Get Support
Recently active
We have cloud Jamf Pro and both an on prem DP and a cloud one. Most packages need to be available to users on or off campus, but there are a few which are used only in the campus computer labs and which are too big for the cloud DP to accept. In order to not attempt to sync those ginormous packages every time, I've got the cloud DP set to sync specific files instead of the full contents of the master, and the biggies are unchecked. The big downside to this is that each time I add a new package that DOES need to be in the cloud, I have to remember to go into the settings and add a checkmark for it. Assuming there is no way to change the default for new packages to "yes" from "no", is there any other clever scheme I could use to ease the administrative overhead?
Hi Guys,I've been following the documentation and training videos for setting up a limited access DMZ deployment of Jamf Pro, which for the most part has been easy to follow. I've updated web.xml to block access to the api servlet, but wanted to remove the documentation as well. The relevant step in that training instructs you to remove the API directory from the web root to stop the API documentation being accessible... only there is no API directory on my deployment. If I access: https://jamfproserver:8443/api I'm presented with a page that allows me to choose between "classic API" and "JAMF Pro API" pages. I've removed the classicapi directory, so it 404s, but the JAMF Pro API link takes me to active documentation. I assume this folder has simply been moved and the training / documentation is lagging behind, in which case I'd love to know where it's now located. Any help appreciated!
Writing a extension script to use the API to get some LDAP info on lastuser.Even thought API will only have read ability to Jamf LDAP setup the API call will be running daily on every endpoint and I do not want the API password in the script.Any ideas on how to get around this?
Hi friends,I am new at Jamf and appreciate your help.We use Jamf Pro in the cloud and we have a local Microsoft CA server.My goal is to install certificates from the local CA using Jamf pro cloud on the mac devices.I understand there are two ways to do this:1. Using Jamf ADCS Connector2. Using Jamf SCEP with local NDES serverAm I right?What is the right and secure way to do it?We also have Azure and Intune if that can help. Thanks
Our previous Jamf admin showed me how to package Citrix Workspace for Jamf, but at that time it was a PKG file. Now it's a DMG. The Installer PKG (in the DMG) bundles Citix Workspace and something called "Citrix Enterprise Browser". There's a way to install just Citrix Workspace, according to https://docs.citrix.com/en-us/citrix-workspace-app-for-mac/install-uninstall.html (search for "Install only Citrix Workspace app" on that page). You need to download an XML file and then can run a Terminal command line that installs the Citrix Workspace.app file in your desired location.So my bright idea was to take that .app file, drag it to Composer, then build a PKG to get just a clean install of Citrix Workspace that I could then deploy via Jamf, but it doesn't work. The app installs, but when I attempt to connect to Citrix, the cursor just spins forever and doesn't connect. But when I launch the app using the build instructions from Citrix, I can connect just fine.I'm not sure
I have a bit of dilemma where I need to remove Jamf Framework and enroll many devices at once. I was thinking we can do something with a script:#!/bin/bashsudo jamf removeFrameworksudo jamf enroll -prompt -nopolicy #After this is run, it would request for JSS and password. This is where I am stuck. I understand this is a bad Security practice. But I still want to do this. I was thinking of creating a one-time account to do this push and removing the account.With that said, my question is:Is there a way to add the username and password inside the script so that when "sudo jamf enroll" runs, it uses the credential to bypass it? I don't want the users to enter the credentials instead use a one-time script to run everything and complete it.
We're trying to give access to subsets of machines to tier 1 technicians using Sites but we're running into a glitch. The tier 1 accounts see the Start Session button under Management/Remote Assist but when they click it it just spins. Bringing up the browser console I find permission denied error for a XHR call to /computers.html after the button is clicked. Even giving the tier 1 admins Administrator Site Access isn't enough. Is there something they have to be granted at the Full Access scope? Since the UI shows the users the Start Session button I think this is a bug.
We recently initiated Federated Authentication in our environment and I have noticed a strange thing - if I am trying to add an account via Apple Business Manager and I I want to set it's "Role" to Administrator - it automatically selects Authentication: "Apple". Only if I select Staff it is added as "Federated". Does it mean that Administrator "Role" account on Business Apple Manager can only be authenticated via Apple? As it requires attaching a working phone number in such case... Any insight on this would be great!
Troubleshooting steps Extensive trouble shooting steps are available from Microsoft at: https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-mac-sso-extension-plugin Removing PSSOe from a user account To force an update to a user account with PSSOe, unscope the configuration profile with the steps below. This allows for the device to be re-registered or the local macOS UNIX user account to be paired with a different cloud identity provider account. Secure Enclave method - Un-scope the configuration profile. Check to see if any legacy SSOe payloads are still on the device and remove those configurations as well even though the Platform SSOe keys are missing. Reboot the computer. Open System Settings, Users & Groups, select the “i” next to the user account. Confirm the Platform Single Sign-on section is missing from the user account. Password method - Un-scope the configuration profile. Optionally, rebo
Hi Everyone,After 2 years of using an older package of Garageband with All Loops, it's time for me to repackage it and I'm wondering how to best do it. In the past, I created a 10Gig+ package of Garageband and all the loops using Composer (this is why it's been 2 years). The music teachers want the students to have access to all the loops and since we have Standard accounts it makes it easier if Garageband is just ready to go without Admin privileges to install the loops later. Should I try to install Garageband using Mac Apps Store and then try to push the loops after? We don't assign the students Apple IDs so I'm not sure if I can push out Garageband directly to devices. I had tried in the past but did not seem to have success. And then where would I find the loops? They seem to be buried in various locations. Thank you in advance for any advice and guidance.
Hi,I have done the setup for Device Compliance for iOS following the Jamf Docs, however when i go to the Self Service app on my iphone, and go to Microsoft Authenticator. There is no option to register. I can confirm my iphone is in both the compliance and applicable group in Jamf and my Entra account is in the group which is used in the Intune Partner Compliance portal Im not sure what im missing?thanks
When the inactivity timer kicks in and logs you out, logging back in and going to the devices inventory, I have to re-select all the columns I wanted again, and in the order that I wanted them.
I am migrating my workflow of managing the macOS ALF firewall from scripts/policies to Jamf MDM profiles. Found odd behavior that prevents users from making changes.Even though I have explicitly set the new ALF profile to allow users to modify ALF if needed (Jamf Privacy & Security > Firewall settings change > Enable user changes to the firewall settings), the ability to manage ALF locally is greyed-out (disabled) on my test Macs - even though the user is a local admin(and can authenticate to unlock the Security & Privacy pane.As soon as I remove the profile (un-scope the target Mac) the ability to modify ALF returns.When I examine the raw XML plist (/Library/Managed Preferences/com.apple.security.firewall.plist) I dont see any key/value pairs related to restricting users from modifying ALF (assuming I'm looking in the correct location.)When I look at the raw XML plist (/Library/Managed Preferences/com.apple.security.firewall.plist) I don't see any key/value pairs related
Hi all,We have a Mac that shows "This Mac is owned by unknown" in the Remote Management window when provisioning. It is in ABM, assigned to one of our two MDMs.I tried switching it between MDMs in ABM, no luck. Also tried changing the PreStage Enrollment on each MDM server, no luck. Anyone ever see this? If so, any idea how to resolve? I opened a ticket with Jamf Support, but wanted to check here too. PS, I know I can "release" the device and use an iPhone to re-add it, but hoping that would be a last resort.TIA
Hi all,We have tested out the Jamf Compliance Editor and it works wonderfully till the point that we wipe the laptop and re enroll it. In order to better understand and troubleshoot the availability of the policies, we have set the remediation and compliance policies to ongoing and also added them to self service so that we can see when we run run them. For some reason, on a wiped laptop the remediation policy will be made available only one time after i ran the audit policy. However, the laptop wont be scoped to the remediation policy after that no matter what we did: Restart, waiting for 24-36 hours, reset baseline, ran audit policy again, delete the device from Jamf before enrolling, erasing the Macbook reinstalling OS from scratch and enrolling. The only thing that did work, was to install the compliance editor on the wiped laptop locally => create a new project => select the standard that we are aiming for (CIS1 in our case) => Create Guidance => Cl
Hi Folks,I'm Darshan Hiranandani, trying to figure out how to set my Mac's Wi-Fi to "Low Data Mode." Does anyone know the steps to enable this feature? I'd appreciate any guidance or suggestions from those who have done it before.Thanks in advance for your help!RegardsDarshan Hiranandani
On the 29th of July we will be removing two software titles from App Installers : BlueJeans and JetBrains AppCode. Verizon made the announcement that BlueJeans was sunset on March 29, 2024. You can read the announcement here. JetBrains announced the end of sales and support for AppCode back in December of 2022. You can read the announcement here. Whilst both titles will be removed from App Installers on Monday the 29th of July, they will not be removed on any Mac computers on which they are currently installed. As a reminder you can see the monthly history of what titles are added and retired from App Installers and Patch Management on the documentation page here.
I am working on an integration using the rest API, with the mobile devices I am having issues finding the correct attribute to correlate that a device is encrpyted.When I went into the iOS.security I find "HardwareEncryption" with a number, I cant find any documentation in regards to what the numbers mean, or how to identify that a mobile device is encrypted or not.
We are trying to understand how to pull what has been done when someone requests elevation through JamfConnect. I know that we can look at there reasonslog to see what reason they selected and when they elevated, but we will want to know what was changed. I thought there was something about being able to forward to Jamf Protect and we've added a couple configurations for both the reasons log and subsystem == "com.jamf.connect.daemon" && category == "PrivilegeElevation" however this is not providing us with what happened. Did they change system settings, did they uninstall or install an application? Has anyone set this up successfully? We're working with our SIEM but need to know where to get these logs first before we can look to forward them anywhere.
conditional access or device compliance for macOS? Which one is the better way? we start to register mac with Conditional access. should i wait of 10.43 and register all mac with device compliance? Thanks
I have run into a problem whereby apparently no users have a Secure Token, and there appear to be operations you can't perform unless you are Secure Token-enabled.All the documentation says that the admin user created during pre-stage enrollment should get the secure token, but it just flat-out doesn't. Multiple reinstalls, never does.I have found other people saying that they have the same problem, but that if they use a JAMF policy to create another user (as admin) and check the box to say that it's eligible to receive the secure token, they find that that works. It doesn't for me.And of course I can't use command line utilities to enable secure token because nobody is enabled.Secure Token-wise, our machines appear to be basically orphaned.Anyone have any ideas about how to fix this?Thanks,Lisa.
Testing installing this app https://github.com/root3nl/SupportApp and something isn't quite right that I can't figure out. 1. I have a Policy with this package where the Scope is my test computer.2. I have a Configuration Profile using Application & Custom Settings > External Applications using this json file.The Scope is a Smart Computer Group.3. The Smart Computer Group uses Criteria where the Profile Identifier "is" the Value of "149694A2-D63C-4195-94C6-26B778EFA58D" which is the Identifier of the application. The app is installed on my test computer but it is not picking up any of the settings from the json file. Any input would be appreciated.
I am looking for a solution to disable/hide the ability to activate Airplane Mode on iPadOS. I work in a K-12 school district and we have lots of devices around for various needs. Some offsite as well. Students and/or parents are turning on airplane mode and not allowing us to communicate with the device. I understand they can just disconnect from their own network but I'm trying to mitigate possibilities for no connection. If there is a way, pleas let me know what you got.
This is slightly alarming. Our lab Macs are set up with AD authentication (thru NoMAD) ; network users get a local home created at first login on any given computer. Network user accounts get standard permissions. Today I noticed that user homes are created with wrong permissions on some (but not all!) of the lab Macs. I would expect user homes to be owned by [some_user]:staff with default permissions 700. On some machines this is the case; on others I'm seeing 750 or 755. Especially weird because I just nuked & paved the whole lab, so configs should be identical. Am I overlooking something obvious? Where does the umask get set? I don't see anywhere in NoMAD to control it; is it coming from the AD server? [Intel iMacs running 13.6.7, highest os version they support]
I am in the process of installing Sophos using a policy. Sophos has several PPPCs, and Kernels that need to be put in place. These are being pushed by a configuration profile.I do not want the install of sophos to happen before the configuration policy is on the system, yet I do not see any option when creating a smart computer group to determine if the configuration policy has been applied. How do I verify the policy is in place before the install? Thanks in advance for your help!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!