Get Support
Recently active
Is there a script to set up the home page for Microsoft Edge ?
Looking for some help with a script issue please.I've written a script based on Charle Edge's https://github.com/jamf/MakeMeAnAdmin to use in a Cyber Essentials Mac build. Whilst the original script temporarily elevated the users privileges I want to create a temporary separate admin account.Everything works well apart from the final stage (lines 50-65, labelled "# Write a script for the launch daemon to run to delete the temporary admin account if it exists, delete the launch daemon then provide feedback to user.") to cleanup the admin account. This part of the script does work when run manually so I'm thinking it's an issue with permissions and/or ownership.Any advice would be appreciated. Thanks#!/bin/bash ############################################### # "I need admin". # John Moore, April 2024. # Based on "MakeMeAnAdmin.sh" by Charles Edge, see https://github.com/jamf/MakeMeAnAdmin. # This Jamf Self Service script will provide the user with access to a separate admin ac
Hello!I have successfully packaged, deployed, and tested the GMetrix plugins for Adobe CC 2021. This works for both Intel and Apple Silicon Macs.Using Composer:Download the GMetrixSMSe.app from their website Open composer and create/start capturing a new package deploymentPlace the App in /ApplicationsOpened the App and LoginOpen the settings pane and click on the Plugins PaneGo through every Adobe App installation procedureCreate the package source in ComposerOnce Composer is finished, here are the Directories needed:/Applications/GMetrixSMSe.app/Library/Application\\ Support/GMetrix/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.aftereffects/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.animate/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.dreamweaver/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.illustrator/Library/Application\\ Support/Adobe/CEP/extensions/gmetrix.lita.adobe.indesign
hey guys… having trouble scoping a self service policy to a specific Azure directory group. I deployed the policy to all comptuers and all users, but limited the scope to our our Operations team group in Azure. This obviously requires user to login to self service to see the policy, but logging into self service fails when using directory creds. Directory user lookups are successful in the Cloud Identity Provider settings so I know Jamf can see the users, and we have self service set to allow users to login using directory creds. Anyone got any thoughts as to what I”m doing wrong
I'm trying to put together a CIS lvl 1 plist for firefox deployed via JAMF pro and unsure which compliance options are related to which keys in the plist, or where to start beyond adjusting the standard plist, does anyone have any resources to aid with this? or a baseline plist to share?
Hi,for some time now the Management Commands on my Jamf Pro instance have not been working. They are staying on the "Pending" status. This also affects the installation of Mac Apps (the ones with the VPP licenses). As far as I can tell all of my devices are affected? Is there anything I can do about this?Kind regards
I would like to setup PowerBI dashboards for Jamf.However I cannot find a good up-to-date guide that steps through all the steps. Jamf's YT video https://youtu.be/PBsP84G-vtg?si=G4zj7mc2gZpH15Ml is great, but the narrator just says to use an account that has get rights to computers, etc. but does not explain how you would set that up. I find many YT tech tutorial videos are like that - missing important info that the narrator just assumes everyone knows.I have an AD/LDAP service account added to Jamf and have given it read permissions to everything. But when I try to use that account to connect to Jamf in PowerBI it fails to authenticate and so does my regular account. I'm not clear on what URL to use for our on-prem Jamf environment. Is it https://yourcompany.domain or https://yourcompany.domain/api?Jamf's GitHub page is 4 years old! https://github.com/jamf/powerbi/ - can't this be updated? It still talks about the custom connector which I understand you
Hi, I don't like the new HUD on Jamf School.Is there any way to have the legacy version?Thanks.
The state of Indiana has decided for government organizations that they are going to provide grants for/subsidize the cost for Crowdstrike statewide if orgs opt in to the program. We did and are successfully hoping to get a changeover made to Crowdstrike. We've tested Crowdstrike and it seems to work fairly well. The only problem will lie in removing Carbon Black. Our subscription to it ends at the end of June. We have generated a mass deregistration code. I'm assuming when our subscription lapses that we will lose console access. Would I be wise to somehow export a list of individual uninstall codes? Probably yes, but I am unfamiliar with how to go about doing that. What I don't want to see is that some situation where the client is uninformed of the company-wide de-registration code and will only take the individual uninstall code. I'm not sure whether we will lose console access either. Is anyone familiar with this process?
Good afternoon JAMFNation, I am working on deploying iPads that act as a thin client. Single App mode with Microsoft Remote Desktop. I have read into Managed App Configurations but have found nothing of use. Do you guys know of, if possible, how to preset RDP sessions in the Microsoft Remote Desktop app? I would like to have everything preconfigured. The site receives the iPad, opens it up, with DEP and MDM it configures itself, locks down and enters single app mode with RDP. And listed are the Remote Desktop sessions that will be used + when clicked on it will ask for Username and password (lock down adding/saving users) Is this possible? !
Good morning!Relatively new and inexperienced MAC admin, so please be gentle and feel free to talk to me like you're talking to a 5th grader!In troubleshooting MDM communication with a large number of our Macs, the support tech I was working with suggested adding some EA's to assist in seeing what was going on. It definitely helped to identify and point us to a resolution, but one of them doesn't appear to be working the way I think it should? Note, that my background is mostly Windows enterprise, not any Bash, so I'm not sure exactly how to troubleshoot and resolve to get this particular EA to display what I want.Here's what was provided: #!/bin/bash theIDs=$(security find-identity -v | awk '{print $3}' | tr -d '"' | grep -E '^[A-Za-z0-9]{8}-[A-Za-z0-9]{4}-[A-Za-z0-9]{4}-[A-Za-z0-9]{4}-[A-Za-z0-9]{12}$') echo "$theIDs" if [ -z "$theIDs" ]; thenecho <result>"ERROR - No keychain identities matching a UUID found on this system.</result>"exit 1elseecho "At
I'm starting to see issues where a computer with a standard user is logged in, and when an authorization window pops up, like when you're changing system settings or authorizing an install, the computer will not accept the admin username and password. If I log into the same computer as the admin, it accepts the password without issue. I created a second admin account, and it is having the same issue when a standard user is logged in. I've checked to make sure the admin accounts have a securetoken granted, and they do.Has anyone else ran into this problem and found a fix?
I've already put in a ticket with Apple and perused the macadmins Slack, but I thought someone here might have had the same issue or know of a fix...We have a fleet of about 3800 machines. Most are Catalina, but we have about 800 running Big Sur and we're currently testing out Monterey (about 10 machines there). We're seeing a lot of problems with both SSH and Screen Sharing (also through ARD) where, if the machine is running Big Sur or Monterey and it sits for a day or two (like over a weekend) without being used remotely, it is no longer accessible via SSH or VNC/Screen Sharing/ARD. Rebooting the machine fixes this, but it's hard to do that since 1) the machine is onsite and the user is typically trying to get in from offsite and 2) SSH doesn't work. Currently we have a policy in Jamf that will reboot the machine for us and that normally fixes it, but now *users* are experiencing it and putting in tickets. This problem only occurs on the Monterey and Big Sur machines - Catalina never
I saw 2 accounts listed under Managed Local Administrator Accounts, 1 labeled as "jamf binary" and the other being "PreStage". I looked for where the 1st account was defined and I found it under User Initiated Enrollment > Computers > Managed Local Administrator Account > Create Managed Local Administrator Account I have a feeling that this was defined when we were going through the initial training with Jamf and something we don't really need because we don't allow user initiated enrollments and all our devices are enrolled from Apple School Manager. I'm not sure why Jamf would create this account on devices that have undergone ADE (I've confirmed its presence in our ADE devices with a dscl read). Would there be any issues with me removing that account?
Hello everyone,When I try to connect my iPad to a Mac or Windows with iTunes, I receive the following error message: "This iPad is supervised by another computer and cannot be used with this computer." If anyone has a solution, please suggest it.
Hi, I am attempting to deploy a Font payload and it never installs on the iPad. I upload the .ttf files on the Font page under general payload, this uploads the four files successfully. At this point I have created a Fonts profile and test it by manually installing the profile on a iPad. The task tells me it deployed successfully and the activity log gives me a green tick for that Font profile. But I do not see the Font profile installed on the device under the Mobile Device Management profile and I am unable to choose the fonts in Pages. Now, I have had success installing the Fonts manually using the iFont app, as it creates local profiles for each Font and I am then able to see the Fonts in Pages. But from my understanding I should not need to use the iFont app as I am using the Font payload in Jamf to deliver the Fonts directly. Why is the payload not working?
Hi All!So I've done my research on this already around JAMF Nation and everyone seems to be able to disable wifi completely wether its through managed prefs or a config profile. I have a script running that turns off wifi if hard lined and in turn if not hard lined allow wifi. This is for a lab setting so they really don't need wifi. What I want to do is to hide the icon in the menu bar through JAMF. There is a check box in network prefs "Show wifi status in menu bar" that if unchecked hides it. I tried doing a snapshot with composer but that didn't work out. Also theres a few other prefs I was hoping to add as well. In advanced wifi prefs I want to have checked "Require admin authorization to: create computer to computer networks, change networks, turn wifi on or off." That way even if they become disconnected from from ethernet they would still need an administrator to turn on wifi. Any help or direction with this would be greatly appreciated!
Anybody facing this?I am trying to upload a new IDP certificate to Jamf Pro for my Google IDP. However at the IDP settings page, it keeps failing to connect to cloud service provider. This blocks me from saving new IDP configurations on my Jamf Pro. Testing of the existing configurations works fine but the setting keeps failing to connect.
Hello, I attempted to enroll my M1 computer in my Jamf server using User-Initiated Enrollment. While the MDM profile installed successfully on the computer, it appears as unmanaged, and the Jamf binary is not installed either. Interestingly, it enrolled successfully on another server. As I'm running out of ideas on how to resolve this issue, I thought I'd reach out here to see if anyone encounter the same issue.
Okta has updated their server side rule for "automatically send push" to be a per-user setting stored in the Okta directory instead of a device based cookie stored on the individual computer.The "unexpected push" happens any time the Jamf Connect menu bar app does a background password check of the user's credentials AND the device is configured to use OktaIdentityEngine as the Provider AND the app defined by OIDCClientID has an Okta Authentication Policy that requires multiple factors for authentication. What Jamf Connect is doing - Interpret a response from Okta that MFA is required to obtain a token as a valid password. Ignore the fact that we didn't get an access token because we don't need one. What OKTA is doing - Getting a request to log in on an app that requires MFA, looks at the user's value for "Send push automatically" stored now on the server, sends the user a push notification. Example graphic below - (Also, this is the only known locat
We're running in to an issue with our SSO policy. Our Mac's are enrolled using the users Azure logon. We currently don't have kerberos in place, so are config profile is set to SSO. The tech who configured this created a policy that runs the below command at every network change per the apple documentation. The issue we're experiencing is that when there is a network change it kicks off sometimes it gets stuck the majority of policies don't run like our software updates. If you go in to policy audit of a device, it's just the sso policy. We just have the user restart and run recon and it's fixed and it doesn't happen to all users. Curious is anybody else has ran in to this. We do have a test group that is removed from the policy to see how it goes and just made if available to them if it doesn't connect correctly. #!/bin/bash killall AppSSOAgent Sleep 5 app-sso -a "oursite" -R -q exit 0
Greetings,question: Is there a way to capture the LAPS password stored in JAMF prior to purging a computer from Jamf? We have a strict 60 day purge policy in place; if the device has not contacted Jamf in 60 days or more, we are required to purge (delete) the devices from Jamf. However, we are on the cusp of deploying LAPS and a question that has come up is if a LAPS managed computer is purged, and a tech happens to find it sitting in a corner (something that happens with depressing frequency), is there a way to determine what the LAPS password was at the time it was purged from Jamf.I know there are alternatives to deleting devices that have not been in contact, but there are some politics around that in my organization, so I'm wondering if there is a technical solution.
Hi everyone,I have a question. I have a batch of experimental Macs that need to be managed and registered with Jamf.Question 1: These experimental Macs cannot connect to the internet. Is there a way to deploy policies through Jamf?Question 2: If internet access is needed for proper deployment, I know Jamf has port information. I would like to ask experienced experts which specific ports need to be opened.All Macs with normal internet access can receive policies correctly. I want to know how to ensure that the network-isolated Macs can also receive policies from Jamf. Thank you, everyone.
Looking to change from Facetime to Teams via script or config. Is this possible in Jamf or script?
I have a computer that is not reporting the correct macOS version in Jamf. The computer is checking in, and also performing inventory updates. About This Mac shows macOS 14.5, but Jamf shows macOS 12.7.2. We used the Terminal command to force an inventory update, and also removed the MDM profile and re-enrolled. All those previous commands show up in Management History, but macOS is still incorrect in Jamf. Are there any other troubleshooting steps I can perform?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!