Get Support
Recently active
Hi, I've been back and forth with support for over a week trying to get Jamf Connect to issue a user certificate upon connection. I've got a User Certificate Configuration profiles in Jamf that i can request certificates through self service with no issues. But for some reason, Jamf Connect just can't handle the request. Our CA admin can't even seen any failed requests from any of my test machines trying to request certs. Kerberos appears to be working as i'm able to generate new tickets with a good connection to Jamf Connect and SSO works with all of our SSO secured sites. in the Jamf Connect logs when a connection is made i'm receiving the following:I'll be the first to tell you that i think certificates are magic so i don't fully understand them. And I'm not sure what "Certificate doesn't match current user principal" means. We're authenticating through OKTA to get our kerberos Tickets. In the JAMF connect logs I can see that Kerberos Auth Succee
Hi,I have set up Cloud identity providers and I am wondering if there is a mechanism that will allow me to do a sync of users from Microsoft Entra ID to Jamf Pro automatically.I mean users from the "users" tab not from the system tab "User accounts and groups".How is the issue of sychronization of accounts solved ?
Hello,We have a few devices that have not checked in to Jamf pro since 9/23/23. These are active devices. What are the reasons Macs stop check-in, and how to fix these issues? Thanks
Hello all, I did some research into scripting, specifically the Outlook dictionary, when I was first developing the signature and how to create it. That is now working great and we are able to deploy a solution that removes any old signatures and adds a new signature, however I am running into an issue with setting it as the default in Outlook. This is my script: #!/usr/bin/osascript --Looks up username for dscl. No "whoami" because when deployed its run as root. set user to do shell script "stat -f '%Su' /dev/console" --Grabs information from AD and selects the needed part set fullname to do shell script "dscl . -read /Users/" & user & " RealName | awk -F 'RealName:' '{ print $1 }'" set email to do shell script "dscl . -read /Users/" & user & " EMailAddress | awk '{ print $2 }'" set phonenumber to do shell script "dscl . -read /Users/" & user &
I just added a new computer to the "Applicable" Smart Group on Jamf. Last time the connection to Intune was synced was at this morning. Any idea how to force sync this so new devices get synced?
I have tried to create a PPPC config with the utility and given a couple apps "allow" for accessibility, and "let standard users approve" for input monitoring and screen recording. while I understand these settings will not show in the macOS GUI, the users are still not able to enable these settings without admin prompt. I have only tested on Ventura, but we have a few machines (with more to come) running Sonoma. Is there something I'm missing?
We are starting to rollout Microsoft Defender and I have been tasked with tagging the Macs on the Jamf side. I have been given the XML they are using in intune but I am not finding documentation to turn that into something Jamf useable.<dict><key>key</key><string>GROUP</string><key>value</key><string>****** - ***** - *****GLOBAL ******</string></dict></array></dict>
Hey guys, So I was checking out our ABM and noticed that majority of the Macs have order history numbers that was associated with the Mac. I was wondering if there is a way to pull that data from ABM and put it into JAMF in the Purchasing section. Is there a way to do that?
This is a heads up for any organization using the Jamf Pro integration with Cisco ISE... According to the Cisco rep on a call I had a short time ago regarding Jamf's planned removal of Basic Authentication for the Classic API in the Very Near Future there is no support for Bearer Token authentication in Cisco ISE at this time (i.e. ISE 3.3), and they do not have a specific timeframe for when that support will be added but it isn't on the near-term roadmap. If your organization relies on the Cisco ISE integration with Jamf Pro I'd suggest you contact your Jamf Customer Success Manager ASAP and let them know that removal of Basic Authentication prior to support being added in Cisco ISE would not be welcome. I'd also suggest you open a TAC case with Cisco asking when they're going to implement Bearer Token authentication in ISE because it sure doesn't look like they consider it a priority given that Jamf has been saying for a over a year that Basic Authentication support was going to be r
We may be getting some new users joining from outside the USA. We are using JAMF Pro. I am guessing it will work OK in other countries, but looking for any sage advise from others who may be going this route.For example - we are about 80% zero touch deployment, but have a few things still to manually set up and check by hand. We won't be able to do a hand check for these things for people outside the USA, but we can likely remote in and manually do those things.I am curious if/how we can arrange for a Mac to be purchased and added into ABM in a foreign country. Will we need to contact an Apple rep that is local to the user? Or is it just as easy as finding a reseller locally who can do it? We want to avoid having to walk the user through connecting the Mac to ABM via Configurator.
Hello!I am curious to see if anyone else has seen this. I have noticed since macOS Sonoma has been introduced, it seems that when it gets to Locate Hardware Information (macOS version), it would take a few minutes longer than I have seen before. Now it seems to take about 5 minutes. Is this something that is common?Also, on the same area, when I do the recon command while off-network it would take about double the time. I suspect that because our Macs are domain joined, it is trying to find the domain and the OU it belongs (in JAMF, the information for the MachineOU changes from its current OU location to "not valid") before it times out.Has anyone else seen this? Please note, I don't have access to change anything, I'm a tech that uses JAMF and reports anything. :) Thank you!
Hi, How can we disable native user login on mac and have only jamf screen to login . Currently we have a painful process of login for users where they have to enter password twice one for local user and and other for jamf login screen.
Hi all, I see that there is an option to prevent changes to bluetooth for iOS devices.My question is, does the Jamf have the ability to disable bluetooth entirely? We have a security requirement to disable it.Thanks!
I have a list of computers that I want to run a script against it. However, they don't have anything in common that I can use a smart group. I was looking at static groups with no success. Is there a way that a .csv or plain text file can be uploaded to get a group created? so I don't have to manually do 50 endpoints.
Trying to do zero touch with our next batch of computers, so I've been working on a new Enrollment Profile. Everything's working well...with one exception.The test computer is in prestage with all the user fields filled in. The idea was, they turn on their MacBook, get to the Create a Computer Account screen, and everything's prepopulated (and can't be changed) except the password. So in the Enrollment Profile under Account Settings, I have "Pre-fill primary account information" checked, then "Device owner details" for Information Type, then "Lock primary account information" checked.What's happening is actuality is nothing's getting prefilled. All the fields are blank on the Create a Computer Account page.The one curious thing I'm seeing is that when I look at that computer in Jamf, sometimes the User and Location fields are still blank by the time the computer gets to the Computer Account screen — almost like the prestage info isn't getting to Jamf fast enough to prepopulat
Hi,it seems a couple of my VPP Tokens have been revoked. The token all come from the same Apple School Manager. Is there anything I can do about this myself? Renewing the Tokens does not do anything. Jamf Support is responding really slow and the situation has been like this for a month now. Any Advice would be appreciated.
We are having an issue with some of our devices where we can't change the password on the local user. It Brings up this message. This has something to do with this option checked below in our prestage. Is there any way to fix this problem? It affects most of our staff as we are switching over to Jamf Connect. Any advice on how to fix this? We do not use this anymore.
Is there any way to customize the Jamf Pro administration interface with colors, background or logo ? (Except just dark and light mode)When working with 3 different Jamf Pro enviroments back and forth, it is easy to make changes in the wrong environment.
We have a user who has just started and they have a personal iPhone backed up to iCloud. We want them to be able to restore this backup to a new, managed iPhone but it doesn't seem to work.We wipe the Managed iPhone and allow Proximity Setup, the Personal iPhone sees the Managed iPhone and goes through the steps to restore and it appear to be working, however after enrolment through our IdP the Managed iPhone goes to the Home Screen and nothing happens (apart from our required Managed Apps being there).Does anyone have any success doing the above? I'm wondering if it's even possible to do?
I've started looking into the Jamf+Intune Device Compliance, but I'm having a hard time finding what all this will gain for us. My organization currently does not use Conditional Access in Jamf or Intune. We might at some point start, but that is a ways down the road at best. Other than access to those Conditional Access Policies, are there any other benefits to enabling Device Compliance?
Hello everyone, I would like to activate and configure Platform SSO via Jamf Pro for our macOS devices. The aim is for the user to be able to log in directly to the Mac with their Microsoft Entra ID account. Can someone send me a link to some documentation? Or does it not work yet? I would be grateful for any information. Best regards
Hey folks..Does anyone have any experience working with the platform SSO feature of Ventura? One of our clients would like to use it, as they do not have a budget for Jamf Connect. I'm not really finding much info on how to setup in my Google searches.
I have around 30 MacBook Air computers which were shipped with macOS Big Sur. I was thinking of creating a static computer group and add the serial number for those MacBooks so that I could then add them to a policy which updates the software from macOS Big Sur to macOS Sonoma when the user logs in. Is this possible? The devices I have are PreStage enrolled for ADE. I'm still early in learning more about JAMF so if anyone had some advise or direction on how to go about this that would be greatly appreciated. The use case is that just now if we give one of these to a user it will enrol on Big Sur which is unsupported. Is there a better way? Can we upgrade them to Big Sur then erase the MacBook so it then enrols and installs macOS when next user logs in? As far as I'm led to believe this would install macOS Big Sur again as this is what the device was shipped with.
Is there an easy way to make the settings for more admin groups? They will have same privileges, but to different sites.We have 37 different groups to same amount of sites. Each groups have to admin one site. We are using SSO for admins, who comes from AD.
We have started using the MDM commands to "DOWNLOAD_AND_INSTALL" Apple Updates with a postpone option. The end user will get the notification like this The problem that we are seeing, is that if they click anywhere on the message, other than "options" button (not in this pic) the message just goes away. Then you have to wait 24 hours (give or take) before it shows up again.I'm not sure if this is something that i have configured incorrectly or just a "bug" from macOS.Has anyone else seen this? We are on macOS 13.x and Jamf 10.40.1
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!