Get Support
Recently active
Hello Mac Admins!Not a shell script expert!! But still managed to achieve this comprehensive script. Give it a shot and let me know how it performs in your environment. As always, feedback is welcome!I’m excited to share a robust, advanced macOS Sequoia upgrade automation script tailored for enterprise environments. This script ensures a seamless upgrade experience by performing pre-upgrade checks, deferral management, Secure Token validation, and notifying users at every step to keep them informed. It has been designed to address common challenges in macOS upgrades and provides full automation with error handling to reduce user friction and IT overhead.This solution leverages JAMF Pro to manage the upgrade workflow and works well for both JAMF Self Service policies and automated deployments#!/bin/bashLOGFILE="/var/log/com.scb.sequoia_update.log"DEFERRAL_FILE="/Library/Preferences/com.scb.sequoia_update_deferral.plist"MAX_DEFERRAL_DAYS=1CURRENT_DATE=$(date +%Y-%m-%d)CURRENT_EPOCH=
I am reaching out to seek your assistance regarding a customized requirement for taking snapshots on Jamf, involving multiple applications bundled as a single package. I would greatly appreciate your guidance and expertise in achieving this.I have been exploring the functionalities of Jamf and its ability to capture snapshots, which I find extremely useful for managing software deployments. However, I have encountered a specific scenario where I would like to create a custom snapshot that includes multiple applications within a single package.Could you please provide me with step-by-step instructions or guidance on how to achieve this? Here are some specific details regarding my requirements:Snapshot Purpose: I would like to capture a snapshot of a specific software configuration that includes multiple applications installed on a macOS device.Multiple Applications: The package I want to create should include several applications, each with its own specific settings and configurations.C
Hi teamI think I already know the answer to this one (cheers Apple for that brick wall) but asking anyway as there are smarter brains at work here than I :)Using Display Link for dock drivers and keen to know if System settings to enable Display Link Manager (And Jamf Remote Assist for that matter) can be scripted as part of the app policy in Jamf Pro?
Hi Jamf community!Wanted to share this with the community and possibly get some input on how else I can block JDK from getting installed. The problem is, JDK uses "Installer" process which makes it really difficult to block that as I dont want to block any other app from being installed. Below are some other methods I've tried so far with the outcomes. 2 things to note:1. All our users are local admins (yes, i know!)2. I do not have Jamf Protect.Code Signature Verification:I attempted to block Oracle JDK installations using code signature verification, focusing on the Team Identifier VB5E2TV963 from a previously installed JDK.Also tried using hash values for both the dmg and the pkg within it. The closest ive come is that it does detect the installer but does nothing to block it. Outcome: I successfully identified the Team Identifier, but my current implementation isn't effectively blocking installations across different paths.Script Development:I created a script located at
For safety and sanity, we'd like to be able to disable this feature on in our fleet. I couldn't find any documentation on a configuration profile payload or policy setting or even a homebrew script to disable this feature. A config profile would obviously be best as it would prevent the users from re-enabling. An ongoing policy that uses either a script or an actual policy payload would be... fine I guess, but less preferred as between recurring checkins the user could do whatever they wanted. Does anyone have any resources on this?
Hi everyone, I'm just putting out feelers to see if anyone knows of any alternatives to Carousel digital signage that are reliable, and bonus points if they use apple tvs as the players. We've been happy with carousel for a few years, but them eliminating the on-prem product while charging SO much more for the cloud product has me thinking about alternatives.
Hello everyone. I am testing Privilege Escalation for the first time with JC; 2.39.0. I want to do a very basic any user can escalate for 30 minutes with no password needed, just need to select a reason. The profile is deploying to the test workstation however the Request escalation is not appearing. Here are the necessary snippets. Any assistance you can give will be greatly appreciated. <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>Appearance</key><dict><key>AlternateBranding</key><true/><key>MenubarIcon</key><string>/usr/local/jamfconnect/cdi-LM@1x.png</string><key>MenubarIconDark</key><string>/usr/local/jamfconnect/cdi-DM@1x.png</string><key>ShowWelcomeWindow</key><false/></dict><key>Cust
hey folks.. For stupid reasons unknown, I've been tasked with disabling the QUIC / HTTP3 protocol in our browsers. I got Chrome disabled no problem, but can't find anything regarding disabling it in Safari. Has anyone done this and can share the way??
I've had MMA setup for a few years now and it mostly works but it's been devices based and I've never had it working based on device/user. For example we have a lab of Macs and we only want MMA available for a particular faculty member and not an option for students. If I scope it to a user it never shows up. We have to scope it based on device but then it's open for all users of that device to have access to using MMA.Maybe it's a setting I have but scoping to a user never works. As for 3rd party, there're apps out there but many are pretty pricey. We need something that's not crazy pricey that can replace MMA and be controlled through JAMF or a cloud service or server.
Hello there, I'm trying to add custom trusted sites to uBlock on Chrome and JAMF is throwing an error saying the PLIST format is incorrect. I'm wondering if any of you have a template for whitelisting domains in uBlock that you'd be able to share. Below is what I'm trying to use that is not working. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>trustedSiteDirectives</key> <string>"trustedSiteDirectives":{"microsoft.com", "adobe.com", "office.com"}</string> </dict> </plist>Thank you in advance
Hello, I did a bit of searching for this answer, but I wasn’t able to find anything as exact as what I’m looking for. I have a 100 something iPad 8th Gen’s. I keep getting told that they will no longer be supported in Jamf Pro around the fall of 2025. This is from someone internally in my company. From what I’m seeing, it’s not necessarily 8th Gen’s that are no longer supported, it is devices that are not able to be updated to a certain iOS.The way I understand it, as long as the device is not older that 4 major iOS versions, then it is supported. So in the Fall of 2025, as long as the device is iOS 16 or higher (assuming iOS 19 comes out), it is still supported. Am I correct on this?
We are preparing to switch from eDirectory to Active Directory. When we enroll devices via eDirectory, the devices are registered with:- username (abcdef#)- full name- email...among other things.We have a lot of manually created accounts in eDirectory for, among other things, shared units and/or non-personal units that lack email addresses.We are in the pipeline to run a script to replace all device usernames with the people's email addresses but the big question is what do we do with the devices that have accounts (manually created) that have no email addressesCan you, for example, set up a new PreStage that you enroll them via again that does not tie them to a user account or are there other options?
Hello, everybody.There's a profile we are supposed to enable outside of school hours. Meaning, everyday when the students leave school until they come back. That includes weekends and holidays, of course.How should we go about doing it? It seems there's an option to do just the opposite of what I need: "don't install this profile during the configured holidays".Thanks in advance.
HelloFirst of all, sorry if this is already solved in some other thread. I have not found it.It turns out that in my son's school they force me to install on his computer the JAMF application to know what he does during school hours. But it so happens that I don't want them to be able to know what my son (or whoever may use the computer) does outside of school hours. I assume that the hours when the application works can be configured in the application. But since they are the ones who install it, and I don't have administrator permissions on it, I can't know if they set it up correctly or not.What options do you recommend me so that this does not happen? I had thought of creating a virtual machine and have them install the application on that machine. Another option I had considered was to install a second operating system on an external hard drive, and outside school hours boot the computer from it. But maybe I am making my life too complicated and there is a simpler option, such as
We are building up a python script that fills the Users (Teachers / Students) into the classes with the jamf api. We are doing good so far but we have trouble updating the User Class or Group assignments. We are using the Documentation on https://school.jamfcloud.com/api/docs/It seems that we can add groups but we want a full upgrade. The user should loose the existing group / class assignments and get the new ones that is in the put. Should we use https://school.jamfcloud.com/api/docs/#api-Users-Update or https://school.jamfcloud.com/api/docs/#api-Classes-Assign_users ?
We have the following set in App Config in Outlook.<dict><key>com.microsoft.outlook.Mail.FocusedInbox</key><false/><key>com.microsoft.outlook.Mail.OrganizeByThreadEnabled</key><false/><key>com.microsoft.outlook.Contacts.LocalSyncEnabled</key><true/></dict> We have confirmed the below works <key>com.microsoft.outlook.Mail.FocusedInbox</key><false/>but the below settings don't work <key>com.microsoft.outlook.Mail.OrganizeByThreadEnabled</key> <false/> <key>com.microsoft.outlook.Contacts.LocalSyncEnabled</key> <true/>
I’m using JAMF to push a script to set defaults for a Sharp BP 70C31 printer with the goals of: Printer sharing off, B&W default Print release on. My command: lpadmin -p SHARP_BP_70C31___Main_Building -L Main_Building -E -v lpd://172.16.17.200/ -P /Library/Printers/PPDs/Contents/Resources/SHARP\\ BP-70C31.PPD.gz -o printer-is-shared=false -o ARCMode=CMBW -o ARPrintRelease=True The first two are working, but print release is not.If I run the command I find the *True value set: lpoptions -p SHARP_BP_70C31___Main_Building -l ARPrintRelease/Print Release: False *True CUPS also shows the value set to on, but the print dialog does not have the Print release checkbox checked. If the jobs afre submitted anyway, the intended print release effect does not happen. What may be going on with this?
The Return to Service app that I put on a group of iPads in June of this year (2024) has worked great. When I launch the app here in October, I saw an error inside a red box:Error 405<NSHTTPURLResponse: 0x3005fc160> {URL: https://OurJSS:8443/api/v2/mdm/commands } {Status Code: 405,...Does anyone have ideas about what might be happening or where I might look to get more info on the problem?Thanks.
Hi, all!Many, more thant 40%, of Norwegian children have their time split living with either parent after a breakup. Both parents should be able to be logged in to their individual Jamf Parent to manage their offsprings device. Today the parents needs to log on/off when the student moves between them. That's an inconvenience.Please help upvote this Idea:https://ideas.jamf.com/ideas/SCH-I-366Tim
Darnit!Back to the books!
I've got multiple developers who are having an issue where when connected to Cisco VPN User Tunnel, they are not able to connect to a USB connected iPhone in Xcode. When not connected to Cisco VPN User Tunnel, the developers are able to access the USB connected phone without issue.
Hey there! I have a problem where, randomly, the downloads from App Store are not working anymore. For example, I am trying to install 2 devices. Same OS. Word will install on one, and the other one says "AppStore request (submitVPPRequest) timed out". It does not make sense to me.
Battery capacity under Hardware section shows 1% in Jamf Pro 11 (not sure if this issue existed prior).When I look in System Information, it's at 94%.
Hi all,after the update to OS18, students can no longer receive files via airdrop on managed devices. They can, however, still send. And it does not seem to be a general OS18 issue. Anyone else have this issue?
We have set up Single Sign-on via Azure, and it works like a charm.However, a couple of weeks ago, an alert popped up that the "Signing Certificate issued by SSO Identity Provider is expiring in .. days".I followed the instructions to "Visit your SSO Identity Provider to update the certificate", and the newly activated certificate is valid until June 2026. But, the alert does not go away. In the SSO settings, we originally linked to a URL for the Identity Provider Metadata Source; and, this URL did not change in Azure when the new certificate was activated. I tried to replace the URL with the updated metadata file, but still no change in the alert. I suspect that the best practice for SSO certificate management involves updating it more than 30 days ahead of the expiration (30 days, being when the alerts started); and, since it progressed to the point of alerting, it can't be undone? Having reached this point, however, I wonder what I can
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!