Get Support
Recently active
How do you guys set it up? Building? Room number? Department? Currently I have set up as just room number. is the a better way the set this up? Thanks!
We are a University with Apple School Manager and Federated Apple ID setup, devices managed by Jamf Pro. Recently we've seen an issue with new users signing in to our shared iPads. They sign in with the federated account details fine, are prompted to create a passcode as normal:Then, when logged into the iPad, when the screen locks then the prompt to enter their passcode to unlock it is not the same as the normal federated one, its a numerical keyboard only, so they have no way of entering the alphanumeric passcode they just created:I've found that resetting the users passcode within School Manager resolves the issue. But its not a workable solution to have to do this for an entire class during a teaching session. Has anyone else experienced this issue?
What is the proper way to automatically enroll a new device into a Static Group during prestage enrollment? I'm using Sonoma 14.4.1. Currently I have to do this manually after the end user boots up the machine. There are policies configured to a certain Static groups new devices needs to belong in.
Hi Jamf community,I'm looking for a Jamf content filtering solution that will work on just a handful of iOS and Mac devices - currently 3.Jamf protect looks perfect for this but has a 25 user of 50 device minimum and can only be deployed through Jamf Pro which has similar minimums. Jamf Safe Internet looks great too and can be purchased per device but I don't think this can be deployed through Jamf Now.Is it possible for an individual/family to use Jamf School and apply Jamf Safe Internet? Are there any other solutions that you know of?Thanks!
HiWe are in the process of removing local admin rights for users machines. We are trying to figure out how to install command line tools, such as xcode, from self service. The issue we are foreseeing is authentication. We want to write scripts to take care of these installs and wanted to see if anybody else has dealt with something like this and may have some tips.
This post was originally posted to my personal blog, which you can find by following this link. With Jamf Pro 10.49 admins can now use OAuth client credentials flow for authenticating to the product's APIs. The documentation for the new API Roles and Clients can be found here. The implementation is straightforward: Go to Settings > System > API Roles and Clients Create an API Role Select all of the applicable Jamf Pro API role privileges it should grant. Create an API Client. Select one or more API Roles to assign to it. Enable the API Client. Generate the Client Secret. You can now use the client ID and secret to obtain access tokens. This shell example below is taken from Jamf's developer docs. curl --request POST "${url}/api/oauth/token" \\ --header "Content-Type: application/x-www-form-urlencoded" \\ --data-urlencode "grant_type=client_credentials" \\ --data-urlencode "client_id=${client_
Hello, sorry for my bad english. I'm searching for a solution: students can change DNS setting and skip our UMBRELA configuration.I'm looking for something that can prohibit DNS changing when they are on our network, but when they are outside, they can do if they want. Could you help me whit this one? ThanksBR
Estoy enfrentando un desafío en mi compañía relacionado con la personalización de los equipos que operan con macOS Sonoma. La política de la empresa requiere que el sistema operativo refleje los colores corporativos, y el color naranja, que está disponible en la configuración de 'Aspecto' de macOS, es nuestro color representativo.Para implementar esto, he creado un archivo .plist que se distribuye a través de un perfil de configuración, con el objetivo de que todos los equipos de la compañía adopten este color de acento. Adicionalmente, este perfil también está configurado para que la barra de desplazamiento se muestre de manera permanente.A pesar de haber intentado todas las modificaciones posibles, no he logrado que estos cambios se apliquen correctamente en los equipos. ¿Alguien podría asistirme con este problema?A continuación, adjunto el código del .plist que he estado utilizando:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "h
To All, we are looking for a way to import 400+ computers into JAMF Pro, Any help would Great
Hi All,Just wanted to see if we are still in the same boat where we cannot install or manage In-App purchases for iPads etc.. Is it still the same that because we go through Apple School Manager for the apps, there is no way to get the In-App options?Thanks!
Hello Jamf Nation!We have several exciting new features including new Login functionality, Managed Software Updates enhancements, Packages page redesign, and more! You can find more information in the release notes when you enroll.Starting with the Jamf Pro 11.6.0 Beta, we will be deleting any Jamf Cloud Beta instances that have not been accessed for more than 90 days. Once a beta instance is deleted, it is not recoverable. If you would like to retain your existing beta instance, please log into your instance within the next 30 days. You can find your instance at account.jamf.com >> Feedback >> Jamf Pro Beta.If your Jamf Cloud Beta instance is deleted, you’re always welcome to create a new one in the Beta section of Jamf Account. Please email any questions to beta@jamf.comHow to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access.
Trying to renew our DEP server token before it expires, have logged into Apple School Manager and clicked on the MDM to download the token p7m file, then tried to upload that file to the expiring instance and it says "The file received is not valid"Any Suggestions?
Hi Everyone,I've been doing some testing with the Mac OS onboarding feature and getting mixed results. On first login with newly enrolled Macs I see Self Service launch as expected but the Mac OS onboarding screen doesn't kick in. I've checked that all polices are set to be available in Self Service, frequency set to once per computer with no other trigger enabled and I've made sure all required polices are ticked in Mac OS onboarding. I've made sure Mac OS onboarding feature itself is enabled and "Launch Self Service when done" is enabled in User initiated enrolment. I've seen some success with leaving the Mac for 10-15 minutes then relaunching self service which kicks Mac OS onboarding in to life but it's not consistent. Any help greatly appreciated.
I have a script that save in a text file the last logins, but I need to show the text file content in a popup window on the finder, with an OK button to close it.Any idea?
Certainly! Here's a revised version:---Hi everyone,I'm reaching out for some guidance on integrating external data into Jamf Cloud. Specifically, I'm looking to import data from sources like Eracent ITMC or Landesk Asset Lifecycle Manager. As someone new to Jamf, I'm trying to figure out how to import an asset tag into an attribute for all Mac devices.The process ideally involves matching serial numbers from the external source with those in Jamf, extracting the associated asset tag numbers, and then scheduling daily data discovery. Any insights or guidance on how to configure APIs or recovery tools for this purpose would be greatly appreciated.Thank you in advance for your help!
Hello team,I am using advancedcomputersearches ( https://your.jamf.server/JSSResource/advancedcomputersearches/id/<id>) API to obtain information of computers including FileVault_2_Personal_Recovery_Key, it was working fine until recently all fields are returned great except FileVault_2_Personal_Recovery_Key field. Which if I look in the JamfPro search results they are all returned perfectly. Thank you,
Hi,I am the System Administrator at an educational institution that utilizes Jamf software (has done so since Jamf was still called Casper). I am also a part of the security team, and a security software we utilize sent me a weekly report that an account called 'casperread' tried to reach a website known for phishing called contrarymeeting.com I am hoping someone here can possibly explain why this happened, and if I need to be concerned. Does Jamf still rely on these legacy service accounts? Why is it trying to reach addresses on the internet to begin with?
We are trying to update a lab of computers to 10.7.3. These computers are partitioned 50/50 with a 10.6.8 partition and and a Windows XP partition. We are getting the following error when trying to run the update: *Mac OSX could not be installed on your computer Mac OS X can't be installed on the disk Macintosh HD, because a recovery system can't be created.* Wondering if anyone else has run into this problem and if so how did you get around it?? We have tried the install both through SelfService and by just running the install straight from the computer.
Hi, I wrote this script to remove the Recovery HD and add the space to the Macintosh HD volume. Maybe you'll find this usefull. ---#!/bin/sh diskutil list > /tmp/diskutil while read linedo# Find the Mac OS X 10.7 Recovery HD volume and eraseif `echo ${line} | grep "Recovery HD" 1>/dev/null 2>&1`; thenrecovery_hd=echo "${line}" | awk '{ print $7 }'diskutil eraseVolume HFS+ Blank /dev/${recovery_hd}# Find the Macintosh HD volume and merge with erased Recovery HD volumeif `echo ${line} | grep "Macintosh HD" 1>/dev/null 2>&1`; thenmacintosh_hd=echo "${line}" | awk '{ print $7 }'diskutil mergePartitions HFS+ "Macintosh HD" ${macintosh_hd} ${recovery_hd}fifidone < /tmp/diskutil--- Kind Regards, Martin van Diemen t +31 (0)205677744 G-Star Raw C.V.www.g-star.com
I am working on deploying a new zero-touch provisioning process. This new policy alerts the user that they're running an outdated macOS if they enroll a Mac running macOS older than Sonoma. The alert includes a button to click to launch Software Update. After the upgrade to Sonoma, the ZTP policy launches automatically thanks to a launchdaemon that gets installed on Macs running an OS older than Sonoma. After the ZTP policy completes, the user needs to reboot. When they login, they are kept waiting 10-12 minutes before they reach the desktop. When I ran this through on my test Mac, I found that softwareupdatd is responsible for this but I have not figured out exactly what is allegedly updating. Since we just ran an upgrade to Sonoma, all of the OS components should be up to date. If a Mac running Sonoma (any version of Sonoma) enrolls, we don't see this issue. This is not a complete disaster. It's just an annoyance. I did not see this happen with a Mac VM that I enrolled yesterday. The
We are transitioning to the latest version of MS Office 2021. We currently have 2019 installed, using both the serializer and 365 licensing (I'm not sure I am labeling the two license types properly). I saw a video from last years JNUC that made it seem like all I have to do with the serialized installs is to install the new serializer for 2021 Office. For 365 users, nothing needs to be done. Is this actually the case? Do I need to install the full Office 2021 package? If I am understanding properly, I don't have to do that (save for new installations).
HelloHas anyone managed to install SAP with SSOI had to install the Secure Login Client but it seems I missing the Kerberos Token and can't find any good articles anywhere
Hi all, Is there an easy way to remove the Wifi Menu icon via Casper? I found a thread from a year ago but didn't really understand what was said in it and was hoping things might have changed since. Composer doesn't seem to catch it and there's nothing in the config profiles for it. Thanks!
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 11.4.2 fixes the following product issue: Jamf Pro Server [PI117958] A database table issue that could cause server instability and an HTTP 503 error has been resolved. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 11.4.2 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. If you would like to upgrade manually, navigate to https://account.jamf.com/products/jamf-pro and click Upgrade (Standard Cloud) or Schedule Upgrade (Premium Cloud) at the top of the page. Subscr
I am trying to create a script that displays a message when a specific application is launched to alert the user it is not supported and they're using it at their own risk. I was able to get the base script I want to trigger together, but cannot seem to find a way outside of constant loop checking running processes to trigger it (below). I thought maybe a daemon would be my best bet but I can't seem to find a way to know if the application is launched. #!/bin/bash# Infinite loop to continuously monitor processeswhile true; do # Check if 'Microsoft OneNote' process is running if pgrep -x "Microsoft OneNote" > /dev/null; then echo "Microsoft OneNote process has started!" fi # Adjust sleep time as needed to avoid high CPU usage sleep 5 # Check every 5 seconds, adjust as necessarydone Anyone have a way to launch a script only at application launch, not by checking if it is running/open?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!