Get Support
Recently active
So with the PPPC utility try to grant access to Word, Profile is uploaded to user but still admin rights necessary what am I missing?
Our school division uses Active Directory and managed Apple IDs. I currently allow personal Apple IDs to be set up on a computer. Some users have been granted administrative access on the computer they use because of the remote work they do. I have observed that when personal Apple IDs are used with an account when a software update is available it will prompt for authentication but the username section is greyed out with just their username, but even when using their current password it says try again. This also happens with some other things like require lock screen password. The lock screen issue just came to my attention today but the Software Update I've been getting around that by either remoting into the computer, logging into our local account and authenticating there or pushing out a Software Update policy in Jamf Pro to that computer. Does anyone know why this happens with personal Apple ID and how I can get around this? This seems to happen at l
Note: macOS Sequoia Beta topic here, but with the OS right around the corner I figured it is a good time to make a feature request prior to its release.Two of our engineers have been testing Sequoia in our environment in prep for the upcoming release. Everything seemed to be going smoothly for weeks until we tried to connect to our network on campus (both of us are telecommuters) while attending a team meeting. Upon connection attempt to our wireless network we get caught in a cycle of unable to verify our user certificates (required to connect to our network)We've found that this is due to the new feature in Sequoia called “Rotate Wifi Address” which randomizes the Mac Address of the system upon connecting to wifi. This is a per-network setting that can be manually toggled off.It appears ISE isn’t able to link our MacBooks to a hardware profile with this enabled, which may be causing it to deny the connection. I've scoured and have been unable to find any other call out
Hello,I'm working on Jamf Pro, I'm taking over the work of a colleague who has left. He set up "Zero Touch" and "DEPNotify", he set up an AD that is used to do Zero Touch. This AD is now only used for that. We are on Google. Is it possible to replace the AD with a Google LDAPS, without going through Jamf Connect, and thus directly create a user session and a password linked to their Google account?The existing configuration uses an Active Directory (AD) for authentication in the Zero Touch workflow, but this AD is now only used for this purpose.The goal is to remove the need for existing AD and integrate directly with Google authentication, without using Jamf Connect.The desired outcome is that users can authenticate with their Google accounts during Zero Touch deployment and have their Mac provisioned according to policy.Merci de votre aide.
We are running into issues getting our IPads registered through Intune by Jamf. We are using OFFICE365 GCCHIGH, which requires our devices to be compliant in order to access our resources. We have the configuration profile set. We are just stuck at the self service(registration intune) part. It works fine when we do it through the Mac, but with the IPads we’re stuck. Does anyone have advice on how to proceed or any best practices using GCCHIGH environment?
We have rolled out about 3000 iPads for K through 2nd graders. The students need to take a web-based test and the test requires popups. In JAMF, Restriction there is an option that allows popups and that seemed to work years ago. However, it does not seem to be working now. It seems like Safari has its own settings nowadays. We want to push out the "allow popup" settings to the web browser so the kids do not have to worry about that. Ideally, it would be good to have a setting like "allow popup for these web sites". I have tried Chrome and Firefox and various app config settings from what I could find on the internet, but nothing has worked yet. Are there any current recommendations with the modern web browsers?
We are deploying team via Jamf app catalogue I have started to notice when it updates it just install another verison next to old version. This doesnt seem to be happening on all machines across our site. I have been trying to build out a smart group to get an idea of how many machines are effected.I feel something like this should work but cant get it report reliable results. Does anyone have any suggustion for how I can better track this? Thanks
Hi Nation, we enrolled MDM for institutional iPhones (not BYOD). Now, after some time in production, our users complain, that they cannot copy and paste phone numbers from the managed Gmail app to iOS contacts app.The devices are fully managed, but the native iOS apps do not seem considered as managed apps, and the pasteboard is blocked. (Users did not add a private or managed Apple ID on the device.) Is there a way to "manage" the native iOS apps or consider them as trusted apps?Here are our current restrictions:- Documents from managed sources open in unmanaged destinations - restricted- Documents from unmanaged sources open in managed destinations - restricted- Pasteboard respects managed/unmanaged document restrictions - enforced- Managed apps can write contacts to unmanaged contacts accounts - restricted- Unmanaged apps to read contacts from managed contacts accounts - restrictedLooking forward to your thoughts or maybe a reference to anothe
Hi All, We did the update to a more recent version of Jamf Pro. We lost the Jamf Admin.app feature and now I'm having issues getting packages into Jamf Pro. I have tried using Jamf Sync, and also just copying the files directly to one of our FSD points. Then I create the package entry under Settings -> Computer Management -> Packages with the package filename as the display name and add the filename of the package and save. Here's what I am seeing: It's not even trying to install the package from an FSD. I had a similar situation a few weeks ago, and it just starting working on its own, so I am wondering do I have to do anything else for Jamf to 'see' the package? We have 24 FSD points, do I need to sync the file with each FSD? I thought it used to sync automatically if I added the file to the principal distribution point. Any info is helpful..
Is it possible to made smart groups when a specific configuration profile is installed So if I look for a config profile called "Extension" I would like to have a smart group on those computers who have this or not. I can of course create some EA, but doubt how to create this as script
This has been talked about a lot here and I see a lot of these posts, but man I cannot figure out what I am doing wrong. I am trying to write a script that will update a plist in the user folder as well as license the application upon installation. So I want the script to run post pkg install. I have this script and I am able to get it to run successfully locally, but clearly when jamf runs, it runs as root. I have actually tried several ways to get it to run as the user, without success. The most recent option I tried was from here: https://community.jamf.com/t5/jamf-pro/need-help-forcing-script-to-run-commands-under-current-logged-on/m-p/189391/thread-id/178192 #!/bin/bash#Get username#Open OffShoot to make sure nl.syncfactory.Hedge.Mac.plist existsmyuser="$(id -u -n)" echo "Username: $myuser" sleep 1 echo "OffShoot Will Open To Create nl.syncfactory.Hedge.Mac.plist" open /Applications/OffShoot.app sleep 2#Kill OffShoot ps -ef | grep OffShoot | grep -v grep | awk '{print $2}' |
Now that Apple deprecated the Disable of External Disks feature in their MDM framework with the release of Big Sur so this no longer functions as it did in previous versions on MacOS, has anyone been able to disable USB or USB Mass Storage Devices? I tried writing a script that unloaded the IOUSBMassStorageDriver.kext but that did not work. My company cannot have any flash drives connected to their macs but i cannot seem to get it to work. Any suggestions? We have about 50 2015 macs and the rest are 2019 USB-C macs.
I am trying to test this new Software Updates feature on some Sonoma computers. I have pushed some commands but am just now seeing the caveat that the first command is the only one that will run. (The first command I sent to my computer is not going to run!) My macOS computer is sitting at "Update in progress" where I pushed "Latest major version" without realizing that Apple released a major version yesterday that is blocked via Restricted Software.How do I cancel this existing Software Update attempt so that I can try pushing the Latest Minor Version? (Each time I try, I am presented with "Existing Plan For Device In Progress" err ExistingPlanForDeviceInProgress. I just need to clear the existing plan, right?
I'm seeing this issue with certain installers on Sonoma 14.6.1. When deploying via recurring check-in trigger, the policy just fails. When triggering via Self Service, I see the pop-up (attached) and after accepting and authenticating, the install works as expected. I've dug through some older threads to see if there was a problem with the Jamf and Terminal PPPC that we use but I can't find the issue! I've attached screenshots of the Config Profiles I've tried, also tried the one linked below but no joy! Please could someone help me find what I am missing!https://github.com/jamf/JamfPrivacyPreferencePolicyControlProfiles
I have a pair of Apple Silicon Mac's that are Jamf managed and a third that is vanilla, out of the box...no Jamf at all. What I am seeing is on the managed Mac's (M1 Air, M3 Pro) is that if they are either on WiFi or Ethernet via a docking station or a Belkin Ethernet dongle, when I restart the computer, it will show an IP address and give every indication that the computer is online. Reality though, they are not online. I have to unplug/plug back in the Ethernet or disable WiFi and reenable it. Only then will the computer be online. The out of the box Mac doesn't have this issue. My personal M1 Air, that I have just done update after update since its release...I don't have this issue. I have seen an uptick in WiFi at home dropping offline more often, but when I turn on the computer for the day, it will be connected.
Hello everyone,At the beginning of the year, we started our journey from leaving Novell in favor of Active Directory and MS Cloud. Now it's time to make adjustments for our Apple environment. We have chosen not to use Jamf Connect (initially) but rely on our supplier that they can do it well without (though not as well as with). But there are some important points for us to get across.- Not binding the units to ADs- Enable access to network volumes, own storage volume and sharedIs there anyone in the community who is in such an environment and what have you done to solve it? Or is there any specific way to go to solve it, recommendations?Then another little thing. We will (sadly) move part of our Apple environment to Intune for financial reasons. As I don't know much about Intune, I take the opportunity to ask the question if anyone here knows. Can we run Macs in Intune without binding them or is it a must on that side?
I have a Smart Group monitoring computers where the bootstrap token isn't escrowed. In the past week, I noticed a couple freshly wiped + re-enrolled computers (all on Sonoma 14.2 and 14.2.1), where the first user logging into the computer isn't getting the Secure Token or Volume Ownership. Also, the bootstrap token doesn't get escrowed. Background: in our 1:1 deployments, we have a PreStage-created, hidden local admin account. In this 1:1 PreStage, we have enrollment customization turned on, pointing to our SSO IdP. User gets a device, logs in through SSO, which populates their info into the local user creation screen. They enter their password again, and get logged into the device. Enrollment finishes, and for some reason Jamf is showing the PreStage admin account as the only Secure Token holder and Volume Owner. And as mentioned, bootstrap Token doesn't get escrowed. I can fix manually using sudo profiles install -type bootstraptoken, but trying to figure out why this is happeni
This might be a stupid question but here goes. I'm looking to use LAPS with Jamf and I can't seem to find the "ClientManagementID" for the API call./v2/local-admin-password/{clientManagementId}/account/{username}/passwordAny help will be appreciatedThanks in advance.
Hello All, I was wondering if anyone here has been able to successfully implement OneDrive Known folder move?We are trying to move user's Desktop and Documents folders to OneDrive, without any user interaction, we have tried to apply these settings using the Applications and Custom settings payload, we can see the CP in System preferences Profiles but nothing changes in Onedrive. Other settings like hide dock icon and open at login are successfully applied with the same CP.<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>KFMBlockOptOut</key> <true/> <key>KFMOptInWithWizard</key> <string>xxxxxxxxx</string> <key>KFMSilentOptIn</key> <string>xxxxxxxxx</string> <key>HideDockIcon</key> <true/> <key>OpenAtLogin&l
Apple Classroom - Students show up, but as "offline" in the teachers classroom console. We are using Securly SMART Pac. The students Ipad are getting the classroom profile, so that seems to be working. Any ideas? Firewall port? Smart Pac issue? I'm grasping at straws here. Thanks for your help.
Hi,Just in case anyone is struggling with the Cisco Secure Client deployment, modification of the xml file, etc etc, below is the step by step guide offered by Jamf Support, it differs slightly from the guide here - How to deploy Cisco Secure Client via JAMF (MacOS) – Cisco Umbrella ( Which is still great for the configuration profile setup ) 1. Download cisco-secure-client-macos-#.#.#####-predeploy-k9.dmg from Cisco's Download site2. Double click the DMG to mount it. You should see the items below.3. Create a temporary folder to store files. For example:* Click shift+command+G on the keyboard, enter /Users/Shared/, and click enter.* Right click and select New Folder.* Enter folder name, i.e: CiscoSecureClient4. Drag and drop Cisco Secure Client.pkg and Profiles from mounted DMG to the folder you created in the previous step.5.Open terminal and navigate to the folder you created above (i.e. cd /Users/Shared/CiscoSecureClient) then run the following command:* installer -
Hello,Our organization utilizes Microsoft PowerApps Portal to foster a community for our macOS users, providing a space to share ideas, tips, and best practices. We are looking to implement notifications, either through Jamf’s Self Service portal or the Mac notification center, to alert users when new posts are made. If anyone has experience with integrating notifications between PowerApps and Jamf, or can provide guidance, it would be greatly appreciated.
Anyone else getting 503 errors from Jamf Pro
Think i missed something in the install i followed the instructions and from a video done about a year or two ago and i get that cannot reopen error i ran the log command and i do see the JSON missing error and i can see it in the setup but i am guessing it's not installing it Nudge -simulate-os-version "14.2" -disable-random-delayzsh: command not found: NudgeIT Admin@jason-zs-mini MacOS % log stream --predicate 'subsystem == "com.github.macadmins.Nudge"' --style syslog --color noneFiltering the log data using "subsystem == "com.github.macadmins.Nudge""Timestamp (process)[PID] 2024-09-17 15:42:24.183975-0500 localhost Nudge[627]: [com.github.macadmins.Nudge:user-interface] Finished delay2024-09-17 15:42:24.190505-0500 localhost Nudge[627]: [com.github.macadmins.Nudge:sofa] Failed to decode previously cached
Hi there, I am trying to automate some processes based on our LDAP integration. At this we have a stable integration with our LDAP and all the tests are successful. (Settings: System > LDAP servers).Group Names and GIDs are found. So far I was able to use the information for some configuration profiles. Now I want to use it for associating specific devices with a smart computer group but I am somehow stuck. Ultimately, it should result like this: If user is member of a specific LDAP group, then the user's device to be associated automatically with a specific computer smart group. In system > computer management, I created custom "extension attributes" to map the "Directory Service Attribute" "gidNumber" to the LDAP attribute for "GID". But it does not seem to work. Any idea what I am missing?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!