Get Support
Recently active
Hello,1) We want to name our Macbooks based on below criteria: Prefix + 5 digits 00001 --> 99999.No duplicate should be created.Process should be silent or at least automated.2) We want as well to rename already enrolled computers using same criteria:Prefix + 5 digits 00001 --> 99999.No duplicate should be created.Process should be silent or at least automated.We intend to apply this naming convention on:Most machines are DEP Enrolled.Some are Self-InitiatedJamf Pro looks limited in this context.Any ideas ?
Part 1: Download Server Token from Apple Business ManagerLog in to Apple Business Manager: Go to https://www.apple.com/business/.Access Preferences: Click your account name in the bottom left corner and select "Preferences."Download Server Token:Click on "Payments and Billing."Under the "Apps and Books" tab, click "Download" next to the appropriate server location (ensure it matches your Jamf server region).The token downloads to your computer's Downloads folder (usually named something like "com.apple.vpp.itunescontent.serverlocationtoken").Part 2: Configure Volume Purchasing in Jamf Pro/Now Open Jamf Pro/Now: Launch the Jamf Pro/Now application.Go to Settings: Click on "Settings" in the sidebar menu.Access Volume Purchasing:In Jamf Pro: Under the "Global" section, click "Volume Purchasing."In Jamf Now: Click on "Volume Purchasing" directly.Add a New Location (Jamf Pro only):If this is your first time setting up Volume Purchasing, click "New."Enter a descriptive name for the
We have a requirement for a Kisk devices on our reception for a Power Apps built for visitors.I am utilising a single app mode to deploy this. However the application is not installing without entering the apple id.
Hey ya'll, we are about to roll out Jamf Connect to our users and I'm struggling with how to report our progress. Currently, we have a policy for the Jamf Connect app in our self service, and I can look at logs to see who ran the policy. My concern is if these logs get flushed. Is there a place to see my current Jamf Connect license count, and even better to see which devices are using a license? Thanks!
I'm trying to pair an airtag to an iphone and I get the error message "your device management settings do not support airtag". We have no restriction in JAMF for this. The only similar post I could find "Can't pair airtag on ipad" was caused by "Devices tab in Find My app is disabled" remaining in the device profile. I have searched for this and it is not present on the device so I'm not sure what is going on.
A multi-step process to help Jamf Pro admins zero-in on policy failures Background We recently executed a single-script Jamf Pro policy on All Computers and observed a 99.4 percent success rate. While this could certainly be viewed as an A+ result, what to do about the remaining 0.6 percent? Continue reading …
Hello, We've had content filtering enabled on all of our students iPads. We had a case where explicit content was seen via search on Safari. The interesting thing is that this same configuration profile is pushed to multiple iPads, but its not being applied to all of them. It shows as pushed and active configuration profile on the device, the restriction is visible under Profile > Restrictions. 1. iPad #1 is iPad 5th gen on OS 14.4.2 and the configuration profile works as it should. Searching for the term "Sexy" gives the restriction notice. 2. iPad #2 iPad 9th gen on OS 17.4.1 and the configuration profile seems to be ineffective. Searching for the term "Sexy" shows explicit content. I've gone through and compared the other configuration profiles to see if there is any discrepancies, to no avail. What could be causing this issue? Why is the content filtering being applied to one device but not the other? We are dealing with this scen
Hi there, I have a script that runs once on each machine in our macOS fleet. The script essentially creates a launchdaemon that runs a script that kills and restarts jamf binaries on machines once a day to mitigate the jamf checkin issues (no we do not have a force restart schedule). Issue I'm noticing is that some devices (about 50) even though they have the launchdaemon loaded it doesn't seem to be restarting their Jamf binaries. My thinking is it may be the script that is not working as intended. I intend for the restart script to be re-ran everyday on the local machine but some devices have not checked in for weeks now. #!/bin/sh cat << 'EOF' > /private/var/tmp/JamfRestart.sh #!/bin/sh sudo killall jamf sleep 10 sudo jamf policy EOF chmod 755 /private/var/tmp/JamfRestart.sh chown root:wheel /private/var/tmp/JamfRestart.sh cat << EOF > /Library/LaunchDaemons/com.JamfRestart.plist <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//A
Hi all, I'm changing a configuration profile to exclude the local admin account for the password complexity requirements. I'm wondering what affects this may have on existing local accounts on the MacBook. Will they be forced to change their exisiting password? Will the timer on their password policy restart? I'm kinda nervous to hit the distribute to all right now because I'm not sure what the effect will be.
Hello JAMF Nation, Has anyone been able to successfully create and package with the WFBS Trend client to be pushed out via policy in JAMF every single attempt I have made as resulted in failure or corrupted installations. I have found several posts here, that have helped with potential ideas but unable to get anything going successfully. Keep in mind I am a JAMF NOOB but am learning more and more each day. I have 30 machines that are out in the field and have been tasked to creating packages for: Skype for Business WFBS TrendMicro That are a bit of a challenge any assistance would be greatly appreciated. Thank You
Hello Jamf Community, We are currently in the process of setting up an on-premises Jamf server but have encountered an error. The computer begins to enroll with the MDM after entering the user credentials in Remote Management, then retrieves enrollment profile, begins to install enrollment profile, then gives an error. The error: Enrolling with management server failed. Unable to contact the SCEP server at https://our-server-domain.local:8443//CA/SCEP Has anyone experienced this issue, or know what is causing it and how to fix it? Also, I am not sure why it is inserting two forward slashes after the port and before CA: 8443//CA. Any and all help is greatly appreciated. Thank you.
We're doing some testing in our QA environment and configured all our Config Profiles to match what is in Prod. We've enrolled 4 Mac's and they show Invalid and the Recovery key is super long. I did try the github reissue filevault key, also escrowbuddy and ran the files and processes command, but neither work. When I run the reissue command and type in password and it's successful and I run a jamf recon, the recovery key validation changes to Valid, but the recovery key is still wrong and when you refresh it, it goes back to Invalid.
It seems like every time i try to make Custom Settings for a config profile, no matter how I make the plist file (xCode, VSStudio, manual creation, Jamf Pro spits out : JSON format is incorrect. I'm really confused at what I'm doing wrong.It will accept an actual JSON format, but then nothing populates in the form editor or Plist preview panes.What am I doing wrong? How should i go about making custom settings for external apps?Thanks in advance! Here is a sample from my OneDrive config profile<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>AllowTenantList</key> <string>TenantID</string> <key>BlockExternalSync</key> <true/> <key>DisablePersonalSync</key> <true/> <key>DisableTutorial</key> <true/> <key>FilesOnDemandEnabled</key>
I am simply trying to repackage some drag and drop apps as flat packages using Composer. We do this so we can use them in our provisioning workflows via Jamf Pro. Note: I have tried composer 10.44 to 10.48 and get the same results. Using FileZilla as an example: That is pretty much it. No postinstall, but I am signing with my developer installer ID. I have tried to notarize and staple the .pkg's, but Apple does not like something in the .app file so I get "Invalid Package". I have tried all kinds of things to try and clear any security flag, but nothing seems to work. The only thing that does work is control clicking and selecting Open, then open anyway. That does not work when attempting to deploy to thousands of computers. Our help desk will get overwhelmed with calls. I have tried all of the following to fix the issue via script (kitchen sink from various how to's I found): # disable gatekeeper su
So way, way outside my comfort zone, but feeling this days the importance of stretching myself I think I've a highly relatable topic for JNUC 2024 pertaining to the experience of being a Macadmin in a very Windows world, and all the trials and tribulations arising therefrom. I've submitted both my proposal and introductory video, and working from my outline following is what I've come up with:Good morning/afternoon! My name is Chad Jones. I’m currently the Jamf/Mac endpoint administrator for the City of Phoenix. This is a role I’ve held for about 3.5 years. A little about me: my professional infotech experience stretches back a quarter century to February, 1999, when I assumed my first desktop support role. Within eighteen months I was promoted, and then again about 2.5 years later. Twelve years of my career was spent directly supporting the needs of our executives and elected officials (Mayor, Council, and City Manager). I routinely received kudos for my technical acumen, ability to e
Perhaps someone has done this before, I didn’t really search around for it before I put this workflow together. As we know, the jamf binary does not use APNs, so we haven’t had a way to “send a push command” to call the jamf binary for things like ‘jamf recon’, ‘jamf policy’, etc.. Until now. Sorta. Here is my workflow for achieving this. Create a LaunchDaemon that watches for a particular Managed Preference (MCX) plist Run a script via the LaunchDaemon that reads the MCX file for the jamf verb (recon, policy, etc) Create a Configuration Profile with the “Custom” payload to push the MCX file Scope the Configuration Profile to a Static Group Add a Mac to the static group to force a call to the jamf binary via MDM/APNs The LaunchDaemon File Name: /Library/LaunchDaemons/com.yourdomain.daemon.mdm_trigger.plist <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/Pr
Looking for some help please as - I am not getting any help with Jamf Support at this moment and the case is at a HIGH level. We are new to Jamf School this year and transfer over from Securely MDM. The issue is Teachers are not seeing any of the default settings in the JAMF TEACHER APP - Nor are they seeing their classes. We are a school district made up of 5 buildings - ALL SIS info is imported into ASM from Infinite Campus - Teachers and students are assigned their correct building in ASM and the class right now shows 25 students and an instructor that class. Also, everything looks to be right as the groups and classes are set up correctly in JAMF SCHOOL but when the teacher opens up the JAMF TEACHER APP nothing is showing in their layout. Here is what i see or I think it is an issue - Organization - Settings - ASM - Sync Settings - there is a box to be checked under that setting called "ALLOW TEACHERS in ASM to use JAMF TEACHER - When I select that - I get an
Since updating some of our iPads to iPadOS 17.4 I've noticed guest sessions on Shared iPads taking nearly a full 3 minutes to login. On iPadOS 17.3.1 and older, guest sessions log in and are good to go in about 15-20 seconds. Has anyone else observed this behavior?
I have a computer that is enrolled but MDM Capability is No and under Management, Management Commands are missing. I tried to re-enoll it via enrollment URL but that didn't make a difference. Any ideas?
Hi All, I'm looking for some advice with configuring Shared iPads with Jamf School.When we set the Automated Device Enrollment Profiles IOS setting of our iPad's as a shared device and we do not apply Only allow temporary sessions, we do not have the ability to allow guest users to sign in as Guest is not shown on the lock screen.When we set the Automated Device Enrollment Profiles IOS settings to only allow Temporary Sessions, the end user cannot sign the iPad's into iCloud, and participate in Apple Classroom.Is there a way to allow the Guest account to Sign in to to iCloud to facilitate the end users being able to join a class that is hosted at our location? then, once they log off, the next user can use the Guest account and sign in to join their class and so on?Any advice would be appreciated as i am quite new to Jamf School.
Is there anyway to run particular script when pushed a particular configuration profile to a system?use case: on some Mac jamf policy check-in policy stalled due to unknown issue, we have to ran killall command then run jamf policy command. so planning to run these commands via script with help of configuration profile. when a particular configuration profile pushed the command should run.
As Cisco is phasing out just Umbrella we have to create a package using their secure client instead. Whilst I have followed the instructions here (https://docs.umbrella.com/deployment-umbrella/docs/customize-macos-anyconnect-installation#prerequisites) to customise the installation on a single machine, I have been completely unsuccessful is creating a package from the customisation. Has anyone done this and if so could they share what they did? It does not help when the help documents refer to the product as anyconnect still, and some of the documents online I did find about building a package in Composer refer to xml files which do not exist in the updated secure client...so I am stuck on this.Many thanks!
Hello, I would like to enable an admin account that gets filevaulted during enrollment and gets a securetoken and recovery key. What is the best way to do this via Jamf?
I am running into an issue with a script where the new API token is expiring before it finishes. I know there is a way to renew the token with a keep-alive command, but I'm not having any luck getting the syntax of the command correct. Does anyone know how to renew an active token in the new API? Thanks for your help!
I've been trying to use the api/v2/mobile-devices/detail endpoint to get data on all mobile devices registered with Jamf. I have already done the same for computers using api/v1/computers-inventory, but for mobile-devices there is a bug.When calling the mobile-devices endpoint with sections IOS and LOCATION, I get a 400 response back. The request looks like this:api/v2/mobile-devices/detail?page-size=1000&section=IOS&section=LOCATIONThe response returned says "INVALID_REQUEST_PARAMETER_TYPE, Invalid value of request parameter: section, Required type: java.util.Set".If I do the same with sections GENERAL and HARDWARE instead, I get a 200 response with the data I want.api/v2/mobile-devices/detail?page-size=1000&section=GENERAL&section=HARDWAREGiven that sections that exist on the computer endpoint work while others don't, it seems like the endpoint might use the same enums for sections as the computer inventory endpoint despite the sections on the object being different.I
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!