Get Support
Recently active
Hello. I am fairly new to Jamf Pro and in the process of learning while cleaning up some of the work that was created before me. I have a question regarding pre-stage enrollments and the best practice for moving forward. Currently, our iPads are not automatically assigned to a pre-stage enrollment as we have 4 different pre-stage enrollments. This leads to devices never being enrolled in Jamf as they are shipped out to the end user. I would like to automatically assign all iPads to our generic DEP pre-stage enrollment and then manually move the ones we need in a different pre-stage enrollment. We will not need to do this often and this will at least allow us to have all iPads enrolled in management. Am I correct in thinking that devices already assigned to a different pre-stage enrollment will stay there after this change is made, even if wiped? It is my understanding you can only have devices in one pre-stage enrollment at a time and you have to unselect the one it is currently assign
Hello all, I'm new to JAMF and I was wonder if there a way to change the names under Browse in Self-Service? By default, It group all the software and policy group under "All" , Can I change it to something else like "Software " ?Thanks for the help.
Fellow Jamfnation citizens, While macOS High Sierra is not anymore supported by Apple, does Jamf still allow to install jamf binary on Macbooks with unsupported macOS and allow to manage or supervise them ? Does the same apply to other unsupported macOS like Big Sur and Catalina?
Hello , Im using this Make Me admin Script https://github.com/jamf/MakeMeAnAdmin , it works perfectly to give the user admin acces , but where i can find the logs ( to see what the user did with the admin acces ? Thank you
Hey all I'm new to Jamf School. I'm trying to do a pilot program this year for Jamf Teacher and Jamf Student for our ipads. I currently have Jamf teacher and student working well. However, I can't get Apple Classroom "View screen" to work. I went through the Jamf Restriction settings and allowed for Apple Classrooms to view the screen. Anything I'm missing, any settings that are hidden on the jamf school side?
Is there anyway to manage Opera browser? I searched in Opera not able to find mcx/configuration profile.
Monterey: https://swcdn.apple.com/content/downloads/62/35/052-09275-A_9GJLP5ERYO/bn3yyowf9ulxzdfmu7ia1ihnh7at3rw2s1/Safari17.5MontereyAuto.pkgVentura: https://swcdn.apple.com/content/downloads/20/22/052-69114-A_HXAGLW506N/2eosf2mygag5y38grze3znqgmnss0bbpdd/Safari17.5VenturaAuto.pkg
We have a user getting the below error and can't access anything. The help desk also reset the password. A couple of commands were ran, the removeFramework command was ran and they then tried the profiles -renew -type enrollment, and get the Update prompt and it opens system preferences and then I choose update again, but it looks like it doesn't do anything. I can see all the profiles.
I am trying to run a series of reports in Casper Inventory that sort the laptops in my deployment by last check in date, and anything that has not checked in to the JSS in over 4 weeks. The report works fine, but it fails to add in the user's short name or long name. I would really like this to work since I can just generate this report and hand it off to someone in administration and they can make sure these laptops are still here. I know some students come to school and turn their airport connection off, on purpose, because they know that we use remote desktop and push out updates over the network. Other machines are off site at the repair center. However, I would love a way to audit everything off my notes and off of my records for repair. I also have some machines that have not checked in for a whole year, now these machines I think had a major component replaced and/or the asset tag replaced and it is in inventory as a different machine. Any way to make it so the sho
So in https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/Apple Says: "Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on."It seems like we would want to keep the end user from enabling this on MDM devices. Has anyone seen any documentation on how to disable Lockdown Mode? I can't see any in any MDM reference publicly available.
A user has rebooted their AD Bound Macbook after updating the device to Ventura. They typically sign in with their AD account that has been made a mobile account. Now suddenly when they try to login they are greeted with a page that only allows them to enter the password for the guest account (Which we never enabled as far as I'm aware.) There is no option for the 2 local administrator accounts that are meant to be on the device nor the staff member's mobile account or even other user to manually enter credentials. I have a suspicion this has something to do with the ventura upgrade vs AD. Has anyone else encountered this issue?
I'm trying to set up Nudge which is a program that pings users to update their computer. I have everything in the JSON file setup, but I can't seem to find a way to create a URL for the button "Update Now" to take them to software update. The default uses "munki://updates" and the instructions take you to Jamf Self Service for macOS URL Schemes which seems to only take the user to Self Service? Would you have to make the button point to Self Service and create a link in Self Service that takes the user to Software Preferences? Forgive me if this is simple, I'm new to Jamf (and IT) and Google doesn't seem to have an answer. Thanks!
Hello,I have added 1Password8 to the Jamf App Catalogue in our Jamf Test instance, On the Deployment status tab I'm getting App Installer deployment status Unavailable The App Installer deployment status cannot be retrieved. Check your configuration settings or refresh the page.I have verified all the settings and it seems correct to me. I'm not sure what if I'm missing something or?Can I get some assistance on this to fix this issue?
Hello All, So I work for a college with a large distribution of apple TV's managed by JAMF. We're looking to stream an event through YouTube and would like to push it to the TV's. We have the YouTube app installed, but is there a way to configure the app through JAMF to automatically go to a particular channel or YouTube URL? This way the tech's don't have to go around the entire campus with fiddly Apple remotes to pull up the stream.Thanks,
Hi Everyone,Just wanted some opinion and advice on this. We have been Using JAMF Pro to manage our Mac OS and iPad OS since 2017. We just had a change of management and the IT Head wants to implement Microsoft Intune to manage all devices including macs and iPads. We currently use SCCM to manage windows devices and JAMF Pro for apple Macs/iPadsHis idea is to get rid of both and just use Intune to mange all devices. Can Intune do everything that JAMF can? Any feedback on this would be appreciated.
We have a local administrator account created as a part of our prestage and manual enrollment processes. It has no counterpart in our IdP (Azure in this case). However, the Jamf Connect Menu Bar app launches and demands a username and password.Dragging the window off the side of the display is an ugly solution. Is there a way to exempt a specific user/group from needing to connect with (or even launching) the menu bar? I thought it might be a Login Item, but no such luck.
Today we released Jamf Connect 2.35.0. This release includes the following changes and improvements: The new URL Scheme and Command Line Elevation (URLCommandLineElevation) key prevents unsanctioned privilege elevation via URL schemes and the command line interface. Elevation from the command line interface is only allowed when URL Scheme and Command Line Elevation is set to true. The ZIP file from the Collect logs button now includes the com.jamf.connect.actions and com.jamf.connect.shares domains. Resolved Issues [PI116170] The Jamf Connect login window now informs users their account is locked after multiple failures to enter the correct password on computers without FileVault encryption. [PI117370] Configurations of the Jamf Connect menu bar app with Kerberos no longer experience password expiration timers not resetting after a user successfully changes their password. [PI117524] Jamf Connect will now notify users when a privilege elevation denial occurs due to loc
I used Radar to create a ZTNA + Next Gen VPN activation profile for iOS, exported and used that in Jamf Pro to create two iOS Configuration profiles, for Supervised and BYOD devices. These contain per-app VPN payloads that match the setup instructions. Uses our Entra identity provider. I configured the apps to use the VPN, and everything appears to work. JAMF Trust App lights up green, VPN Settings shows wpa.wandera.com:32005 with the correct apps listed. Radar sees me, accessing the sites, which it says it's allowing. VPN icon briefly appears when I pull up the apps. But no data is loading through Outlook or Teams. Push notifications are coming through but I can't get it to sync any data.I followed the instructions here to add additional hostnames to the Traffic Matching tab of the Access Policy config, which is set to route 365 apps through America West. I've added the IP ranges for both East and West IP pools to my Entra Named Locations. Notably I am not seei
Has anyone seen this before? Suddenly when trying to sign in(for the first time) to newly enrolled AD joined macs, I am getting this lego block icon with an OK option. Click it, screen goes black then hit any key and youre back at the login screen.The only changes I made yesterday were with application policies. I would start there, but first I need to know what this icon is? Literally cant find anything about it online. Pretty frustrating. Has anyone seen this before? I also dont follow the logic of "removing old app policies and fixing ones that havent been working" breaks AD logins? I join new devices manually. I set primary domain controller, add directory admin group, create local account at login without confirmation, dont set UNC path, home directory is /bin/bash. Nothing has changed. I just set one up yesterday and its fine.Im assuming its related to policy changes I made, some how, but I cant find anything about this useless error icon. Has anyone seen this? Thank you.
Hey everyone,A device in our fleet recently stopped communicating. I checked and sure enough: Last Enrollment: 21/03/2022 at 12:52 PMMDM Profile Expiration Date: 21/03/2024 at 12:52 PM We have the default renew 180 days before expiry so was a bit confused. Check logs and see Failed Command:Command: Renew MDM Profile Error: The Device is locked Any thought on why this may have happened? Guessing only solution is to wipe and re-enrol? TIA.
We have a bunch of printer presets set for our users. We use "Find Me" printing with our fleet of 50+ Canon copiers. I would like to configure Presets so our users can select "Last Used Settings" if they like, but it is always going back to "Default Settings". So I am wondering if this feature is NOT available??? If I send out presets, can I not allow my users to select "Last Used Settings"?
Hello All,I am going to renew the JSS Built-in CA certificate, I saw in JAMF site that the signed config profile might be affected, so I want to generate a report of signed configuration profiles in my JAMF cosnole before going to renew it. If needed I will re-push by re-creating/cloning those CPs, but how to generate a report of such signed CPs from JAMF console.JSS built-in CA gets expired in 10 years so this is the foirst time I am going to do it. Your help will be appreciated!
Hi Jamf Nation, I hope someone will show me the light here. The screensaver activation in Ventura with Jamf Connect for login access doesn't work. Yes, I know an active user needs to be logged in for the screen saver to start. Still, in Mac Labs and classrooms, we have a multi-login environment where idle users get kicked out after a determined period of inactivity. Then the Mac sits at the Jamf Connect Login screen until is in use again with no screen saver running and burning the display for hours of inactivity. I'm staying with Ventura until the JAMF screensaver module is updated and compatible with Sonoma. Cheers!
Hi,I've been testing Remote Assist and it works like a charm apart for one thing:The documentation mentions being able to do 'Unattended Sessions' - I've not been able get it to work without having a user logged in at the other end.Anybody have much luck with this?Regards,Steve.
Hey Everyone! Jamf Connect: 2.32.0macOS: Sonoma 14.3.1 A little back story here. We have Jamf Connect setup with Azure/Entra as our IDP. Our organization is working on moving from a Local on premise AD to Azure/Entra cloud only solution. With that being said I made some cloud only accounts in Azure/Entra and have been playing with new cloud only groups for Jamf Connect with the "Standard" and "Administrator" roles. I have no problem logging in as these cloud accounts with a standard or administrator role. Here is where I am stuck, on a login with my account which originates from LocalAD and is synced to Azure/Entra I am prompted to do MFA via the Microsoft Authenticator app at the Jamf Connect login screen when I restart or come up from a shut down to unlock the Mac (THIS IS WHAT I WANT) the PROBLEM is with these new Azure/Entra only cloud accounts I am NOT prompted for MFA even though it is setup for the user and they are not in any exclusion groups or CA policies that
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!