Get Support
Recently active
Hi all, how would I change the password of the managed devices inside of Jamf, I know how to instruct them to change it from their end but im not sure how to change it from our end, how would I do this?
We are wanting to move to using the "Mac App" and the Jamf App catalog to manage several apps. Since it only support Smart Groups, simply assigning it to "All Managed Clients" or similar seems a bit lazy to me. What kind of workflows are you using? Generally we use a Policy that installs the app the first time to a static group that needs the application, not everyone gets Sketch for example. Then we use Patch Management for updates. We do have company wide applications such as Zoom that All Managed works for. Just interested in how others have gotten around the single Smart Group limitation of Mac Apps.
Got a question regarding WiFi troubleshooting. Our networking team was asking if there is a similar command like what they run on the windows side for troubleshooting (Netsh WLAN show WLANreport). Is there something similar that can be run on the Mac side? I was just going to enable logging and hoping that would capture the data the network guys would need to troubleshoot some disconnects on the local device. Since our users don't have admin rights, I was trying to create a policy that deploys the enable command via files and processes or even a script, but it doesn't enable logging./usr/libexec/airportd debug +AllUserland +AllDriver +AllVendor.
Hi,I use jamf school and we get new persons in our school. They will become iPads and in the last I mad new Persons in Jamf school. After i set everything for the new persons i send them a eMail with the initial Datas (Name and random generated password) with a short message. Now i cant find this point in jamf school and i cant send this information. Was something changed in jamf school in the past, or I am "blind" für this option. This is also relevant, if some person will loose his initial Datas, so I can send this too.ThxSchiller
So today I decided to get one of these old intel machines, a 2015 Macbook Pro a whirl. It has been erased and removed from Jamf as well as ASM, but still has the prompt to enroll in remote management during setup. I erased it again, but to no avail. Anyone got a clue what could be happening?
Hello All, We enabled SSO for Google Chrome and Edge browsers through a config profile, so that our users can log into the internal site without prompting the username and password again and again when they are in office network, all sudden it stopped working. Any idea what might be the reason, I can tell you the below is set in my config profile for GC and Edge and was working before.<key>AuthNegotiateDelegateAllowlist</key> <string>*.mycompany.com</string> <key>AuthServerAllowlist</key> <string>*.mycompany.com</string> Any idea what might be the cause and resolution?
I have a Mac that's already been encrypted with FileVault (Moving it from AirWatch as the MDM to Jamf), and the Disk Encryption page for this specific computer is blank. The computer's been encrypted according to System Preferences, but Jamf for some reason isn't able to see that information, or any information relating to ecryption for that matter. What can I do to get Jamf to see the FileVault info and escrow the recovery key? We're running Jamf Cloud if that's important
Hello all, After configuring a basic time machine setup Mac OS server running on Mac Pro with Sierra Setting up a Time Machine Configuration profile with the time machine folder address that I can navigate to across the network via smb (smb://mycompany.com/Timemachine) With folder restrictions set, and a size limit of 25gb The configuration profile logs show 'completed' on my test machine - but no backup ever initiates, and nothing is backed up to the folder Is there any other setting I need to apply? Do I need to input a managed preferences configuration and set 'enable time machine' in conjunction with the config profile? PS: I am aware TM isn't the best enterprise resource for backing up, but it's what I will have to make do with for now
I have a four computers which don't regularly checkin. It's my understanding, this is done by the Jamf binary, and is scheduled by /Library/LaunchDaemons/com.jamfsoftware.task.1.plistHowever, I have a bit of a struggle to go from there. The only computer I have access to is my own (probably next week I can debug another computer). When I check the com.jamfsoftware.task.1 global daemon on my own computer with Launch Control I see it has an error state, with exit code 1.When I check jamf help policy, exit code 1 is not documented...And when I run the same command from the command line, the exit code is also 1, and there are no error messages... Any pointers?
Hi allWe have 256GB Hard drives in our Mac90gb or so is usually taken up by the Logic pro sound files - sometimes slightly more.Then as users log in usiing AD accounts as our mac's are binded by AD - it leaves profile on the system and after month or 2 the mac device gets full. Only way round this is to manually delete the user profile folders in \\UsersI dont wish to do this every half term - can we automate this or stop it creating profile on login?Another thing that was mentioned by teacher is below? I am not sure how to overdcome this - can you advice? The only apps we need to use are:- Logic Pro- Google chrome / Safari We used to have a very limited number of apps in the finder but this is no longer the case - students can access Apple music, Photobooth and a whole host of programmes that we never need to use. It would be helpful to completely remove these from the Macs.Thanks in advance
As a follow-up to a recent post regarding some additional IP address that have been included in the Outbound traffic from Jamf Cloud, below is a list of the Outbound IP Address that have been added. For a complete list, please see the “Permitting Inbound/Outbound Traffic with Jamf Cloud” document located here: Permitting Inbound/Outbound Traffic with Jamf Cloud - Technical Articles | Jamf Regions IP Addresses U.S. (All Regions) 3.20.128.255 13.59.243.28 3.136.211.17 34.210.123.67 52.34.235.199 44.233.235.210 3.143.53.82 3.143.197.217 3.138.59.62 44.241.188.201 35.80.208.227 44.242.64.192 3.23.255.131 3.143.15.105 3.130.63.29 52.89.86.60 44.234.217.245 52.34.212.159 eu-central-1 18.195.58.189 3.120.154.185 3.66.207.103 3.65.178.125 3.65.51.99 35.156.181.161 18.196.78.65 52.28.3.192 3.72.173.10 eu-west-2 13.41.154.59 3.11.42.21 18.135.155.218 18.168.143.142 18.135.241.236 18
Is there any way to get JAMF to run a script locally on a JAMF pro server? I am trying to find a good solution to create a bearer token to pass to a script as I do not want to pass API user name/ password or base64, or encrypted credentials to a script that gets a bearer token as these all will eventually be viewable on the users machine. If there was a way for a script to be run locally on the Jamf server to create the bearer token that then could be passed to a policy at least it would be more secure as we have control over the JAMF server. Any solutions out there?
hello,We had a question from a customer evaluating Jamf Connect Login, if it can work with on premises AD (they have a hybrid environment). Essentially, they would like to mimic NoMAD and NoLOAD behavior (local account, remaining days of password appearance, native macOS login screen).I am aware that JCL works only with Entra. Best regardsK
We have a bunch of iPads (Nearly 100) that we've added to the MDM (some manually and some were put on there by our equipment provider) and have app licences set up on Apple School Manager. I can deploy the apps/licences through JAMF and they start to install on the iPads, but they keep asking for an Apple Sign In before it can actually install it.Is there some kind of setting/profile somewhere that I can add to the iPad so it silently installs apps instead of asking every time?
I'm looking at using the Software Update feature to handle MacOS software updates.Under the Download, install, and allow deferral option, it prompts you for a number of deferrals to allow. What exactly is a deferral, and how often do they occur? For instance, If I wanted to allow a user to defer an update for up to two weeks, how do I determine how many deferrals need to be allowed to accomplish that?Also, under the Target version option, assuming a device can run the latest version of MacOS, what is the difference between Latest version based on device eligibility vs Latest major version vs Latest minor version? Are these terms defined somewhere?
We have encountered the scenario described in this post: https://developer.apple.com/forums/thread/715220We took a brand new MacBookPro that came with Ventura pre-installed on it and after it enrolled via DEP, we sometimes login as the admin account and run sudo jamf policy to speed up the full enrollment process. This time we discovered that we encountered a problem. It appears that Ventura now doesn't let us run Terminal commands that change apps. In System Settings > Privacy & Security > App Management Terminal was listed but not enabled.Is there an MDM setting in Jamf that will allow us to pre-approve Terminal and any other apps we need to have this functionality?
I've been trying to figure out a way to utilize this new service across our mac devices that still require LDAP user authentication. Has anyone else successfully got this to work?Right off the bat I cannot figure a simple solution of injecting the certificates Google requires to a client and authenticate directly. So I started digging into the idea of running open directory and using stunnel. I ran into some road blocks configuring the .conf file and getting it to communicate to google. Is this the way to go? Or is there is better solution I am not able to find online?
so we made the switch to device complinace recently but i have a few macs that are reporting in to intune instead of entra. this is a very small percentage of macs, less than 10 persent, but its infuriating... has anyone seen this?
hi,i am trying to create a site to site tunnel between our Jamf Trust tenant and our Meraki MX 100 firewall on prem, no matter what proposal or cypher settings i try, i cant seem to get the tunnel up.I see this error on the Jamf Trust log and i assure you, everything has been entered correctlyDefinitionYour authentication failed due to an error in the IKE_AUTH exchange.TroubleshootingVerify the IKE domain ID on the customer side is correct.Verify you are using IKEv2.Verify that you have specified the correct matching pre-shared keys.
HelloI am having a reoccurring issue where students in a classroom when using JAMF Connect it states that their local account is locked out when trying to sign in.If I find the MAC on JAMF Pro and go to Local user accounts and click manage on the locked out user I have the option to Unlock Account or Delete Account, the Unlock Account does not seem to unlock the user and the only method I have found that works is to Delete the account which is not ideal with student accounts who may not have backed up all their work.Is there any other option or a script that could unlock that account?Thank you
I am using a pretty generic version of the DEPNotify script, but I would like to be able to have it display a visual log of what applications have installed/failed all on the screen while the DEP enrollment is running so that techs have an easy way to verify all required apps have installed, without checking them one by one. Does anyone have any advice or tips on how to best get started? Scripting isn't my strongest area, but I generally can get by but this one has me scratching my head
Greetings!We have received a notice from campus network security team, saying that in coming months, internet inbound network traffic, where network traffic originated from public internet and to be received within campus networks, will be denied as default, but the outbound to the internet is allowedI am concerned the connection of our 60 iPads to JamfPro cloud, I read the document at https://learn.jamf.com/en-US/bundle/technical-articles/page/Permitting_InboundOutbound_Traffic_with_Jamf_Cloud.html . I'd like to clarify whether I need to ask the campus network team to add the IPs of "ap-northeast-1" under "Outbound Traffic from Jamf Cloud" onto their whitelists.Regards.Simon
We have a lot of old machines that have not completed a check-in, in quite some time. I really would prefer not to delete these, as the data could potentially be useful in the future (Such as a FileVault recovery key, or user/program data). Is it possible to "Archive" a computer? Or is deleting them the only thing JSS can do currently?
Hello everyone. We are no longer using Nudge and would like to uninstall it. Anyone have an idea on how to do this? I do not see an uninstall in the download of the apps. This needs to be pushed out via JAMF.
Hi, I have an iPad set up as a Shared Device, when a specific user logs on and wants to use the camera app to use the video mode, instantly a message shows saying that the storage is full. The iPad has 40gb free, the iCloud storage for the user has 2gb free. Anyone else that have ran into this issue?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!