Get Support
Recently active
Hello people my name is Sanjeev Mansotra from Dubai. I'm new to this community, please help to solve my query. How can Jamf Safe Internet be integrated with existing school networks to ensure compliance with both local data protection regulations (such as GDPR or CIPA) and institutional cybersecurity protocols, while maintaining seamless network performance and minimal latency for students accessing educational resources across a multi-campus setup? Additionally, what strategies can be employed to monitor and enforce safe internet usage without infringing on user privacy, and how can Jamf's threat detection capabilities be customized to address institution-specific vulnerabilities and emerging threats?
First a warm hello to the community and a happy new year to everyone 🙂I am looking for a solution to run a client policy (job) on jamf pro immediately after setting the scope to the policy instead of triggering it with a event like "change networkstate" or "recurring check-in". The reason is, we have to change a configuration file on the client dependent of a server event in our windows domain.I cannot find any article here, so I would be glad, if someone can help me to solve my problem.greetings,Michael
Is there an option to remove a user's ability to perform mass actions in jamf Pro? We recently conducted a risk assessment, and we discovered that anyone can perform a mass action as long as they have permission to use that action on an individual device. Is there a permission or another tool you have used that would remove the jamf users ability to do something like wipe all devices but allow to still wipe one device at a time?
Hello Everybody, Our Macbooks on the domain. So we are deploying AD certificate to our macbooks. I have 2 question for this.1- How this is working? For example, I'm login in a macbook nothing happens.(certificate not installed) But after reboot or log out then login, AD Certificate is installed. Why do i reboot or logout? 2- AD certificate is applying to all users. When we are setting up a macbook, login with local account. So Jamf try to add AD certificate to local account. I dont want it. How do i set exclude for the local accounts? This is a local account and AD certificate always pending.Thank you.
Hello, I'm new to Jamf. Does anyone have suggestions on configuring Cisco VPN to install during the initial startup or right after logging in with my Windows credentials?
Hi I would like to:Defer a major update (from Sonoma to XX) for 90 days & Allow all minor updates (from 11.5.2 to 11.5.3) How i can achieve that.
Is there a way to display a computer group in the Jamf Pro Dashboard based on whether it is Locked in Computer > Management? I tried all the advanced options but could not find anything that seems to work.
Hi, our company has canceled the BYOD option. I have my own mac and two options. Enroll your mac or start working on a company laptop with windows. Honestly, I'd rather stay on a mac, but I'm afraid that if the company blocked my laptop via jamf, I wouldn't be able to use it for my private purposes.I can think of a solution:Bual boot, when I would have 2 systems on the mac (both under the same apple ID), but I would only enroll one, so in case of potential blocking, I could still use the mac on the other system.Does anyone have any experience with this?
Hi, We use 1 Jamf instance for multiple school facilities, sometimes a device needs to be moved to a different location within our Jamf instance. Though since about 2 months ago, we are unable to move devices. This is the error:The device could not be moved because it is not associated with a server token in the main location.Anyone have an idea what's going on?I checked all our certificates, enrollment and purchase all valid
Good morning.We are deploying Jamf on approximately 200 new Macs that we are replacing for our employees; however we have around 60 already in operation, which were added to ABM by the Apple Reseller.To avoid asking employees to use the terminal and type "sudo profiles renew -type enrollment" command, is there a way to make this process automatic?I would like to be able to share a file by email and saying to them "Just launch it and wait until Setup your Mac will start". I tried with Automator without success.Any ideas?
Hello, since a while we get an error message when trying to transfere the configuration Profile to our Ipads.I think it is since we updated to IOS 18 / IOS 18.01, but not sure about that.The error message is: Beim Einstellungsdienst für Netzwerkauslastung ist ein Fehler aufgetreten. / permission deniedAny idea what is causing that problem and how to solve?Udo
https://ideas.jamf.com/ideas/JPRO-I-769 upvote if you agree, i think this would be a great place to add notes for other admins, troubleshooting steps that have been taken in the past, etc.
Historically, I've been using this command to restrict modifying WiFi settings to admins only: /usr/libexec/airportd en0 prefs DisconnectOnLogout=Yes JoinMode=Automatic JoinModeFallback=DoNothing RememberRecentNetworks=No RequireAdminIBSS=Yes RequireAdminNetworkChange=Yes RequireAdminPowerToggle=Yes I've recently realized this no longer works on Sonoma. Does anyone know of an alternative way to enable this on Macs running Sonoma?
Just curious if anybody has run into an issue where you uninstall app, but won't reinstall, but the policy logs show successful reinstall. A while back I was testing a snagit version and used the uninstaller, but after that, I could never get it to reinstall. I went through the Mac and removed every file related to Snagit, went in to the /Jamf folder and removed anything related to snagit. For that I eventually just reimaged it. I just came across the issue again uninstalling cisco secure client. I have a script that uninstalls the old version of AnyConnect and modified it, but it broke something and didn't uninstall. I gave myself admin rights and just ran the uninstallers for both the client and the dart agent. Verified all other files were gone including in the /Jamf folder. Now when I try to install the old version which we use in our current deployment, it doesn't install, but the policy log says it was successful. It does install the /opt/anyconnect folder, but not all the compon
Hello all, I'm puzzled as to why the option to share a note in the Notes app or an image in the Preview app via Messages isn't showing up (see image below). From what I understand, these sharing options can't be disabled on a Mac, so my guess is that something in JAMF may be restricting it. We simply want users to be able to share notes by clicking the box with arrow and selecting Messages. We've checked our restrictions, and there don't appear to be any in place, so it shouldn't be that. Any help would be greatly appreciated.
I have this need.I would like that during the enrollment phase, if a user belongs to a certain list, he is added to a static group.I don't know if there is something similar or a different and simpler approach for my need.Basically I have 100 users with an Office 365 license and I would like that only those entitled to be able to install the available software on self-service.In my imagination the ideal script should do this:an enroll policy that checks whether the email address present in the user & location section is contained in a specific file on Google Sheet.I use something similar to rename Macs, this script actually downloads the .csv file locally (with serial and asset name) and writes it to jamf pro with the -fromfile function (bash).While in my case I should probably use the API to write to the static group.Any suggestions or help would be greatly appreciated. Obviously I also accept different approaches, which however are not manual (at the moment I check each enroll vi
I'm following this page and trying to get the MDM commands, but when I use a JSS account on myaccount.jamfcloud.com/api/doc/#/mdm/get_v2_mdm_commands I get a 400 returned, and when I use an API account I get a 401 returned. The full URL for CURL/Postman is: https://{myaccount}.jamfcloud.com/api/v2/mdm/commands?page=0&page-size=100&sort=dateSent%3Aasc *EDIT* I realized I missed the "filter" field and it's working now.
In a recent deployment of the SecureConnector, we are discovering a large number of systems generating errors after the SecureConnector deployment. It is suspected the process is being spawned twice. Our install policy is very generic without any custom configurations. Has anyone experienced similar behavior or found a resolution? 6/29/15 9:16:46.339 PM sshd[22462]: error: Bind to port 2201 on 127.0.0.1 failed: Address already in use.6/29/15 9:16:46.340 PM sshd[22462]: fatal: Cannot bind any address.
Hello! I am a student at a school, so I'm not sure how much help the Jamf community will give me but my school laptop's Jamf sometimes will stop blocking apps that are meant to be blocked, e.g. Terminal, Activity Monitor, App Store, Messages and Facetime. I am not sure why it seemingly at random sometimes stops blocking apps. My school had an issue similar to this 2 years ago where after a few days without a restart or shutdown, it would stop restricting apps but that was fixed. It seems something similar happened 2 days ago to me. Late yesterday my jamf was finally fixed via a periodic MDM profile refresh. I am not asking for a way to do this as I do not plan to do this as I follow the rules that are set but I am intrigued by how my school's IT could fix it and if it is fixable so I can forward them the issue and the fix for it.
Hello Jamf Nation, Seeking for advice from people using cloud instance of Jamf Pro with Google Could Identity Provider. We are moving from local LDAP server to Cloud IdPs (Google). We've configured Google LDAPS connection in Jamf Pro settings - everything seems to be OK so far. The question is - how users, after they imported into Jamf from Google during enrolment, will be updated? If they change department or position in Google LDAPS - I believe Jamf will not sync them automatically. Previously we could access our database directly, but now it's also going to the cloud (we migrating from on-premises as well). Is the only option - updating them via API calls? Thanks!
Hey all. getting ready to move LAPS into our system. what are the best steps to incorporate with already managed macs?
Is there an updated script to install Google Drive? I have been trying to deploy Google Drive via Self Service using the package installer. 9/10 times it fails, whereas installing Google Chrome with a script works every time. I would like to do this with Google Drive. I have seen a few scripts out there, but they are many years old.
Please clarify the doubt. Let's say I'm managing 50 mac devices manually. Then my organization wants to manage those mac devices through Intune and organization don't want to do Factory reset. So, solution would be Account driven enrollment. In these 50 mac devices, end users using their personal iCloud id's.If they initiate the account driven enrollment, will they get a prompt to sign out from iCloud account and login with managed apple id's? Or what's the process of it. Kindly explain. Thanks.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server: Security Issues Jamf provides the CVE-ID for security issues with high or critical severity when possible. [PI119913] Updated a third-party library to resolve a known vulnerability (CVE-2023-45857). [PI121204] Resolved a "Credentials Management Error" for some SMTP server configurations. Jamf Pro Server [PI121197] Jamf Pro upgrades no longer fail due to issues during the font migration process if a database table contains null values. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 11.10.1 based on your hosted d
For several years now, Apple has highlighted the important role that partners and Admins play in testing beta versions of their upcoming operating systems and submitting feedback for any issues that can (and do, particularly in the early versions) appear. They also provide some great tools that make it easy for this to be done, but those tools are only half of the story. The other half is an effective testing strategy that, when executed properly, will both provide Apple’s engineers with invaluable data for resolving unforeseen issues prior to public release and also give you ample opportunity to ensure your readiness (and confidence!) to deploy the latest OS version upon public release. This benefits your organisation and users alike by offering the latest software features to enhance workflows and maintaining security standards across your Apple fleet. This post aims to provide an overview of the tools Apple provides to Admins for beta testing at scale, as well as highlighting best p
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!