Get Support
Recently active
Scenario is this tried to add macbook to ABM via Apple configurator 2 it worked but checked mdm server it shows correctly, but when we boot macbook, after the wifi connection it doesn't redirect to the policy pop-up via jamfpro can anyone face with this issue?
I've recently been tasked with getting intune complaince/jamf working to test if its viable to go forward with. I've been working on setting it up on our sandbox environment and was wondering if anyone's tried setting up the conditional access policy on the Microsoft side. Like what they used for testing or anything they had to tweak or change to get working. Id to know what you guys used for a test policy thats easy to see quick results. -In theory if a mac isnt compliant things like "Unable to sign into outlook" would be possible or some kind of email notification to prompt the user to update. -What have you guys used the integration for that you've been pleased with?
HiThe fields bar code 1 and bar code 2 in a computers inventory / general list, can they be references from the mac? if so where is the file that data comes from?https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/Computer_Inventory_and_Criteria_Reference.html
Overview:I was really struggling to configure SMTP with M365. We have a distribution list that our Operations team are all apart of and wanted to receive email notifications from Jamf for a variety of reasons.Our environment has MFA enabled and I was continuously fighting with both Jamf/Azure to figure out a workaround to the authentication errors I was seeing in the Jamf Server Logs.It wasn't until after creating a service account without MFA applied it(account being authenticated in Jamf SMTP) and enabling "Send As" and "Send on behalf" in the distribution list by adding the service account to the delegates list that mail was delivered.Lets look at a couple server logs I was experiencing first. Server Log Error generated from an account with MFA enabled:javax.mail.AuthenticationFailedException: Authentication unsuccessful, the request did not meet the criteria to be authenticated successfully. Contact your administrator.With the error above I messed around in Azure quite a bit a
I discovered that this model only has an HDMI and power cable connection. Previous TV models have connected to our network with a network cable, so how does one get this 3rd Generation connected and enrolled in JAMF? This new device configuration has prevented me from configuring them as I did before with a cabled connection.--The TV is present in Apple School Manager and enrolled in JAMF Pro.--I cannot find the TV in our JAMF inventory by searching on serial number. (makes sense as it has not connected to any WiFi yet)--When powered on and connected to a monitor, the TV sees but will not connect to our open guest network: " The WiFi network requires further authentication to connect. Use your iPhone or iPad to continue". Choosing this option goes nowhere. So I then try a secured WiFi network... --We created a special wireless configuration for TVs to auto-join a secure WiFi network, but this is not automagically working as with previous generations. It appe
Seems like I cannot finish jamfproinstaller mysql Ver 8.0.35 for Linux on x86_64openjdk version "11.0.21" 2023-10-17 LTSInstalling...Executing set-java-home...JAVA_HOME is ''...Setting JAVA_HOME to '/usr/lib/jvm/java-11-openjdk-11.0.21.0.9-2.0.1.el8.x86_64'Starting Tomcat InstallationDetected previously installed Tomcat...Upgrading Tomcat service...Reloading system daemon...Enabling Tomcat to run at startup...Copying backup of Tomcat (/usr/local/jss/tomcat) to /usr/local/jss/backups/tomcat/2023-11-07_07-53-12...Copying Tomcat files...Setting permissions...Restoring /usr/local/jss/tomcat/conf/*.xml...Transforming the server.xml...Error: Could not transform the server.xml Any thoughts?
I am unable to find a way to added Cisco Thousand Eyes Uninstall to Managed Login Items as it is a EXEC file it doesn't have a bundle id or team identifier. Hoping someone has setup a different EXEC that might know what I need to add the config profile. Thanks
Hi all, I'm wondering if anyone has had success in packaging Maya 2022 with a non-network server license key, which our institution is able to put on 1200 machines. I tried referencing this post, but havent been able to successfully deploy the program with my modifications. Any help would be appreciated. Thank you.
Hello All,We were using following script to rename the computer name and it was working before 2 months.#!/bin/bash# jamf ApiapiUser="####"apiPass="####"jssURL="our_jamf_instance_url"serial=$(system_profiler SPHardwareDataType | awk '/Serial\\ Number\\ \\(system\\)/ {print $NF}')serialc=$(system_profiler SPHardwareDataType | awk '/Serial\\ Number\\ \\(system\\)/ {print substr($0,length-5)}')base=$(curl -H "Accept: text/xml" -sfku "${apiUser}:${apiPass}" "${jpsURL}/JSSResource/computers/serialnumber/${serial}/subset/Location" | xmllint --xpath "/computer/location/building/text()" -)echo Building:$basescutil --set ComputerName $base-$serialc-Mscutil --set HostName $base-$serialc-Mscutil --set LocalHostName $base-$serialc-Mcname=$(scutil --get ComputerName)echo ComputerName:$cnameexit 0 Now the script is returning error cript result: -:1: parser error : Document is empty^Building:scutil: invalid option -- 8usage: scutilinteractive access to the dynamic store.or: scutil --prefs [
First time I've attempted an OS upgrade in Jamf. Trying to upgrade some devices at work from Monterey to Ventura. I have a Smart Group to show me how many devices are running Monterey. In Jamf, I went to "Software Updates", found the name of my group and selected the checkbox, then clicked "Update 1 selected".Then selected “Download, install, and allow deferral” and set “Target version” to the most recent version of Ventura (13.6.8). Set the deferral value to 1. End users have received plenty of notifications by now, but thought I'd try to make the upgrade process as painless as possible for them.Did this about a week ago. None of the devices installed the new OS. When I query a specific device in Jamf and look in "Management > Management Commands", I see this: Not sure what I've done wrong.
Hi Guys, We are building out our login workflows, and a good question was asked. Why are we going Local and not using Mobile Accounts when we bind anyway? Most videos seem to hint that local accounts are the recommended option, but I can't seem to find a hard list of Pro/Cons for reasons to go local over mobile. Any insight as to why we would go local over mobile would be helpful. We are using the Kerberos SSO Extension to give user's Kerberos tickets after they login. The concern is that user's don't get a Kerberos ticket upon login which I believe is what a mobile account would do for us. Thanks in advance!
Have a lab of 20 Mac Minis using Jamf Connect & Google IDP. The login screen shows Sign in with Google as it should but it'll randomly resize the login window which is behavior we're not looking for. Sometimes it'll show the complete Sign in with Google box including the Create Account & Next button, and further down. Other times it'll load a much smaller cropped window with a scroll bar (showing the field for the e-mail or phone login but missing the ability to see the Next button without scrolling down) and place it towards the bottom of the screen instead of centering it on the screen. All systems are using the same model of monitor, same resolution. Not sure if anyone else has experienced this behavior? My thought is maybe it's the newest version of MacOS as they've now been upgraded to 14.5 and this was not happening on 13.x. Just very odd behavior that it'll sometimes load properly then you reboot the machine and it's a 50/50 chanc
I have been tasked with setting up a Ring deployment for all my supported platforms. JAMF is the last on my list.I cannot figure out how to setup a Ring deployment approch within JAMF. Does this management platform support such a deployment model?
Has anyone made a script or profile to rename devices in jamf pro? right now, there is onl;y 1 option (within pre-stage enrollment) and i'd like to have a 2nd. my goal it to name the phones using a prefix of P followed by the serial, and a prefix of a T for the ipads. anyone doing something like this?
Hello,We are currently working on the macOS Beta program and would like to remove the Feedback Assistant from the Beta testers. However, the Restricted Software option to remove or kill the process is not working. We also attempted to uninstall the application using the script below, but nothing seems to be effective. Do you have any suggestions or alternative methods to achieve this?Remove script:sudo rm -rf "/System/Library/CoreServices/applications/Feedback Assistant.app"
So, our Jamf cloud instance has started displaying the above when sending management commands to all our Mac OS devices...Device newly enrolled and still the same..anyone have any ideas..cancelled and cleared all commands and still no joy..all push certs etc are valid..pulling what hair I have left out at the mo..:-(
Hello, I have a big issue with Jamf Connect using Google as the ID provider,when trying to log in with Google, after the 2FA validation, I get an infinite loop.so then I tried to log in to local mode with "allow local connection when no network" I also got an endless loop.Also when trying to switch network SSID I get a black screen for 30 seconds...There are also visual issues with Google ID and Jamf Connect, the MFA screen is cut in half, and it always asks for authorization, I mean it's an awful experience.The only way to log in to the MacBook was to nuke the installation of Jamf Connect completely.Is someone having the same issues?
Hi,we are using JamfSchool for our school lab with M2 MacMinis. We would like to disable some apps like Messages, TV and Music. Therefore, we put those apps into the "Paths to disallowed applications" in the "Safelist and Blocklist Applications" payload. This mainly does the job and blocks the apps.However, shortly after login the users get a pop-up that they don't have permissions to run "MessagesActionsExtension", "MusicCacheExtenstion", or "TVCacheExtension".Any idea how to disable those extensions from loading or how to disable those pop-ups?
I am trying to create a PLIST for global protect to have the portal address populated so that our users do not have to enter it manually. Any suggestion?Current version of GP is v6.0.2
Hi all, Relatively new User to JAMF Pro here, I'm looking to enable access for users for multiple tenants.Within our business we have 10+ JAMF Pro instances and a user has requested access to administer machines in another tenant to what his account is created in.After doing some research I can see the best way to accomplish this appears to be to create some access groups, one for the domain they are not currently a part of (I plan on creating a 'enrollment only' group and a 'admin' group for each) and give it the requisite level of access, that's all fine until I come to add the user as a member, the user in question is not visible in the subset of users.If I change the 'site', the list from the 'Members' section doesn't change, so I can only assume this list is static.So I have a few questions:• Why doesn't the user I need to administer appear in the 'members' user list for any of the groups and are these lists specific to the tenant?• How can I make them available to this selec
Hello Teams, Kindly help me with a script to remove admin right on some of our MAC managed by JAMF.
Hi, It there a way to not allow users to sync their device with their personal iCloud? Ie not allowing icloud drive. ThanksJared
Hi,We've got a Mac that was in ABM but was released and re-added via Apple Configurator (for iOS). Initially, it showed in ABM and Jamf Pro but now it doesn't show in Jamf Pro, despite being attached to it in ABM.Remove from Jamf Pro and re-allocate via ABM doesn't bring it back in to Jamf Pro.New Token generation and re-sync doesn't bring it back in to Jamf Pro either.Any ideas?
Hello everyone,I'm trying to assign a MacBook Pro to my company's MDM (from Apple Business Manager), but the serial number does not appear in a PreStage Enrollment section, as it should. It's a first time, I have this problem. Previously everything worked fine. During 11 months, I have unassigned and assigned many of our laptops to MDM, but today it did'nt work. Is there any delay in synchronization between MDM server and Apple Business Manager? It's already more than 6 hours that I assigned a laptop to MDM, but it still does not appear in the PreStage Enrollment list.
Hi there,we are trying to set up the Jamf-Proxy for Venafi PKI and we are running into issues. We set up everything according to the manual. From my understanding Jamf-Cloud is getting connected to the Proxy as I can see a request on the Proxy itself. There is a POST command in the direction of the Venafi PKI which then is stopped with an error : x509: certificate signed by unknown authority.Also we are able to connect to the Venafi PKI from the Proxy via API. Has anyone ever seen the same error and knows what we might have to configure?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!