Get Support
Recently active
Hey Everyone, Is it possible to pre-fill the email address "username" in the Cisco AnyConnect interface? we use profiles, I tried to add <User>user@example.com</User> in the server_list but it's not pre-filling it for some reason! Any tips on that? Thanks
While fetching policy using sudo jamf policy, we are getting the error:Any idea what might be causing this issue?
Hi all,I have an issue where staff are taking student-configured laptops out of the carts and using them as their own teacher MacBooks. Student laptops aren't configured in the same way as staff laptops and I'd like to prevent this from happening.While I can limit who can sign in to the actual Jamf Connect app by OU, I can't figure out how to limit who can log in to the Connect OAuth login screen. Does anyone know how to do this?The only limit I can find in Google Cloud Console is domains, not groups, subdomains, or OUs.Thanks!
We have two main admin groups with one having FULL access and the second which is the main one technicians use that has been setup with custom privileges. We want techs to have the option when they go to "Smart Computer Groups" > "View" to then have the ability to select the "Action" button and delete the computers. They do not see this button and I've sifted through the privileges and can't seem to find this access.
For troubleshooting, I'm trying to gather the Device ID of devices that have been registered with Azure/Entra via the Company Portal. I came across this particular post https://www.macbuddy.info/blog/lets-get-conditional-aad-id-ea which has the EA I'm trying to use. I've modified it slightly to give a result if there's no Device ID on the Mac. What I'm seeing though using either the original or modified script is what appears to be an intermittent issue where I will run 'recon' on my test machine, get the Device ID but then running 'recon' again will remove the Device ID. Running 'recon' again will sometimes bring it back sometimes not.I don't think it's a permissions issue as I should think it wouldn't work at all.Again I don't think it's the 'security find-certificate' issue line in the script as it does work sometimes.I'm at a loss to explain why it's happening.
Hi-We currently have a pretty small library of apps provisioned from our purchasing volume that are meant to be scoped to specific computers. I have most of those apps configured to install automatically rather than via self service because each app is supposed to be installed on specific machines that really shouldn't ever be without them. The apps are scoped to the specific machines they are meant to appear on via static computer groups, but for some reason each machine in my fleet is being pestered with "App Install - [Mac App]" MDM commands that are marked "Pending - All licenses are in use or the license is not assigned yet." Obviously, it's not a huge deal since only the scoped machines appear to be getting the license from the VPP and installing the app, but I am confused why these commands are being sent to machines that are out of scope for the app? Is there anything I need to do other than make sure the scope is correct for each Mac App?
I'm trying to push Certificate and set EAP and x.509 Basic Policy to Always Trust. I tried installing the cert and then modifying the settings, exporting the cert, then add it to a config profile but when deploying it, the settings never stick.I also tried to push it via policy with PostInstall script: security add-trusted-cert -d -r trustRoot -k "/Library/Keychains/System.keychain" "/private/tmp/certs/certname.cer" srm "/private/tmp/certs/certname.cer"Also tried : security add-trusted-cert -d -r trustAsRoot -k "/Library/Keychains/System.keychain" "/private/tmp/certs/certname.cer" srm "/private/tmp/certs/certname.cer"All with no luck. Has anyone tried this or maybe have the knowledge to help? Thanks
I see update or create policy documentation on Classic API. This API is getting a policy object in xml format, without its scripts property (unlike the response from GET on this api that returns xml of policy including its scripts).There is a way to link or unlink a script to a policy instance through API call? Thanks in advance
Is there a policy configuration that can prevent the on/off toggle for cellular data from being turned off? In Jamf Pro > Devices > Configuration Policies > Restrictions > Functionality, I see two settings related to cellular data that you can restrict: Modifying cellular planModifying cellular data app settings After testing, neither of these disable the Cellular Data on/off toggle setting. Is this not possible to restrict or am I missing something? Thanks in advance for the help.
Hello everyone,I would like to implement a script to set screen time for iPads, is this possible?Is it possible to set screen time using a script in JAMF Pro?Thanks in advance for your answers !
The jamf protect section on the official website says that it can prevent data leaks by detecting and logging AirDrop transfers, but is it possible to use jamf protect to check the contents of photos and videos sent via AirDrop by managed devices? Or does that mean that we can only see the AirDrop usage logs, but not the specific contents?
Jamf seems to have taken over Jetbrains Toolbox installation and causes issues when doing any software update.Toolbox is looking for/using /Library/Application Support/JamfAppInstallers/com.jetbrains.toolbox folder but Jamf keeps on deleting it. Need to recreate it manually every time to update a tool otherwise the Jetbrains software doesn't run at all.Can't see any setting to change this folder or to stop Jamf from removing it (and the child folders). Is there something that can be done?Thank you.
[https://blogs.technet.microsoft.com/office_for_mac_support_team_blog/2017/08/10/mac-outlook-support-utilities/](link URL) Microsoft has released some useful utilities for Mac Outlook 2016. OutlookSearchRepair: This utility will repair search results for Microsoft Outlook. Why use it: Search results within Outlook show nothing or return older items only such as when you are looking for an email you know you have and might already be looking at it but it doesn't show up in the search result. OutlookResetPreferences: This utility will reset all Outlook Preferences back to defaults. Why use it: This utility resets customizations you've made to Outlook from the Outlook menu > Preferences... It also stores settings of the Outlook window size and position. This utility shouldn't be needed often but we made it just in case. The Outlook Preferences file does not contain all the app's preferences and reseting Outlook Preferences will not remove email or account sett
hello, I am looking for a scrip to help me remove objects for inactivity of more than 90 days, however I have not achieved.I’m not that good at programming or command lines.I have researched and searched several forums however I have not found a script to help me run what I am looking for.someone from the community can guide me. I am new to the JAMF tool and my knowledge is very poor.
Hey everyone, I am in the home stretch of an application deployment but have one user experience issue I would like to resolve if possible. I have a new working Sophos deployment, however I get the attached pop up any time the policy runs for install. It must be accepted to install the software and bypassing that for our end users would be excellent. So far i have tried xattr -d com.apple.quarantine /var/tmp/SophosInstall/Contents/Helpers/SophosCBR.bundle before the install kicks off with no success. Any input would be greatly appreciated on if this is even possible to prevent.
System Preferences -> Security & Privacy -> Privacy -> Advertising Does anyone know of a way to enable this via plist or conf profile?
I'm working on setting up a policy for GlobalProtect 5.1.4 which switches to System Extension from Kernel Extensions. I've set up a config profile to approve the system extension. First I tried just the team ID, then I added the ALLOWED SYSTEM EXTENSIONS as well. but when I run systemextensionsctl list I get 1 extension(s) --- com.apple.system_extension.network_extension enabled active teamID bundleID (version) name [state] * PXPZ95SK77 com.paloaltonetworks.GlobalProtect.client.extension (5.1.4-45/1) GlobalProtectExtension [activated waiting for user] and System Preferences>Security & Privacy still has this prompt How can I approve this for the user?I tried a blanket PPPC config profile that just gave it all access, but still have that prompt. Anyone know how to solve this?
Hi All, I want to leverage the "system_profiler SPInstallHistoryDataType" command which will tell me all of the installed macOS updates. To do that I can add a pipe and grep the string "macOS". However I'm looking to get both the macOS update(s) that were installed and the Install Date when it happened into an Extension Attribute. As an example, one of the results of the command is below: macOS Mojave Security Update Developer Beta 2021-001: Version: 10.14.6 Source: Apple Install Date: 1/29/21, 9:11 AM From the above text, I'm looking to only display what is below into the EA: macOS Mojave Security Update Developer Beta 2021-001: Install Date: 1/29/21, 9:11 AM I'm not sure what what the command syntax will look like to get rid of the "middle" data from the result of the command. As you can imagine, the EA will continually update as new "macOS updates" get installed. Thanks to anyone that can offer guidance.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issue: Jamf Pro Server[PI119651] Creating or editing computer configuration profiles with payloads that require you to click Configure no longer causes the Jamf Pro user interface to spin indefinitely if debug mode is enabled in Settings > Information > Jamf Pro server logs. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 11.7.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. If you would like to upgrade manually, navigate to h
Hey everyone,We're currently in the POC phase with Jamf, and there's something that's really bugging me. We tried Kandji before, and their FileVault solution is way better than Jamf's. With Kandji, you just set up the profile, assign it to a Blueprint, and if FileVault is already enabled, it prompts the user to enter their password, rotates the key, and escrows it to their server. If FileVault isn't enabled, it forces the user to log off to enable FileVault and escrow the key. But with Jamf... it's not as simple as creating the config profile.For machines that already have FileVault enabled, we had to set up EscrowBuddy. The instructions were clear, but now we have 10 devices enrolled and 8 of them haven't escrowed their FileVault2 key to the Jamf server. This could go on forever because there doesn't seem to be an integrated solution (I couldn't find one in the options or this forum) that forces the user to log off.Does anyone have experience with this or know how to tackle the logoff
Can site access Admins create SCEP configuration profiles? I ask because when a site access admin creates a new configuration profile and selects the SCEP option from the left side configuration profile options, the user interface just spins and spins forever without giving an error. Same for an admin user added to group access for a site.The SCEP configuration profile settings only appear if signed onto Jamf as a full access administrator and showing/selecting Full Jamf Pro in the site list drop-down.It's like this on both our Jamf Pro Cloud Production and Development sites.Is this by design?
Hi there, We use the "Restrict the App Store" option in Jamf Pro Profile Config but this seems to not do anything to stop a user from signing in with their own Apple ID into the App Store on their MacBook. Does anyone know how to block signins to App Store?
I have seen bunch of scripts online but if someone has a working script which can deploy will be very helpful. I am looking a script which checks the last reboot of the machines. Then it would check if the reboot occurred less than 7 days or not. If the user hasn't rebooted for more than 7 days, the script will restart their machines. They will receive a popup that their laptop will be restarting and also allows them to extend the time by few hours before the laptop restarts.
We are unable to enrol new 4K Ethernet Apple TVs into Apple School Manager via Configurator 2.This was working perfectly a few months ago. When I click prepare, I can see the Apple TV is rebooting but not showing up under the devices in ASM. Has anyone encountered this issue recently?
Hello, Our organization is trying to implement VPN on shared iPads by implementing Jamf Trust App. It is working on our single user devices. On our shared iPads when we open Jamf Trust app and try to enable we receive error 412 reference 22a86ba1841985b8. I couldn't find other posts online referencing this error to see what we may be doing wrong.Has anyone been successful in implementing Jamf Trust on shared iPads or have tips of where to go from here?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!