Get Support
Recently active
I sent in a support ticket about this but they're not available yet so I figured I'd post here too. We use JAMF Cloud and every single package that we had uploaded to our distribution point has disappeared. Policy logs report that the files don't exist. The web interface says "availability pending" for each package. The text for each one appears in red in JAMF Admin. Has this happened to anyone before?
Jamf Concepts is a site to browse utilities built by Jamfs, for the Jamf community. Jamfs often create fun and useful utilities to solve customer challenges. When these utilities cannot make it into our products, at least not right away, we still need a way to share them with you. That’s why we created the Jamf Conceptssite. Jamf Concepts is an evolution of what Jamfs have been doing since our earliest days. Before, if a Jamf created a utility, it might have been be shared by Support, posted in Jamf Nation, in the Apple App Store or in our GitHub. The Jamf Concepts site gives Jamf customers a central repository to view, investigate and implement a utility. To view our concept projects and learn more, please visit concepts.jamf.com.
do anyone have a script that will add AD Group Membership to OSX maxchine in AD. or a Apple script that will call a web service to addcomputergroup
Hello community.When I create or delete something on my Jamf site through api call (for example, creating a new policy with POST on "/JSSResource/policies/id/-1"), I am getting a successful response with code 200 and the newly created policy's id.Then, I am trying to fetch all policies from my Jamf site (GET on "/JSSResource/policies"), but the response does not contain the newly created policy. Should I wait for few seconds before I fetch my policies and check if the creation succeeded? (Since I am running a code that does it I need to know how much sleep time I should add). Are there a different solution than doing busy waiting?All I wrote I experience for DELETE requests as well.Thanks in advance
We used to authenticate our JAMF users (as owners of iPad-devices) against an Active Directory on our local Windows Server 2016 for several years. The server accepts only SSL connections and uses a special user for ldap-requests by jamf (no anonymous connections). The connections are secured by "Let's Encrypt" wildcard certificates which are renewed at least every three months. After each renewal I had to re-enter the domain-name on the organization/preferences/synchronization tab.This scenario worked fine since 2020. It works still fine for other services (e.g. our timetables by WebUntis, which authenticate via ldaps, too, and it's also used by our Nextcloud and by local scripts)Since several weeks it does not work any more: When I enter either LDAP-Server or LDAP-Port, there is an error "Fehler beim Abrufen des LDAP-Zertifikats" (Error retrieving the LDAP certificate). These errors are listed in our server's log:Event-ID 2085:Internal event: An LDAP over Secure Sockets Layer (SSL) co
Hi, I am looking for a way to sync my Exchange Global Address List to my users iPhones. But Jamf Pro seems to have no obvious way to do that. Can anyone point me in the right direction? Kind regards
I've got an issue with Screen Sharing on to a lab of Macs where the screen is completely black apart from the cursor moving being visable. Using Screen Sharing via Finder or using the Apple Remote Desktop application presents this issue. The only fix I've found so far is to send the "Disable Remote Desktop" command from Computers > Management > Management Commands, force the device to check into Jamf Pro, then send the "Enable Remote Desktop" command to the device. After these steps, the black screen issue is resolved and screen sharing/ARD works as expected. When this issue occurs, I can easily log into Jamf Pro, send the management command to a smart group of my lab Macs, another management command to force them to update inventory, then a third command to force them to re-enable Remote Desktop. Is there any way to automate this process into a policy so an engineer doesn't need to log in and manually run the commands?
i need to be able to isolate a single user with multiple machines, with very strict policies. any ideas on how to accomplish this?
Looking for a script to achieve this from JAMF Pro for all the managed devices
Is there any way to directly install the newest MacOS from the Recovery Mode for Macs with ARM chip? For example: I have an M2 Pro MacBook Pro that is currently on MacOS Ventura. Now I want to set it up for a new user, but if I delete the HD and reboot it in recovery I still can only install Ventura. I would have to install Ventura, Update to Monterey and then go through the whole process again.
Hi everyone,So I am trying to make it possible to ban certain apps depending on which grade the students are in. This would be really easy in a 1:1 environment, of course, but my iPads are in shared mode using managed IDs. I thought smart device groups would be a solution but this does not seem to do anything. Is this even possible with a shared iPad/managed IDs environment? Thanks a millionAlex
Hello Jamf Nation! This post is to provide you with an update related to the Microsoft and Jamf Device Compliance integration and the Conditional Access deprecation timelines. As of Jamf Pro 11.6 and 11.7.1, the Microsoft and Jamf Device Compliance integration can be fully leveraged in these environments. Jamf Pro environments hosted in Jamf Cloud, including Jamf Cloud Premium and Jamf Cloud Premium Plus Jamf Pro on-premises deployments Microsoft 365 Government Community Cloud (GCC) and GCC High In Jamf Pro 11.7, an issue (PI119904) related to internal proxies was identified that might prevent some customers from migrating from Jamf Pro Conditional Access to Jamf Pro Device Compliance. This issue will be resolved in Jamf Pro 11.9, and this fix is available to test in the 11.9 beta. Customers who are not using an internal proxy are not blocked and should proceed with their migration. You can go to Jamf’s Known Issues page for more information about
Hi all, So a teacher reports that the students have found a way to bypass a lock to a specific app or a website. Apparently, if the student restarts the device, they will get thrown back into the app / website, but they won't be lock. Can anyone else confirm this?
Hi,How have you got Jamf Connect configured with Google Drive for cloud storage?Is it possible to automatically login to Google Drive app once you have signed into Jamf Connect?Or do users have to sign into Google Drive after?Thanks,
Hi Everyone,So, I have about 85 iPads in a school running Jamf School, connected with the Apple school manager. All iPads run in shared mode and are updated to 17.4.1Since putting them all in shared mode, I have needed to start using managed IDs, obviously, but the message "sign in to iCloud" keeps re-appearing for all students and teachers. They can put their code in, and it signs them correctly, but the problem is, especially when working with young kids, that they click the message away. They need to be signed in because otherwise, they can't sync up to the cloud with pictures and settings, etc. Has anyone else had this problem and found a work around for it? Any input would be really appreciated.CheersAlex
I've been looking at finding unique ways to deal with the x-vpn, its tricky in bypassing our firewall. From what I can see it creates a tunnel to a private network within the client machine, and then passes the traffic via https, through a series servers categorised as content servers, is is needed for access via the firewall as most of the time this will be a sever that is side loading content for a general use website. and with 8000 servers for it to chose from, its not so easily blocked. I had implemented a certain level of application blocks, which are circumventable, if you know what hidden files to look for and delete, and for some of the more savvy users it still remains in use. my latest consideration of attack, is to see how to set route or a gateway for the utun6 connection it creates, that directs any traffic within the 172 network range, back to 172.0.0.1netstat -nrshows what gets routed and how when x-vpn is connected: Internet: Destination Gatew
Hello party people.So, we had a bit of a shakeup a few months ago, and people got let go. A couple of people took the chance to take their computers and "forget" to bring them back.There's one machine, a M1 MBPro, running 13.2.0, that its owner seems to have absconded with. After verifying that they was no longer employed, I sent the Lock Computer command with the Remote Lock Passcode set and a friendly message suggesting they call us. Thing is, it's still saying Pending and the machine has checked into Jamf twice a day since. I canceled the initial try and redid it this morning, and the Last Push coincides with the date this computer last checked in... So, the machine is checking in, and I don't think that the Lock Device is firing. I've done some searching, and there was an issue with M1s and earlier OS versions, but that isn't it, I don't think. Any ideas?
Hello,I am not sure if I am looking for the wrong item or not wording my search correctly to find anything relevant but is there a way to disable or delete the wireless connection or options on our Macs that are hardwired with ethernet. We have students connecting to our wireless that requires authentication which then breaks the connection to the internet. They assume because it's not on wireless it loads slower or doesn't have internet. The only configuration item I see under the configuration profile is to define a SSID, but I'd like to disable it all together.
Previously you could use the the airport prefs command to edit things like RequireAdminNetworkChange and RequireAdminPowerToggle (WiFi > Advanced > Require administrator authorisation to change betwork & turn WiFi on and off)With macOS 14 this command is now deprecated and doesn't do anything. What is the "new" way to set these settings (Either by script/command or by configuration profile)
I looked through Configuration Profiles but not seeing anything for this. On the Advanced tab in Network configuration, there is a check box to only allow administrators to turn off wireless. Is it possible to set that with a Configuration Profile so that users cannot turn off wireless?
Looking for some assistance in configuring iPads so that the Okta plugin is automatically installed into Chrome. Under Mobile Devices : Mobile Device Apps I select Chrome and navigate to the App Configuration Screen. In the Preferences field I believe we need to create a PLIST file and copy the code into this field. Has anyone created a PLIST for Okta's Chrome Plugin for Ipads. I keep getting failures trying to create the PLIST. Any assistance is greatly appreciated. Thx
We have an environment with a mix bag of 11, 12, 13 and 14 MacOS. Our target is to bring everyone up to an iteration of 14 so we can just us Jamf Pro to push out software updates going forward. Is there a method that can be done to easily get these users upgraded to 14? Maybe some sort of automation etc?
I'm trying to figure out how "Allow user to be granted first secure token" functions on the back end. I have seen a few tools that will generate the first secure token for a local account they create if the secure token has not been generated yet. Apple is claiming this is impossible, which has me wanting to know how it works even more. Anyone know the terminal command the Jamf binary is using for this? New Features and Enhancements - Jamf Pro Release Notes 11.2.0 | Jamf
I need to remove the signature from a profile so that it is readable. In the past I have used this command: openssl smime -inform DER -verify -in /Path/To/Profile I get a "Verification failure" when I try this. How can I remove the signature? It has been a while since I have needed to do this so has the procedure changed? I found some websites that said I can do this using Configurator but the profile won't open in Configurator.
Hello Im trying to deploy avast through caspersuite to our macs when we image them and what not and its not working correctly. I was wondering how you guys do something like that? I talked to avast support and they said to use a repackaged installer, I am fairly new to mac so unsure on how to do that. is there a tool to use to do such a thing? I use the DMG from the avast for business portal and its set up with correct info however using composer it doesnt like to work correctly.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!