Get Support
Recently active
We got alot of student devices. We want to be able to clear history and website data on them. Right now the option on the iPad is dimmed - Settings -> Safari - Clear History and Website Data.I'm trying to find out where the restriction is set to dimm the function on the device. I've looked everywhere and tested this and that without any good result. Anybody able to point me in the right direction?
Hello, My user iPhone is not communicating with Jamf any longer.- Last Inventory Update:04/11/2024 at 3:26 AM- MDM Profile Expiration Date:12/05/2025 at 3:56 AM- Management commands: 46 pending- iPhone is always networked: wifi, 4G- can't install/reinstall apps from selfservice- iPhone network setting reset: doneQuestion: How to re-establish connection between the device & jamf ? re-enrollment is a heavy trick to recommend How to identify the root cause of this behaviour?
Hi All,Currently, Jamf Pro does not distribute/push a few of our configuration profiles to the devices. Is there a way where I can force these Config Profiles to the devices in Jamf Pro? i selected all computers in scope, when I do re-save action it asks me if I want to distribute to all enrolled devices or newly enrolled devices but this is not an ideal solution. There must be a way to force them
We are an M365 municipality and use IOS mobiles in the field with Jamf Pro. With that said, we have several shared IOS devices. Think of all the Fire or Public Works crews that have a shared crew iPhone or iPad. There may be 3-8 people on a crew rotating shift to shift, so no one is logging into an Entra/M365 account on these devices. Coming up with a photo management solution for these shared devices has been elusive. With the person assigned devices, managing photos is easy. The person is logged into M365 on the device through Outlook, Teams etc. So, they can "share" their Photo app content with themselves to their OneDrive. Or, I can create a shared OneDrive for the whole department, and they can each have their own folder in there. I know I can create a managed Apple ID that is assigned to shared devices and content could be copied to iCloud. But how in the world would I get that content over to a shared OneDrive in M365? There's no way we're going down the road where users are log
Hi!I have a few devices with remote employees that started the JamfNow Enrollment process but got stuck somehow mid way through. So the profiles have already been installed from the blueprint but the Device page in JamfNow is super sparse without any options to unenroll or wipe and only a few of the tiles (e.g. Assigned To, Blueprint, Serial Number). This seems to put the device into a limbo state where the user can't remove those profiles themselves, I can't change or unenroll them remotely from JamfNow, and any attempt by the user to go back through Open Enrollment to get into a good state raises errors due to the already present profiles. Anyone run into this before and find a solve other than asking the user to hard wipe and reset their laptop, which I'd really prefer to avoid given it can cause a full day of non- productivity for them? Thanks!
Hey All, Since moving some of our machines to MacOS Sonoma, our old script which would set company ScreenSavers has stopped working. Has anyone found a solution? i cant seem to get any script to work or able to find one.
Looking after iOS devices for a large IT company.We have a 'default' set of restrictions; every newly setup device gets this. There are other profiles as well that look after things for all devices (passcodes are a good example). Restrictions, though, are the main concern.So, there are manually created restriction profiles for managers. Another set for those in comms. Another set for interns, another set for something else, and so on. Things are now a little arbitrary.TLDR managers can use WhatsApp and USB (for Carplay) connections. Comms are allowed to use WhatsApp, and interns are allowed to use only critical apps (for example, only Outlook, Teams, and MS Authenticator). Everybody else just gets the Default (automatically) and can play with the Calander and other not-so-important stuff. But not WhatsApp! GDPR laws in Europe.A static group based on serial is used to 'map' each device to each set of restrictions.What is starting to get on my nerves is the 'configuration creep'. I
Bonjour à tous,J’ai mis en place la solution de filtrage JAMF Trust, l’application bien installée, visible sur RADAR, le filtrage WEB fonctionne correctement.Cependant, je me suis rendu compte d’un problème un peu plus tard, j’ai un conflit avec le VPN Cisco qui confond le paramètre DNS de JAMF Trust.Lorsque le VPN Cisco est monté, le filtrage WEB ne fonctionne plus.Lorsque je désactive le VPN, le filtrage fonctionne à nouveau.Avez-vous déjà vu cela ?Pourriez-vous s’il vous plaît avoir une solutionMerci beaucoup pour votre aideTraduit avec DeepL.com (version gratuite)
Has anyone successfully implemented Classlink as their Single Sign Out for Jamf Pro?
Hello,I'm currently developing a profile automation system on Jamf Pro and I'm having a problem deploying wallpapers. I want to automate their deployment but I don't want to go through device commands. So I've opted for smart groups in the Jamf GUI, but I can't find anything to modify a smart group from the api.Do you have any ideas?
Hi, we have a situation where we're seeing several devices that have recently checked in but aren't provided inventory updates which means some of our policies aren't kicking off. Is there a way to force a recon in this situation? Do we scope a recon specifically to these devices and when they check-in next time it should kick off the recon? Or is there a better method to handle this?
We are implementing a "home made" solution so our AD students can login into specific Macs on specific time remotely using Screen Sharing.In order to complete our solution, we thought on activating Screen Sharing (not ARD) on specific hours by sending scripts to activate/deactivate Screen Sharing.We haven't found the command lines to add users/groups to the "only these users" menu.Yes, it is easy to do it with ARD (ARDAgent / kickstart), but we need to use Screen Sharing.Anyone knows the commands to set specific users to use Screen Sharing ?
Hello, I am new to this discussions, but I have already found here so many solution in the last few months that I decided to create an account in the hope that someone will be able to help me on an issue that I have and for which I haven't been able to find a solution on Google. At work, we have 3 WiFi SSID, One for laptops, one for smartphone and one for guest.The smartphone and laptop wifi have a lot of security and uses the AD account for connection.However, for the guest WiFi, it has a standard password and is "outside" our network. With these command line: security delete-generic-password -D "802.1X Password" -s com.apple.network.eap.user.item.wlan.ssid.Laptop security delete-generic-password -D "802.1X Password" -s com.apple.network.eap.user.item.wlan.ssid.Smartphone We are able to remove the Laptop wifi password on Keychain Access. For both Laptop and Smartphone. However, we are having an issue for the guest network.Unlike Smartphone and Laptop WiFi, as well as having the
Hi Jamf Nation Team,Is there an automatic way to move the inactive Macs from one production site to another? We have identified the Macs that need to be moved to the inactive site, but can we move them automatically when they reach the "inactive" status?
Hello, I'm at the point where I had to create Sites in Jamf. I've never had a problem adding VPP licenses to apps but now when I scope an app, i.e. GMail, to "Campus A", I get "Content not available to assign to mobile devices". If I remove the site (in other words Full Jamf), I can assign VPP to the apps. (I tried adding it first to Full Jamf and then changing it to Site and I still had the same problem).Do I need to add these sites to ASM?
Hello, I applied a "Facetime Deletion" and " iMessage App Deletion" within the Restricted Software. The process name I used was -----System/Applications/FaceTime.app and /System/Applications/Messages.app I restricted the exact process name, applied "delete application" and "kill process". Both apps still appear on the dock bar on the test Macbook laptop. Am I missing something?
I have a Mac mini that after upgrading to Monterey 12.7.5 will not allow a password to be entered. Tried multiple keyboards (this machine is usually headless). Keyboard still works in recovery. Mouse works at login. No policies/CPs have been scoped to limit input. Was fine before the update. Anyone seeing something like this?
Hi Everyone,Is there a method to automatically enable LastPass in the browser? For instance, without having to manually click on the extension icon in the browser.Thanks,Kenneth
So we have found for a managed and a non managed Sonoma machine, there is a bug in Apple's Lockdown mode.In order to enable Lockdown mode, one must be an admin on the machine.Once Lockdown mode is enabled, one can no longer use Apple's ARD program or ssh into that device. This is to be expected based on Apple's documentation.We also have an additoinal admin type account on our machines so the Tech department can work on machine without the end user's login information. We could log in with that account, go to systems prefs and disable.HOWEVER disabling lockdown mode with the other account DOES NOT restore the ability to use ARD or ssh into the machine.I have reached out to Apple and our Apple SE but have received no followup communication.
Hello All, We noticed that mac users are getting kicked out from Zscaler, and internet is becoming very slow. In that case we are supposed to loginto Zscaler manually, any idea why it is happening? Is it specific to macOS version? What is the solution on this? Any log can help me to do the troubleshooting? Please tell me the path of that log to collect it.
Looking to limit UIE to a specific group via SSO and/or Cloud Identity Provider (Azure).Currently we have SSO configured via Okta and CIP setup with Azure. Anyone got ideas on how to do the restrictions? I've tried adding the group under Access, but it still allows all users.
We are investigating potential inconsistencies in device registration status for the Jamf Pro Device Compliance integration with Microsoft Entra.Observations:Devices are marked as non-compliant in Microsoft Entra despite appearing as compliant within Jamf Pro's "Compliant" Smart Group.The Jamf AAD plist file and the MS-ORGANIZATION-ACCESS keychain entry go missing on affected devices.Re-registration through Self Service/Microsoft Company Portal temporarily resolves the issue, but devices fall out of registration again after a period of time, then fall out of complaince. (approximately two weeks).Environment:Jamf Pro version: 11.4.2 (presumed not to be related to recent product issues)Request:I would appreciate any insights from the community regarding similar experiences or potential solutions.
Hello,I'm looking for Managed login items in profile configuration. I've seen it in documents and video (see screenshots), but don't see it in my Jamf Pro.My interface is in French.Where is it?
Talk about a BS money grab
I've run into a troubling issue.I used the JAMF Software update BETA Install Action to set a "Download and schedule to install" for last Friday night with a deadline just before midnight Friday.The scope was for macOS 14 devices to update to macOS 14.5On Monday morning, two users had reported that they were stuck at a Recovery Mode screen - asking to "Enter your recovery keys to unlock the volume Macintosh HD".I supplied the escrowed FV2 keys to the users. One user was able to move beyond the Recovery screen and work normally - now operating on macOS version 14.5Unfortunately, the other user is not able to get past the screen - with the error "The supplied password failed to unlock the disk".I don't know if I have any options to get past this, with the JAMF escrowed key not working.Thanks for any thoughts.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!