Get Support
Recently active
Our Jamf version 10.16.1-t1572055156iPad in discussion, 13.2.3Mac version 10.15.1 I had a situation Friday where I had to put an iPad in Enable Lost Mode. I have played with this before, with iOS 12, and Mac 10.14.x last year. Turn it on, turn it off, just easy peasy. Today Monday, YOU CAN NEVER TURN ENABLED MODE OFF!! I even plugged the iPad into an ethernet adapter we have for this very thing, as in the past if a user turned off the 1-1 iPad, it would never connect to wifi until you get passed the iPad code. Can't get past the iPad code, can't connect to wifi. Can't connect to wifi, no command from Jamf is gonna hit the iPad. So we got an ethernet adapter, so we could get Jamf commands to hit the iPad through an ethernet connection. I MUST MENTION THAT THE IPAD WAS TURNED OFF when enable lost mode was on, because the beep beep sound from enabling lost mode, was driving the person crazy. Turning off the iPad when in Lost mode, BIG NONO!! After that....Turning off th
I am trying to figure out how to allow the computers to keep the system.log, install.log, and a few other logs for 90 days. Apple's newsyslog.conf man is gone and I've searched and haven't had much luck. Can someone point me to the direction on how we can set this value, to keep certain logs for 90 days?
I've been trying to script a plist change to com.Safari.plist that sets the value for the favorites toolbar show to true. Here is what i'm running, and what it returns: #!/bin/sh defaults write /Users/$3/Library/Preferences/com.apple.Safari.plist ShowFavoritesBar-v2 -bool true defaults read com.apple.Safari exit 0 Script result: {"ShowFavoritesBar-v2" = 1;} I think I'm missing that step that tells the OS to ignore the cashed version of this file and use the modified one. Gabe ShackneyPrinceton Public Schools
I have had a few users where after they change their password with Jamf Connect, the password expiration countdown time turns into a negative number. For one user in particular, we have tried re-logging into Jamf Connect, clearing the Kerberos tickets, killing the service and restarting the app, and nothing has updated the date to the correct time. Instead of saying "Password Expires: 55 days" it counts backwards to his old expiration date with "Password Expires: -4 Days" Does anyone know where Jamf Connect Sync v1 gets this date from/how to fix this issue?
I'm working to push out network threat prevention in Jamf Protect as described here: https://learn.jamf.com/bundle/jamf-protect-documentation/page/Configuring_Network_Threat_Prevention.htmlUsing Jamf Pro, We have successfully deployed the configuration profile to 4 pilot machines, however, the DNS Settings are disabled and the option to enable them is greyed out. As a result, Network Threat Prevention is not working on these machines. My guess is a previous admin changed a setting in Jamf Pro that disables DNS settings, but I feel like I'm running around in circles trying to find it. I apologize for the wildly open ended question, but I'm curious if anyone has any ideas on how I could enable these DNS settings? Appreciate any help! Thank you!
Hello, I have a problem with the managed iPads at my JAMF School.In fact, many of the devices were previously shown to me as inactive. I have now fixed this problem, but now I can no longer upload new profiles to the devices. Or rather manage them.When I reset one of the devices, I get the message: "Guided Access is not available. Please contact your admin."So I can no longer do anything with the device.Thank you for help. Hallo, ich habe ein Problem mit den verwalteten iPads bei meinem JAMF School.Undzwar, wurden mir bisher viele der Geräte als inaktiv angezeigt, diese Problem habe ich nun behoben, aber nun kann ich keine neuen Profile mehr auf die Geräte aufspielen. Beziehungsweise diese verwalten.Wenn ich eines der Geräte zurücksetzt wird, bekomme ich die Nachricht: "Der geführte Zugriff ist nicht verfügbar. Bitte wende dich an deinen Admin."Somit kann ich mit dem Gerät nichts mehr machen. Danke für die Hilfe. MfG.: M.K.
Can't quite figure out an issue with Office (M365) for iPad, accessing the print function in the menu on some iPads but not others. The one on the left is my own iPad and the one on the right is an extra one I work with.The one on the left is an iPad Pro and the one on the right is an iPad 8, they're running the same iPadOS (17.6.1), they have the same version of Office, and they're signed in with the same Microsoft account.However, they do not use the same LDAP account and they are located in two different sites in Jamf. That is the only difference. Neither device has any restrictions whatsoever in Jamf. The only profiles of importance are MDM Profile and Passcode.Anyone who has experienced something similar and who possibly knows what could be the cause and possibly has a solution to the problem?I am absolutely not sure if the problem has a relation to Jamf, our LDAP or something else.
I pushed out the 2.38.0 version, and the grey box around the Entra ID/Microsoft login is very, very big.It's not breaking anything, but it just looks weird. I even had some staff working the desk ask if the Macs had been hacked or something, as it looked like an opened webpage window to them. I guess in some manner it is a "webage", but I told them no, it's not hacked.Any solution to make it look like this again?
Hello to all, Sometimes I remotely wipe my test macs for various reasons. Is the best practice that after the wipe command is sent, and it begins to wipe, should I also delete the device from JAMF inventory or leave it in JAMF inventory?
Today we are releasing Jamf Protect Agent version 6.1.1; highlights include: Data endpoints for Kafka and syslog are now available in Jamf Protect and Jamf Protect Offline Deployment Mode in the action configurations. The protectctl info command has updated flags related to telemetry and diagnostic output destination. For environments with high compliance requirements, Jamf Pro now provides a configuration schema that can be used to configure Jamf Protect Offline Deployment Mode without using the interface. See the Jamf Protect release history or the Jamf Protect Offline Deployment Mode release history for more information.
When i look into inventory I have several devices that are not displaying the device phone number. If the device phone number isn't displaying does this cause any issues with apps? For us it seems that we have issues with the device not getting self service or able to install apps that we push to the device if the device phone number isn't pulling into inventory. Is there a way to force inventory to get the device phone number? I have tried to do an inventory update and it still does not pull in the device phone number.
Since its announcement earlier this year, Jamf Routines has helped Business and Enterprise plan customers automate workflows by integrating the Jamf platform and common business apps Jamf customers use. There are now 9 new templates available in Jamf Routines. These templates add value to a variety of management workflows. The new templates include integrations with common business applications like Jira, Freshservice, and Webex. They can also automate management workflows like wiping a mobile device, or applying wallpaper to a mobile device to create better shared device experiences. Below is a full list of the new templates: Notify Me in Webex Automatically send a notification to Webex on a schedule or when a specified event occurs in Jamf Pro. Create Ticket in Jira Creates a ticket in your Jira project when a specified event occurs in Jamf Pro. Create Ticket in Freshservice Creates a ticket in your Freshservice project when a specified
Hi All,Does anyone know if it's possible to deploy the Adobe CC apps via Jamf App Installers (awesome feature, by the way!) and then issue just the Shared Device licence from the Adobe Admin Console to licence them? It sounds logically possible, since you can just deploy the Shared Device licence file and the Adobe menu bar app without any other apps in the Admin Console... basically, I'd far rather deploy the Jamf packages than go through the Admin Console rigmarole if at all possible.
Just spent 30+ hours working on this so I thought I'd share Had a few users contact me yesterday with the inability to use teams on their mac. Initial diagnosis was teams cache, so after combing thru thousands of posts and trying to clear the cache with no success, i began trying to uninstall/'reinstall, again, no success. This morning i was affected and ended up installing an OLD version of teams successfully. i tried to upgrade teams through the desktop client and same result. it was then that i noticed that the old version allowed me to use single sign on, and the new version wasnt even getting there. the current resolution is that i have turned off ourMicrosoft Enterprise SSO plug-in for the affected devices. if anyone happens to find the url for teams, feel free to share, or i will when i find it so i can put a nail in this coffin and be done with it. for today anyways.....until MS screws up something ELSE!
Has anyone seen this issue where when a user is sending an email to either a windows device or another Mac using office 365 and it has embedded images, but the when the other user gets it, it switches to an attachment. It's hit and miss and eventually goes away and we think it's only this one user that has issues. Our exec support is still trying to schedule a time to troubleshoot because it got escalated up and this user is a EA. The user sending the emails is on 16.87 and the user getting the email is on 16.88.
Hi, I am trying to create a naming script for computers in my organization based on the inventory preload /Asset Tag field. The goal is to have the computer name be set based on the serial number.i.e.. If serial is 12345 then name be set to COMP-ID-01Thanks,
We currently have multiple Pre-Stage Enrollments in place. One for Middle School Students, one for High School Students, one for Middle School Staff, and one for High School Staff. It has been recommended that we flatten our pre-stage one or two enrollments, however we assign the devices to a Site (Middle School/High School) during the enrollment process. This triggers Site Specific Policies to run (printer installs, software installs, etc.) and prep the device for use in that building. Were we to only have two enrollments (Staff and Student), What would be the best way to assign those devices to their respective sites after the fact, or do we have the most efficient setup? Additionally, we want to know if there's a way to Bulk Remove device records from devices that have been enrolled? Thank you for any suggestions you may have. -Micah
I’m trying to use a script in Jamf to send an email to a user. Specifically want to do this from a policy: policy installs a package, then emails that user some information.I’m trying to use the Python script from this page as a starting point: https://community.jamf.com/t5/jamf-pro/sending-an-email-via-script/m-p/186819.For testing purposes, I’m only running the script--I don’t have the package included in the policy so that I can focus on getting the script working.I haven’t used Python before. I’m guessing this script is just a skeleton and I need to do some additional things to get it to run, but I don’t know what those things are. I’ve filled in the SMTP_SERVER, SMTP_PORT, and SMTP_FROM values and had our Exchange/Outlook person verify they were correct.When I scope the policy to one of my test devices, the status in the log for the policy just says “Pending” and never changes. If I try running the policy by triggering it from Terminal (sudo jamf policy -trigger [name_of_pol
How do I install and Configure LogonBox VPN on MAC? Please help with this app. I have been trying to automate the installation of this app for a while but the command is not working and failing with the Installation Command Line Error.I am requesting the Steps to Automate this case.
So I have a configuration profile thats installable via execution URL:jamfselfservice://content?entity=configprofile&id=120&action=execute .Said config profile has the "Allow Removal" flag checked. Does JAMF Self Service have a "remove" URL similar to the execution URL , that I can use in Shell script, so I can have a non interactive , script triggered removal of the config profile?
We have recently enforced OKTA MFA for all our users and experiencing an unexpected behaviour on some of the user’s device. They users are prompted for 2FA on jamf login screen after native login, however we have not enforced any mfa on device level.Could anyone please assist in understanding why this is happening and any recommendation to avoid such prompts.Thanks,
I have an iMac that was in Apple School Manager. I meant to temporarily unassign it for troubleshooting purposes, but I think I must have released the device instead because now I am not able to add the serial number back into ASM. Apple Support told me that I'm basically out of luck and I can never add that computer back into our DEP ever again. They told me that it is essentially released forever. I can't believe that even Apple cannot help me re-assign this device, even with proof of ownership. Has this happened to anyone else? And if so, were you ever able to re-assign the device in ASM somehow?
I wanted to monitor if our Macs are doing their Microsoft Defender Full and Quick Scans properly in Jamf.As I couldn't find any solution out-of-the-box I came up with a custom script, in case anybody got the same need.The problem I faced, was that the Mac only saves the state of the last 7 scans (Quick and Full Scans are combined). So let's say you schedule your Quick Scans once per day and your full scans once per week and the user is on vacation only on the "Full-Scan-Day", you have no chance to see, if a full scan never ran or just the week before, but was overwritten by Quick Scans.That's why I came up with two different timestamps for the full scans, that one timestamp will always be in Jamf, to see when the last full scan ran, the second one might not really be needed, as it only checks the Full Scan within the last 7 scans.The script might be a bit fragile as it relies on Microsoft to keep the same format for the "mdatp scan list" command, but for now it works :)You will a
I am seeking help with a project. I have created a package within Adobe that I want to push to a Smart group.This package contains approved versions of specific Adobe software. I also need to downgrade the software it it exceeds the version.Any help will be appreciated.
It's extremely annoying that Jamf have decided to prevent Jamf Pro cloud instances from being upgraded before 14th September to v11.9.0, after already bumping v11.8.0 of Jamf Pro.It does not seem fair that we are still waiting for key features to be made available in Jamf Pro, which should have already been released months ago.Why Jamf are you making life so difficult with getting new key new features made available to Jamf Pro customers?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!