Get Support
Recently active
Hello everyone. I am testing Privilege Escalation for the first time with JC; 2.39.0. I want to do a very basic any user can escalate for 30 minutes with no password needed, just need to select a reason. The profile is deploying to the test workstation however the Request escalation is not appearing. Here are the necessary snippets. Any assistance you can give will be greatly appreciated. <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>Appearance</key><dict><key>AlternateBranding</key><true/><key>MenubarIcon</key><string>/usr/local/jamfconnect/cdi-LM@1x.png</string><key>MenubarIconDark</key><string>/usr/local/jamfconnect/cdi-DM@1x.png</string><key>ShowWelcomeWindow</key><false/></dict><key>Cust
hey folks.. For stupid reasons unknown, I've been tasked with disabling the QUIC / HTTP3 protocol in our browsers. I got Chrome disabled no problem, but can't find anything regarding disabling it in Safari. Has anyone done this and can share the way??
I've had MMA setup for a few years now and it mostly works but it's been devices based and I've never had it working based on device/user. For example we have a lab of Macs and we only want MMA available for a particular faculty member and not an option for students. If I scope it to a user it never shows up. We have to scope it based on device but then it's open for all users of that device to have access to using MMA.Maybe it's a setting I have but scoping to a user never works. As for 3rd party, there're apps out there but many are pretty pricey. We need something that's not crazy pricey that can replace MMA and be controlled through JAMF or a cloud service or server.
Hello there, I'm trying to add custom trusted sites to uBlock on Chrome and JAMF is throwing an error saying the PLIST format is incorrect. I'm wondering if any of you have a template for whitelisting domains in uBlock that you'd be able to share. Below is what I'm trying to use that is not working. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>trustedSiteDirectives</key> <string>"trustedSiteDirectives":{"microsoft.com", "adobe.com", "office.com"}</string> </dict> </plist>Thank you in advance
Hello, I did a bit of searching for this answer, but I wasn’t able to find anything as exact as what I’m looking for. I have a 100 something iPad 8th Gen’s. I keep getting told that they will no longer be supported in Jamf Pro around the fall of 2025. This is from someone internally in my company. From what I’m seeing, it’s not necessarily 8th Gen’s that are no longer supported, it is devices that are not able to be updated to a certain iOS.The way I understand it, as long as the device is not older that 4 major iOS versions, then it is supported. So in the Fall of 2025, as long as the device is iOS 16 or higher (assuming iOS 19 comes out), it is still supported. Am I correct on this?
We are preparing to switch from eDirectory to Active Directory. When we enroll devices via eDirectory, the devices are registered with:- username (abcdef#)- full name- email...among other things.We have a lot of manually created accounts in eDirectory for, among other things, shared units and/or non-personal units that lack email addresses.We are in the pipeline to run a script to replace all device usernames with the people's email addresses but the big question is what do we do with the devices that have accounts (manually created) that have no email addressesCan you, for example, set up a new PreStage that you enroll them via again that does not tie them to a user account or are there other options?
Hello, everybody.There's a profile we are supposed to enable outside of school hours. Meaning, everyday when the students leave school until they come back. That includes weekends and holidays, of course.How should we go about doing it? It seems there's an option to do just the opposite of what I need: "don't install this profile during the configured holidays".Thanks in advance.
HelloFirst of all, sorry if this is already solved in some other thread. I have not found it.It turns out that in my son's school they force me to install on his computer the JAMF application to know what he does during school hours. But it so happens that I don't want them to be able to know what my son (or whoever may use the computer) does outside of school hours. I assume that the hours when the application works can be configured in the application. But since they are the ones who install it, and I don't have administrator permissions on it, I can't know if they set it up correctly or not.What options do you recommend me so that this does not happen? I had thought of creating a virtual machine and have them install the application on that machine. Another option I had considered was to install a second operating system on an external hard drive, and outside school hours boot the computer from it. But maybe I am making my life too complicated and there is a simpler option, such as
We are building up a python script that fills the Users (Teachers / Students) into the classes with the jamf api. We are doing good so far but we have trouble updating the User Class or Group assignments. We are using the Documentation on https://school.jamfcloud.com/api/docs/It seems that we can add groups but we want a full upgrade. The user should loose the existing group / class assignments and get the new ones that is in the put. Should we use https://school.jamfcloud.com/api/docs/#api-Users-Update or https://school.jamfcloud.com/api/docs/#api-Classes-Assign_users ?
We have the following set in App Config in Outlook.<dict><key>com.microsoft.outlook.Mail.FocusedInbox</key><false/><key>com.microsoft.outlook.Mail.OrganizeByThreadEnabled</key><false/><key>com.microsoft.outlook.Contacts.LocalSyncEnabled</key><true/></dict> We have confirmed the below works <key>com.microsoft.outlook.Mail.FocusedInbox</key><false/>but the below settings don't work <key>com.microsoft.outlook.Mail.OrganizeByThreadEnabled</key> <false/> <key>com.microsoft.outlook.Contacts.LocalSyncEnabled</key> <true/>
I’m using JAMF to push a script to set defaults for a Sharp BP 70C31 printer with the goals of: Printer sharing off, B&W default Print release on. My command: lpadmin -p SHARP_BP_70C31___Main_Building -L Main_Building -E -v lpd://172.16.17.200/ -P /Library/Printers/PPDs/Contents/Resources/SHARP\\ BP-70C31.PPD.gz -o printer-is-shared=false -o ARCMode=CMBW -o ARPrintRelease=True The first two are working, but print release is not.If I run the command I find the *True value set: lpoptions -p SHARP_BP_70C31___Main_Building -l ARPrintRelease/Print Release: False *True CUPS also shows the value set to on, but the print dialog does not have the Print release checkbox checked. If the jobs afre submitted anyway, the intended print release effect does not happen. What may be going on with this?
The Return to Service app that I put on a group of iPads in June of this year (2024) has worked great. When I launch the app here in October, I saw an error inside a red box:Error 405<NSHTTPURLResponse: 0x3005fc160> {URL: https://OurJSS:8443/api/v2/mdm/commands } {Status Code: 405,...Does anyone have ideas about what might be happening or where I might look to get more info on the problem?Thanks.
Hi, all!Many, more thant 40%, of Norwegian children have their time split living with either parent after a breakup. Both parents should be able to be logged in to their individual Jamf Parent to manage their offsprings device. Today the parents needs to log on/off when the student moves between them. That's an inconvenience.Please help upvote this Idea:https://ideas.jamf.com/ideas/SCH-I-366Tim
Darnit!Back to the books!
I've got multiple developers who are having an issue where when connected to Cisco VPN User Tunnel, they are not able to connect to a USB connected iPhone in Xcode. When not connected to Cisco VPN User Tunnel, the developers are able to access the USB connected phone without issue.
Hey there! I have a problem where, randomly, the downloads from App Store are not working anymore. For example, I am trying to install 2 devices. Same OS. Word will install on one, and the other one says "AppStore request (submitVPPRequest) timed out". It does not make sense to me.
Battery capacity under Hardware section shows 1% in Jamf Pro 11 (not sure if this issue existed prior).When I look in System Information, it's at 94%.
Hi all,after the update to OS18, students can no longer receive files via airdrop on managed devices. They can, however, still send. And it does not seem to be a general OS18 issue. Anyone else have this issue?
We have set up Single Sign-on via Azure, and it works like a charm.However, a couple of weeks ago, an alert popped up that the "Signing Certificate issued by SSO Identity Provider is expiring in .. days".I followed the instructions to "Visit your SSO Identity Provider to update the certificate", and the newly activated certificate is valid until June 2026. But, the alert does not go away. In the SSO settings, we originally linked to a URL for the Identity Provider Metadata Source; and, this URL did not change in Azure when the new certificate was activated. I tried to replace the URL with the updated metadata file, but still no change in the alert. I suspect that the best practice for SSO certificate management involves updating it more than 30 days ahead of the expiration (30 days, being when the alerts started); and, since it progressed to the point of alerting, it can't be undone? Having reached this point, however, I wonder what I can
Hi allFirst post on here, exciting times! So we have a deployment process with Jamf Pro that pushes out an admin account with LAPS enabled. All good there. Except we have a mac that has the account manually created, which is blocking LAPS from effectively working on this specific device when needed. Wondering how clean it is to either change name on this account or delete entirely from Jamf pro without the need to manually intervene on the mac? I dare say this kind of post has occurred before so feel free to direct me there if so. Thanks for the assistance everyone!
has anyone had any success in packaging the iOS simulater from the xcode developer page with any success?
Today we are releasing Jamf Pro 11.10. Highlights include: New Keys for System Extension PayloadJamf Pro includes two new system extension types for computers with macOS 15 or later. In macOS 15, end users can see and disable previously installed managed system extensions (e.g., endpoint security tools) through System Settings or Finder. You can use these new settings (Non-removable system extensions and Non-removable system extensions from UI) to prevent end users from removing these system extensions.If you use Jamf Protect, which runs as a system extension, Jamf strongly recommends configuring this new MDM setting to restrict users from disabling Jamf Protect.Note: This feature is also included in Jamf Pro 11.9.1 or later. App Installers Workflow ImprovementWhen using App Installers to install an app via Self Service, Jamf Pro automatically detects and updates the app regardless of the version installed on a computer in scope. (Previously, unknown versions were not updated.) An un
Is there no way to correctly add AirPrint printers with Jamf Pro? I see that it's exceedingly easy with Jamf School, which we don't have (despite being a school.) It's also exceedingly easy with iOS devices. But for some reason it appears to be impossible for macOS via Jamf Pro.I keep revisiting this over the years, and there's never been any updates.I'm paranoid because LPD is being deprecated and will disappear at some point soon, even though it's been years since the ominous warning showed up.I know that adding it via Terminal technically works, but it always has a generic printer icon. I don't want it to technically work. I would like the printers to have the correct icons associated with the printer name as a visual cue for the students.Am I missing something? Or is this still not fully implemented for Jam Pro for the past who-knows-how-many-years?
please upvote if you agree https://ideas.jamf.com/ideas/JPRO-I-740 the thinking goes like this i want to add Multiple poliucies and profiles to a group, or even a single machine, currently we have to go into each policy and profile to add the mac/group. this request would allow us to select the device, or static/smart group, and then add the policy's/profiles to that group
Hello Nation!Noticed an older Wake on LAN policy that we have here in our Jamf Pro is returning errors. The command that the policy pushes is systemsetup -setwakeonnetworkaccess on and this is the Result of the command:2022-03-25 10:57:04.301 systemsetup[90262:4178974] ### Error:-99 File:/System/Volumes/Data/SWE/macOS/BuildRoots/533514bb11/Library/Caches/com.apple.xbs/Sources/Admin/Admin-911/InternetServices.m Line:379setwakeonnetworkaccess: On My first guess was that the computers that were getting the error may have the setting already enabled, but after unchecking the Wake for Network box in the power settings and redeploying the policy to a device to test, it still returned the same result. When resorting to Google-Fu, outside of using a homebrew pkg or pearl, I mostly saw others use the same command as myself to enable wake on network. Did the newer macOS updates change anything that I am missing that would affect this, or is there any other method that doesn't involve homebr
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!