Get Support
Recently active
We are using Jamf pro, Jamf connect and Microsoft intune.We start facing a issue when user password expire and need to change password.Any specific thing I need to set in 365 ?ThanksEC
I've taken up to Jamf 300 and the training course resources used to be available here:https://docs.jamf.com/education-services/resources/Anyone know if the link has changed or if the materials are no longer publicly available?Thanks!
Is there a way to prompt users to allow Location Services after the Return to Service app runs? I don't see how the average user could be directed to go and set Location Services. I understand Apple still does not allow it to be set by default. Thanks for your thoughts.
Getting the notification that the Push Proxy Cert is expired. Been getting this for the last 2 weeks since the update to Jamf Pro Cloud Version11.4.2-t1713554080Went into Global > Push Certificates, clicked on Push Proxy Settings, clicked renew, and am watching the endless spinning.Logged into Jamf to make sure the account used to make the cert is correctDeleted the cert and re-added it with a fresh date, then next day got the alert againVerified connection in the Global > Cloud Services connection, updated credentials as wellAt a loss here how to fix this.
I researched a few companies that integrates well with Jamf and ZenDesk. RefTabZluriOnetoOneIf any have any other suggestion to help better my work flow through out the day. Ideally we would use this system to also track our other devices such as chargers or etc.
Looking for some guidance on how to suppress the Jamf Connect sign in window for a strictly local user account. In this particular work flow we have a few Mac's setup as Podcast stations using Hindenburg because of this there's only a local account on the machine called "Podcast" to preserve the application preferences. I would like to allow network logins on these machines (if possible) by leaving the Jamf Connect client installed. The issue I'm having now is when a user signs into the local "Podcast" account they're presented with the Jamf Connect "sign in" window which is causing confusing. I've gone over the various Jamf Connect keys but I can't seem to locate any options to suppress this window.Help!
We ran into an issue where one of the higher-ups within our organization was having printer troubles and one of our technicians remotely logged into their Mac with the managed admin credentials. The higher-up took issue with this as the user's account does contain sensitive documents and they're not a fan of the possibility that anyone in our department is able to remotely log in using the Screen Sharing app. Any ideas on how to designate Jamf Remote Assist as the only RD software and possibly disable or remove Screen Sharing capabilities without completely disabling RD? Ideally, the end-user would have to allow the screen sharing session and the Screen Sharing app allows any user to connect if they have the correct admin credentials.
Is there a way for Jamf to get the current Private MAC address of a Supervised, managed iPad?NOT the hardware MAC address!I've used Extension Attributes for other things for IMacs, but this one seems a bit curlyI have a bunch of iPads and the Wi-Fi config hasn't got disable randomisation ticked and I didn't want to just update the Wi-Fi profile without trying to find some way to look up the iPad by current MAC address first.Thanks for any suggestions!
Hi all, i have a small package (.pkg)that installs FortNAC persistent Agent, the trigger is "Once per computer" this works perfect. Now there is an update for this package (.pkg) what is the best way to update this package?So remove the old package and add the new package to the Policy but how do I reset that this policy run again?or turn off this policy (and later remove) an make a complete new policy with the new package? thanks
Hello, I'm trying to figure out how to change the "Hostname" and "Local Hostname" of our fleet of MacBooks to use the Serial number instead of the name of the computer that ends up being the name of the employees, which is not great for privacy and security.I tried many scripts from Jamf Nation and also Github but can't get any to work.I don't want to force users to have their computer name using serial number tho, just hostname and localhostname.Do you guys have a solution for that? Thank you
Learn how to provide your users more detailed feedback for standard Jamf Pro Self Service policies with a proof-of-concept script from Bart Reardon, the creator of swiftDialogBackgroundEarlier this week on the MacAdmin’s #swiftdialog channel, Drew Diver asked if it were possible to use swiftDialog as a status bar for Jamf Pro’s Self Service.“Ah, the Holy Grail …” was my reply.@bartreardon may just have delivered (once again).Continue reading …
¿Cómo puedo configurar Jamf Pro para que solicite el nombre del equipo al iniciar o finalizar el proceso de configuración del sistema operativo, de modo que el equipo tome el número de inventario asignado y, al aplicarse las políticas de Falcon y Netskope, ya aparezca con el nombre real?
We have been using this script likely stolen from somewhere without source for a few years now to configure the nomad launch agent. The python bits need to be updated and unfortunately I don't know python which is making it a tad bit complicated to update. Any advice would be much appreciated. loggedInUserPid: looks to be printing the user ID which is simple enough to translate to bash.launchctlCmd: I have not the foggiest what this does to try to translate it.**We are moving to JAMF connect later this year. #!/bin/sh ## postinstall #*============================================================================= #*==============================å=============================================== #* REVISION HISTORY #*============================================================================= #* Date: #* Author: #* Solution: #*============================================================================= pathToScript=$0 pathToPackage=$1 targetLocation
I have a bit of a stupid question. Why doesn't the Enrollment Method display for Computers in the Device Record? For example, in the screenshot below, you'll see the enrollment method is blank for a computer that passed through Prestage like normal.But for mobile devices, the enrollment method properly displays in the inventory record.This in no way seems to effect any function within Jamf. I'm just wondering why this is and if its the same for everyone. Thanks!
We have recently ported over our Mac Apps to the Jamf App Catalog, but are running into a bit of a snag. The initial deployment went great, but we have had a few users manually remove an application that was pushed out via the Jamf App Catalog.We created a new JAC deployment for the application, and made it distributed via Self Service, but the status on those computers are "Unqualified for App Installer". I am assuming that this is because it thinks it already has it from the initial deployment? Is there a local file that it keys off of for the install status? Is there a way that I can override this?Thanks
Hi Everyone, I am planning to implement JAMF-LAPS (Local Administrator Password Solution).I have a look of this https://github.com/red5coder/Jamf-LAPS?search=1I just want to gather everyone feedback on this one.Also, I would like to seek help if anyone has implemented this before and can guide me on how to implement this approach using Jamf Pro cloud? Thank you,
I have GLDAP working for our main domain, but I'd like to add and additional google domain for secure ldap logins. Is this possible?
Hello!I am currently trying to install Veeam via JAMF and I am using the instructions from this post: https://community.jamf.com/t5/jamf-pro/deploying-veeam-agent-for-mac-using-jamf/m-p/246434#M230724The agent is installed & gets full disk access but does not import the configuration for the backup job. Is there an updated install instruction?
Hi all,We need to stop personal iPhone/iPad from connecting the work macs. We have tried deploying this one: https://github.com/jamf/jamfprotect/tree/main/device_controls/restrict_mobiledevices_syncing_with_finderThis one is actually effective partially in stopping Finder to do the sync with iPhone. However, in Photo.app and Image Capture.app, there's still personal device.Is there a specific preference domain or key we will apply to stop all iOS/iPadOS from connecting to the work mac?
Hello,We have an old piece of hardware (I say old – it's from 2019) that doesn't have newer software, so it still has kernel extensions instead of system extensions. I can't mandate replacing the hardware, so I'm stuck with it.I'm trying to figure out how to get the software to install under Sonoma on a Silicon Mac. I have found plenty of stuff that says that I have to boot into Recovery, go to the Startup Security Utility, and check the box "Allow remote management of kernel extensions and automatic software updates". But of course naturally I want to automate this, not have to have somebody go around and do this.The JAMF article about managing legacy kernel extensions includes this baffling item:"Note: Enrolling computers with JAMF Pro via a PreStage Enrollment can automatically enable this setting. No further action is needed.""CAN automatically enable." What does that even mean? There's nothing about how to do it, and I can't find any settings in my pre-stage enrollment that seem t
Is there a method I can use, WebUI or API that will show me the recent smart group memberships a computer has had recently? I need historical groups not necessarily the ones the computer is a member of at the time I'm looking.Thanks
I sure hope that this is so easy that you all snicker and make fun of how inept I am. Since updating to Jamf Pro 10 on December 7th, configuration profiles are not being applied to existing and newly deployed iMacs. I have confirmed that all necessary ports are still open and that the Jamf server as well the iMacs are communicating with APNs and the commands are shown as pending in the iMac inventories. Per the suggestion of support my Jamf server was opened to communication over port 80. I have flushed all commands and restarted everything. Policies apply just fine. My client machines are 100% distributed. Any suggestions will be greatly appreciated.
This is a double question for Jamf School (and it limitations):I've noticed that when a user installs an app via the AppStore on an ipad (ios 16.7) the VPP license counter isn´t reduced/changed. Also when a user installs an App the app isn´t seen as a managed app but isn´t seen as a user app either.I would like to know:1. What is the best way for a user to install a managed app? Should the app store be used?2. Does jamf **school** have a separate "app store App" for managed apps? The reasoning behind this quest is quite stupid: the app supplier needs de app cache cleared from time to time to change modes (this is a testing app with a testleader and testclient mode) and Apple doesn´t have a clear cache option like Android, re-installation is the only way as far as I know.
I was wondering if anyone has experience with setting up Apache Guacamole to allow remote access to Mac computer labs? https://guacamole.apache.org Currently I have setup a test Guacamole environment that is allowing remote connections to the Macs using the inbuilt macOS version of VNC. However the remote session is quite laggy, with a delay as much as 2 seconds. I have tried tweaking the Guacamole VNC settings to see if this can be improved, but haven't managed to find anything that works. I have also tried running realVNC server on the macs and got the same delay. Oddly this delay is not present when remotely connecting a Windows 10 PC via VNC in Guacamole or when I VNC directly into the Macs. Would appreciate any ideas anyone has about how to rectify the delay. Thanks
Hi All,We've been requested to disabled SSH on all our macbooks by our security team as its been highlighted as a risk when connected to public wifi.So I wrote a script to disable it and it was working fine.But, I'm now seeing all the devices which had it disabled are all slowly turning it back on. I've looked through logs and cant figure out what is turning it back on. We don't have SSH enabled at enrolment anymore and I have no SSH settings in any config profiles or policies so I'm baffled as to what is turning it back on.Anyone else ever come across this or know a way to disable SSH for good?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!