Get Support
Recently active
Hello all, I have run into an odd issue here on two M1 MacBook Airs I'm working on. When proceeding to the Microsoft Azure sign in page for my school district, I get prompted with an error."Invalid Request: Error from request to URL: ,Error: the certificate for this server is invalid. You might be connecting to a server that is pretending to be "login.microsoftonline.com" which could put your confidential information at risk., STATUS: 0" I have checked the MacBooks in Jamf Pro and they have the correct certificates installed. It is also only happening to these 2 devices so I'm not sure what could be causing the inability to sign in through Microsoft Azure.
Anyone in JAMFnation use it? Pros Cons? How bad is it to implement and have you seen any degradation on the Mac's? Thanks in advance.
Trying to configure it in our environment but can not seem to find the configuration profile setting for it. The white papers says:To add suggested Managed Apple ID Default Domains that will display on the login screen, click + Add a domain and enter the domain names. Each school domain must include the top-level domain, such as .com, .edu, .org, and so on:https://learn.jamf.com/en-US/bundle/security-focused-jamf-solution-guide-education/page/Configure_a_Secure_Environment_with_Shared_iPad_Using_Jamf_School.htmlBut this is for Jamf School and we user Jamf Pro Cloud and the corresponding setting do not seem to exist (or I'm just looking in the wrong place. The setting do not seem to show in pre-stage settings or as a configuration profile. Anyone have a clue how to manage this in Jamf Pro?
Afternoon All. Hoping someone can help have been trying to package Maya & Mudbox 2024 for serveral weeks and facing issues I think with the license demon not starting before its get licensed.I get below error from Jamf log connecting to Service failed: reading configuration file /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data failed: open /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data: no such file or directory connecting to Service failed: reading configuration file /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data failed: open /Library/Application Support/Autodesk/AdskLicensingService/AdskLicensingService.data: no such file or directoryMy scripting ablity isnt up to much, I think I just need a few lines in my current script to ensure the license demon is running before the license process starts. Can anyone help? Have tried a few scripts on here but keep facin
Build an Configuration Profile for test purpose set home folder to https://www.apple.com Profile is installed but Firefox don't react to it at all.Used the policies.json from here https://github.com/Jamf-Custom-Profile-Schemas/JSON-Schema-for-Jamf-Pro-Applications-and-Settings-MDM-Payload/blob/master/Mozilla/Firefox.jsonFireFox is installed with InstallomatorScreenshot: What am I missing?
Hello,Using JamfNow, I am able to enrol a Mac purchased via Apple business. (i.e. device was automatically inserted into ABM on purchase of device by Apple).I am able to use created blueprint within JamfNow to push the setup to the Mac.I have 1 issue, the status screen for the device says that Activation lock is not activated, when I look on the Mac looking at System Information I can see that activation lock is not activated. I have tried the various combinations of activating Find My on the Mac, deactivating, wiping the Mac, reinstalling. I have gone as far as wiping the Mac by erasing disk and reinstalling OS around 10 times trying the various combinations without luck.I have even have gone as far as removing the Mac from JamfNow and ABM and trying to get activation lock to activate outside of the ABM without success.My understanding is that while a user cannot remove the management profiles, they could wipe the Mac and reinstall using their own Apple ID or if stolen the
Since there's no configuration profile options for the IOS Microsoft Edge browser, I assume the only option I have to do any customization is to add XML to the App Configuration tab within the Edge Mobile app page. Does anyone have or can point me towards official guidance on Edge settings options using this method? Specifically, I am looking to disable Copilot in IOS Edge because it's driving people nuts in certain web-based apps. But it would be nice to have documentation on customizing any number of web browser settings if anyone has any. I've seen some references, but they all appear to apply to MacOS Edge and I need any information on configuration options for IOS Edge. Thanks!
Hey Everyone! We are looking to send out documentation to our fleet on how to enable and use TouchID on their macOS system should they want to. That being said, I am having a hard time determining which macOS systems in our fleet even support it. I am not looking for if it is enabled, disabled, or if fingerprints have been registered just trying to see if the touch sensor technology is even there on some systems in our fleet. Can this be accomplished with an Extension Attribute? If so, can anyone point me in the right direction? I tried like every one of them suggested in this thread but not working on 14.5 Sonoma as an EA or linked to a Smart Group: https://community.jamf.com/t5/jamf-pro/touchid-extension-attribute/m-p/170024 Looking to avoid painstakingly going through each model and looking it up, hah. Thank You!
We woud like to be able to monitor for changes to the sudoers file on Jamf Pro devices, via Jamf Protect.We tried creating a new custom analytic, but it does not seem to work during our testing - no events are logged in the Alerts tab. Anyone know if there is an issue with our setup? It wont let me add a screenshot, so here is the 'predicate' in the Summary tab for the analytic:( $event.isModified == 1 AND $event.path ==[cd] "/private/etc/sudoers" )The 'Event Type' is 'File System Event'
I've run into an issue with using Company Portal to register Macs in Entra for compliance purposes. It SEEMS to be a permissions issue. My admin account can register them, but my Joe Schmoe user account with no privileges can't. What I can't wring out of Microsoft or Jamf is what type of permissions my normal account might need to perform this action. We use Intune, not Jamf, for our mobile device management and we have Windows machines there as well. I can register or enroll all of those devices just fine, in testing. And my Admin account works just fine. Shows the device, compliance syncs over. All the fun bells and whistles. But with my regular account, I get this incredibly generic error when trying to even sign into Company Portal from the Self Service registration workflow... Anyone have any ideas what permissions/privileges our standard accounts might need to register Macs in Entra for compliance?
Is there any application that can be used for the iPad and Macbooks to record the screen as it goes through ADE? I want to be able to use this for training purposes for our staff and IT department to make how-to. I have a bezel but it doesn't allow the ability to record the enrollment screen when enrolling a new device through our prestage.
Can anyone explain why do some computers in Jamf drops the minor Operating System Version.ie. If I have two M3 computers with macOS 14.7.0 build (23H124)One show in Jamf as 14.7 and the other shows as 14.7.0 We have seen this for many minor releases and help in fixing this anomaly would be appreciated as it messes up our reporting.
Hi All, Has anyone got the script enable the migrating local account with cloud identify (Azure), Pleas see link for more information: https://learn.jamf.com/en-US/bundle/jamf-connect-documentation-current/page/Existing_Local_Account_Migrations.html Kind Regards
Hi Jamf Nation, Is there a remote lock script that someone can recommend for a Mac in Jamf Pro that not managed? (Can only be deploy by Jamf Pro)Also is there a script to turn Mac's from unmanaged to Managed in Jamf Pro? Thanks in Advance Nation!
Hey. Im trying to upgrade GoodNotes for Institutions into GoodNotes for Business. There is only an instruction how to install a license key for iPad/iPhone (https://support.goodnotes.com/hc/en-us/articles/7568710302607-Installing-Goodnotes-for-Business-Enterprise-via-Jamf-Pro?source=search&auth_token=eyJhbGciOiJIUzI1NiJ9.eyJhY2NvdW50X2lkIjoyNTM0NzUsInVzZXJfaWQiOjc3MDkxMDA4MjcwMjMsInRpY2tldF9pZCI6MjMzMjk5LCJjaGFubmVsX2lkIjo2MywidHlwZSI6IlNFQVJDSCIsImV4cCI6MTY5NTIyMjU1OX0.MN6d_0tdipaCu0_cJb_fbyPYt1kHRPpY9l69iLvegXo). Does someone know how I can install a license on MacBook via JamfPro?
so a s test with my lab systems i tried to re-enroll it to my admin account in JAMF to see if we can just hand over a system with out a re-images and now it's hung trying to install the JAMF profile will not let me delete the old one or over ride it. how should i have done this.It seem to cause other problem the systems show up in inventory but not when i try to add it to a policy.Any uninstall scripted that i should have used or is re-image the only option?
HI, we need to package Avaya Agent with specify config.xml that has the necessary settings. The Config.xml will need to be placed into User/username/ Library/Preferences/Avaya-Agent/ folder which only gets created after the app is opened the first time after installation. Has anyone had the same scenario and found a workaround / solution. Placing files into an user profile could be done with a postflight script but the folder does not exist yet and has a lot more then just that config.xml that is being created. Thanks in advance
Hello, I need to figure out how to run a policy to check screen saver time settings so we can force a set time if it doesn't match. I'd assume that you could check against a value in the "~/Library/Preferences/com.apple.screensaver.plist" but not sure. Any ideas? I see a lot of older posts floating around about forcing a screen saver time in various ways. I need to check the time first before doing that. Thanks!
HiWe are facing an issue where ex-employees have signed in with personal accounts on icloud on corporate devices. Its been a pain while re-purposing the device where find my mac cannot be removed . I know we can restrict signing in to personal accounds via configuration policy but management dont want to take that route at this point of time . 1. is there a way other than contacting apple support to remove find my mac from the computer while wiping it ?2. if we enable activation lock , will that help to erase or disable find my mac for users Any help would be appreciated, Thanks,
Our staff now has the error message " This provider is unavailable due to a device management profile" If we disable defender then they get access again. I cannot find any setting in the profiles that would be blocking OneDrive.
We have one VPP account hooked into our jamf pro cloud install. We did originally have an additional site set up which would create an global entry and an additional entry for the second site, but that was an inherited mistake which was since fixed. A couple of weeks ago I went through and started removing old apps or apps with no scope. Once there were fewer entries, I noticed that every time I added a new app to the Mobile Device Apps list, it would create an extra duplicate entry with the default options. We normally only do auto-install, but there's always a duplicate entry for the same app set to Make Available in Self Service with no scope. Why is this happening and how can I fix it?
Hey, We need to upload the personal recovery key from jamf to snipe using the jamf2snipe script. Any idea where i can find the subset to this? Thank you!
Hey Jamf Nation!Do you need to create a custom MacOS Dock for your users?I created a guide for the Jamf community, complete with scripts and packages, to help you do that.After struggling to find a current, working solution I decided to build one myself. Since it took some time to make, I thought I'd share it with others that are looking to do the same thing. Hope it's helpful!GitHub Repo with Full Guide Here: https://github.com/bluemoosegoose/Build-a-Custom-MacOS-Dock Some info about it:This Guide allows you to craft a custom MacOS dock for your environment, written specifically for Jamf Pro Admins.Verified working on Monterey 12.3.1 and should be backwards compatible.The custom dock will be built once, on first login, for any user that logs in to the Mac.After the dock has been built once, it will not run again automatically, which is the intended behavior because we want our users to have our custom dock during onboarding and then give them the ability to make ch
Hi everyone, I have a question about removing a device from inventory preload. for example, there are 10 devices in preload. I selected one of them and click delete it, will this action will delete the rest of 9 devices? just wanted to make sure the action only remove the devices I selectedBest Regards
I’m currently developing a remediation policy for Self Service that triggers the uninstall and reinstall of a profile. While I can successfully remove and reinstall the profile, I need a verification step to check if the profile was reinstalled. I'm using the following command:bashprofiles show -o stdout | grep "ProfileDisplayName = "$profileName"" | /usr/bin/awk '{print $3}' | sed 's/[[:punct:]]//g'This works perfectly for single-word profile names, like "Zoom," but fails with multi-word names, such as "Zoom Profile," resulting in "no such file or directory." I’ve tried enclosing the profile name in both single and double quotes, and using "${profileName}", but nothing seems to work.Could anyone suggest how to modify the command so it successfully handles profile names with more than one word? Here’s the function I created for verification:bashfunction checkInstall() {installed=$(profiles show -o stdout | grep "ProfileDisplayName = "$profileName"" | /usr/bin/awk '{print $3}' | sed 's/
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!