Get Support
Recently active
I've already put in a ticket with Apple and perused the macadmins Slack, but I thought someone here might have had the same issue or know of a fix...We have a fleet of about 3800 machines. Most are Catalina, but we have about 800 running Big Sur and we're currently testing out Monterey (about 10 machines there). We're seeing a lot of problems with both SSH and Screen Sharing (also through ARD) where, if the machine is running Big Sur or Monterey and it sits for a day or two (like over a weekend) without being used remotely, it is no longer accessible via SSH or VNC/Screen Sharing/ARD. Rebooting the machine fixes this, but it's hard to do that since 1) the machine is onsite and the user is typically trying to get in from offsite and 2) SSH doesn't work. Currently we have a policy in Jamf that will reboot the machine for us and that normally fixes it, but now *users* are experiencing it and putting in tickets. This problem only occurs on the Monterey and Big Sur machines - Catalina never
I saw 2 accounts listed under Managed Local Administrator Accounts, 1 labeled as "jamf binary" and the other being "PreStage". I looked for where the 1st account was defined and I found it under User Initiated Enrollment > Computers > Managed Local Administrator Account > Create Managed Local Administrator Account I have a feeling that this was defined when we were going through the initial training with Jamf and something we don't really need because we don't allow user initiated enrollments and all our devices are enrolled from Apple School Manager. I'm not sure why Jamf would create this account on devices that have undergone ADE (I've confirmed its presence in our ADE devices with a dscl read). Would there be any issues with me removing that account?
Hello everyone,When I try to connect my iPad to a Mac or Windows with iTunes, I receive the following error message: "This iPad is supervised by another computer and cannot be used with this computer." If anyone has a solution, please suggest it.
Hi, I am attempting to deploy a Font payload and it never installs on the iPad. I upload the .ttf files on the Font page under general payload, this uploads the four files successfully. At this point I have created a Fonts profile and test it by manually installing the profile on a iPad. The task tells me it deployed successfully and the activity log gives me a green tick for that Font profile. But I do not see the Font profile installed on the device under the Mobile Device Management profile and I am unable to choose the fonts in Pages. Now, I have had success installing the Fonts manually using the iFont app, as it creates local profiles for each Font and I am then able to see the Fonts in Pages. But from my understanding I should not need to use the iFont app as I am using the Font payload in Jamf to deliver the Fonts directly. Why is the payload not working?
Hi All!So I've done my research on this already around JAMF Nation and everyone seems to be able to disable wifi completely wether its through managed prefs or a config profile. I have a script running that turns off wifi if hard lined and in turn if not hard lined allow wifi. This is for a lab setting so they really don't need wifi. What I want to do is to hide the icon in the menu bar through JAMF. There is a check box in network prefs "Show wifi status in menu bar" that if unchecked hides it. I tried doing a snapshot with composer but that didn't work out. Also theres a few other prefs I was hoping to add as well. In advanced wifi prefs I want to have checked "Require admin authorization to: create computer to computer networks, change networks, turn wifi on or off." That way even if they become disconnected from from ethernet they would still need an administrator to turn on wifi. Any help or direction with this would be greatly appreciated!
Anybody facing this?I am trying to upload a new IDP certificate to Jamf Pro for my Google IDP. However at the IDP settings page, it keeps failing to connect to cloud service provider. This blocks me from saving new IDP configurations on my Jamf Pro. Testing of the existing configurations works fine but the setting keeps failing to connect.
Hello, I attempted to enroll my M1 computer in my Jamf server using User-Initiated Enrollment. While the MDM profile installed successfully on the computer, it appears as unmanaged, and the Jamf binary is not installed either. Interestingly, it enrolled successfully on another server. As I'm running out of ideas on how to resolve this issue, I thought I'd reach out here to see if anyone encounter the same issue.
Okta has updated their server side rule for "automatically send push" to be a per-user setting stored in the Okta directory instead of a device based cookie stored on the individual computer.The "unexpected push" happens any time the Jamf Connect menu bar app does a background password check of the user's credentials AND the device is configured to use OktaIdentityEngine as the Provider AND the app defined by OIDCClientID has an Okta Authentication Policy that requires multiple factors for authentication. What Jamf Connect is doing - Interpret a response from Okta that MFA is required to obtain a token as a valid password. Ignore the fact that we didn't get an access token because we don't need one. What OKTA is doing - Getting a request to log in on an app that requires MFA, looks at the user's value for "Send push automatically" stored now on the server, sends the user a push notification. Example graphic below - (Also, this is the only known locat
We're running in to an issue with our SSO policy. Our Mac's are enrolled using the users Azure logon. We currently don't have kerberos in place, so are config profile is set to SSO. The tech who configured this created a policy that runs the below command at every network change per the apple documentation. The issue we're experiencing is that when there is a network change it kicks off sometimes it gets stuck the majority of policies don't run like our software updates. If you go in to policy audit of a device, it's just the sso policy. We just have the user restart and run recon and it's fixed and it doesn't happen to all users. Curious is anybody else has ran in to this. We do have a test group that is removed from the policy to see how it goes and just made if available to them if it doesn't connect correctly. #!/bin/bash killall AppSSOAgent Sleep 5 app-sso -a "oursite" -R -q exit 0
Greetings,question: Is there a way to capture the LAPS password stored in JAMF prior to purging a computer from Jamf? We have a strict 60 day purge policy in place; if the device has not contacted Jamf in 60 days or more, we are required to purge (delete) the devices from Jamf. However, we are on the cusp of deploying LAPS and a question that has come up is if a LAPS managed computer is purged, and a tech happens to find it sitting in a corner (something that happens with depressing frequency), is there a way to determine what the LAPS password was at the time it was purged from Jamf.I know there are alternatives to deleting devices that have not been in contact, but there are some politics around that in my organization, so I'm wondering if there is a technical solution.
Hi everyone,I have a question. I have a batch of experimental Macs that need to be managed and registered with Jamf.Question 1: These experimental Macs cannot connect to the internet. Is there a way to deploy policies through Jamf?Question 2: If internet access is needed for proper deployment, I know Jamf has port information. I would like to ask experienced experts which specific ports need to be opened.All Macs with normal internet access can receive policies correctly. I want to know how to ensure that the network-isolated Macs can also receive policies from Jamf. Thank you, everyone.
Looking to change from Facetime to Teams via script or config. Is this possible in Jamf or script?
I have a computer that is not reporting the correct macOS version in Jamf. The computer is checking in, and also performing inventory updates. About This Mac shows macOS 14.5, but Jamf shows macOS 12.7.2. We used the Terminal command to force an inventory update, and also removed the MDM profile and re-enrolled. All those previous commands show up in Management History, but macOS is still incorrect in Jamf. Are there any other troubleshooting steps I can perform?
Shared iPads can be configured with a quota to prevent it gets full quickly, could be on the teachers maneged IDs to bypass that quota or use the iCloud 200Gb on that account? If I had 200Gb account but the shared iPad had 3Gb you can't move photos or videos from the iPad to icloud, it get full easly. Thank you very much
Hi, when Safari is block in profiles settings in Jamf School, it is still possible to access a browser in the "passwords" menu. Is it possible to disable this icon ?Thx
I did an enrollment invitation the other day and noticed that only the MDM profile downloads for installation. What happened to the certificate that was supposed to download next? It never downloads. Is it part of the MDM profile installation now? Seems like the certificate gets installed with the MDM profile in the single download. The certificate looks like it is downloading but nothing downloads.
Pre-Ventura, I've been used a couple of different scripts to delete users' folders via a Jamf policy. It's worth noting this script only deleted the folder, but did not delete the user account with the OS. When a user with a deleted folder would log in again, their user folder would be recreated as a default user folder and they'd go on their merry way.With Ventura, the script will delete the user folder, but when the user tries to log in again, the computer will hang. Testing has shown the problem is the lingering user account. If I manually delete the account, log in works normally for then.I'm curious what scripts y'all are using to accomplish user removal in Ventura? I've been using the script below which removes the user accounts via "sysadminctl -deleteUser [username]", but sometimes it doesn't catch all the users. #!/bin/bash # Loop through users with homes in /Users; use grep to exclude any accounts you don't want removed (i.e. local admin and current user if
Good afternoon, I'm hoping someone can offer some advise on an issue I'm seeing in my company lately. Our macbooks have started to repeatedly prompt for "*insert application* wants to use your confidential information stored in "webproxy.*********" in your keychain. To allow this, enter the "login" keychain password". End users will enter their login password and select "Always Allow", but it just keeps repeating over and over again. In the past, I could always fix this by going to their login keychain, select the proxy entries, and under "Access Control" I'd select "Allow all applications to access this item". However, this doesn't seem to be working anymore and I can't figure out how to stop the constant bombardment of password prompts they're seeing. We have both Intel and M1 macbooks running up to date Big Sur and Monterey installs.
From Apple WWDC 24: What’s new in device managementLearn about the latest management capabilities for iOS, iPadOS, macOS, and visionOS, then discover the latest changes to Apple Business Manager and Apple School Manager. We'll also share updates to Activation Lock, SoftwareUpdate, and Safari management. https://developer.apple.com/videos/play/wwdc2024/10143/
I've often read on posts (or heard on YouTube videos) the admonition that one really shouldn't have many PreStage Enrolments without really being told the reason why not. Here I am looking at 8 of them and I can see that apart from one (Staff Macbooks which require Jamf Connect Config Profiles in PreStage), there really isn't that much difference between Lab 1, Lab 2, etc PreStages so I could technically combine them to just Lab PreStage. However, I assign computers to each PreStage and use the PreStage "membership" to populate our Smart Groups (e.g. Lab 1 Smart Group has criteria of memberof Lab 1 PreStage). If you are using a single PreStage for all your devices, how do you populate your Smart Groups? The only way I can see is if you make multiple criteria using "Serial Number equals XXXX" with the OR operator which I find more tedious than just checking them under the correct PreStage. Keen to hear how others are doing it.
Hi All,This one has come up before in the forums, but I am trying to determine why my script has stopped working in my test environment but still is working fine in production. It's the same script and I made sure to change the script to reflect the API user in test. We have a field in our preload called AssetTag which the script should be reading and then renaming the device to based on serial. This script is failing with the following error: Asset Tag is being set in the preload and is being seen by JAMF on the record but is not completing the change. Script exit code: 1Script result: Asset Tag is empty. Exiting...Error running script: return code was 1. /bin/bash #set the variables for the server and API account jssUser=APIUSER jssPass=PASSWORD jssHost=https://jamfcloudinfohere.jamfcloud.com #get the serial number serialNumber="$(ioreg -l | grep IOPlatformSerialNumber | sed -e 's/.*\\"\\(.*\\)\\"/\\1/')" #get the asset tag from jamf asse
Our GSX connection certificate is about to expire. We got a new one from Apple's GSX services. The JAMF pro documentation says there is a renew button. It's totally missing from our 11.3 cloud instance. I've opened a ticket with JAMF but heard nothing back. I went ahead and removed the old certificate and uploaded the new one. The only way I could to get the certificate in there. I also loaded up a new API token. Now, I'm getting unauthorized. GSX has came back and said it's a Jamf UI problem as the cert and account look good. Wondering if anyone else has noticed this? Renewing the Apple Certificate You can use Jamf Pro to upload a renewed Apple certificate without removing the existing certificate so the connection with GSX is not lost. A notification is displayed 31 days prior to the expiration date of the Apple certificate. In Jamf Pro, click Settings in the sidebar. In the Global section, click GSX connection. Click E
Hello all, is it just me or can Jamf app Installers only be assigned to smart groups? Hoping this changes as I have several that really do not make sense to make smart groups for since there is not really a common thread between the users. I guess I could make a Smart group that is just members of the static group, but this seems like a redundant approach.
Greetings! I'm trying to create an EA that detects when a user has added their own user to a device. We need an indicator of "setup-ed-ness" on laptops. A device that a user has never powered on, or has but never logged in to, needs to not run a couple policies, but once someone has their user account (John Doe), it should be in a "ready" state.So I'm searching for "Machines with known accounts, plus more." We have two accounts fleet-wide, with predictable names. Once someone logs in with Jamf Connect, there should be a third account. But I can't write a one-size fits all for known1, known2, as well as unkonwn1, unkonwn2, unknownN in a Smart Group, at least not that I'm aware. I can create a smart group that checks for the presence of the expected users.I was thinking I'd need to write an EA, but zsh is giving me a devil of a time taking dscl's output and putting it into an array I can cross-check.Anyone have any guidance on a pre-existing EA that's c
We've noticed that since upgrading to Sonoma we are unable to push commands to laptop that is not logged in. If it is still on the log in window (Displaying list of users) we are not able to push Lock or Wipe Commands, they stay on pending. This is happening even if we plug a network cable in.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!