Get Support
Recently active
Hi Jamf Nation Team,Is there an automatic way to move the inactive Macs from one production site to another? We have identified the Macs that need to be moved to the inactive site, but can we move them automatically when they reach the "inactive" status?
Hello, I'm at the point where I had to create Sites in Jamf. I've never had a problem adding VPP licenses to apps but now when I scope an app, i.e. GMail, to "Campus A", I get "Content not available to assign to mobile devices". If I remove the site (in other words Full Jamf), I can assign VPP to the apps. (I tried adding it first to Full Jamf and then changing it to Site and I still had the same problem).Do I need to add these sites to ASM?
Hello, I applied a "Facetime Deletion" and " iMessage App Deletion" within the Restricted Software. The process name I used was -----System/Applications/FaceTime.app and /System/Applications/Messages.app I restricted the exact process name, applied "delete application" and "kill process". Both apps still appear on the dock bar on the test Macbook laptop. Am I missing something?
I have a Mac mini that after upgrading to Monterey 12.7.5 will not allow a password to be entered. Tried multiple keyboards (this machine is usually headless). Keyboard still works in recovery. Mouse works at login. No policies/CPs have been scoped to limit input. Was fine before the update. Anyone seeing something like this?
Hi Everyone,Is there a method to automatically enable LastPass in the browser? For instance, without having to manually click on the extension icon in the browser.Thanks,Kenneth
So we have found for a managed and a non managed Sonoma machine, there is a bug in Apple's Lockdown mode.In order to enable Lockdown mode, one must be an admin on the machine.Once Lockdown mode is enabled, one can no longer use Apple's ARD program or ssh into that device. This is to be expected based on Apple's documentation.We also have an additoinal admin type account on our machines so the Tech department can work on machine without the end user's login information. We could log in with that account, go to systems prefs and disable.HOWEVER disabling lockdown mode with the other account DOES NOT restore the ability to use ARD or ssh into the machine.I have reached out to Apple and our Apple SE but have received no followup communication.
Hello All, We noticed that mac users are getting kicked out from Zscaler, and internet is becoming very slow. In that case we are supposed to loginto Zscaler manually, any idea why it is happening? Is it specific to macOS version? What is the solution on this? Any log can help me to do the troubleshooting? Please tell me the path of that log to collect it.
Looking to limit UIE to a specific group via SSO and/or Cloud Identity Provider (Azure).Currently we have SSO configured via Okta and CIP setup with Azure. Anyone got ideas on how to do the restrictions? I've tried adding the group under Access, but it still allows all users.
We are investigating potential inconsistencies in device registration status for the Jamf Pro Device Compliance integration with Microsoft Entra.Observations:Devices are marked as non-compliant in Microsoft Entra despite appearing as compliant within Jamf Pro's "Compliant" Smart Group.The Jamf AAD plist file and the MS-ORGANIZATION-ACCESS keychain entry go missing on affected devices.Re-registration through Self Service/Microsoft Company Portal temporarily resolves the issue, but devices fall out of registration again after a period of time, then fall out of complaince. (approximately two weeks).Environment:Jamf Pro version: 11.4.2 (presumed not to be related to recent product issues)Request:I would appreciate any insights from the community regarding similar experiences or potential solutions.
Hello,I'm looking for Managed login items in profile configuration. I've seen it in documents and video (see screenshots), but don't see it in my Jamf Pro.My interface is in French.Where is it?
Talk about a BS money grab
I've run into a troubling issue.I used the JAMF Software update BETA Install Action to set a "Download and schedule to install" for last Friday night with a deadline just before midnight Friday.The scope was for macOS 14 devices to update to macOS 14.5On Monday morning, two users had reported that they were stuck at a Recovery Mode screen - asking to "Enter your recovery keys to unlock the volume Macintosh HD".I supplied the escrowed FV2 keys to the users. One user was able to move beyond the Recovery screen and work normally - now operating on macOS version 14.5Unfortunately, the other user is not able to get past the screen - with the error "The supplied password failed to unlock the disk".I don't know if I have any options to get past this, with the JAMF escrowed key not working.Thanks for any thoughts.
Hello Team,After installing Nudge and pushing the configuration profile, the Nudge Agent do not open. We have 12.4.0 version of OS Installed.Please let me know what is that has to be changed/Modified. I've install Nudge_Suite-1.1.8.81421.pkg and configured the profile too.Upload FilePLIST file containing key value pairs for settings in the specified domain <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PayloadContent</key> <array> <dict> <key>PayloadContent</key> <dict> <key>com.github.macadmins.Nudge</key> <dict> <key>Forced</key> <array> <dict> <key>mcx_preference_settings</key> <dict> <key>optionalFeatures</key> <dict> <key>acceptableApplicationBundleIDs</key> <array> <
Hello,We are currently in the process of utilizing Zero Touch Deployment for JAMF Pro and also need to deploy JAMF connect but are having some issue on the EntraID side for verification. I am thinking of going ahead and deploying enrollment and utilizing a local account on the computers while I continue to test/troubleshoot Jamf connect and installing at a later date through a policy. If I was to do this, and when ready to deploy connect enable the "convert local account to network account", would the users documents/programs/setting etc. remain in the converted account or will it delete them? I ask as we have to have a 3rd party install a proprietary program onto each of the computers prior to giving them out to employees and I don't believe JAMF connect would be set up in time for our appointment.I appreciate any insight!
I recently got the Return to Service workflow working on some test iPads. When I deployed it to my student iPads and tried to run it manually through the app it returned the following error message in the management tab in JSS: Erase DeviceMDM profile is required for Return to Service on this device. I'm a bit confused by this message because the iPad is present and checking in since the app got pushed out just this morning. Trying to search for this error message is getting a lot of generic MDM results so I'm hoping someone else might have come across this with RtS or something else and it's something easy I'm completely overlooking.
We have been creating a local Administrator account during enrollment on every machine. We are now questioning whether this is necessary at all. Currently all of our users are administrators and we do not use standard accounts. Can anyone think of a good reason as to why we would need another administrator account on the machine?
Hey everyone, we're currently working on upgrading to MacOS Sonoma using Jamf Pro as Admin. We're looking for a way to run the upgrade overnight without requiring end users to enter admin credentials. According to Apple Support documentation, users need to be volume owners to initiate the upgrade, but they still need admin credentials to do so.https://support.apple.com/guide/deployment/about-software-updates-depc4c80847a/web#dep7d4a58bedCan we implement any type of policy to run the upgrade without asking for admin credentials?
HiI am trying to ascertain the ECCN number for Jamf Connect. I cannot find this on the product document. Is anyone able to help? Thanks
I've been testing out a script to run the following command in Terminal: sudo dseditgroup -o edit -d <accountname> admin The command works fine when you put in the account name, but of course this is not ideal when there are about 100 Macs in scope. Is there any way to invoke the "current user" to be added to the line above? Ideally the script will check who is the current logged in user and remove their administrator rights. FWIW these are mobile AD accounts with local admin rights. Thanks!
How do you get SMB network shares to mount using Jamf Configuration Profiles, under macOS Mojave 10.14.5? All that I have seen is various bash and AppleScript scripts. I was looking for a way to mount the shares without resorting to scripting.
I'm looking at integrating some Macs with Azure AD. I had a call with a Jamf sales guy today about Connect and he mentioned there was a feature that in Connect that didn't work without using Jamf Pro as well. Something to do with local account / password synchronization with Azure AD. Does anyone have an idea what that is?We already use Intune as our MDM, so I don't plan on shelling out money for another MDM solution as well.
Hello, not a direct jamf question however i have configured the Kerberso SSO Extension and working fine. I want to create a launchAgent/LaunchDaemon to trigger a script when com.apple.KerberosPlugin.ConnectionCompleted i have as below but not working. Any ideas on how to get this working ?When i run launchctl list | grep the namei get error 78The script working fine when ran from terminal.launchDaemon.plistKeepAlivetrueLabelname.plistRunAtLoadtrueProgramArgumentspathtoScript-notificationcom.apple.KerberosPlugin.ConnectionCompleted-actionpathtoScript/nameofscript.sh
Hello community,I've seen a tremendous number of posts related to this issue. During DEP enrollment using a PreStage Enrollment configuration, the local MacOS account hangs for a while then fails with the error "Computer account creation failed".A high number of posts refer to the potential fix as being related to any of the following, which I've diligently tried to no avail:Complete wipe and reinstall of MacOS, removing any potential leftover files, users or authorization keys that might lead to the issue.Ticking and unticking of the "Setup Assistant Options" in the PreStage Enrollment configuration, which allows administrators to skip configuration steps during first-time enrollment.Skipping the local account creation altogether, creating a standard account or creating an administrator account through the PreStage Enrollment "Account Settings" page.None of these worked. However, I've tried creating a new, empty PreStage Enrollment, and adding back my desired settings, configuration p
HiWe are testing using intune to deploy an app in Kiosk mode with devices DEP enrolled. Everything is working great but we are trying to plan for different scenarios. Anyone know what happens when there is a Wi-Fi failure, if you're in Kiosk mode you can't get out to reconfigure the Wi-Fi , if your Wi-Fi has failed the ipad can't pick up the new profile moving it out of Kiosk mode to configure it. As well anyone push an enterprise cert for Wi-Fi for devices.
We were using Pulse Secure (and its older version, Junos Pulse) VPN software in our environment but have since upgraded. In looking for a way to remove the old clients we ran across their uninstallers. Running those prompted the users to save the old settings and notified them when the uninstall was complete... We didn't want this! Found a way to make it silent! If you dig into the uninstaller app, you can see that it's just calling a simple shell script that allows for arguments for ignoring all prompts and not saving the old config. I'm posting those one liner scripts here for anyone else who might be looking to do the same! Pulse Secure: !/bin/sh sudo sh /Library/Application Support/Pulse Secure/Pulse/Uninstall.app/Contents/resources/uninstall.sh 0 Junos Pulse: !/bin/sh sudo /library/Application Support/Juniper Networks/Junos Pulse/uninstall.app/contents/resources/Uninstall.sh 0 Now just build the Jamf policy to call these scripts and update maintenance. Set it to re
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!