Get Support
Recently active
hello,We had a question from a customer evaluating Jamf Connect Login, if it can work with on premises AD (they have a hybrid environment). Essentially, they would like to mimic NoMAD and NoLOAD behavior (local account, remaining days of password appearance, native macOS login screen).I am aware that JCL works only with Entra. Best regardsK
We have a bunch of iPads (Nearly 100) that we've added to the MDM (some manually and some were put on there by our equipment provider) and have app licences set up on Apple School Manager. I can deploy the apps/licences through JAMF and they start to install on the iPads, but they keep asking for an Apple Sign In before it can actually install it.Is there some kind of setting/profile somewhere that I can add to the iPad so it silently installs apps instead of asking every time?
I'm looking at using the Software Update feature to handle MacOS software updates.Under the Download, install, and allow deferral option, it prompts you for a number of deferrals to allow. What exactly is a deferral, and how often do they occur? For instance, If I wanted to allow a user to defer an update for up to two weeks, how do I determine how many deferrals need to be allowed to accomplish that?Also, under the Target version option, assuming a device can run the latest version of MacOS, what is the difference between Latest version based on device eligibility vs Latest major version vs Latest minor version? Are these terms defined somewhere?
We have encountered the scenario described in this post: https://developer.apple.com/forums/thread/715220We took a brand new MacBookPro that came with Ventura pre-installed on it and after it enrolled via DEP, we sometimes login as the admin account and run sudo jamf policy to speed up the full enrollment process. This time we discovered that we encountered a problem. It appears that Ventura now doesn't let us run Terminal commands that change apps. In System Settings > Privacy & Security > App Management Terminal was listed but not enabled.Is there an MDM setting in Jamf that will allow us to pre-approve Terminal and any other apps we need to have this functionality?
I've been trying to figure out a way to utilize this new service across our mac devices that still require LDAP user authentication. Has anyone else successfully got this to work?Right off the bat I cannot figure a simple solution of injecting the certificates Google requires to a client and authenticate directly. So I started digging into the idea of running open directory and using stunnel. I ran into some road blocks configuring the .conf file and getting it to communicate to google. Is this the way to go? Or is there is better solution I am not able to find online?
so we made the switch to device complinace recently but i have a few macs that are reporting in to intune instead of entra. this is a very small percentage of macs, less than 10 persent, but its infuriating... has anyone seen this?
hi,i am trying to create a site to site tunnel between our Jamf Trust tenant and our Meraki MX 100 firewall on prem, no matter what proposal or cypher settings i try, i cant seem to get the tunnel up.I see this error on the Jamf Trust log and i assure you, everything has been entered correctlyDefinitionYour authentication failed due to an error in the IKE_AUTH exchange.TroubleshootingVerify the IKE domain ID on the customer side is correct.Verify you are using IKEv2.Verify that you have specified the correct matching pre-shared keys.
HelloI am having a reoccurring issue where students in a classroom when using JAMF Connect it states that their local account is locked out when trying to sign in.If I find the MAC on JAMF Pro and go to Local user accounts and click manage on the locked out user I have the option to Unlock Account or Delete Account, the Unlock Account does not seem to unlock the user and the only method I have found that works is to Delete the account which is not ideal with student accounts who may not have backed up all their work.Is there any other option or a script that could unlock that account?Thank you
I am using a pretty generic version of the DEPNotify script, but I would like to be able to have it display a visual log of what applications have installed/failed all on the screen while the DEP enrollment is running so that techs have an easy way to verify all required apps have installed, without checking them one by one. Does anyone have any advice or tips on how to best get started? Scripting isn't my strongest area, but I generally can get by but this one has me scratching my head
Greetings!We have received a notice from campus network security team, saying that in coming months, internet inbound network traffic, where network traffic originated from public internet and to be received within campus networks, will be denied as default, but the outbound to the internet is allowedI am concerned the connection of our 60 iPads to JamfPro cloud, I read the document at https://learn.jamf.com/en-US/bundle/technical-articles/page/Permitting_InboundOutbound_Traffic_with_Jamf_Cloud.html . I'd like to clarify whether I need to ask the campus network team to add the IPs of "ap-northeast-1" under "Outbound Traffic from Jamf Cloud" onto their whitelists.Regards.Simon
We have a lot of old machines that have not completed a check-in, in quite some time. I really would prefer not to delete these, as the data could potentially be useful in the future (Such as a FileVault recovery key, or user/program data). Is it possible to "Archive" a computer? Or is deleting them the only thing JSS can do currently?
Hello everyone. We are no longer using Nudge and would like to uninstall it. Anyone have an idea on how to do this? I do not see an uninstall in the download of the apps. This needs to be pushed out via JAMF.
Hi, I have an iPad set up as a Shared Device, when a specific user logs on and wants to use the camera app to use the video mode, instantly a message shows saying that the storage is full. The iPad has 40gb free, the iCloud storage for the user has 2gb free. Anyone else that have ran into this issue?
Hey Everyone, Is it possible to pre-fill the email address "username" in the Cisco AnyConnect interface? we use profiles, I tried to add <User>user@example.com</User> in the server_list but it's not pre-filling it for some reason! Any tips on that? Thanks
While fetching policy using sudo jamf policy, we are getting the error:Any idea what might be causing this issue?
Hi all,I have an issue where staff are taking student-configured laptops out of the carts and using them as their own teacher MacBooks. Student laptops aren't configured in the same way as staff laptops and I'd like to prevent this from happening.While I can limit who can sign in to the actual Jamf Connect app by OU, I can't figure out how to limit who can log in to the Connect OAuth login screen. Does anyone know how to do this?The only limit I can find in Google Cloud Console is domains, not groups, subdomains, or OUs.Thanks!
We have two main admin groups with one having FULL access and the second which is the main one technicians use that has been setup with custom privileges. We want techs to have the option when they go to "Smart Computer Groups" > "View" to then have the ability to select the "Action" button and delete the computers. They do not see this button and I've sifted through the privileges and can't seem to find this access.
For troubleshooting, I'm trying to gather the Device ID of devices that have been registered with Azure/Entra via the Company Portal. I came across this particular post https://www.macbuddy.info/blog/lets-get-conditional-aad-id-ea which has the EA I'm trying to use. I've modified it slightly to give a result if there's no Device ID on the Mac. What I'm seeing though using either the original or modified script is what appears to be an intermittent issue where I will run 'recon' on my test machine, get the Device ID but then running 'recon' again will remove the Device ID. Running 'recon' again will sometimes bring it back sometimes not.I don't think it's a permissions issue as I should think it wouldn't work at all.Again I don't think it's the 'security find-certificate' issue line in the script as it does work sometimes.I'm at a loss to explain why it's happening.
Hi-We currently have a pretty small library of apps provisioned from our purchasing volume that are meant to be scoped to specific computers. I have most of those apps configured to install automatically rather than via self service because each app is supposed to be installed on specific machines that really shouldn't ever be without them. The apps are scoped to the specific machines they are meant to appear on via static computer groups, but for some reason each machine in my fleet is being pestered with "App Install - [Mac App]" MDM commands that are marked "Pending - All licenses are in use or the license is not assigned yet." Obviously, it's not a huge deal since only the scoped machines appear to be getting the license from the VPP and installing the app, but I am confused why these commands are being sent to machines that are out of scope for the app? Is there anything I need to do other than make sure the scope is correct for each Mac App?
I'm trying to push Certificate and set EAP and x.509 Basic Policy to Always Trust. I tried installing the cert and then modifying the settings, exporting the cert, then add it to a config profile but when deploying it, the settings never stick.I also tried to push it via policy with PostInstall script: security add-trusted-cert -d -r trustRoot -k "/Library/Keychains/System.keychain" "/private/tmp/certs/certname.cer" srm "/private/tmp/certs/certname.cer"Also tried : security add-trusted-cert -d -r trustAsRoot -k "/Library/Keychains/System.keychain" "/private/tmp/certs/certname.cer" srm "/private/tmp/certs/certname.cer"All with no luck. Has anyone tried this or maybe have the knowledge to help? Thanks
I see update or create policy documentation on Classic API. This API is getting a policy object in xml format, without its scripts property (unlike the response from GET on this api that returns xml of policy including its scripts).There is a way to link or unlink a script to a policy instance through API call? Thanks in advance
Is there a policy configuration that can prevent the on/off toggle for cellular data from being turned off? In Jamf Pro > Devices > Configuration Policies > Restrictions > Functionality, I see two settings related to cellular data that you can restrict: Modifying cellular planModifying cellular data app settings After testing, neither of these disable the Cellular Data on/off toggle setting. Is this not possible to restrict or am I missing something? Thanks in advance for the help.
Hello everyone,I would like to implement a script to set screen time for iPads, is this possible?Is it possible to set screen time using a script in JAMF Pro?Thanks in advance for your answers !
The jamf protect section on the official website says that it can prevent data leaks by detecting and logging AirDrop transfers, but is it possible to use jamf protect to check the contents of photos and videos sent via AirDrop by managed devices? Or does that mean that we can only see the AirDrop usage logs, but not the specific contents?
Jamf seems to have taken over Jetbrains Toolbox installation and causes issues when doing any software update.Toolbox is looking for/using /Library/Application Support/JamfAppInstallers/com.jetbrains.toolbox folder but Jamf keeps on deleting it. Need to recreate it manually every time to update a tool otherwise the Jetbrains software doesn't run at all.Can't see any setting to change this folder or to stop Jamf from removing it (and the child folders). Is there something that can be done?Thank you.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!