Get Support
Recently active
I have a bit of a stupid question. Why doesn't the Enrollment Method display for Computers in the Device Record? For example, in the screenshot below, you'll see the enrollment method is blank for a computer that passed through Prestage like normal.But for mobile devices, the enrollment method properly displays in the inventory record.This in no way seems to effect any function within Jamf. I'm just wondering why this is and if its the same for everyone. Thanks!
We have recently ported over our Mac Apps to the Jamf App Catalog, but are running into a bit of a snag. The initial deployment went great, but we have had a few users manually remove an application that was pushed out via the Jamf App Catalog.We created a new JAC deployment for the application, and made it distributed via Self Service, but the status on those computers are "Unqualified for App Installer". I am assuming that this is because it thinks it already has it from the initial deployment? Is there a local file that it keys off of for the install status? Is there a way that I can override this?Thanks
Hi Everyone, I am planning to implement JAMF-LAPS (Local Administrator Password Solution).I have a look of this https://github.com/red5coder/Jamf-LAPS?search=1I just want to gather everyone feedback on this one.Also, I would like to seek help if anyone has implemented this before and can guide me on how to implement this approach using Jamf Pro cloud? Thank you,
I have GLDAP working for our main domain, but I'd like to add and additional google domain for secure ldap logins. Is this possible?
Hello!I am currently trying to install Veeam via JAMF and I am using the instructions from this post: https://community.jamf.com/t5/jamf-pro/deploying-veeam-agent-for-mac-using-jamf/m-p/246434#M230724The agent is installed & gets full disk access but does not import the configuration for the backup job. Is there an updated install instruction?
Hi all,We need to stop personal iPhone/iPad from connecting the work macs. We have tried deploying this one: https://github.com/jamf/jamfprotect/tree/main/device_controls/restrict_mobiledevices_syncing_with_finderThis one is actually effective partially in stopping Finder to do the sync with iPhone. However, in Photo.app and Image Capture.app, there's still personal device.Is there a specific preference domain or key we will apply to stop all iOS/iPadOS from connecting to the work mac?
Hello,We have an old piece of hardware (I say old – it's from 2019) that doesn't have newer software, so it still has kernel extensions instead of system extensions. I can't mandate replacing the hardware, so I'm stuck with it.I'm trying to figure out how to get the software to install under Sonoma on a Silicon Mac. I have found plenty of stuff that says that I have to boot into Recovery, go to the Startup Security Utility, and check the box "Allow remote management of kernel extensions and automatic software updates". But of course naturally I want to automate this, not have to have somebody go around and do this.The JAMF article about managing legacy kernel extensions includes this baffling item:"Note: Enrolling computers with JAMF Pro via a PreStage Enrollment can automatically enable this setting. No further action is needed.""CAN automatically enable." What does that even mean? There's nothing about how to do it, and I can't find any settings in my pre-stage enrollment that seem t
Is there a method I can use, WebUI or API that will show me the recent smart group memberships a computer has had recently? I need historical groups not necessarily the ones the computer is a member of at the time I'm looking.Thanks
I sure hope that this is so easy that you all snicker and make fun of how inept I am. Since updating to Jamf Pro 10 on December 7th, configuration profiles are not being applied to existing and newly deployed iMacs. I have confirmed that all necessary ports are still open and that the Jamf server as well the iMacs are communicating with APNs and the commands are shown as pending in the iMac inventories. Per the suggestion of support my Jamf server was opened to communication over port 80. I have flushed all commands and restarted everything. Policies apply just fine. My client machines are 100% distributed. Any suggestions will be greatly appreciated.
This is a double question for Jamf School (and it limitations):I've noticed that when a user installs an app via the AppStore on an ipad (ios 16.7) the VPP license counter isn´t reduced/changed. Also when a user installs an App the app isn´t seen as a managed app but isn´t seen as a user app either.I would like to know:1. What is the best way for a user to install a managed app? Should the app store be used?2. Does jamf **school** have a separate "app store App" for managed apps? The reasoning behind this quest is quite stupid: the app supplier needs de app cache cleared from time to time to change modes (this is a testing app with a testleader and testclient mode) and Apple doesn´t have a clear cache option like Android, re-installation is the only way as far as I know.
I was wondering if anyone has experience with setting up Apache Guacamole to allow remote access to Mac computer labs? https://guacamole.apache.org Currently I have setup a test Guacamole environment that is allowing remote connections to the Macs using the inbuilt macOS version of VNC. However the remote session is quite laggy, with a delay as much as 2 seconds. I have tried tweaking the Guacamole VNC settings to see if this can be improved, but haven't managed to find anything that works. I have also tried running realVNC server on the macs and got the same delay. Oddly this delay is not present when remotely connecting a Windows 10 PC via VNC in Guacamole or when I VNC directly into the Macs. Would appreciate any ideas anyone has about how to rectify the delay. Thanks
Hi All,We've been requested to disabled SSH on all our macbooks by our security team as its been highlighted as a risk when connected to public wifi.So I wrote a script to disable it and it was working fine.But, I'm now seeing all the devices which had it disabled are all slowly turning it back on. I've looked through logs and cant figure out what is turning it back on. We don't have SSH enabled at enrolment anymore and I have no SSH settings in any config profiles or policies so I'm baffled as to what is turning it back on.Anyone else ever come across this or know a way to disable SSH for good?
We got alot of student devices. We want to be able to clear history and website data on them. Right now the option on the iPad is dimmed - Settings -> Safari - Clear History and Website Data.I'm trying to find out where the restriction is set to dimm the function on the device. I've looked everywhere and tested this and that without any good result. Anybody able to point me in the right direction?
Hello, My user iPhone is not communicating with Jamf any longer.- Last Inventory Update:04/11/2024 at 3:26 AM- MDM Profile Expiration Date:12/05/2025 at 3:56 AM- Management commands: 46 pending- iPhone is always networked: wifi, 4G- can't install/reinstall apps from selfservice- iPhone network setting reset: doneQuestion: How to re-establish connection between the device & jamf ? re-enrollment is a heavy trick to recommend How to identify the root cause of this behaviour?
Hi All,Currently, Jamf Pro does not distribute/push a few of our configuration profiles to the devices. Is there a way where I can force these Config Profiles to the devices in Jamf Pro? i selected all computers in scope, when I do re-save action it asks me if I want to distribute to all enrolled devices or newly enrolled devices but this is not an ideal solution. There must be a way to force them
We are an M365 municipality and use IOS mobiles in the field with Jamf Pro. With that said, we have several shared IOS devices. Think of all the Fire or Public Works crews that have a shared crew iPhone or iPad. There may be 3-8 people on a crew rotating shift to shift, so no one is logging into an Entra/M365 account on these devices. Coming up with a photo management solution for these shared devices has been elusive. With the person assigned devices, managing photos is easy. The person is logged into M365 on the device through Outlook, Teams etc. So, they can "share" their Photo app content with themselves to their OneDrive. Or, I can create a shared OneDrive for the whole department, and they can each have their own folder in there. I know I can create a managed Apple ID that is assigned to shared devices and content could be copied to iCloud. But how in the world would I get that content over to a shared OneDrive in M365? There's no way we're going down the road where users are log
Hi!I have a few devices with remote employees that started the JamfNow Enrollment process but got stuck somehow mid way through. So the profiles have already been installed from the blueprint but the Device page in JamfNow is super sparse without any options to unenroll or wipe and only a few of the tiles (e.g. Assigned To, Blueprint, Serial Number). This seems to put the device into a limbo state where the user can't remove those profiles themselves, I can't change or unenroll them remotely from JamfNow, and any attempt by the user to go back through Open Enrollment to get into a good state raises errors due to the already present profiles. Anyone run into this before and find a solve other than asking the user to hard wipe and reset their laptop, which I'd really prefer to avoid given it can cause a full day of non- productivity for them? Thanks!
Hey All, Since moving some of our machines to MacOS Sonoma, our old script which would set company ScreenSavers has stopped working. Has anyone found a solution? i cant seem to get any script to work or able to find one.
Looking after iOS devices for a large IT company.We have a 'default' set of restrictions; every newly setup device gets this. There are other profiles as well that look after things for all devices (passcodes are a good example). Restrictions, though, are the main concern.So, there are manually created restriction profiles for managers. Another set for those in comms. Another set for interns, another set for something else, and so on. Things are now a little arbitrary.TLDR managers can use WhatsApp and USB (for Carplay) connections. Comms are allowed to use WhatsApp, and interns are allowed to use only critical apps (for example, only Outlook, Teams, and MS Authenticator). Everybody else just gets the Default (automatically) and can play with the Calander and other not-so-important stuff. But not WhatsApp! GDPR laws in Europe.A static group based on serial is used to 'map' each device to each set of restrictions.What is starting to get on my nerves is the 'configuration creep'. I
Bonjour à tous,J’ai mis en place la solution de filtrage JAMF Trust, l’application bien installée, visible sur RADAR, le filtrage WEB fonctionne correctement.Cependant, je me suis rendu compte d’un problème un peu plus tard, j’ai un conflit avec le VPN Cisco qui confond le paramètre DNS de JAMF Trust.Lorsque le VPN Cisco est monté, le filtrage WEB ne fonctionne plus.Lorsque je désactive le VPN, le filtrage fonctionne à nouveau.Avez-vous déjà vu cela ?Pourriez-vous s’il vous plaît avoir une solutionMerci beaucoup pour votre aideTraduit avec DeepL.com (version gratuite)
Has anyone successfully implemented Classlink as their Single Sign Out for Jamf Pro?
Hello,I'm currently developing a profile automation system on Jamf Pro and I'm having a problem deploying wallpapers. I want to automate their deployment but I don't want to go through device commands. So I've opted for smart groups in the Jamf GUI, but I can't find anything to modify a smart group from the api.Do you have any ideas?
Hi, we have a situation where we're seeing several devices that have recently checked in but aren't provided inventory updates which means some of our policies aren't kicking off. Is there a way to force a recon in this situation? Do we scope a recon specifically to these devices and when they check-in next time it should kick off the recon? Or is there a better method to handle this?
We are implementing a "home made" solution so our AD students can login into specific Macs on specific time remotely using Screen Sharing.In order to complete our solution, we thought on activating Screen Sharing (not ARD) on specific hours by sending scripts to activate/deactivate Screen Sharing.We haven't found the command lines to add users/groups to the "only these users" menu.Yes, it is easy to do it with ARD (ARDAgent / kickstart), but we need to use Screen Sharing.Anyone knows the commands to set specific users to use Screen Sharing ?
Hello, I am new to this discussions, but I have already found here so many solution in the last few months that I decided to create an account in the hope that someone will be able to help me on an issue that I have and for which I haven't been able to find a solution on Google. At work, we have 3 WiFi SSID, One for laptops, one for smartphone and one for guest.The smartphone and laptop wifi have a lot of security and uses the AD account for connection.However, for the guest WiFi, it has a standard password and is "outside" our network. With these command line: security delete-generic-password -D "802.1X Password" -s com.apple.network.eap.user.item.wlan.ssid.Laptop security delete-generic-password -D "802.1X Password" -s com.apple.network.eap.user.item.wlan.ssid.Smartphone We are able to remove the Laptop wifi password on Keychain Access. For both Laptop and Smartphone. However, we are having an issue for the guest network.Unlike Smartphone and Laptop WiFi, as well as having the
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!