Get Support
Recently active
Just wanted to see if there were any other Mac Admin's here on JAMF nation that are in the Omaha Metro area? If so, I thought I would see if there were any interest in forming a local JAMF user group or meet up?
We are deploying new iPad 10's to our students. In one of our configuration profiles functionality restrictions restrict "modifying account settings" but that seems to affect the prestage setup assistant option for "Apple ID and iCloud" in that it is not displayed even though it is the only option we have unchecked. When "modifying account settings" is allowed, the setup assistant option IS displayed during enrollment. We do not have "install configuration profiles before setup assistant" selected in the profile because we don't want the profile to enforce any restrictions prior to the "setup Assistant". This is precisely because we do want students to login to their Managed AppleID before the modifying account settings restriction kicks in.What am I missing? In the meantime we deploy the iPads with "modifying account settings" allowed and are forced to then manually run an inventory check which we've designed to pick up a passcode and then deploy another config that restric
I am trying to install CrowdStrike agent on an iPhone (iOS) but keep running into errors. Steps taken: 1. CrowdStrike app is pushed out to iOS via 'Mobile Device Apps' + Managed Distribution - Successful 2. Created a configuration profile for mobile devices. Content Filter payload configured. Filter Type - Plugin Identifier - com.crowdstrike.falconmobileFilter WebKit - Unchecked Filter Socket - Checked Under Custom data, I have key/value mapping I got from CrowdStrike that contains the following key/value pairs: user_email$EMAILhostname$SERIALNUMBERskip_legalTruecloud_id<REDACTED>customer_id<REDACTED>provisioning_token<REDACTED>The application installs but when I open the application and click "Get Started" I see the following error - Crowdstrike missing deploymeny profile ios. Content Profile does not exist. Can someone help?
Hi Anyone, we have a company AWS own VPN. When we run the AWS VPN its bypasses the Jamf Radar policy and the user can be access how we can fix this issue
Hello! I have an advanced computer search setup that I use to keep eyes on what version of macOS our users are on, and ideally I'd like to be able to email the entire list using the "Action" command. When I have tried this in the past emailing just a single user, I am able to send the email through JAMF, so I believe my SMTP settings are correct. When I try to send an email with multiple users (sometimes 50-100) I receive an error command saying the email could not be sent. I have verified that there are email addresses for each user in the list. Is there something else I should be trying? Thanks in advance for your help! Keith
where at Jamf to inform about this?
I'm working creating a script that performs several functions. One of the functions requires me to obtain the computer's Jamf Pro ID. I'm trying to figure out how to do this using the new API. I thought if I have a variable for the computer's serial number I could use that to query for the Jamf Pro ID. Is this possible?
Hello, Jamf Nation! The Jamf ID update is now complete. Your name, email, phone number, language and email opt-out status have been migrated. Please reset your Jamf ID password and re-enroll in Multi-factor Authentication (MFA), if applicable. Your time zone will be set automatically to the browser time zone when logging in for the first time with your new password. Action Required: Reset Your Password Please reset your password by following these simple steps: Visit Jamf Account: Head over to account.jamf.com. Click on ‘Continue with Jamf ID’: This button will display if you've logged in recently. Enter your Email Address Click ‘Log in using Jamf ID’: This enables you to continue with your Jamf ID credentials, as opposed to utilizing SSO if it has been enabled for your organization. Click on 'Reset Password': You'll find this option on the login page. Click on it to initiate the password reset process. Enter Your Email: Provide the email address as
Hello,One of our users is requesting that we change their Name, Email, Username in all of our systems for their legal name change. I am wondering how that will work with Jamf Connect. The Jamf Connect login screen should authenticate to Okta and allow them in but I am curious if there are other steps we would need to do like changing the Record Name value or disconnecting/reconnecting the local account with the IDP account. Anyone have experience with this?
Hi, all.I'm having two huge problems with Composer (Version 11.4.1 running on an M2 MacBook Air w/ macOS 14.4.1).When I create a source, I can't see files at all to interact with them. They appear to be there (see screenshot), and I can sort of kind of navigate the filesystem inside there with the arrow keys, but I see nothing. This makes it impossible to work with Composer atm, and it's a crucial part of my Jamf workflow. Anyone here seen this or know how to fix it? I've already tried uninstalling, ripping out the Composer prefs, and reinstalling. No joy.When I try to create a source from an existing file, I'm able to do it from a .dmg, but not a .pkg. Those always fail.Anyway, HELP! Is there maybe a beta I can try? I dunno…
We have a user who has discovered a log file on their MacBook called MCXTools.log that is being endlessly written to with the same entry (ID's have been obfuscated for security): Aug 27 13:45:39 mdmclient[20216] [0:MDMDaemon] Using MDM profile: <DeviceEnrollment> [CloudConfiguration:SetupAssistant] EnrollID: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX (User:XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX) <Payload: JAMF Manual Enrollment Payload: MDM (<com.apple.mdm> 00000000-0000-0000-A000-XXXXXXXXXXXX:00000000-0000-0000-A000-XXXXXXXXXXXX) from profile: MDM Profile (00000000-0000-0000-A000-XXXXXXXXXXXX:00000000-0000-0000-A000-XXXXXXXXXXXX)> It has been writing these lines (and others) endlessly ever since it was enrolled. I cannot find any information on the internet about this log file and wondered if anyone has seen this before and what it is doing?
Is there a way to run a configuration profile that is set to self service distribution via the command line? I've tried jamf policy -id X, but it didn't work.
Hey all,I hope someone can help.I have an iPad (7th Gen) that I've successfully added to Apple Business Manager (ABM) using Apple Configurator. After that, I moved the iPad to our MDM server in the pre-stage enrollment, but it never appears in JAMF.I’ve tried releasing it from ABM and re-adding it, but the issue persists.I've done this process with 20 other iPads without any problems, so I'm not sure what's going wrong this time. I even left it in ABM overnight to see if it just needed more time, but that didn’t resolve the issue either.Any ideas on what might be happening or what else I can try?Thanks in advance for your help
Hi folks,Since yesterday my fleet of 750 iPads started asking users to change their passcode.I have never had this before, I wasn't aware iPad passcodes expired.And I've never configured any passcode expiry nor can I find where to do it in Jamf School.They're behaving as if I've applied a profile requiring a passcode, which I have not.A mixture of iPadOS 16-17Any thoughts appreciated.Thanks
Hey Everyone,Does anyone know how to disable the "Wacom Desktop Center" app from auto launching during a user's first login?(I don't remember having this issue last year when setting our computer lab iMacs at my community college.)
Our Jamf Pro is currently setup to use LDAP for adding Directory Accounts. I want to switch to using Entra for Cloud IdP.Anybody run into any issues when making the switch? Did you do a straight swap or have both Cloud IdP and LDAP configured at the same time?
I've messing around with the below script I found, so we can allow some users to forget ssid's. When I forget the wifi, I still get the admin prompt, but if I hit cancel on the prompt, it does forget the ssid. Just trying to figure out how to get the prompt to not show on Sonoma. #!/bin/bash # Get a list of preferred Wi-Fi networks wifiList=$(networksetup -listpreferredwirelessnetworks en0 | sed 's/^\\*//') # Present a dialog box for selecting a Wi-Fi network to forget selectedWifi=$(osascript -e 'choose from list {'"${wifiList}"'} with prompt "Select the Wi-Fi network to forget:"' | tr ',' '\\n' | sed -n 2p) if [ -n "$selectedWifi" ]; then # Forget the selected Wi-Fi network without requiring admin privileges sudo -u $USER networksetup -removepreferredwirelessnetwork en0 "$selectedWifi" echo "Wi-Fi network '$selectedWifi' has been forgotten." fi echo "Please select the Wi-Fi network you want to forget."
I'm sure the really smart people will be able to improve the steps I took to insert the Serial and prevent updates. 1: Download the newest version 10.3. Upload to the JSS2: Install on your test machine. Authorize with your serial. This process will create the com.finaldraft.finaldraft. plist. I used Composer to capture the file.3: I then created a policy with the installer, and the license package and the script below that runs after the install is complete #!/bin/sh Define logged in user user=ls -la /dev/console | cut -d " " -f 4 Run command with sudo as user sudo -u $user defaults write /Users/$user/Library/Preferences/com.finaldraft.finaldraft.v10.plist IT-Install XFDY-XXXX-XXXX-XXX sudo -u $user defaults write /Users/$user/Library/Preferences/com.finaldraft.finaldraft.v10 SUEnableAutomaticChecks -bool no When run for the first time the Authorization box pop up with the Serial pre populated. That's it
Hi there,We currently have Google Workspace configured in Jamf Pro. This allows us to manually search for users in "Users and Location" to assign them to a device.We also have Jamf Connect in our environment that associates the local account with an Okta account which is linked to the user's Google Workspace email.Is there some way to automate assigning user details into User and location based on the username of a logged in user?
I need to update the PaperCut server on our Macs via the /Applications/PaperCut Print Deploy Client/data/config/client.conf.toml file so our devices will pick it up.I created a pkg with Composer that solely consists of that modified file, but it is failing to deploy.Here is the error I'm receiving:Installation failed. The installer reported: installer: Package name is PaperCutConfig installer: Installing at base path / installer: The install failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. The package is attempting to install content to the system volume.)Any help would be appreciated.
Hey All.. We are implementing PaperCut and it is working for the most part, except we have a few printers that are not working, most notably the HP P1606. We are using the generic PS driver, which works for most other models. We have tried using the HP 1600 series driver as well, but we get garbage output when it prints from the LPR queue. I have tried switching the LPR queue to HP Universal PS, HP Universal PCL but nothing seems to help. Anyone have any ideas?
We have a policy in Jamf that applies a disk encryption configuration defined in Jamf Pro's settings. (Settings \\ Disk encryption configurations)We also have a device that needs to run the built-in guest user, but not in Safari-only mode that is enforced when FileVault is on. FIleVault has already been enabled via that policy on this particular device.Based on a test, it seems that if we disable FileVault, it will just turn it back on per that policy that previously ran & applied the disk encryption configuration.Short of wiping the device and not applying that policy, is there a way to clear out that configuration as-is, to prevent FileVault from turning back on?
I have several older OS machines to upgrade, Big Sur, Monterey, Ventura. I am configuring Nudge to launch the Erase-Install script but when Nudge attempts to launch the actionButtonPath of "jamfselfservice://content?entity=policy&id=2909&action=execute" the screen flashes and I get an error stating that "Self Service Quit Unexpectedly."Now if I open self service first and THEN click the Update Device button the upgrade starts and completes successfully, but I doubt many of my users would think to do this and I would rather this not be the 'permanent' solution.Is there a known issue (with solution) where the installation URL from Self Service does not function as expected?Thank you in advance!
Hi all,I'm looking for some advice please?I have a lab of 20 Macs joined to a Windows domain. I've pushed out Office LTSC Standard 2021 and the volume license serializer via Jamf which is working well. When a student logs into a Mac using their domain credentials and open Word, I can see that it’s activated with the volume license.However, I encounter issues when the Office applications prompt students to sign in. If they enter their student Office365 credentials then Office LTSC converts to a Microsoft 365 Subscription license. I’m then unable to revert the license back to our volume license. Logging out of Office LTSC results in Office LTSC showing as ‘Not activated”. I'm just wondering if anyone else has come across this before? Is there anyway I can force it to use the volume license? Any help of advice would be great, thanks! N
I have tried a few methods and scrips but I was not successful. Any has a solution or a way to make the script below work ? !/bin/bashdefaults write com.google.chrome IncognitoModeAvailability -integer 2 Thanks
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!