Get Support
Recently active
Background While we're waiting for @NightFlight's Extention Attribute Execution Frequency feature request to be implimented, here's my two cents, which was inspired by @brad's approach for only occasionally capturing the status of a computer's Recovery HD. Approach As one of the first steps of an Extension Attribute script, you pass the name of the Extension Attribute and the desired execution frequency (in days) to a client-side function. A client-side plist stores the epoch and the result. During subsequent inventory updates, if the current epoch is less than the given frequency, it just reads the previous result from the plist instead of executing the entire Extension Attribute script. For example, I have an EA for “Model Name”; how many times do you need to run that Extension Attribute? (Once per quarter? Once per year? Certainly not every time.) Results Early tests show an overall inventory collection that is 1.6x faster, using the following as a gauge before and after:
hi,We use SPARK email software.With APPLE volume purchasing we have deployed the app with JAMF and the APP STORE.When SPARK makes an update and it appears in the App Store, JAMF downloads the update but cannot deploy it on the client workstations because it systematically asks for the workstation's admin code.How can I automate these updates?cordially
What are the ways to manage software updates for non-supervised mobile devices? We have several hundred mobile devices enrolled using the UI method and would like to keep their iOS versions up-to-date. I understand that the "Update iOS Version" remote command only works on ADE/Supervised devices. Is there a way to manage software updates for non-supervised mobile devices?
I am testing a reset local user password Policy in case a user forgets his macbook login password. I see this as a trigger option: "Startup - When a computer starts up. A startup script that checks for policies must be configured in Jamf Pro for this to work"What kind of Startup Script would I need for this policy to take effect? This may come up in the future and would like to have this available for a real situation. OTW, the trigger is Recurring Check-in but it doesn't seem to check-in after I reboot ans wait 15 minutes. I don't believe Recurring Check-In will happen until after the user logs in. This won't help if I can't reset the password through Policy. Any help/advice is always greatly appreciated.
We have an odd behavior in our environment for some of our machines. If you try to shutdown/restart using the GUI method - it hangs. What happens in you see the background and the mouse cursor...and it just stays there. Screen never goes black and doesn't shutdown/restart. So because it's stuck you can still SSH into the machine and run commands. So I wrote a script to kill processes to try to figure out which process might be hung. While I didn't figure out which process is causing this I did learn that if you kill the following processes(AppleUserHIDDrivers, IOUserBluetoothSerialDriver, IOUserDockChannelSerial) four times it will kernel panic your machine. Tweaked the script to avoid processes that will kill the remote session...but it doesn't seem any process I kill causes it to move forward and shutdown/reboot. Anyone experience anything like this?
We have a user who's time zone is set wrong..if we try to change it we can't as it is greyed out."This setting has been configured by a profile"I assume this is a JAMF Profile?
Hi, just trialing Jamf Protect alongside our subscription of Jamf Pro and have linked the two together via API Client and imported the Default Plan and added my laptop to the scope, but it doesn't appear to have actually installed Jamf Protect. What am I missing/doing wrong?I also note that I cannot select the option Automatically deploy the Jamf Protect PKG with plans option under Jamf Pro > Settings > Jamf Apps > Jamf Protect.
I would like to know if JAMF Pro supports "Privileged identity management (PIM)". After logging into the Jamf Admin website, we would like to require our IT users to PIM before doing certain actions. For example, before viewing a FileVault Recover Key. I know that in Microsoft Azure console/webpage, our company requests us to PIM before doing "admin" task.
Is it possible to use a pre-downloaded version of Sonoma and install it for standard users by using Nudge?My workflow at the moment is I am using Nudge without the erase and install script, because I am using a policy I run beforehand with only a single command line to fetch full installer in the processes and files tab. Nudge then opens system settings -> softwareupdate, but it looks like it is re-downloading even though there is a 'install macOS Sonoma' in the applications folder. Maybe I am missing something. I have watched several videos and read thru the wikis for Nudge and the erase and install script, but I can't find anything saying for sure there is way to do this for standard users.
We are going all online for the ACT this year and we have to use Pearson's TestNav app in order for the students to test on their school-issued Macbook Airs. They are running MacOS Ventura (or Sonoma for those who upgraded before we had the chance to block updates).The TestNav documentation says that we need to disable all of the notifications for the students while they're taking tests. I haven't been able to find a reliable way to do this. I found some scripts but they may be outdated because they keep throwing errors. Does anyone have a solution to this? I need to send a command through Jamf Pro to all of the student Macbooks to turn off notifications before the test then send another command to re-enable them after the test. Would forcing them into Focus mode do the trick?Here's the script I found. I modified it slightly by replacing "unload" with "bootout" using the syntax I found here:https://joelsenders.wordpress.com/2019/03/14/dear-launchctl-were-all-using-you-wrong/Both old an
I recently had to configure Zscaler for my environment and I figured I would share incase it helps anyone.Prior to 3.9 Zscaler was configured with a script, the JAMF documentation is eh and the got the script they provide from someones GitHub repo.[Guide] Zscaler Client Connector Deployment with JAMF Pro for MacOS - Connectors / Client Connector - ZenithWith 3.9 Zscaler is now configured with a configuration profile, which at the time of writing is documented for intune and not JAMF. Zscaler has advised they will update their JAMF Documentation, but as of 6 weeks and they still have not updated their documentation. The intune docuemtantation is simple enough to use with JAMF. Deploying Zscaler Client Connector with Microsoft Intune for macOS | ZscalerThe Zscaler app can be provided in 2 ways. The non-managed app which will not respect any configuration profiles, and a deployable .pkg which is what you want to use. Build the policy to deploy the package as usual, nothing screw
How to stop all adobe products when installing a new version of adobe 2019
Hello. I am fairly new to Jamf Pro and in the process of learning while cleaning up some of the work that was created before me. I have a question regarding pre-stage enrollments and the best practice for moving forward. Currently, our iPads are not automatically assigned to a pre-stage enrollment as we have 4 different pre-stage enrollments. This leads to devices never being enrolled in Jamf as they are shipped out to the end user. I would like to automatically assign all iPads to our generic DEP pre-stage enrollment and then manually move the ones we need in a different pre-stage enrollment. We will not need to do this often and this will at least allow us to have all iPads enrolled in management. Am I correct in thinking that devices already assigned to a different pre-stage enrollment will stay there after this change is made, even if wiped? It is my understanding you can only have devices in one pre-stage enrollment at a time and you have to unselect the one it is currently assign
Hello all, I'm new to JAMF and I was wonder if there a way to change the names under Browse in Self-Service? By default, It group all the software and policy group under "All" , Can I change it to something else like "Software " ?Thanks for the help.
Fellow Jamfnation citizens, While macOS High Sierra is not anymore supported by Apple, does Jamf still allow to install jamf binary on Macbooks with unsupported macOS and allow to manage or supervise them ? Does the same apply to other unsupported macOS like Big Sur and Catalina?
Hello , Im using this Make Me admin Script https://github.com/jamf/MakeMeAnAdmin , it works perfectly to give the user admin acces , but where i can find the logs ( to see what the user did with the admin acces ? Thank you
Hey all I'm new to Jamf School. I'm trying to do a pilot program this year for Jamf Teacher and Jamf Student for our ipads. I currently have Jamf teacher and student working well. However, I can't get Apple Classroom "View screen" to work. I went through the Jamf Restriction settings and allowed for Apple Classrooms to view the screen. Anything I'm missing, any settings that are hidden on the jamf school side?
Is there anyway to manage Opera browser? I searched in Opera not able to find mcx/configuration profile.
Monterey: https://swcdn.apple.com/content/downloads/62/35/052-09275-A_9GJLP5ERYO/bn3yyowf9ulxzdfmu7ia1ihnh7at3rw2s1/Safari17.5MontereyAuto.pkgVentura: https://swcdn.apple.com/content/downloads/20/22/052-69114-A_HXAGLW506N/2eosf2mygag5y38grze3znqgmnss0bbpdd/Safari17.5VenturaAuto.pkg
We have a user getting the below error and can't access anything. The help desk also reset the password. A couple of commands were ran, the removeFramework command was ran and they then tried the profiles -renew -type enrollment, and get the Update prompt and it opens system preferences and then I choose update again, but it looks like it doesn't do anything. I can see all the profiles.
I am trying to run a series of reports in Casper Inventory that sort the laptops in my deployment by last check in date, and anything that has not checked in to the JSS in over 4 weeks. The report works fine, but it fails to add in the user's short name or long name. I would really like this to work since I can just generate this report and hand it off to someone in administration and they can make sure these laptops are still here. I know some students come to school and turn their airport connection off, on purpose, because they know that we use remote desktop and push out updates over the network. Other machines are off site at the repair center. However, I would love a way to audit everything off my notes and off of my records for repair. I also have some machines that have not checked in for a whole year, now these machines I think had a major component replaced and/or the asset tag replaced and it is in inventory as a different machine. Any way to make it so the sho
So in https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/Apple Says: "Configuration profiles cannot be installed, and the device cannot enroll into mobile device management (MDM), while Lockdown Mode is turned on."It seems like we would want to keep the end user from enabling this on MDM devices. Has anyone seen any documentation on how to disable Lockdown Mode? I can't see any in any MDM reference publicly available.
A user has rebooted their AD Bound Macbook after updating the device to Ventura. They typically sign in with their AD account that has been made a mobile account. Now suddenly when they try to login they are greeted with a page that only allows them to enter the password for the guest account (Which we never enabled as far as I'm aware.) There is no option for the 2 local administrator accounts that are meant to be on the device nor the staff member's mobile account or even other user to manually enter credentials. I have a suspicion this has something to do with the ventura upgrade vs AD. Has anyone else encountered this issue?
I'm trying to set up Nudge which is a program that pings users to update their computer. I have everything in the JSON file setup, but I can't seem to find a way to create a URL for the button "Update Now" to take them to software update. The default uses "munki://updates" and the instructions take you to Jamf Self Service for macOS URL Schemes which seems to only take the user to Self Service? Would you have to make the button point to Self Service and create a link in Self Service that takes the user to Software Preferences? Forgive me if this is simple, I'm new to Jamf (and IT) and Google doesn't seem to have an answer. Thanks!
Hello,I have added 1Password8 to the Jamf App Catalogue in our Jamf Test instance, On the Deployment status tab I'm getting App Installer deployment status Unavailable The App Installer deployment status cannot be retrieved. Check your configuration settings or refresh the page.I have verified all the settings and it seems correct to me. I'm not sure what if I'm missing something or?Can I get some assistance on this to fix this issue?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!