Get Support
Recently active
Hi all, I see that there is an option to prevent changes to bluetooth for iOS devices.My question is, does the Jamf have the ability to disable bluetooth entirely? We have a security requirement to disable it.Thanks!
I have a list of computers that I want to run a script against it. However, they don't have anything in common that I can use a smart group. I was looking at static groups with no success. Is there a way that a .csv or plain text file can be uploaded to get a group created? so I don't have to manually do 50 endpoints.
Trying to do zero touch with our next batch of computers, so I've been working on a new Enrollment Profile. Everything's working well...with one exception.The test computer is in prestage with all the user fields filled in. The idea was, they turn on their MacBook, get to the Create a Computer Account screen, and everything's prepopulated (and can't be changed) except the password. So in the Enrollment Profile under Account Settings, I have "Pre-fill primary account information" checked, then "Device owner details" for Information Type, then "Lock primary account information" checked.What's happening is actuality is nothing's getting prefilled. All the fields are blank on the Create a Computer Account page.The one curious thing I'm seeing is that when I look at that computer in Jamf, sometimes the User and Location fields are still blank by the time the computer gets to the Computer Account screen — almost like the prestage info isn't getting to Jamf fast enough to prepopulat
Hi,it seems a couple of my VPP Tokens have been revoked. The token all come from the same Apple School Manager. Is there anything I can do about this myself? Renewing the Tokens does not do anything. Jamf Support is responding really slow and the situation has been like this for a month now. Any Advice would be appreciated.
We are having an issue with some of our devices where we can't change the password on the local user. It Brings up this message. This has something to do with this option checked below in our prestage. Is there any way to fix this problem? It affects most of our staff as we are switching over to Jamf Connect. Any advice on how to fix this? We do not use this anymore.
Is there any way to customize the Jamf Pro administration interface with colors, background or logo ? (Except just dark and light mode)When working with 3 different Jamf Pro enviroments back and forth, it is easy to make changes in the wrong environment.
We have a user who has just started and they have a personal iPhone backed up to iCloud. We want them to be able to restore this backup to a new, managed iPhone but it doesn't seem to work.We wipe the Managed iPhone and allow Proximity Setup, the Personal iPhone sees the Managed iPhone and goes through the steps to restore and it appear to be working, however after enrolment through our IdP the Managed iPhone goes to the Home Screen and nothing happens (apart from our required Managed Apps being there).Does anyone have any success doing the above? I'm wondering if it's even possible to do?
I've started looking into the Jamf+Intune Device Compliance, but I'm having a hard time finding what all this will gain for us. My organization currently does not use Conditional Access in Jamf or Intune. We might at some point start, but that is a ways down the road at best. Other than access to those Conditional Access Policies, are there any other benefits to enabling Device Compliance?
Hello everyone, I would like to activate and configure Platform SSO via Jamf Pro for our macOS devices. The aim is for the user to be able to log in directly to the Mac with their Microsoft Entra ID account. Can someone send me a link to some documentation? Or does it not work yet? I would be grateful for any information. Best regards
Hey folks..Does anyone have any experience working with the platform SSO feature of Ventura? One of our clients would like to use it, as they do not have a budget for Jamf Connect. I'm not really finding much info on how to setup in my Google searches.
I have around 30 MacBook Air computers which were shipped with macOS Big Sur. I was thinking of creating a static computer group and add the serial number for those MacBooks so that I could then add them to a policy which updates the software from macOS Big Sur to macOS Sonoma when the user logs in. Is this possible? The devices I have are PreStage enrolled for ADE. I'm still early in learning more about JAMF so if anyone had some advise or direction on how to go about this that would be greatly appreciated. The use case is that just now if we give one of these to a user it will enrol on Big Sur which is unsupported. Is there a better way? Can we upgrade them to Big Sur then erase the MacBook so it then enrols and installs macOS when next user logs in? As far as I'm led to believe this would install macOS Big Sur again as this is what the device was shipped with.
Is there an easy way to make the settings for more admin groups? They will have same privileges, but to different sites.We have 37 different groups to same amount of sites. Each groups have to admin one site. We are using SSO for admins, who comes from AD.
We have started using the MDM commands to "DOWNLOAD_AND_INSTALL" Apple Updates with a postpone option. The end user will get the notification like this The problem that we are seeing, is that if they click anywhere on the message, other than "options" button (not in this pic) the message just goes away. Then you have to wait 24 hours (give or take) before it shows up again.I'm not sure if this is something that i have configured incorrectly or just a "bug" from macOS.Has anyone else seen this? We are on macOS 13.x and Jamf 10.40.1
Hello,1) We want to name our Macbooks based on below criteria: Prefix + 5 digits 00001 --> 99999.No duplicate should be created.Process should be silent or at least automated.2) We want as well to rename already enrolled computers using same criteria:Prefix + 5 digits 00001 --> 99999.No duplicate should be created.Process should be silent or at least automated.We intend to apply this naming convention on:Most machines are DEP Enrolled.Some are Self-InitiatedJamf Pro looks limited in this context.Any ideas ?
Part 1: Download Server Token from Apple Business ManagerLog in to Apple Business Manager: Go to https://www.apple.com/business/.Access Preferences: Click your account name in the bottom left corner and select "Preferences."Download Server Token:Click on "Payments and Billing."Under the "Apps and Books" tab, click "Download" next to the appropriate server location (ensure it matches your Jamf server region).The token downloads to your computer's Downloads folder (usually named something like "com.apple.vpp.itunescontent.serverlocationtoken").Part 2: Configure Volume Purchasing in Jamf Pro/Now Open Jamf Pro/Now: Launch the Jamf Pro/Now application.Go to Settings: Click on "Settings" in the sidebar menu.Access Volume Purchasing:In Jamf Pro: Under the "Global" section, click "Volume Purchasing."In Jamf Now: Click on "Volume Purchasing" directly.Add a New Location (Jamf Pro only):If this is your first time setting up Volume Purchasing, click "New."Enter a descriptive name for the
We have a requirement for a Kisk devices on our reception for a Power Apps built for visitors.I am utilising a single app mode to deploy this. However the application is not installing without entering the apple id.
Hey ya'll, we are about to roll out Jamf Connect to our users and I'm struggling with how to report our progress. Currently, we have a policy for the Jamf Connect app in our self service, and I can look at logs to see who ran the policy. My concern is if these logs get flushed. Is there a place to see my current Jamf Connect license count, and even better to see which devices are using a license? Thanks!
I'm trying to pair an airtag to an iphone and I get the error message "your device management settings do not support airtag". We have no restriction in JAMF for this. The only similar post I could find "Can't pair airtag on ipad" was caused by "Devices tab in Find My app is disabled" remaining in the device profile. I have searched for this and it is not present on the device so I'm not sure what is going on.
A multi-step process to help Jamf Pro admins zero-in on policy failures Background We recently executed a single-script Jamf Pro policy on All Computers and observed a 99.4 percent success rate. While this could certainly be viewed as an A+ result, what to do about the remaining 0.6 percent? Continue reading …
Hello, We've had content filtering enabled on all of our students iPads. We had a case where explicit content was seen via search on Safari. The interesting thing is that this same configuration profile is pushed to multiple iPads, but its not being applied to all of them. It shows as pushed and active configuration profile on the device, the restriction is visible under Profile > Restrictions. 1. iPad #1 is iPad 5th gen on OS 14.4.2 and the configuration profile works as it should. Searching for the term "Sexy" gives the restriction notice. 2. iPad #2 iPad 9th gen on OS 17.4.1 and the configuration profile seems to be ineffective. Searching for the term "Sexy" shows explicit content. I've gone through and compared the other configuration profiles to see if there is any discrepancies, to no avail. What could be causing this issue? Why is the content filtering being applied to one device but not the other? We are dealing with this scen
Hi there, I have a script that runs once on each machine in our macOS fleet. The script essentially creates a launchdaemon that runs a script that kills and restarts jamf binaries on machines once a day to mitigate the jamf checkin issues (no we do not have a force restart schedule). Issue I'm noticing is that some devices (about 50) even though they have the launchdaemon loaded it doesn't seem to be restarting their Jamf binaries. My thinking is it may be the script that is not working as intended. I intend for the restart script to be re-ran everyday on the local machine but some devices have not checked in for weeks now. #!/bin/sh cat << 'EOF' > /private/var/tmp/JamfRestart.sh #!/bin/sh sudo killall jamf sleep 10 sudo jamf policy EOF chmod 755 /private/var/tmp/JamfRestart.sh chown root:wheel /private/var/tmp/JamfRestart.sh cat << EOF > /Library/LaunchDaemons/com.JamfRestart.plist <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//A
Hi all, I'm changing a configuration profile to exclude the local admin account for the password complexity requirements. I'm wondering what affects this may have on existing local accounts on the MacBook. Will they be forced to change their exisiting password? Will the timer on their password policy restart? I'm kinda nervous to hit the distribute to all right now because I'm not sure what the effect will be.
Hello JAMF Nation, Has anyone been able to successfully create and package with the WFBS Trend client to be pushed out via policy in JAMF every single attempt I have made as resulted in failure or corrupted installations. I have found several posts here, that have helped with potential ideas but unable to get anything going successfully. Keep in mind I am a JAMF NOOB but am learning more and more each day. I have 30 machines that are out in the field and have been tasked to creating packages for: Skype for Business WFBS TrendMicro That are a bit of a challenge any assistance would be greatly appreciated. Thank You
Hello Jamf Community, We are currently in the process of setting up an on-premises Jamf server but have encountered an error. The computer begins to enroll with the MDM after entering the user credentials in Remote Management, then retrieves enrollment profile, begins to install enrollment profile, then gives an error. The error: Enrolling with management server failed. Unable to contact the SCEP server at https://our-server-domain.local:8443//CA/SCEP Has anyone experienced this issue, or know what is causing it and how to fix it? Also, I am not sure why it is inserting two forward slashes after the port and before CA: 8443//CA. Any and all help is greatly appreciated. Thank you.
We're doing some testing in our QA environment and configured all our Config Profiles to match what is in Prod. We've enrolled 4 Mac's and they show Invalid and the Recovery key is super long. I did try the github reissue filevault key, also escrowbuddy and ran the files and processes command, but neither work. When I run the reissue command and type in password and it's successful and I run a jamf recon, the recovery key validation changes to Valid, but the recovery key is still wrong and when you refresh it, it goes back to Invalid.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!