Get Support
Recently active
At a state agency, employees are required to request and get an approved exception to perform work outside the USA. See how we use tools and reporting from multiple Jamf services to enforce and monitor these requirements. We will also focus on potential security incidents to look out for when users travel and discuss some related use cases for Jamf Executive Threat Protection that may fit the needs of your organization.I'm putting the final touches on the presentation. Any recommendations/topics that may increase interest to focus on are much appreciated.https://reg.jnuc.jamf.com/flow/jamf/jnuc2024/sessioncatalog2024/page/sessioncatalog/session/1711629202398001pwEE
Hi All,I am trying to install nexthink collector in my Mac but ended up getting the error "the installer encountered the error that caused the installation to fail. contact the software manufacturer for assistance" . Need help with installation.
We are using MS365 as our identity provider and collaboration/productivity platform with Jamf School. Our students will have access to Shared or 1-1 iPads on the Elementary ages.Does anyone have any suggestions on how we can simplify student sign-in so students can sign in securely without MFA/hardware key on Jamf School enrolled iPads?
Today we released Jamf Connect 2.38.0. This release includes the following changes and improvements: Suppress Google Consent Prompts in the Jamf Connect Login WindowIf you use Google Cloud as an identity provider (IdP) and unexpected consent prompts display during each user login with Jamf Connect, see the Suppressing Google Consent Prompts in the Jamf Connect Login Window troubleshooting instructions. This configuration change resolves PI118708. Notice of Upcoming Support Removal for Jamf UnlockThe Jamf Unlock mobile app will no longer be supported when macOS 15 Sequoia releases. Devices using Jamf Unlock can be unpaired via the Jamf Connect menu bar under Paired devices. Improvements to Jamf Connect LogsAdministrators can now collect crash reports by using the Collect logs button to help troubleshoot customer and product issues. By default, the crash reports can be found in /Library/Logs/DiagnosticReports. Other Changes and ImprovementsTemporary elevation features can now ski
We have Macs that get purchased from a 3rd party vendor and they informed me that it takes 1 - 2 weeks from when they are delivered until they show up in Apple School Manager. Waiting 2 weeks to set up a computer after it arrives is a bit much.Does anyone else see delays this long in ASM?
Please vote on my idea to bring back the old Inventory user interface at https://ideas.jamf.com/ideas/SCH-I-315
I have a user that I deployed TUP to that finds that it no longer works after it was previously successful:User has been able to elevate rights first time aroundCount down timer expired (which we have set to 60 minutes)User selects 'Request admin privileges' again from JC menuJC authenticates with our IdP (Entra) successfullyAuthentication window closes, JC menu item still reads 'request admin privileges', countdown timer doesn't start, as if nothing happened.User is still a 'standard' user in 'Users & Groups'Has anybody else witnessed such behaviour?
As per the title - after the enforced interface update, doing an Export in Devices/Inventory and selecting Model Name results in all iPads showing as "iPad" and not, say, "iPad 9th Gen (Wi-Fi)" or similar.This makes it horrendously difficult to do any forward planning for replacement of old devices, let alone across 30 instances of Jamf School to get total numbers.Is anyone else encountering the same issue, or is it just my instances?~~~~~~(Steps to recreate - go to Devices/Inventory, click Export, click Select All, or even just Model Name, then open the downloaded CSV and check the Model Name column)
i keep seeing this message in the JAMF Pro server logs.2024-05-17 07:33:26,762 [INFO ] [duledPool-3] [CsaTokenMonitor ] - CSA accessToken expiration: 2024-05-19T00:13:27Z, refreshToken expiration: 2024-05-31T00:13:27Z2024-05-17 07:33:26,762 [INFO ] [duledPool-3] [CsaTokenMonitor ] - Did not refresh token pair.anyone know what the token is and where i update it Be kind new to JAMF
Hey everyone, I didn't manage to connect our Macs to our wifi network that is using 802.1x authentication at Jamf Connect login window ! Our Macs are not binded to AD and we would use user credentials.Can you shed some light on how to configure it properly to make it work? Thanks in advance
Greetings ProgramsWith the upcoming macOS Sequoia, do you know if there are any profile keys or MDM commands that can control Apple AI services, or disable them (for example Siri)?Thank you!
Hello All, I've seen some older posts on here in regards to logging users out of their iCloud account but can't get them working as of right now. We are looking to disable iCloud across our org, but some users are logged in. I've tested disabling iCloud via a config profile, which works, but doesn't log anyone out of iCloud that's already logged in. Does anyone have a working script that logs a user out of their iCloud account?
Greetings Programs, With the upcoming macOS Sequoia, do you know if there are any Profile Keys or MDM Commands that can control Apple AI services, or disable them (for example Siri)? Thank you!
We are K-12 and students have been selecting wi-fi - Information and editing our wi-fi settings. Is there a way to lock such things as auto-join, Private Wi-Fi Address and Limit IP Address Tracking? Students are also able to change DNS settings and then tell the teacher they are unable to work.We currently have a profile for all of our school wifi's but I do not see away to get granular in Jamf School.
Hi together,we have some find of strang issue here. We want to set a corporate wallpaper for our managed MacBooks. We tried different approaches already mentioned in this community. At the moment the setup is with Desktoppr, the wallpaper will be copied in the prestage and then set via a script which checks if the wallpaper is available, checks the logged in user and then set the background picture. This works and the wallpaper is set. Also different approaches with Lock wallpaper works until this step. The strange issue we are experencing is on the M series Macs. The lockscreen appears with the corporate wallpaper, after the login the wallpaper is gone and the standard macOS Sonoma wallpaper is there. After 10 to 15 seconds the corporate wallpaper appears again and is there. We also have one Intel Mac in testing and there it is not the case. Any ideas what is causing this issue?Best regards
I have been using Installomator and it has been working great. However, is there an option for the app/script to perform a check-in and install the latest update only if the app is already installed. Currently, when I run Installomator, it installs the app regardless of whether it was previously installed or not.For instance, during my testing, I didn't install Google Chrome on one machine and installed it on another using Self Service. I would like Installomator to update the app, but only on the computer where it was installed by the user/Self Service. On the machine where Google Chrome was not installed previously, I don't want Installomator to perform any installation.Is there a way to modify the script so that it only runs when the app is detected on the system? This would ensure that Installomator updates the app only when it is already present. TY
Is there a way to better prevent back ups of items such as pdfs, excel docs, word docs, directory's from being backed up on a institutional device without restricting the user from using them while actively working with the us?
Hello, we have enabled LAPS from api with the default settings for our local admin account. While the password has been changed for all devices, the admin password is working few times and after that the password is no longer working. We waited for password rotation, still not working. The device is connected to the internet, so it should get the new password. We have tried to change it from API and if we look in device inventory, the password has changed but still not working on the device. Devices with OS from 13.x to 14.x are effected. Has anyone encountered this issue? Regards,Traian
I am trying to uninstall Adobe products version 2023 from all iMacs in our school. I am using this script: #!/bin/sh"/Library/Application Support/Adobe/Adobe Desktop Common/HDBox/Setup" --uninstall=1 --sapCode="$4" --baseVersion="$5" --platform=osx10-64 --deleteUserPreferences=trueand assigning the sapcode and base version according to the product in policy, but it is not doing anything. any idea? our iMacs are Silicon
Hi guys,I have two big challenges that I am facing right now.1. Jamf Connect and the configuration in a Microsoft hybrid environment. Jamf Connect is well documented, but I can't find anything about how it can be configured in a Microsoft hybrid environment, in Entra/Azure itself it is super documented.2. how do I configure a classic 802.1X authentication via Jamf Pro? You won't find anything real online. But I've already come across the Jamf ADCS Connector, is that the way?Thanks in advance for the help!
I finally was able to enable the Elevate Privileges option in the Jamf Connect menu and it seems to be working ok. How can I audit who has used it, when, and why?I saw the documentation about possibly seeing up a SIEM to receive that information, but I'm not sure I know how I would do that. We use Rapid7, and I feel like there's a way but might take a bit of work. Is there any other way to gather that information just so we can see who's using it and why? I tried the log stream command in the documentation just to see what information it showed but it didn't seem to do anything and just sat there at a blinking cursor. I checked Azure's sign-in logs and nothing of note in there either unless I was looking in the wrong place. Security needs me to remove local admin rights from all computers, but we still need to allow our devs to install things for their job and we don't want to be buried under a bunch of requests to remote in and use admin credentials
We had a security incident where somebody gained access to one of our jamf administrator accounts and made unauthorized change to configuration profiles. How can we see everything done with that account in the last 30 days or something?
I am looking for a solution to do the following. I have about 90 iPads that are in Single App Mode. They are always connected to power and on ethernet connection. Occasionally, we would like to be able to black out the screen in some manner so there's nothing being displayed on the screen. We also need a way for it to come back to the Single App Mode from that black screen. I would be great to be able to do this remotely and not have to touch all 90 iPads. I don't believe the app we're using supports Autonomous Single App Mode. Thank you all!
Hello everyone, My company and I are looking to allow our users access to the print options on the mac with out full admin credentials. These users have local accounts on their computer, not domain based.I know the following script that most people have used on the forms is below, however, it uses the term everyone. /usr/sbin/dseditgroup -o edit -a everyone -t group lpadminI know that if I replace everyone with the specific user, e.g. Charlie, then Charlie would get access to the Printer group but not Anthony, even though they share the same computer. However, this would require me to replace the name every time I give the script to another user or run it in Jamf. Is there a way to specify that you only want the current logged in user to be added to this group? I have tried the following in replace of everyone but I end up with the error Record was not found:whoami`whoami`$USER$LoggedInUser Thanks in Advance
We are installing some basic list of apps some from the App Store and some from Jamf App CatalogIn some cases Jamf App Catalog apps (Chrome and Google Drive) do not install. ContextThese are brand new M1 MacbooksSome apps will install (like Zoom) pretty consistentlyHappens 10-20% of laptopsPersists over days I tried - restarting the machine- running a manual inventory update - running client reset (jamf recon || true; jamf manage || true; jamf policy || true)- checking if installation is pending (not)- reassigning the computer to the group for which the apps are installed- creating a different deployment of the app for that specific computer Any ideas?N00b to Jamf, what logs can I pull to see what happened with app installations
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!