Get Support
Recently active
I am doing some testing with macOS 15 before any widespread deployment.I use Jamf Pro polices and packages to update Jamf Connect to the newest version (currently 2.39).On macOS 13.6.7 and 14.6.1 the policy runs fine without any issues however on macOS 15 it is giving me an integrity error:Verifying package integrity...Installation failed. The package could not be verified.I can install Jamf Connect 2.39 directly via the dmg file and JamfConnect.pkg file on macOS 15, however this is not practical as most of the managed computers are offsite.This seems to be an Apple integrity check issue. Any thoughts on how to work around this issue.Thanks
I am able to successfully build & deploy custom preferences using the Application and Custom Settings on Configuration Profiles. What's not working is just the AllowTenantList setting. I think it's a syntax problem so any help would be greatly appreciated. M$ website to deploy & configure on macOS says: The example for this setting in the .plist file is:<key>AllowTenantList</key><array><dict><key>TenantId1</key><Bool>True</Bool><key>TenantId2</key><Bool>True</Bool></dict></array> We only have the one tenant ID so this looks like:<key>AllowTenantList</key><array><dict><key>My_Company's_Key</key><Bool>True</Bool></dict></array> Before I save the config profile, Jamf shows a summary of the settings. All the boolean keys are showing their correct true/false, but this string just says " AllowTenantList=[{}] " inst
OverviewDeploying bookmarks as an admin is deeply off putting. Every web browser does it differently, files change often and if you do it wrong, your users lose 100's of saved websites that they have accumulated over the years. Using a configuration profile to toggle a setting enforces that setting on a device when the profile installed. By pushing bookmarks into Google Chrome in this fashion, they end up in a managed bookmarks folder that:- the user is not able to change.- has no effect on the user's existing bookmarks.I have not found a great step-by-step guide to perform this task online so here's my attempt at this. Feedback is not only welcome but encouraged.You will need the following:1. A macOS device2. Basic knowledge of the Terminal application (or Xterm or similar)3. The ability to create, read & update a computer configuration profile in the JSS.Part 1: Use Terminal to create a basic .plist file1. Open Applications > Utilities > Terminal.app2. Run the following com
Ok, to start I'm brand new to JAMF and Mac management in general, so please bear with me. This post is kind of two-fold. I'm trying to figure out expected behavior and possibly some guidance on whether or not what we have in place is the best way to do this kind of thing. Basically, we have Network configurations that set up our Wired and Wifi Network connections and configure for 802.1x authentication. We have some expired certs to servers that no longer exist that I've been asked to remove, and I also have been asked to "fix" the connection to handle the MAC address randomization that is turned on by default for MacOS Sequoia. The profiles (wired and wifi) both have a certificate chain, a network connection and a SCEP cert that is used for user auth.In order to test, I've made a copy of the existing profile, and moved a few devices over to it.As soon as the test profile hits, the devices are disconnected from the network, because it appears it removes the existing network connection
Our 802.1x network has been working for more then a years, but again and again I have seen the isse, where users first time they connect got the attached image. The user certificate is located in the users login keychain - I don´t know if that has anything to do with it We use network payload - and just asking me if this somehow can be stopped so this popup will not appear anymore.
Our current environment uses the user name to inject credentials in kerberos for use with Okta. I'm trying to create a script to change the user name / home folder name to mirror their user name in our Active Directory environment.
We are having an odd issue on a couple of our macs (both iMac and MacBook).The menu bar disappears, and you then cannot type, you can see apps in Applications but not select them, you can get Spotlight up but you cannot type into it. Not happening to many but quite an odd issue with no pattern that I can discern.Having Googled it and tried the suggestions of Disk 1st Aid and starting in Safe Mode, neither worked. Also tried reinstall of the OS which worked for a while but the issue came back. Tried user profile removal and then adding back in which seemed to work for a few weeks but the issue has just returned for the same user. So wondering if anybody else has had this issue, and has anyone got any solution/suggestions?Many thanks
We've been using an ACDS for several years to push certs to our devices now but in the last couple of weeks we're getting an error: "unable to decrypt profile".I can see the the ADCS server is receiving the request from Jamf Pro, the CA is creating the cert and we're getting a 200 response back on IIS when I look at the ADCS server but the ceritificate isn't added under the devices -> certificates and it fails to push out saying failed to decrypt profile.The Jamf server logs show the below:2024-09-23 19:33:01,274 [ERROR] [Pki-Pool-31] [ertificatePayloadInjector] - Failed to get pending PKI payload certificatecom.jamfsoftware.jss.core.service.certapi.CertificateRequestServiceException: Request has failed with status INTERNAL_ERROR. Initiate another request in the future.at com.jamfsoftware.jss.objects.pki.adcs.AdcsCertificatePayloadInjector.retrieveCertificate(AdcsCertificatePayloadInjector.java:151) ~[classes/:?]at com.jamfsoftware.jss.objects.pki.adcs.AdcsCertificatePayloadInjector
Hey there,I am currently working to black Sequoia Beta and eventually the Public Release. At the time of this post, Beta 3 is available. I have been trying to find the right process name to use to block the app from installing in "Restricted Software". I've used "Sequoia" *Sequoia "Install macOS Sequoia Beta" "Install macOS Sequoia Beta.app" Just wanted to share currently the one that works is "macOS Sequoia 15 Beta"
Hello, We are having issues with Configuration Profiles. When we push out any configuration profile to machines, we often have this error "Unable to decrypt encrypted profile" when checking to see if it failed in the JSS. Usually if we use terminal and do either sudo jamf recon or sudo jamf manage commands it goes through, but it is not any more. We also just implemented more vLANs in our environment, but all of the other Casper functions like Remote, JSS Policies, Self Service, Managed Preferences, etc work normally. I checked the SSL and Tomcat tickets to make sure they were up to date and they are good. We are using Version 9.32. Any light on this would be great! Ryan
Hello guys,I would like to set a password to pass the prestage enrollement page. I can't find anything on this topic. Do you have any ideas? Thanks.
This happened across our org with no changes in azure or JAMF pro. Unsure of what is causing the issue. We've never had to set up a configuration profile for OneDrive prior to this.Has anyone seen this before?
Hi All,We use iPads with our TK-2nd grade students. We are coming across an issue where they have lots of Safari tabs open. A co-worker found one with over 100 tabs open. Is there a way to have these close after so many days? I know it can be done manually on each device but we have over 2000 devices out and that would be insane to try and take care of individually.Thanks!
I've tried importing the CSV file using the updated MUT format, however it isn't transferring to JAMF.
Hello all, I've been having quite a frustrating time trying to re-enroll one of our iPads to Jamf Pro recently and I feel like I've run out of thing to try so I'm hoping someone can lead me in the right direction or inspire a new way to try and get this thing running again. Heres whats going on and ill try to keep it brief:- iPad at our organization was having trouble opening multiple apps (select app, would come up for a moment and crash).- Tried multiple things to fix but no luck so I resorted to un-enrolling the device, wiping it and start from scratch. - Tried to re-enroll the iPad via Apple Configurator 2 and have run into multiple errors Provisional enrollment failed. [MCCloudConfigErrorDomain - 0x80EF(33007)] being the most common.- I've managed to re-enroll the iPad on our ASM but I'm hit with other errors now: "The configuration for your iPad could not be downloaded from organization ... cancelled" or in some cases a popup stating the iPad is not "supervise
I am just now starting to deploy mobile devices so forgive me for any lack of basic knowledge. I am assigning users in my domain a Managed Apple ID so we can manage and regulate purchases and such. But my users have reported not being able to use the AppStore. I read online this is not allowed for Managed Apple ID's. Am I going about this wrong because at this point I don't think I even need to use them as I can do most of everything in Jamf. Wipe, release activation locks etc. Should I just drop them and use personal ID's? My ORG wants managed for purchases. Am I going about this incorrectly? Any advice is welcomed and thanks in advance. Also, JNUC 19 around the corner!!
At present I am facing difficulties in deploying packages using Jamf Pro and I'm unsure of where I might be making mistakes. If anyone has experience with this and could provide some insight, I would greatly appreciate it.
Good morning,I hope you can help me, I know it is possible to block YouTube on Safari using the blacklist settings to block the site (YouTube). The problem is that we have some teachers who use Google Classroom and who send some links (Youtube) so the students can do their work.The problem starts there, YouTube being blocked, it is not possible to open the links that teachers send to YouTube, does anyone know a solution for this?Make it possible to just open the links that the teachers send.This is happening with iPad profiles.Thank you very much
A quick-and-dirty Jamf Pro Policy hack for testing Microsoft_Office_Reset_2.0.0.pkg Introduction Office-Reset is a free downloadable tool from @pbowden that Mac Admins can use to fix problems and errors encountered with Microsoft Office for Mac apps and version 2.0 Beta 1 includes more than two dozen changes. The following quick-and-dirty hack will allow Jamf Pro admins to easy deploy the entire Microsoft_Office_Reset_2.0.0.pkg during the beta phase before the app-specific .PKGs are available. Continue reading …
Hi AllDoes anyone know how I could create a group to filter out and display iPads that do not have an app installed? For example, because one or the other iPad was offline during distribution or does not communicate with the Jamf.Thanks Peter
Hello, During Auto Device Enrollment the users local accounts are created using either E# (employee) or LC# (contractor). On occasion we have LC's come on as employees and switch from LC# to E#. So, the local user account stays as LC# and then all sorts of issues start to occur on the Mac. In the past we have just wiped the mac and enrolled it again so it grabs their new E# account and leaves no trace of the LC#.If I recall I've been told that running "sudo profiles renew -type enrollment" should fix it but I have not had that work for me.Is there some way we can get the local user account to change from LC# to E# without erasing the Mac? PS. I do go into our jamf instance and change the account there from LC# to E# by searching in our user database in jamf but this obviously does not correct the issue on the Mac.
I am currently experiencing issues with our Shared iPads. In Shared Mode, it is no longer possible to log in with a guest account. The button and the option on the lock screen no longer appear. This affects both previously configured iPads and newly set up devices.I found a temporary solution by enabling "Allow only temporary sessions" in the Shared profile. However, this prevents users from signing in with an Apple ID, which limits the usefulness of this fix.Initially, we suspected the issue was related to the iOS 18 update. However, the same problem occurs on iPads running iOS versions 17.5.1 and 17.6.1, indicating that the issue is not specific to iOS 18.
Greetings!I currently work at a school which manages students' iPads through Jamf School, which works really well in most cases.We have configured a dynamic group whose member scope is based on a region which is determined by the school's public IP which is fixed. In most cases this setup works flawlessly.However, with some devices this does not work, which means that upon returning home and even rebooting their devices students' iPads are still treated as if they were on campus. I can only undo this by manually refreshing the device status/network details. Even when the iPads receive a new IP, Gateway etc. from their home dhcp server, the public IP is unaltered and thus the restriction profile is not removed. This can not be explained by a flawed configuration of the private networks either, since in case of siblings one iPad uninstalls the restriction profile as expected, whereas the other does not.This also "works" the other way around: When students arrive on campus and connect to
Can someone explain why the Device Inventory user interface in Jamf School has changed from the previous (legacy) version? I see from this post on Jamf Nation: This change doesn’t just offer a new look but improved speed when loading devices. For schools with large deployments, this means you can manage your Apple devices in an even faster and improved manner with quicker loading and bulk commands. We manage almost 5200 iPads, and while I’ve noticed more success with bulk operations, the need to constantly deselect before selecting a new set of 500 iPads is time-consuming. I would prefer a slower interface if it meant avoiding accidental bulk operations. For instance, I accidentally erased 20 Apple TVs before fully understanding the new system. There have also been instances where I refreshed unintended devices because I forgot to deselect them. I appreciate that the new interface shows the storage of each iPad, not just the remaining storage (though this feature works inconsiste
I have completed the vpp configuration of the app and put it in selfservice. The problem is that some ipads will prompt when downloading: the certificate of the App "com.apple.Keynote" cannot be found. As a result, normal installation cannot be achievedHow can I do next.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!