Get Support
Recently active
Hello Gurus, I am fairly new to JAMF, so I'm still learning. I would like to use Azure groups to assign configuration profiles. I was able to connect to our Entra ID environment from Settings > Cloud identity providers. I can query and find our Azure groups from Settings > User accounts and groups. The problem I'm facing is that these Azure groups are not showing up under Scope when I am setting up Computers > Configuration Profiles or even Policies. The reason for this is to set up different applications/policies for users in different departments. Since we already have different security groups set up for departments, I'd like to utilize what we already have in Azure. We'd also want to avoid LDAP and stick with Cloud only. What am I missing here? Thanks!
Hi there. I am fairly new to Jamf and have been handed control of a school who is already setup. I have a teacher who wants students to take a photo on the ipad and then be able to open gallery, select the photo and email it to themselves. But there is no email listed when they try to share the photo. Does anyone know where to allow this in the dashboard? Thanks.
Just wondering if there is a way to enable the Safari Homepage button so that it's visible. I would like to do this on the command line so that I can have Jamf do it
Hi there,Looking for instructions on how to install the Veeam Agent for Mac. Veeam doesn't have any instructions they just say to "refer to the documentation of your MDM solution.". Obviously there's nothing in the documentation for how to install the Veeam agent using Jamf.Can anyone help me out here? Thanks!Sincerely,
We use iPads for our Electronic Flight Bags, and one of the applications on these devices utilizes the native iPadOS Mail app to send emails. We operate in a Microsoft Exchange Online environment and have successfully pushed email accounts assigned to user devices with OAuth, where they enter their password and 2FA. However, we also use backup devices assigned to planes or loaners, which are user-agnostic. We are trying to push a centrally managed service account for these devices, as the pilots wouldn’t know the password for this email account. Modern Auth is disabled for this account, so a username and password should suffice. Despite this, when setting up the configuration profile, it still prompts for a password on the device when the profile syncs. Does anyone have any ideas or suggestions on how to resolve this issue?
I've installed Zoom via VPP on several iPad's. Recently got a call that the customer stated they were required to update Zoom. When they went to the App Store to update they got this message: "Zoom cannot be updated because it was refunded or purchased with a different Apple ID". This customer was not signed into a Apple ID. I was under the impression that since it was "purchased" via VPP, that it wouldn't need an Apple ID associated in order to update.How does everyone else update non-Apple apps on iPad's that were installed via VPP?Thanks for any help in advance.
I've an idea up at https://ideas.jamf.com/ideas/JPRO-I-778 that I'm honestly kinda jazzed about! Don't know if it will work--still workshopping.The 36,000 ft fly-by is:1) Eliminate Cloud Standard for the SLG space, making Cloud Premium the entry point.2) Bundle training at least up through 200 with the product; offer this "free" for 6mos - 1year. For an org not convinced there's an exit clause with a Jamf-determined fee.3) Admins both go through training before their own onboard, and must participate in at least one peer org's onboard before their own. The notion is pay it forward and/or servant leadership.4) At the end of the introductory period, org's agree to sign on for no less than 3-5 years.5) Orgs that go above and beyond in assisting with onboards maybe get to host a JNUC (a little friendly competition). Where not prohibited by law, policy, etc, perhaps entities may negotiate a waiver of fees pertaining to
Hi all, We are running the latest production ring version of OneDrive (23.153.0724.0003) and setup known folder move via the official Microsoft documentation, has anyone been able to get this working on the production ring? Deploy and configure the OneDrive sync app for Mac - SharePoint in Microsoft 365 | Microsoft LearnI found an article that suggested it was a known issue with Microsoft on the production ring but that was from 2022 so i assumed it would've been fixed by now.Has anyone been able to setup KFM move for Desktop and Documents to OneDrive?
Hey guys, I need to deploy VSCode & Jetbrain Snyk extension via Jamf. VScode is in format .vsix and Jetbrain is looking like a simple folder with one Library and .jar files inside this folder.Have any of you had to deal with such an installation?Thank you in advance.Regards
I setup Platform SSO (enclave) and it works... okay. Outlook and OneDrive both still require me to enter the email address to begin. It's better than nothing, but deeper integration to capture username prompts would be great. And, it would be ideal if we didn't need Company Portal to broker this login. Jamf Connect is already connected to Entra. So, it would be great if it can broker platform SSO, and autofill usernames in apps with the app prefixes defined in the profile.
We have Jamf School in use and now we need to reassign the push certificates to a central Apple-account since before we used to renew them with the personal ones. In Jamf i have the option to change the Apple-Account to which the certificate is assigned but will it affect in any way our MDM and will the devices be still available ? Thanks in advance
Greetings, My grad school is starting a new project to look at how to get user account data (Mac Home folder) transferred from a users old computer to a new computer when the user and the computers are fully remote. We currently provision all computers on-site, and then ship them to the remote user. The user is then responsible for the transfer of data from the old computer to the new one. This results in a fairly heavy lift for the user and support staff. We're moving towards a low-touch process where the user can initiative the provisioning out of the box, so we're investigating ways to reduce the data transfer load as well. Apple Migration Assistant is somewhat less than ideal; it's sort of all or nothing (well, not exactly, but it's not great) and we've had many bad experiences with it on managed devices. We use CrashPlan for home folder backup, but it's very slow at restoring folders over a couple gigs in size. Suggestions? Are there home grown soluti
Afternoon All Hopefully someone has seen this before. I have recently patched VLC media player the install media is DMG so used Repackage https://bitbucket.org/twocanoes/repackage/src/master/?ref=steemhunt application to create a PKG for deployment. I have noticed that some devices don't unmout the sparsebundle within pkg package. I though this might have been some issues with creation of the pkg. So I delete the current version and recreated it.Testing the new package created in same way this doesnt seem to happen.I though removing the orginal pkg from DP would stop it being mounted seems not. So I have created a policy forcely remove it on login. /usr/sbin/diskutil unmount force /Volumes/1010139C-84D6-4178-A17F-D3DD4F424C8C.This seems to be working fine if the machine is rebooted, I think this should sort itself out overtime as the machines are powered off daily. On restarting a device which has just run the above command it doesnt get mounted on login.I have two ques
I'm trying to use Jamf Sync from the command line to keep a local backup of our jamfcloud packages. It works great from the GUI (so everything is in my keychain), but in the CLI I can't get it to connect to the server. The issue is with the formatting of the source I think. With the "Name" for my source in the GUI set as "JamfCloud" (for my JCDS), and the local directory named "JamfcloudBackup" I've tried... -s JamfCloud -d JamfcloudBackup -p-s JCDS:JamfCloud -d JamfcloudBackup -p-s JCDS:xxxxxxxx.jamfcloud.com -d JamfcloudBackup -p-s JCDS:https://xxxxxxxx.jamfcloud.com -d JamfcloudBackup -p-s https://xxxxxxxx.jamfcloud.com -d JamfcloudBackup -p And I get the same response... Loading distribution pointsCouldn't find the source distribution point or folder: The help page says to use "the source name" but is that the name defined in the GUI, or the actual URL in my case?
We have recently purchased Jamf Business and have an Intune backbone for Windows. I know in previous experience that there is a Jamf and Intune connector but upon searching, it looks like that will be deprecated. Is there another way of going about reporting machine info to Intune from Jamf Pro?
How is everyone handling SecureTokens? We are seeing issues with password resets outside of macOS and the SecureToken not working anymore, I am guessing because they aren't getting sync'd up. NoMaD is not allowing users to change their passwords anymore from within macOS even though the password criteria is met.
HiDid anybody try this?How to turn on the "Reminder To Enable Auto Backup" popup for managed devices – Goodnotes SupportI can not get it to work with the provided XML config. When I add the red part of the suggested configuration I get this error:"Unexpected key "" while parsing <dict/>."Adding a "/" before "key" lets me save the file but breaks my working license key config.Any ideas? I find the feature itself to be very useful!
Hi, we need to create a few certificate authenticated wifi profiles to distribute to macs, as the office is mainly windows and the number of macs is 20 or so, there is not much desire to set up an azure app proxy, ndes etc to allow jamf pro to connect to the internal CA through scep to generate certs, but looking through the documentation am not sure if it is possible to access the internal CA through scep when creating a new wifi profile.
Hi I've been searching around for an answer to this but cant find anything that answers it. A) Whats the preferred option, Is using the SCEP Proxy preferred over using the ADCS Connector? B) Is there any functionality difference between the two options once its set up? Or do they perform identical functions Struggling to figure out what the difference is, and why I would go with one over the other. I've got an environment where because of the organisations security requirements we need to use ADCS Connector instead of the SCEP Proxy functionality. I just want to make sure that the ADCS connector will provide the same "end state" functionality as using the SCEP proxy. Any suggestions appreciated. Thanks!Kevin
A new OS in the fall means it's time to review and update EAs. Post your new versions that will support macOS Sequoia (15). I realized that I still had one using `airport` (which is (way) deprecated), so here's my new Current Wi-Fi.sh: #!/bin/bash # 1.3 240808 PWC SSID=$(/usr/bin/wdutil info | awk -F: '/SSID/ { print $NF;exit } ') SSID=${SSID:1} if [[ -z $SSID ]]; then echo "<result>Not Connected</result>" else echo "<result>${SSID}</result>" fi exit 0 Let's f^%#!^ go!
Hello I'm trying deploy EndNote 21 so that End Users can open Word and the Cite While You Write plug-in will be configured. Have tried to use configurater to do this and while everything seems to be in the write place the plugin doesnt load in word.i did come accross this old post https://community.jamf.com/t5/jamf-pro/endnote-x8-w-cite-while-you-write-deployment/m-p/148974#M138024Which I have tried to updated. #!/bin/bash WordMajVersion=`defaults read "/Applications/Microsoft Word.app/Contents/Info" CFBundleShortVersionString | awk -F "." '{print $1}'`WordMinVersion=`defaults read "/Applications/Microsoft Word.app/Contents/Info" CFBundleShortVersionString | awk -F "." '{print $2}'` case $WordMajVersion in15) echo "Word version 15.xx, need to confirm it is above 15.24"if [ ${WordMinVersion} -ge 24 ]; thenrm -dfR /Library/Application Support/Microsoft/Office365/User Content.localized/Startup/Word/EndNote CWYW Word 2016.bundle#Copy the new oneditto "/Applications/EndNote 21/Cit
As one of the maintainers of the Jamf Pro terraform plugin here i'd like to request a new feature to assist with creating Jamf Pro based terraform resources as templates, whereby there would be the ability to export from the gui a template of existing resources into HCL (hashicorp configuration language). The exported template would help admins understand the HCL syntax and properties that deploy admin's resources. The exported template would function as a starting point for new and existing users of the plugin and would act as a basis from which it can be modified for the admin's specific scenario. The exported resource template process would attempt to create a usable template from the off and would be autogenerated, however there would be an understanding that exported templates could still require some modifications before they can be used to deploy Jamf Pro resources. The feature request would enable admin's to pick one or more resources from the gui for exporting to a
The situation:We are using jamf school in conjunction with Azure Entra. This means that users can log in to a 1:1 iPad via SSO. This has worked without any problems so far. The problem:Now we wanted to use some shared iPads. We have created a corresponding DEP profile. When a user now wants to log in to the device, the following happens: Immediately after entering the managed Apple ID, a code prompt appears. The required code is of course not known, as none has been entered yet. You would actually expect a window to open with an MS login screen where you can enter the user password. In the activity log I find an error: “Install/update profile (AzureProfile)” with the content “Profile installation failed / The payload type ‘com.apple.webClip.managed’ may not be installed for the system in multi-user mode.”This profile does not originate from us, but is probably created automatically because of the SSO. There are numerous posts on the subject of webClips, which cannot be easily integra
Hi, I'm wondering if anybody else is having issues with iOS18 and JAMF School? Currently, we've noticed the following: On restrictions, we have 'Allow creation of VPN configurations' turned off. On the new iOS, VPN and device management are now lumped together. Having this setting turned off means you can't see device management at all, so you can't see any certificates or restrictions that are installed. A colleague has informed me that they have had issues with certificates not working properly with in upgrade to the new iOS, but it has worked if factory reset. Another issue I've noticed is Bluetooth. In settings on JAMF School, there's an option for Bluetooth "Enforce Bluetooth on devices with JAMF School Student 6.2.0 or later". I am now able to toggle Bluetooth on iOS 18 which will cause absolute chaos for teachers as we heavily use Apple Classroom. Bluetooth can not be toggled on iOS 17 with this JAMF school setting enabled. Is anybody else having these issues? Does anybody
Hello community, does Jamf plan to make an iOS and iPadOS app for administrators?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!