Get Support
Recently active
Hi, When trying to download Self Service from the JSS (JAMF cloud), I am met with the above error message. I have performed this ask previously with on premise solutions and had no problem - but it seems unless I automatically install it (which I don't want to do as it will install for everyone) I cannot use the app and test out the functionality. Is there a way around this?
Hello Jamf Nation, In Jamf Protect, alerts pertaining to threat prevention have been updated to include additional information about the malware detected, including available reference articles from Jamf Threat Labs to enable further investigation. For additional information, review the release notes via the Jamf Learning Hub. Thank you,The Jamf Protect team
We have a bunch of machines that have done their initial check-in but have not inventoried yet.As such the Console reports them as having the name "DEP - sernum", I need a smart group that can capture those devices so I can use it to exclude the devices from other Smart Groups that produce E-Mail Security alerts.As an example ....We have an Extension Attribute that checks the root user, if it has been enabled it returns "Enabled" if not it returns "Disabled" We then have a security Smart Group, that checks the attribute and populates with devices that have the "Enabled" state, and sends a Security Alert to relevant people.However we are seeing that group populate and trigger Alert E-Mail for devices named "DEP - sernum" and we want to exclude those devices as they are in an initial check in limbo. We tried a simple Computer Name like "DEP -" Criteria, but it seems to ignore those devices in any Computer Name based criteria.Any advice would be greatly appreciated.
Hello-We've recently been setting up our iOS/iPad infrastructure, and are trying to get a configuration for shared iPads ready. We are generally a microsoft org so I looked into and configured the Microsoft Authenticator app + the Microsoft Authenticator Enterprise SSO extension (or whatever it is called), and to my chagrin it still appears to be in preview mode (I think). The other solution I've been looking into is just putting the iPads in shared mode and then syncing managed AppleIDs from EntraID for users to log in. My issue with that solution is there appears to be no (easy) way to enforce that users use our managed appleID domain at login. This is really frustrating, because without a way to ensure users are using our managed AppleIDs, our org will likely have to plainly disable most features that make AppleIDs useful (and we'd like to make sure people are using only managed accounts on our devices). Does anybody have a recommendation to either serve SSO directly from EntraID or
I'm working on a new post install script for Nudge. Delivering Nudge settings using a profile has not been as reliable as I would like it to be. I found Dan Snelson's Nudge post install script (https://github.com/dan-snelson/Nudge-Post-install/wiki) and it has been a good starting point. Its command to load the launch agent doesn't work. My understanding is that we need to use Launchctl bootstrap instead of Launchctl load as we did with older versions of macOS. I have other scripts that load launch daemons that use bootstrap/bootout. These work well. Since a launch agent loads when a user logs in, it's different. What is the proper command to load a launch agent using a script deployed by Jamf Pro? If I can get this one thing to work, it pretty much wraps up getting this done.
Hello, So I'm circling back to this as last summer I have been having the same issue I am experiencing now. Which is Mac Apps both App Store and Jamf Catalog do not work at all. I have created a test with Loading the 2024 Creative Cloud suite put my test mac into a group and made sure mac was online, connected, and open. I send off the App to automatically install but absolutely nothing happens. I tried with a couple macs I have here to test. Nothing works, I've checked our firewalls to make sure nothing in there is blocking anything, and nothing. I dont know if someone knows some way of better troubleshooting or finding out where in the process of software install it is. We need to do a mass upgrade this upcoming weeks it would be nice to use this feature instead of making bunch of profiles and scripts.
Hi there,I try to remove all "old" users from our iMacs, managed with JAMF School. The useres have an AD account and during first login on an iMac we create a local (mobil) account on the mac. At the end of the year we want to rmove all these users and there data.If I run a "sudo /usr/sbin/sysadminctl -deleteUser $user" on the client, the user is totally removed (after I once gave the terminal full access to the drive in system preferences). But if I run a JAMF Script with the same command, I got the error:### Error:-14120 File:/AppleInternal/Library/BuildRoots/91a344b1-f985-11ee-b563-fe8bc7981bff/Library/Caches/com.apple.xbs/Sources/Admin/DSRecord.m Line:563Nearly the same, if using the command "sudo dscl . delete /Users/$user": dscl DS Error: -14120 (eDSPermissionError)All users, the first local Admin and root have "Secure Token" enabled. After I disabled System Integrity Protection in rescue mode with "csrutil disable", the JAMF Script is doing the job without error, but this is no
Hello dear Community,overnight the entire login screen disappeared two managed silicon Macs, MacOS 14.5.The login screen only shows a guest account, which is not available either because the FileVault is actived.I was able to access the hard drive using Target Mode and the data and user folders are still there. Has this ever happened to anyone? What could be the causes? I would be grateful for any tips.
I have added the OneDrive app from App Store via Jamf Pro for our domain networked iMacs. Installation of OneDrive on iMac is successful, however, when trying to log in as a user I keep seeing the error: OneDrive Files On-Demand didn't start. Please restart your computer and try again. Error code: -1912600610 I have tried all the fixes via terminal commands to enable files on demand, but the error still shows on the iMac. Has anyone experienced this with new iMacs on Sonoma 14.3? Is there another way to get this working? I have unscoped and rescoped the OneDrive just to make sure but still the same. Thanks
For those that have implemented Memcached for your on-prem environments, what kind of hardware specs did you give your server? Looking at the latest release notes, I saw that Ehcache has been deprecated and Memcached is now required.
Is it possible to run a report on which devices have a passcode assigned?
Jamf 100 was just updated to version 6.0! Learn more here about the updates below! The Jamf 100 Course is the first of many offerings to increase your knowledge of Jamf products. There are four sections in this course: Section 1: Device Fundamentals Section 2: Jamf Pro Setup and Infrastructure Section 3: Jamf Pro Management Section 4: Jamf Pro Policies and Scripts Each section ends with a Section Review that includes a simulation that lets you apply what you've learned. Each lesson in this course includes: Goal: A statement or statements about the content in the lesson Video: A short demonstration of the content in the lesson Key Points: Brief descriptions of content covered within the video Review: Comprehension questions to recap the lesson content Practice: Exercises to apply the information from the lesson in a managed environment Resources: Links to lesson-related content The Jamf Pro Associate Exam is available for purchase at traini
Trying to get the latest Apple Silicon Adobe installer to work. Anyone done it very recently successfully?I used to use this:https://community.jamf.com/t5/jamf-school/adobe-creative-cloud-install/m-p/253089/highlight/true?lightbox-message-images-253102=12661i385B93C05EBFE0B5#M574But the most recently downloaded version downloads a pkg (that JAMF School won't accept. So I tried compressing the pkg per this:https://community.jamf.com/t5/jamf-pro/adobe-product-package-fails-to-install/m-p/301598And that didn't work. I also tried putting the new pkg inside a folder and using composer and the procedure from the first link and that didn't work either.Anyone have something that does?
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server [PI118519] Functionality to upload or edit an On Device Content Filter mobile device configuration profile downloaded via a Jamf Security Cloud or Jamf Safe Internet tenant now works as expected. [PI118598] In Jamf Self Service for macOS, the continuous loading spinner now disappears as expected after the page refreshes. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 11.6.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf C
Hii need help.We want to monitor Time Machine. If Time Machine is disabled on Macs, Jamf Protect should trigger an alert and notify me. In the custom analytics, there is a sensor type called "File System Event" that can monitor which files are created, updated, or deleted. The question is, is it possible in Jamf Protect to match the content of files (plist) when creating custom analytics? For example, to search for a key "LastKnownEncryptionState" in /Library/Preferences/com.apple.TimeMachine.plist?We also want to monitor the firewall . If users disable them, we need to be notified. In Jamf Protect, we can create custom analytics and upload scripts. I have already implemented this for the firewall. When I use the terminal and execute the command 'socketfirewallfw', Jamf Protect is alerted and I receive a notification. However, Jamf Protect does not get alerted when I disable the firewall through the System Preferences on the desktop.please with examples :)Thanks
hello. Does anybody know how to modify the password requirements to remove this requirement "Not have two consecutive, or three sequential characters". I checked all over JAMF and i looked at apple's pwpolicy and there is nothing that shows that requirements. Our computers are not attached to AD. Thank you!
Hello,After going through efforts in attempt to get the AutoDesk Maya application packaged up, wanted to post here with regards to how I did it so that others can leverage it (its a culmination of multiple different techniques, and some digging deep to get the right scripting language). Maya includes Arnold Render and will be installed along with Maya. There are two passes that need to occur, as I had found that the licensing components don't always work the first time around.1) Mount the dmg acquired from AutoDesk and copy the 'Install Maya 2024.app' to /tmp/, and remove all the spacing to just 'InstallMaya2024.app'2) Leverage this script (test local first, then attach as post-installation script in WhiteBox Packages) #!/bin/sh #Application Info (For each AutoDesk app, change the app/year/pKey/package) app="Maya" year="2024" pKey="Product Key" #Location where the application file is going to sit (remove the spaces) pkgpath="/tmp/InstallMaya2024.app" #For Redundant Servers (3),
How is everyone capturing new print qeue now jamf has removed Jamf admin which had a nice feature to do it. This Jamf alternative https://github.com/jamf/jamf-printer-managerHowever it didnt seem to pickup the new print qeue I created.ThanksTom
Hello, we are preparing for Jamf 11.6 upgrade and losing JAMF Admin.Our JAMF Pro is on-prem with local file distribution point - so the way we are going to manage packages is copying it directly to distribution point folder, then creating a matching record in JAMF Pro packages.Recently I was going through a list of our packages, and noticed some of them have pkg.zip format, not just pkg or dmg. Moreover, when I tried to re-upload new versions of those apps packages as pkg - JAMF Admin converted them to pkg.zip again, while the size of those packages wasn't big.Do you know, why is JAMF Admin doing that? And what are the possible consequences if we upload just pkg, not pkg.zip for those apps to distribution point in future, when JAMF Admin is gone?Thank you!
We have 300 Macs. Most of our users are developers with standard accounts, but they have the SAP Privileges app installed which allows them to elevate their account to admin.We notice a lot of unapproved apps are installed. We need to stop this, so we are going to release the necessary apps to Self Service. We are planning to remove SAP Privileges from all users or limit SAP Privileges only to certain users.Couple questions about this:1. Once we have released the necessary apps to Self Service, is there any way to prevent users with SAP Privileges from installing other apps from other places (App Store, DMG and PKF files)? Dont want to use JAMF restricted software. Might be using Santa.2. We know that adding printers require admin rights. What else should be configured in JAMF in advance to allow users to continue working normally and to minimize the number of contacts to the Service Desk? Which user tasks really require admin rights?3. Are you still allowing adminstrator accounts? Why
Hi Everyone, I am new to Jamf Pro and i need a bash script to upgrade brew in our environment. Command i want to run - "brew upgrade xz". Could someone please help me with the shell script on priority? Thanks
how to do custom subdomain for jamfcloud to point my own domain
Microsoft has released Company Portal 5.2401.2 with support for Platform SSO.Users with SSO profiles receive a pop-up requesting registration with Azure Account to synchronize the local Mac password.Has anyone had this experience?
Been playing with this today I have everything working fine except for the DefaultSearchengine. it won't switch to Ecosia (don't ask)I created 2 versions one witha forced extension for the ecosia plugin. But this locks the user from being able to change setting..without extension<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>DefaultSearchProviderEnabled</key><true/><key>DefaultSearchProviderName</key><string>Ecosia</string><key>DefaultSearchProviderSearchURL</key><string>https://www.ecosia.org/search?tt=</string><key>HomepageIsNewTabPage</key><false/><key>HomepageLocation</key><string>**********</string><key>NewTabPageLocation</key><string>https://www.ecosia.org/?c=en</string><key>RestoreOnStartup</ke
I recently had a user complain to one of our technicians that the low power mode setting requires admin credentials to modify. A vast majority of the macs in our fleet are laptops, and I don't mind letting users change this setting on the fly. Looking into it online, most folks have said to allow system.preferences.energysaver, but it doesn't look like that is actually linked to the low power mode option at all. Is there another key I can use to modify the behavior of low power mode in the battery pane? Thanks.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!