Get Support
Recently active
Hello Jamf Nation! This post is to provide you with an update related to the Microsoft and Jamf Device Compliance integration and the Conditional Access deprecation timelines. As of Jamf Pro 11.6 and 11.7.1, the Microsoft and Jamf Device Compliance integration can be fully leveraged in these environments. Jamf Pro environments hosted in Jamf Cloud, including Jamf Cloud Premium and Jamf Cloud Premium Plus Jamf Pro on-premises deployments Microsoft 365 Government Community Cloud (GCC) and GCC High In Jamf Pro 11.7, an issue (PI119904) related to internal proxies was identified that might prevent some customers from migrating from Jamf Pro Conditional Access to Jamf Pro Device Compliance. This issue will be resolved in Jamf Pro 11.9, and this fix is available to test in the 11.9 beta. Customers who are not using an internal proxy are not blocked and should proceed with their migration. You can go to Jamf’s Known Issues page for more information about
Hi all, So a teacher reports that the students have found a way to bypass a lock to a specific app or a website. Apparently, if the student restarts the device, they will get thrown back into the app / website, but they won't be lock. Can anyone else confirm this?
Hi,How have you got Jamf Connect configured with Google Drive for cloud storage?Is it possible to automatically login to Google Drive app once you have signed into Jamf Connect?Or do users have to sign into Google Drive after?Thanks,
Hi Everyone,So, I have about 85 iPads in a school running Jamf School, connected with the Apple school manager. All iPads run in shared mode and are updated to 17.4.1Since putting them all in shared mode, I have needed to start using managed IDs, obviously, but the message "sign in to iCloud" keeps re-appearing for all students and teachers. They can put their code in, and it signs them correctly, but the problem is, especially when working with young kids, that they click the message away. They need to be signed in because otherwise, they can't sync up to the cloud with pictures and settings, etc. Has anyone else had this problem and found a work around for it? Any input would be really appreciated.CheersAlex
I've been looking at finding unique ways to deal with the x-vpn, its tricky in bypassing our firewall. From what I can see it creates a tunnel to a private network within the client machine, and then passes the traffic via https, through a series servers categorised as content servers, is is needed for access via the firewall as most of the time this will be a sever that is side loading content for a general use website. and with 8000 servers for it to chose from, its not so easily blocked. I had implemented a certain level of application blocks, which are circumventable, if you know what hidden files to look for and delete, and for some of the more savvy users it still remains in use. my latest consideration of attack, is to see how to set route or a gateway for the utun6 connection it creates, that directs any traffic within the 172 network range, back to 172.0.0.1netstat -nrshows what gets routed and how when x-vpn is connected: Internet: Destination Gatew
Hello party people.So, we had a bit of a shakeup a few months ago, and people got let go. A couple of people took the chance to take their computers and "forget" to bring them back.There's one machine, a M1 MBPro, running 13.2.0, that its owner seems to have absconded with. After verifying that they was no longer employed, I sent the Lock Computer command with the Remote Lock Passcode set and a friendly message suggesting they call us. Thing is, it's still saying Pending and the machine has checked into Jamf twice a day since. I canceled the initial try and redid it this morning, and the Last Push coincides with the date this computer last checked in... So, the machine is checking in, and I don't think that the Lock Device is firing. I've done some searching, and there was an issue with M1s and earlier OS versions, but that isn't it, I don't think. Any ideas?
Hello,I am not sure if I am looking for the wrong item or not wording my search correctly to find anything relevant but is there a way to disable or delete the wireless connection or options on our Macs that are hardwired with ethernet. We have students connecting to our wireless that requires authentication which then breaks the connection to the internet. They assume because it's not on wireless it loads slower or doesn't have internet. The only configuration item I see under the configuration profile is to define a SSID, but I'd like to disable it all together.
Previously you could use the the airport prefs command to edit things like RequireAdminNetworkChange and RequireAdminPowerToggle (WiFi > Advanced > Require administrator authorisation to change betwork & turn WiFi on and off)With macOS 14 this command is now deprecated and doesn't do anything. What is the "new" way to set these settings (Either by script/command or by configuration profile)
I looked through Configuration Profiles but not seeing anything for this. On the Advanced tab in Network configuration, there is a check box to only allow administrators to turn off wireless. Is it possible to set that with a Configuration Profile so that users cannot turn off wireless?
Looking for some assistance in configuring iPads so that the Okta plugin is automatically installed into Chrome. Under Mobile Devices : Mobile Device Apps I select Chrome and navigate to the App Configuration Screen. In the Preferences field I believe we need to create a PLIST file and copy the code into this field. Has anyone created a PLIST for Okta's Chrome Plugin for Ipads. I keep getting failures trying to create the PLIST. Any assistance is greatly appreciated. Thx
We have an environment with a mix bag of 11, 12, 13 and 14 MacOS. Our target is to bring everyone up to an iteration of 14 so we can just us Jamf Pro to push out software updates going forward. Is there a method that can be done to easily get these users upgraded to 14? Maybe some sort of automation etc?
I'm trying to figure out how "Allow user to be granted first secure token" functions on the back end. I have seen a few tools that will generate the first secure token for a local account they create if the secure token has not been generated yet. Apple is claiming this is impossible, which has me wanting to know how it works even more. Anyone know the terminal command the Jamf binary is using for this? New Features and Enhancements - Jamf Pro Release Notes 11.2.0 | Jamf
I need to remove the signature from a profile so that it is readable. In the past I have used this command: openssl smime -inform DER -verify -in /Path/To/Profile I get a "Verification failure" when I try this. How can I remove the signature? It has been a while since I have needed to do this so has the procedure changed? I found some websites that said I can do this using Configurator but the profile won't open in Configurator.
Hello Im trying to deploy avast through caspersuite to our macs when we image them and what not and its not working correctly. I was wondering how you guys do something like that? I talked to avast support and they said to use a repackaged installer, I am fairly new to mac so unsure on how to do that. is there a tool to use to do such a thing? I use the DMG from the avast for business portal and its set up with correct info however using composer it doesnt like to work correctly.
I'm trying to deploy Avast through Jamf Pro to our company MacBooks. This script & steps found here used to work, but there have been changes with Avast that seem to have since broken this process. There are several issues the first being that Avast Business Anti-virus now seems to rely on another App called Avast Business Agent. The other problem seems to be that the Avast that core shields now also includes the "Real Site" protection as well and this needs to be enabled as well. Any help on figuring out how to auto-install and setup the configuration profiles for this would be appreciated.
Hello, We have been using JAMF Connect tied with Azure AD to setup local user accounts on Mac. However recently we have started to see the error message "Password verification unsuccessful: Invalid Client. Contact your IT Administrator" However the password is correct and before we have been able to shut down the mac turn it back on and it has gone through ok, however this time it doesn't seem to have worked. Has anyone else had this issue/knows any workarounds?
Has anybody figured out in current version Google Chrome how to enforce incognito mode (private mode)? As anybody knows in education, expecting students to log out of registration or instructional websites doesn't always happen and occasionally another student or individual will come along and be able to access the previous user's private data. About the only 'sure' way we have 'fixed' this is to encourage students to reboot the computer after they are done. Most of the browsers have an enforceable privacy mode, but Google Chrome doesn't seem to. Any suggestions or ways you have managed to do this would be greatly appreciated!
Hello!We have a Jamf Connect window setup that works well except for one part: If you are a new hire and haven't setup your account yet (we use Okta), when you receive a new machine and get to that window, you'll let it sit but it will auto-continue to a standard MacOS login window. Without walking through the setup process that immediately follows the JC window, the machine will never pickup your username and you'll find yourself in a type of soft-lock where the machine doesn't have an account to use and we need to reach out to these users to walk them through a complete wipe/rebuild from Recovery. I assume there's just some setting/property in our Jamf Connect config profile that "autocomplete's" but I'm unsure what it is. Potentially the "Allow Local Fallback" property? We use that for it's intended use after the user has already setup an account to login to their machine, but our problem of course occurs only for new hires only when they haven't setup an account first.For what
I have a 10.13.6 fresh build mac with an local admin account created by macOS setup Assistant it has a secureToken, but then i bind the machine to our AD which has the setting enabled for mobile accounts, then login as a AD user and get the prompt Enter a secureToken Administrators name and password to allow this mobile account to use file vault.You can select bypass but would prefer we dont get this prompt in the first place for non filevaulted machines.Does anyone know how to suppress this?thanks
Hey Everybody, Ever since Jamf Pro 11.5 I have been seeing very long waits for packages to be completed via the GUI, for example, a single DMG that is 19MB in size can take 15 to 60 minutes for the Availability Pending alert to disappear. Is this now the new normal? If so, can't say it's an improvement.
Hello All, Looking to see if anyone has a bash script to pull brew installations and then use that in an Extension Attribute to pull from all machines. Similar to this post: https://community.jamf.com/t5/jamf-pro/home-brew-and-collect-application-usage-information/m-p/249337 - Can't get the EA working from the post above though :(
Here is a script that will remove all class data from your instance. If you use macOS' TextEditor, be sure to Convert to Plain Text. Ensure that the file is saved as .shI hope this helps!Have a great day and be well!Here is the script:#!/bin/bash###################################################################################################### THIS SCRIPT IS NOT AN OFFICIAL PRODUCT OF JAMF SOFTWARE# AS SUCH IT IS PROVIDED WITHOUT WARRANTY OR SUPPORT## BY USING THIS SCRIPT, YOU AGREE THAT JAMF SOFTWARE# IS UNDER NO OBLIGATION TO SUPPORT, DEBUG, OR OTHERWISE# MAINTAIN THIS SCRIPT####################################################################################################### DESCRIPTION# This script retrieves class information from the JAMF Pro RESTful API, saves it as an XML file,# and then uses that XML file to delete the classes.# Requires a user that has READ and DELETE privileges for Classes.#########################################################################
Hi Jamf AdminsThe annoying automatic logout from jamf after a short time. Every time login again and navigate back to where you were.Simply annoying.What do you think about this community?CheersPeter
Hi all,I am struggling to find a script that i can use to automatically set open with for certain file types: i.e. .csv to open with Excel, .pdf to open with Adobe Reader I had a look at MSDA but couldn't find any working examples. TIA.
We are facing a problem where user accounts are locked for unknown reasons, and we are trying to find out if our users are entering their passwords correctly (we have a password policy that auto-locks user accounts after N failed attempts).So I'm trying to search logs for events of users typing the wrong password, and I'm running this command:log show --predicate 'subsystem == "com.apple.opendirectoryd" AND category == "auth" AND eventMessage contains "invalid credentials"' --style syslog --info --signpost --last 1h But it shows many "invalid credentials" messages; and every time the user locks the screen, an "invalid credentials" message is generated.Therefore, two questions:1) Does anyone know why an "invalid credentials" message is generated on the screen lock?2) How can I know when users are really entering their password incorrectly and not just locking screens?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!