Get Support
Recently active
If I run the command disable and prevent activation lock on a system that has activation lock enabled it does not disable it. Is this normal?If I run it on a system with out activation lock enabled it does prevent the user from enabling it. But would like to also disable activation lock on systems that people have logged into their apple id and enabled find my mac.
A few months ago, I was able to use the Jamf API to obtain a computer's room assignment. I need to now get the computer's site. I don't care if I can only obtain the site ID or its actual name. I need this so I can avoid creating a separate installer package for the different regions in my company. I want the install script to first obtain the computer's site assignment and then choose the appropriate customization for each region. I thought this would be similar to getting the room assignment but apparently it's not. Does anyone know the correct way to do this?
Just got my first request for an ebook in the 10 years I've been using Jamf. Of course assumed it worked like normal Apps, but why would anything be that consistent or easy right? I understand we have to send an invite to the user which I have, however it doesnt seem to send. We are using Managed Apple ID's with ASM but the user cannot login to Books (message stating managed apple ids cannot log into to books or the appstore) and I dont see the invitation showing in self service, and I also tried checking all the check boxes for Automatically accept the VPP invitation for managed apple ids. If I look at the invitation status it shows..."Missing Managed Apple ID". The staff member is logged into their Apple ID in system preferences and Apple Classroom is working normally so again, no idea what else I need to do. But if they could just make this a bit more complex to manage...that might help. Gabe ShackneyPrinceton Public Schools
Hello all,I get the error"An error occurred while trying to determine if the Software License and Service Agreement has been accepted. You will be logged out in 5 seconds"After upgrading from 11.7 to 11.9.1 and restoring a newer database Any ideas?
In Patch Management Spotify is indicating that version 1.2.43.420 is the latest version even though 2 newer versions have been released since that one. Can this be fixed to display the correct latest version.
Provide users with detailed feedback while removing Acrobat’s Add-in from Microsoft 365 Background Each time Adobe Acrobat Pro is installed or updated, the Acrobat Add-in is silently added back to the Microsoft 365-related User Content Startup folders. The Add-in relies on external dynamic libraries, which we purposely disable by setting DisableVisualBasicExternalDylibs to true: Unless non-Microsoft extensions are being used, set this value to true via a Configuration Profile to improve security. This causes users to observe error messages in the following applications: Microsoft Excel Microsoft Word Microsoft PowerPoint Continue reading …
Hello everyone,Now I'm about to go crazy when nothing works for me. What's the best way to backup, wipe and restore a mobile device (iPad)?In my case I need to backup all on a device, wipe it and get all photos, notes and so on back on the same device after wiping it.I've tried a some on a test device to backup on a Mac, wipe it and restore. Tried it two ways.1. Restore before anything else after wiping it.2. Signed in to Wi-Fi and remote control and the restoring.In one of the cases (think it was the second) I got some back but far from all. Didn't get Self Service for one example and far from all photos. In the other case it looked like I got all apps and so on back, but many of the apps hade a cloud in the bottom of it. Self Service had a cloud and when clicking it, it couldn't be downloaded.
Our organization is not currently allowing AI software on any device, including using the built in CoPilot in Edge. I found some documentation, but it isn't 100% clear on how to disable it.Anyone have an easy way to make this happen in Jamf?
I am looking for a way to fully disable Airdrop for CIS standard security reasons on our Macs, the typical defaults write com.apple.NetworkBrowser DisableAirDrop -bool YES removes the option from finder but this option still lives in the go menu and the CIS check continues to fail. Any Ideas or special config profiles people have created?
I am trying to locate a device that was previously assigned to a user so that I can deauthorize an app that was used on it. The guidance from the app provider (Kuta), says I need to log in on the old device to deauthorize it. Any help would be appreciated!
I recently deployed Cisco AMP and everything seem to be running without a problem, but after upgrading to MacOS 15 I'm asked to Allow Network Filter. Has anyone experience that or have a suggestion to approving it from JAMF Pro?
Today we are releasing a maintenance version of Jamf Pro; this release includes the following changes and improvements: New Keys for System Extension Payload Jamf Pro includes two new system extension types for computers with macOS 15* or later. In macOS 15*, end users can see and disable previously installed managed system extensions (e.g., endpoint security tools) through System Settings or Finder. You can use these new settings (Non-removable system extensions and Non-removable system extensions from UI) to prevent end users from removing these system extensions. If you use Jamf Protect, which runs as a system extension, Jamf strongly recommends configuring this new MDM setting to restrict users from disabling Jamf Protect. *Feature support is based on testing with the latest Apple beta releases. Resolved Issues Jamf Pro Server [PI119868] Syncing packages to all nodes in clustered environments (including Jamf Cloud-hosted environments) no longer requires extended time to co
Does anyone have any experience working with Talech register? Current client having an issue where the application wont work upon initial configuration profile install. Client found a work around by uninstalling the management profile manually - then the application works. However if at any time the application gets logged out - the app goes blank and the whole process of removing and reinstalling the profile manually starts over. Any help is appreciated.
I am installing Maya 2024 and I am running into this popup. I am able to get the license to verify via the network server when putting in my credentials. I haven't tried on a non-admin machine.I created a configuration profile with Managed Login Items, and added the Team Identifier/Bundle ID to it and deployed it to my machines and still getting the popup. I've not seen this popup before. Anyone have any info/experience on this?Here is the script I am using, with the AutoCad and Mudbox install lines removed: #!/bin/bash ### Install AutoDesk Combo 2023 (AutoCAD, Maya & MudBox) ### silently @ login window with network licenses (aka multi-user lab/classroom deploy) ### 2022.07.27 by JonW ### Simply update variables/products below the function section as desired ### Read the additional details at the end of the script for more clarity on licensing. ### Ensure: ### 1) installer app(s) re-packed from .dmg by Composer & deployed to /private/tmp (
I have found this excellent manifest example from @talkingmoose to show the basic force install of an extension. The extension makes use of extension settings that we want to pre-set. The instructions for doing this from the command line on Mac are here https://docs.deque.com/devtools-for-web/4/en/devtools-configuration#macos-policy-configuration. I have added a snippet of the PLIST file below as well. The question is - how do I configure these settings as part of the installation for the extension within Jamf?{ "title": "Google Chrome Extensions (com.google.Chrome)", "description": "Install extensions in Google Chrome", "__feedback": "bill@talkingmoose.net", "properties": { "ExtensionInstallForcelist": { "title": "Extension Install Forcelist", "description": "Add extension IDs. Paste the extension ID in front of the default text.", "property_order": 5, "type": "array", "items": {
So with the PPPC utility try to grant access to Word, Profile is uploaded to user but still admin rights necessary what am I missing?
Our school division uses Active Directory and managed Apple IDs. I currently allow personal Apple IDs to be set up on a computer. Some users have been granted administrative access on the computer they use because of the remote work they do. I have observed that when personal Apple IDs are used with an account when a software update is available it will prompt for authentication but the username section is greyed out with just their username, but even when using their current password it says try again. This also happens with some other things like require lock screen password. The lock screen issue just came to my attention today but the Software Update I've been getting around that by either remoting into the computer, logging into our local account and authenticating there or pushing out a Software Update policy in Jamf Pro to that computer. Does anyone know why this happens with personal Apple ID and how I can get around this? This seems to happen at l
Note: macOS Sequoia Beta topic here, but with the OS right around the corner I figured it is a good time to make a feature request prior to its release.Two of our engineers have been testing Sequoia in our environment in prep for the upcoming release. Everything seemed to be going smoothly for weeks until we tried to connect to our network on campus (both of us are telecommuters) while attending a team meeting. Upon connection attempt to our wireless network we get caught in a cycle of unable to verify our user certificates (required to connect to our network)We've found that this is due to the new feature in Sequoia called “Rotate Wifi Address” which randomizes the Mac Address of the system upon connecting to wifi. This is a per-network setting that can be manually toggled off.It appears ISE isn’t able to link our MacBooks to a hardware profile with this enabled, which may be causing it to deny the connection. I've scoured and have been unable to find any other call out
Hello,I'm working on Jamf Pro, I'm taking over the work of a colleague who has left. He set up "Zero Touch" and "DEPNotify", he set up an AD that is used to do Zero Touch. This AD is now only used for that. We are on Google. Is it possible to replace the AD with a Google LDAPS, without going through Jamf Connect, and thus directly create a user session and a password linked to their Google account?The existing configuration uses an Active Directory (AD) for authentication in the Zero Touch workflow, but this AD is now only used for this purpose.The goal is to remove the need for existing AD and integrate directly with Google authentication, without using Jamf Connect.The desired outcome is that users can authenticate with their Google accounts during Zero Touch deployment and have their Mac provisioned according to policy.Merci de votre aide.
We are running into issues getting our IPads registered through Intune by Jamf. We are using OFFICE365 GCCHIGH, which requires our devices to be compliant in order to access our resources. We have the configuration profile set. We are just stuck at the self service(registration intune) part. It works fine when we do it through the Mac, but with the IPads we’re stuck. Does anyone have advice on how to proceed or any best practices using GCCHIGH environment?
We have rolled out about 3000 iPads for K through 2nd graders. The students need to take a web-based test and the test requires popups. In JAMF, Restriction there is an option that allows popups and that seemed to work years ago. However, it does not seem to be working now. It seems like Safari has its own settings nowadays. We want to push out the "allow popup" settings to the web browser so the kids do not have to worry about that. Ideally, it would be good to have a setting like "allow popup for these web sites". I have tried Chrome and Firefox and various app config settings from what I could find on the internet, but nothing has worked yet. Are there any current recommendations with the modern web browsers?
We are deploying team via Jamf app catalogue I have started to notice when it updates it just install another verison next to old version. This doesnt seem to be happening on all machines across our site. I have been trying to build out a smart group to get an idea of how many machines are effected.I feel something like this should work but cant get it report reliable results. Does anyone have any suggustion for how I can better track this? Thanks
Hi Nation, we enrolled MDM for institutional iPhones (not BYOD). Now, after some time in production, our users complain, that they cannot copy and paste phone numbers from the managed Gmail app to iOS contacts app.The devices are fully managed, but the native iOS apps do not seem considered as managed apps, and the pasteboard is blocked. (Users did not add a private or managed Apple ID on the device.) Is there a way to "manage" the native iOS apps or consider them as trusted apps?Here are our current restrictions:- Documents from managed sources open in unmanaged destinations - restricted- Documents from unmanaged sources open in managed destinations - restricted- Pasteboard respects managed/unmanaged document restrictions - enforced- Managed apps can write contacts to unmanaged contacts accounts - restricted- Unmanaged apps to read contacts from managed contacts accounts - restrictedLooking forward to your thoughts or maybe a reference to anothe
Hi All, We did the update to a more recent version of Jamf Pro. We lost the Jamf Admin.app feature and now I'm having issues getting packages into Jamf Pro. I have tried using Jamf Sync, and also just copying the files directly to one of our FSD points. Then I create the package entry under Settings -> Computer Management -> Packages with the package filename as the display name and add the filename of the package and save. Here's what I am seeing: It's not even trying to install the package from an FSD. I had a similar situation a few weeks ago, and it just starting working on its own, so I am wondering do I have to do anything else for Jamf to 'see' the package? We have 24 FSD points, do I need to sync the file with each FSD? I thought it used to sync automatically if I added the file to the principal distribution point. Any info is helpful..
Is it possible to made smart groups when a specific configuration profile is installed So if I look for a config profile called "Extension" I would like to have a smart group on those computers who have this or not. I can of course create some EA, but doubt how to create this as script
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!