Get Support
Recently active
Hi all,We have a Mac that shows "This Mac is owned by unknown" in the Remote Management window when provisioning. It is in ABM, assigned to one of our two MDMs.I tried switching it between MDMs in ABM, no luck. Also tried changing the PreStage Enrollment on each MDM server, no luck. Anyone ever see this? If so, any idea how to resolve? I opened a ticket with Jamf Support, but wanted to check here too. PS, I know I can "release" the device and use an iPhone to re-add it, but hoping that would be a last resort.TIA
Hi all,We have tested out the Jamf Compliance Editor and it works wonderfully till the point that we wipe the laptop and re enroll it. In order to better understand and troubleshoot the availability of the policies, we have set the remediation and compliance policies to ongoing and also added them to self service so that we can see when we run run them. For some reason, on a wiped laptop the remediation policy will be made available only one time after i ran the audit policy. However, the laptop wont be scoped to the remediation policy after that no matter what we did: Restart, waiting for 24-36 hours, reset baseline, ran audit policy again, delete the device from Jamf before enrolling, erasing the Macbook reinstalling OS from scratch and enrolling. The only thing that did work, was to install the compliance editor on the wiped laptop locally => create a new project => select the standard that we are aiming for (CIS1 in our case) => Create Guidance => Cl
Hi Folks,I'm Darshan Hiranandani, trying to figure out how to set my Mac's Wi-Fi to "Low Data Mode." Does anyone know the steps to enable this feature? I'd appreciate any guidance or suggestions from those who have done it before.Thanks in advance for your help!RegardsDarshan Hiranandani
On the 29th of July we will be removing two software titles from App Installers : BlueJeans and JetBrains AppCode. Verizon made the announcement that BlueJeans was sunset on March 29, 2024. You can read the announcement here. JetBrains announced the end of sales and support for AppCode back in December of 2022. You can read the announcement here. Whilst both titles will be removed from App Installers on Monday the 29th of July, they will not be removed on any Mac computers on which they are currently installed. As a reminder you can see the monthly history of what titles are added and retired from App Installers and Patch Management on the documentation page here.
I am working on an integration using the rest API, with the mobile devices I am having issues finding the correct attribute to correlate that a device is encrpyted.When I went into the iOS.security I find "HardwareEncryption" with a number, I cant find any documentation in regards to what the numbers mean, or how to identify that a mobile device is encrypted or not.
We are trying to understand how to pull what has been done when someone requests elevation through JamfConnect. I know that we can look at there reasonslog to see what reason they selected and when they elevated, but we will want to know what was changed. I thought there was something about being able to forward to Jamf Protect and we've added a couple configurations for both the reasons log and subsystem == "com.jamf.connect.daemon" && category == "PrivilegeElevation" however this is not providing us with what happened. Did they change system settings, did they uninstall or install an application? Has anyone set this up successfully? We're working with our SIEM but need to know where to get these logs first before we can look to forward them anywhere.
conditional access or device compliance for macOS? Which one is the better way? we start to register mac with Conditional access. should i wait of 10.43 and register all mac with device compliance? Thanks
I have run into a problem whereby apparently no users have a Secure Token, and there appear to be operations you can't perform unless you are Secure Token-enabled.All the documentation says that the admin user created during pre-stage enrollment should get the secure token, but it just flat-out doesn't. Multiple reinstalls, never does.I have found other people saying that they have the same problem, but that if they use a JAMF policy to create another user (as admin) and check the box to say that it's eligible to receive the secure token, they find that that works. It doesn't for me.And of course I can't use command line utilities to enable secure token because nobody is enabled.Secure Token-wise, our machines appear to be basically orphaned.Anyone have any ideas about how to fix this?Thanks,Lisa.
Testing installing this app https://github.com/root3nl/SupportApp and something isn't quite right that I can't figure out. 1. I have a Policy with this package where the Scope is my test computer.2. I have a Configuration Profile using Application & Custom Settings > External Applications using this json file.The Scope is a Smart Computer Group.3. The Smart Computer Group uses Criteria where the Profile Identifier "is" the Value of "149694A2-D63C-4195-94C6-26B778EFA58D" which is the Identifier of the application. The app is installed on my test computer but it is not picking up any of the settings from the json file. Any input would be appreciated.
I am looking for a solution to disable/hide the ability to activate Airplane Mode on iPadOS. I work in a K-12 school district and we have lots of devices around for various needs. Some offsite as well. Students and/or parents are turning on airplane mode and not allowing us to communicate with the device. I understand they can just disconnect from their own network but I'm trying to mitigate possibilities for no connection. If there is a way, pleas let me know what you got.
This is slightly alarming. Our lab Macs are set up with AD authentication (thru NoMAD) ; network users get a local home created at first login on any given computer. Network user accounts get standard permissions. Today I noticed that user homes are created with wrong permissions on some (but not all!) of the lab Macs. I would expect user homes to be owned by [some_user]:staff with default permissions 700. On some machines this is the case; on others I'm seeing 750 or 755. Especially weird because I just nuked & paved the whole lab, so configs should be identical. Am I overlooking something obvious? Where does the umask get set? I don't see anywhere in NoMAD to control it; is it coming from the AD server? [Intel iMacs running 13.6.7, highest os version they support]
I am in the process of installing Sophos using a policy. Sophos has several PPPCs, and Kernels that need to be put in place. These are being pushed by a configuration profile.I do not want the install of sophos to happen before the configuration policy is on the system, yet I do not see any option when creating a smart computer group to determine if the configuration policy has been applied. How do I verify the policy is in place before the install? Thanks in advance for your help!
Hi, I would like to check if anyone is still able to use the Energy Saver Profile in JAMF school?I have a Energy Saver Profile setup for all computer but seems like it not working anymore. Thank you
Hi, folks. We have some users who use their mobile hotspot on their Macs from time to time while traveling. Their mobile data is metered, so they enable "low data mode" under System Settings > Network > Wi-Fi > Details. Does this affect Jamf policies in any way? We deploy app updates with Jamf, which could quickly hit the data cap. I'd like to defer some/all policy downloads until Low Data Mode is disabled. Does anyone have a clever solution to avoid Jamf policies downloading large packages over metered connections?
Has anyone recently packaged and deployed Read & write (Text Help). Having some problems with PPPC profile which should be turning on accessibility for the software. Despite creating the profile using jamf ppc tool and deploying to the device Im still been prompted for admin rights to turn on the setting. Has anyone had this issue?
I recently had our Dev instance of Jamf Pro reset and I'm the process of rebuilding it. I added Entra as our Cloud IDP. Running 'test' with a few usernames, I was able to look users up and I have been successfully able to add 'Directory Service Users's into the 'Users and Groups' list. My only problem is, when I try to login to Jamf Pro with my Entra details it tells me 'Invalid Information Provided'What am I missing?
In Settings -> Automated Device Enrollment and via the API call "device-enrollments" you can view "deviceAssignedDate" which is the date each device was enrolled in your orgs JAMF. Assuming DEP machines that should be relatively close to the purchase date of those machines. The date is already in JAMF and it seems silly to have to run an api call to write it back as a searchable field assigned to each machine object. Both ADE and Computer objects have serial numbers so I can't imagine the match would be that hard. Seems it would be a way to get that information without needing GSXIs anyone already using "deviceAssignedDate" via the API and writing back?Is it already a searchable field and I'm missing it?
Hi,We've recently noticed that many of our users are missing the roster tab in jamf pro. We suspect there was some an issue when they were originally imported from ASM. This has since caused problems with the EDU profile installing which affects Classroom working.I'm interested to know if there was a way I could search for users with the roster tab missing? I've tried using the advanced searches and attempted "Roster User Status" but didn't have any luck.I'm hoping there is a way to search for this as I can then focus on all of these specific users rather than wait for them to contact us. Thanks in advance!
Is there a way to control notifications settings for apps deployed from Jamf Pro via something like a Plist file?
I am having issues updating a classic API script with the bearer token. Testing the script below I seem to have an issue somewhere as the variable will not propagate accordingly. I am getting "MBA-1" every time I run the script. # Getting the computer's serial number to make the API call serialnumber=$(system_profiler SPHardwareDataType | awk '/Serial/ {print $4}') # Decrypting the string above function DecryptString() { echo "${1}" | /usr/bin/openssl enc -md md5 -aes256 -d -a -A -S "${2}" -k "${3}" } string=$(DecryptString $EncryptedString $Salt $Passphrase) model=$(system_profiler SPHardwareDataType | grep "Model Identifier" | awk '{print $3}' | sed 's/[1-9].*$//') case $model in MacBookPro) short=MBS ;; MacBook) short=MB ;; MacBookAir) short=MBA ;; iMac) short=IMC ;; *) short=UNK ;; esac # A basic API Call that's getting information for the computer. # computerxml=$(curl -s -H “Authorization: Bearer ${token}” -H ${jamfurl}/JSSRes
Hello everyone! We currently use DUO MFA for our 2nd way to authorize who you are, the first being your password. DUO MFA has glitched too many times and it is NOT JAMF, and not Apple MacBook Pros running Sonoma 14 fault. I am wondering what MFA products are you using, if any. I am also wondering if there is a script out there that forces the user to use the fingerprint reader after they enter their password which would suffice MFA? If yes, I could dump DUO MFA program for once and all. When I reached out to DUO Tech support about the app glitches, you wouldn't believe the steps the end user has to take to get past DHO MFA. The steps are not for novice Mac users at all. Any suggestions greatly appreciated as always.
The new interface lacks a proper 'storage' column.While it does have one, the column only shows the capacity of the device, not the remaining capacity.
Could i please request the effort to implement the below Jamf Cloud engineer activities? Jamf Pro cloud tenant configuration & build- Pre-configuration of all settings for certificates, user accounts, enrolmentmethods, sites, buildings, and department groups.- Create policies and configuration profiles as required.- Support with the linking of Apple School Manager devices with resellers / Appleas required.- Configuration of pre-stage enrolment policies.- Configuration support of Jamf Pro distribution points and caching servers.- Upload of existing packages (20).- Audit and recreation of existing and new scripts, respectively.- Configuration of sites, buildings and departments in Jamf Pro with categoryassignation to all items.
Hi JamfNation,since the update to macOS 14.1 the Microsoft SSO Extension does not work anymore. Machines with up to 14.0 are doing fine, but 14.1 just breaks it. It doesn’t work anymore in Self Service, in Safari, in the Office Apps (here it goes so far as displaying an error when for example connect to a Data-File, lying on a sharepoint, we had to deactivate the SSO Config Profile there), it seems to be completely broken.The same goes for iOS / iPadOS 17.1. Did I overlook something I have to adjust with the updates? Is anyone to reproduce this? Is it a bug?Thankful for any input. RegardsDaniel
Hi Quick question in regards to why I cant see any FV personal recovery keys in Jamfpro when FV encryption is fully enabled. Seems rather a critical piece of info to not have available no? Any advice or help greatly appreciated
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!