Get Support
Recently active
Hi, I am facing an issue where I have followed Microsoft instructions here: https://learn.microsoft.com/en-us/defender-endpoint/mac-jamfpro-policies?view=o365-worldwide To get Defender running on our Macs, however it breaks Onedrive. Throwing the "OneDrive Files On-Demand didn't start. Please restart your computer and try again." I have done some digging and 'I'm pretty sure the issue is the MDATP MDAV System Extensions configuration policy. This is set to only allow system extensions you add to the list, the document tells you to add the below:com.microsoft.wdav.epsextcom.microsoft.wdav.netextThen OneDrive breaks so i'm pretty sure I just need a specific system extension to add for OneDrive but I can't get this information from Jamf support or Microsoft.
Hi,Ran into something just recently that I know has been occurring for at least the last week or two, not sure exactly when it started. We have a cloud Jamf pro instance, and maybe about half our macs were joined via user invitation (user-initiated enrollment), every single one of them is showing the wrong user for enrollment. So say it's User1's machine, and I know they enrolled by an email invitation, I go into details on the device and it shows that User2's was the email invitation. If I check User2's, it says User3's was the invitation, and so on.While I don't know for sure when it started, I do know it wasn't always doing this, at least at the end of 2023 I am sure it was showing correctly.I don't think this is causing any issue, apart from confusion, local user accounts and all are showing up correctly, but is this something that other people are seeing?
Jamf published Build a Computer Information script for your Help Desk on the Jamf Blog this morning. In that post I used the term "module" to refer to a short script snippet that can read a piece of information from a Mac and display that information as part of a dialog shown to the end user. For example, this gets the computer name: # Display computer name runCommand=$( /usr/sbin/scutil --get ComputerName ) computerName="Computer Name: $runCommand" This Jamf Nation Discussion is for anyone who's needing assistance creating additional modules and/or helping others create modules.
Hello,A laptop was recently deployed to an end user and when the user attempts to install the MDM Profile, it prompts her for a username and password since she is not an admin.There is a local admin account that was created by the pre-stage enrollment but it's not accessible.I can see the laptop within Jamf Pro but cannot push any changes.Are there any suggestions on how to proceed since she's not an admin on the computer?
How do we manage the "Automatically allow built-in software to receive incoming connections" and "Automatically allow downloaded signed software to receive incoming connections" options in the Firewall pane of System Settings? The only options in Jamf Pro are "Block all incoming connections and Control incoming connections for specific apps." Am I missing something?Screen shots for reference.
Does anyone know of a way other than Composer of creating a .pkg package containing folders to be installed at specific locations? I'm trying to package the latest Unreal Engine for installation on our Media Department's Macs. Epic doesn't provide any sort of deployment tools, they just tell you to "install it through the launcher and mirror that using your deployment tools. Or you can compile it from source!" which is extremely unhelpful. There are two folder structures, both are in /Users/Shared - one is /Users/Shared/Epic Games and the other is /Users/Shared/UnrealEngine. Unfortunately, it seems that in recent years the size of Unreal Engine has ballooned massively and in total these folders take up 29GB. To put it into Composer I'd need double that amount of free space (29GB for Composer to copy it into its Source folder structure, and another 29GB for when it writes the package) and I just don't have that much free space right now. Is there a way I can create a package from th
Afternoon!I reimaged around 30 iMacs 2017s and erased and reset up the HDDs as APFS and everything seemed good to go. However, I noticed that the Hard drives are filling up fast (school isn't in session so I'm the only one who has logged on) and are now maxed out. I originally thought that I must have spaced out and just sloppily messed up*. So, I re-imaged them again (I paid special attention to what I was doing this time around) and the same thing happened. They are Smart verified and I also ran Disk Inventory X which shows only about 80 GBs of real usage (this sounds about right). I'm wondering if the age of the HDDs could be doing this since they are used A LOT and constantly on. Any thoughts or articles would be great because the college won't want to buy new iMacs (but maybe new SSDs).*I've tackled setting up maybe a few thousand (if not many thousand) and this is the first time that I have encountered this.Thanks in advance!
Hey everyone,Just an FYIIn our organisation we found that Airdrop was not working properly on MacOS Sonoma (14.2.1 at the time of writing). After troubleshooting I found that this was caused by the CrowdStrike Falcon sensor.Crowdstrike have already released an updated version of Crowdstrike on the 9th of Jan (7.10.xx) that appears to fix this issue.Just an FYI to help anyone who may be troubleshooting a similar issue. Perhaps check your sensor deployment policy and alter it if required.Thought I'd post as I couldn't find anything here about this. There a little chatter about this issue on the MacAdmins slack too.
I'm seeing an unusual issue (I think). Our M1's are getting Bootstrap Tokens Escrowed correctly. The for some reason (I've worked with Support on this), the Mac's are then becoming unmanaged ticking "Allow Jamf Pro to perform management tasks" as per Support brings the Mac back into managed.I'm noticing that the Mac's that have gone through this process no longer have an Escrowed Token. To fix this I was going to deploy a policy that users would run to re-escrow the token, however the Mac's still believe the token is escrowed as per terminal command.While I'm still trying to work out the root cause as to why Mac's are becoming unmanaged, I'm not sure how best to move forward with the Bootstrap token issue?
Hello I have a question. We are currently testing Jamf Connect and we want to have it where on the second restart the jamf connect login window will disappear the authchanger should kick in but it does not. After the 4th restart attempt then the Login Window disappears. How the flow should be: You are on the mac home screen > you restart > you login to the jamf connect login window with your okta creds > then migrate > then back to the home screen > upon second restart the login window should not appear anymore but it does
So,We have 60 Licences for ARD.We scoped it to a number of AD Groups.It's set to 'make available in Self Service.Now, It states that all 60 licences are in use, even when they have not been installed on some of the devices..So, I then removed some of the AD groups scope so that there are less than 60, however, It still states that all 60 are in use??After removal of the groups, I refreshed the content for ARD, no joy!I'm confused??How the heck does that figure??Anyone got any ideas??T.I.A
Just wanted to see if anyone else had an SMTP issue upgrading an internally hosted Jamf Pro server from 10.x to 11.x? If so, how did you resolve it? We have two internally hosted Jamf Pro server environments, in the 10.x environment SMTP works fine, however in the 11.x upgraded environment it stopped working. We have a ticket open, but wanted to check here too.
Help, wise ones!We currently have Now and Protect for our 8 MacBooks, this ensures we are compliant for our ISO27001 standard. We have a new employee who wanted a Windows laptop and now we need something that does what Jamf does for the MacBooks. It's just the 1! Any help courteously received.
Every year we offer our graduating seniors the opportunity to purchase their school owned laptop. With that we have an off-boarding process in Jamf that is executed via Self Service by our Team to execute a script to do the following:Remove all licensed software.Unbind from Active directory and convert the Mobile account to a local one (cool utility found here).Remove the Jamf binary with "jamf -removeframework" and use the API to delete the Jamf record. This year as I test on some computers, I find it to be a bit buggy with errors and spending lots of time troubleshooting a process that has ben rock solid the last couple of years. Is anyone doing something similar and can share how you handle this type of situation? Perhaps it's time for some major cleanup of how I handle these.
Is Anyone else experiencing this? We have our screen saver set to come on after 10 minutes, and needs to be unlocked to get back into the device. I have an Intel device that will not accept the "correct" password. Have to reboot it to allow me to log back in.
Hi,How do I know from jamf whether the device is connected and communicating?Charles
Hi all, with the imminent deprecation of Jamf Admin app does anyone else experience very slow upload speeds for PKGs and DMGs using the web GUI interface?
Hi,I have a teacher who's using SONY headphones, so i wanted to push him the sony app.The purchased app is properly synced from ASM/VPP Store to JAMF.But when i load the device in JAMF school and want to "add" the app to the device, the app isnt not listed.But i can see the app under JAMF-Apps.What cant prevent an app to show up .
We've had about 5 students bring their iPads to us and say that all their apps have been deleted.Every app pushed out by Jamf is gone. Jamf shows that no config profiles are applied, no apps are installed, and there is no last inventory date - it's like it's become unenrolled except the management buttons are still showing, though clicking them does nothing.I'm not 100% sure but it does seem to have started with the 17.4.1 update.The students are sometimes using the iPads at the time - I don't see anything in the management logs to explain it - just that it uninstalls the apps.Has anybody else experienced this? Any advice?Thanks
We know that it's possible to set a managed app configuration for iOS apps. But how can you do that with macOS apps? Can't find anything in the docs or the Internet in general for that. Our specific use case is that we want to use JAMF Teacher on macOS. Since we have an on-prem JAMF pro, we need to distribute a managed app configuration with the JAMF teacher app. No problems on iOS. But with macOS..? There's no place to even insert any app config for macOS apps (I think this is a hybrid app if it matters). Any advice?
Hey Jamf peoples. Is there a way to get jamf to run a local script without waiting to see the results of the script? I've written up a pretty basic Jamf Helper script to aide with encouraging/forcing users to restart their computers. Because I set a long time out on the jamf helper window, Ideally I'd echo a script locally to the computer and then have Jamf start the script and immediately exit the policy. When I test using an event trigger, the policy doesn't doesn't complete on Jamf's side until the local script resolves. Is this possible without something like a launch daemon or launch agent? This is basically what I was trying to do: #!/bin/bash#variablesscriptPath="/Library/myOrg/restart.sh"directoryPath=$(dirname $scriptPath)mkdir -p $directoryPathtouch $scriptPathecho '#!/bin/bashorgIcon="/Users/Shared/MyOrgLogo.icns"helper=/Library/Application\\ Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelperdate1=$(date "+%y%m%d")pmDate=$(da
Hey everyone,Are any of you experiencing issues connecting your MacBook to guest Wi-Fi networks like hotel or airport Wi-Fi? Some users are encountering error messages and are unable to pass through capital.apple.com.Any ideas on how we can resolve this issue?Thanks.
I am using the following script as a EA to pull up the users iCloud account name, this works fine but if the machine hasn't updated inventory, or, if the user hasn't created a iCloud account then its just blank, I would like the script to report None if the iCloud account doesn't exist, could anyone modify the script to accommodate this ? #!/bin/bash for user in $(ls /Users/ | grep -v Shared); do if [ -d "/Users/$user/Library/Application Support/iCloud/Accounts" ]; then Accts=$(find "/Users/$user/Library/Application Support/iCloud/Accounts" | grep '@' | awk -F'/' '{print $NF}') iCloudAccts+=(${user}: ${Accts}) fi done echo "<result>$(printf '%s ' "${iCloudAccts[@]}")</result>"
Hello All,I need a help to set proxy pac on mac devices through a config profile so that user cant change it.I built a config profile and under the payload proxies I choose automatic proxy configuration and provided my organization's proxy pac and then I deployed on my mac, I can see it did not set the proxy. How to do it and any issue will happen if I deploy thsi config profile at the time of enrollment as my organization's proxy passes network traffic through cloud Zsclaer and just after setting the proxy it ask for authentication with user's work email and password. Please tell me how to fix these two issues. Your help will be appreciated! :)ThanksAsif
We have implemented a setup of JAMF Pro with Jamf connect into our environment. We have a mix of standard and admin users, and then we have a process to do admin items as needed. One area is our Network items, standard users cant troubleshoot, forget networks, etc. This is obviously a massive issue, and being unable to connect to on travel or troubleshoot to get things moved along to the network, is creating massive productive gaps. From what I see, Apple really locks down some of this, but it makes no sense why its so locked down. Any work around? We really need ALL users, to be able to control their network settings. ESP, when they travel for company events. Thanks,
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!