Get Support
Recently active
I have created a configuration profile using "Application and Custom Setting" Payload with Application domain as "com.microsoft.wdav" where I am enabling "Real-Time Protection" (attached screenshot). When I push this config profile, it enables the "Real-Time Protection" on device and make it restricted (attached screenshot) stating "This setting is managed by the organisation"When I upgrade the macOS to 14.7, suddenly the real time protection setting becomes unrestricted. As far as I know, any application setting managed by JAMF is restrcted by default. Hence, I need you help to understand why the setting is reverted post OS upgrade? And, how can I ensure that real time protection is restricted for user to make the changes?
These unwanted logoffs happen in most cases when I click on the "Refresh" button after uploading PKGs to our Jamf Cloud server (hosted by Jamf).I always use Safari (with a 2-factor auth.) for Jamf tasks, should I change the browser or is it a browser settings thing?
Hello! We are unable to log into any computer that is bound to Active Directory with the mobile account that is created. We've noticed that:- On Jamf, impacted computers will stop checking in.- Computers will flap on the network, that is, they will intermittently lose connection and gain connection.- When we log into a local administrator account, use sudo jamf policy and other commands and log out, the mobile account will be accessible for only a temporary period of time.- AD connection is valid, and all iMacs are in the proper OU. There are no duplicate entries.- All computers are on Sonoma.- We use Crowdstrike, and no alerts have been triggered. Any ideas as to why this may be happening?
Hello! Trying to polish up our Jamf Connect configuration, but I notice upon reboot the Jamf Connect screen doesn't pop up, I have Filevault disabled, and I made it so the authchanger script runs every time the computer logs in. This is the plist file:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>CreateJamfConnectPassword</key><true/><key>CreateNewUserHide</key><true/><key>DemobilizeUsers</key><true/><key>DenyLocal</key><true/><key>DenyLocalExcluded</key><array><string>orgadministrator</string></array><key>EnableFDE</key><false/><key>EnableFDERecoveryKey</key><false/><key>LocalFallback</key><false/><key>LoginWindowMessage</key><string>Welcome to xyz! Please log
Hello,Does anyone know a way to pass through the password from a presage enrollment SSO login to the Exchange ActiveSync settings so the user doesn't need to "Edit Settings"?This would be great, especially with the rollout of iPad OS 18 and them hiding Mail another layer deep in settings. Thanks!
Hi all, I'm a JAMF newbie (and to any kind of Mac administration). I recently completed an engagement with JAMF to assist in setting up JAMF Pro, but JAMF connect was out of scope for the statement of work. The professional services engineer did a great job of explaining what next steps I should need to take to get JAMF connect setup. To get to the point: I created a configuration policy for both JAMF connect and JAMF connect login, targeted to our test Mac - then deployed the JAMF connect app to the Mac but it does not seem to be taking the settings needed to work. The JAMF connect app is also not auto-launching when the system restarts. To get into more detail: I used the JAMF connect configurator to finish setting up the Entra login details. Everything tested successfully. Per the engineer's suggestion, rather than saving the mobile config file, he suggested it's better to save the XML data from the configurator, ten create a configuration policy per each XML. I
I am receiving the "Unhandled exception" error when I attempt to install Apple Classroom on ANY MacBook. This is via VPP. I cannot find anywhere that someone else has had this error for apps. I have already shuffled around licenses to VPP accounts to see if it was a licensing issue.Has anyone else experienced this in their environment and how did you resolve it?
We've been pushing certain iOS apps to our Macs such as Google Authenticator and VCastSender with Jamf. After updating my M1 Mac to macOS 15, I've been unable to open them. I've been getting the "The application xxx.app can't be opened" pop-ups instead. On macOS 14, on occasion you would get these same errors but it was usually rectified by deleting and reinstalling the app through Self Service. This method does not work in Sequoia.
So in a lab setting where students share computers is there a way to automatically allow Wacom tablets in 2023?Not sure why this is so difficult. Is allowing it and getting the user to approve the only way? Really annoying that when the user signs in the Wacom utility pops up and wants interaction. We are new to JAMF and this is one of the main reasons we got it so that we don't have to manually install it on hundreds of Macs.Any insight is appreciated. Did a search here but those threads are not much help.
Please create a Self Service app/web clip that allows user to update inventory from their device.
Hello,When our students graduate we offer the option for them to keep the devices. We wipe and delete them from JAMF when they sign them out during the final days of school. Once we do this if they restore from an iCloud Backup, all of our configuration profiles are added back via the backup without the iPad enrolling back into our MDM server. One profile we have is to deny the ability to factory reset the iPad via Settings. This means the graduated students are unable to reset their device that has pulled its old management controls. The only way to wipe them is to put them in DFU mode and use Apple Configurator 2.Is there a better way to release these devices through smart groups or anyone else noticing this.Thanks!
Hey All!Just a small question, and more like IM wondering if anyone has been able to do this.In our computer lab, we one of the machines connected to two monitors; the monitors are one standard monitor and one projector. Sometimes when we log into the machine as admin and set it so that the left monitor (standard) is the primary one and the projector is the extended, the projector will sometimes take over.In short this then requires either to login while looking at the projector screen, but if it's off, we just yoink the cable out and plug it back in. Honestly, the solution to just unplug the cable is fine, but our lab tech/admin is inquiring if there's a way we can make it easier on folks and keep that monitor as the primary. Is this something that can be set via script or config profile?
We have some users who have long since received a new Mac but for what ever reason they won't return the old Mac. I see in Jamf Pro that they are still using these old Macs and the new ones. We could send a remote lock command to the old Macs but I think that would complicate matters with our remote users. Instead, I want to use Swift Dialog to launch a full screen alert to the users that they need to return the old Mac. The only option that will be provided will be to shut the Mac down. I will include a 60 second timer. When it runs out, the Mac will shut down. I want to use a launch daemon to launch a script that I will install locally on these old Macs. I'm having trouble getting the script to launch using the launch daemon. The script does launch immediately after the launch daemon gets installed and loaded, but it does not launch when the computer is restarted/shut down and then started up again. I see in the error log an entry that says "id: : no such user". It appears that the s
In our Mac fleet are Clients who have Microsft Teams 1.x and 2.x installed. It turned out that "Microsoft Teams (work or school)" in Version 24231.x changed its Name back to "Microsott Teams". Does this mean that it will remove a installed "Microsoft Teams" in Version 1.x ? How does this effect Jamfs Patch Management for Microsoft Teams?
When I create document in Microsoft word document in mac and try to save it, it gives me options to save data to local storage, OneDrive and additionally it shows 'Manage Storage accounts'Manage Storage accounts >> shows OneDrive, Dropbox, Box, Egnyte, ShareFile, iManage online storage account options.Can we disable all these options via PPPC file/script/Config policy? anybody faced this issue?
We're currently working on bringing macOS users that are on version 13 to macOS 14. We want to restrict users from upgrading on their own to macOS 15 until it is fully vetted out. The question here is, if we were to enable this would it also impact our users that are trying to get to version 14 from lower versions?
Hello, I'm trying to get into the App Installers settings page -- Settings -> Computer Management -> App InstallersBut each time I go there I get a '404 Page Not Found' message.Is it not available because we are hosting jamf on our premises? or is there something else wrong?We our Jamf Pro version is 11.9.1-t1726060704
I'm trying to find out if it's possible to retrieve Apple Push Notification emails from the Jamf database. We're unsure about the specific Apple ID that was used for the APNs, and we need to figure out if there's a way to locate this information.
I'm relatively new to using JAMF and I've looking around at the community posts but I haven't found an existing post that answers this. I'm trying to create a search criteria using the Extension Attribute function which would work for an Advanced Computer Search that'd allow me to check if a Local User Account on a MacBook has admin rights or not.When I check an individual device I can see a field under Local User Accounts that has a Yes or No to indicate if the local account has admin rights or not but I'm not having any luck with trying to create a filter for this so I can see which devices have admin accounts.Any assistance with this would be appreciated.
Hi, I am trying to install Cisco Any Connect through jamf pro and facing a weird situation here , the logs of policies and configuration profiles show successfully installed but the app is not found anywhere on the laptop . i am sharing the install.log here for reference ""./postinstall" in /private/tmp/PKInstallSandbox.GRMsQD/Scripts/anyconnect-4.10.5cspVc2023-11-17 11:08:12-05 MacBook-Pro package_script_service[1309]: PackageKit: Preparing to execute script "postinstall" in /tmp/PKInstallSandbox.GRMsQD/Scripts/anyconnect-4.10.5cspVc2023-11-17 11:08:12-05 MacBook-Pro package_script_service[1309]: Set responsibility to pid: 1174, responsible_path: /System/Applications/Utilities/Terminal.app/Contents/MacOS/Terminal2023-11-17 11:08:12-05 MacBook-Pro package_script_service[1309]: PackageKit: Executing script "postinstall" in /tmp/PKInstallSandbox.GRMsQD/Scripts/anyconnect-4.10.5cspVc2023-11-17 11:08:12-05 MacBook-Pro installer[2294]: PFPkg: No file found at path: /private/tmp/An
Hi Jamf Team, I am encountering an issue with a script that I am using in a Jamf extension attribute. The script is not returning output always “No_Certificate_Found” when processed through Jamf. I need assistance to validate the issue and understand why it is not picking up the results properly. When I trigger an inventory update through Jamf's built-in functun, no results are returned. However, when I manually run the command via Jamf using “sudo jamf recon”, I am able to retrieve the expected results. Similarly, the script works when executed via Self Service. It seems that the script is not functioning properly when built in inventory option is enabled and not running as user in Jamf. Could you please assit this issue? I have attached the script. Thank you for your assistance. #!/bin/bash # Expiry Date | Certificate Name | SHA-256 Hash | Keychain Path #20-Jan-2024 | Manikandan R | 40C6326E5B3458F07A1D2E4DDBEF59728A425C92612FA022263C73BA51FEB8E | "/Users/test/Library/K
Hi all, Starting a few weeks ago, our Google Chrome pkg has been failing. It's strange, it's a simple policy, it's been working for years. I even created a new policy and downloaded the newest package from Google. The policy log says it's installed successfully on the MacBook. It even logs an appropriate amount of time in the policy log. But the app does not get added to the application folder. Anyone have an ideas or ways to diagnose this?
One thing that wasn't made clear before we purchased Jamf Connect is that according to the guide (and so far, from our testing) that in order to use Jamf Connect AND FileVault there's essentially at least 3 login prompts. 4 if you include an MFA prompt.https://docs.jamf.com/jamf-connect/2.1.3/administrator-guide/FileVault_Enablement_with_Jamf_Connect.htmlIs there any way around this? We need to have our Macs encrypted, but 3 prompts for password is quite excessive.
After the prestage enrollment process, is there a method to utilize the SecureToken or Mobile account user for escrow?
We have been trying to track how big of an issue iCPR is (scope-wise), but have not been able to get an extension attribute working properly to show who has it on. How are you all handling this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!