Get Support
Recently active
Wondering if anyone can share their method for creating a PKG file from the source files for the TN5250J emulator? Some of our users are using an older version that's getting flagged by our Information Security team, so it's time to upgrade them. I don't know how our last Mac admin created the package for that older version, and so far anything I've tried to build in Composer doesn't result in a working package. Haven't found any answers yet on the internets. Only related post I could find in the forums here was this one, which didn't garner any responses: Mac M1 Java and iSeries TN5250j - Jamf Nation Community - 225341.GitHub download page for the emulator is Releases · tn5250j/tn5250j (github.com).
So I wanted to push an OS update to my test Macs, which I have previously done via Inventory, pick the machines I want, Actions, Update OS version etc.It's still there, I can still choose its radio button, but a blue box appears saying "You can now use Software Updates to manage OS updates". But the Software Updates feature appears to be a beta, and I don't particularly want to use a beta. I would like to use the existing Update OS Version mass action.The blue box says that I can continue using the existing feature, but that it will be deprecated in a future version. But the "Next" button is greyed out, with no indication as to why.So, despite the wording, is it already deprecated? Or should the Next button still be available, and if it should be, has anyone got any ideas about why it isn't?Thanks,Lisa.
I am an Active Directory user and log in to my Mac using AD authentication.This allows me to check the last user to log in to the Mac from the computer usage logs in the computer's history, but is there a way to collect SSO user information when using Platform SSO?thanks
BackgroundNow that macOS Monterey is out, we wanted to allow our opt-in Beta Testers with local admin rights easy access to nuke-and-pave their Macs the "Apple" way:macOS Monterey includes Erase All Content and Settings, a way to quickly and securely erase all of your settings, data, and apps, while maintaining the operating system currently installed. If your Mac includes this feature when using macOS Monterey, use it instead of other utilities to erase your Mac.Source: HT212749Smart GroupErase AssistantAnd / Or CriteriaOperatorValue Operating System Versiongreater than or equal12.0.1 and(Architecture Typeisarm64 or Boot ROMlikeiBridge)PolicyOptionsGeneralDisplay Name: Erase AssistantExecution Frequency: OngoingFiles and ProcessesExecute Command: /usr/bin/su \\- "/usr/bin/stat -f%Su /dev/console" -c "/usr/bin/open '/System/Library/CoreServices/Erase Assistant.app'" ScopeTargetsErase AssistantSelf ServiceSelf Service Display N
Hi, We have some smart groups that set target OS on Mac products, which currently forces user above the target OS to downgrade via DFU blaster..... our target Stable OS in ventura, but unfortunately newly purchased macs with m3 processors will not go back to Ventura, so i want to exclude them from them from the smart group. Is there a processor identifier/or model identitfier i can use as advanced criteria in the smart groups to select M3 processors?
Hey guys, we're looking for an opportunity to grey out the option "Allow this user to administer this computer" in system settings. Our users are no local admins and we do not want them to enable that option. Any ideas? thank you so much, Best, Florian
Here is a script I made to remove old installations of Cisco AnyConnect that were done back before a choices.xml file was used. #!/bin/bash #This script will uninstall the full install of Cisco AnyConnect with all the modules # It will first look for the existance of the dart installer. If it is there, it will run. # then it will run the full anyconnect uninstaller. After that is completed, then we can install # the new version of Cisco Anywhere that only installs the VPN component. if [ -e "/opt/cisco/anyconnect/bin/dart_uninstall.sh" ] then /opt/cisco/anyconnect/bin/dart_uninstall.sh else echo "no DART to remove" fi /opt/cisco/anyconnect/bin/anyconnect_uninstall.sh exit 0 It works great... with the exception that in Big Sur and Mojave (I haven't tested other versions), it throws up the following dialog: Obviously the point of running things in Self Service is so end users don't have to get an admin to authenticate for them. Does anyone know how I can make this alert not
Has anyone figured out an automated way to allow non admin users to the System Preferences -> Security & Privacy -> Privacy to be able to Allow anyways to open apps. i've tried #!/bin/shsecurity authorizationdb write system.preferences allowsecurity authorizationdb write system.preferences.datetime allowsecurity authorizationdb write system.preferences.SecurityPrivacy allowsecurity authorizationdb write system.preferences.security allowexit 0 But still cant get this to work with out admin credentials.
I know that most folks are recommending user-driven provisioning where the end-user gets to enjoy the process of being involved in setting up their Macbooks. Our org is not one of those. Our users prefer to get their Macbooks and get to work immediately and not have to wait for apps to install or things to be configured while they sit and do nothing. We achieve this in Windows by pre-provisioning (Microsoft calls it white glove) where we assign common apps (Office, Chrome, VLC, etc) to the devices rather than the user and we leave user-specific apps (not all users get Adobe Creative Cloud for example) to be installed after the user logs in. This way, we can get a fleet of Windows laptops ready for use by anyone with very minimal delays experienced by the user (they can work in Outlook and Chrome while Adobe CC is being installed in the background). I plan to achieve the user side of things using DEPnotify but any suggestions how to pre-provision common apps? Is putting the comon a
I'm looking for a way to not have Keynote, Numbers, and Pages install on enrollment. Is there a way to do this? Or do I just have to remove them afterward?
Lately, every Mac that has tried to perform user-initiated enrollment in Jamf has been met with "Device Signature Error in the jamf log. To resolve, we perform these steps:1. Remove Jamf Framework2. Remove Jamf CA certificate3. Remove contents of /Library/Application Support/JAMF/Downloads/4. Run this command: sudo update_dyld_shared_cache -force5. Delete the mac from Jamf console6. Run the QuickAdd package on the mac7. Approve the Device Management Profile on the Mac8. Assign the user to the Mac in the Jamf Pro console This issue seems to have started with MacOS 10.14.5, but that may be coincidence. I have attached screenshots from an affected Mac. We have 3 macs that are broken right now, and 2 that were repaired using the procedure above. Anyone else seeing encountering this?
Hi,We're in the process of deploying Taegis XDR from SecureWorks to our Macs. Unfortunately like most XDR's it's a mess. Has anyone used Jamf to deploy Taegis.Beside the privacy settings, one of the issues we have is automating the registration process. SecureWorks provides a .mobileconfig profile for inTunes but not Jamf. I tried using it anyways but it didn't work. Are there differences in an InTune mobileconfig and a Jamf mobileconfig? I thought a mobileconfig file or plist would be the same no matter the MDM.TIA,Chuck
Hello everyone,Is there any way to solve the installation of Office 365 without creating a package and policy with all the apps? Maybe with a script in some way through Self Service?
I have a number of users that are using Loom, but don't have administrative access on their computers anymore. How is everyone dealing with updates like this? I see that it can be managed by Patch Management, but how do I push out the updates when they are sent as a .dmg?
Dear Team,I know that with Jamf Protect can do App Control to block all the know apps with attribute like hash file/team id/sign id....Can Jamf Protect support to control the all black list apps not only App Store but also the third-part apps.Example my Org has many departments. Each departments will have the whitelist apps. Therefore, it is not in the whistlist the apps should not launch. The thing here is due to user's role need administrator permission, it is hard to control except check inventory manually. Mass thank
I am working with a Jamf environment that currently does not have any Jamf LAPS capable admin accounts. They did not create a “Management Account” in User-initiated enrollment. They did not create a “local administrator account” int PreStage Enrollment. We have since specified a “Management Account” and a “local administrator account”. With two separate names. They are using Apple Business Manager Automated Device Enrollment. There are some locations that do not have ABM, so they are using User-initiated enrollment. (That is begin resolved). LAPS is working with newly enrolled Mac systems using either admin accounts. Is there away to retroactively add a User-initiated enrollment “Management Account”? I’ve tried using “jamf policy -trigger enrollmentComplete”. This will successfully re-run the enrollment policies, but it does not create the “Management Account” from User-initiated enrollment. “profiles -N” does work. But that requires user interaction. Thought
We have a Mac that will be used in a production environment (Live TV). I would like to keep it in JAMF but essentially just for record keeping, loss prevention and for our security software. A broadcast engineer will be responsible to keep it running. We tend to have a bunch of updates triggered by smart groups, basically if it has this software then do the update or action.Without excluding this computer from every single smart groups one-by-one, is there a way to single out a computer so any action to the computer is explicitly and only when it's named? Perhaps just a way to exclude it from all smart groups/groups.
Hello everybody,I don't know if this is possible, but I have a question regarding the interaction between JAMF Connect and a Synology connected to AD DS.On my MAC fleet, JAMF Connect is perfectly deployed, and allows me to open a session as user@mydomain.comOn my local network, I have a Synology NAS which is joined to Entra (Azure) Domain Services, and therefore which allows authentication as Domain\\User and therefore the use of the Entra account as for JAMF Connect.I would like to know if it was possible to allow an automatic connection of my SMB share, using the Kerberos ticket, or other, generated at the JAMF Connect connection.If so, how can I go about it?Thanks!
HI all,The latest patch definition for the new Teams has not been updated for nearly a week now.The new Zoom 6.0.1 definition appeared within a day so just wondering is this normal for Teams?There should be en entry for version 24074.2607.2799.9843 which was released on 12th April.
I'm working as MacOS support engineer. We planed to initiate automation the app update using package in Jamf Pro.Here what I want exactly means Create Package (example Chrome) with the configuration of force install and update to upcoming latest version. Anyone pls help me to find out better solution.
Hi all, Just wondering if anybody has had any luck connecting to Okta as an LDAP source. It's enabled on our Okta instance and others apps can connect to it, however when I try and configure the JSS it gives me a connection error every time no matter what config I've tried.
Few devices are not able to get the latest released MacOS update when connected with internal corporate network. Can anybody tell us which all things need to be whitelisted in order to get the devices updated with Apple update server directly. Thanks!
I am trying to automate the creation of an Outlook signature and I have most of the parts down except I can't find a way to pass values from User and Location to the script. I thought passing $FULLNAME or $POSITION as script parameters would work but all it does is literally pass the string "$FULLNAME" to the script.
Hello!I need a hand writing an Extension Attribute script to gather "Reason for privilege elevation".The below command works in Terminal directly on a Mac running macOS 14 to gather the info but I don't know how to then parse it into a script for an Extension Attribute. The text in bold is what I want to gather. An endless running list of reasons would be ideal. Any help would be much appreciated 😊sudo log show --style compact --predicate 'subsystem == "com.jamf.connect"' --debug --info | grep "Reason for privilege elevation:"Result:2024-04-04 10:09:22.221 Df Jamf Connect[55703:31aeb0] [com.jamf.connect:PrivilegeElevation] Reason for privilege elevation: Admin elevation test 12024-04-04 10:18:37.006 Df Jamf Connect[55703:31aeb0] [com.jamf.connect:PrivilegeElevation] Reason for privilege elevation: Figma install
Having concluded that FileVault isn't going to be a good idea in our domain-joined, student lab environment, I have made a configuration profile to disable it. This configuration profile is applied during the pre-stage enrollment – i.e. as early as it possibly can be. I have verified that it is indeed applying within seconds of the computer getting past the voiceover setup prompts. And yet, the first user who logs in, gets a big prompt for enabling FileVault, *with enabling it checked by default*, i.e. enabling it!If I manually uncheck the box and click Continue, and then go look in System Settings, FileVault says that it is disabled by policy and does not allow the user to change it! So the configuration profile is clearly applying, but it seems not to prevent the first user being prompted anyway.Any idea how I can stop the first user getting this prompt?(The funny thing is, before I created the configuration profile to disable FileVault, the first user was NOT prompted in this way. I
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!