Get Support
Recently active
Hey Everyone,Ran into an issue today that was out of the blue and fun I think would be helpful for some of you. Earlier today a couple of my users were signed into Teams and sat them at a disconnected screen and to sign back in. After relaunching Teams it brought them to a "We Ran Into Trouble 1002" and a "Something Went Wrong 1001(or 1000)" error page. Effectively making them unable to open and even attempt to sign into Teams.Troubleshooting through this and blowing out the cache in ~/Library/Application\\ Support/Microsoft/Teams/Cache and a restart did not resolve it and there are no Microsoft Teams Identities Cache entries in the Keychain to remove either if you are using either or both Jamf Connect and the Microsoft SSO Extension. To resolve this I had to delete the Teams Cache folder from the machine, un-scope the MS SSO Extension to the device and after a restart the user is prompted to sign into Teams again without an issue. I believe this is stemming from an issue of users
Have a Mac that's lost contact with Jamf...Trying to update the MDM profile with "sudo profiles renew -type enrollment" but end up with a "different server URL" error. (I guess the prestage changed)sudo jamf removemdmprofile didn't work - maybe because the machine has Ventura?When I ran jamf policy I got "device signature error"After running jamf removeframework the "bad" MDM profile persists. ... Is the only solution to wipe the device or have I missed something?
We have limited number of licenses for MainStage, just enough for the number of teachers. We're now replacing their ageing Macbooks with newer ones but they can't install the app using self-service because there are no free licenses. How have others worked around this (without purchasing extra licenses)? I have created a script that deletes the app and do a recon (the record for the device in Jamf no longer shows the app as installed in inventory) but the license is not released (Mac Apps still show all licenses are used). Is there a delay when this gets updated or do I really have to wipe the old device before the record is updated?
Has anyone had any luck getting defender config profiles to block USB storage in jamf? I had gotten it to work using the guide provided by Microsoft a few months ago, but recently it appears to no longer be working. We've tried changing the plist that microsoft provided in the config profile to disable USB but it just doesnt appear to work. If anyones in a similar situation and gotten it to work, id love to know what you did. Our company isnt looking to use jamf protect just for the USB blocking.
Is it possible to export a list of just the applications found across all devices without listing the device name. Basically I want just a list of applications so that periodically I can run the report, go through the list and look for odd applications that I'm not familiar with and follow up from there. The current computer inventory export > applications file is huge and takes to long to go through as EVERY device has chess.app installed for example. If not I might have to go to plan B
I'm trying to create a smart group to remove applications. Normally I just do application title 'has' Application.app. However, I'm finding users have renamed 'Application.app' to other values, like 'Application (1234).app or 'Application (112233) (445566).app' and so on, probably to maintain specific build numbers of the app. Is there any smart group criteria that I could use to catch all those modified names? I tried the `Application %.app` wildcard in the name, but that returned 0 results.
Hi,I am running Mac OS X 13.3.1 for 100 iMacs, after a schedule maintenance update, I would want to make sure student account is able to login to the iMac. I used to be able to use osascript but now it give an error keystroke not supported.`osascript -e 'tell application "System Events"' -e 'keystroke "admin"' -e 'keystroke tab' -e 'delay 0.5' -e 'keystroke "abcd1234"' -e 'delay 3.5' -e 'keystroke return' -e 'keystroke return' -e 'end tell'`I was reading the articles but not getting any results.https://community.jamf.com/t5/jamf-pro/10-7-auto-login-with-osascript-at-welcome-screen-just-isn-t/m-p/52599https://community.jamf.com/t5/jamf-pro/issue-running-a-script-at-the-login-screen-with-casper-remote/m-p/128877#M117994Any others successful method that can share?Thank you
I've read in all the other articles/discussions on people having the same issues as me in deploying the new version of AMP... but have yet to see a clear-cut solution on getting this deployed... I've seen the "solution" of finding the hidden policy.xml file in the DMG, but am still a little confused about that part.... Can anyone (maybe not exactly) step-by-step have an easier way of deploying this?
This isn't a big deal, but it worked when I tested over a month ago. When running installing the client, it does the update correctly and removes the old icon, but it's not adding the new icon to the end of the dock. If I run the update without the old agent installed, it installs and adds the icon to the end of the dock, just doesn't do it when there is a previous version installed.
Hello, I would like to configure the "Wait to send Messages for -+ " under the "Undo Send" to 20 seconds for all MacBook Outlook clients through JAMF Pro. Can this be done?
I was having issues getting smartcards to work on my M2 MacBooks. I'm able to pair the card and unlock the system using the card, however when it shuts down and gets to the FV2 logon it says " smartcard configuration is invalid for this account" Has anyone else run into this? Any ideas where to start? Thanks,
Hi, When trying to download Self Service from the JSS (JAMF cloud), I am met with the above error message. I have performed this ask previously with on premise solutions and had no problem - but it seems unless I automatically install it (which I don't want to do as it will install for everyone) I cannot use the app and test out the functionality. Is there a way around this?
Hello Jamf Nation, In Jamf Protect, alerts pertaining to threat prevention have been updated to include additional information about the malware detected, including available reference articles from Jamf Threat Labs to enable further investigation. For additional information, review the release notes via the Jamf Learning Hub. Thank you,The Jamf Protect team
We have a bunch of machines that have done their initial check-in but have not inventoried yet.As such the Console reports them as having the name "DEP - sernum", I need a smart group that can capture those devices so I can use it to exclude the devices from other Smart Groups that produce E-Mail Security alerts.As an example ....We have an Extension Attribute that checks the root user, if it has been enabled it returns "Enabled" if not it returns "Disabled" We then have a security Smart Group, that checks the attribute and populates with devices that have the "Enabled" state, and sends a Security Alert to relevant people.However we are seeing that group populate and trigger Alert E-Mail for devices named "DEP - sernum" and we want to exclude those devices as they are in an initial check in limbo. We tried a simple Computer Name like "DEP -" Criteria, but it seems to ignore those devices in any Computer Name based criteria.Any advice would be greatly appreciated.
Hello-We've recently been setting up our iOS/iPad infrastructure, and are trying to get a configuration for shared iPads ready. We are generally a microsoft org so I looked into and configured the Microsoft Authenticator app + the Microsoft Authenticator Enterprise SSO extension (or whatever it is called), and to my chagrin it still appears to be in preview mode (I think). The other solution I've been looking into is just putting the iPads in shared mode and then syncing managed AppleIDs from EntraID for users to log in. My issue with that solution is there appears to be no (easy) way to enforce that users use our managed appleID domain at login. This is really frustrating, because without a way to ensure users are using our managed AppleIDs, our org will likely have to plainly disable most features that make AppleIDs useful (and we'd like to make sure people are using only managed accounts on our devices). Does anybody have a recommendation to either serve SSO directly from EntraID or
I'm working on a new post install script for Nudge. Delivering Nudge settings using a profile has not been as reliable as I would like it to be. I found Dan Snelson's Nudge post install script (https://github.com/dan-snelson/Nudge-Post-install/wiki) and it has been a good starting point. Its command to load the launch agent doesn't work. My understanding is that we need to use Launchctl bootstrap instead of Launchctl load as we did with older versions of macOS. I have other scripts that load launch daemons that use bootstrap/bootout. These work well. Since a launch agent loads when a user logs in, it's different. What is the proper command to load a launch agent using a script deployed by Jamf Pro? If I can get this one thing to work, it pretty much wraps up getting this done.
Hello, So I'm circling back to this as last summer I have been having the same issue I am experiencing now. Which is Mac Apps both App Store and Jamf Catalog do not work at all. I have created a test with Loading the 2024 Creative Cloud suite put my test mac into a group and made sure mac was online, connected, and open. I send off the App to automatically install but absolutely nothing happens. I tried with a couple macs I have here to test. Nothing works, I've checked our firewalls to make sure nothing in there is blocking anything, and nothing. I dont know if someone knows some way of better troubleshooting or finding out where in the process of software install it is. We need to do a mass upgrade this upcoming weeks it would be nice to use this feature instead of making bunch of profiles and scripts.
Hi there,I try to remove all "old" users from our iMacs, managed with JAMF School. The useres have an AD account and during first login on an iMac we create a local (mobil) account on the mac. At the end of the year we want to rmove all these users and there data.If I run a "sudo /usr/sbin/sysadminctl -deleteUser $user" on the client, the user is totally removed (after I once gave the terminal full access to the drive in system preferences). But if I run a JAMF Script with the same command, I got the error:### Error:-14120 File:/AppleInternal/Library/BuildRoots/91a344b1-f985-11ee-b563-fe8bc7981bff/Library/Caches/com.apple.xbs/Sources/Admin/DSRecord.m Line:563Nearly the same, if using the command "sudo dscl . delete /Users/$user": dscl DS Error: -14120 (eDSPermissionError)All users, the first local Admin and root have "Secure Token" enabled. After I disabled System Integrity Protection in rescue mode with "csrutil disable", the JAMF Script is doing the job without error, but this is no
Hello dear Community,overnight the entire login screen disappeared two managed silicon Macs, MacOS 14.5.The login screen only shows a guest account, which is not available either because the FileVault is actived.I was able to access the hard drive using Target Mode and the data and user folders are still there. Has this ever happened to anyone? What could be the causes? I would be grateful for any tips.
I have added the OneDrive app from App Store via Jamf Pro for our domain networked iMacs. Installation of OneDrive on iMac is successful, however, when trying to log in as a user I keep seeing the error: OneDrive Files On-Demand didn't start. Please restart your computer and try again. Error code: -1912600610 I have tried all the fixes via terminal commands to enable files on demand, but the error still shows on the iMac. Has anyone experienced this with new iMacs on Sonoma 14.3? Is there another way to get this working? I have unscoped and rescoped the OneDrive just to make sure but still the same. Thanks
For those that have implemented Memcached for your on-prem environments, what kind of hardware specs did you give your server? Looking at the latest release notes, I saw that Ehcache has been deprecated and Memcached is now required.
Is it possible to run a report on which devices have a passcode assigned?
Jamf 100 was just updated to version 6.0! Learn more here about the updates below! The Jamf 100 Course is the first of many offerings to increase your knowledge of Jamf products. There are four sections in this course: Section 1: Device Fundamentals Section 2: Jamf Pro Setup and Infrastructure Section 3: Jamf Pro Management Section 4: Jamf Pro Policies and Scripts Each section ends with a Section Review that includes a simulation that lets you apply what you've learned. Each lesson in this course includes: Goal: A statement or statements about the content in the lesson Video: A short demonstration of the content in the lesson Key Points: Brief descriptions of content covered within the video Review: Comprehension questions to recap the lesson content Practice: Exercises to apply the information from the lesson in a managed environment Resources: Links to lesson-related content The Jamf Pro Associate Exam is available for purchase at traini
Trying to get the latest Apple Silicon Adobe installer to work. Anyone done it very recently successfully?I used to use this:https://community.jamf.com/t5/jamf-school/adobe-creative-cloud-install/m-p/253089/highlight/true?lightbox-message-images-253102=12661i385B93C05EBFE0B5#M574But the most recently downloaded version downloads a pkg (that JAMF School won't accept. So I tried compressing the pkg per this:https://community.jamf.com/t5/jamf-pro/adobe-product-package-fails-to-install/m-p/301598And that didn't work. I also tried putting the new pkg inside a folder and using composer and the procedure from the first link and that didn't work either.Anyone have something that does?
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server [PI118519] Functionality to upload or edit an On Device Content Filter mobile device configuration profile downloaded via a Jamf Security Cloud or Jamf Safe Internet tenant now works as expected. [PI118598] In Jamf Self Service for macOS, the continuous loading spinner now disappears as expected after the page refreshes. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 11.6.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf C
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!