Get Support
Recently active
Hello Jamf Nation! I am encountering a rather vexing issue with Forcepoint's Safari extension. The extension is prompting for users to enable it, however upon enabling the extension they are still prompted every few minutes that the extension is not enabled. Closing and reopening Safari causes the extension to once again show as disabled and continue to prompt the user to enable it. I've had mixed success with rebooting machines causing the extension to finally stay enabled however this has been incredibly inconsistent, sometimes requiring 2-3 reboots or sometimes not working at all. Has anyone else seen behavior like this with a Safari extension or have any pointers on where to even look with troubleshooting this? I admittedly don't have a very strong understanding of how extensions for Safari work and could use any and all advice! Thank you!
I have been able to successfully add dock items but I would like to remove several default items from student users docks. Do I need to add them to the Dock Items and then delete them? I don't see any information on how to remove default items like facetime, etc. I am new to jamf and have new macs to set up for our classroom labs. Any help is appreciated.
I updated 4 MacBook's and a Studio that where still running macOS 12 about 3 weeks ago, and JAMF still show them running the old OS how can i force the full scan of the systems
All,Have a question remotely accessing a macOS device that has FileVault 2 enabled via JSS. I have a few machines at one location that perform utility functions and were previously not encrypted with FV2. Once connected to the VPN I would access with ARD or Jamf Remote. With new compliance parameters these utility devices are now encrypted with FV2 via JSS Configuration profile. The issue that I'm running into is that when I have to reboot the device I can't log in remotely because the device has decrypt with the local user login. Once logged in I can access remotely but this becomes an issue because with any needed reboot. Looking for some suggestions or recommendations from anyone who may have run into a similar situation in their enviornment. Thanks in advance for any feedback.
Today we are releasing Jamf Pro 11.7. Highlights include: Managed Software Updates Now Generally AvailableThis release of Jamf Pro includes the following enhancements: Improved interface with higher visibility of update statuses when viewing software update information in an individual device record Added an event store view which was previously only available via the Jamf Pro API Improved stability and functionality, including resolutions to issues that caused software update plans to not complete Automated Certificate Management Environment (ACME) payload supportThe ACME Certificate payload is an alternative for SCEP and is used to obtain certificates from a certificate authority for computers and mobile devices enrolled with Jamf Pro. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. See the latest release notes video for a brief overview of new features and enhancements. To access new versions of Jamf Pro
Has anyone figured out how to push bookmarks to Chrome on iOS from JAMF? I can add them to Safari without an issue but can't seem to add them to Chrome.
Is there a way to push bookmarks into certain browsers via JSS onto managed IPads?
Does anyone know anything about Jamf's plan to support the ACME feature introduced in macOS 13 (and to be enhanced in macOS 14)https://support.apple.com/en-us/guide/deployment/depb95c66a07/web
Best practice for devices that are lost/stolen?Is it possible to create a group policy and or group of computers that we can select all and send a wipe command/lock when it comes online? If so what's the best approach.Thank you!
Hello,I am having trouble setting up device compliance in Jamf Pro. I followed the instructions found here: https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Device_Compliance.html but when I got to the part where I was redirected to the Microsoft Intune webpage, nothing happened. The Microsoft login window appears; I enter my email address and am then brought back to Jamf Pro with a "Registration Request" error and another warning below that states it is "Establishing connection" with directions to "Open consent URL." I click on the open consent URL, get to the Microsft login window, enter my Azure email address, and am then brought back to the Jamf Pro screen with these same two messages. I have Azure GA rights and have tried two different browsers (Safari and Edge) with no success. Has anyone else come across this issue? I figured that I'd try here before submitting a ticket with Jamf. Here is the error and warning messages Registr
Hello,Our JAMF API integration has been working fine for a few years now, but suddenly its stopped workingI've done two things to try to make it work:1. Changed passwords to be 15 characters2. Enabled "Allow Basic authentication in addition to Bearer Token authentication" in settings > system > password policyBut still we are getting 401 unauthorized.Here's our codeSet creds = "%username%:%password%"Set base64 = base64 "%creds%"HTTPHEADER "Authorization", "Basic %base64%", "string"Set tokenjson = HTTPSEND "https://%domainname%/uapi/auth/tokens", "application/x-www-form-urlencoded", "" And we also tried to get a bearer token, with the same issuesSet creds = "%username%:%password%"Set base64 = base64 "%creds%"HTTPHEADER "Authorization", "Basic %base64%", "string"Set tokenjson = HTTPSEND "https://%domainname%/api/v1/auth/token", "application/json", "" As I said this was all working, so I don't think there's anything wrong with the code, any ideas ?
Hi all, I was curious if there is a way to deploy a unique wallpaper to each iPad in our organization showing their asset tag identifier using a payload variable? This is sort of what I'm looking to do, but my organization doesn't use Jamf School, we use Jamf Pro. Thanks!
Hello !First of all, please excuse me if the questions are found somewhere else, but I can't find clearly the informations needed. Please note that I'm not familiar with API.As the basic authentication will be soon removed, I already disabled it in Jamf Pro. I checked all my scripts and it seems that it's working fine. However, I have some questions:1) I read that classic API uses JSSResource as part of the URI. And I have this example to get the department of a computer. I would like to change that so I can use the api/v1 URI but I can't find the exact path. Actually, I get the department this way:department=$(curl -H "Accept: application/xml" --header "Authorization: Bearer ${token}" "${jssURL}JSSResource/computers/serialnumber/${macSerial}" | xmllint --xpath "string (//computer/location/department)" -)How should I change this ? And first of all, is it still possible to do this way ?2) I use keywords in the position and room fields of a computer's inventory. It allows me to put those
Hi Team, We are trying to package the MindManager software but when user is trying to install the package it prompts for the license key. We would like this go as a silent install. Would like to know if there is a way we can avoid the License prompt window. Thank you,Paul +1 813-617-2521
Hi, I'm trying to package MindManager v22 (14), but when I try to test it out, it prompts me to log into an email MindJet account first before entering the license key. Is there a way to bypass for a silent install?We've packaged the v12 in the past and used the script below, but I can't seem to get it working for v22.Any help is appreciated.Mitch #!/bin/bash ##################################################################################################### # # ABOUT THIS PROGRAM # # NAME # MindManagerSettings.sh -- Set License and accept EULA # # #################################################################################################### # # HISTORY # # Version: 1.1 # - Philipp Reinheimer, 14.04.2018 # # #################################################################################################### #---Variables---# currentuser=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) #---Lice
New User Interface and Faster Loading for the Devices Overview in Jamf School We are please to bring to Jamf School a new improved user interface to view devices and deliver bulk action commands. This new interface can be turned on in the Jamf School Management System by navigating to; Settings > Appearance and then ticking checkbox next to New User Interface. This will then change the “Overview” section under "Devices" to “Inventory”. You can change back to the original interface at any time by unchecking the box. This change doesn’t just offer a new look but improved speed when loading devices. For schools with large deployments, this means you can manage your Apple devices in an even faster and improved manner with quicker loading and bulk commands. This will be the default interface from 1st August 2022 but we encourage our Jamf School customers to turn on this new view ahead of the roll out date. We welcome your feedback as you test this ne
With the old interface, you were guaranteed that every column would fit the viewport width to 100%.With the new one, if you add more columns, it forces you to scroll left and right to see everything.Not only that, but there is a maximum number of columns allowed.Why enforce a maximum number of columns if the screen is just going to force a horizontal scrollbar anyway? Seems rather arbitrary to me, the whole point of a maximum number of columns would be to stop the horizontal scrollbar from appearing.
The new user interface for devices remembers the filter and even the selected iPads even if the filter is changed. I accidentally erased 20 devices inadvertently before I realized what I was doing. The previous interface did not behave this way. Could there be some sort of UI toggle that disables this functionality? I'd hate to forget what I had selected and erase or do some other function before it's too late. After the fact I did see there is a warning that says: "After filter, some selected devices may not display in the table. Your previously selected devices will still be scoped." I'd rather this not be the case. I always want to see what my scope is. At the very least I should be able to deselect items that are in scope. At least in Jamf Pro I can clear the filter and sort by selected to unselect items.
Hello,I need to rename the computers using the Full Name that is set in User and Location.I have a script that renames using the login user but the name I need is the Full Name in Jamf.Any idea how to retrieve the Full Name ?thanks for your help.
Hi all. I have been tasked with changing the background image on the login window to reflect new company branding. I am looking for confirmation to see if anyone has been able to successfully do this in Monterey, and if so, how as I believe it is a protected system file and is not possible with FileVault enabled.I started testing with this older article Setting Screensaver, Lock Screen, and FileVault screen to same image (Mojave) as well as several posts found on the Apple community boards with no success. I am hoping to avoid disabling FileVault on hundreds of machines simply to change an image.Any guidance you can provide would be appreciated.
Does anyone have suggestions on how to scope a configuration profile by network location?For example; We have a configuration profile to bind to our Active directory and it fails when these devices can not reach the domain controller. Not a great example as most of us are moving away from binding.Another example would be to allow Bonjour (mDNS) on a home network and disable it on the enterprise and public networks. We have disabled Bonjour for a long time to reduce the visibility of our devices and their services, however when these devices go home disabling Bonjour may break features like finding shared disks, using screen sharing, and printing.
It's very glad to push the OS software updates with the recent software update feature through JAMF Pro.But it will be great to provide any tracking of these deployments, as once we push the software updates we couldn't track them and unknowingly deploying further deployments to the same target machines and it causes the issues with this feature.
I'm in the process of updating our plotter drivers for our Z6DR. I have taken the PKG out off the installer and uploaded to jamf. Im having some issues around deploying it if a user is logged in it install without any issues.However if no one is logged in It fails and I get this messageInstallation failed. The installer reported: installer: Package name is Universal_PostScriptinstaller: Upgrading at base path / installer: The upgrade failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurred while running scripts from the package “Universal_PostScript.pkg”.)this just the installer as it come from HP as anyone see something smiliar when deploying print drivers Thanks
My organisation has recently procured Jamf, and it's a majority Windows org.I'm quite new to Jamf, but familiar with MDMs, and most of my day is spent using a Windows machine. We have a number of applications that we have API access to, and I've been successful in setting up API access within powershell using client credentials, and able to make basic GET calls, and some simple POST commands - such as creating departments, or categories. I have a list of departments I need to create, and want to also create smart groups for each of those departments, pulling in computers where the department is set to a specific value.I've created a smart group manually and able to GET the configuration options in an API output.My familiarity with API is using JSON for the POST calls, but looking at the GET output, it's an XML format, in a single string (weird to me, but maybe that's shell standard?)However, I cannot get it to POST and create a group, when I modify the specific options from t
I don't know how to upload an extension attribute, but, I wrote this as it came out of a need. The mere presence of MobileMeAccounts.plist doesn't tell you if someone is actively signed in to iCloud or not. However, the contents of that plist file will tell you if someone is or is not signed in to iCloud. This EA was tested in Catalina, and other versions may vary milage. This EA will print the email address used to sign in to iCloud. #!/bin/sh ## Get logged in user loggedInUser=$(stat -f%Su /dev/console) icloudaccount=$( defaults read /Users/$loggedInUser/Library/Preferences/MobileMeAccounts.plist Accounts | grep AccountID | cut -d '"' -f 2) if [ -z "$icloudaccount" ] then echo "<result>Null</result>" else echo "<result>$icloudaccount</result>" fi
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!