Get Support
Recently active
Hi all!We are currently testing our implementation of Jamf Pro Cloud. I am trying to set Chrome as the default browser for my organization, but I cannot find the option to do that through Jamf. And anything online about this is over a few years old. I just wanted to check in and see if there has been a change to this, or if anyone has a clever way of getting around it!Thanks!
Hello, after updating to Jamf Connect 2.36.0 this morning, my users are getting super annoying pop-up to setup local login 2FA on their computers, I suspect that this is caused by the new feature introduced in 2.36.0 called "Offline MFA Reminder (OfflineMFAReminder) but this key is not yet available in "Jamf Connect Configuration".Is there any way to rollback affected users to 2.35.0 or is the key (OfflineMFAReminder) might work if I add it in the Jamf Connect configuration profile?Big mess from Jamf here...
I am trying to come up with an easy solution for locking down iPads to single mode to just display a website. I wrote a simple browser that does this, but Jamf installs the app and it won't run. Will I need an Enterprise certificate or is there a work around?
Hey guys, our users have no admin rights on their Macs. Is it possible to allow them to use the Erase option in settings app (General => transfer and reset => erase all content and settings? It seems like the erase app actively needs admin rights, and these things seems like cannot be handled using privilege management systems like BeyondTrust. We tried to run the commands stated here from self service, but also there same message as stated above. Any hints / proposals? If not, I guess the only way for users is holding down their power button and reinstall from there, right? However we would prefer the way from settings app since it's more convenient. Thank you so much for your thoughts on that. bestFlory
Restored about 40 Macs last week via our cloud-hosted Jamf. When it is finished, you must activate the Mac before you can set up a new account, to verify with Apple. All machines could not complete it due to void certificate. It was something I had never experienced before. But it should still work out, right? Anyone know, experienced the same thing? The computers are not even a year old and more computers are to be restored this week.I've checked all our certificates and they're up-to-date, so it hasn't anything todo with that. The error comes in recovery mode after selected Wi-Fi when it tries to activate.
I've just recently started enrolling iPads via DEP into our newly setup and configured JSS. I've enabled a few restrictions in one of the configuration profiles I've deployed but I don't see any that restrict signing into iTunes & App Store. I'd like my users to be able to sign into their iPads with their Apple School Manager Apple IDs so they can install free apps via the App Store but both the "Sign In" and "Create New Applie ID" buttons are greyed out under the iTunes & Appe Store setting. How/can this be done?
Is their a way to send notifications to users with iPads to register their devices with Entra ID just like Macs with some kind of pop up window alerting the user that it needs to be completed. I know that their are no policies for mobile devices so was tying to see if there is anything else I could possibly leverage besides sending a mass communication out.
Afternoon All Is anyone using Jamf connect to enable filevault we are in the final stages of rolling out Jamf connect campus wide. It seems to be working find for new builds however we are seeing different behaviour for exisiting devices. Some devices are enabling filevault fine some arent even after an inventory update. All devices have same 3 config profiles for Jamf connectJamf Connect LicenseJamf Connect Menu BarJamf Connect Login 1-2-1 V.1 (Has updated key to EnableFDE set to true)and Escrow recovery key config profile to bring the key back to Jamf ( there are some filevault settings managed here as well)It mainly Intel 27" Imacs from 2020 which dont seem to be encrypted seeing the same issues on M1 as well. However other Intel and M1 Imacs have encrypted in the pilot group. I cant find any information for Jamf connect for weather it tries again at somepoint. Im also not sure if my escrow profile is causing some sort of clash as we have that set to enable
Got Regex?
Today we released Jamf Connect 2.36.0. This release includes the following changes and improvements: Zero Touch App Activation with Jamf Connect and Jamf TrustJamf Connect is now able to generate a unique token that can activate Jamf Trust for macOS, which creates a “zero touch” experience where users no longer have to manually sign in to their Jamf Trust app. This allows for the activation of Jamf Connect's Zero Trust Network Access capabilities without requiring users to manually interact with Jamf Trust. For more information, see Zero Touch App Activation with Jamf Connect and Jamf Trust. The User Promotion Biometrics (UserPromotionBiometrics) setting allows administrators to require Touch ID as a form of authentication prior to a temporary elevation session. This setting will be available in Jamf Connect Configuration with a future release. The User Promotion Role (UserPromotionRole) setting now supports the following additional identity providers: Okta-OIDC, OneLogin, PingFedera
So I am working on getting all of our Mac devices registered with Entra ID. I have set up the notification to let the users know that they need to register and then it directs them to self service to do so. This is great , however my issue is with the triggers, I'm looking for a way that if the Mac such as mine currently is registered with Entra ID, how can I no longer have my device receive the pop up notification. I only want the pop up to trigger if the device is not registered, so this will help with current Macs as well as new macs when they come into our environment. I've looked every where for solutions and could not find any hoping someone here has found a way to get this done.
Today we are releasing Jamf Pro 11.6. Highlights include: Compatibility with watchOSManagement capabilities are available in Jamf Pro for Apple Watch devices with watchOS 10 or later that are paired with a supervised iPhone with iOS 17 or later. The enrollment process begins with the end user's iPhone using Apple's declarative device management. Note: This feature is only available for Jamf Cloud-hosted environments. Support for FIDO2 AuthenticationSelf Service for macOS supports the FIDO2 authentication method for single sign-on. FIDO2 is a type of Universal 2nd Factor (U2F) authentication where credentials can be accessed on a device instead of a server. It enables passwordless authentication, including passkeys, local biometric access, and hardware keys. Note: FIDO2 must be configured via your identity provider (IdP). For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. See the latest release notes video for a
I've noticed that periodically some devices in our Jamf Pro cloud instance lose their User & Location information.We're then having to go through and manually update this by pasting their local user account name into the User & Location search, which validates them against Entra ID and updates it correctly. I've not been able to determine why this information is being wiped out for some, not all, devices.1) How can we stop this information being removed?2) We have Cloud Identity provider configured with Entra, and Jamf Pro can look up the data when we manually specify it. User attribute mapping is setup. How can I automate this process? In the majority of cases, our users local account name is in their Entra ID account name format. I can pull the logged in user via a script, but passing this via jamf recon -endUsername <value> just populates the username, it does not do the entra ID mapping. Many thanks for any suggestions!
I'm trying to trigger a policy (that launches a Swift Dialog window) when a user logs in for the first time. Setting the policy trigger to 'Login' seems to work when using a local account. However, if I login using an Entra ID using Jamf Connect, the policy doesn't trigger.The purpose is for setup of new Macs given to end users.Anybody have an elegant method getting a policy to trigger on login whilst using Jamf Connect? (Recurring check-in would take a bit to long for what I'm trying to achieve)
Hi Jamf support,Our current license is 78 users, and then please help to provide your quotation about add number of users, for example, please quote us the additional 22 users with your cost by email, and we can start the confirmation by reply, thank you for your attention. Best Regards,Samuel (support team)
I have team of developers that need to use Sudo and developer tools on the mac means they have been given admin right to laptops, Anyone have any recommendations on how i can give them the rights they need without giving them full blown admin rights to laptop?
We have a school that have a set of shared iPads which they occasionally erase. Since 17.5 the setup half completes but they then lose connection to the MDM (Jamf School) and nothing gets installed. When using a hotspot it completes fine. They've not done anything to their school network so are wondering what has changed between 17.4.1 and 17.5 that would interfere with the setup on the school network.Anu suggestions?ThanksAndrew
Has anyone managed to get this working? We have tried to set this up without any success. We have added the required certificate to our Config Profile and I can see it on the machines in Keychain Access but our Network team say the devices are presenting the JSS Built in Certificate to the server instead of the certificate we have added in the Config Profile?The certificate is trusted and we have the correct common name, but it doesn't appear to be being sent out from the mac.Any suggestions appreciated.
jamf recon command when run in verbose mode shows that it works upto JSS is available and doesnot update inventory. When check the JAMF client logs, there is a couple of error messages. JSS connectivity state change - state: notActive, user: nil Error triggering policy id: 386 error: Error Domain=NSCocoaErrorDomain Code=4099 "The connection to service named com.jamf.management.daemon.selfservice was invalidated." USerInfo={NSDebugDescription=The connection to service named com.jamf.management.daemon.selfservice was invalidated.}
Does anyone know how I can use a RegEx in a smartgroup for devices less than 12.0.1
Now that v11.1 is released comments are for the production release. 1) Performance still seems quite laggy. Almost unusable.Setup - Control computer and target computer on the same LAN. Both on my desk. macOS firewall disabled on both. WAN is 600/40 business cable.Actions (clicks, opening windows, etc) performed by the control computer appear instantly on the target computer - but take roughly 1.5 seconds to register on-screen on the control computer. By comparison, under the same setup/conditions, Splashtop SOS has a lag of roughly 0.5 seconds (or less).Looks like there's still a far amount of performance tuning to be done. 2) During a control session. . .When the control computer moves the mouse, the cursor moves on the target computer.When the user at the target computer moves the mouse, the cursor DOES NOT move in the control computer's session window. Items highlight when clicked by the user at the target computer - but no cursor movement. This creates two prob
We are currently in the process of preparing a migration from traditional AD binding to Jamf Connect with EntraID. Most users login's are working fine, however when a user with a local password that is different than their Entra password attempts to log in, they are hit with a screen that says "Verify Password, Invalid Password". I was under the impression that if configured correctly, it would instead prompt the user to enter their old password to sync the two. When the user enters their old local password, it does not sync it to the new one and just continues to prompt them for their old local password whenever they log in. Currently, our Jamf Connect login window profile is set to passthrough auth and disallow a separate local and entra password and I can't seem to find any other options that would be missing. Any thoughts?
I am on JAMF Pro 11.5.1 and I am having a strange issue on a number of macs where Self Service is crashing immediately but only for Mobile accounts. Local Accounts can open Self Service without any problems. Has anyone run into this before? I have tried re-installing Self Service and re-running recon and policy but its still persisting.
I need to turn off the Ad topics, Site-suggested ads, and Ad measurement from Google Chrome to 200 MacBooks, do you know if there is a way we can do this through JAMF via script?
We are relatively new to Jamf Pro. NFR/Test was set up for us to use by Jamf staff. Now that we have a few devices in our PRODUCTION instance and ABM setup along with that, I decided to stand up the Test/NFR environment. When I get to the point of creating the new MDM server in ABM, I am prompted to download a new "MDM Server Token." However, I am warned that doing that will result in my existing token being reset. I do not want to break Production. Is there a way around this? Thanks.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!