Get Support
Recently active
Hello,I am in the process of testing the implementation of CIS v8 Benchmark for macOS and one issue that I am running into is that I cannot find the profile that allows for touch ID when logging into the computer after being locked. For reference, I created the baseline using Jamf Compliance Editor. I have gone through the profiles that were imported but can't seem to find the one that allows for this. Any help would be greatly appreciated. Thank you in advance!
Looks like Apple was hacked by IntelBroker. What are you guys' thoughts? Wonder what implications the release AppleConnect-SSO will have. It has not been updated since 2016 per the docs, but I would not be shocked to learn that its foundation is very similar to more current tools like Apples Kerberos SSO extension and possibly PSSO. Knowing the code base would make these tools much easier to reverse engineer for exploitation. Has Apple Been Hacked? June 2024 Breach Exposes Source Code, Hacker Claims (forbes.com)
Hello. I am in need of assistance on this. I have a ticket open with JAMF support but no answers yet. Here's an overview:On premise JAMF behind a firewall.• Conditional access connected to Intune and devices are enrolled in Intune.• Only laptops using conditional access. About 40-50. Recently updated to a Jamf cloud instance• We are un-enrolling devices from On Premise and re-enrolling in Jamf cloud.• Laptops would be last. We need to find a method to move from Conditional access to device compliance.I need to find out if there is a way to have BOTH conditional access and device compliance active in Azure/Intune. This way we could move devices slowly to cloud instance and register them with conditional access. Otherwise we have to pull the switch on all 40+ laptops at the same time and move them over, and enroll them all in Device compliance. Thanks for any information!
New Jamf Admin here I have recently pushed a Firefox update for version 126.0.1 and am getting a lot of reports that Firefox doesn't open back up after updating. The app refuses to open and the only fix is reinstalling the app again. I'm not pushing the app with the configuration profile option selected. Does anyone know why this would be happening?
Hello Team,I am deploying the Nexthink collector v24.5.1.23, I did repackage it, and if I install manually by double clicking on it, then it works fine, but when I am deploying through a JAMF policy it is failing saying that " Installation failed. The package could not be verified." But the same way I am deploying the previous version v23 and it is working fine, where is the issue and how to fix it?
Looking for ways to push OS updates to users i tried nudge way to hard to setup for a novice user, so i tried the JAMF Pro software update and i get the ScheduleOSUpdate Missing 'ProductKey' error every time i try a Minor or Major update any other way to push the updates? or fix this error
Safeguarding personal information is a fundamental commitment to which we adhere at Jamf. Safeguarding isn’t just securing the data entrusted to us, but also maintaining compliance with various privacy laws and regulations. In our efforts to demonstrate our commitment, we are providing you all with the following important updates: Jamf is proud to participate in the Student Privacy Pledge, and we’ve updated our Privacy Notice to reaffirm our commitment to the Student Privacy Pledge and to further clarify the third parties we use to process personal information. These updates include reinforcing our dedication to protecting student privacy by ensuring all practices align with the highest standards of data protection and transparency, as well as providing more detailed information about the types of customer data we collect, how it is used, and the third parties involved in processing this data. Additionally, we have added information to our Privacy Notice on how we communicate br
Hello everyone,Using JAMF Trust or any other solution, I try to block all comunications except HTPP/HTTPS.But I don't see any possible option on security cloud.Using a configuration profile, I can only block applications.Does anyone or a JAMF expert have any ideas?Thanks for your help
Hi,I have set the Configuration Profile up correctly, it works fine, but I would like the Admin to be excluded.I tried the Exclusions section, and added the Type as 'Directory Service/Local User' and the name 'Admin' but this does not work.Any other suggestions please?Thanks, Will
Has anyone else been experiencing issues with dark mode in Jamf Pro 11? I've noticed for a while that sometimes when I go to Policies, they all load in white at first:Yesterday, I noticed while it was loading everything that I could see the plus to create a new policy. Since that's what I was there for, that's what I did. Then, this happened: Policies nested inside Policies. I tried duplicating this, and it seems like I only see this after I get a session timeout notification. If I extended it or let it expire and go back, I see this issue.
Hi,I am using JAMF cloud and trying to workout ADE (First time) but i keep getting an error on my brand new Macbook Studio saying "Enrolling with Management Server Failed. "Amazon Root CA 1" certificate is not trusted.Any ideas ?I have opened a support case however it looks like its just taking time, so thought maybe I'd ask you guys for some ideas while waiting.
Hello Jamf Nation, I am trying to implement the nist macos security compliance project into our organization devices, https://github.com/usnistgov/macos_security . I have read through the wiki and it keeps saying in each page that: We recommend working off of one of the OS branches, rather than the main branch I am wondering how can i generate the script and configuration profiles and put them in jamf while we have different mac os versions, i.e. ventura, monterey, sonama. I hope i am expressing my self clear. Please any guidance on that? Thank you,
I wanted to make a popup window that users had to click on to acknowledge they were getting an update that would close their open application.I created a notifyScript , a notifyPolicy, and a updatePolicy.notifyPolicy is set to enabled, recurring check-in, automatically rerun, on next.notifyPolicy is set to enabled. notifyPolicy passes the name of updatePolicy into notifyScript as an argumentnotifyScript uses updatePolicy name as a custom event trigger to call update PolicyWhen notifyPolicy runs, i get the following:"No policies were found for the "updatePolicy" trigger.Where am i going wrong?
Is there a script to set up the home page for Microsoft Edge ?
Looking for some help with a script issue please.I've written a script based on Charle Edge's https://github.com/jamf/MakeMeAnAdmin to use in a Cyber Essentials Mac build. Whilst the original script temporarily elevated the users privileges I want to create a temporary separate admin account.Everything works well apart from the final stage (lines 50-65, labelled "# Write a script for the launch daemon to run to delete the temporary admin account if it exists, delete the launch daemon then provide feedback to user.") to cleanup the admin account. This part of the script does work when run manually so I'm thinking it's an issue with permissions and/or ownership.Any advice would be appreciated. Thanks#!/bin/bash ############################################### # "I need admin". # John Moore, April 2024. # Based on "MakeMeAnAdmin.sh" by Charles Edge, see https://github.com/jamf/MakeMeAnAdmin. # This Jamf Self Service script will provide the user with access to a separate admin ac
Hello!I have successfully packaged, deployed, and tested the GMetrix plugins for Adobe CC 2021. This works for both Intel and Apple Silicon Macs.Using Composer:Download the GMetrixSMSe.app from their website Open composer and create/start capturing a new package deploymentPlace the App in /ApplicationsOpened the App and LoginOpen the settings pane and click on the Plugins PaneGo through every Adobe App installation procedureCreate the package source in ComposerOnce Composer is finished, here are the Directories needed:/Applications/GMetrixSMSe.app/Library/Application\\ Support/GMetrix/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.aftereffects/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.animate/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.dreamweaver/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.illustrator/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.indesign
hey guys… having trouble scoping a self service policy to a specific Azure directory group. I deployed the policy to all comptuers and all users, but limited the scope to our our Operations team group in Azure. This obviously requires user to login to self service to see the policy, but logging into self service fails when using directory creds. Directory user lookups are successful in the Cloud Identity Provider settings so I know Jamf can see the users, and we have self service set to allow users to login using directory creds. Anyone got any thoughts as to what I”m doing wrong
I'm trying to put together a CIS lvl 1 plist for firefox deployed via JAMF pro and unsure which compliance options are related to which keys in the plist, or where to start beyond adjusting the standard plist, does anyone have any resources to aid with this? or a baseline plist to share?
Hi,for some time now the Management Commands on my Jamf Pro instance have not been working. They are staying on the "Pending" status. This also affects the installation of Mac Apps (the ones with the VPP licenses). As far as I can tell all of my devices are affected? Is there anything I can do about this?Kind regards
I would like to setup PowerBI dashboards for Jamf.However I cannot find a good up-to-date guide that steps through all the steps. Jamf's YT video https://youtu.be/PBsP84G-vtg?si=G4zj7mc2gZpH15Ml is great, but the narrator just says to use an account that has get rights to computers, etc. but does not explain how you would set that up. I find many YT tech tutorial videos are like that - missing important info that the narrator just assumes everyone knows.I have an AD/LDAP service account added to Jamf and have given it read permissions to everything. But when I try to use that account to connect to Jamf in PowerBI it fails to authenticate and so does my regular account. I'm not clear on what URL to use for our on-prem Jamf environment. Is it https://yourcompany.domain or https://yourcompany.domain/api?Jamf's GitHub page is 4 years old! https://github.com/jamf/powerbi/ - can't this be updated? It still talks about the custom connector which I understand you
Hi, I don't like the new HUD on Jamf School.Is there any way to have the legacy version?Thanks.
The state of Indiana has decided for government organizations that they are going to provide grants for/subsidize the cost for Crowdstrike statewide if orgs opt in to the program. We did and are successfully hoping to get a changeover made to Crowdstrike. We've tested Crowdstrike and it seems to work fairly well. The only problem will lie in removing Carbon Black. Our subscription to it ends at the end of June. We have generated a mass deregistration code. I'm assuming when our subscription lapses that we will lose console access. Would I be wise to somehow export a list of individual uninstall codes? Probably yes, but I am unfamiliar with how to go about doing that. What I don't want to see is that some situation where the client is uninformed of the company-wide de-registration code and will only take the individual uninstall code. I'm not sure whether we will lose console access either. Is anyone familiar with this process?
Good afternoon JAMFNation, I am working on deploying iPads that act as a thin client. Single App mode with Microsoft Remote Desktop. I have read into Managed App Configurations but have found nothing of use. Do you guys know of, if possible, how to preset RDP sessions in the Microsoft Remote Desktop app? I would like to have everything preconfigured. The site receives the iPad, opens it up, with DEP and MDM it configures itself, locks down and enters single app mode with RDP. And listed are the Remote Desktop sessions that will be used + when clicked on it will ask for Username and password (lock down adding/saving users) Is this possible? !
Good morning!Relatively new and inexperienced MAC admin, so please be gentle and feel free to talk to me like you're talking to a 5th grader!In troubleshooting MDM communication with a large number of our Macs, the support tech I was working with suggested adding some EA's to assist in seeing what was going on. It definitely helped to identify and point us to a resolution, but one of them doesn't appear to be working the way I think it should? Note, that my background is mostly Windows enterprise, not any Bash, so I'm not sure exactly how to troubleshoot and resolve to get this particular EA to display what I want.Here's what was provided: #!/bin/bash theIDs=$(security find-identity -v | awk '{print $3}' | tr -d '"' | grep -E '^[A-Za-z0-9]{8}-[A-Za-z0-9]{4}-[A-Za-z0-9]{4}-[A-Za-z0-9]{4}-[A-Za-z0-9]{12}$') echo "$theIDs" if [ -z "$theIDs" ]; thenecho <result>"ERROR - No keychain identities matching a UUID found on this system.</result>"exit 1elseecho "At
I'm starting to see issues where a computer with a standard user is logged in, and when an authorization window pops up, like when you're changing system settings or authorizing an install, the computer will not accept the admin username and password. If I log into the same computer as the admin, it accepts the password without issue. I created a second admin account, and it is having the same issue when a standard user is logged in. I've checked to make sure the admin accounts have a securetoken granted, and they do.Has anyone else ran into this problem and found a fix?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!