Get Support
Recently active
Hi! New to Jamf and discovering all the APIs! I wanted to find out if there is an API command to Unenroll an iOS device from Jamf? I can see that we have a Deletes a mobile device enrollment profile by ID API, does this have the same result of removing the enrolled profile and all the configs from the managed iOS device in Jamf.
Hello everyone,I hope to find some help here with our issue. We are using the Kerberos SSO Extension to synchronize the passwords of Mac users with their Active Directory (AD) passwords.During initial setup, the user logs in with their AD account, followed by a password synchronization window. Here, they enter both their AD password and the Mac password to synchronize them.This process works initially.However, we have a department at one location experiencing an issue where the password synchronization window pops up as many as 50 times a day. It doesn’t matter whether a password is entered or if someone just clicks "cancel".We have reinstalled all the Macs at this location. Everything was fine for about a month, and then the problem gradually started again.I went to the location with my MacBook and did not experience the problem there. The colleagues also have this issue at home over VPN.All are using macOS 14.4.1. However, the problem was also present in previous versions, including
Hello everyone, I've been searching high and low for a way to be able to update the username in a VPN profile based on the user who is logged in. We are currently using a configuration profile which works only when only 1 person uses a Macbook but as soon as a 2nd user logs in, the username of the 1st user remains in the VPN settings when the 2nd user tries to connect. Has anyone managed to find a way around this?
Hello everyone, I would like to know if it is possible to deploy pkg from a url. The reason I'm asking is because the linked url contains a version of the pkg that automatically logs in our agent. If I simply download the pkg of the agent and store it on a cloud or other distribution point, it simply installs a generic agent which then needs to be logged into. You can understand how it’d be problematic to log into every computer individually after the agent has been installed. Atera has a terminal command that allows one to download an instance of their agent with a url. This instance automatically logs in the user into the linked Atera environment upon completion of the install through terminal. Does anyone know of a way to use Jamf Pro to ease that process so the agent of the url can be deployed on computers rather than the generic one from the pkg file? Thank you.
Hi all i tried all to deploy the 1 password Google Chrome extension but it is not working did anybody do that and able help for me
What are we talking about? Handling json in the macOS shell of your choosing. Why? Because there still isn't a great way to do this natively, it's extremely useful given how many macOS binaries & logs output json-ish data, and, there are ways of working around this limitation. Arg-nauts is an unforgivable pun, however, there are some real explorers in this area. I rounded some of them up here: https://community.jamf.com/t5/jamf-nation/firefoxy/td-p/266970 I will try to be a bit more exhaustive this time... • From the crafty Joel Brunner (you may know him as @brunerd...) jpt: https://www.brunerd.com/blog/2022/02/01/jpt-1-0-can-deal-with-multiple-json-texts/ljt: https://www.brunerd.com/blog/2022/02/22/ljt-1-0-0-a-little-json-tool-for-your-shell-script/ I have used ljt in production. It's lightweight & works a treat. Once you're on Joel's blog, check out ALL of his json related posts! • The post below inspired much ado in the Mac Admins Slack channels rega
With recent IOS updates, the "Bringing Devices Together" settings reverts to default despite users toggling it off. This is problematic because some users carry both a work phone and a personal phone while on duty. The person may toggle off this setting in the Airdrop settings menu, only to have it toggle back on with IOS updates. We would like the option to keep Airdrop on but toggle off this setting in a persistent way or turn off device proximity notifications, because it's annoying to the users. Any thoughts on how to do this?
This might show up twice due to login weirdnesses, if it does I apologize...I'm creating a new prestage enrollment, and I have around 10 devices I want to assign. I have individually found the serial numbers one at a time which is tedious but doable and checked the assign box, but in the interest of verifying that the correct machines (and only the correct machines) are assigned, I want to see only the assigned machines, not the several hundred "Not Assigned" ones. the "Filter Results" box will let me filter for "Assigned" but that still shows me all the "Not Assigned" ones as well - I cannot figure out or find online the correct syntax to exclude the "Not Assigned".
I'm using JamfPro MDM in cloud to manage computers on a campus. I wanted to allow users (employees) to be able to change their local user password (99% are standard, non-admin users) via the mac computer's Users & Groups settings user "Change Password" button while at the SAME TIME NOT ALLOWING them to change the "Allow this user to administer this computer" toggle listed on the same popup window. I tested by creating an duplicate config profile for security & privacy settings with the only change being to allow password change. This policy was applied to a test machine and unfortunately it gives users the ability to decide if the user can administer the computer which defeats the purpose. I don't understand why this one change password setting in the security & privacy config profile section does more than give password change permission. Any thoughts or suggestions with this?A while ago, I resorted to a self-service app script, that the user would trigger, that would requ
Is anyone else's Tomcat settings in Jamf Pro Server Tools broken after upgrading to 11.3 on On-Prem Windows Server?Webserver is running just fine but Jamf Pro Server Tools show it as "not running" and throwing an error when trying to start it.Can control Tomcat through net start/stop tomcat9 or the tomcat9w.exe without any issue.As per warning:As a result of PI116512, new installations and upgrades using the installers will fail if Java 21 is installed. Mitigation: Uninstall Java 21 and reinstall Java 11, or manually install Jamf Pro.we stayed on Java 11.Just curious if this is something with our install or a general update issue?Thanks!
I have an asset that was auto-enroll via JAMF connect. However, the asset did not do the filevault encryption eventho the policy is there. I opened up a ticket with the to resolve the problem ont he new devices. However, I still have a few devices lingering with filevault not enable.I just tried to manually enable one of these assets and then cycle the key. However, it is not letting me.when I tried with my account. it doesnt take my password or the admin password. if I do it under, a users account it asks for the admin password and the same thing it doenst look like it takes.This is on a M2 with Ventura (13.6.5)I know this has to do with the security token not being enable for the account. Not sure how to fix this. any help greatly appreciated.
Hi all, we're having a difficult time uninstalling Sophos Endpoint Protection from our Mac endpoints with Jamf. This particular enterprise version of Sophos employs Tamper Protection, which was easy enough for us to disable by creating a policy that deletes the SophosSecure.keychain file that Tamper Protection creates on all the endpoints, but even with Tamper Protection disabled we can't figure out how to remotely uninstall the client itself. So far, we've tried the following approaches, both of these scoped to a test machine with Sophos Endpoint Protection installed and with Tamper Protection disabled: Packaged the Sophos uninstaller (Remove Sophos Endpoint.app) with Composer and added it to a Policy with the Packages payload (specifically, we installed Sophos on the test machine, started Composer and took a before snapshot, uninstalled Sophos, then took an after snapshot, saved and uploaded the resulting .pkg to Jamf) Created a Policy with the Files & Processes
After weeks of working and looking for a solution with Sonoma NOT showing the WiFi through the control center to all my wired lab users, I felt you might stumble across this and need specifics to a solution. I disable the WiFi on my machines. I do so by running: sudo networksetup -setnetworkserviceenabled Wi-Fi offThis will cause the WiFi icon to show an explanation point. This is a nasty thing for users, making them think that they don't have internet when they do. So to eliminate this, I created a Configuration Profile that I push out to these computers.Here it is: Then under Application & Custom Settings, I choose Upload and created the following: The scope will be those computers running Sonoma. I hope you find this useful.Jack LawtonIT Manager/Lab Manager (5 labs - 100+ machines)School of Journalism and New MediaUniversity of Mississippi
I am installing Maya 2024 and I am running into this popup. I am able to get the license to verify via the network server when putting in my credentials. I haven't tried on a non-admin machine.I created a configuration profile with Managed Login Items, and added the Team Identifier/Bundle ID to it and deployed it to my machines and still getting the popup. I've not seen this popup before. Anyone have any info/experience on this?Here is the script I am using, with the AutoCad and Mudbox install lines removed:#!/bin/zsh ### Install AutoDesk Combo 2023 (AutoCAD, Maya & MudBox) ### silently @ login window with network licenses (aka multi-user lab/classroom deploy) ### 2022.07.27 by JonW ### Simply update variables/products below the function section as desired ### Read the additional details at the end of the script for more clarity on licensing. ### Ensure: ### 1) installer app(s) re-packed from .dmg by Composer & deployed to /private/tmp (root:wheel 75
Does anyone have experience distributing papercut printers (running on a Windows print server) via Casper to Macs? The problem I am having is with authentication on our AD domain. On the Windows computers, a user logs in using AD credentials, and is not prompted again for a username password when they print. When I setup the printer on a Mac (not distributed through Casper) it does not require secondary authentication. But, the Casper distributed printer does prompt for authentication. I've found the line in the printers.conf file which controls this: "AuthInfoRequired negotiate" vs "AuthInfoRequired username,password". Does anyone have any thoughts on why Casper changes this setting when distributing the printer?
Ever since I updated our organization's JAMF cloud server to ver. 11.3 last week, our team can't change the hostname of our client Mac devices. Though I still can type within the textbox to attempt the changes. However, the save button does nothing other than redirecting me back to the General Tab Prior to the update (i.e. on ver. 11.2), we have no problems changing the hostnames of our client Mac devices and the changes takes effect in an instant. I've also confirmed that our Policy for Computer Names is enabled at Maintenance > Reset Computer Names At this point I'm not sure whether the issue is on our JAMF cloud server, or whether there is a bug on the latest version that I'm not aware of. Appreciated for any inputs.
Hi All, may I know is there any script to know what the value for default browser. In the environment there are multiple browsers using, each one sited their own default browser. Need to know what is the default browser seted each Mac.thanks in advace
Anybody know how to block a site like: https://sites.google.com/view/games-unblockedd/ without blocking other Google Sites? Kids are using these sites with embedded games but if I block any sites.google.com it blocks teacher created sites. Thanks!
Hello everyone,I'm hoping this is a somewhat easy fix. We have one application inside of our self service "Intune Registration" even if we complete the intune registration process when we close out of self service we get "An error occurred while saving. selecting the 'Ok' prompt opens a new prompt, asking if we want to quit anyway. Selecting Quit anyway doesn't actually quit self service and the prompt, just disappears for a second then reopens with 'an error occurred while saving' ok prompt into a loop. We make it finally quit after selecting cancel. Question being, we don't need anything to save anything and this often confuses our users, how can we make this app behave just like the other apps where theres no saving involved.
I want to utilize Platform SSO with JAMF and Entra as our IDP. I was able to test the microsoft SSO plugin, but I couldn't get platform SSO to work. My goal is to have the user log in with their Entra ID credentials and to have their passwords sync. Any help would be greatly appreciated.
Hello.Does anyone have any experience mapping custom attributes from Google Workspace into Jamf Pro. We are using Google Workspace as our Cloud Identity Provider, and I am trying to sync a custom attribute from Google to populate into the "Department" field in the Mappings editor.I've tried just about every combination of attributes I can think of to try and get the data to pull across correctly, but nothing is working. For reference, the exact thing I am trying to achieve is pulling data from a Custom Attribute called "jamf" with my users' department name, as the actual Department attribute in Google Workspace isn't providing the correct info from our HR system. But when I enter "jamf" as the attribute in the Department field in Jamf Pro, it returns "no value" after a test search. I've also tried "user.jamf", "jamfJamf" and what feels like dozens of other variants to no avail.Any thoughts?
Trying to create a script (python or bash) to push out in a policy via Jamf Pro to delete Google Chrome.app from a system. I've tried various scripts online (new to scripting sorry) and everything fails. I'm currently testing this script and trying to run it manually using bash chrome-uninstall.sh but it keeps saying command not found. What am I doing wrong? #!/bin/bash # Remove Chrome rm -rf /Applications/Google Chrome.app/ exit 0
Hi All, We have an issue with students changing their background to a custom wallpaper after upgrading to ios 17. Students are doing this through focus mode. I can't find any restrictions to block this. Is there any way around this or a solution?Can anyone also confirm if they are having this issue too? Kind Regards,
HiI would like to use self service on iPadOs to be able to change between two configuration profiles. it always seems to fail one it. is there a way to use selfservice todo a group move instead. or am i one the right track already?
Our Dev team is looking at vr/ar for training. Does anyone know if JAMF will support it? or can it currently do that like its a mobile device?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!