Get Support
Recently active
This has been talked about a lot here and I see a lot of these posts, but man I cannot figure out what I am doing wrong. I am trying to write a script that will update a plist in the user folder as well as license the application upon installation. So I want the script to run post pkg install. I have this script and I am able to get it to run successfully locally, but clearly when jamf runs, it runs as root. I have actually tried several ways to get it to run as the user, without success. The most recent option I tried was from here: https://community.jamf.com/t5/jamf-pro/need-help-forcing-script-to-run-commands-under-current-logged-on/m-p/189391/thread-id/178192 #!/bin/bash#Get username#Open OffShoot to make sure nl.syncfactory.Hedge.Mac.plist existsmyuser="$(id -u -n)" echo "Username: $myuser" sleep 1 echo "OffShoot Will Open To Create nl.syncfactory.Hedge.Mac.plist" open /Applications/OffShoot.app sleep 2#Kill OffShoot ps -ef | grep OffShoot | grep -v grep | awk '{print $2}' |
Now that Apple deprecated the Disable of External Disks feature in their MDM framework with the release of Big Sur so this no longer functions as it did in previous versions on MacOS, has anyone been able to disable USB or USB Mass Storage Devices? I tried writing a script that unloaded the IOUSBMassStorageDriver.kext but that did not work. My company cannot have any flash drives connected to their macs but i cannot seem to get it to work. Any suggestions? We have about 50 2015 macs and the rest are 2019 USB-C macs.
I am trying to test this new Software Updates feature on some Sonoma computers. I have pushed some commands but am just now seeing the caveat that the first command is the only one that will run. (The first command I sent to my computer is not going to run!) My macOS computer is sitting at "Update in progress" where I pushed "Latest major version" without realizing that Apple released a major version yesterday that is blocked via Restricted Software.How do I cancel this existing Software Update attempt so that I can try pushing the Latest Minor Version? (Each time I try, I am presented with "Existing Plan For Device In Progress" err ExistingPlanForDeviceInProgress. I just need to clear the existing plan, right?
I'm seeing this issue with certain installers on Sonoma 14.6.1. When deploying via recurring check-in trigger, the policy just fails. When triggering via Self Service, I see the pop-up (attached) and after accepting and authenticating, the install works as expected. I've dug through some older threads to see if there was a problem with the Jamf and Terminal PPPC that we use but I can't find the issue! I've attached screenshots of the Config Profiles I've tried, also tried the one linked below but no joy! Please could someone help me find what I am missing!https://github.com/jamf/JamfPrivacyPreferencePolicyControlProfiles
I have a pair of Apple Silicon Mac's that are Jamf managed and a third that is vanilla, out of the box...no Jamf at all. What I am seeing is on the managed Mac's (M1 Air, M3 Pro) is that if they are either on WiFi or Ethernet via a docking station or a Belkin Ethernet dongle, when I restart the computer, it will show an IP address and give every indication that the computer is online. Reality though, they are not online. I have to unplug/plug back in the Ethernet or disable WiFi and reenable it. Only then will the computer be online. The out of the box Mac doesn't have this issue. My personal M1 Air, that I have just done update after update since its release...I don't have this issue. I have seen an uptick in WiFi at home dropping offline more often, but when I turn on the computer for the day, it will be connected.
Hello everyone,At the beginning of the year, we started our journey from leaving Novell in favor of Active Directory and MS Cloud. Now it's time to make adjustments for our Apple environment. We have chosen not to use Jamf Connect (initially) but rely on our supplier that they can do it well without (though not as well as with). But there are some important points for us to get across.- Not binding the units to ADs- Enable access to network volumes, own storage volume and sharedIs there anyone in the community who is in such an environment and what have you done to solve it? Or is there any specific way to go to solve it, recommendations?Then another little thing. We will (sadly) move part of our Apple environment to Intune for financial reasons. As I don't know much about Intune, I take the opportunity to ask the question if anyone here knows. Can we run Macs in Intune without binding them or is it a must on that side?
I have a Smart Group monitoring computers where the bootstrap token isn't escrowed. In the past week, I noticed a couple freshly wiped + re-enrolled computers (all on Sonoma 14.2 and 14.2.1), where the first user logging into the computer isn't getting the Secure Token or Volume Ownership. Also, the bootstrap token doesn't get escrowed. Background: in our 1:1 deployments, we have a PreStage-created, hidden local admin account. In this 1:1 PreStage, we have enrollment customization turned on, pointing to our SSO IdP. User gets a device, logs in through SSO, which populates their info into the local user creation screen. They enter their password again, and get logged into the device. Enrollment finishes, and for some reason Jamf is showing the PreStage admin account as the only Secure Token holder and Volume Owner. And as mentioned, bootstrap Token doesn't get escrowed. I can fix manually using sudo profiles install -type bootstraptoken, but trying to figure out why this is happeni
This might be a stupid question but here goes. I'm looking to use LAPS with Jamf and I can't seem to find the "ClientManagementID" for the API call./v2/local-admin-password/{clientManagementId}/account/{username}/passwordAny help will be appreciatedThanks in advance.
Hello All, I was wondering if anyone here has been able to successfully implement OneDrive Known folder move?We are trying to move user's Desktop and Documents folders to OneDrive, without any user interaction, we have tried to apply these settings using the Applications and Custom settings payload, we can see the CP in System preferences Profiles but nothing changes in Onedrive. Other settings like hide dock icon and open at login are successfully applied with the same CP.<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>KFMBlockOptOut</key> <true/> <key>KFMOptInWithWizard</key> <string>xxxxxxxxx</string> <key>KFMSilentOptIn</key> <string>xxxxxxxxx</string> <key>HideDockIcon</key> <true/> <key>OpenAtLogin&l
Apple Classroom - Students show up, but as "offline" in the teachers classroom console. We are using Securly SMART Pac. The students Ipad are getting the classroom profile, so that seems to be working. Any ideas? Firewall port? Smart Pac issue? I'm grasping at straws here. Thanks for your help.
Hi,Just in case anyone is struggling with the Cisco Secure Client deployment, modification of the xml file, etc etc, below is the step by step guide offered by Jamf Support, it differs slightly from the guide here - How to deploy Cisco Secure Client via JAMF (MacOS) – Cisco Umbrella ( Which is still great for the configuration profile setup ) 1. Download cisco-secure-client-macos-#.#.#####-predeploy-k9.dmg from Cisco's Download site2. Double click the DMG to mount it. You should see the items below.3. Create a temporary folder to store files. For example:* Click shift+command+G on the keyboard, enter /Users/Shared/, and click enter.* Right click and select New Folder.* Enter folder name, i.e: CiscoSecureClient4. Drag and drop Cisco Secure Client.pkg and Profiles from mounted DMG to the folder you created in the previous step.5.Open terminal and navigate to the folder you created above (i.e. cd /Users/Shared/CiscoSecureClient) then run the following command:* installer -
Hello,Our organization utilizes Microsoft PowerApps Portal to foster a community for our macOS users, providing a space to share ideas, tips, and best practices. We are looking to implement notifications, either through Jamf’s Self Service portal or the Mac notification center, to alert users when new posts are made. If anyone has experience with integrating notifications between PowerApps and Jamf, or can provide guidance, it would be greatly appreciated.
Anyone else getting 503 errors from Jamf Pro
Think i missed something in the install i followed the instructions and from a video done about a year or two ago and i get that cannot reopen error i ran the log command and i do see the JSON missing error and i can see it in the setup but i am guessing it's not installing it Nudge -simulate-os-version "14.2" -disable-random-delayzsh: command not found: NudgeIT Admin@jason-zs-mini MacOS % log stream --predicate 'subsystem == "com.github.macadmins.Nudge"' --style syslog --color noneFiltering the log data using "subsystem == "com.github.macadmins.Nudge""Timestamp (process)[PID] 2024-09-17 15:42:24.183975-0500 localhost Nudge[627]: [com.github.macadmins.Nudge:user-interface] Finished delay2024-09-17 15:42:24.190505-0500 localhost Nudge[627]: [com.github.macadmins.Nudge:sofa] Failed to decode previously cached
Hi there, I am trying to automate some processes based on our LDAP integration. At this we have a stable integration with our LDAP and all the tests are successful. (Settings: System > LDAP servers).Group Names and GIDs are found. So far I was able to use the information for some configuration profiles. Now I want to use it for associating specific devices with a smart computer group but I am somehow stuck. Ultimately, it should result like this: If user is member of a specific LDAP group, then the user's device to be associated automatically with a specific computer smart group. In system > computer management, I created custom "extension attributes" to map the "Directory Service Attribute" "gidNumber" to the LDAP attribute for "GID". But it does not seem to work. Any idea what I am missing?
Originally deployed withprestage set to "Enforce device name" set to Serial Number. Configuration Profile allows name change. Set name VIA MUT and the device gets new name and it looks like it is good for that day... Next day the device does inventory, and it reverts back to serial#. Is there any way to fix this aside from wiping 1600 ipads and getting a new prestage? I was not aware that enforcing the mobile device name meant we wouldn't be able to change it from our end later... that's quit the... feature. IF I set the name MANUALLY, then the name does stick. I really don't want to manually name 1600 ipads though. The description in Prestage for "Enforce Mobile Device Names" reads - "Mobile device name will revert to the value entered if the device name is changed by the user". This is false. What it should say is "Mobile device name will revert to the value entered if the device name is changed by Any means other than throug
My Automated Enrollment on the Jamf Now side is working fine however I'd like to add the Jamf Security cloud (RADAR/Jamf Protect product) as an integration in the UEM section. However there's no option for Jamf Now but there are options for Pro,School etc which seems strange. Then when creating the activation profile manually theres an option for Jamf Now but when selected nothing happens. I've enrolled the devices manually and they're showing as unmanaged as I've used the QR code from the admin pages as the QR codes sent to end users dont actually work. Any help is appreciated.
We use Okta/FIDO2 to allow users to login to Self Service and see certain Apps only they are assigned.We're seeing an issue where the private browser window has automatically filled in the username with a different one (some users have 2 Okta accounts, one for elevated privileges elsewhere in our business).Anyone else seeing this? Is it Jamf, or Okta? It's been hard to narrow down so far.
I'm working through the usual new macOS approval process for my org. Everything checked out on my test machines, so I updated my daily driver. Now, every 30 minutes or so I am getting a popup that is new to macOS 15 saying "sudo is trying to execute a command as administrator." Clicking "Cancel" makes it pop up again a few seconds later, and authenticating with an admin makes it pop up again about 30 minutes later. I like this popup in theory, but as implemented it doesn't give anywhere near enough information to figure out why it is showing up or if it's a valid request. I've ruled out our in-house launchagents and the like, and it doesn't seem to be happening on test machines with normal user programs installed. That makes me think it's tied to some admin related tool like Jamf Sync, Packages, autopkgr, or something else that most users won't have installed. Alternatively, it could be some driver set like the LogiOptions+ needed for some keyboards. Is anyone else seeing this recurri
Hey everyone, getting some really strange errors the last few days on all my macs. To be clear, I am only running AD, and nothing has changed on the mac side of the house what so ever. Currently if you UNCHECK the "create mobile user account at login" box, network users log in without error. However, once you check this box and try to log in a network user, a dialog box pops: "You are unable to log in to the user account "abcdefg" at this time" Logging in to the account failed because an error occurred. Any conversation or help would be great, as we are completely stuck on this side about what would be causing this issue. Note that last week our engineer rolled the DC's, and the problem was gone for the rest of the day Friday, but it has once again returned. I am simply looking for any and all info to try and resolve this issue.
I'm trying to find a functional EA under Sonoma that I can use to create a search for users who still have mobile accounts. Does anyone have one that works for builds later than 14.3? I'm unsure what may have changed against other EAs I've found here.
Apart from waiting for Apple to release a patch for this. Can I ask what other mitigations people are doing or thinking about doing for this recent issue?
Is it still the case that there is no way of allowing Location Services for a specific app, for non admin users? I don’t see a PPPC option for it, and it’s been stated that this is impossible in the past. Zoom soft-phone client wants location services enabled for 911 call routing. Users don’t have admin rights.I've seen someone say the below works for Big Sur, but even then I believe that just enables the general Apple location services, and not specifically for an app in particular.#!/bin/sh sudo /usr/bin/defaults write /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd LocationServicesEnabled -int 1 sudo /usr/bin/defaults write /Library/Preferences/com.apple.timezone.auto Active -bool trueI need Location Services checked for Zoom specifically.
I am trying to prepare for our next semester. I do not upgrade instructional machines until the semester is over. In doing so, I learned that my older Intel machines could be moved up to 13.6.3 and started to do so. However, for the Lab Instructor machine, this disables valuable features within Remote Desktop for non-admin users. For my lab instructors logging in via AD, this would be the three options to the: Copy, Install, and Unix. Of all these Copy would be my critical loss for a lab instructor. They can still observe.13.6.2 still allows my non-admin users access to all these features.Also, for machines running Sonoma (my M1 machines) I also loss the ability to login to all lab machines at once via my admin account. This would be using the Send Unix Command of an osascript The error they return is 143:162: execution error: Not authorized to send Apple events to System Events.So . . . if Apple Remote Desktop is still part of your
A profile called "whitelist during school hours" is setup with a time filter. It has a whitelist, so that private games and other unwanted apps will disappear from the students' home screen. Unfortunately, the profile works only for 60-80 % of the iPads automatically. We have to push the button "re-try" in the administration console, or we have to ask the students to open the app Jamf Student, so that their iPads asks the Apple Push Server for any updates (including updates on profiles).Have you experienced non-reliability with time filtered profiles?Any suggestions how to fix that are welcome. (We tried IP address based profiles that work a bit better, but they aren't reliably either.)
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!