Get Support
Recently active
While testing the Temporary User Promotion feature I noticed that nothing happens when clicking the option in the menu bar. I have various attributes set as far as UserPromotionRole, UserPromotionReason, UserPromotionChoices. Any thoughts? Running on JC 2.37.0. com.jamf.connect plist<dict><key>Appearance</key><dict><key>MenubarIcon</key><string>********************</string><key>MenubarIconDark</key><string>*******************</string><key>ShowWelcomeWindow</key><false/></dict><key>CustomMenuItems</key><dict><key>getsoftware</key><string>Self Service</string></dict><key>HiddenMenuItems</key><array><string>preferences</string><string>quit</string></array><key>IdPSettings</key><dict><key>OktaAuthServer</key><string>***************<
Hi All, I have created the CyberArk config profile with below info and it got installed successfully. 1) Approved kernel extension with bundle id: DF8U2CCCD8 2) PPPC with the following: Identifier: com.cyberark.CyberArkEPMEndpointSecurityExtensionCode Requirement:anchor apple generic and identifier "com.cyberark.CyberArkEPMEndpointSecurityExtension" and (certificate leaf[field.1.2.840.113635.100.6.1.9] / exists / or certificate 1[field.1.2.840.113635.100.6.2.6] / exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists / and certificate leaf[subject.OU] = DF8U2CCCD8)Service:SystemPolicyAllFiles = Allow 3) System Extensions:It will not work with the Team ID only. In my testing you must add the system extension for this to work.Team ID: DF8U2CCCD8Allowed System Ext: com.cyberark.CyberArkEPMEndpointSecurityExtension I was executing the installer via below cmd as a script:sudo /private/tmp/Install CyberArk EPM.app/Contents/MacOS/CyberArkEPMInstaller -configuration /priv
Hello All,I'm not entirely sure what it is used for, but the DeclarativeManagement command is stuck pending for a lot of our MacBooks. I am seeing this issue during enrollment, and also in computers that have already been enrolled. It looks like this is a new Jamf command?During enrollment, the computers grab their profiles. Sometimes (and I don't know why it's only sometimes) the DeclarativeManagement command will come up during the profile installation part of enrollment. I noticed that when this happens, on the computer you see "Waiting for management server" and it will be stuck like this forever. If you cancel the DeclarativeManagement, the enrollment immediately continues. For the computers that have already been enrolled, DelcarativeManagement is randomly appearing in the pending commands. But since it gets stuck, it is also preventing other commands from completing. I need to cancel the DeclarativeManagement command and then
I am working on a remediation policy for Self Service that will trigger the uninstall and then reinstall of a profile. Doing this is easy to do. I created a smart group then excluded the smart group from the profile I was testing with. Once the policy causes the Mac to be added to the smart group, the profile gets removed. When the Mac is removed from the smart group the profile is installed again. But there's a problem... I wanted to have a step that would verify the the profile did get reinstalled. To do that, I used this command: profiles show -o stdout | grep "ProfileDisplayName = "ProfileName"" | /usr/bin/awk '{print $3}' | sed 's/[[:punct:]]//g') When I was testing this on my own Mac and a test Mac, I was testing removing a profile we have for Zoom. The profile is simply named "Zoom". The command above works perfectly for a profile named with just one word. If the profile is named something like "Zoom Profile" the command will output "no such file or directory". I have tried
What would cause a brand new computer to skip user creation right after an internet network is chosen? We have a few recent computers that went out and some of the computers in that shipment, seemingly upon choosing a network, enrolls the computer and the management user then goes straight to the login screen. Mind you that other computers from the same shipment worked/enrolled normally.
I don't usually discuss beta stuff in public channels, but this new "feature" is already being discussed publicly so I figured we should be good. macOS Sequoia adds weekly permission prompt for screenshot and screen recording apps - 9to5Mac Is it just me, or has Apple gone way past crossing the line of security notifications that they used to criticize Windows Vista over with UAC? Get a Mac - Vista Vs Mac - Security - New Mac Add (youtube.com)
Any suggestions on how to do this?
Hello! We are running macOS 14.6.1 on a fleet of iMac's and Macbook Pros. The Mac's can AirDrop to other devices (EG it can see my phone and sends files successfully to it) but the Mac itself doesn't appear to AirDrop too. (So I cannot AirDrop from my phone to the Mac). We've different various devices (Managed and non managed) and the Mac doesn't appear as an AirDrop destination of any of them. These devices are new so we can't test with other versions of macOS (So we don't know if it's a new thing or always been like this!). The Mac's are all MDM managed and we have tried being on the same WiFi network (And also not being on the same WiFi network). They have WiFi and Bluetooth enabled. We tried the solution here but it didn't make any difference (We checked, the command does the value correctly). Has anyone else seen this or have any ideas on how to fix it?! Thank you in advance
I am trying to setup managed favorites in Microsoft edge. can someone share a working plist for managed browsers in edge?My basic requirement is to have few URLs in managed favorites and then few URLs in folders structure something like this:url-Microsoft.comurl-Intune.microsoft.comJamf(folder) url-id.jamf.com url-jamfcloud.comInternal(folder) url-abc.com Appreciate your help in advanced.
Looking at the Jamf School API documentation, I have found it to be 'lacking'.Example:Devices - List DevicesGEThttps://api.zuludesk.com/devices This is incorrectIt should behttps://api.zuludesk.com/api/devices It would also help if they gave an example curl command like Jamf Pro API documentation has.
I am trying to retrieve the scope of apps, including the catalog and associated scopes/groups for my instance, but so far, I have been unable to fetch the app information as outlined in the API documentation at api.zuludesk.com. According to the documentation, the GET URL provided is as follows:https://{yourDomain}.jamfcloud.com/apps/:idthe response would include the serial number of the devices but I am only getting the following:","vendor":"Mathematics Rockx Pty Ltd","price":0,"isDeleted":false,"isDeviceAssignable":true,"is32BitOnly":false,"isCustomB2B":false,"deviceFamilies":["iphone","ipad","ipod"],"isTvOSCompatible":false,"isMacOsCompatible":false,"autoGrant":true,"autoRevoke":true,"totalLicenses":149,"usedLicenses":0,"availableLicenses":149,"isVppV2":false} #Script for testing purposes, retrive app ID#30 #Headers Authorization not included for security ------Python scriptAPP_DETAIL_URL = 'https://xxxx..jamfcloud.com/api/apps/30' # Headers for the GET request headers = { 'User-Ag
Hi, I am looking for some help to see if there is an existing JAMF Brand Computer Extension for reporting all local groups on a computer and\\or a particular group name. I would also like it to report all of its membership. ANy help is appreciated. Thanks!!
We had a device that was not able to be managed, so we tried to delete the device and remove the profile to re-enroll. We are not allowed to remove the MDM profile, and reinstalling the profile through self enrollment fails, stating "New profile does not meet criteria to replace existing profile". For additional info, this computer was part of a pre-stage enrollment originally.
We are after changing the naming convention for classes imported with ASM. Is there a way to mass delete the classes in there now? Thanks
Today we released Jamf Connect 2.39.0. This release includes the following changes and improvements: The Jamf Connect menu bar app now displays the temporary privilege elevation duration in the format "HH:MM:SS" to improve usability when elevating users for more than 60 minutes. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
We use Solarwinds for asset tracking and internal support. The installation instructions have you running a command to silently install. How would that be done? I'm used to Intune allowing your to run an install command but not sure where to do that here. Thanks.
Hello Jamf Nation! The Jamf Pro 11.10.0 Beta Release features several improvements including a new Self Service branding option, App Installers workflow enhancements and more. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions. The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
I can find the Apple calculator app using New in the Mobile Device Apps.When added it shows Content not available to assign to mobile devices under Managed Distribution. Also, I am unable to find it when searching in Apps and Books in Apple School Manager. I assume these apps are NOT device assignable. If that is correct then how do you get them onto a device? This only happens with Apple apps. I have no issues with any 3rd party apps. Any help would be appreciated. Thanks!
Hi Jamfers!Is there a way I can use authchanger to force Jamf Connect to display the 'local login' screen by default as opposed to the 'Azure Login' (or whichever IdP screen you might use)I've managed to use 'sudo authchanger -reset' to switch the Jamf Connect login window off, and 'sudo authchanger -reset -JamfConnect' to turn it back on, but I'd like our users to have easy access to the Azure login option should they require it. The reason: our on-prem WiFi uses 802.1x security and doesn't play nice with Jamf Connect, so users will have to switch to local login when on-site anyway. I'd just like to save them all one less click in the morning :-)We've looked into workarounds for the WiFi security but local login seems like it is going to be our best course of action as the alternatives would be more hassle than it is worth. Thanks for your help and time! Steve.
Our infra team changed the wifi password for an SSID that was also being user for an iPad in our office, the iPad itself is in single app mode by a configuration profile.Problem is, it cannot access the internet anymore and obviously jamf commands do not work on it, apart from wiping the machine itself, are there any other options we can use?
Hello together,I am currently looking for a solution to automatically create tickets when a device becomes uncompliant. We check the compliants with JAMF.I can have emails sent automatically with Smart Groups, but only to my user.Would I have to create a service user for this or is there another way?Many thanks in advance!Regards,Jonas
Is there a way to block specific sudo commands from being ran? Two specific commands that I have in mind are: sudo jamf removeFramework or sudo /usr/local/jamf/bin/jamf removeFramework sudo -s We don't want users with admin rights to be able to remove the Jamf framework, and we don't want them to be able to elevate their Terminal session to root. We use CyberArk EPM to allow non-admin users to run sudo commands that they need to run as part of their jobs. I recently discovered that non-admin users can run both of these commands with CyberArk installed. Both are very dangerous. We want to be able to allow legitimate admins to be able to run these commands. I sometimes have to run removeFramework to clear out issues with the Jamf agent or Jamf keychain issues. I also frequently elevate terminal sessions to root to be able to view the contents of certain directories where a normal sudo command won't do it. We just want our regular users to not be allowed to run these commands. I can't thi
I am trying to fetch all policies through an API call to endpoint `/JSSResource/policies`But I am getting only 25 policies, without any header of `next` `page` or something like this.How can I query for all policies and not just random 25 of them?Thanks in advance
Does anyone have an issue where Jamf's implementation of Service Now does not allow you to see tickets opened by others on your team? I opened a ticket to ask if this is on their radar and can we expect a fix. I got the usual boilerplate response (for this issue; second time opening a ticket):To confirm, the way our ServiceNow support portal is setup, admins can only see tickets in their portal that they have submitted under their Jamf ID.Service Now is highly configurable and customizable. Yes we know the ability to see each others' tickets is not currently possible. That was not our question.We want to know if the team that is responsible for the development of Jamf's Service Now implementation is aware of the issue/impact, and do they plan to fix it?I will not be submitting a Feature Request, because this is not a Jamf product issue. This is a Service Now implementation issue.Thoughts?
Will be getting a large end user department who got approved for Macs to use NPM/homebrew/Git, etc I know how to gather what's installed - but how do ya'll patch that stuff? Assuming you have a company policy that *any* install needs to be current - how would one approach that via Jamf? Sure, there are exceptions where a dev needs a certain build but how does one accomplish patching those packs via Jamf?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!