Get Support
Recently active
Hello All, So I work for a college with a large distribution of apple TV's managed by JAMF. We're looking to stream an event through YouTube and would like to push it to the TV's. We have the YouTube app installed, but is there a way to configure the app through JAMF to automatically go to a particular channel or YouTube URL? This way the tech's don't have to go around the entire campus with fiddly Apple remotes to pull up the stream.Thanks,
Hi Everyone,Just wanted some opinion and advice on this. We have been Using JAMF Pro to manage our Mac OS and iPad OS since 2017. We just had a change of management and the IT Head wants to implement Microsoft Intune to manage all devices including macs and iPads. We currently use SCCM to manage windows devices and JAMF Pro for apple Macs/iPadsHis idea is to get rid of both and just use Intune to mange all devices. Can Intune do everything that JAMF can? Any feedback on this would be appreciated.
We have a local administrator account created as a part of our prestage and manual enrollment processes. It has no counterpart in our IdP (Azure in this case). However, the Jamf Connect Menu Bar app launches and demands a username and password.Dragging the window off the side of the display is an ugly solution. Is there a way to exempt a specific user/group from needing to connect with (or even launching) the menu bar? I thought it might be a Login Item, but no such luck.
Today we released Jamf Connect 2.35.0. This release includes the following changes and improvements: The new URL Scheme and Command Line Elevation (URLCommandLineElevation) key prevents unsanctioned privilege elevation via URL schemes and the command line interface. Elevation from the command line interface is only allowed when URL Scheme and Command Line Elevation is set to true. The ZIP file from the Collect logs button now includes the com.jamf.connect.actions and com.jamf.connect.shares domains. Resolved Issues [PI116170] The Jamf Connect login window now informs users their account is locked after multiple failures to enter the correct password on computers without FileVault encryption. [PI117370] Configurations of the Jamf Connect menu bar app with Kerberos no longer experience password expiration timers not resetting after a user successfully changes their password. [PI117524] Jamf Connect will now notify users when a privilege elevation denial occurs due to loc
I used Radar to create a ZTNA + Next Gen VPN activation profile for iOS, exported and used that in Jamf Pro to create two iOS Configuration profiles, for Supervised and BYOD devices. These contain per-app VPN payloads that match the setup instructions. Uses our Entra identity provider. I configured the apps to use the VPN, and everything appears to work. JAMF Trust App lights up green, VPN Settings shows wpa.wandera.com:32005 with the correct apps listed. Radar sees me, accessing the sites, which it says it's allowing. VPN icon briefly appears when I pull up the apps. But no data is loading through Outlook or Teams. Push notifications are coming through but I can't get it to sync any data.I followed the instructions here to add additional hostnames to the Traffic Matching tab of the Access Policy config, which is set to route 365 apps through America West. I've added the IP ranges for both East and West IP pools to my Entra Named Locations. Notably I am not seei
Has anyone seen this before? Suddenly when trying to sign in(for the first time) to newly enrolled AD joined macs, I am getting this lego block icon with an OK option. Click it, screen goes black then hit any key and youre back at the login screen.The only changes I made yesterday were with application policies. I would start there, but first I need to know what this icon is? Literally cant find anything about it online. Pretty frustrating. Has anyone seen this before? I also dont follow the logic of "removing old app policies and fixing ones that havent been working" breaks AD logins? I join new devices manually. I set primary domain controller, add directory admin group, create local account at login without confirmation, dont set UNC path, home directory is /bin/bash. Nothing has changed. I just set one up yesterday and its fine.Im assuming its related to policy changes I made, some how, but I cant find anything about this useless error icon. Has anyone seen this? Thank you.
Hey everyone,A device in our fleet recently stopped communicating. I checked and sure enough: Last Enrollment: 21/03/2022 at 12:52 PMMDM Profile Expiration Date: 21/03/2024 at 12:52 PM We have the default renew 180 days before expiry so was a bit confused. Check logs and see Failed Command:Command: Renew MDM Profile Error: The Device is locked Any thought on why this may have happened? Guessing only solution is to wipe and re-enrol? TIA.
We have a bunch of printer presets set for our users. We use "Find Me" printing with our fleet of 50+ Canon copiers. I would like to configure Presets so our users can select "Last Used Settings" if they like, but it is always going back to "Default Settings". So I am wondering if this feature is NOT available??? If I send out presets, can I not allow my users to select "Last Used Settings"?
Hello All,I am going to renew the JSS Built-in CA certificate, I saw in JAMF site that the signed config profile might be affected, so I want to generate a report of signed configuration profiles in my JAMF cosnole before going to renew it. If needed I will re-push by re-creating/cloning those CPs, but how to generate a report of such signed CPs from JAMF console.JSS built-in CA gets expired in 10 years so this is the foirst time I am going to do it. Your help will be appreciated!
Hi Jamf Nation, I hope someone will show me the light here. The screensaver activation in Ventura with Jamf Connect for login access doesn't work. Yes, I know an active user needs to be logged in for the screen saver to start. Still, in Mac Labs and classrooms, we have a multi-login environment where idle users get kicked out after a determined period of inactivity. Then the Mac sits at the Jamf Connect Login screen until is in use again with no screen saver running and burning the display for hours of inactivity. I'm staying with Ventura until the JAMF screensaver module is updated and compatible with Sonoma. Cheers!
Hi,I've been testing Remote Assist and it works like a charm apart for one thing:The documentation mentions being able to do 'Unattended Sessions' - I've not been able get it to work without having a user logged in at the other end.Anybody have much luck with this?Regards,Steve.
Hey Everyone! Jamf Connect: 2.32.0macOS: Sonoma 14.3.1 A little back story here. We have Jamf Connect setup with Azure/Entra as our IDP. Our organization is working on moving from a Local on premise AD to Azure/Entra cloud only solution. With that being said I made some cloud only accounts in Azure/Entra and have been playing with new cloud only groups for Jamf Connect with the "Standard" and "Administrator" roles. I have no problem logging in as these cloud accounts with a standard or administrator role. Here is where I am stuck, on a login with my account which originates from LocalAD and is synced to Azure/Entra I am prompted to do MFA via the Microsoft Authenticator app at the Jamf Connect login screen when I restart or come up from a shut down to unlock the Mac (THIS IS WHAT I WANT) the PROBLEM is with these new Azure/Entra only cloud accounts I am NOT prompted for MFA even though it is setup for the user and they are not in any exclusion groups or CA policies that
Hey all!Sorry that this question is a bit off topic. But does anyone know if there is an equivalent to Jamf Techer (and/or Apple Classroom) in the Windows/Intune world?
Hi, were currently having some issues with our network thruput. Ive been looking at ways to save some of what we have, and have noticed that i could manually enable low data mode on my iPad. is there any way that i could roll this out through Jamf School, where we already distribute the network information and our global proxy thanks
We are attempting to use the mass action to update iPads (~10,000 in batches of 200-300) in our environment, but updates are seemingly being hung up in the pending commands when there are other pending/failed commands.I've tested on numerous iPads to confirm that clearing out old pending/failed commands (sometimes these are months, or even years, old) and running update inventory allows the update to go through normally.My question is...is there a way to mass cancel pending/failed commands, but excluding certain commands? I don't see any issues with mass cancelling failed commands, but I am concerned about mass cancelling pending commands where a device may still have an important command pending - Wipe Device, Enable Lost Mode, Unmanage Device - that would be processed when the device checks in.
SO Apple will release a new way to install apps in the EU starting with iOS 17.5. See link:https://developer.apple.com/support/web-distribution-eu/Question is, how do you block this from an MDM standpoint? I haven't been able to find any documentation on if there's an MDM restriction setting for this, if it's included in the previous key released for 17.4 or if this is currently uncontrollable via MDM. Has anyone else seen anything about this?
I have students grabbing other students' iPads. And. Get their password by clicking on the Wi-Fi. Settings.
Hello everyone,Just want to know if anyone knows if Microsoft only uses Jamf for Mac or for all types of Apple devices at their office?
With the modern requirements for authentication to wireless networks, using 802.1x with certificates is becoming necessary.I have been trying to search for more information as to whether JAMF School can deploy client certificates, but everything I can find relates to JAMF Pro (which I know can do this very well).Any pointer to documentation or solution to suggest?
Hi Jamf Admins what can we do about screen time when parents set it?Can this setting be deleted via the Jamf Portal or is it only possible via the iPad itself or Jamf Parent App with clear Parent restrictions?If it is not possible to intervene via the Jamf Web. Will it be possible in the future/near future without Parent App?Because otherwise the iPads are restricted in the classroom or interfere with functions if the screen time is set by parents or students.Thanks for your feedback.Nice RegardsPeter
Hi there, is there a way to get an extension attribute in Jamf to report a target file's last modified date?
Hi there, does anyone know if Installomator has a "block app from launching" option or if there is a way to script a block app launch until an update to completed. Currently in our environment we have Installomator handling patch management with SwiftDialog, users still decide to launch whatever app is being updated while the SwiftDialog clearly shows it is updating 😑 Ideally would like to be able to block the app from launching while updating or to have a separate script that will block the app from launching until the update is completed.
Mostly Sonoma 14.4.1 OSWe have a Configuration Profile that has Require Passcode, Complex Passcode and Alphanumeric Value along with values in the rest of the settingsThis prevents the users from changing values in Lock Screen for Start Screen Saver when inactive, Turn display off on battery inactive, Turn display off on power adapter when inactive and Require password after screen saver begins or display is turned offI removed this from a target computerI cloned this configuration profile and added the clone to a target computerThis resulted in users being able to change the values for all of these itemsFor compliance we need to set Require password after screen saver begins or display is turned off to Immediately and prevent users from changing this valueI have been looking in Apple documentation and Jamf Community but the closest I have found was an un answered question at the bottom of the post from 03-27-2024 https://community.jamf.com/t5/jamf-nation/don-t-require-password-after-s
Hello all, I am running into a problem with 2 colleagues who use a Macbook. Usually when they start the Cisco anyconnect VPN, they log in with their credentials and the anyconnect client remains on a blank page.After restarting the applications more than 10 times, it works againSee the screenshotsThey are both on a different MacOS. One is running 14.4.1 and the other one is on 14.1.1.And they both have the latest version of Cisco anyconnect VPN 5.1.2.42. They experienced the same issue at the older version: 4.10.07061The rest of our laptops in our organization run on Windows, and none of them have this problem.Does anyone recognize this problem and perhaps know how we can fix it? Any help is greatly appreciated!
I'm starting to investigate restricting access to the App Store on our macOS, iOS, and iPadOS devices. The technical side is easy enough with just a config profile, but I'm unsure what will happen to existing machines that have installed things from the App Store. I don't think these applications will be uninstalled, but I'm not sure about if they'll get future updates. Can someone clarify the behavior around existing App Store installs after the App Store has been restricted?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!