Get Support
Recently active
[https://blogs.technet.microsoft.com/office_for_mac_support_team_blog/2017/08/10/mac-outlook-support-utilities/](link URL) Microsoft has released some useful utilities for Mac Outlook 2016. OutlookSearchRepair: This utility will repair search results for Microsoft Outlook. Why use it: Search results within Outlook show nothing or return older items only such as when you are looking for an email you know you have and might already be looking at it but it doesn't show up in the search result. OutlookResetPreferences: This utility will reset all Outlook Preferences back to defaults. Why use it: This utility resets customizations you've made to Outlook from the Outlook menu > Preferences... It also stores settings of the Outlook window size and position. This utility shouldn't be needed often but we made it just in case. The Outlook Preferences file does not contain all the app's preferences and reseting Outlook Preferences will not remove email or account sett
hello, I am looking for a scrip to help me remove objects for inactivity of more than 90 days, however I have not achieved.I’m not that good at programming or command lines.I have researched and searched several forums however I have not found a script to help me run what I am looking for.someone from the community can guide me. I am new to the JAMF tool and my knowledge is very poor.
Hey everyone, I am in the home stretch of an application deployment but have one user experience issue I would like to resolve if possible. I have a new working Sophos deployment, however I get the attached pop up any time the policy runs for install. It must be accepted to install the software and bypassing that for our end users would be excellent. So far i have tried xattr -d com.apple.quarantine /var/tmp/SophosInstall/Contents/Helpers/SophosCBR.bundle before the install kicks off with no success. Any input would be greatly appreciated on if this is even possible to prevent.
System Preferences -> Security & Privacy -> Privacy -> Advertising Does anyone know of a way to enable this via plist or conf profile?
I'm working on setting up a policy for GlobalProtect 5.1.4 which switches to System Extension from Kernel Extensions. I've set up a config profile to approve the system extension. First I tried just the team ID, then I added the ALLOWED SYSTEM EXTENSIONS as well. but when I run systemextensionsctl list I get 1 extension(s) --- com.apple.system_extension.network_extension enabled active teamID bundleID (version) name [state] * PXPZ95SK77 com.paloaltonetworks.GlobalProtect.client.extension (5.1.4-45/1) GlobalProtectExtension [activated waiting for user] and System Preferences>Security & Privacy still has this prompt How can I approve this for the user?I tried a blanket PPPC config profile that just gave it all access, but still have that prompt. Anyone know how to solve this?
Hi All, I want to leverage the "system_profiler SPInstallHistoryDataType" command which will tell me all of the installed macOS updates. To do that I can add a pipe and grep the string "macOS". However I'm looking to get both the macOS update(s) that were installed and the Install Date when it happened into an Extension Attribute. As an example, one of the results of the command is below: macOS Mojave Security Update Developer Beta 2021-001: Version: 10.14.6 Source: Apple Install Date: 1/29/21, 9:11 AM From the above text, I'm looking to only display what is below into the EA: macOS Mojave Security Update Developer Beta 2021-001: Install Date: 1/29/21, 9:11 AM I'm not sure what what the command syntax will look like to get rid of the "middle" data from the result of the command. As you can imagine, the EA will continually update as new "macOS updates" get installed. Thanks to anyone that can offer guidance.
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issue: Jamf Pro Server[PI119651] Creating or editing computer configuration profiles with payloads that require you to click Configure no longer causes the Jamf Pro user interface to spin indefinitely if debug mode is enabled in Settings > Information > Jamf Pro server logs. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 11.7.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. If you would like to upgrade manually, navigate to h
Hey everyone,We're currently in the POC phase with Jamf, and there's something that's really bugging me. We tried Kandji before, and their FileVault solution is way better than Jamf's. With Kandji, you just set up the profile, assign it to a Blueprint, and if FileVault is already enabled, it prompts the user to enter their password, rotates the key, and escrows it to their server. If FileVault isn't enabled, it forces the user to log off to enable FileVault and escrow the key. But with Jamf... it's not as simple as creating the config profile.For machines that already have FileVault enabled, we had to set up EscrowBuddy. The instructions were clear, but now we have 10 devices enrolled and 8 of them haven't escrowed their FileVault2 key to the Jamf server. This could go on forever because there doesn't seem to be an integrated solution (I couldn't find one in the options or this forum) that forces the user to log off.Does anyone have experience with this or know how to tackle the logoff
Can site access Admins create SCEP configuration profiles? I ask because when a site access admin creates a new configuration profile and selects the SCEP option from the left side configuration profile options, the user interface just spins and spins forever without giving an error. Same for an admin user added to group access for a site.The SCEP configuration profile settings only appear if signed onto Jamf as a full access administrator and showing/selecting Full Jamf Pro in the site list drop-down.It's like this on both our Jamf Pro Cloud Production and Development sites.Is this by design?
Hi there, We use the "Restrict the App Store" option in Jamf Pro Profile Config but this seems to not do anything to stop a user from signing in with their own Apple ID into the App Store on their MacBook. Does anyone know how to block signins to App Store?
I have seen bunch of scripts online but if someone has a working script which can deploy will be very helpful. I am looking a script which checks the last reboot of the machines. Then it would check if the reboot occurred less than 7 days or not. If the user hasn't rebooted for more than 7 days, the script will restart their machines. They will receive a popup that their laptop will be restarting and also allows them to extend the time by few hours before the laptop restarts.
We are unable to enrol new 4K Ethernet Apple TVs into Apple School Manager via Configurator 2.This was working perfectly a few months ago. When I click prepare, I can see the Apple TV is rebooting but not showing up under the devices in ASM. Has anyone encountered this issue recently?
Hello, Our organization is trying to implement VPN on shared iPads by implementing Jamf Trust App. It is working on our single user devices. On our shared iPads when we open Jamf Trust app and try to enable we receive error 412 reference 22a86ba1841985b8. I couldn't find other posts online referencing this error to see what we may be doing wrong.Has anyone been successful in implementing Jamf Trust on shared iPads or have tips of where to go from here?
We have access to JAMF Safe Internet due to buying the EDU ultimate bundle for some of our devices. Is there a way to only apply it to devices when they are offsite? I do think you could do this with a configuration profile that only applies when the device is not onsite in JAMF school, but those don't always change quickly and it sounds like when the profile is applied and removed it would disrupt Internet activity on the device.Here are some secondary questions and thoughts from my testing so far: Privacy - While I understand why some places would want this, in our environment we tell the students they should have no expectation of privacy when using our devices. We really need to be able to see which students accessed what sites when something gets passed the filter that should not have. Local DNS - Having to create an entry for every local DNS resource will be time consuming and hard to maintain. I wonder if they could allow you to do a domai
So I have a configuration profile set up, and configured Require Passcode to Unlock Screen and I have it set to never. But when I log on to the machine, it doesn't seem to be correct. When I look in the system settings, it is set to "immediately", which is the complete opposite of what I want. Why are these settings completely contradicting each other, am I completely missing something here?
This might be more of a rant than anything.I've spent my day just simply trying to get a script together for our Cart devices to rename the devices to the Bar Code 1 value since those don't change through restores and would enable my techs to just restore the device and put it back in the cart. Zero touch beyond actually restoring the device.For completionist sake I did get it to work fully as expected!Come to find out the bearer token you need to generate only lasts for 30 minutes meaning that hard coded credentials either get passed via the script or in the $4 $5 fields.I kind of get the idea behind only having a 30 minute token but you really can't make it any longer? For instance doing the restores on the carts only take about 2 or 3 days. I can't just set it for 5 days then just regen a new token every summer?Am I just looking at this the wrong way?
With basic auth going away in the next release, has anyone been able to find a way to connect PowerBI and Jamf?
We're trying to scope smart groups based on Patch Reporting: {Application} Less than Latest Version. Currently we only have Patch Reporting: Google Chrome in there. How do we add more for other applications, or am I mistaken and Google Chrome is the only one supported by JAMF?
We had a macbook with activation lock with find my mac with personal account, we use the erase device option on Jamf School and request a pin, we set up.After the erase or before, I didn't know if make the erase, stop the process with the activation lock screen on recovery assistant.We try to write the bypass code at activate with MDM Key but didn't work too.Any idea, we use normally the bypass with iPads but normally with Macbook didn't had problems until now.Thank you
I'm trying to remove all Office 365 applications and any file with the word Microsoft in it from all our Macs. I wrote a .sh script and it is installed with Composer. Then a I have a script run that is sudo sh /path to .sh command. The Composer package will remove all the applications after a while but most of the rest of the files aren't removed. If I copy one line and paste it into Terminal it will run and remove the file(s). Why will the Terminal commands work in Terminal but not when I run them in Composer. My .sh script is setup like this but with a lot more paths listed: Thanks!sudo rm -R /Applications/Microsoft\\ Excel.app;sudo rm -R /Applications/Microsoft\\ OneNote.app;sudo rm -R /Applications/OneDrive.app;sudo rm -R /Applications/Microsoft\\ Outlook.app;sudo rm -R /Applications/Microsoft\\ PowerPoint.app;sudo rm -R /Applications/Microsoft\\ Word.app;sudo rm -R /Applications/Microsoft\\ Teams.app;sudo rm -R /Applications/Microsoft\\ To Do;sudo rm -R /Applications/Office.app;su
I'm trying to set up and test LogCollection. I created a Jamf user account and want to give it the barest privileges, only what is needed to connect and upload the logs. The only privileges I have configured for this account is create/update Attachment Assignments and create/update File Attachments. When I run the policy, I get the error "The request requires user authentication". What else do I need to provide this account to be able to connect and upload the log files?
Hi Team,Does anyone know how to enforce the screensaver after 15 minutes of inactivity and require a password to unlock in Sonama?I've been trying through a script but it doesn't seem to work, and end-users are still able to change the settings through System Settings., even after the screen lock Password is required need to unlock the screen
Hello, I am trying to package an application, specifically Charles Proxy, and I am able to get it to deploy fine, but the application requires admin rights to access the Mac proxy settings after the install. I can't seem to figure out how to grant these rights to the application before I deploy it to the users. Is there any trick to this or will this application now require admin rights to use? I am just getting into application packaging so sorry if this is confusing, if there is anything I can clarify, let me know.
JAMF newbie here...Our K-12 school is looking at a hybrid approach in terms of technology and I'm wondering if somebody could share their experience or thoughts around this.Current situationTeachers are all assigned a laptop device (Microsoft OS) and we use Microsoft as our primary platform in the school.We have a BYOD policy for students and they are opting more and more to bring iPads to the school. As a result, we considering rolling out JAMF to manage the iPads. The majority of the apps we use are Microsoft (e.g. Teams, OneNote, etc)From a management perspective, could the teachers still engage with JAMF features such as lock screen, etc from their laptops or would they need an iPad as well to do this?
I need a way to force logout the user after FileVault2 has been enabled. I see some old post from 2014, but nothing new. Any ideas how to force log out the user which would be the local admin account once FileVault 2 has been kicked off. I tried this didn't work #!/bin/sh # # Step 1: Log out Active User command. CurrentUser=$(stat -f%Su /dev/console) OtherActiveUsers=$( who | grep -v _mbsetupuser | grep -v ttys000 | grep -v "$CurrentUser" | sed 's/console.*//' ) loggedInUID=$( echo "$OtherActiveUsers" | while read userName; do id -u "$userName" done ) echo "$OUsers" | while read userName; do echo "$loggedInUID" | xargs /bin/launchctl asuser "$loggedInUID" sudo -iu "$userName" "/usr/bin/osascript -e 'tell application "loginwindow" to «event aevtrlgo»'" done exit 0 and this #!/bin/sh ## Get the logged in user's name loggedInUser=$( ls -l /dev/conso
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!