Get Support
Recently active
Hello guys,I would like to set a password to pass the prestage enrollement page. I can't find anything on this topic. Do you have any ideas? Thanks.
This happened across our org with no changes in azure or JAMF pro. Unsure of what is causing the issue. We've never had to set up a configuration profile for OneDrive prior to this.Has anyone seen this before?
Hi All,We use iPads with our TK-2nd grade students. We are coming across an issue where they have lots of Safari tabs open. A co-worker found one with over 100 tabs open. Is there a way to have these close after so many days? I know it can be done manually on each device but we have over 2000 devices out and that would be insane to try and take care of individually.Thanks!
I've tried importing the CSV file using the updated MUT format, however it isn't transferring to JAMF.
Hello all, I've been having quite a frustrating time trying to re-enroll one of our iPads to Jamf Pro recently and I feel like I've run out of thing to try so I'm hoping someone can lead me in the right direction or inspire a new way to try and get this thing running again. Heres whats going on and ill try to keep it brief:- iPad at our organization was having trouble opening multiple apps (select app, would come up for a moment and crash).- Tried multiple things to fix but no luck so I resorted to un-enrolling the device, wiping it and start from scratch. - Tried to re-enroll the iPad via Apple Configurator 2 and have run into multiple errors Provisional enrollment failed. [MCCloudConfigErrorDomain - 0x80EF(33007)] being the most common.- I've managed to re-enroll the iPad on our ASM but I'm hit with other errors now: "The configuration for your iPad could not be downloaded from organization ... cancelled" or in some cases a popup stating the iPad is not "supervise
I am just now starting to deploy mobile devices so forgive me for any lack of basic knowledge. I am assigning users in my domain a Managed Apple ID so we can manage and regulate purchases and such. But my users have reported not being able to use the AppStore. I read online this is not allowed for Managed Apple ID's. Am I going about this wrong because at this point I don't think I even need to use them as I can do most of everything in Jamf. Wipe, release activation locks etc. Should I just drop them and use personal ID's? My ORG wants managed for purchases. Am I going about this incorrectly? Any advice is welcomed and thanks in advance. Also, JNUC 19 around the corner!!
At present I am facing difficulties in deploying packages using Jamf Pro and I'm unsure of where I might be making mistakes. If anyone has experience with this and could provide some insight, I would greatly appreciate it.
Good morning,I hope you can help me, I know it is possible to block YouTube on Safari using the blacklist settings to block the site (YouTube). The problem is that we have some teachers who use Google Classroom and who send some links (Youtube) so the students can do their work.The problem starts there, YouTube being blocked, it is not possible to open the links that teachers send to YouTube, does anyone know a solution for this?Make it possible to just open the links that the teachers send.This is happening with iPad profiles.Thank you very much
A quick-and-dirty Jamf Pro Policy hack for testing Microsoft_Office_Reset_2.0.0.pkg Introduction Office-Reset is a free downloadable tool from @pbowden that Mac Admins can use to fix problems and errors encountered with Microsoft Office for Mac apps and version 2.0 Beta 1 includes more than two dozen changes. The following quick-and-dirty hack will allow Jamf Pro admins to easy deploy the entire Microsoft_Office_Reset_2.0.0.pkg during the beta phase before the app-specific .PKGs are available. Continue reading …
Hi AllDoes anyone know how I could create a group to filter out and display iPads that do not have an app installed? For example, because one or the other iPad was offline during distribution or does not communicate with the Jamf.Thanks Peter
Hello, During Auto Device Enrollment the users local accounts are created using either E# (employee) or LC# (contractor). On occasion we have LC's come on as employees and switch from LC# to E#. So, the local user account stays as LC# and then all sorts of issues start to occur on the Mac. In the past we have just wiped the mac and enrolled it again so it grabs their new E# account and leaves no trace of the LC#.If I recall I've been told that running "sudo profiles renew -type enrollment" should fix it but I have not had that work for me.Is there some way we can get the local user account to change from LC# to E# without erasing the Mac? PS. I do go into our jamf instance and change the account there from LC# to E# by searching in our user database in jamf but this obviously does not correct the issue on the Mac.
I am currently experiencing issues with our Shared iPads. In Shared Mode, it is no longer possible to log in with a guest account. The button and the option on the lock screen no longer appear. This affects both previously configured iPads and newly set up devices.I found a temporary solution by enabling "Allow only temporary sessions" in the Shared profile. However, this prevents users from signing in with an Apple ID, which limits the usefulness of this fix.Initially, we suspected the issue was related to the iOS 18 update. However, the same problem occurs on iPads running iOS versions 17.5.1 and 17.6.1, indicating that the issue is not specific to iOS 18.
Greetings!I currently work at a school which manages students' iPads through Jamf School, which works really well in most cases.We have configured a dynamic group whose member scope is based on a region which is determined by the school's public IP which is fixed. In most cases this setup works flawlessly.However, with some devices this does not work, which means that upon returning home and even rebooting their devices students' iPads are still treated as if they were on campus. I can only undo this by manually refreshing the device status/network details. Even when the iPads receive a new IP, Gateway etc. from their home dhcp server, the public IP is unaltered and thus the restriction profile is not removed. This can not be explained by a flawed configuration of the private networks either, since in case of siblings one iPad uninstalls the restriction profile as expected, whereas the other does not.This also "works" the other way around: When students arrive on campus and connect to
Can someone explain why the Device Inventory user interface in Jamf School has changed from the previous (legacy) version? I see from this post on Jamf Nation: This change doesn’t just offer a new look but improved speed when loading devices. For schools with large deployments, this means you can manage your Apple devices in an even faster and improved manner with quicker loading and bulk commands. We manage almost 5200 iPads, and while I’ve noticed more success with bulk operations, the need to constantly deselect before selecting a new set of 500 iPads is time-consuming. I would prefer a slower interface if it meant avoiding accidental bulk operations. For instance, I accidentally erased 20 Apple TVs before fully understanding the new system. There have also been instances where I refreshed unintended devices because I forgot to deselect them. I appreciate that the new interface shows the storage of each iPad, not just the remaining storage (though this feature works inconsiste
I have completed the vpp configuration of the app and put it in selfservice. The problem is that some ipads will prompt when downloading: the certificate of the App "com.apple.Keynote" cannot be found. As a result, normal installation cannot be achievedHow can I do next.
HelloI am having an issue getting Nudge to prompt for an update.I have installed the configuration profile & the latest nudge suite via policy to a test mac.The only 2 values i have set are requiredMinimumOSVersion & requiredInstallationDateI've confirmed that nudge can see the profile by running /Applications/Utilities/Nudge.app/Contents/MacOS/Nudge -print-profile-config<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>osVersionRequirements</key><array><dict><key>requiredMinimumOSVersion</key><string>15</string></dict><dict><key>requiredInstallationDate</key><string>2024-09-25T00:00:00Z</string></dict></array></dict></plist>But, if i check library/preferences and look at the nudge plist via xcodeIt does not have the same values
I have a simple content filtering configuration profile we use for ipads that is failing now with "permission denied" Any thoughts?
I'm an instructional coach trying to support teachers with using JAMF teacher more in their classrooms. I was hoping I could create lessons and then share them with teachers to take some of the time off their plate. Is there a way to do this? I can't seem to find a way, but maybe I'm missing something!
I'm getting the following error when running my script "[student: command not found/Library/Application Support/JAMF/tmp/student profile". The script checks to see who is lpgged in, and if it is "student" it needs to change the user's profile pic". script below:"#!/bin/sh# determines current userconsoleUser=$( /usr/bin/stat -f%Su /dev/console )if [$consoleUser == "student"]; thendscl . create /Users/$consoleUser Picture "/Users/Shared/THS_Files/images/Howie.png"fiif [$consoleUser == "howardstudent"]; thendscl . create /Users/$consoleUser Picture "/Users/Shared/THS_Files/images/Howie.png"fi"
I'm trying to re-enroll a device that has not checked in for some time due to the MDM Profile expiring on the device. we've tried to do a sudo jamf recon and get the following:Retrieving inventory preferences from (jamfserver)... Finding extension attributes... Locating accounts... Locating applications... Locating hard drive information... Searching path: /System/Applications Locating software updates... Locating printers... Searching path: /Applications Locating hardware information (macOS 13.6.0)... Submitting data to (jamf server)... There was an error. Invalid Message - The message could not be parsed.Looking at the log we are seeing:[ERROR] [502:CPPrefPaneExt] [CE] Profile installation (MDM Profile (00000000-0000-0000-A000-4A414D460003:00000000-0000-0000-A000-4A414D460003)) ==> New profile does not meet criteria to replace existing profile. <CPFAccess:102>Jamf is telling us that we need to re-image the machine, but it's really not acceptable for this u
Hi all, so, pretty new to Jamf, but I work at a school where lots of random softwares are used frequently in specific labs. One software we're using is OpenToonz, an animation software, and a FFmpeg plug in, which I have to point to a file path for OpenToonz to find the folder for. Problem is, this preference file is stored in /Applications/OpenToonz/OpenToonz_stuff/profiles/layouts, and generates a folder called "settings.usernamehere" So, I can create the preferences file and move it to a specific path on scoped computers, but what I can't seem to figure out is how to create a file based off the name of the current logged in user, and place it in that specific file path. (i.e settings.currentLoggedInUser) I assume a script is the way to go, but my googling has failed me this time around, and I'm a little out of my depth. Either way, appreciate any help you can give!
HiI've set up sso connections to connect each time the mac is restarted.In my case, users always connect by sso. But I want users to be able to switch macs easily between each other.Except that once user A lends his Mac to user B, even if I've forced all connections to go through sso. it will ask me for user A password because filevault needs to unlock the disk before proposing a connection by sso.Do you have any idea how I can work filefault and sso together so that user B can connect without requiring user A password?Thanks
Small shop so there not much need to automate much but to Rename laptops we've been editing them in Jamf Pro and then running a Policy that connects script: !/bin/bash ComputerName="$4"scutil --set HostName $ComputerNamescutil --set LocalHostName $ComputerNamescutil --set ComputerName $ComputerName To an "App" made available via scoping in Self Service. It works but seems like I'm doubling my workload. I'd like to keep the Self Service app and initiate the naming from it using a script like: !/bin/bash newName=$( osascript -e 'text returned of (display dialog "Enter a new name for your Mac..." default answer "" with title "Name Your Computer" with icon file posix file "/System/Library/CoreServices/Finder.app/Contents/Resources/Finder.icns")' )scutil --set ComputerName "$newName"echo "Setting ComputerName to $newName"exit 0 This 2nd script works if I run it from Terminal on t
Hola, I have an iMac running MacOS Monterey 12.7.6 that I loaded onto Jamf, and I can't get the Jamf Connect Login window to pop up, leaving the default MacOS login screen for local users. The Jamf Connect Login window has no issues loading with any other devices. FileVault is not enabled.I saw this post and tried a couple different things from it but wasn't able to get far: https://community.jamf.com/t5/jamf-connect/jamf-connect-login-window-stopped-displaying-at-boot/m-p/292707I tried to run the command /usr/local/bin/authchanger -reset -jamfconnect but AuthChanger isn't being recognized as a command. I tried to go to /usr/local/bin/ & /usr/local/jamf/bin but neither of them had authchanger there. When I check the Profiles, It looks like Jamf connect Login successfully installed. I also tried making a new Configuration Profile to flip both the DenyLocal and LocalFallback, trying various different combinations, and that didn't help.
Hi I hope you can help, for a long time we have been using a Teamviewer custom branded Host package installer pkg which gets set up after initial enrolment. It goes into a single Teamviewer group and then we change the grouping depending on location in Teamviewer its worked well for us over the years.. We have had a company rebrand and so we updated the first install pkg. Now when the new pkg runs and installs the easy access is activated as intended but the check/tick box is still editable by a standard user whereas before it was locked (greyed out) and only editable by admin. Has anyone been able to work out how to disable the option to untick by a standard user please..This is the current script #!/bin/bashsudo launchctl load /Library/LaunchDaemons/com.teamviewer.teamviewer_service.plistsleep8APITOKEN= Goes herewhile true; doprocess=$(ps aux | grep TeamViewerHost | grep -v grep | wc -l) echo "Process: $process"if [ $process -gt 2 ]; thenecho "Ass
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!