Get Support
Recently active
Hello everyone and I hope you are doing well!Was just curious if there is a Timeout Function for the Jamf Setup App that is currently being used for shared iPads. For example, if there is a shared iPad that is currently logged into using Jamf Setup and it hasn't been used in 20-30 minutes. Is there a way for a timeout to kick in and so the system would notice and execute "This iPad hasn't been used in 30 minutes, so we are going to auto logout the currently signed in user since they are most likely not using this device anymore." Let me know if there's any other details I can provide.Thank you so much and I hope you have a nice day!
Any orgs out there leveraging WiFi only iPhones that are shared between on-campus staff and ALSO trying to implement device level PIN (unique per user) enforcement in tandem with Jamf Setup + Jamf Reset (Soft reset) Wanted to try to see if other organizations have anything similar and what experiences you all have with this. We are moving away from Imprivata Ground Control (Mobile Access Mgr) to due the sheer cost and inconsistencies with reliance on phone cases + docks + host machines. Aiming to have all workflows handled OTA (Over The Air).We have noticed that if staff forget to soft reset a phone using Jamf Reset that it puts a rather large burden on other clinical staff and/or IT Support staff to wipe / reprovision and setup the devices again.Appreciate your time and shared experiences! We are looking at Jamf Return to Service as a replacement to Jamf Reset, but that requires all devices to be iOS 17+ compatible, which we aren't quite there yet. This still wouldn't solve for the is
Hi Everyone,Currently, I am having issues with printing to Ricoh printers in our schools with macs running on both Big Sur and Monterey. Whenever certain students or staff print, they get the following error:ERROR : invalidfont OFFENDING COMMAND : show STACK: (!)I have managed to find a workaround with a change to the Rasterizer in the PPD files of the print drivers, by running the below script:#!/bin/sh cd /etc/cups/ppd find ./ -type f -exec sed -i '' -e "s/TTRasterizer: Type42/TTRasterizer: None/" {} ;However, any mac that I run it on throws the following error:find: -exec: no terminating ";" or "+"If anyone has any input on this, I would appreciate it! If you have any other questions, please let me know!
If the Apple Silicon Mac computers can not be enrolled through PreStage Enrollment, the Recovery Lock can only be set from remote command, here's how to do it in Jamf API. 1. First, we need to know the managementId of the target computer. we can copy it from computer‘s inventory. (Jamf Pro Server 10.50.0 and above) 2. Open the Jamf Pro Server API page (https://yourInstance.jamfcloud.com/api, or https://yourjss.domain.com:8443/api) , and choose Jamf Pro API PRODUCTION View. 3. Navigate to "MDM", and choose "POST /v2/mdm/commands", then click "Try it now". 4. Modify the request json body. Input the managementId and the recovery lock password. Set to empty ("") will remove the recovery lock password, set to a different one from previous can RESET the existed recovery lock passcode directly. (PS: Firmware/EFI passcode cannot be reset, must be removed and then set a new passcode.) (copy paste and modify it) { "clientData": [ { "managementId": "6c1c6fd
Hello everyone,I'm a new Mac JAMF admin at my organization and first time poster here. First off want to say thanks to the community here, as I've already received lots of help here already perusing the forums with other questions I've had (that have previously been covered). I do have a question as it pertains to firmware / recovery locks as it pertains to M1 Macs.Currently managing a fleet of around 700 Macs. I'll just state what our organization is wanting to have happen and maybe some of you have suggestions that I haven't thought of or found. I have orders from up top to try to lock down MacOS, so employees are unable to wipe it and bypass JAMF. There was some sort of an incident, which has prompted this request. Ultimately if a user is having a problem with their MacOS device, we would like them to bring it to IT for a reimage to ensure the JAMF MDM profile is present. It was my understanding a Firmware password was previously used on Intel Macs but this feature is not pres
Forgive me if this is answered in another discussion - I have seen similar posts, but nothing that gets to the root of what I am trying to accomplish. I am also, unfortunately not versed in BASH scripting, hence the reason for reaching out... I am trying to put together a policy that includes a script to completely remove any installed versions of Oracle JAVA - including multiple JDK versions if found. I am familiar with the official method published here: https://www.java.com/en/download/help/mac_uninstall_java.xml However, if a machine has multiple JDK versions installed, I need a way to detect those and loop through an uninstall command to remove each. Does anyone have a script that will accomplish this? Thanks for any insight that can be provided... Brian
Guys,Since Jamf introduced Compliance Benchmarks which helps admin to manage and report security compliance on macOS. If that's the case, then Intune integration is mainly for conditional access and no need to check for compliance status as Jamf itself let us know the device compliance status. Is my understanding being correct?
Newbie here so sorry if this has been asked ( i already search the forums beforehand and found nothing) We want to create a report in Jamf to detect all versions of Java or any Java App installed. I know other applications it's app name +.app for the value when I create an Application title search, but that didn't work. Assuming since java is added mostly as an extension ( i think). Any help or other links to how it's done would be appreciated! Thanks
After Google announced they would not be allowing basic credentials for SMTP, we are struggling to get the Google OAuth to work. We have followed the steps below and still not have had any luck. It keeps giving us this error but we have tried multiple URLs for the failover and it is not working. Any suggestions?References: SMTP Server IntegrationsPreparing a Google Workspace for Jamf Pro Jamf Pro SMTP Walkthrough
Hello Jamf Nation! The Jamf Pro 11.11.0 Beta Release features Managed Device Attestation, updated Computer and Mobile Device Inventory Reporting and lots more. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions. The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
I have jamfpro allow the camera only in specific specific apps, and disable the camera in the browser and others at all.However, Disabling the camera will also prevent third-party apps from using the camera.How do I deal with this?
we are using jamf connect for account creation for our environment and we are populating accounts from okta ldap and okta is idp.I am able to download and enrol my device with user initiated process but for auto enrolment I am not able to proceed after doing authentication with okta.I can provided crews and I can approve okta prompt for authentication successfully but right after successful authentication the login window on the devices remains as it is and password box goes blank.
In my organization, students are often unaware that they need to release devices from their iCloud accounts. Because of this, we experience a fair amount of Activation Lock Errors. Previously, when using the bypass codes provided for each user in JAMF, they worked consistently. Recently (over the past 6 months) I have noticed that there are an increasing number of codes that are not working ot remove Activation Lock from the devices. Currently I am attempting to contact each of the students with directions on how to release the activation lock, however, they are no longer students of the university, so often times, they are not checking their university email, so a better solution is preferable. Has anyone else experienced this? Whether you have or have not had these same issues, can anyone offer a better solution?
Hi,We issued a new ipad to our speech teacher. She has many apps on her old ipad that we only purchased one license for. How do I transfer the paid license to the new ipad? Will she lose all the data from those apps in the old ipad? Both ipads are managed via JAMF Pro. Any help will be greatly appreciated. Thanks.
Estoy buscando ayuda para dar a los usuarios con perfil estándar en macOS la posibilidad de agregar y eliminar redes Wi-Fi sin que el sistema les solicite la contraseña de administrador, pero limitando este permiso solo a la gestión de redes Wi-Fi.Quisiera saber si alguien ha creado o conoce un script que permita otorgar estos permisos, y que pueda enviarse a los dispositivos a través de políticas en Jamf Pro. Agradecería mucho si alguien pudiera compartir una solución o guiarme en el proceso.¡Gracias de antemano!
Hi We've noticed recently that a reliable script to return jamf ext attributes has stopped working in ventura, somona and sequia.oldPass=$(curl -s -f -u $apiUser:$apiPass -H "Accept: application/xml" $apiURL/JSSResource/computers/udid/$udid/subset/extension_attributes | xpath -e "//extension_attribute[name=$extAttName]" 2>&1 | awk -F'<value>|</value>' '{print $2}' | tail -n +1 ) We used to be able to retrieve the value of an ext attribute with the above but it seems to have broken. i see lots online refering to "xmllint xpath" as a fix but doesn't work in our case, just returns an empty value.
We have been seeing several personal IOS devices being prompted to register or sign in with Jamf Pro registration. Our environment uses Intune for MDM, so this creates several issues, including some configuration profiles with applications and such. These are often phones that we are attempting to register in Intune, as well as the users signing in and registering their device with MS Authenticator.
I have a CIS requirement from our security team that will disable an NFS, HTTP, and FTP server and I'm having a difficult time coming across anything on JAMF Nation or Google searches. Is anyone doing anything like this? Thanks!
Hi there, We are using Jamf School and Jamf Pro. Formerly, we had Jamf Pro, but for some select iPads, are still using Jamf Pro. For this particular app, we have 222 purchased licenses, and I removed about 70+ serial numbers off the scope. Jamf Pro is still saying there are 200 in use, with 22 remaining. I have some pushed to Jamf School MDM iPads. Apple School Manager says the same. There are "22" remaining. It's been that number whether I take off or add. There are more problems I have, but for this question, I am curious why the "In use" amount doesn't change. I tried to transfer some licenses over (because we had a volume purchasing problem). When I tried pushing the app, it would ask me to sign in with an iTunes account so I just put most of the licenses back into the other MDM that works with volume purchasing. Hopefully this makes sense! I took over from our previous Jamf admin so I'm still learning a lot of things and uncovering stuff. Thank
Hello Mac Admins!Not a shell script expert!! But still managed to achieve this comprehensive script. Give it a shot and let me know how it performs in your environment. As always, feedback is welcome!I’m excited to share a robust, advanced macOS Sequoia upgrade automation script tailored for enterprise environments. This script ensures a seamless upgrade experience by performing pre-upgrade checks, deferral management, Secure Token validation, and notifying users at every step to keep them informed. It has been designed to address common challenges in macOS upgrades and provides full automation with error handling to reduce user friction and IT overhead.This solution leverages JAMF Pro to manage the upgrade workflow and works well for both JAMF Self Service policies and automated deployments#!/bin/bashLOGFILE="/var/log/com.scb.sequoia_update.log"DEFERRAL_FILE="/Library/Preferences/com.scb.sequoia_update_deferral.plist"MAX_DEFERRAL_DAYS=1CURRENT_DATE=$(date +%Y-%m-%d)CURRENT_EPOCH=
I am reaching out to seek your assistance regarding a customized requirement for taking snapshots on Jamf, involving multiple applications bundled as a single package. I would greatly appreciate your guidance and expertise in achieving this.I have been exploring the functionalities of Jamf and its ability to capture snapshots, which I find extremely useful for managing software deployments. However, I have encountered a specific scenario where I would like to create a custom snapshot that includes multiple applications within a single package.Could you please provide me with step-by-step instructions or guidance on how to achieve this? Here are some specific details regarding my requirements:Snapshot Purpose: I would like to capture a snapshot of a specific software configuration that includes multiple applications installed on a macOS device.Multiple Applications: The package I want to create should include several applications, each with its own specific settings and configurations.C
Hi teamI think I already know the answer to this one (cheers Apple for that brick wall) but asking anyway as there are smarter brains at work here than I :)Using Display Link for dock drivers and keen to know if System settings to enable Display Link Manager (And Jamf Remote Assist for that matter) can be scripted as part of the app policy in Jamf Pro?
Hi Jamf community!Wanted to share this with the community and possibly get some input on how else I can block JDK from getting installed. The problem is, JDK uses "Installer" process which makes it really difficult to block that as I dont want to block any other app from being installed. Below are some other methods I've tried so far with the outcomes. 2 things to note:1. All our users are local admins (yes, i know!)2. I do not have Jamf Protect.Code Signature Verification:I attempted to block Oracle JDK installations using code signature verification, focusing on the Team Identifier VB5E2TV963 from a previously installed JDK.Also tried using hash values for both the dmg and the pkg within it. The closest ive come is that it does detect the installer but does nothing to block it. Outcome: I successfully identified the Team Identifier, but my current implementation isn't effectively blocking installations across different paths.Script Development:I created a script located at
For safety and sanity, we'd like to be able to disable this feature on in our fleet. I couldn't find any documentation on a configuration profile payload or policy setting or even a homebrew script to disable this feature. A config profile would obviously be best as it would prevent the users from re-enabling. An ongoing policy that uses either a script or an actual policy payload would be... fine I guess, but less preferred as between recurring checkins the user could do whatever they wanted. Does anyone have any resources on this?
Hi everyone, I'm just putting out feelers to see if anyone knows of any alternatives to Carousel digital signage that are reliable, and bonus points if they use apple tvs as the players. We've been happy with carousel for a few years, but them eliminating the on-prem product while charging SO much more for the cloud product has me thinking about alternatives.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!