Get Support
Recently active
Hello folks,I know that there are already a few threads about reading out local admins. Either I didn't understand what was available or what I needed wasn't there. We would like to read out on all devices where local admins exist. with the exception of three admin users from IT. On the one hand, it would be if the admins were listed in the computer object under User and Location. and on the other hand, if we had a smartgroup where all computers are available with local admins (except for the three admins users from IT).Cheers
I'm looking to run msupdate in my build script so I always have the latest Office products on devices before users get the device. I've noticed in the past that even running the GUI, it doesn't actually update any apps until you've been using them for a while. Has anyone had luck using MAU (msupdate in particular) prior to the first run?
Comic Sans is just my type.Not really. You’ve got a story! You know what you want to say. How do you say it? Your presentation deck is how you turn your ideas into something visual for your audience. It’s going to complement what you’re there to say. You as the speaker are not there to complement your presentation deck. com·ple·ment | kämpləmənt | verb to complete or bring to perfection In other words, what you say is more important than what you show, but what you show can help you with what you’re saying. Apple Keynote, Google Slides, and Microsoft PowerPoint are the three big presentation tools. If you choose to use Google Slides, make sure you install the Google Docs Offline extension in Google Chrome or Microsoft Edge and then turn on “Available offline”. Always assume you can’t rely on conference Wi-Fi. Stick with one of these. You could create your presentation in something else and then create a PDF, but you’ll really limit yourself later when we discuss animations. And
Hey there - does anyone else use CyberArk EPM (end point management) to manage admin rights and third party app installations more easily? We're beginning to roll out a test bed in my company, and I'm working on the mac deployment. CyberArk provides some instructions for deploying here, but I'm struggling with them. It seems to want the zip file deployed as the package, and there is no pkg, but I've never used a zip file as an installer through Jamf. Anyone got this deployed? Or have any insight on using zip files to deploy apps?
our packager is using the official documentation and asked a specialist with help see below but no luck seems to get stuck, epm is fully removed from the MAC, it was even rebuilt to insure this. Any ideas why we can't seem to package it? https://community.cyberark.com/s/article/Deploying-EPM-Agents-on-macOS-with-Jamf-Pro https://community.cyberark.com/s/article/EPM-How-to-configure-JAMF-for-EPM-Agent-distribution Send over an example of the command being usedThe user is an admin with sudo - Try running sudo ls / if it prompts for credentials then the user has sudo rights.Try putting the files on the Desktop. Then confirm they are not quarantined by gatekeeper xattr -l /path/to/your/file if it returns com.apple.quarantine you need to run xattr -d com.apple.quarantine /path/to/your/file to fix.Confirm these first... if no luck, we can isolate further by creating a mac VM. It only takes a few minutes using Orka Desktop. The VM will be clean and try again there. &
Hello Everyone, I'm sure this has been covered but I'm trying to upload SentinelOne install as a package in Self-Service in Jamf but I keep getting "Availability Pending" and the install displays Error when I try to install in Self-Service. I was wondering if the Availability Pending error is the root cause? Please help. The file size is 65.3MB Thanks.
Work being carried out with a new VPN implementation, we've identified that macOS users with iCPR enabled causes problems, I was hoping to setup an EA to bring inventory the current status of Private Relay On or Off. I found this page Determining “iCloud Private Relay” and “Limit IP tracking” status in macOS – brunerd.Which I thought with some tweaking would do the trick, however during testing the status is always Off. I believe the issue is with this line. childData=$(/usr/libexec/PlistBuddy -c "print :" /dev/stdin 2>/dev/null <<< $(plutil -extract "${key}" xml1 -o - /dev/stdin <<< "${parentData}" | xmllint --xpath "string(//data)" - | base64 --decode | plutil -convert xml1 - -o -))
Going over Jamf nation posts the past few weeks, and it seems like there is an uptick in posts and comments that look very much to be made by chat bots. I have also seen more people marking their own comments as solutions to their own posts and such. Has anyone else noticed this trend or is it just me?
This appears to been touched based on in the past, but appears to of died once catcher was put into place for check coverage.apple.com however, I noticed in Monterey and possibly big sur, you can see applcare+ status, under >Apple Logo > About my Mac > SupportAnd was wondering, if this can be added to an extension attribute, as like the ability to get the battery condition of a MacBook, and if so where on earth is the information stored.
Devices are connected to pro and are showing managed and are showing correct profiles, etc.We get two different error messages:Self serv is a component of jamf pro developed by jamf, this app must be associated with a jamf pro serverandProfile installation failed. the SCEP server returned an invalid response
I'm working on a new .mobileconfig file to distribute 802.1x settings. I can make this work in a file built by ProfileManager, but when I build what appears to be the same thing on my JSS and load it on a test box, I'm getting "Acquired: cannot prompt for missing user name" from eapolclient in console.app. I want to compare the two mobileconfig files, so I converted the PM file with plutil: >>plutil -convert xml1 PMFile.mobileconfig When I try to convert the JSS-generated file: >>plutil -convert xml1 JSSFile.mobileconfig JSSFile.mobileconfig: Property List error: Unexpected character 0 at line 1 / JSON error: JSON text did not start with array or object and option to allow fragments not set. Is there a way to get a standard Property List file from the JSS? (I can't convert to JSON either).
I am looking to implement CIS Benchmark on macOS Sonoma devices and we have Jamf Pro as an MDM.Can someone help here for scripts and configuration profiles for macOS Sonoma Compatible ?I found the old one which we had used for Catalina https://github.com/jamf/CIS-for-macOS-Catalina-CP is this still eligible for macOS Sonoma ?Thanks & RegardsJaved Khan
I'm wondering if there's a way to restore a delete config profile within Jamf.I found an article that basically said to change the ID number in the URL until you find the profile that you need, click Download, and then when you upload the mobileconfig it should use the same ID number.This doesn't seem to work anymore. I can find the profile, and I can download it just fine, but re-uploading it gives it a different ID number. I'm not certain this is a problem, but I don't want to be messing with things until they break further.We had a WiFi configuration profile we want to restore as we think it got deleted before it got removed from devices, and suspect it's now causing us trouble.On a related note, if anyone knows how to configure PEAP to use individual logins from the network, without having the Macbooks actually connected to the domain, please let me know as that would also solve the problem. We can just not push a profile, but then we can't get the certificates assigned to the netw
In lab or shared Mac, we have 802.1X profile, running the latest Jamf Connect, and Sonoma. All users first login through Jamf Connect to create their account, and the "Select Your Wi-Fi Network" screen comes up. We can skip it by clicking Continue because it already having Wi-Fi. Then goes to the desktop. It never does that in any macOS version except Sonoma. Not sure what causes that. Anyone has any ideas? Thanks
HI,I'm currently setting up the configuration profiles for our iPads and am trying to figure out if there is a way to have bookmarks preconfigured on the iPad for regular sites.At this stage I have some webclips set up, but I'm trying to avoid having too many tiles on the iPad and would prefer them in bookmark form in either Chrome or Safari.Any help would be greatly appreciated.
Hello Jamf Nation!Our Art program recently purchased some Epson SureColor P900 printers. They have a long history of purchasing Epson 3800, 3880, and P800 printers, so it wasn't surprising they purchased this model to replacing some worn out printers that couldn't be repaired any longer. All of them had a standard Apple Installer .pkg file available for download from the Epson.com support site. I go to the Epson site for the P900 drivers and all that's available is a small download - "SCP900_Lite_64NR2_NA.dmg" which inside of it has the "Epson Installer" application. No package file. I attempted to capture the Epson software and driver install using Jamf Composer, but printing fails on the captured package no matter how I manipulate it - "Software is missing. Contact the manufacturer for the latest printer software." Opened a support ticket and the first reply back from them was to go to Epson.com and select the OS and download the driver for the mod
I'm running an on-prem instance of Jamf Pro 11.5.1 and still testing getting packages uploaded to our File Share distribution points before jumping to the next version. When we upload packages using either Jamf Sync or Directly to the SMB share, they only install/download the package with a VERY low success rate (10 percent or so). The Policy will complete without any issue, but it won't run the package the vast majority of the time. Screenshot included showing what I am talking about. If we upload the package using Jamf Admin, we have 0 issues with packages associating with the policy. Is there some way to tell the jamf pro instance that the package exists, it seems like there is something that runs with jamf admin that just doesn't run with Jamf sync or when manually uploading to the smb share.
We have created a configuration profile to block/Defer macOS Sequoia but it is currently pending for 500 of our machines. I know some of these machines are still in use and checking in. Currently it has completed on 1700 machines. I am trying to figure out what could be stopping it from successfully completing on these last 500 machines as I know some of them are actively being used.
We have a Mac Studio running macOS Ventura. it's connected to a Studio Display via Thunderbolt, and to a Crestron system via HDMI, which feeds two large displays at the front of the classroom. The problem is that on power-on, the login screen defaults to the large displays, which are to the instructors' backs. We'd like to either force the login screen to be on the Studio Display, or if that's not possible, at least have the displays mirrored at startup so the instructors can see where they're typing (and hopefully avoid typing their password into the username field for all to see!). I read that if an admin set the primary display to be the Studio Display, that it should respect that setting on future reboots, including for the login screen, but that doesn't seem to be the case.We're looking for a solution that "just works," i.e. doesn't involve instructors having to disconnect cables before login, etc. We didn't seem to have this problem last year when we were running macOS Monte
I'm trying to script the removal and re-adding of SecureTokens. We have run into an issue where the users have changed their passwords outside of macOS and now the accounts with SecureTokens are not able to install macOS updates. Can this be done, anyone have any examples? When I try to do it manually, I get a Operation is not permitted without secure token unlock.
Notability has announced changes to their Education license model, info found Here.I ran into an issue deploying the license key to macOS devices following their instructions Here.The sample XML for macOS deployment file doesn't indicate what the "Preference Domain" should be set when deploying via Configuration Profile in Jamf.You should enter com.gingerlabs.Notability for the Preference Domain field.Here's an example of my PLIST file:<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>com.apple.configuration.managed</key> <dict> <key>License Key</key> <string>YOUR_LICENSE_KEY</string> <key>iCloud Allowed</key> <true/> <key>Link Sharing Allowed</key> <true/> <key>Note Gallery Allowed</key> <true/> <key>GIF Library All
Is anyone using Lumu Defender as an addition to your security stack? They are trying to integrate with Jamf Protect at the moment but thats not why I'm asking for help. I am trying to automate the install process, and get as far as getting to the point where it wants an activation code to tie it back to our cloud instance for definitions/signatures etc with out having to have our end users (student or staff) copy paste it into the pop up box. At the moment its a rather somewhat complicated Automator workflow as when I tried doing the install with Composer, I cant seem to get it to install properly. Looking for ideas if anyone is using them. Thanks
This is under duress and pressure seeing that they need the ipad ASAP.And since I do not do this often, last time was 2022 when I installed an ipad, and since there are many ways to add a device to Jamf, on top of the fact that our Jamf account was created in haste back in 2019 and then handed to me, it has many variations of managed devices.I was handed a new ipad bought from Verizon, not apple which is the easiest i know.I tried using Configurator by adding an mdm, but it was not valid and deleted it. I used a different MDM profile in the configurator and it wants to erase the ipad as does the prepare process. Is there a way to add the device to JAMf Pro and be managed without erasing it? - gerald
Hey everyone, new to Jamf here. We have a remote desktop app that requires us to allow access via the remote desktop setting in privacy and security (shown below). We have many remote machines and are trying not to have to enable it one by one. Anyone know if it's possible to set this in Jamf? I looked in the PPPC on our config profile but I don't see this "Remote Desktop" setting.
Aside from getting the logged on user, what'a a way to get the username that's assigned to the computer in Jamf? I would like to use it for a policy script.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!