Get Support
Recently active
I've noticed that periodically some devices in our Jamf Pro cloud instance lose their User & Location information.We're then having to go through and manually update this by pasting their local user account name into the User & Location search, which validates them against Entra ID and updates it correctly. I've not been able to determine why this information is being wiped out for some, not all, devices.1) How can we stop this information being removed?2) We have Cloud Identity provider configured with Entra, and Jamf Pro can look up the data when we manually specify it. User attribute mapping is setup. How can I automate this process? In the majority of cases, our users local account name is in their Entra ID account name format. I can pull the logged in user via a script, but passing this via jamf recon -endUsername <value> just populates the username, it does not do the entra ID mapping. Many thanks for any suggestions!
I'm trying to trigger a policy (that launches a Swift Dialog window) when a user logs in for the first time. Setting the policy trigger to 'Login' seems to work when using a local account. However, if I login using an Entra ID using Jamf Connect, the policy doesn't trigger.The purpose is for setup of new Macs given to end users.Anybody have an elegant method getting a policy to trigger on login whilst using Jamf Connect? (Recurring check-in would take a bit to long for what I'm trying to achieve)
Hi Jamf support,Our current license is 78 users, and then please help to provide your quotation about add number of users, for example, please quote us the additional 22 users with your cost by email, and we can start the confirmation by reply, thank you for your attention. Best Regards,Samuel (support team)
I have team of developers that need to use Sudo and developer tools on the mac means they have been given admin right to laptops, Anyone have any recommendations on how i can give them the rights they need without giving them full blown admin rights to laptop?
We have a school that have a set of shared iPads which they occasionally erase. Since 17.5 the setup half completes but they then lose connection to the MDM (Jamf School) and nothing gets installed. When using a hotspot it completes fine. They've not done anything to their school network so are wondering what has changed between 17.4.1 and 17.5 that would interfere with the setup on the school network.Anu suggestions?ThanksAndrew
Has anyone managed to get this working? We have tried to set this up without any success. We have added the required certificate to our Config Profile and I can see it on the machines in Keychain Access but our Network team say the devices are presenting the JSS Built in Certificate to the server instead of the certificate we have added in the Config Profile?The certificate is trusted and we have the correct common name, but it doesn't appear to be being sent out from the mac.Any suggestions appreciated.
jamf recon command when run in verbose mode shows that it works upto JSS is available and doesnot update inventory. When check the JAMF client logs, there is a couple of error messages. JSS connectivity state change - state: notActive, user: nil Error triggering policy id: 386 error: Error Domain=NSCocoaErrorDomain Code=4099 "The connection to service named com.jamf.management.daemon.selfservice was invalidated." USerInfo={NSDebugDescription=The connection to service named com.jamf.management.daemon.selfservice was invalidated.}
Does anyone know how I can use a RegEx in a smartgroup for devices less than 12.0.1
Now that v11.1 is released comments are for the production release. 1) Performance still seems quite laggy. Almost unusable.Setup - Control computer and target computer on the same LAN. Both on my desk. macOS firewall disabled on both. WAN is 600/40 business cable.Actions (clicks, opening windows, etc) performed by the control computer appear instantly on the target computer - but take roughly 1.5 seconds to register on-screen on the control computer. By comparison, under the same setup/conditions, Splashtop SOS has a lag of roughly 0.5 seconds (or less).Looks like there's still a far amount of performance tuning to be done. 2) During a control session. . .When the control computer moves the mouse, the cursor moves on the target computer.When the user at the target computer moves the mouse, the cursor DOES NOT move in the control computer's session window. Items highlight when clicked by the user at the target computer - but no cursor movement. This creates two prob
We are currently in the process of preparing a migration from traditional AD binding to Jamf Connect with EntraID. Most users login's are working fine, however when a user with a local password that is different than their Entra password attempts to log in, they are hit with a screen that says "Verify Password, Invalid Password". I was under the impression that if configured correctly, it would instead prompt the user to enter their old password to sync the two. When the user enters their old local password, it does not sync it to the new one and just continues to prompt them for their old local password whenever they log in. Currently, our Jamf Connect login window profile is set to passthrough auth and disallow a separate local and entra password and I can't seem to find any other options that would be missing. Any thoughts?
I am on JAMF Pro 11.5.1 and I am having a strange issue on a number of macs where Self Service is crashing immediately but only for Mobile accounts. Local Accounts can open Self Service without any problems. Has anyone run into this before? I have tried re-installing Self Service and re-running recon and policy but its still persisting.
I need to turn off the Ad topics, Site-suggested ads, and Ad measurement from Google Chrome to 200 MacBooks, do you know if there is a way we can do this through JAMF via script?
We are relatively new to Jamf Pro. NFR/Test was set up for us to use by Jamf staff. Now that we have a few devices in our PRODUCTION instance and ABM setup along with that, I decided to stand up the Test/NFR environment. When I get to the point of creating the new MDM server in ABM, I am prompted to download a new "MDM Server Token." However, I am warned that doing that will result in my existing token being reset. I do not want to break Production. Is there a way around this? Thanks.
Wondering if anyone can share their method for creating a PKG file from the source files for the TN5250J emulator? Some of our users are using an older version that's getting flagged by our Information Security team, so it's time to upgrade them. I don't know how our last Mac admin created the package for that older version, and so far anything I've tried to build in Composer doesn't result in a working package. Haven't found any answers yet on the internets. Only related post I could find in the forums here was this one, which didn't garner any responses: Mac M1 Java and iSeries TN5250j - Jamf Nation Community - 225341.GitHub download page for the emulator is Releases · tn5250j/tn5250j (github.com).
So I wanted to push an OS update to my test Macs, which I have previously done via Inventory, pick the machines I want, Actions, Update OS version etc.It's still there, I can still choose its radio button, but a blue box appears saying "You can now use Software Updates to manage OS updates". But the Software Updates feature appears to be a beta, and I don't particularly want to use a beta. I would like to use the existing Update OS Version mass action.The blue box says that I can continue using the existing feature, but that it will be deprecated in a future version. But the "Next" button is greyed out, with no indication as to why.So, despite the wording, is it already deprecated? Or should the Next button still be available, and if it should be, has anyone got any ideas about why it isn't?Thanks,Lisa.
I am an Active Directory user and log in to my Mac using AD authentication.This allows me to check the last user to log in to the Mac from the computer usage logs in the computer's history, but is there a way to collect SSO user information when using Platform SSO?thanks
BackgroundNow that macOS Monterey is out, we wanted to allow our opt-in Beta Testers with local admin rights easy access to nuke-and-pave their Macs the "Apple" way:macOS Monterey includes Erase All Content and Settings, a way to quickly and securely erase all of your settings, data, and apps, while maintaining the operating system currently installed. If your Mac includes this feature when using macOS Monterey, use it instead of other utilities to erase your Mac.Source: HT212749Smart GroupErase AssistantAnd / Or CriteriaOperatorValue Operating System Versiongreater than or equal12.0.1 and(Architecture Typeisarm64 or Boot ROMlikeiBridge)PolicyOptionsGeneralDisplay Name: Erase AssistantExecution Frequency: OngoingFiles and ProcessesExecute Command: /usr/bin/su \\- "/usr/bin/stat -f%Su /dev/console" -c "/usr/bin/open '/System/Library/CoreServices/Erase Assistant.app'" ScopeTargetsErase AssistantSelf ServiceSelf Service Display N
Hi, We have some smart groups that set target OS on Mac products, which currently forces user above the target OS to downgrade via DFU blaster..... our target Stable OS in ventura, but unfortunately newly purchased macs with m3 processors will not go back to Ventura, so i want to exclude them from them from the smart group. Is there a processor identifier/or model identitfier i can use as advanced criteria in the smart groups to select M3 processors?
Hey guys, we're looking for an opportunity to grey out the option "Allow this user to administer this computer" in system settings. Our users are no local admins and we do not want them to enable that option. Any ideas? thank you so much, Best, Florian
Here is a script I made to remove old installations of Cisco AnyConnect that were done back before a choices.xml file was used. #!/bin/bash #This script will uninstall the full install of Cisco AnyConnect with all the modules # It will first look for the existance of the dart installer. If it is there, it will run. # then it will run the full anyconnect uninstaller. After that is completed, then we can install # the new version of Cisco Anywhere that only installs the VPN component. if [ -e "/opt/cisco/anyconnect/bin/dart_uninstall.sh" ] then /opt/cisco/anyconnect/bin/dart_uninstall.sh else echo "no DART to remove" fi /opt/cisco/anyconnect/bin/anyconnect_uninstall.sh exit 0 It works great... with the exception that in Big Sur and Mojave (I haven't tested other versions), it throws up the following dialog: Obviously the point of running things in Self Service is so end users don't have to get an admin to authenticate for them. Does anyone know how I can make this alert not
Has anyone figured out an automated way to allow non admin users to the System Preferences -> Security & Privacy -> Privacy to be able to Allow anyways to open apps. i've tried #!/bin/shsecurity authorizationdb write system.preferences allowsecurity authorizationdb write system.preferences.datetime allowsecurity authorizationdb write system.preferences.SecurityPrivacy allowsecurity authorizationdb write system.preferences.security allowexit 0 But still cant get this to work with out admin credentials.
I know that most folks are recommending user-driven provisioning where the end-user gets to enjoy the process of being involved in setting up their Macbooks. Our org is not one of those. Our users prefer to get their Macbooks and get to work immediately and not have to wait for apps to install or things to be configured while they sit and do nothing. We achieve this in Windows by pre-provisioning (Microsoft calls it white glove) where we assign common apps (Office, Chrome, VLC, etc) to the devices rather than the user and we leave user-specific apps (not all users get Adobe Creative Cloud for example) to be installed after the user logs in. This way, we can get a fleet of Windows laptops ready for use by anyone with very minimal delays experienced by the user (they can work in Outlook and Chrome while Adobe CC is being installed in the background). I plan to achieve the user side of things using DEPnotify but any suggestions how to pre-provision common apps? Is putting the comon a
I'm looking for a way to not have Keynote, Numbers, and Pages install on enrollment. Is there a way to do this? Or do I just have to remove them afterward?
Lately, every Mac that has tried to perform user-initiated enrollment in Jamf has been met with "Device Signature Error in the jamf log. To resolve, we perform these steps:1. Remove Jamf Framework2. Remove Jamf CA certificate3. Remove contents of /Library/Application Support/JAMF/Downloads/4. Run this command: sudo update_dyld_shared_cache -force5. Delete the mac from Jamf console6. Run the QuickAdd package on the mac7. Approve the Device Management Profile on the Mac8. Assign the user to the Mac in the Jamf Pro console This issue seems to have started with MacOS 10.14.5, but that may be coincidence. I have attached screenshots from an affected Mac. We have 3 macs that are broken right now, and 2 that were repaired using the procedure above. Anyone else seeing encountering this?
Hi,We're in the process of deploying Taegis XDR from SecureWorks to our Macs. Unfortunately like most XDR's it's a mess. Has anyone used Jamf to deploy Taegis.Beside the privacy settings, one of the issues we have is automating the registration process. SecureWorks provides a .mobileconfig profile for inTunes but not Jamf. I tried using it anyways but it didn't work. Are there differences in an InTune mobileconfig and a Jamf mobileconfig? I thought a mobileconfig file or plist would be the same no matter the MDM.TIA,Chuck
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!