Get Support
Recently active
We currently have multiple Pre-Stage Enrollments in place. One for Middle School Students, one for High School Students, one for Middle School Staff, and one for High School Staff. It has been recommended that we flatten our pre-stage one or two enrollments, however we assign the devices to a Site (Middle School/High School) during the enrollment process. This triggers Site Specific Policies to run (printer installs, software installs, etc.) and prep the device for use in that building. Were we to only have two enrollments (Staff and Student), What would be the best way to assign those devices to their respective sites after the fact, or do we have the most efficient setup? Additionally, we want to know if there's a way to Bulk Remove device records from devices that have been enrolled? Thank you for any suggestions you may have. -Micah
I’m trying to use a script in Jamf to send an email to a user. Specifically want to do this from a policy: policy installs a package, then emails that user some information.I’m trying to use the Python script from this page as a starting point: https://community.jamf.com/t5/jamf-pro/sending-an-email-via-script/m-p/186819.For testing purposes, I’m only running the script--I don’t have the package included in the policy so that I can focus on getting the script working.I haven’t used Python before. I’m guessing this script is just a skeleton and I need to do some additional things to get it to run, but I don’t know what those things are. I’ve filled in the SMTP_SERVER, SMTP_PORT, and SMTP_FROM values and had our Exchange/Outlook person verify they were correct.When I scope the policy to one of my test devices, the status in the log for the policy just says “Pending” and never changes. If I try running the policy by triggering it from Terminal (sudo jamf policy -trigger [name_of_pol
How do I install and Configure LogonBox VPN on MAC? Please help with this app. I have been trying to automate the installation of this app for a while but the command is not working and failing with the Installation Command Line Error.I am requesting the Steps to Automate this case.
So I have a configuration profile thats installable via execution URL:jamfselfservice://content?entity=configprofile&id=120&action=execute .Said config profile has the "Allow Removal" flag checked. Does JAMF Self Service have a "remove" URL similar to the execution URL , that I can use in Shell script, so I can have a non interactive , script triggered removal of the config profile?
We have recently enforced OKTA MFA for all our users and experiencing an unexpected behaviour on some of the user’s device. They users are prompted for 2FA on jamf login screen after native login, however we have not enforced any mfa on device level.Could anyone please assist in understanding why this is happening and any recommendation to avoid such prompts.Thanks,
I have an iMac that was in Apple School Manager. I meant to temporarily unassign it for troubleshooting purposes, but I think I must have released the device instead because now I am not able to add the serial number back into ASM. Apple Support told me that I'm basically out of luck and I can never add that computer back into our DEP ever again. They told me that it is essentially released forever. I can't believe that even Apple cannot help me re-assign this device, even with proof of ownership. Has this happened to anyone else? And if so, were you ever able to re-assign the device in ASM somehow?
I wanted to monitor if our Macs are doing their Microsoft Defender Full and Quick Scans properly in Jamf.As I couldn't find any solution out-of-the-box I came up with a custom script, in case anybody got the same need.The problem I faced, was that the Mac only saves the state of the last 7 scans (Quick and Full Scans are combined). So let's say you schedule your Quick Scans once per day and your full scans once per week and the user is on vacation only on the "Full-Scan-Day", you have no chance to see, if a full scan never ran or just the week before, but was overwritten by Quick Scans.That's why I came up with two different timestamps for the full scans, that one timestamp will always be in Jamf, to see when the last full scan ran, the second one might not really be needed, as it only checks the Full Scan within the last 7 scans.The script might be a bit fragile as it relies on Microsoft to keep the same format for the "mdatp scan list" command, but for now it works :)You will a
I am seeking help with a project. I have created a package within Adobe that I want to push to a Smart group.This package contains approved versions of specific Adobe software. I also need to downgrade the software it it exceeds the version.Any help will be appreciated.
It's extremely annoying that Jamf have decided to prevent Jamf Pro cloud instances from being upgraded before 14th September to v11.9.0, after already bumping v11.8.0 of Jamf Pro.It does not seem fair that we are still waiting for key features to be made available in Jamf Pro, which should have already been released months ago.Why Jamf are you making life so difficult with getting new key new features made available to Jamf Pro customers?
Hey all, Anybody managed to install Elastic agent via jamf pro? during the installation process, it asks whether I want to instal it in /Library/agent and I have yes/no options That is pausing the installation process and I need away to auto answer with yes !Thoughts?
Hello,I am trying to copy and paste this script https://github.com/Macjutsu/super/blob/5.0.0-beta2/super in to Jamf. It is close to 10,000 lines. When I copy and past short snippets of the script, Jamf allows me to save it, no problem. However, if I try to copy and paste the whole thing, I get a 403 error saying to contact my IT Administrator, which that is me. :) I don't have an issue copying and pasting other, smaller scripts. Is there a limit to how many lines you can paste and save at one time?Thank you ahead of time for your advice.
We are a school housed on a church campus which means there is often foot traffic in our rooms outside of school hours for church activities. We have our wifi ssids and the church has theirs, not tumultuous - we just have different needs to accommodate. We largely don't have an issue allowing the use of our technology, but recently noticed our Apple TVs connecting to the church's guest network. We obviously want to keep our devices on our network.Is it possible in Jamf School to restrict the ability to change Wi-Fi networks on TVos?
what are you guys/gals doing with the 'secure token' popup ? I don't have FV2 enabled and AD users are getting the popup, so we have them select 'bypass'. i created a configuration profile, using the custom settings payload i added this .plist file (com.apple.MCX as preference domain) <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict> <key>cachedaccounts.askForSecureTokenAuthBypass</key> <true/></dict></plist>
Hello,I installed the sccm plugin for jamf, but I have a problem. I have the synchronization which is carried out but the data does not appear in sccm.I looked in the logs of the plugin but I have no error, the xml files are well created.Have you encountered this problem before ? Regards
We deployed the new cisco secure client last week along with the new configuration profile. The profile installed on 341 devices and is pending on 54 devices. I spot checked some of the devices and they're online and checking in correctly, but the profile isn't installing and causing issues when trying to use the VPN. Any ideas other then restarting. These Mac's are currently running Sonoma.
Reading Jamf documentation on this is kind of confusing . During prestage enrollment for computers is activation lock automatically enabled? There is in option in the device prestage for a ios/ipad devices that allows you to turn this on, but for computers that option is not there but the jamf documentation seems to hint that its automatic for Macs? Also to check the status of actitation lock on the mac documentation is confusing. It says the Activation Lock status is displayed in the device's inventory information with a value of "Enabled" or "Not enabled". The device's status will show as "Not enabled" if Activation Lock was configured for the device in Apple Business Manager or Apple School Manager during enrollment. I'm asking this because I'm noticing Macs in apple school manger are showing as activation locked off even though we enroll our Macs through a prestage, Maybe I'm just confused and the Not enabled, activation locked off mean User activation lock is off and no
I see references to a Shared iPad setting for default domain that would help speed up logins for kids. Apparently it was in iOS 16?Is this functionality included in Jamf? I can't seem to find it anywhere.https://support.apple.com/en-is/HT213470https://www.jamf.com/blog/what-os-16-means-for-education/ https://developer.apple.com/documentation/devicemanagement/settingscommand/command/settings/shareddeviceconfiguration
Hello Jamf Nation! The Jamf Pro 11.8.0 Beta Release features a number of exciting improvements and enhancements for managing your Apple devices. Starting with 11.8.0, Jamf Pro admins will be able to set a minimum OS for MacBooks, iPhones, and iPads through prestage enrollment. Intune Platform Single Sign-on is now supported, alleviating end-user password fatigue. New Configuration Profile keys are introduced for MAC address randomization on macOS, Lockdown Mode, and more. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions. The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com
Hey all,I'm attempting to use the JAMF Pro API to wipe a computer via MDM. I'm using the "Try it out" feature in the API page on our Jamf Pro instance, to make sure I'm not missing anything.Here's the request: curl -X 'POST' \\ 'https://[OUR JAMF INSTANCE]:8443/api/v2/mdm/commands' \\ -H 'accept: application/json' \\ -H 'Authorization: Bearer [TOKEN REMOVED]' \\ -H 'Content-Type: application/json' \\ -d '{ "clientData": [ { "managementId": "74EDC9D1-FB3F-5E28-BA0F-3E71E88FB00E" } ], "commandData": { "commandType": "ERASE_DEVICE", "pin": "123456" } }' And the response: { "httpStatus": 500, "errors": [ { "code": "SYSTEM_EXCEPTION", "description": "Unable to perform MDM operation", "id": "0", "field": null } ] } This is strange. We're able to wipe a device just fine using the "Wipe Computer" button on the computer's "Management" tab in the web interface.The PIN is correct, and the computer ID
Today we are releasing Jamf Pro 11.9. Highlights include: Compatibility with Apple Operating SystemsCompatibility and new feature support are based on testing with the latest Apple beta releases of macOS Sequoia 15, iOS 18, iPadOS 18, tvOS 18, visionOS 2, and watchOS 11. Minimum OS EnforcementWhen you enroll computers and mobile devices with Jamf Pro via Automated Device Enrollment, you can use a PreStage enrollment to specify a minimum operating system version the device must have before continuing enrollment. When a device does not have the operating system you specified in Jamf Pro, the user is prompted to update the device before Setup Assistant continues. This feature enhances your organization's security by ensuring devices have the required operating system version the moment they are enrolled. Automated Device Enrollment for Apple Vision ProOrganizations can enroll institutionally owned Apple Vision Pro devices with Jamf Pro using Automated Device Enrollment. Automated De
We are having issues where Secure Token is not being assigned to the first user who logs in. (I THINK this started in mid-July, but am no 100% sure) In fact, according to an extension attribute we use to see who has Secure Token, no one has Secure Token on the Macs in question. This has caused endless issues including being unable to install macOS updates. This appears to be happening only on our faculty/staff machines, which are Filevault enabled. It does not appear to happen on our lab machines, with do not have Filevault enabled. I can't think of any changes we made in mid-July that would cause this issue. Our Macs are bound to Active Directory (yes, I know, that's not recommended, but due to security software we use such as Admin by Request, we must do so.) The end user is the first person to log into the Mac. Our users are not admins on their machines, but can get admin privileges temporarily using Admin By Request.&
I hope everyone is doing well! I've been working in the IT help desk domain since 2020. I'd like to switch to endpoint management or JAMF Admin, and I intend to enroll JAMF 200 by the end of next month. However, before I do that, I need some Clarification on the following points.1. What information is required of me previous to the course?2. Will there be lab access? If so, for how long?3. Will study materials be distributed?4.Will the video recording be shared?Kindly let me know if there is anything else I should know.Thankyou all.
Any one know why this is restricted to JAMF cloud? With DDM and macOS14+ I can't see how JAMF cloud would be needed at all
I received notice that my SSO cert is expiring in a few weeks and I can not find anything on what the process is to update it. I talked to the person that runs our AD side and he doesn't remember ever doing this so he wasn't sure if this autoupdates automatically. Any advice on where to start would be much appreciated! Thanks!
I have a problem with a few users (SVP's) who are getting the error message when checking to see if chrome is updated. They go to about chrome and the error shows below. We have uninstalled chrome multiple times, I've tried looking up this error message no info found on it, I've put in support tickets unfortunately nothing has worked, I've manually pushed out chrome via a policy and the error still appears I'm now doing the Mac apps the device is up to date but this error message still appears, even when the user was 5 versions behind last year this message appeared. HELP!!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!