Get Support
Recently active
Has anyone else run into issues where macOS users no longer receive Notification Center notifications from Jamf patch management events? For a long time this worked fine. I'd update an app via JPS patch management, and the user would get a Notification Center notice when each new update was available and the SS dock icon would show the number of ready updates in the red badge. But here lately neither of those happen. No Notification Center notices when a new update is ready and red badge only shows on the SS dock icon when the SS app is running. Details. . .Jamf Pro 10.8.0Push Certs are currentSelf Service settings for macOS has "Enable Self Service Notifications" checked.I worked a ticket with Jamf support but they kind of threw up their hands and said "yep, seeing some inconsistencies with this" and assigned it a PI number (PI-005955).Anything else I should be looking at? I mean I feel like this is pretty important since how else will my users know when they
I would like to know what kind of ACP level JAMF Pro has. ACP Level in here is related to Cybersecurity.
Hello, I've been using the Splunk intergration for some time now but the last week or so it is now complaining that it cant verify the SSL when attempting to connect to our Jamf Instance. Nothing has changed in terms of configuration. Looking at various documentation and things in github, it says there was a feature added some time ago to allow connections to instances with invalid certificates. To be sure, the certificate is valid but I cant get our Splunk to connect to it. Has any one had this sort of issue? Is there a way to tell the jamf add on not to verify SSL? The specific error that i get is[SSL: CERTIFICATE_VERIFY_FAILED]
Hi guys! Have you recently experienced an issue where Jamf Connect is automatically initiating Okta Push Notifications?
Hi AllI use App installers in Jamf Pro to install and update apps. I have end user experience enabled to notify users on new updates and when an app will auto quit to apply the patches .I need to use IBM notifier for this and I need help in setting this up .Thanks
Today we are releasing a maintenance version of Jamf Connect. Jamf Connect 2.36.1 addresses the following product issues: [CON-5250] Offline MFA reminders no longer send when OfflineMFAReminder is disabled. [CON-5251] PrivilegeElevation logs now appear in the correct category. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Thank you!The Jamf Connect team
Optimized to leverage SYM-Helper (1.2.0), Setup Your Mac (1.15.0) leverages new features of swiftDialog (2.5.0)IntroductionApple’s Automated Device Enrollment helps streamline Mobile Device Management (MDM) enrollment and device Supervision during activation, enabling IT to manage enterprise devices with “zero touch.”Setup Your Mac is a script which aims to simplify initial device configuration by leveraging swiftDialog and Jamf Pro Policy Custom Events to allow end-users to self-complete Mac setup post-enrollment.SYM-Helper is a stand-alone macOS app to help Jamf Pro admins more easily deploy Setup Your Mac.Continue reading …
Hello, I took and passed the Jamf Certified Associate exam yesterday (2/22/20). I see that the badge has been posted to my profile. Will I receive a copy of the certificate as well? Also is there a place to download a receipt to prove I paid for the exam? I didn't receive any email confirmation when I purchased and completed the exam. I am wanting to pass this information onto my employer (I used my own personal Jamf Nation account and not my employer's, if that matters at all) Thanks!
Hello,I would like to have your opinions on a subject concerning FileVault computers that need to be sent to an external customer after-sales support.What is the best procedure knowing that our managers want the devices to be sent to the external support service encrypted.These Macs only have one FV user account and SecureToken, that of the end-user whose password we don't know.The only local admin account created during the prestage is managed by LAPS.What would you advise me?Thank you
I mean, there is definitely not a technical limitation, but an artificial one. One can still make another smart group that includes the "latest version" smart group within it, and be able to scope actions based on it.
In the last couple months new devices, and devices that have been wiped and re-enrolled, are showing up with Apple IDs. It's only happening on devices with Ventura and Sonoma.Did something change? We disabled all the iCloud/AppleID sign in options under preferences with a config profile. iMessages, Apple Music, Apple TV, are disabled as well.My only guess is there as an app, or feature, we haven't found that is allowing Apple IDs.Any ideas?
Hi, I am trying to deploy Office 2021 (VolumeLicense) and with that I want do disable the ability for users to login to office and use their private Office 365 licenses.On this site (https://learn.microsoft.com/de-de/microsoft-365/enterprise/network-requests-in-office-2016-for-mac?view=o365-worldwide) I found three preferences witch to my understanding should just do that: defaults write com.microsoft.Word UseOnlineContent -integer 0 defaults write com.microsoft.Excel UseOnlineContent -integer 0 defaults write com.microsoft.Powerpoint UseOnlineContent -integer 0 But they don't seem to work (not when deployed through Jamf or run locally).Has anyone been handling this?
I wanted to see if anyone else has or is experiencing this, we have a jamf cloud hosted instance. So far jamf support has been unable to determine the cause of the issue. When signing into Self Service, which uses Okta for us, instead of going into Self Service and seeing your available applications to you, it opens a webkit window of our jamf pro dashboard inside the Self Service app, if you don't have login rights to our console then the user gets access denied. This is a screen grab from our dev enviroment, where the issue started happening first and then "magically" started occurring on our production instance which is on a slightly older version of jamf. Of our identity team that manages Okta says they have made no changes. I have tried turning SSO on and off for the instance, turning off SSO for Self Service and turning that back on, but it's still the same experience. Both instances were working perfectly fine up until about week ago. &nb
Hi all!We are currently testing our implementation of Jamf Pro Cloud. I am trying to set Chrome as the default browser for my organization, but I cannot find the option to do that through Jamf. And anything online about this is over a few years old. I just wanted to check in and see if there has been a change to this, or if anyone has a clever way of getting around it!Thanks!
Hello, after updating to Jamf Connect 2.36.0 this morning, my users are getting super annoying pop-up to setup local login 2FA on their computers, I suspect that this is caused by the new feature introduced in 2.36.0 called "Offline MFA Reminder (OfflineMFAReminder) but this key is not yet available in "Jamf Connect Configuration".Is there any way to rollback affected users to 2.35.0 or is the key (OfflineMFAReminder) might work if I add it in the Jamf Connect configuration profile?Big mess from Jamf here...
I am trying to come up with an easy solution for locking down iPads to single mode to just display a website. I wrote a simple browser that does this, but Jamf installs the app and it won't run. Will I need an Enterprise certificate or is there a work around?
Hey guys, our users have no admin rights on their Macs. Is it possible to allow them to use the Erase option in settings app (General => transfer and reset => erase all content and settings? It seems like the erase app actively needs admin rights, and these things seems like cannot be handled using privilege management systems like BeyondTrust. We tried to run the commands stated here from self service, but also there same message as stated above. Any hints / proposals? If not, I guess the only way for users is holding down their power button and reinstall from there, right? However we would prefer the way from settings app since it's more convenient. Thank you so much for your thoughts on that. bestFlory
Restored about 40 Macs last week via our cloud-hosted Jamf. When it is finished, you must activate the Mac before you can set up a new account, to verify with Apple. All machines could not complete it due to void certificate. It was something I had never experienced before. But it should still work out, right? Anyone know, experienced the same thing? The computers are not even a year old and more computers are to be restored this week.I've checked all our certificates and they're up-to-date, so it hasn't anything todo with that. The error comes in recovery mode after selected Wi-Fi when it tries to activate.
I've just recently started enrolling iPads via DEP into our newly setup and configured JSS. I've enabled a few restrictions in one of the configuration profiles I've deployed but I don't see any that restrict signing into iTunes & App Store. I'd like my users to be able to sign into their iPads with their Apple School Manager Apple IDs so they can install free apps via the App Store but both the "Sign In" and "Create New Applie ID" buttons are greyed out under the iTunes & Appe Store setting. How/can this be done?
Is their a way to send notifications to users with iPads to register their devices with Entra ID just like Macs with some kind of pop up window alerting the user that it needs to be completed. I know that their are no policies for mobile devices so was tying to see if there is anything else I could possibly leverage besides sending a mass communication out.
Afternoon All Is anyone using Jamf connect to enable filevault we are in the final stages of rolling out Jamf connect campus wide. It seems to be working find for new builds however we are seeing different behaviour for exisiting devices. Some devices are enabling filevault fine some arent even after an inventory update. All devices have same 3 config profiles for Jamf connectJamf Connect LicenseJamf Connect Menu BarJamf Connect Login 1-2-1 V.1 (Has updated key to EnableFDE set to true)and Escrow recovery key config profile to bring the key back to Jamf ( there are some filevault settings managed here as well)It mainly Intel 27" Imacs from 2020 which dont seem to be encrypted seeing the same issues on M1 as well. However other Intel and M1 Imacs have encrypted in the pilot group. I cant find any information for Jamf connect for weather it tries again at somepoint. Im also not sure if my escrow profile is causing some sort of clash as we have that set to enable
Got Regex?
Today we released Jamf Connect 2.36.0. This release includes the following changes and improvements: Zero Touch App Activation with Jamf Connect and Jamf TrustJamf Connect is now able to generate a unique token that can activate Jamf Trust for macOS, which creates a “zero touch” experience where users no longer have to manually sign in to their Jamf Trust app. This allows for the activation of Jamf Connect's Zero Trust Network Access capabilities without requiring users to manually interact with Jamf Trust. For more information, see Zero Touch App Activation with Jamf Connect and Jamf Trust. The User Promotion Biometrics (UserPromotionBiometrics) setting allows administrators to require Touch ID as a form of authentication prior to a temporary elevation session. This setting will be available in Jamf Connect Configuration with a future release. The User Promotion Role (UserPromotionRole) setting now supports the following additional identity providers: Okta-OIDC, OneLogin, PingFedera
So I am working on getting all of our Mac devices registered with Entra ID. I have set up the notification to let the users know that they need to register and then it directs them to self service to do so. This is great , however my issue is with the triggers, I'm looking for a way that if the Mac such as mine currently is registered with Entra ID, how can I no longer have my device receive the pop up notification. I only want the pop up to trigger if the device is not registered, so this will help with current Macs as well as new macs when they come into our environment. I've looked every where for solutions and could not find any hoping someone here has found a way to get this done.
Today we are releasing Jamf Pro 11.6. Highlights include: Compatibility with watchOSManagement capabilities are available in Jamf Pro for Apple Watch devices with watchOS 10 or later that are paired with a supervised iPhone with iOS 17 or later. The enrollment process begins with the end user's iPhone using Apple's declarative device management. Note: This feature is only available for Jamf Cloud-hosted environments. Support for FIDO2 AuthenticationSelf Service for macOS supports the FIDO2 authentication method for single sign-on. FIDO2 is a type of Universal 2nd Factor (U2F) authentication where credentials can be accessed on a device instead of a server. It enables passwordless authentication, including passkeys, local biometric access, and hardware keys. Note: FIDO2 must be configured via your identity provider (IdP). For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. See the latest release notes video for a
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!