Get Support
Recently active
Hey all!Sorry that this question is a bit off topic. But does anyone know if there is an equivalent to Jamf Techer (and/or Apple Classroom) in the Windows/Intune world?
Hi, were currently having some issues with our network thruput. Ive been looking at ways to save some of what we have, and have noticed that i could manually enable low data mode on my iPad. is there any way that i could roll this out through Jamf School, where we already distribute the network information and our global proxy thanks
We are attempting to use the mass action to update iPads (~10,000 in batches of 200-300) in our environment, but updates are seemingly being hung up in the pending commands when there are other pending/failed commands.I've tested on numerous iPads to confirm that clearing out old pending/failed commands (sometimes these are months, or even years, old) and running update inventory allows the update to go through normally.My question is...is there a way to mass cancel pending/failed commands, but excluding certain commands? I don't see any issues with mass cancelling failed commands, but I am concerned about mass cancelling pending commands where a device may still have an important command pending - Wipe Device, Enable Lost Mode, Unmanage Device - that would be processed when the device checks in.
SO Apple will release a new way to install apps in the EU starting with iOS 17.5. See link:https://developer.apple.com/support/web-distribution-eu/Question is, how do you block this from an MDM standpoint? I haven't been able to find any documentation on if there's an MDM restriction setting for this, if it's included in the previous key released for 17.4 or if this is currently uncontrollable via MDM. Has anyone else seen anything about this?
I have students grabbing other students' iPads. And. Get their password by clicking on the Wi-Fi. Settings.
Hello everyone,Just want to know if anyone knows if Microsoft only uses Jamf for Mac or for all types of Apple devices at their office?
With the modern requirements for authentication to wireless networks, using 802.1x with certificates is becoming necessary.I have been trying to search for more information as to whether JAMF School can deploy client certificates, but everything I can find relates to JAMF Pro (which I know can do this very well).Any pointer to documentation or solution to suggest?
Hi Jamf Admins what can we do about screen time when parents set it?Can this setting be deleted via the Jamf Portal or is it only possible via the iPad itself or Jamf Parent App with clear Parent restrictions?If it is not possible to intervene via the Jamf Web. Will it be possible in the future/near future without Parent App?Because otherwise the iPads are restricted in the classroom or interfere with functions if the screen time is set by parents or students.Thanks for your feedback.Nice RegardsPeter
Hi there, is there a way to get an extension attribute in Jamf to report a target file's last modified date?
Hi there, does anyone know if Installomator has a "block app from launching" option or if there is a way to script a block app launch until an update to completed. Currently in our environment we have Installomator handling patch management with SwiftDialog, users still decide to launch whatever app is being updated while the SwiftDialog clearly shows it is updating 😑 Ideally would like to be able to block the app from launching while updating or to have a separate script that will block the app from launching until the update is completed.
Mostly Sonoma 14.4.1 OSWe have a Configuration Profile that has Require Passcode, Complex Passcode and Alphanumeric Value along with values in the rest of the settingsThis prevents the users from changing values in Lock Screen for Start Screen Saver when inactive, Turn display off on battery inactive, Turn display off on power adapter when inactive and Require password after screen saver begins or display is turned offI removed this from a target computerI cloned this configuration profile and added the clone to a target computerThis resulted in users being able to change the values for all of these itemsFor compliance we need to set Require password after screen saver begins or display is turned off to Immediately and prevent users from changing this valueI have been looking in Apple documentation and Jamf Community but the closest I have found was an un answered question at the bottom of the post from 03-27-2024 https://community.jamf.com/t5/jamf-nation/don-t-require-password-after-s
Hello all, I am running into a problem with 2 colleagues who use a Macbook. Usually when they start the Cisco anyconnect VPN, they log in with their credentials and the anyconnect client remains on a blank page.After restarting the applications more than 10 times, it works againSee the screenshotsThey are both on a different MacOS. One is running 14.4.1 and the other one is on 14.1.1.And they both have the latest version of Cisco anyconnect VPN 5.1.2.42. They experienced the same issue at the older version: 4.10.07061The rest of our laptops in our organization run on Windows, and none of them have this problem.Does anyone recognize this problem and perhaps know how we can fix it? Any help is greatly appreciated!
I'm starting to investigate restricting access to the App Store on our macOS, iOS, and iPadOS devices. The technical side is easy enough with just a config profile, but I'm unsure what will happen to existing machines that have installed things from the App Store. I don't think these applications will be uninstalled, but I'm not sure about if they'll get future updates. Can someone clarify the behavior around existing App Store installs after the App Store has been restricted?
Hi, I've been back and forth with support for over a week trying to get Jamf Connect to issue a user certificate upon connection. I've got a User Certificate Configuration profiles in Jamf that i can request certificates through self service with no issues. But for some reason, Jamf Connect just can't handle the request. Our CA admin can't even seen any failed requests from any of my test machines trying to request certs. Kerberos appears to be working as i'm able to generate new tickets with a good connection to Jamf Connect and SSO works with all of our SSO secured sites. in the Jamf Connect logs when a connection is made i'm receiving the following:I'll be the first to tell you that i think certificates are magic so i don't fully understand them. And I'm not sure what "Certificate doesn't match current user principal" means. We're authenticating through OKTA to get our kerberos Tickets. In the JAMF connect logs I can see that Kerberos Auth Succee
Hi,I have set up Cloud identity providers and I am wondering if there is a mechanism that will allow me to do a sync of users from Microsoft Entra ID to Jamf Pro automatically.I mean users from the "users" tab not from the system tab "User accounts and groups".How is the issue of sychronization of accounts solved ?
Hello,We have a few devices that have not checked in to Jamf pro since 9/23/23. These are active devices. What are the reasons Macs stop check-in, and how to fix these issues? Thanks
Hello all, I did some research into scripting, specifically the Outlook dictionary, when I was first developing the signature and how to create it. That is now working great and we are able to deploy a solution that removes any old signatures and adds a new signature, however I am running into an issue with setting it as the default in Outlook. This is my script: #!/usr/bin/osascript --Looks up username for dscl. No "whoami" because when deployed its run as root. set user to do shell script "stat -f '%Su' /dev/console" --Grabs information from AD and selects the needed part set fullname to do shell script "dscl . -read /Users/" & user & " RealName | awk -F 'RealName:' '{ print $1 }'" set email to do shell script "dscl . -read /Users/" & user & " EMailAddress | awk '{ print $2 }'" set phonenumber to do shell script "dscl . -read /Users/" & user &
I just added a new computer to the "Applicable" Smart Group on Jamf. Last time the connection to Intune was synced was at this morning. Any idea how to force sync this so new devices get synced?
I have tried to create a PPPC config with the utility and given a couple apps "allow" for accessibility, and "let standard users approve" for input monitoring and screen recording. while I understand these settings will not show in the macOS GUI, the users are still not able to enable these settings without admin prompt. I have only tested on Ventura, but we have a few machines (with more to come) running Sonoma. Is there something I'm missing?
We are starting to rollout Microsoft Defender and I have been tasked with tagging the Macs on the Jamf side. I have been given the XML they are using in intune but I am not finding documentation to turn that into something Jamf useable.<dict><key>key</key><string>GROUP</string><key>value</key><string>****** - ***** - *****GLOBAL ******</string></dict></array></dict>
Hey guys, So I was checking out our ABM and noticed that majority of the Macs have order history numbers that was associated with the Mac. I was wondering if there is a way to pull that data from ABM and put it into JAMF in the Purchasing section. Is there a way to do that?
This is a heads up for any organization using the Jamf Pro integration with Cisco ISE... According to the Cisco rep on a call I had a short time ago regarding Jamf's planned removal of Basic Authentication for the Classic API in the Very Near Future there is no support for Bearer Token authentication in Cisco ISE at this time (i.e. ISE 3.3), and they do not have a specific timeframe for when that support will be added but it isn't on the near-term roadmap. If your organization relies on the Cisco ISE integration with Jamf Pro I'd suggest you contact your Jamf Customer Success Manager ASAP and let them know that removal of Basic Authentication prior to support being added in Cisco ISE would not be welcome. I'd also suggest you open a TAC case with Cisco asking when they're going to implement Bearer Token authentication in ISE because it sure doesn't look like they consider it a priority given that Jamf has been saying for a over a year that Basic Authentication support was going to be r
We may be getting some new users joining from outside the USA. We are using JAMF Pro. I am guessing it will work OK in other countries, but looking for any sage advise from others who may be going this route.For example - we are about 80% zero touch deployment, but have a few things still to manually set up and check by hand. We won't be able to do a hand check for these things for people outside the USA, but we can likely remote in and manually do those things.I am curious if/how we can arrange for a Mac to be purchased and added into ABM in a foreign country. Will we need to contact an Apple rep that is local to the user? Or is it just as easy as finding a reseller locally who can do it? We want to avoid having to walk the user through connecting the Mac to ABM via Configurator.
Hello!I am curious to see if anyone else has seen this. I have noticed since macOS Sonoma has been introduced, it seems that when it gets to Locate Hardware Information (macOS version), it would take a few minutes longer than I have seen before. Now it seems to take about 5 minutes. Is this something that is common?Also, on the same area, when I do the recon command while off-network it would take about double the time. I suspect that because our Macs are domain joined, it is trying to find the domain and the OU it belongs (in JAMF, the information for the MachineOU changes from its current OU location to "not valid") before it times out.Has anyone else seen this? Please note, I don't have access to change anything, I'm a tech that uses JAMF and reports anything. :) Thank you!
Hi, How can we disable native user login on mac and have only jamf screen to login . Currently we have a painful process of login for users where they have to enter password twice one for local user and and other for jamf login screen.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!