Get Support
Recently active
Hi there, i had a message that our push-certificat will run out in 1 month. I probably made a mistake while renewing this cert. I generated a complete new one and now i cannot push to existing computers anymore. sudo profiles renew -type enrollment Registration with the administration server has failed.The update to an MDM profile contains another push topic What can i do? Frank
It would be nice to have a "notes" section in static device groups so I could add info like classroom locations and current teachers (i.e. these 20 ipads are spread across 5 classrooms 4 ipad each room). I could make individual static groups per room, but that seems like a lot of hassle with teachers/classrooms changing and moving. How do you guys keep track of ipad locations?
Does anyone have a script to use an EA to report on the Expiration date of the JAMF connect license or where this can be viewed on the device?
I am trying to create an API Role that has full access. Is there a way to do this without having to click every single privilege in the list? Am I missing something? Thank you for your help!
I'm wanting to enable the "Defer Updates of software updates" to block Sonoma when it comes out, but we don't have an outstanding Restrictions profile in place.So take this screenshot from below. This is some of the default things ticked/unticked etc in a Restrictions profile.So. if i JUST want to have the restrictions for defering software updates.....should i leave the existing options enabled....or....untick them all?I just don't want to push out a restrictions profile, and then block a load of things that perviously were allowed.Thanks
Hello all,We want to host caching servers in each site, and we've run into a few roadblocks in this area.The main one, is we want to tell the computers to only use the cache on the servers, and not cache locally. We could not find such an option.Another issue, we think we solved, was the fact the actual server had to be excluded from the policy that distributes the caching profile in order to configure it differently. Can anyone share their experience with caching servers? We just want all macs under the same public IP to reach the server that's on that site.
Is there a way to get a list of all installed software from the JSS? What I am looking for is a list of every installed application in our environment.
During integration of Jamf Pro with Entra, a Global Administrator account is needed and this account must exist on the Entra tenant. Often, we use the same account to set up the app registrations for Jamf Connect and to create the various changes for conditional access exemptions, etc. Once these are set up, can this Global Administrator account be safely removed from Entra without affecting any of the integrations or applications created?
Well I am not sure this is even possible to do, but here goes...Update Macs to OSX 12.3, and Google Meet screensharing has broken.I have a PPPC configuration set up to allow non admins to be able to authorise screensharing, all they have to do is go there and click the tickbox.The fix for the issue is...Uninstall google Chrome.Remove Google Chrome from the list in the System Preferences>Privacy>ScreenSharing.Reinstall Google ChromeAdd Google chrome back in to the list for ScreenSharing. Ok I can script finding all of the Chrome stuff and remove that. But how on earth do I go about removing it from the ScreenSharing list.I have around 400 Macs with possibly 2000 different accounts spread across multiple campuses, up to 80 miles apart. So the manual method of going to each mac in turn is not going to happen. Does removing it as the Administrator on each Mac, remove it for all users on each Mac? If so is there any way possible to script that? Any help will be greatly
Random question, but is it possible or are there any scripts out there that could report on Hardware issues? * Display issues/cracked screens (number of nits) * Overheating * Fan Issues etc
I'm attempting to create a configuration profile for GlobalProtect so that users don't have to enter the vpn server address. When testing the following which was added to a configuration profile in Jamf, it still prompts. Any ideas? And, yes, I have our real address in the one I'm using. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Palo Alto Networks</key> <dict> <key>GlobalProtect</key> <dict> <key>PanSetup</key> <dict> <key>Portal</key> <string>vpn.server.edu</string> <key>Prelogon</key> <string>0</string> </dict> </dict>
Hello, I am trying to uninstall iMovie on managed devices. We initially pushed the app through a policy for some reason I do not remember. Since iMovie is asking users to sign into apple id in order to update to the latest version it is not working since we restrict the app store and apple id. We now want to push the iMovie app through the JAMF pro app catalog to make it easier to update. I tried pushing the app through the jamf catalog with the app already installed but it does not seem to download the latest version and remains at the version installed from the policy. What would be the best way to uninstall the app that was pushed through a policy?
I was able to get some phenomenal help from @sdagley and @rayjd1650 on this before, but cannot seem to find any keys for disabling the crash reports. I have dug through the Crash Reporter docs and the policy-templates, but am unable to find a key to disable this feature. If anyone knows a solution, I'd love to read it. Thank you in advance
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issue: Jamf Pro Server [PI121695] Functionality for viewing computer inventory information in the General pane of the Jamf Pro interface and retrieving inventory information for certain endpoints in the Jamf Pro API, including App Installers endpoints, has been restored. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. If you would like to upgrade manually, navigate to https://account.jamf.com/produ
We generally restrict student ipads to not allow Airdrop. We use a Static Device Group exemption to allow it for a select few students who use it to share app data with their teacher. Everything was working well until we started to update the student ipads to iOS17.x. Teacher ipads, even ones on iOS17.x can still Airdrop. Student ipads, once on iOS17, can Airdrop to the teacher ipad, but the teacher ipad can't Airdrop back to the same student ipad. How do I find the setting that needs to be changed?
How would I force install this extension? https://microsoftedge.microsoft.com/addons/detail/jbkfoedolllekgbhcbcoahefnbanhhlh And also set my self-hosted server URL? https://bitwarden.com/help/configure-clients-selfhost/#tab-macos-55MXwgIamulyigoLoAbLMo An example plist would be much appreciated. Thank you in advance.
Has anyone else had their FileVault key rotated since updating to Sequoia?It's happened on 2 test machines we've updated from Sonoma to Sequoia (both ARM).The personal recovery key then doesn't escrow to Jamf and becomes invalid.Checking in to see if anyone else is seeing this before we roll out any further.
We were told that Jamf Connect is basically NoMAD rebranded (sales agent's words not mine) so I assumed it'll work exactly like NoMAD. We used NoMAD in the past to authenticate to local AD and access to file shares was not a problem. With it now becoming unsupported, we decided to look at Jamf Connect. Now, we're trialling Jamf Connect and for the life of me, I can't get it to authenticate to file shares. I suspect that it is passing incorrect credentials (i.e. just the ShortName value) because when I connect using Finder to an SMB share, if I use the default entry, it fails but when I add the AD domain part (@domain.local), it goes through. So now I have 2 problems: 1. Some of our users will have a ShortName value of firstname.lastname (they auth to Entra ID using firstname.lastname@external.domain.com). How can I change this so that it uses the sAMAccountname? I've read that you can pass additional attributes but have not seen an example of how to properly do this
We have two Jamf Pro instances in use; one is a test environment and the other is our production environment.Over the course of the last couple of years both instances might have entries the other one does not have.At the moment I'm preparing a project to overhaul our instances so that our production server resembles our test server (as much as possible).Do you know of any tools/tips to compare both servers? Ideally it generates some sort of report with found differences.Any tips are much appreciated.
As a rookie question, I wondered how you'd either make a directory or move contents of old folder to another - as a user. I know policies run as root but if I want it to do something in the users directory - how would I execute that? Getting the user, I can do: curUser=$( stat -f%Su /dev/console ) If I want to run something like "mkdir foo" shouldn't it be something like: su - "$curUser" -c 'mkdir "/Users/$curUser/foo"' Although I try that as a policy for my own computer and it doesn't do anything. The goal being to put the contents of one directory in another so their old data isn't overwritten
I am attempting to get a policy working which is able to run minor Adobe updates in our environment using Adobe's Remote Update Manager, and after a lot of tinkering I am making progress but am once again stuck.Logs from my script:Script result: Creative Cloud app located; proceeding ... Starting Adobe RemoteUpdateManger... RemoteUpdateManager version is : 2.6.0.9 Starting the RemoteUpdateManager... ************************************************** No new updates are available for Acrobat/Reader ************************************************** Following Updates are applicable on the system : (KBRG/12.0.3.270/osx10-64) (AEFT/22.6.0.64/macuniversal) (FLPR/22.0.8.217/osx10-64) (AICY/17.4.0.051/macuniversal) (IDSN/17.4.0.051/macuniversal) (AUDT/22.6.0.66/macuniversal) (PRLD/22.6.0.6/osx10-64) ************************************************** Following Updates are to be downloaded : (KBRG/12.0.3.270/osx10-64) (AEFT/22.6.0.64/macuniversal) (FLPR/22.0.8.217/osx10-64)
Hey everybody, I'm looking to see if someone can point me in the right direction. I spent 14 years doing Apple Service, mostly in/out of warranty repairs and setups for customer's homes and office. None of that was JAMF related and I am now working at a company doing support for the corporate office that is mainly Windows but anything Mac related falls on me. It was the CIO's idea to get someone with macOS knowledge. I have been there for about a year now and just a couple weeks ago was given an Auditor Role. In the past year mac support has prob taken up about 15% of my time. The CIO loves AI and theyre working on implementing CoPilot for everyone eventually and it works just fine on Windows. He messaged me the other day because CoPilot is not working on one of his 2 macs and I told him I don't have a Copilot License to troubleshoot it and he got me license within a few minutes (yay :-/). On my mac and his, Copilot works in Teams, Appears in Excel, and Powerpoint but does not produce
The last week we are getting reports that people are loosing the Self Service app on there Macs.Anybody in the same situation? We're in the cloud with version 11.10.1.
Hi everyone, according to a notification in my Jamf account page I should be able to see the "Jamf Product Roadmap" option as described here: https://learn.jamf.com/en-US/bundle/jamf-account-documentation/page/Help_and_Resources_in_Jamf_Account.html#ariaid-title2 I'm not seeing it though, do others do? here's what I see:
I updated a IOS iPad Pro to version 18 and now I can't view VPN and Device Management to look at my MDM enrollment information. I can't seem to find anything that would gray this out in my Jamf Pro Configs. Mind you, in version 17.x I do not have this problem with any of my enrolled devices. I will also point out that when it is missing TV Provider is listed 2 times in the General section and both are greyed out. When VPN and Device Management is listed and grayed out TV Provider is listed 1 time above this. This is oblivious a bug in iOS 18 or Jamf Pro. Any help is appreciated.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!