Get Support
Recently active
Hello everyone,Is there any way to solve the installation of Office 365 without creating a package and policy with all the apps? Maybe with a script in some way through Self Service?
I have a number of users that are using Loom, but don't have administrative access on their computers anymore. How is everyone dealing with updates like this? I see that it can be managed by Patch Management, but how do I push out the updates when they are sent as a .dmg?
Dear Team,I know that with Jamf Protect can do App Control to block all the know apps with attribute like hash file/team id/sign id....Can Jamf Protect support to control the all black list apps not only App Store but also the third-part apps.Example my Org has many departments. Each departments will have the whitelist apps. Therefore, it is not in the whistlist the apps should not launch. The thing here is due to user's role need administrator permission, it is hard to control except check inventory manually. Mass thank
I am working with a Jamf environment that currently does not have any Jamf LAPS capable admin accounts. They did not create a “Management Account” in User-initiated enrollment. They did not create a “local administrator account” int PreStage Enrollment. We have since specified a “Management Account” and a “local administrator account”. With two separate names. They are using Apple Business Manager Automated Device Enrollment. There are some locations that do not have ABM, so they are using User-initiated enrollment. (That is begin resolved). LAPS is working with newly enrolled Mac systems using either admin accounts. Is there away to retroactively add a User-initiated enrollment “Management Account”? I’ve tried using “jamf policy -trigger enrollmentComplete”. This will successfully re-run the enrollment policies, but it does not create the “Management Account” from User-initiated enrollment. “profiles -N” does work. But that requires user interaction. Thought
We have a Mac that will be used in a production environment (Live TV). I would like to keep it in JAMF but essentially just for record keeping, loss prevention and for our security software. A broadcast engineer will be responsible to keep it running. We tend to have a bunch of updates triggered by smart groups, basically if it has this software then do the update or action.Without excluding this computer from every single smart groups one-by-one, is there a way to single out a computer so any action to the computer is explicitly and only when it's named? Perhaps just a way to exclude it from all smart groups/groups.
Hello everybody,I don't know if this is possible, but I have a question regarding the interaction between JAMF Connect and a Synology connected to AD DS.On my MAC fleet, JAMF Connect is perfectly deployed, and allows me to open a session as user@mydomain.comOn my local network, I have a Synology NAS which is joined to Entra (Azure) Domain Services, and therefore which allows authentication as Domain\\User and therefore the use of the Entra account as for JAMF Connect.I would like to know if it was possible to allow an automatic connection of my SMB share, using the Kerberos ticket, or other, generated at the JAMF Connect connection.If so, how can I go about it?Thanks!
HI all,The latest patch definition for the new Teams has not been updated for nearly a week now.The new Zoom 6.0.1 definition appeared within a day so just wondering is this normal for Teams?There should be en entry for version 24074.2607.2799.9843 which was released on 12th April.
I'm working as MacOS support engineer. We planed to initiate automation the app update using package in Jamf Pro.Here what I want exactly means Create Package (example Chrome) with the configuration of force install and update to upcoming latest version. Anyone pls help me to find out better solution.
Hi all, Just wondering if anybody has had any luck connecting to Okta as an LDAP source. It's enabled on our Okta instance and others apps can connect to it, however when I try and configure the JSS it gives me a connection error every time no matter what config I've tried.
Few devices are not able to get the latest released MacOS update when connected with internal corporate network. Can anybody tell us which all things need to be whitelisted in order to get the devices updated with Apple update server directly. Thanks!
I am trying to automate the creation of an Outlook signature and I have most of the parts down except I can't find a way to pass values from User and Location to the script. I thought passing $FULLNAME or $POSITION as script parameters would work but all it does is literally pass the string "$FULLNAME" to the script.
Hello!I need a hand writing an Extension Attribute script to gather "Reason for privilege elevation".The below command works in Terminal directly on a Mac running macOS 14 to gather the info but I don't know how to then parse it into a script for an Extension Attribute. The text in bold is what I want to gather. An endless running list of reasons would be ideal. Any help would be much appreciated 😊sudo log show --style compact --predicate 'subsystem == "com.jamf.connect"' --debug --info | grep "Reason for privilege elevation:"Result:2024-04-04 10:09:22.221 Df Jamf Connect[55703:31aeb0] [com.jamf.connect:PrivilegeElevation] Reason for privilege elevation: Admin elevation test 12024-04-04 10:18:37.006 Df Jamf Connect[55703:31aeb0] [com.jamf.connect:PrivilegeElevation] Reason for privilege elevation: Figma install
Having concluded that FileVault isn't going to be a good idea in our domain-joined, student lab environment, I have made a configuration profile to disable it. This configuration profile is applied during the pre-stage enrollment – i.e. as early as it possibly can be. I have verified that it is indeed applying within seconds of the computer getting past the voiceover setup prompts. And yet, the first user who logs in, gets a big prompt for enabling FileVault, *with enabling it checked by default*, i.e. enabling it!If I manually uncheck the box and click Continue, and then go look in System Settings, FileVault says that it is disabled by policy and does not allow the user to change it! So the configuration profile is clearly applying, but it seems not to prevent the first user being prompted anyway.Any idea how I can stop the first user getting this prompt?(The funny thing is, before I created the configuration profile to disable FileVault, the first user was NOT prompted in this way. I
Hi All, I am looking for some advice with firewall rules for Jamf Remote Assist. The Jamf documentation is a little sparce. We are currently packet capturing the connection, but wondered if anyone has already figured out what IPs/hostnames are needed to be added to a firewall. I have found the ports from a web search. Enabling Jamf Remote Assist - Jamf Pro Documentation 11.5.0 | JamfAny help would be appreciated. CheersGT
Hello Jamf friends!I am new to the IT world, any assistance would be greatly appreciated. We have new Macbooks that we would like for users to sign in by using their Office 365 work domain credentials. We have Jamf Pro. What is the best way to do so in Jamf Pro? Any articles or videos would be great. Thank you,
Anyone sussed out a way to remotely manage the startup security utility settings on Apple Silicon Macs? We use a lot of music production software that requires the "Reduced Security" option to be enabled and I haven't seen a way to deploy these settings either in PreStage or as part of enrollment. Is manually changing these on each device the only option here? Currently all devices on Ventura but moving to Sonoma over the summer. Appreciate any help.
I am trying to enrol my Mac mapped to your prestage in ABM.I am able to click Enrol on the Remote Management screen and can authenticate successfully on okta app.As soon as the authentication is successful the login page remains as it is and the password box goes blank.Nothing happens after this so am not able to enrol my device and there is no error on screen.Other users and test device was enrolled successfully at same time its just my own Mac is not enrolling.I wonder if this has to do anything with the Okta LDAP group membership.The testing for my account is successful when checked in jamf LDAP.We are using jamf connect for enrolment.
I've got an application installed on a number of mac devices, I'm looking to have this run when a user logs. How can I achieve this?- The application is pushed through a Jamf policy.- The devices are shared and logged in by many people.- The application was composed and packaged in house.
This may be a newbie question but I have looked everywhere: Initially I was trying to get Jamf Tools: after some googling, it says I will need jamf nation account and go to My Assets.I create a jamf account for myself but ofcourse, no subscription hence no tools.My workplace uses Jamf Pro. I thought I can connect the two together and download the tools I will need. How do I connect the two together so I can use their subscription and download the jamf tools? If you say, "you dont connect your personal jamf nation account to their company's Jamf Pro":1. Do you create a new jamf nation account for each company you work with?2. My initial thought was I would use my jamf nation account -connect it to work email-work company and get the subscription and once I move to a new company, I would "un-link" and connect to theirs instead of creating bunch everywhere. Another reason I thought of using my jamf nation account is to have my certification in all in one place. It woul
Hello Jamf Nation! We have two important notifications for Jamf Protect users who may be affected by future deprecations and changes. Support for macOS 11 will be removed in a future Jamf Protect release. Jamf recommends updating to macOS 12.x or later to ensure continued support. The existing telemetry feature is expected to be incompatible with the next major macOS version. Jamf Protect is developing a new version of telemetry that is compatible with current and future versions of macOS. The improved version of telemetry provides more detailed configuration options, better refinement and visibility of telemetry data, and improved resource utilization.The existing telemetry feature will continue to be available to allow customers time to migrate to the new version. Prior to releasing the new telemetry feature, Jamf will provide more detailed documentation of telemetry events and data via a telemetry data model, as well as migration information. Existing SIEM applications and integra
Hi everyone,I'm encountering an issue when running a shell script via JAMF. The script only works if it is written as a one-liner. When I try to run the same script in its normal, multi-line format, JAMF throws errors. Interestingly, if I save the script as a file and execute it, it works perfectly. Additionally, JAMF seems to dislike empty lines in the script and throws errors related to them.Here is a snippet from my Script which fails: to_json_array(){ local list=("$1") local array="[" while IFS= read -r item; do item=$(printf "%s" "$item" | sed 's/"/\\\\"/g') array+="\\"$item\\", " done <<< "$list" array="${array%, }]" echo "$array" } And that's the error to this: 1:233: execution error: /Library/Application Support/ZuluDesk Scripting/com.zuludesk.scripting.60a1e7ef-234b-11ef-8da8-024f99ac106f/com.zuludesk.scripting.60a1e7ef-234b-11ef-8da8-024f99ac106f.command: line 25: syntax error near unexpected token `{ ' /Library
We recently implemented Okta Verify for our desktop MFA logins. Which works good most of the time but does require an active network connection most of the time to function correctly. Our office WiFI is radius authenticated, so it won't connect at the Mac login window. We do have ethernet at desks, but the network USB-C network adapters don't always connect at the login window either. Once a user is logged in the adapter gets authorized and will connect. So if there is no network connection, Okta verify wants you to use a off-line device access code to log into the machine, and if a use hasn't restarted or logged out in more than five days that factor is disabled, thus requiring an admin to login get the network adapter activated and then log out and let the user log in again and get a push verification factor, and then they are in. Here is the question.... How do I allow network adapters to activate at the login window, always? I understand that not allowing without a user login
Hi Jamf friends, Newbie here- to Jamf and Macbook! Does anyone have Power BI downloaded on their Macbook? If so, what steps did you take to have it operating successfully? Did you have to enforce any configurations in Jamf to allow this download? Thank you,
Hello Everyone, We have have seen in Jamf Connect menubar password expiration countdown is not showing, we using the Azure Hybrid. Added the Kerberos tickets and password expiration, countdown settings was added but still seeing the same issue.Can anyone help me with solution ASAP and getting the below error. Kerberos authentication failed with error: KerbError
Hi,I'm trying to create a configuration profile for distributing fonts, but no matter what file I try to upload (I've confirmed the fonts work fine on a local Mac), I get the following error:"File format not supported." Has anyone run in to this and know what needs doing to make it work? I've searched the forum but I've been unable to find anything on this particular issue.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!