Get Support
Recently active
Hi All, I am looking for some advice with firewall rules for Jamf Remote Assist. The Jamf documentation is a little sparce. We are currently packet capturing the connection, but wondered if anyone has already figured out what IPs/hostnames are needed to be added to a firewall. I have found the ports from a web search. Enabling Jamf Remote Assist - Jamf Pro Documentation 11.5.0 | JamfAny help would be appreciated. CheersGT
Hello Jamf friends!I am new to the IT world, any assistance would be greatly appreciated. We have new Macbooks that we would like for users to sign in by using their Office 365 work domain credentials. We have Jamf Pro. What is the best way to do so in Jamf Pro? Any articles or videos would be great. Thank you,
Anyone sussed out a way to remotely manage the startup security utility settings on Apple Silicon Macs? We use a lot of music production software that requires the "Reduced Security" option to be enabled and I haven't seen a way to deploy these settings either in PreStage or as part of enrollment. Is manually changing these on each device the only option here? Currently all devices on Ventura but moving to Sonoma over the summer. Appreciate any help.
I am trying to enrol my Mac mapped to your prestage in ABM.I am able to click Enrol on the Remote Management screen and can authenticate successfully on okta app.As soon as the authentication is successful the login page remains as it is and the password box goes blank.Nothing happens after this so am not able to enrol my device and there is no error on screen.Other users and test device was enrolled successfully at same time its just my own Mac is not enrolling.I wonder if this has to do anything with the Okta LDAP group membership.The testing for my account is successful when checked in jamf LDAP.We are using jamf connect for enrolment.
I've got an application installed on a number of mac devices, I'm looking to have this run when a user logs. How can I achieve this?- The application is pushed through a Jamf policy.- The devices are shared and logged in by many people.- The application was composed and packaged in house.
This may be a newbie question but I have looked everywhere: Initially I was trying to get Jamf Tools: after some googling, it says I will need jamf nation account and go to My Assets.I create a jamf account for myself but ofcourse, no subscription hence no tools.My workplace uses Jamf Pro. I thought I can connect the two together and download the tools I will need. How do I connect the two together so I can use their subscription and download the jamf tools? If you say, "you dont connect your personal jamf nation account to their company's Jamf Pro":1. Do you create a new jamf nation account for each company you work with?2. My initial thought was I would use my jamf nation account -connect it to work email-work company and get the subscription and once I move to a new company, I would "un-link" and connect to theirs instead of creating bunch everywhere. Another reason I thought of using my jamf nation account is to have my certification in all in one place. It woul
Hello Jamf Nation! We have two important notifications for Jamf Protect users who may be affected by future deprecations and changes. Support for macOS 11 will be removed in a future Jamf Protect release. Jamf recommends updating to macOS 12.x or later to ensure continued support. The existing telemetry feature is expected to be incompatible with the next major macOS version. Jamf Protect is developing a new version of telemetry that is compatible with current and future versions of macOS. The improved version of telemetry provides more detailed configuration options, better refinement and visibility of telemetry data, and improved resource utilization.The existing telemetry feature will continue to be available to allow customers time to migrate to the new version. Prior to releasing the new telemetry feature, Jamf will provide more detailed documentation of telemetry events and data via a telemetry data model, as well as migration information. Existing SIEM applications and integra
Hi everyone,I'm encountering an issue when running a shell script via JAMF. The script only works if it is written as a one-liner. When I try to run the same script in its normal, multi-line format, JAMF throws errors. Interestingly, if I save the script as a file and execute it, it works perfectly. Additionally, JAMF seems to dislike empty lines in the script and throws errors related to them.Here is a snippet from my Script which fails: to_json_array(){ local list=("$1") local array="[" while IFS= read -r item; do item=$(printf "%s" "$item" | sed 's/"/\\\\"/g') array+="\\"$item\\", " done <<< "$list" array="${array%, }]" echo "$array" } And that's the error to this: 1:233: execution error: /Library/Application Support/ZuluDesk Scripting/com.zuludesk.scripting.60a1e7ef-234b-11ef-8da8-024f99ac106f/com.zuludesk.scripting.60a1e7ef-234b-11ef-8da8-024f99ac106f.command: line 25: syntax error near unexpected token `{ ' /Library
We recently implemented Okta Verify for our desktop MFA logins. Which works good most of the time but does require an active network connection most of the time to function correctly. Our office WiFI is radius authenticated, so it won't connect at the Mac login window. We do have ethernet at desks, but the network USB-C network adapters don't always connect at the login window either. Once a user is logged in the adapter gets authorized and will connect. So if there is no network connection, Okta verify wants you to use a off-line device access code to log into the machine, and if a use hasn't restarted or logged out in more than five days that factor is disabled, thus requiring an admin to login get the network adapter activated and then log out and let the user log in again and get a push verification factor, and then they are in. Here is the question.... How do I allow network adapters to activate at the login window, always? I understand that not allowing without a user login
Hi Jamf friends, Newbie here- to Jamf and Macbook! Does anyone have Power BI downloaded on their Macbook? If so, what steps did you take to have it operating successfully? Did you have to enforce any configurations in Jamf to allow this download? Thank you,
Hello Everyone, We have have seen in Jamf Connect menubar password expiration countdown is not showing, we using the Azure Hybrid. Added the Kerberos tickets and password expiration, countdown settings was added but still seeing the same issue.Can anyone help me with solution ASAP and getting the below error. Kerberos authentication failed with error: KerbError
Hi,I'm trying to create a configuration profile for distributing fonts, but no matter what file I try to upload (I've confirmed the fonts work fine on a local Mac), I get the following error:"File format not supported." Has anyone run in to this and know what needs doing to make it work? I've searched the forum but I've been unable to find anything on this particular issue.
We populate Jamf Pro User and Location by running a script upon login to do a "jamf recon -endUsername $3". This populates the Username field in Jamf Pro which in turn causes Entra ID Cloud Identity Provider to populate the rest of the fields in User and Location (such Full Name, Email Address, Phone Number, etc). We are using $EMAIL to populate the Configuration Profile for Outlook to auto-load the user's email address but we find that Jamf does not replace that variable in the Configuration Profile and it remains blank. We suspect that it's because the Configuration Profile is deployed prior to the User and Location Email Address field is populated. Is there a way to "delay" the deployment of the profile? I know I can use Smart Groups for this but doing so will result in multiple groups that we need to maintain so looking at alternative ways to do it. Any suggestions?
Greetings! We are having an interesting issue at our company. Using both PCs and Mac computers by the creative departments. When we try to save an Excel/Powerpoint file on our Windows file servers we get a sharing violation error, the permission table gets messed up and the file cannot be re-opened again until our server guys re-inherit the rights on the file servers. All Macs connect via SMB. The Macs are running El Capitan (not fully up-to-date, 10.11.4) and the Windows file servers are all Windows Server 2012 R2. Previously not just excel sheets and powerpoint presentations had this problem but all other files as well. The servers are utilizing DFS and we also have Talon File Services installed. We are granting access to the servers via Active Directory groups, two different ones, one for read-only and one for read/write. When the issue happens the file loses all individual and group rights in ACL, only the currently editing user is there with read/write access and everyone wit
I was wondering if there was a way to remove JAMF trust of my iPad during holidays since the parents had to buy the iPads during the holidays I would like to remove JAMF trust off my iPad is there a way to do that
Trying to delete User accounts with JAMF Schools Script.I had it not error before and it seemed to delete but the account would still be on the login screen. ~ #!/bin/bashusers=("Class1")# Delete users and their home directoriesfor user in "${users[@]}"; do# Check if the user existsif dscl . -read /Users/$user &>/dev/null; then# Delete the user accountsudo dscl . -delete /Users/$user# Remove the user's home directorysudo rm -rf /Users/$userecho "Deleted User -> $user and their home directory"elseecho "User $user does not exist"fidone Im returning 1:233: execution error: /Library/Application Support/ZuluDesk Scripting/com.zuludesk.scripting.08af6178-237d-11ef-8da8-024f99ac106f/com.zuludesk.scripting.08af6178-237d-11ef-8da8-024f99ac106f.command: line 2: : command not found /Library/Application Support/ZuluDesk Scripting/com.zuludesk.scripting.08af6178-237d-11ef-8da8-024f99ac106f/com.zuludesk.scripting.08af6178-237d-11ef-8da8-024f99ac106f.command: line 4: : comm
What is the best route to set a specific desktop image for managed devices. So far I have seen the create a package that deplys the specific image you want. Then create a configuration policy to lock the desktop picture and putting the path of the file. Is this the best way? Thanks
I have a script to remove the default apps from the dock but I can't get it to execute when a user logs in. It only works when I run the policy in terminal or from Self Service. The policy is set to trigger at login but doesn't seem to run. Is there an issue with the script or a Jamf policy setting that should be modified? #!/bin/bash# Get currently logged in usercurrentUser=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }')# Path to dockutil tooldockutilbin="/usr/local/bin/dockutil"# Sleep for 30 secondssleep 30# Remove default Mac apps from the dock/bin/launchctl asuser $(id -u $currentUser) $dockutilbin --remove 'App Store' --restart $loggedInUserPlist/bin/launchctl asuser $(id -u $currentUser) $dockutilbin --remove 'Contacts' --restart $loggedInUserPlist/bin/launchctl asuser $(id -u $currentUser) $dockutilbin --remove 'FaceTime' --restart $loggedInUserPlist/bin/launchctl asuser $(id -u $currentUser) $dockutilbin --re
Hey everyone!Is it possible to restrict creation of more than one user accounts using Jamf Connect or restrict it only to an assign user in Jamf Pro?What I did:Enrolled a device, went through Setup Assistant, created an account with Jamf Connect, logged out and when I accidentally entered credentials of another user in Login Window, another user account was created on a computer alongside the one already existed (and hidden admin account).What is the setting, that I need to change, so that it would not be possible to create another account?
Is there a way to truly lock an iPad in JAMF that disables the end user for putting in their passcode to clear the message sent within the Device>Management>Lock Device? It seems useless to send a lock device command only to have the end user be able to put in their passcode and ignore the command sent.
The yesterday announced Apple TV 4K has no USB-C connector on the back:Apple TV 4K specs As we have no DEP, we have to use Apple Configurator to enrol the Apple TVs into the JSS. Does anyone know if and how we can enrol the Apple TV 4K without DEP?
We are installing the LG CreatBoard application on all of our new Mac Laptops, and the main installation goes without issues. The issue we are running into is that upon first launching the application, it installs the MAXHubUSB audio drivers and requires admin rights.Has anyone been able to install the audio drivers separately and get the system settings plists updated so the application sees the driver installed?the folder with the plists is /Library/Preferences/Audio/ Thanks for any assistance.....
My company is making a switch from Jamf to a new MDM, and we are in the process of migrating them over. I have been unenrolling the laptops from Jamf first and then usually deleting the profile in the Jamf console. However, I found a few profiles in Jamf that I missed. Despite them being unenrolled on the device for over a week, they are still checking in with Jamf according to the console. How is this possible? How is the device still checking in when JAMF has been removed from the device?
i am working on setting a specific wallpaper with company logo. I have created the package, policy and configuration profile to push the set wallpaper and lock it. The problem is the jpeg does not fit on the screen and comes out blurry, I messed with it a bit on my computer and see that if I set it to "Fit to Screen" it comes out alright. Is there a setting or easy script that I can push to make sure it sets it to "Fit to Screen on all machines? Thanks
Hi Jamf Nation,I need some guidance\\assistance as I cannot figure out how to find the settings I am seeking in mobile devices\\configuration profile to remove users ability's to change Software Update\\Automatic Updates settings on an ipad. I have a configuration profile on mac devices that restrict users users ability's to change Software Update\\Automatic Updates as JAMF manages the settings for the end customer.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!