Get Support
Recently active
I'm trying to determine if this is possible. I know Jamf can keep track of what applications are installed. Is it possible for it to track when an application is installed via a 3rd party app store or cli and not from the official app store or self service app? Maybe via an extension attribute or something. I'm still researching this outside of this post as well. If i do find an answer outside of this forum. I will update this post to include those instructions for anyone that may need it in the future.
What happens if software vendor releases bad patch via Mac Apps? Is there a way to stop a bad patch if set to automatically patch devices that fall in the smart device? Users are receiving notifications that the app is ready to be applied, forcing the app to quit. We then found out that the update is breaking part of our environment. I have turned off the deploy button in Mac Apps for that app, but isn't the download already cached on the device and ready to deploy as soon as the application force quits? Any way to stop this?
A few years ago I was able to get my fleet transitioned from AD accounts to local accounts with managed passwords via Enterprise Connect and then kerberos SSO. Since we're no longer binding I've created a workaround to leverage ad groups to apply policies. My policy reads the Kerberos SSO signed in credential, strips that to just their User ID, and then runs a /usr/local/bin/jamf policy -username $founduser The policy is great when run via self service, however it fails running on an automated trigger. My first chat with Jamf Support tried to tell me that i was reading the username incorrectly which is why it fails, however I think it's due to the fact it's a policy calling another policy. I get a Script result: Local User Profile name is USERID Checking for User Specific Policies This policy trigger is already being run: root 4028 0.0 0.1 411796288 33456 ?? S 8:20AM 0:00.23 /usr/local/jamf/bin/jamf policy -event CLIENT_CHECKIN -stopConsoleLogs Does anyone do anything like this? Have a
I’m new to Jamf development and have been learning a bit from our senior Jamf developer, who said one of our biggest complaints from end users was not knowing when an application had finished updating because it would never relaunch.So that’s what I set out to explore. My goal was to create and deploy a browser package that would automatically relaunch the browser post-update.Someone on the forums suggested using Jamf Pro > Computers > Content Management > Mac Apps > Jamf App Catalog, since there I would have the ability to select the option “Automatically open app after update.”Should mention here that this is different from the Packaging process we are using, which can be described as:Create a new Package when a new version of an app becomes availableUpdate the existing Patch Management policy to reflect the new version of the appDeploy to whatever groups we’ve scoped in the Patch Management policyFor my test:I created a Smart Group that contains just one of my test Macs.
I have recently created a script that I will be using for a monthly policy to encourage users to reboot their Macs regularly. I'm using Swift Dialog to show a prompt to users to reboot. I am giving them the ability to defer rebooting up to 3 times. I also added a function in the script that will check if either Zoom or Teams is in a meeting. The Swift Dialog window won't appear if either app is in a meeting. Instead a launch daemon is installed and loaded to ensure that the policy runs again. When a user defers, the deferral time is written to a PLIST. The PLIST tracks the time and date of each deferral, how many times the user has deferred, and how many deferrals are remaining. The launch daemon is also installed after a deferral. I want the launch daemon to launch the policy again 1 day after the user defers or after the script finds that the user is in a Zoom or Teams meeting. In my tests, I set the StartInterval to 300 seconds so I wouldn't need to wait a full day. After I saw that
Hello,does anyone have any experience using the DNS configuration setting? I set it to use https://dns.google/dns-query on our Apple TVs to bypass our content filter, which worked, but now they're not checking in anymore! It's probably fine since I can just reset them if I need to get rid of that, but it would be nice to know they're still otherwise working properly.
Hi there, Has anyone managed to get the end user notification payload in jamf to work? Seems all the configurations I have applied using app bundle Ids dont adjust notifications end user side at all. I still get prompted to allow notifications for the apps I've configured in the profile.
Hi there, is there a way to check the logs of a admin user in jamf pro portal to identify what they have done on the portal. We have few members who has access to the portal buy i cant see any way of pulling a report of what that user has done.Thanks very much!
Hi,I'm looking to automate the sign-in process for the Office suite on Mac devices used by our students. Ideally, I want Office to automatically pick up their login details and sign them in with their credentials. So far, I haven't had any success in implementing this.Has anyone managed to get this working? Any advice or resources would be greatly appreciated. is there a script out there somewhere I can use to achieve this?
Hi all! Wanted to see if anyone else is seeing this issue before I reach out to Jamf Support.When deploying apps from the Jamf Catalog with Mac Apps the applications deploy but never report back as Complete. After confirming that any app that we've tested has successfully updated they only show In Progress it the deployment status. It never changes and is very frustrating when trying to track the updates for our InfoSec Office. I've gone through the instructions numerous times and still no joy here.Suggestions would be greatly appreciated.
From AP:cisco C9120AXI-B ARMv8 Processor rev 0 (v8l) with 1875204/1065904K bytes of memory.Processor board ID FJC26381AZTAP Running Image : 17.6.4.56Primary Boot Image : 17.6.4.56Backup Boot Image : 0.0.0.0Primary Boot Image Hash:Backup Boot Image Hash:1 Multigigabit Ethernet interfaces Controller:Cisco Catalyst 9800-40 Wireless Controller17.3.4c My thoughts were that the controller was supposed to downgrade or upgrade an AP if the versions did not match to match the controller. Is that not how this works? Or do I need to update the controller to match the 60 AP's we just bought?
My original posting for this started off as just an Extension Attribute. In the past 3 days, it has become a full blown workflow. Here's that workflow. JAMF Software Deployment: Nessus Agent for Apple Macintosh INTRODUCTIONTenable Network Security's Nessus software is currently being utilized for vulnerability scanning and vulnerability management within the enterprise. JAMF Software's Casper Suite (JSS) is used to manage Apple Macintosh systems within the enterprise. This includes the deployment of software packages such as the Nessus agent. This article describes the various elements and requirements as utilized by the Casper Suite in order to package and deploy the Nessus agent to Macintosh systems within the enterprise. TOPICS....Preparing for Deployment........The Software............Acquiring the Nessus agent............Creating a Custom PKG Payload................Acquiring and Installing Casper Composer................Overview and Purpose of Creating a Cust
In a computer lab environment, we are currently redirecting student’s desktop documents etc to an alternative ‘Local’ folder created within the profile on logging in. This is done using symbolic links in a script. We were previously redirecting the desktop documents to their network homefolders but these have now been decommissioned, so we are looking to do a local redirection for the purposes of space management.Unfortunately, the local redirection doesn’t appear to work well, in that when you save to the desktop, documents etc, the file doesn’t automatically appear in the relevant folder. You would need to go into Finder and select the relevant folder for it to appear. This isn’t even the case with the Documents folder, selecting it in finder doesn’t bring up the most recent file, you need to put the full path to the redirected Documents into “Go to folder” in order to see the files, else logout & back-in. The files are seen in terminal and using preview app. Relaunchi
I had asked this as a reply to a solved issue but I figured I would open a new conversation here. I've been asked if we can have Jamf Pro capture information (type, serial number, etc.) USB devices and monitors are attached to our managed computers. I've seen on forums that this can be done with the an Extension Attribute utilizing system_profiler but I haven't found clear instructions on how to set this up. I found that running "system_profiler SPDisplaysDataType" and "system_profiler SPUSBDataType" from Terminal provides the info I need but I'm stumped on how to have those commands run in Jamf so the info populates per machine.Thanks in advance!
Good afternoon.I am trying to set up Kerboros SSO in place of binding MacBooks to active directory and using mobile network accounts. This will be on laptops that only have a single user. The only thing I want Kerboros to manage is to sync local account passwords to match a users active directory password. I got things working to the point where the passwords sync and it works pretty slick.The problem I am having is that window to sync their mac password and their Active directory password comes up on every login. The user can cancel out of the window our type their two passwords again, but its a bit annoying that it comes up on every login. Is there a way to have this password sync check pop up maybe only monthly? Thank you, Doug
Is Jamf capable of reporting what monitors and external devices are connected to Macs? If not, is there a 3rd party app that is capable of this? Thanks!
Our institution's push certificate expired, a new one was created and uploaded. My question is around getting the MDM profiles updated on our machines. Is there an easy way I can utilize JAMF (or even ARD?) to automatically update the MDM profile on all of our machines? We have ~200 Macs and I'm hoping we don't have to manually re-enroll them all. Thank you in advance for any advice you can offer!
Hi, communnity!I have a problem regarding app branding. I have set an icon for testing in my DEV instance to check that both app icon and self service banner were working fine. The issue has arrived after having implemented in PROD when we've noticed that Self Service app is not retrieving nor app icon or banner from Jamf Pro/ Settings/ Branding/ MacOS. After that we've been testing in DEV to change to a different icon to check if changes will applied but it's applying the old icon image who's been removed from settings. It's like the old image remain cached.Any clue on that?Thanks in advance,
Hi - so the box tools (or box edit) is a .dmg file. the only way i know how to silent install is a .pkg format (installer command). 1st step via composer is to convert the dmg to pkgthen package it via casper admin.then push out as a policy i get what looks like a confirmation that it installed successfully: Verifying package integrity...Installing BoxToolsInstaller.pkg...Successfully installed BoxToolsInstaller.pkg. but it's not working. box tools is not installed. please help. thanks
instead of waiting for jamf policy to run at the jamf execution frequency Is there a way to force a policy to run instantly?
Hello, I am looking for a solution for the accessibility settings that the NWEA testing app asks for after installation from self service. I have created a package using composer for both Catalina and Big Sur and placed them in self service. The apps are installing on the laptops but now they are asking for the Admin password to make changes in Security and Privacy/Accessibility. We are using both standard user and admin user accounts depending on the location (elementary-standard user, middle school-admin). I would like to avoid this during first launch of the app since we do not want to have to give out the admin credentials to the elementary school users.
I’ve passed the JAMF 200 and have been learning about JAMF from Jamf Catalog and also trying to get more hands on experience at work.I'm keen to learn more and aim to do JAMF 300 in 6 months time. Are there any good books for new Mac Admins? I’m keen to learn more about scripting and macOS so maybe a book on AppleScript? I’m open to any suggestions that may have helped others in their Mac Admin careers.
I've used command sudo jamf removemdmprofile and sudo jamf removeframework to fix certificate expired issue, After that I renerolled my mac with Jamf with web. My mac received all configuration profiles, but self service applicaton and jamf binary can not be pushed on my mac. Anyone knows how to install that manually?
Autodesk sadly doesn't have a removal script for macOS. So I made one using their collection of random documentation. It removes all Autodesk apps, the system files and user files.One piece missing is FlexNet, since this is used by other Applications and should be kept. #!/bin/bash # Autodesk Cleanup Script currentUser=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) # Removes Autodesk Applications sudo rm -rf /Applications/Autodesk/ # Removes Autodesk User Library Files rm -rf /Users/$currentUser/Library/Application Support/AdSSO-v2 rm -rf /Users/$currentUser/Library/Application Support/Autodesk rm -rf /Users/$currentUser/Library/Application Support/Autodesk Installer rm -rf /Users/$currentUser/Library/Logs/Autodesk rm -rf /Users/$currentUser/Library/Logs/Autodesk Installer rm -rf /Users/$currentUser/Adlm sudo rm -rf /Users/$currentUser/Autodesk # Removes all com.autodesk files from user's logs and
Hey y'all! I'm currently mass uninstalling an antivirus program within our environment. I got the script to run as I need it to but with one problem: to complete the uninstall, it prompts for a local admin password to remove the system extension. How do I get around this without going to almost 200+ computers to input local admin information?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!