Get Support
Recently active
Hi,Does anyone use a Mac script to mount AD SMB Path as home folder. I am trying to get it working but struggling to get it to mount the SMB path.The current script looks at the current user in AD and gets the SMB Path. But doesn't mount it. Does anyone use a script to do the same? Script:#!/bin/bash# Log writing functionwritelog() {echo "$(date): $1" | tee -a /var/log/smb_mount.log}writelog "STARTING: User drive mount"# Check if the user's personal network drive is already mountedisMounted=$(mount | grep -c "/Volumes/$USER")if [ $isMounted -ne 0 ]; thenwritelog "Network share already mounted for $USER"exit 0fi# Retrieve SMBHome attribute for the current userwritelog "Retrieving SMBHome attribute for $USER"ShortDomainName=$(dscl /Active\\ Directory/ -read . | grep SubNodes | sed 's|SubNodes: ||g')adHome=$(dscl /Active\\ Directory/"$ShortDomainName"/All\\ Domains -read /Users/$USER SMBHome)if [ $? -ne 0 ]; thenwritelog "ERROR: Cannot read ${USER}'s SMBHome attribute from '/Active D
I am having random apps installing on iPads after manually wiping them, updating the ios and re-enrolling. Clearing pending and failed commands with the mass actions has not seemed to work. I have even checked the iPads I was working on to see if they had any leftover commands and they would all be cleared. But when it gets to the home screen and connects to our wifi, it will start downloading random apps. Only two apps are set to be pushed as they are required by our district. I shouldn't be getting, for example, two different graphing calculators loading on these iPads. Does anyone have any ideas as to why this might be occurring? Thanks.
I have been trying to get Camtasia 2023 to install with JAMF for 2 weeks solid. I am following their Enterprise guide Enterprise Install Guidelines For Camtasia on macOS and I am not getting any luck. I have followed all the steps in creating the LicenseKey file, put into the proper location, and gone so far as to package that separately and deployed that and the Camtasia package (downloaded from the AutoPKG app). Camtasia installs fine, but upon launch, it does not grab the License information. The next issue (which I know is moot until I can solve the first issue) is I would like to utilize all of the "Deployment Options" that are listed on the document above. When I try to do just the one where the software doesn't display the sign-in page, the software cannot see the app license anymore as a valid license. I don't understand why that is.What makes these options difficult is that the plist that they write to isn't created until after the software is launched for the f
I'm having an issue where when I setup screen sharing in macOS when I specify a user to have rights to remote into a Mac using screen sharing the password doesn't work. It just shakes the screen. I did verify that user has rights to Observe and Control (both boxes are checked). If I leave it as Allow access for All Users the same username and password works fine. Is anyone else having this issue? If so, were they able to resolve it? I want to enable this but I don't feel comfortable leaving this open to all users. Thank you!
Hey Jamf Nation family, i´ve got a problem with our managed Apple IDs. This week we created Users in Apple School Manager and imported them into Jamf.After this we purchased a VPP App "Evernote" in Apple School Manager and assigned it to my test users under Jamf Pro => Users => VPP Assignments.So far so good.On my iMac i logged into App Store with my test account and i can see the App "Evernote" under "Purchased".When i click "Install" i only get the message "This Apple ID cannot be used to make purchases."I also can´t install any apps, i get the message above everytime. Can someone help us please?
We have Jamf Pro and the Mac users is connected with the O365 accounts on the device. But suddenly the user can’t log in. I change the password for the user two times but still no luck. Where shall I start searching for error? Can it be sync between O365 and Jamf? Where can I see of the sync is ok? Any tips?
I have disabled "Transfer Information" in DEP AND Blocked "Migration Assistant" in Restricted apps BUT it is still allowing end users to do this during enrollment and set up.Any solutions?
How do you have your mac's setup?We currently have them setup with Active Directory Binded with SMB path as home folder. This is no longer supported / working in any newer OS. As students use these Mac's they use a different Mac every lesson so local users with local data will not work for us.
Hi All,I would like to create below software and add in Selfservice portal in our jamf enviroment, if can give some guideline for this ? https://github.com/AliyunContainerService/ack-ram-tool I checked and found Apple device installation File could be a .pkg, .dmg, or another supported format for macOS applications, not sure software above is compatible for Jamf or not. Thanks and regardsWilson
Happy Tuesday, Jamf Nation!Looks like the behavior of `brew -v` changed with Homebrew version 4.3.11.On the off-chance the following mostly untested EA proves helpful to other Jamf Pro admins: #!/bin/zsh --no-rcs # shellcheck shell=bash #################################################################### # ABOUT # # # # A script to collect the version of Homebrew currently installed. # # If Homebrew is not installed, "Not Installed" will returned. # # # #################################################################### # # # HISTORY # # # # Version 0.0.1, 30-Jul-2024, Dan K. Snelson (@dan-snelson)
So, from time to time we get computers stolen, and more often than one might think, they don't get erased but rather just gets a new admin account (using the .applesetupdone trick).Our users aren't too happy about us collecting geo-location on a daily basis so we crafted a nifty little script that gives us the adress of the stolen computer. The script gets scoped to a static group containing all computers that are stolen (or lost) and set to run ongoing on all triggers (to get as much data as possible). As soon as the computer reports back in to the JSS, these scripts starts collecting data. Along with the adress-script we have another script that prints the safari surf history of the current logged in user to stdin so it gets into the policy log to be viewed and finally one script that prints out the external IP and DNS name of the computer. The adress scripts works by listing all the wifi networks seen by the computer and crafts a URL that requests data from google. The r
Hello,I am running into a strange issue with the wipe computer management command on what seems to be specific 22" iMac models. The issue I am running into is that when I initiate the wipe command on the selected machine, the command goes through at first but when the machine reboots, it results in the "no boot disk found" error screen. I have tested this on several 22" 2019 Intel iMacs and they've all resulted in the same behavior. I have then had to manually restore the Mac via USB drive because the wiping process reverts the machines back to the original base OS. A retrace of my steps:Select Mac to be wiped > start wipe computer command > type in 6-digit wipe pin > observe command going to the Mac > type the same pin into the Mac > allow the Mac to reboot > Mac displays "no boot disk" errorHowever, I have had a 100% success rate with wiping 27" 2020 Intel iMacs. One thing I've noticed that is different about the 2020 iMacs is that they do not ask for the 6-dig
I'm trying to determine if this is possible. I know Jamf can keep track of what applications are installed. Is it possible for it to track when an application is installed via a 3rd party app store or cli and not from the official app store or self service app? Maybe via an extension attribute or something. I'm still researching this outside of this post as well. If i do find an answer outside of this forum. I will update this post to include those instructions for anyone that may need it in the future.
What happens if software vendor releases bad patch via Mac Apps? Is there a way to stop a bad patch if set to automatically patch devices that fall in the smart device? Users are receiving notifications that the app is ready to be applied, forcing the app to quit. We then found out that the update is breaking part of our environment. I have turned off the deploy button in Mac Apps for that app, but isn't the download already cached on the device and ready to deploy as soon as the application force quits? Any way to stop this?
A few years ago I was able to get my fleet transitioned from AD accounts to local accounts with managed passwords via Enterprise Connect and then kerberos SSO. Since we're no longer binding I've created a workaround to leverage ad groups to apply policies. My policy reads the Kerberos SSO signed in credential, strips that to just their User ID, and then runs a /usr/local/bin/jamf policy -username $founduser The policy is great when run via self service, however it fails running on an automated trigger. My first chat with Jamf Support tried to tell me that i was reading the username incorrectly which is why it fails, however I think it's due to the fact it's a policy calling another policy. I get a Script result: Local User Profile name is USERID Checking for User Specific Policies This policy trigger is already being run: root 4028 0.0 0.1 411796288 33456 ?? S 8:20AM 0:00.23 /usr/local/jamf/bin/jamf policy -event CLIENT_CHECKIN -stopConsoleLogs Does anyone do anything like this? Have a
I’m new to Jamf development and have been learning a bit from our senior Jamf developer, who said one of our biggest complaints from end users was not knowing when an application had finished updating because it would never relaunch.So that’s what I set out to explore. My goal was to create and deploy a browser package that would automatically relaunch the browser post-update.Someone on the forums suggested using Jamf Pro > Computers > Content Management > Mac Apps > Jamf App Catalog, since there I would have the ability to select the option “Automatically open app after update.”Should mention here that this is different from the Packaging process we are using, which can be described as:Create a new Package when a new version of an app becomes availableUpdate the existing Patch Management policy to reflect the new version of the appDeploy to whatever groups we’ve scoped in the Patch Management policyFor my test:I created a Smart Group that contains just one of my test Macs.
I have recently created a script that I will be using for a monthly policy to encourage users to reboot their Macs regularly. I'm using Swift Dialog to show a prompt to users to reboot. I am giving them the ability to defer rebooting up to 3 times. I also added a function in the script that will check if either Zoom or Teams is in a meeting. The Swift Dialog window won't appear if either app is in a meeting. Instead a launch daemon is installed and loaded to ensure that the policy runs again. When a user defers, the deferral time is written to a PLIST. The PLIST tracks the time and date of each deferral, how many times the user has deferred, and how many deferrals are remaining. The launch daemon is also installed after a deferral. I want the launch daemon to launch the policy again 1 day after the user defers or after the script finds that the user is in a Zoom or Teams meeting. In my tests, I set the StartInterval to 300 seconds so I wouldn't need to wait a full day. After I saw that
Hello,does anyone have any experience using the DNS configuration setting? I set it to use https://dns.google/dns-query on our Apple TVs to bypass our content filter, which worked, but now they're not checking in anymore! It's probably fine since I can just reset them if I need to get rid of that, but it would be nice to know they're still otherwise working properly.
Hi there, Has anyone managed to get the end user notification payload in jamf to work? Seems all the configurations I have applied using app bundle Ids dont adjust notifications end user side at all. I still get prompted to allow notifications for the apps I've configured in the profile.
Hi there, is there a way to check the logs of a admin user in jamf pro portal to identify what they have done on the portal. We have few members who has access to the portal buy i cant see any way of pulling a report of what that user has done.Thanks very much!
Hi,I'm looking to automate the sign-in process for the Office suite on Mac devices used by our students. Ideally, I want Office to automatically pick up their login details and sign them in with their credentials. So far, I haven't had any success in implementing this.Has anyone managed to get this working? Any advice or resources would be greatly appreciated. is there a script out there somewhere I can use to achieve this?
Hi all! Wanted to see if anyone else is seeing this issue before I reach out to Jamf Support.When deploying apps from the Jamf Catalog with Mac Apps the applications deploy but never report back as Complete. After confirming that any app that we've tested has successfully updated they only show In Progress it the deployment status. It never changes and is very frustrating when trying to track the updates for our InfoSec Office. I've gone through the instructions numerous times and still no joy here.Suggestions would be greatly appreciated.
From AP:cisco C9120AXI-B ARMv8 Processor rev 0 (v8l) with 1875204/1065904K bytes of memory.Processor board ID FJC26381AZTAP Running Image : 17.6.4.56Primary Boot Image : 17.6.4.56Backup Boot Image : 0.0.0.0Primary Boot Image Hash:Backup Boot Image Hash:1 Multigigabit Ethernet interfaces Controller:Cisco Catalyst 9800-40 Wireless Controller17.3.4c My thoughts were that the controller was supposed to downgrade or upgrade an AP if the versions did not match to match the controller. Is that not how this works? Or do I need to update the controller to match the 60 AP's we just bought?
My original posting for this started off as just an Extension Attribute. In the past 3 days, it has become a full blown workflow. Here's that workflow. JAMF Software Deployment: Nessus Agent for Apple Macintosh INTRODUCTIONTenable Network Security's Nessus software is currently being utilized for vulnerability scanning and vulnerability management within the enterprise. JAMF Software's Casper Suite (JSS) is used to manage Apple Macintosh systems within the enterprise. This includes the deployment of software packages such as the Nessus agent. This article describes the various elements and requirements as utilized by the Casper Suite in order to package and deploy the Nessus agent to Macintosh systems within the enterprise. TOPICS....Preparing for Deployment........The Software............Acquiring the Nessus agent............Creating a Custom PKG Payload................Acquiring and Installing Casper Composer................Overview and Purpose of Creating a Cust
In a computer lab environment, we are currently redirecting student’s desktop documents etc to an alternative ‘Local’ folder created within the profile on logging in. This is done using symbolic links in a script. We were previously redirecting the desktop documents to their network homefolders but these have now been decommissioned, so we are looking to do a local redirection for the purposes of space management.Unfortunately, the local redirection doesn’t appear to work well, in that when you save to the desktop, documents etc, the file doesn’t automatically appear in the relevant folder. You would need to go into Finder and select the relevant folder for it to appear. This isn’t even the case with the Documents folder, selecting it in finder doesn’t bring up the most recent file, you need to put the full path to the redirected Documents into “Go to folder” in order to see the files, else logout & back-in. The files are seen in terminal and using preview app. Relaunchi
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!