Get Support
Recently active
Hi allFirst post on here, exciting times! So we have a deployment process with Jamf Pro that pushes out an admin account with LAPS enabled. All good there. Except we have a mac that has the account manually created, which is blocking LAPS from effectively working on this specific device when needed. Wondering how clean it is to either change name on this account or delete entirely from Jamf pro without the need to manually intervene on the mac? I dare say this kind of post has occurred before so feel free to direct me there if so. Thanks for the assistance everyone!
has anyone had any success in packaging the iOS simulater from the xcode developer page with any success?
Today we are releasing Jamf Pro 11.10. Highlights include: New Keys for System Extension PayloadJamf Pro includes two new system extension types for computers with macOS 15 or later. In macOS 15, end users can see and disable previously installed managed system extensions (e.g., endpoint security tools) through System Settings or Finder. You can use these new settings (Non-removable system extensions and Non-removable system extensions from UI) to prevent end users from removing these system extensions.If you use Jamf Protect, which runs as a system extension, Jamf strongly recommends configuring this new MDM setting to restrict users from disabling Jamf Protect.Note: This feature is also included in Jamf Pro 11.9.1 or later. App Installers Workflow ImprovementWhen using App Installers to install an app via Self Service, Jamf Pro automatically detects and updates the app regardless of the version installed on a computer in scope. (Previously, unknown versions were not updated.) An un
Is there no way to correctly add AirPrint printers with Jamf Pro? I see that it's exceedingly easy with Jamf School, which we don't have (despite being a school.) It's also exceedingly easy with iOS devices. But for some reason it appears to be impossible for macOS via Jamf Pro.I keep revisiting this over the years, and there's never been any updates.I'm paranoid because LPD is being deprecated and will disappear at some point soon, even though it's been years since the ominous warning showed up.I know that adding it via Terminal technically works, but it always has a generic printer icon. I don't want it to technically work. I would like the printers to have the correct icons associated with the printer name as a visual cue for the students.Am I missing something? Or is this still not fully implemented for Jam Pro for the past who-knows-how-many-years?
please upvote if you agree https://ideas.jamf.com/ideas/JPRO-I-740 the thinking goes like this i want to add Multiple poliucies and profiles to a group, or even a single machine, currently we have to go into each policy and profile to add the mac/group. this request would allow us to select the device, or static/smart group, and then add the policy's/profiles to that group
Hello Nation!Noticed an older Wake on LAN policy that we have here in our Jamf Pro is returning errors. The command that the policy pushes is systemsetup -setwakeonnetworkaccess on and this is the Result of the command:2022-03-25 10:57:04.301 systemsetup[90262:4178974] ### Error:-99 File:/System/Volumes/Data/SWE/macOS/BuildRoots/533514bb11/Library/Caches/com.apple.xbs/Sources/Admin/Admin-911/InternetServices.m Line:379setwakeonnetworkaccess: On My first guess was that the computers that were getting the error may have the setting already enabled, but after unchecking the Wake for Network box in the power settings and redeploying the policy to a device to test, it still returned the same result. When resorting to Google-Fu, outside of using a homebrew pkg or pearl, I mostly saw others use the same command as myself to enable wake on network. Did the newer macOS updates change anything that I am missing that would affect this, or is there any other method that doesn't involve homebr
Hello all, I have run into an odd issue here on two M1 MacBook Airs I'm working on. When proceeding to the Microsoft Azure sign in page for my school district, I get prompted with an error."Invalid Request: Error from request to URL: ,Error: the certificate for this server is invalid. You might be connecting to a server that is pretending to be "login.microsoftonline.com" which could put your confidential information at risk., STATUS: 0" I have checked the MacBooks in Jamf Pro and they have the correct certificates installed. It is also only happening to these 2 devices so I'm not sure what could be causing the inability to sign in through Microsoft Azure.
Anyone in JAMFnation use it? Pros Cons? How bad is it to implement and have you seen any degradation on the Mac's? Thanks in advance.
Trying to configure it in our environment but can not seem to find the configuration profile setting for it. The white papers says:To add suggested Managed Apple ID Default Domains that will display on the login screen, click + Add a domain and enter the domain names. Each school domain must include the top-level domain, such as .com, .edu, .org, and so on:https://learn.jamf.com/en-US/bundle/security-focused-jamf-solution-guide-education/page/Configure_a_Secure_Environment_with_Shared_iPad_Using_Jamf_School.htmlBut this is for Jamf School and we user Jamf Pro Cloud and the corresponding setting do not seem to exist (or I'm just looking in the wrong place. The setting do not seem to show in pre-stage settings or as a configuration profile. Anyone have a clue how to manage this in Jamf Pro?
Afternoon All. Hoping someone can help have been trying to package Maya & Mudbox 2024 for serveral weeks and facing issues I think with the license demon not starting before its get licensed.I get below error from Jamf log connecting to Service failed: reading configuration file /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data failed: open /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data: no such file or directory connecting to Service failed: reading configuration file /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data failed: open /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data: no such file or directoryMy scripting ablity isnt up to much, I think I just need a few lines in my current script to ensure the license demon is running before the license process starts. Can anyone help? Have tried a few scripts on here but keep facin
Build an Configuration Profile for test purpose set home folder to https://www.apple.com Profile is installed but Firefox don't react to it at all.Used the policies.json from here https://github.com/Jamf-Custom-Profile-Schemas/JSON-Schema-for-Jamf-Pro-Applications-and-Settings-MDM-Payload/blob/master/Mozilla/Firefox.jsonFireFox is installed with InstallomatorScreenshot: What am I missing?
Hello,Using JamfNow, I am able to enrol a Mac purchased via Apple business. (i.e. device was automatically inserted into ABM on purchase of device by Apple).I am able to use created blueprint within JamfNow to push the setup to the Mac.I have 1 issue, the status screen for the device says that Activation lock is not activated, when I look on the Mac looking at System Information I can see that activation lock is not activated. I have tried the various combinations of activating Find My on the Mac, deactivating, wiping the Mac, reinstalling. I have gone as far as wiping the Mac by erasing disk and reinstalling OS around 10 times trying the various combinations without luck.I have even have gone as far as removing the Mac from JamfNow and ABM and trying to get activation lock to activate outside of the ABM without success.My understanding is that while a user cannot remove the management profiles, they could wipe the Mac and reinstall using their own Apple ID or if stolen the
Since there's no configuration profile options for the IOS Microsoft Edge browser, I assume the only option I have to do any customization is to add XML to the App Configuration tab within the Edge Mobile app page. Does anyone have or can point me towards official guidance on Edge settings options using this method? Specifically, I am looking to disable Copilot in IOS Edge because it's driving people nuts in certain web-based apps. But it would be nice to have documentation on customizing any number of web browser settings if anyone has any. I've seen some references, but they all appear to apply to MacOS Edge and I need any information on configuration options for IOS Edge. Thanks!
Hey Everyone! We are looking to send out documentation to our fleet on how to enable and use TouchID on their macOS system should they want to. That being said, I am having a hard time determining which macOS systems in our fleet even support it. I am not looking for if it is enabled, disabled, or if fingerprints have been registered just trying to see if the touch sensor technology is even there on some systems in our fleet. Can this be accomplished with an Extension Attribute? If so, can anyone point me in the right direction? I tried like every one of them suggested in this thread but not working on 14.5 Sonoma as an EA or linked to a Smart Group: https://community.jamf.com/t5/jamf-pro/touchid-extension-attribute/m-p/170024 Looking to avoid painstakingly going through each model and looking it up, hah. Thank You!
We woud like to be able to monitor for changes to the sudoers file on Jamf Pro devices, via Jamf Protect.We tried creating a new custom analytic, but it does not seem to work during our testing - no events are logged in the Alerts tab. Anyone know if there is an issue with our setup? It wont let me add a screenshot, so here is the 'predicate' in the Summary tab for the analytic:( $event.isModified == 1 AND $event.path ==[cd] "/private/etc/sudoers" )The 'Event Type' is 'File System Event'
I've run into an issue with using Company Portal to register Macs in Entra for compliance purposes. It SEEMS to be a permissions issue. My admin account can register them, but my Joe Schmoe user account with no privileges can't. What I can't wring out of Microsoft or Jamf is what type of permissions my normal account might need to perform this action. We use Intune, not Jamf, for our mobile device management and we have Windows machines there as well. I can register or enroll all of those devices just fine, in testing. And my Admin account works just fine. Shows the device, compliance syncs over. All the fun bells and whistles. But with my regular account, I get this incredibly generic error when trying to even sign into Company Portal from the Self Service registration workflow... Anyone have any ideas what permissions/privileges our standard accounts might need to register Macs in Entra for compliance?
Is there any application that can be used for the iPad and Macbooks to record the screen as it goes through ADE? I want to be able to use this for training purposes for our staff and IT department to make how-to. I have a bezel but it doesn't allow the ability to record the enrollment screen when enrolling a new device through our prestage.
Can anyone explain why do some computers in Jamf drops the minor Operating System Version.ie. If I have two M3 computers with macOS 14.7.0 build (23H124)One show in Jamf as 14.7 and the other shows as 14.7.0 We have seen this for many minor releases and help in fixing this anomaly would be appreciated as it messes up our reporting.
Hi All, Has anyone got the script enable the migrating local account with cloud identify (Azure), Pleas see link for more information: https://learn.jamf.com/en-US/bundle/jamf-connect-documentation-current/page/Existing_Local_Account_Migrations.html Kind Regards
Hi Jamf Nation, Is there a remote lock script that someone can recommend for a Mac in Jamf Pro that not managed? (Can only be deploy by Jamf Pro)Also is there a script to turn Mac's from unmanaged to Managed in Jamf Pro? Thanks in Advance Nation!
Hey. Im trying to upgrade GoodNotes for Institutions into GoodNotes for Business. There is only an instruction how to install a license key for iPad/iPhone (https://support.goodnotes.com/hc/en-us/articles/7568710302607-Installing-Goodnotes-for-Business-Enterprise-via-Jamf-Pro?source=search&auth_token=eyJhbGciOiJIUzI1NiJ9.eyJhY2NvdW50X2lkIjoyNTM0NzUsInVzZXJfaWQiOjc3MDkxMDA4MjcwMjMsInRpY2tldF9pZCI6MjMzMjk5LCJjaGFubmVsX2lkIjo2MywidHlwZSI6IlNFQVJDSCIsImV4cCI6MTY5NTIyMjU1OX0.MN6d_0tdipaCu0_cJb_fbyPYt1kHRPpY9l69iLvegXo). Does someone know how I can install a license on MacBook via JamfPro?
so a s test with my lab systems i tried to re-enroll it to my admin account in JAMF to see if we can just hand over a system with out a re-images and now it's hung trying to install the JAMF profile will not let me delete the old one or over ride it. how should i have done this.It seem to cause other problem the systems show up in inventory but not when i try to add it to a policy.Any uninstall scripted that i should have used or is re-image the only option?
HI, we need to package Avaya Agent with specify config.xml that has the necessary settings. The Config.xml will need to be placed into User/username/ Library/Preferences/Avaya-Agent/ folder which only gets created after the app is opened the first time after installation. Has anyone had the same scenario and found a workaround / solution. Placing files into an user profile could be done with a postflight script but the folder does not exist yet and has a lot more then just that config.xml that is being created. Thanks in advance
Hello, I need to figure out how to run a policy to check screen saver time settings so we can force a set time if it doesn't match. I'd assume that you could check against a value in the "~/Library/Preferences/com.apple.screensaver.plist" but not sure. Any ideas? I see a lot of older posts floating around about forcing a screen saver time in various ways. I need to check the time first before doing that. Thanks!
HiWe are facing an issue where ex-employees have signed in with personal accounts on icloud on corporate devices. Its been a pain while re-purposing the device where find my mac cannot be removed . I know we can restrict signing in to personal accounds via configuration policy but management dont want to take that route at this point of time . 1. is there a way other than contacting apple support to remove find my mac from the computer while wiping it ?2. if we enable activation lock , will that help to erase or disable find my mac for users Any help would be appreciated, Thanks,
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!