Get Support
Recently active
The Microsoft forums seems to have little in the way of information regarding exclusions on macOS and my Google fu seems to be broken today.Rather than re-invent the wheel, can those that have implemented Defender share any nuggets of wisdom regarding any system folders / processes that should be excluded as part of the standard configuration config profile. My starter for one would be the jamf binary and /Application Support/JAMF
Howdy,I have a laptop that failed to update the MDM Profile, it's expiring soon. Normally I'd just wipe and re-enrol but this happens to be a Developer's laptop and they can't really afford the downtime. I checked the logs and I see "Update to MDM profile contains different push topic". All other 200 or so devices in the fleet renewed fine, just not this one. Is there anyway to resolve this without wiping the device?TIA.
We can't find a workaround to GarageBand, Logic Pro, MainStage and MuseHub requiring admin rights to install additional stuff (even running Carl Ashley's loopdown with the all parameter still results in Logic Pro wanting to download additional items although GarageBand shows everything installed). So now we're considering deploying MakeMeAnAdmin and reducing the time down to 1min. All good except that the script stores the logs locally which we're concerned about the user deleting. One option is to email it out but that means leaving an unencrypted mail user password in the script which we could live with by creating a mail only account that can only send to internal addresses. But then I remembered seeing a script that sent logs to Jamf but can't remember where. Does anyone know if it's possible to send the MMAA logs to Jamf (and how)? We just need to know what the user did during that window that they were an admin.
Can i export any of my config profiles or policies in Pro and import to JAMF SCHOOL?
Hello all,I've done a search for this but haven't quite found the info I'm after. Basically we are looking to flip the switch on federated authentication via Google for our Managed Apple IDs. We have ~70 people who are currently using their work email address for their Apple ID. Just want to know what their experience will be when we flip that switch. Will it just be a case of re-authenticating with their Google details or will it be more painful? �ny info will be greatly appreciated!
Environment context: 2 different ssids- Open network Captive Portal SSID with a portal enforced (Aruba Clearpass)- WPA2 SSID with an allow all after authentication (by default)While devices are on the default SSID, we are able to push a wifi profile consisting of the captive portal SSID to devices successfully. However, when devices are on the Captive Portal SSID, we are unable to push the default wifi profile back on devices. The following IPs, URLs and Ports have been allowed to devices on the Captive Portal SSID: https://learn.jamf.com/en-US/bundle/jamf-school-documentation/page/Firewall_Ports_IP_Addresses_and_URLs_Used_by_Jamf_School.htmlWe need to switch SSIDs during maintenance periods where having an allow all SSID will be beneficial to us, open to other suggestions on a better workflow as well. Any one has any idea how we can go about this? Thanks for reading
While rolling out Jamf safe internet we see this message in the dashboard for active devices.
I'm pretty sure I know the answer, but can't find the statement in any documentation. Is it possible to pull attributes when you have Cloud Identity Provider enabled for Azure in via extension attributes? If so, what attributes are available?
Today we released Jamf Connect 2.37.0. This release includes the following changes and improvements: Identity provider (IdP) related features and background activity are now disabled by default when Jamf Connect is not linked to an IdP. PingFederate is now a supported IdP when making role-based privilege elevations. The login window web view now expands to better fit certain IdP logins on larger displays. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Thank you!The Jamf Connect team
I've been having this issue for a while and it seems to have been caused by a Jamf PPPC profile that I created to allow standard users to authorize Teams to screen record.On Monterey and earlier operating systems, users get stuck in an endless loop in the new Teams when trying to enable Screen Recording to screen share. They get prompted to authorize it but even when it's authorized, they get asked again, as if it wasn't authorized. The only solution we've found so far is to upgrade to Ventura where it doesn't seem to be an issue but they do have to toggle it off and then back on and if it's already been set ton On. Has anyone experienced this issue? Thank you.
Hello, Our organization would like to set the "Download External Images" to "Only in Messages from my Contacts" which we were able to do with ease. However, we want to add a few known emails to everyones contacts or at least to the "Junk - Safe Senders" list so this change doesn't cause issues with our users. Is there a way to do this?
Hello folks,I am currently testing iOS 18 dev beta. As it stands, Profile-based User Enrolment is no longer supported and you are forced to use Account Driven Enrolment with Managed Apple ID. Is this correct? Are there any official sources from Apple? I haven't found anything about this in the release notes.Best regards,Florian
Hi everyone, With the update to Ventura, is there a way in Jamf Pro to enable users to change the Airplay Receiver settings? We want our users to be able to enable Airplay Receiver and Change the "Allow Airplay for" category without needing admin credentials. We were able to allow users to change these settings when they were under the Sharing menu in Monterey, but these settings were moved to the AirDrop & Handoff and now users can no longer edit (without admin credentials). We currently have AirDrop enabled in Jamf Pro. Thanks!
For the apps that are in Jamf's catalog, you can use less than "Current version" as a way to add users to a smart group, but what about the apps that aren't in the catalog? Is the best method just to run the policy once per week? Or is there something I'm missing here?
Hello,I'm experiencing difficulties enabling FileVault on some macOS devices that were auto-enrolled via JAMF Connect. Despite having the policy in place, FileVault encryption did not initiate.I've opened a ticket for new devices, but there are still a few lingering devices where FileVault remains disabled. When attempting to manually enable FileVault and cycle the key Thank you for your help.Best regards,Darshan Hiranandani
Not a huge deal but since upgrading our Windows On-Prem Jamf server to 11.6 we are not getting any backup notifications.It just shows the following on both production and dev server:Backups run fine, SMTP also works for other notifications.Anyone else affected?
Sorry for the weird title, but I just want to check with the community before moving forward! We have a fully setup Jamf environment where everything is humming along well (enough). We have Okta and don't utilize it for Users/Groups/Buildings/etc and would like to start (unfortunately Okta isn't native for Directory Integration yet. Vote for it here: https://ideas.jamf.com/ideas/JN-I-16061) I've setup Okta successfully in our sandbox Jamf Pro server and everything just fine so we're ready to move forward to Prod but we're not sure if anything will break. Since we don't have any policies, groups, extension attributes, that use LDAP in any way, we don't expect anything to take effect until we start using those, but we also weren't sure. Can anybody confirm that adding an LDAP server to Jamf Pro just adds the ability to start using going forward? Rather than take over some part of your server and break/change things immediately? Thanks a ton!
Hello all,I have a two-part question... Has anyone ever installed the Datadog agent into JamfPro so it can be accessed through SelfService? And do I need to get a script from Datadog to get it configured so it can be installed on the Mac using SelfService?I'm planning to get the free trial of Datadog, but I want to see if this can be done since the trial is only for 14 days. I want to be able to show my management that Datadog works and can be available for all of our users using SelfService. Thanks for any feedback :)
Does anyone have suggestions how to maintain iPads in the Return to Service app scope after it is run? The iPads are dropped from static groups, and I can't think of a smart group that will retain the iPad after it is erased (other than all iPads and I don't want scope this to all iPads).
Hi Mac Community,I'm trying to correctly deploy Unreal to my lab environment and I'm having a time making this work smoothly. My lab setup consists of users logging with standard rights along with accounts being removed at every startup.My issue is, when Unreal is launched, the student has to wait until all the "Compiling Shaders" are finished which can take awhile. I'm aware of a setting called Global Derived Date Cache folder which I've pointed to the /User/Shared/Epic location but it doesn't seem to respect it. Anyone run unto this with a solution? I was hoping to be able to capture this cache folder on a test machine and have it pushed to the full lab. The times that I have done this it still goes through the Compiling Shaders process.
Hi everyone,I am looking to get in touch with any MSPs who are looking to automate their work and realise that the future of the MSP industry at the SMB level is end-user self service.Any one who fits the bill please dm me!
All,I've got an end user who I'm doing a favor for, he's retiring and buying a new Mac which I'm setting up for him. I'd like to use migration assistant to move all his stuff over, while just removing the Jamf stuff-- I don't want the self service app going over, and I certainly don't want any configuration profiles moving over.I haven't tried this in the past, but if I use migration assistant, and JUST move applications and the user folder, not checking any other boxes, will it also bring over configuration profiles, or other managed settings? All the apps on there are either free, site licenses (Which he won't be able to use once he's not connected to our network), or apps he purchased himself, so we're not worried about him taking any licenses he's not supposed to have. My big concern is that he's got an AD account, and we'll need to move him to a local account. Is this possible with migration assistant? Looking forward to hearing any possible suggestions that others have for h
Hello Jamf Nation! In this version Managed Software Updates are now out of "beta" status and ready to test! We've also resolved a few key issues such as PI-118519 and PI-117278. You can find more information in the release notes when you enroll. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Does anyone have input on Docking station, i have been using the J5 Dock's but they see to be hit or miss with the M3 chips i have use LandingZone in the past and they seem to be good but would like to not have to order based on the model type looking for RJ45 2-4 monitor support and 2 USB A and C can always add a hub for more ports
Hi everyone. I am using Composer to build packages a different MDM and really enjoying it.One question I have- am I missing on updates/upgrades? How do I check if a new version is available? Is it paid/free? Where to look for info? Couldn't find any useful info on the product page itself. Right now I have 10.40.0-[lots of digits].
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!