Get Support
Recently active
Greetings Programs, With the upcoming macOS Sequoia, do you know if there are any Profile Keys or MDM Commands that can control Apple AI services, or disable them (for example Siri)? Thank you!
We are K-12 and students have been selecting wi-fi - Information and editing our wi-fi settings. Is there a way to lock such things as auto-join, Private Wi-Fi Address and Limit IP Address Tracking? Students are also able to change DNS settings and then tell the teacher they are unable to work.We currently have a profile for all of our school wifi's but I do not see away to get granular in Jamf School.
Hi together,we have some find of strang issue here. We want to set a corporate wallpaper for our managed MacBooks. We tried different approaches already mentioned in this community. At the moment the setup is with Desktoppr, the wallpaper will be copied in the prestage and then set via a script which checks if the wallpaper is available, checks the logged in user and then set the background picture. This works and the wallpaper is set. Also different approaches with Lock wallpaper works until this step. The strange issue we are experencing is on the M series Macs. The lockscreen appears with the corporate wallpaper, after the login the wallpaper is gone and the standard macOS Sonoma wallpaper is there. After 10 to 15 seconds the corporate wallpaper appears again and is there. We also have one Intel Mac in testing and there it is not the case. Any ideas what is causing this issue?Best regards
I have been using Installomator and it has been working great. However, is there an option for the app/script to perform a check-in and install the latest update only if the app is already installed. Currently, when I run Installomator, it installs the app regardless of whether it was previously installed or not.For instance, during my testing, I didn't install Google Chrome on one machine and installed it on another using Self Service. I would like Installomator to update the app, but only on the computer where it was installed by the user/Self Service. On the machine where Google Chrome was not installed previously, I don't want Installomator to perform any installation.Is there a way to modify the script so that it only runs when the app is detected on the system? This would ensure that Installomator updates the app only when it is already present. TY
Is there a way to better prevent back ups of items such as pdfs, excel docs, word docs, directory's from being backed up on a institutional device without restricting the user from using them while actively working with the us?
Hello, we have enabled LAPS from api with the default settings for our local admin account. While the password has been changed for all devices, the admin password is working few times and after that the password is no longer working. We waited for password rotation, still not working. The device is connected to the internet, so it should get the new password. We have tried to change it from API and if we look in device inventory, the password has changed but still not working on the device. Devices with OS from 13.x to 14.x are effected. Has anyone encountered this issue? Regards,Traian
I am trying to uninstall Adobe products version 2023 from all iMacs in our school. I am using this script: #!/bin/sh"/Library/Application Support/Adobe/Adobe Desktop Common/HDBox/Setup" --uninstall=1 --sapCode="$4" --baseVersion="$5" --platform=osx10-64 --deleteUserPreferences=trueand assigning the sapcode and base version according to the product in policy, but it is not doing anything. any idea? our iMacs are Silicon
Hi guys,I have two big challenges that I am facing right now.1. Jamf Connect and the configuration in a Microsoft hybrid environment. Jamf Connect is well documented, but I can't find anything about how it can be configured in a Microsoft hybrid environment, in Entra/Azure itself it is super documented.2. how do I configure a classic 802.1X authentication via Jamf Pro? You won't find anything real online. But I've already come across the Jamf ADCS Connector, is that the way?Thanks in advance for the help!
I finally was able to enable the Elevate Privileges option in the Jamf Connect menu and it seems to be working ok. How can I audit who has used it, when, and why?I saw the documentation about possibly seeing up a SIEM to receive that information, but I'm not sure I know how I would do that. We use Rapid7, and I feel like there's a way but might take a bit of work. Is there any other way to gather that information just so we can see who's using it and why? I tried the log stream command in the documentation just to see what information it showed but it didn't seem to do anything and just sat there at a blinking cursor. I checked Azure's sign-in logs and nothing of note in there either unless I was looking in the wrong place. Security needs me to remove local admin rights from all computers, but we still need to allow our devs to install things for their job and we don't want to be buried under a bunch of requests to remote in and use admin credentials
We had a security incident where somebody gained access to one of our jamf administrator accounts and made unauthorized change to configuration profiles. How can we see everything done with that account in the last 30 days or something?
I am looking for a solution to do the following. I have about 90 iPads that are in Single App Mode. They are always connected to power and on ethernet connection. Occasionally, we would like to be able to black out the screen in some manner so there's nothing being displayed on the screen. We also need a way for it to come back to the Single App Mode from that black screen. I would be great to be able to do this remotely and not have to touch all 90 iPads. I don't believe the app we're using supports Autonomous Single App Mode. Thank you all!
Hello everyone, My company and I are looking to allow our users access to the print options on the mac with out full admin credentials. These users have local accounts on their computer, not domain based.I know the following script that most people have used on the forms is below, however, it uses the term everyone. /usr/sbin/dseditgroup -o edit -a everyone -t group lpadminI know that if I replace everyone with the specific user, e.g. Charlie, then Charlie would get access to the Printer group but not Anthony, even though they share the same computer. However, this would require me to replace the name every time I give the script to another user or run it in Jamf. Is there a way to specify that you only want the current logged in user to be added to this group? I have tried the following in replace of everyone but I end up with the error Record was not found:whoami`whoami`$USER$LoggedInUser Thanks in Advance
We are installing some basic list of apps some from the App Store and some from Jamf App CatalogIn some cases Jamf App Catalog apps (Chrome and Google Drive) do not install. ContextThese are brand new M1 MacbooksSome apps will install (like Zoom) pretty consistentlyHappens 10-20% of laptopsPersists over days I tried - restarting the machine- running a manual inventory update - running client reset (jamf recon || true; jamf manage || true; jamf policy || true)- checking if installation is pending (not)- reassigning the computer to the group for which the apps are installed- creating a different deployment of the app for that specific computer Any ideas?N00b to Jamf, what logs can I pull to see what happened with app installations
Has anyone else seen this? is there a fix? not a cache issue, nor a browser, happening in all of them.
I'm getting worried about the future of the Jamf Admin and Composer apps. Composer is the only one that has been updated for Apple Silicon, but it is basically the exact same app it's always been since version 9. Composer's interface could use some updating. New package manifests are painfully out of date (My god, it still lists Shockwave!). Jamf Admin really is unchanged since version 9. Jamf Admin REALLY needs to be updated for Apple Silicon and to support Dark Mode. It also needs improved error reporting and recovery. When there's a problem (interrupted connection, bad pkg, wrong phase of the moon, I'm wearing the wrong aftershave to work...) it can take hours for broken uploads to be removed so we can try uploading again.Jamf Admin is a far more efficient method of uploading and editing packages (when it works) than the JSS web interface. I like that I can upload multiple packages at the same time and then edit them afterward. The web interface only allows one upload at a tim
Is there a way for me to make a certain AD user an admin on a mac cart of 30 macbook air's?
Afternoon All Hoping someone can help who being using Jamf app catalogue longer than we have.We recently started using Jamf app catalogue to manage some of core apps for patching etc. I noticed yesterday that there was a new update from chrome it appeared to install fine and chrome seems to be working on the latest version 126.0.6478.183.However we get below error message when going to About chrome, I have noticed it on a handfull of machines but I expect its probably on all of them. Reinstalling chrome doesnt seem to help either have raised a ticket with Jamf support but that hasnt turn up much so far. The logs show chrome updating without error so I'm somewhat puzzled.As anyone else come across this issue with managing chrome via jamf App catalogue?Thanks
Hi all,We use NinjaOne RMM alongside Jamf PRO for remote management of our MacOS devices, and in order to provide remote support we use the NinjaOne remote access app (NC Streamer).It requires these permissions to run:I've created a configuration policy with the scope - Computers with NC Streamer, config below:It isn't applying the permissions remotely. Have I got the right configuration?Many thanks,
Hi there, I am running into an issue. I am trying to pull from our LDAP attribute "phone number" into the Jamf users' profile. Though the mapping is correct, and if I test the LDAP, I do receive the phone number, but it is not populated in the user profile. Other values such as Username, Full Name, Email, and Position are synced. Does anyone have an idea how to solve this? What makes me wonder is that in the Attribute Mappings the Phone number attribute is called "phone" and in the user profile it says "phone number"...
Hello, I have seen that the FortiClient is causing difficulties for some users. However, I have just been able to create a relatively simple solution with which the config files can also be made to work by default. My requirements: macOS 11.2.3 (intel) / Jamf Pro / DEPNotify 1.1.6 complete installation on one system upload the install.mpkg to Jamf Admin start Jamf Composer and create a pkg with the following path incl. all subfolders (all custom settings are saved here): /Library/Application Support/Fortinet new policy: select both pkg-files, I first selected the config-pkg and then the Install.mpkg. That´s all. I had success with this. FortiClient is running perfect with custom settings. No restart needed.
Hi, we will only just now make the update where we lose access to Jamf Admin. Is there any alternative to Jamf Sync for managing our Distribution point? Jamf Sync seems rather barebones to me, you cant even change the categories from there. Losing Jamf Admin really is a step down as there is no replacement that is equal or better. Yes the UI was old, but it worked fine in my opinion. Kind regards
I am using custom schema policies for google chrome browser and in my case, it is not working as of now.Can someone please share the pilist to skip the first login experience in Google chrome browser.
I'm seeing occasional issues where a machine going through our self service provisioning process occasionally get interrupted by our 'catch all' post deployment pushes (designed to catch machines that for whatever reason didn't get an app install/update when we were pushing out during the change request - it's on a recurrent check-in with a smart group of the app not being installed). For this particular app it cuts off all internet traffic until the user signs into the app and during the deployment as the last application installed for this reason, but we're seeing our 'catch all' policy trigger on some devices while the provisioning policy is running and install the app before the other apps are done. What would be the easiest way to put a check in to prevent the catch all policy from triggering while the device is provisioning?
If dlp is installed on the ipad, can an administrator use dlp to view the contents of the ipad's photos app or the contents of a video sent via AirDrop?Also, if dlp is installed on the ipad, can it be viewed in the vpn and device management section of settings?Is there a case where it does not show up?
Hello,Any businesses using conditional access model here? I would like to raise a forum to get some knowledge about practices you use once migrating from legacy Intune integration to new MacOS device Compliance. As JAMF have no way to migrate for now and current legacy integration have issues of its own we have now a dilemma:Should we wait for Jamf Solution to migrate smoothly? Or should turn off legacy and integrate new one without migration? If we go this way - all macs will lose office 365 access and will need to re- register every single device.That will create pretty big service disturbance. Just wonder what practices other companies' approach to deal with this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!