Get Support
Recently active
Hi All, I haven't seen any discussion regarding OBS Studio and creating profile settings using PPPC or manually through JAMF Pro. Many of our teachers are requesting this software for teaching due to remote learning and any input is appreciated. Thank you!
I started getting a SSO timeout issue a few weeks ago when trying to sign in to my jamf pro instance. every morning, i get this time out warning and need to sign out of my office account, quit chrome, then hot my bookmark. Once i get there, i have to then select my account and sign out again, then sign back in. Any way to stop this other then using my failover account?
Hi AllCan anyone tell me, why is isn't possible to switch off the wifi for the App " TI Nspire CAS" over Jamf Teacher and for the App "GeoGebra" is it possible. Because the Apps need the "Guided access" to start Exam mode.Is this a matter of an App developer oder Jamf ?Thanks for you comment or help.Peter
Hello all, Would anyone out there be able to provide me with a Script that on execution would delete all Users and/or User's home folder's with the exception of the user that is logged in and an option to specify specific (admin) users that need to stay on there? It is likely that my Macs have a User Home folders that don't have a local user. So if the Local user doesn't exist, it still should wipe the Home folders of anyone but the current logged in user (and the specified admin user(s). I would be tremendously gratefull!
Hi allSince iOS 17, students can change the background with the new "Focus" function. When will this be integrated into the Jamf restrictions?Thank and best RegardsPeter
Dear community,I´ve got following problem:When erasing a device and wanting it to return to service afterwards, I use this configuration:Return to Service is checked, a valid network configuration is scoped. The option:"Install MDM profile after erasure" is NOT checked, because all our devices are registered in ASM. The documentation says:"If the device is registered in Apple School Manager, the MDM configuration can be omitted."Now when I confirm these settings, I get an error in the activity log saying "Für „Wiederinbetriebnahme“ ist ein MDM-Profil auf diesem Gerät erforderlich." Meaning: "A MDM-profile on the device is required for "return to service"". No erasure takes place.So I cannot use this option, although it is described this way in the documentation.https://learn.jamf.com/bundle/jamf-school-documentation/page/Return_Device_to_Service.html Does anybody experience the same problem or knows a possible solution?Thank You in advance, Daniel
Hi All, I am having issue with Microsoft Login (Azure) appearing on a Pre deployment with computers on Jamf ProCan anyone help me with this issue or send some instructions?
Hi,We have a set of classroom iPads which have been configured in Jamf School to prevent pupils from deleting their browser (Safari) history.Recently a pupil has been searching for inappropriate subjects, how do I delete the browser history now the matter has been dealt with? Thank you.
It would be nice if we were able to have a smart group of all lost mode devices to make it easier to follow up on. I don't see a way to do this.
I can see one mac is present in ABM and assigned to the correct MDM server in ABM but when we are going to provision the mac, it is configuring locally as personal mac device but not enrolling in JAMF automatically. I unassigned the mac from the present MDM and reassigned back to the same MDM server but still no luck. I can see the storage is showing Unknown in ABM portal for this mac, but for other macs it is showing the storage and those are getting enrolled in JAMF automatically. What might be the possible causes and what should be the resolution here?
Is there a document process for Jamf admins to recover Mac OS devices that have been locked with the Lock Computer command? I understand from prior threads there is the risk of brute force activity by the end user that could render the device useless. Is there any recommended best practice from Jamf to prevent this from happening?
Hello! I wanted to see how the hive mind was handling updating Apple's command line tools when they are not installed alongside Xcode. I currently have a smart group set up to track who has it installed without Xcode. I have attempted to push the PKG for 15.3 (from Apple's Developer website), but the issue is that after updated via Jamf, a new incremental update appears in the System Settings. This sort of defeats the purpose of Jamf updating them when the end user will have to manually update them anyway. Is there another way to update command line tools via Jamf that I am missing?Thank you in advance!
I'm having trouble logging in to Mut with my SSO. I get this error message, but I know my Jamf credentials are working because I use them every time I log into Jamf. Do I need to make some changes or have request access? I've tried using this link but still having issues.
Hi all, how would I change the password of the managed devices inside of Jamf, I know how to instruct them to change it from their end but im not sure how to change it from our end, how would I do this?
We are wanting to move to using the "Mac App" and the Jamf App catalog to manage several apps. Since it only support Smart Groups, simply assigning it to "All Managed Clients" or similar seems a bit lazy to me. What kind of workflows are you using? Generally we use a Policy that installs the app the first time to a static group that needs the application, not everyone gets Sketch for example. Then we use Patch Management for updates. We do have company wide applications such as Zoom that All Managed works for. Just interested in how others have gotten around the single Smart Group limitation of Mac Apps.
Got a question regarding WiFi troubleshooting. Our networking team was asking if there is a similar command like what they run on the windows side for troubleshooting (Netsh WLAN show WLANreport). Is there something similar that can be run on the Mac side? I was just going to enable logging and hoping that would capture the data the network guys would need to troubleshoot some disconnects on the local device. Since our users don't have admin rights, I was trying to create a policy that deploys the enable command via files and processes or even a script, but it doesn't enable logging./usr/libexec/airportd debug +AllUserland +AllDriver +AllVendor.
Hi,I use jamf school and we get new persons in our school. They will become iPads and in the last I mad new Persons in Jamf school. After i set everything for the new persons i send them a eMail with the initial Datas (Name and random generated password) with a short message. Now i cant find this point in jamf school and i cant send this information. Was something changed in jamf school in the past, or I am "blind" für this option. This is also relevant, if some person will loose his initial Datas, so I can send this too.ThxSchiller
So today I decided to get one of these old intel machines, a 2015 Macbook Pro a whirl. It has been erased and removed from Jamf as well as ASM, but still has the prompt to enroll in remote management during setup. I erased it again, but to no avail. Anyone got a clue what could be happening?
Hello All, We enabled SSO for Google Chrome and Edge browsers through a config profile, so that our users can log into the internal site without prompting the username and password again and again when they are in office network, all sudden it stopped working. Any idea what might be the reason, I can tell you the below is set in my config profile for GC and Edge and was working before.<key>AuthNegotiateDelegateAllowlist</key> <string>*.mycompany.com</string> <key>AuthServerAllowlist</key> <string>*.mycompany.com</string> Any idea what might be the cause and resolution?
I have a Mac that's already been encrypted with FileVault (Moving it from AirWatch as the MDM to Jamf), and the Disk Encryption page for this specific computer is blank. The computer's been encrypted according to System Preferences, but Jamf for some reason isn't able to see that information, or any information relating to ecryption for that matter. What can I do to get Jamf to see the FileVault info and escrow the recovery key? We're running Jamf Cloud if that's important
Hello all, After configuring a basic time machine setup Mac OS server running on Mac Pro with Sierra Setting up a Time Machine Configuration profile with the time machine folder address that I can navigate to across the network via smb (smb://mycompany.com/Timemachine) With folder restrictions set, and a size limit of 25gb The configuration profile logs show 'completed' on my test machine - but no backup ever initiates, and nothing is backed up to the folder Is there any other setting I need to apply? Do I need to input a managed preferences configuration and set 'enable time machine' in conjunction with the config profile? PS: I am aware TM isn't the best enterprise resource for backing up, but it's what I will have to make do with for now
I have a four computers which don't regularly checkin. It's my understanding, this is done by the Jamf binary, and is scheduled by /Library/LaunchDaemons/com.jamfsoftware.task.1.plistHowever, I have a bit of a struggle to go from there. The only computer I have access to is my own (probably next week I can debug another computer). When I check the com.jamfsoftware.task.1 global daemon on my own computer with Launch Control I see it has an error state, with exit code 1.When I check jamf help policy, exit code 1 is not documented...And when I run the same command from the command line, the exit code is also 1, and there are no error messages... Any pointers?
Hi allWe have 256GB Hard drives in our Mac90gb or so is usually taken up by the Logic pro sound files - sometimes slightly more.Then as users log in usiing AD accounts as our mac's are binded by AD - it leaves profile on the system and after month or 2 the mac device gets full. Only way round this is to manually delete the user profile folders in \\UsersI dont wish to do this every half term - can we automate this or stop it creating profile on login?Another thing that was mentioned by teacher is below? I am not sure how to overdcome this - can you advice? The only apps we need to use are:- Logic Pro- Google chrome / Safari We used to have a very limited number of apps in the finder but this is no longer the case - students can access Apple music, Photobooth and a whole host of programmes that we never need to use. It would be helpful to completely remove these from the Macs.Thanks in advance
As a follow-up to a recent post regarding some additional IP address that have been included in the Outbound traffic from Jamf Cloud, below is a list of the Outbound IP Address that have been added. For a complete list, please see the “Permitting Inbound/Outbound Traffic with Jamf Cloud” document located here: Permitting Inbound/Outbound Traffic with Jamf Cloud - Technical Articles | Jamf Regions IP Addresses U.S. (All Regions) 3.20.128.255 13.59.243.28 3.136.211.17 34.210.123.67 52.34.235.199 44.233.235.210 3.143.53.82 3.143.197.217 3.138.59.62 44.241.188.201 35.80.208.227 44.242.64.192 3.23.255.131 3.143.15.105 3.130.63.29 52.89.86.60 44.234.217.245 52.34.212.159 eu-central-1 18.195.58.189 3.120.154.185 3.66.207.103 3.65.178.125 3.65.51.99 35.156.181.161 18.196.78.65 52.28.3.192 3.72.173.10 eu-west-2 13.41.154.59 3.11.42.21 18.135.155.218 18.168.143.142 18.135.241.236 18
Is there any way to get JAMF to run a script locally on a JAMF pro server? I am trying to find a good solution to create a bearer token to pass to a script as I do not want to pass API user name/ password or base64, or encrypted credentials to a script that gets a bearer token as these all will eventually be viewable on the users machine. If there was a way for a script to be run locally on the Jamf server to create the bearer token that then could be passed to a policy at least it would be more secure as we have control over the JAMF server. Any solutions out there?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!