdi-LM@1x.png</string><key>MenubarIconDark</key><string>/usr/local/jamfconnect/cdi-DM@1x.png</string><key>ShowWelcomeWindow</key><false/></dict><key>Cust
hey folks.. For stupid reasons unknown, I've been tasked with disabling the QUIC / HTTP3 protocol in our browsers. I got Chrome disabled no problem, but can't find anything regarding disabling it in Safari. Has anyone done this and can share the way??
I've had MMA setup for a few years now and it mostly works but it's been devices based and I've never had it working based on device/user. For example we have a lab of Macs and we only want MMA available for a particular faculty member and not an option for students. If I scope it to a user it never shows up. We have to scope it based on device but then it's open for all users of that device to have access to using MMA.Maybe it's a setting I have but scoping to a user never works. As for 3rd party, there're apps out there but many are pretty pricey. We need something that's not crazy pricey that can replace MMA and be controlled through JAMF or a cloud service or server.
Hello there, I'm trying to add custom trusted sites to uBlock on Chrome and JAMF is throwing an error saying the PLIST format is incorrect. I'm wondering if any of you have a template for whitelisting domains in uBlock that you'd be able to share. Below is what I'm trying to use that is not working. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>trustedSiteDirectives</key> <string>"trustedSiteDirectives":{"microsoft.com", "adobe.com", "office.com"}</string> </dict> </plist>Thank you in advance
Hello, I did a bit of searching for this answer, but I wasn’t able to find anything as exact as what I’m looking for. I have a 100 something iPad 8th Gen’s. I keep getting told that they will no longer be supported in Jamf Pro around the fall of 2025. This is from someone internally in my company. From what I’m seeing, it’s not necessarily 8th Gen’s that are no longer supported, it is devices that are not able to be updated to a certain iOS.The way I understand it, as long as the device is not older that 4 major iOS versions, then it is supported. So in the Fall of 2025, as long as the device is iOS 16 or higher (assuming iOS 19 comes out), it is still supported. Am I correct on this?
We are preparing to switch from eDirectory to Active Directory. When we enroll devices via eDirectory, the devices are registered with:- username (abcdef#)- full name- email...among other things.We have a lot of manually created accounts in eDirectory for, among other things, shared units and/or non-personal units that lack email addresses.We are in the pipeline to run a script to replace all device usernames with the people's email addresses but the big question is what do we do with the devices that have accounts (manually created) that have no email addressesCan you, for example, set up a new PreStage that you enroll them via again that does not tie them to a user account or are there other options?
Hello, everybody.There's a profile we are supposed to enable outside of school hours. Meaning, everyday when the students leave school until they come back. That includes weekends and holidays, of course.How should we go about doing it? It seems there's an option to do just the opposite of what I need: "don't install this profile during the configured holidays".Thanks in advance.
HelloFirst of all, sorry if this is already solved in some other thread. I have not found it.It turns out that in my son's school they force me to install on his computer the JAMF application to know what he does during school hours. But it so happens that I don't want them to be able to know what my son (or whoever may use the computer) does outside of school hours. I assume that the hours when the application works can be configured in the application. But since they are the ones who install it, and I don't have administrator permissions on it, I can't know if they set it up correctly or not.What options do you recommend me so that this does not happen? I had thought of creating a virtual machine and have them install the application on that machine. Another option I had considered was to install a second operating system on an external hard drive, and outside school hours boot the computer from it. But maybe I am making my life too complicated and there is a simpler option, such as
We are building up a python script that fills the Users (Teachers / Students) into the classes with the jamf api. We are doing good so far but we have trouble updating the User Class or Group assignments. We are using the Documentation on https://school.jamfcloud.com/api/docs/It seems that we can add groups but we want a full upgrade. The user should loose the existing group / class assignments and get the new ones that is in the put. Should we use https://school.jamfcloud.com/api/docs/#api-Users-Update or https://school.jamfcloud.com/api/docs/#api-Classes-Assign_users ?
We have the following set in App Config in Outlook.<dict><key>com.microsoft.outlook.Mail.FocusedInbox</key><false/><key>com.microsoft.outlook.Mail.OrganizeByThreadEnabled</key><false/><key>com.microsoft.outlook.Contacts.LocalSyncEnabled</key><true/></dict> We have confirmed the below works <key>com.microsoft.outlook.Mail.FocusedInbox</key><false/>but the below settings don't work <key>com.microsoft.outlook.Mail.OrganizeByThreadEnabled</key> <false/> <key>com.microsoft.outlook.Contacts.LocalSyncEnabled</key> <true/>
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!