Get Support
Recently active
I am trying to locate a device that was previously assigned to a user so that I can deauthorize an app that was used on it. The guidance from the app provider (Kuta), says I need to log in on the old device to deauthorize it. Any help would be appreciated!
I recently deployed Cisco AMP and everything seem to be running without a problem, but after upgrading to MacOS 15 I'm asked to Allow Network Filter. Has anyone experience that or have a suggestion to approving it from JAMF Pro?
Today we are releasing a maintenance version of Jamf Pro; this release includes the following changes and improvements: New Keys for System Extension Payload Jamf Pro includes two new system extension types for computers with macOS 15* or later. In macOS 15*, end users can see and disable previously installed managed system extensions (e.g., endpoint security tools) through System Settings or Finder. You can use these new settings (Non-removable system extensions and Non-removable system extensions from UI) to prevent end users from removing these system extensions. If you use Jamf Protect, which runs as a system extension, Jamf strongly recommends configuring this new MDM setting to restrict users from disabling Jamf Protect. *Feature support is based on testing with the latest Apple beta releases. Resolved Issues Jamf Pro Server [PI119868] Syncing packages to all nodes in clustered environments (including Jamf Cloud-hosted environments) no longer requires extended time to co
Does anyone have any experience working with Talech register? Current client having an issue where the application wont work upon initial configuration profile install. Client found a work around by uninstalling the management profile manually - then the application works. However if at any time the application gets logged out - the app goes blank and the whole process of removing and reinstalling the profile manually starts over. Any help is appreciated.
I am installing Maya 2024 and I am running into this popup. I am able to get the license to verify via the network server when putting in my credentials. I haven't tried on a non-admin machine.I created a configuration profile with Managed Login Items, and added the Team Identifier/Bundle ID to it and deployed it to my machines and still getting the popup. I've not seen this popup before. Anyone have any info/experience on this?Here is the script I am using, with the AutoCad and Mudbox install lines removed: #!/bin/bash ### Install AutoDesk Combo 2023 (AutoCAD, Maya & MudBox) ### silently @ login window with network licenses (aka multi-user lab/classroom deploy) ### 2022.07.27 by JonW ### Simply update variables/products below the function section as desired ### Read the additional details at the end of the script for more clarity on licensing. ### Ensure: ### 1) installer app(s) re-packed from .dmg by Composer & deployed to /private/tmp (
I have found this excellent manifest example from @talkingmoose to show the basic force install of an extension. The extension makes use of extension settings that we want to pre-set. The instructions for doing this from the command line on Mac are here https://docs.deque.com/devtools-for-web/4/en/devtools-configuration#macos-policy-configuration. I have added a snippet of the PLIST file below as well. The question is - how do I configure these settings as part of the installation for the extension within Jamf?{ "title": "Google Chrome Extensions (com.google.Chrome)", "description": "Install extensions in Google Chrome", "__feedback": "bill@talkingmoose.net", "properties": { "ExtensionInstallForcelist": { "title": "Extension Install Forcelist", "description": "Add extension IDs. Paste the extension ID in front of the default text.", "property_order": 5, "type": "array", "items": {
So with the PPPC utility try to grant access to Word, Profile is uploaded to user but still admin rights necessary what am I missing?
Our school division uses Active Directory and managed Apple IDs. I currently allow personal Apple IDs to be set up on a computer. Some users have been granted administrative access on the computer they use because of the remote work they do. I have observed that when personal Apple IDs are used with an account when a software update is available it will prompt for authentication but the username section is greyed out with just their username, but even when using their current password it says try again. This also happens with some other things like require lock screen password. The lock screen issue just came to my attention today but the Software Update I've been getting around that by either remoting into the computer, logging into our local account and authenticating there or pushing out a Software Update policy in Jamf Pro to that computer. Does anyone know why this happens with personal Apple ID and how I can get around this? This seems to happen at l
Note: macOS Sequoia Beta topic here, but with the OS right around the corner I figured it is a good time to make a feature request prior to its release.Two of our engineers have been testing Sequoia in our environment in prep for the upcoming release. Everything seemed to be going smoothly for weeks until we tried to connect to our network on campus (both of us are telecommuters) while attending a team meeting. Upon connection attempt to our wireless network we get caught in a cycle of unable to verify our user certificates (required to connect to our network)We've found that this is due to the new feature in Sequoia called “Rotate Wifi Address” which randomizes the Mac Address of the system upon connecting to wifi. This is a per-network setting that can be manually toggled off.It appears ISE isn’t able to link our MacBooks to a hardware profile with this enabled, which may be causing it to deny the connection. I've scoured and have been unable to find any other call out
Hello,I'm working on Jamf Pro, I'm taking over the work of a colleague who has left. He set up "Zero Touch" and "DEPNotify", he set up an AD that is used to do Zero Touch. This AD is now only used for that. We are on Google. Is it possible to replace the AD with a Google LDAPS, without going through Jamf Connect, and thus directly create a user session and a password linked to their Google account?The existing configuration uses an Active Directory (AD) for authentication in the Zero Touch workflow, but this AD is now only used for this purpose.The goal is to remove the need for existing AD and integrate directly with Google authentication, without using Jamf Connect.The desired outcome is that users can authenticate with their Google accounts during Zero Touch deployment and have their Mac provisioned according to policy.Merci de votre aide.
We are running into issues getting our IPads registered through Intune by Jamf. We are using OFFICE365 GCCHIGH, which requires our devices to be compliant in order to access our resources. We have the configuration profile set. We are just stuck at the self service(registration intune) part. It works fine when we do it through the Mac, but with the IPads we’re stuck. Does anyone have advice on how to proceed or any best practices using GCCHIGH environment?
We have rolled out about 3000 iPads for K through 2nd graders. The students need to take a web-based test and the test requires popups. In JAMF, Restriction there is an option that allows popups and that seemed to work years ago. However, it does not seem to be working now. It seems like Safari has its own settings nowadays. We want to push out the "allow popup" settings to the web browser so the kids do not have to worry about that. Ideally, it would be good to have a setting like "allow popup for these web sites". I have tried Chrome and Firefox and various app config settings from what I could find on the internet, but nothing has worked yet. Are there any current recommendations with the modern web browsers?
We are deploying team via Jamf app catalogue I have started to notice when it updates it just install another verison next to old version. This doesnt seem to be happening on all machines across our site. I have been trying to build out a smart group to get an idea of how many machines are effected.I feel something like this should work but cant get it report reliable results. Does anyone have any suggustion for how I can better track this? Thanks
Hi Nation, we enrolled MDM for institutional iPhones (not BYOD). Now, after some time in production, our users complain, that they cannot copy and paste phone numbers from the managed Gmail app to iOS contacts app.The devices are fully managed, but the native iOS apps do not seem considered as managed apps, and the pasteboard is blocked. (Users did not add a private or managed Apple ID on the device.) Is there a way to "manage" the native iOS apps or consider them as trusted apps?Here are our current restrictions:- Documents from managed sources open in unmanaged destinations - restricted- Documents from unmanaged sources open in managed destinations - restricted- Pasteboard respects managed/unmanaged document restrictions - enforced- Managed apps can write contacts to unmanaged contacts accounts - restricted- Unmanaged apps to read contacts from managed contacts accounts - restrictedLooking forward to your thoughts or maybe a reference to anothe
Hi All, We did the update to a more recent version of Jamf Pro. We lost the Jamf Admin.app feature and now I'm having issues getting packages into Jamf Pro. I have tried using Jamf Sync, and also just copying the files directly to one of our FSD points. Then I create the package entry under Settings -> Computer Management -> Packages with the package filename as the display name and add the filename of the package and save. Here's what I am seeing: It's not even trying to install the package from an FSD. I had a similar situation a few weeks ago, and it just starting working on its own, so I am wondering do I have to do anything else for Jamf to 'see' the package? We have 24 FSD points, do I need to sync the file with each FSD? I thought it used to sync automatically if I added the file to the principal distribution point. Any info is helpful..
Is it possible to made smart groups when a specific configuration profile is installed So if I look for a config profile called "Extension" I would like to have a smart group on those computers who have this or not. I can of course create some EA, but doubt how to create this as script
This has been talked about a lot here and I see a lot of these posts, but man I cannot figure out what I am doing wrong. I am trying to write a script that will update a plist in the user folder as well as license the application upon installation. So I want the script to run post pkg install. I have this script and I am able to get it to run successfully locally, but clearly when jamf runs, it runs as root. I have actually tried several ways to get it to run as the user, without success. The most recent option I tried was from here: https://community.jamf.com/t5/jamf-pro/need-help-forcing-script-to-run-commands-under-current-logged-on/m-p/189391/thread-id/178192 #!/bin/bash#Get username#Open OffShoot to make sure nl.syncfactory.Hedge.Mac.plist existsmyuser="$(id -u -n)" echo "Username: $myuser" sleep 1 echo "OffShoot Will Open To Create nl.syncfactory.Hedge.Mac.plist" open /Applications/OffShoot.app sleep 2#Kill OffShoot ps -ef | grep OffShoot | grep -v grep | awk '{print $2}' |
Now that Apple deprecated the Disable of External Disks feature in their MDM framework with the release of Big Sur so this no longer functions as it did in previous versions on MacOS, has anyone been able to disable USB or USB Mass Storage Devices? I tried writing a script that unloaded the IOUSBMassStorageDriver.kext but that did not work. My company cannot have any flash drives connected to their macs but i cannot seem to get it to work. Any suggestions? We have about 50 2015 macs and the rest are 2019 USB-C macs.
I am trying to test this new Software Updates feature on some Sonoma computers. I have pushed some commands but am just now seeing the caveat that the first command is the only one that will run. (The first command I sent to my computer is not going to run!) My macOS computer is sitting at "Update in progress" where I pushed "Latest major version" without realizing that Apple released a major version yesterday that is blocked via Restricted Software.How do I cancel this existing Software Update attempt so that I can try pushing the Latest Minor Version? (Each time I try, I am presented with "Existing Plan For Device In Progress" err ExistingPlanForDeviceInProgress. I just need to clear the existing plan, right?
I'm seeing this issue with certain installers on Sonoma 14.6.1. When deploying via recurring check-in trigger, the policy just fails. When triggering via Self Service, I see the pop-up (attached) and after accepting and authenticating, the install works as expected. I've dug through some older threads to see if there was a problem with the Jamf and Terminal PPPC that we use but I can't find the issue! I've attached screenshots of the Config Profiles I've tried, also tried the one linked below but no joy! Please could someone help me find what I am missing!https://github.com/jamf/JamfPrivacyPreferencePolicyControlProfiles
I have a pair of Apple Silicon Mac's that are Jamf managed and a third that is vanilla, out of the box...no Jamf at all. What I am seeing is on the managed Mac's (M1 Air, M3 Pro) is that if they are either on WiFi or Ethernet via a docking station or a Belkin Ethernet dongle, when I restart the computer, it will show an IP address and give every indication that the computer is online. Reality though, they are not online. I have to unplug/plug back in the Ethernet or disable WiFi and reenable it. Only then will the computer be online. The out of the box Mac doesn't have this issue. My personal M1 Air, that I have just done update after update since its release...I don't have this issue. I have seen an uptick in WiFi at home dropping offline more often, but when I turn on the computer for the day, it will be connected.
Hello everyone,At the beginning of the year, we started our journey from leaving Novell in favor of Active Directory and MS Cloud. Now it's time to make adjustments for our Apple environment. We have chosen not to use Jamf Connect (initially) but rely on our supplier that they can do it well without (though not as well as with). But there are some important points for us to get across.- Not binding the units to ADs- Enable access to network volumes, own storage volume and sharedIs there anyone in the community who is in such an environment and what have you done to solve it? Or is there any specific way to go to solve it, recommendations?Then another little thing. We will (sadly) move part of our Apple environment to Intune for financial reasons. As I don't know much about Intune, I take the opportunity to ask the question if anyone here knows. Can we run Macs in Intune without binding them or is it a must on that side?
I have a Smart Group monitoring computers where the bootstrap token isn't escrowed. In the past week, I noticed a couple freshly wiped + re-enrolled computers (all on Sonoma 14.2 and 14.2.1), where the first user logging into the computer isn't getting the Secure Token or Volume Ownership. Also, the bootstrap token doesn't get escrowed. Background: in our 1:1 deployments, we have a PreStage-created, hidden local admin account. In this 1:1 PreStage, we have enrollment customization turned on, pointing to our SSO IdP. User gets a device, logs in through SSO, which populates their info into the local user creation screen. They enter their password again, and get logged into the device. Enrollment finishes, and for some reason Jamf is showing the PreStage admin account as the only Secure Token holder and Volume Owner. And as mentioned, bootstrap Token doesn't get escrowed. I can fix manually using sudo profiles install -type bootstraptoken, but trying to figure out why this is happeni
This might be a stupid question but here goes. I'm looking to use LAPS with Jamf and I can't seem to find the "ClientManagementID" for the API call./v2/local-admin-password/{clientManagementId}/account/{username}/passwordAny help will be appreciatedThanks in advance.
Hello All, I was wondering if anyone here has been able to successfully implement OneDrive Known folder move?We are trying to move user's Desktop and Documents folders to OneDrive, without any user interaction, we have tried to apply these settings using the Applications and Custom settings payload, we can see the CP in System preferences Profiles but nothing changes in Onedrive. Other settings like hide dock icon and open at login are successfully applied with the same CP.<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>KFMBlockOptOut</key> <true/> <key>KFMOptInWithWizard</key> <string>xxxxxxxxx</string> <key>KFMSilentOptIn</key> <string>xxxxxxxxx</string> <key>HideDockIcon</key> <true/> <key>OpenAtLogin&l
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!