Get Support
Recently active
Has anyone made a script or profile to rename devices in jamf pro? right now, there is onl;y 1 option (within pre-stage enrollment) and i'd like to have a 2nd. my goal it to name the phones using a prefix of P followed by the serial, and a prefix of a T for the ipads. anyone doing something like this?
Hello,We are currently working on the macOS Beta program and would like to remove the Feedback Assistant from the Beta testers. However, the Restricted Software option to remove or kill the process is not working. We also attempted to uninstall the application using the script below, but nothing seems to be effective. Do you have any suggestions or alternative methods to achieve this?Remove script:sudo rm -rf "/System/Library/CoreServices/applications/Feedback Assistant.app"
So, our Jamf cloud instance has started displaying the above when sending management commands to all our Mac OS devices...Device newly enrolled and still the same..anyone have any ideas..cancelled and cleared all commands and still no joy..all push certs etc are valid..pulling what hair I have left out at the mo..:-(
Hello, I have a big issue with Jamf Connect using Google as the ID provider,when trying to log in with Google, after the 2FA validation, I get an infinite loop.so then I tried to log in to local mode with "allow local connection when no network" I also got an endless loop.Also when trying to switch network SSID I get a black screen for 30 seconds...There are also visual issues with Google ID and Jamf Connect, the MFA screen is cut in half, and it always asks for authorization, I mean it's an awful experience.The only way to log in to the MacBook was to nuke the installation of Jamf Connect completely.Is someone having the same issues?
Hi,we are using JamfSchool for our school lab with M2 MacMinis. We would like to disable some apps like Messages, TV and Music. Therefore, we put those apps into the "Paths to disallowed applications" in the "Safelist and Blocklist Applications" payload. This mainly does the job and blocks the apps.However, shortly after login the users get a pop-up that they don't have permissions to run "MessagesActionsExtension", "MusicCacheExtenstion", or "TVCacheExtension".Any idea how to disable those extensions from loading or how to disable those pop-ups?
I am trying to create a PLIST for global protect to have the portal address populated so that our users do not have to enter it manually. Any suggestion?Current version of GP is v6.0.2
Hi all, Relatively new User to JAMF Pro here, I'm looking to enable access for users for multiple tenants.Within our business we have 10+ JAMF Pro instances and a user has requested access to administer machines in another tenant to what his account is created in.After doing some research I can see the best way to accomplish this appears to be to create some access groups, one for the domain they are not currently a part of (I plan on creating a 'enrollment only' group and a 'admin' group for each) and give it the requisite level of access, that's all fine until I come to add the user as a member, the user in question is not visible in the subset of users.If I change the 'site', the list from the 'Members' section doesn't change, so I can only assume this list is static.So I have a few questions:• Why doesn't the user I need to administer appear in the 'members' user list for any of the groups and are these lists specific to the tenant?• How can I make them available to this selec
Hello Teams, Kindly help me with a script to remove admin right on some of our MAC managed by JAMF.
Hi, It there a way to not allow users to sync their device with their personal iCloud? Ie not allowing icloud drive. ThanksJared
Hi,We've got a Mac that was in ABM but was released and re-added via Apple Configurator (for iOS). Initially, it showed in ABM and Jamf Pro but now it doesn't show in Jamf Pro, despite being attached to it in ABM.Remove from Jamf Pro and re-allocate via ABM doesn't bring it back in to Jamf Pro.New Token generation and re-sync doesn't bring it back in to Jamf Pro either.Any ideas?
Hello everyone,I'm trying to assign a MacBook Pro to my company's MDM (from Apple Business Manager), but the serial number does not appear in a PreStage Enrollment section, as it should. It's a first time, I have this problem. Previously everything worked fine. During 11 months, I have unassigned and assigned many of our laptops to MDM, but today it did'nt work. Is there any delay in synchronization between MDM server and Apple Business Manager? It's already more than 6 hours that I assigned a laptop to MDM, but it still does not appear in the PreStage Enrollment list.
Hi there,we are trying to set up the Jamf-Proxy for Venafi PKI and we are running into issues. We set up everything according to the manual. From my understanding Jamf-Cloud is getting connected to the Proxy as I can see a request on the Proxy itself. There is a POST command in the direction of the Venafi PKI which then is stopped with an error : x509: certificate signed by unknown authority.Also we are able to connect to the Venafi PKI from the Proxy via API. Has anyone ever seen the same error and knows what we might have to configure?
Is it possible to change the statement Re-enter your Microsoft Entra ID password... at the creating account window?
Hello Experts, I am trying to run the subject scriptJAMF ECOSYSTEMI have been struggling since yesterday to run the script and getting the following error even my username and password are correctUser Input is NOT OK, we cannot connect to JAMF API and now will EXIT! status_code: 401Could you please help me out what I am doing mistake?
I need to pull a report of all MAC addresses for the computers in my environment and the built-in reporting only can display the Primary MAC address. From other posts it seems the only way is with Extension Attributes but the few scripts I've found (https://community.jamf.com/t5/jamf-pro/how-to-customize-what-gets-inventory-for-primary-mac-address-and/m-p/193541#M182332) don't return any results when creating extension attributes. Does anyone have any ideas on how I can grab this info?Thanks!
How to enforce local backup on the machine for one dive using JAMF Pro? is it policy on jamf pro
So I need to renew the VPP certificate for our cloud server and we don't have access to the apple id last year's was created with. I tried uploading one from the main apple id that is admin for Apple School Manager but it says it doesn't match.I know you can add another VPP token, do i just make a new one? Will i have to reassign all the app licenses?Suggestions? Thoughts? Prayers?
Good morning all!I just had a couple of questions.I have been task to add hardening to the Macs. It occurred to me that it would be easier for the users and to me, for troubleshooting purposes, to deploy 14 rules per week and see how the users get affected.so at first I starting typing the rules that shows under the profile then going to the files and adding the configs one rule at the time. Now, reread the how to use the tool and the only part that it mentioned to do manually if I use the Jamf Pro Upload is to add the Json, which I did. However, Im seeing that the Json is only for exceptions.I'm a bit lost if I have to also do a new policy and runt he script that is uploaded.?Or by using only the profile and allocating it to the machines is enough and I can ignore the Json unless I have to do an exception?I would appreciate if someone can assist me shed some light on the question.
Hey all!We're working on deploying Jamf Connect for our org. In parallel, our security team is working on moving all our MFA for our Okta environment over to WebAuthn with the option of either biometrics or a Yubikey to fulfill it. Does anyone know if Jamf Connect can support WebAuthn methods (or as a bonus, a future state of passwordless with WebAuthn as the only authentication factor)? I've not found any documentation on it, so I'm not hopeful, but wondering if anyone has any experience with this.Thanks,Colton
Hello,Looking for a way to disable end users from changed the Name field on MacBooks using Ventura.System Settings / General / About .....NameI set the name for my student machines and don't want them changing it.
I have noticed, when user start Microsoft teams screenshare for 1st time it asks for 'screen & System Audio Recording' permissionWarning box shows message as below"Microsoft Teams (work or school)" would like to record this computer's screen and audio.grant access to this application in privacy and Security settings, located in system settings.As a user I am allowed to give this necessary permission, is this can be automated, so users don't have to perform additional step in 'privacy and Security settings' while they are on call?
Hi All, I need to replace an existing agent functionality which limits outgoing connections. We are in the process of testing another agent and need to be able to replicate the same functionality on the outgoing firewall.How have been reading about editing the PF config file. Are there any other more manageable and "cleaner" options.TIA.
Vendor Overview BeyondTrust Endpoint Privilege Management allows organizations to: Enforce least privilege dynamically to prevent malware, ransomware, and identity-based attacks, achieve compliance across Windows, macOS, and Linux endpoints, and enable your zero trust strategy — without compromising on productivity. Learn more BeyondTrust EPM: Flexibilities Easily assign macOS computers to a BeyondTrust Endpoint Privilege Management High, Medium or Low Workstyle Flexibility via a Jamf Pro Script Parameter While BeyondTrust Endpoint Privilege Management for Windows policy Workstyles can be filtered based on Microsoft Entra ID groups — as of this writing — macOS policy Workstyles cannot. For macOS, each users’ account must be added to an existing local group for every Mac in your fleet. Continue reading … BeyondTrust EPM: Inspector Leverage swiftDialog to display a user-friendly message about the health of BeyondTrust Endpoint Privilege Management for Mac, while capturing various
With this stupid Apple School/business Manager now, for macs not in ASM/ABM do enrollment invitation using enrollment url still work? I sent one to an email and i enrolled it using that invitation and that seemed to.work fine but SELF SRVICE never installed. MDM profile installed,Configuration profiles installed. Inventory information showed YES for Managed. Why didn't SELF SERVICE install? Looks like all settings are configured correctly for it to install.
I'm working on a client setup right now where the computer goes through ADE/DEP and a tech logs in as the administrator account. That kicks off the DEPNotify Helper script and that workflow. This includes the naming of the computer which, in turn, scopes the FileVault Configuration Profile to the computer. It also includes binding the computer to AD. At this point, if I check fdesetup for a list of enabled users, I just get the admin account. So far, so good. After that the admin logs out (but doesn't reboot or shut down or other wise go back to the FileVault lock screen) and a staff person logs in which creates the mobile account. Now if I run fdesetup I see the admin account and the staff account are both enabled. Jamf confirms the same thing. Both accounts are enabled and FileVault is turned on at this point. However... if I reboot, only the admin account is visible on the lock screen. If I don't reboot, but instead log in as either the staff account or the admin account again and j
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!