Get Support
Recently active
I am trying to create a smart group that will show me Macs that have been booted for more than 7 days. Many times, my team gets support tickets from users that would not have been necessary if they had rebooted their Macs at least once a week. I love that Macs can stay booted for a really long time. My record is 92 days, but to get there, I had to put up with some quirks and minor issues. I just wanted to see how long I could go between reboots. I don't want my users doing this, so I want to create a smart group for Macs that are booted up longer than 7 days, and then display a message asking them to please reboot soon. I have found extension attributes that will show me the up time, or last reboot, but when I go to create the smart group, the operator shows only is, is not, like, and not like. What I need it to show is something like "more than X days ago". Does anyone know how I get this? Maybe I'm using the wrong extension attributes?
The jamf profile description file is incompletely deliveredThere are 10 files, but only 5 can be installed
hi all, i need some advise input from anyone about my environment. we just recently build a new NDES Cert server and we use Azure App proxy pointing to our NDES to deploy 802.1x certificate to allow our azure joined windows devices access to our wifi (we use Cisco ISE for authentication and authorization). We currently have our macs bound to the domain to allow cert request (so it can request cert from the old CA if its in office). We recently got our Jamf Connect setup and have no reason to bind to domain anymore. I want to ask anyone advise of what is the best practice for us to deploy our 802.1x cert to our mac that will be Jamf Connect only? is it possible to integrate our Jamf cloud with our Azure app proxy for certificate deployment (just like intune - windows)?Or do i need to go with Jamf AD CS Connector? or do i go with setup Jamf SCEP so it can point to my NDES server (on prem)? i prefer not to do this as I want to limit the amount of network connection between my NDES servers
Hello, I noticed that "private navigation" is now accessible on Safari despite using a "web content filter" profile present on the devices. Deleting history is still impossible. Thx.Christophe
Hello everyone,I'm looking for help deploying AppleScript through Jamf Pro. I know the basics of bash scripts but almost nothing about AppleScript. I got the following AppleScript from one of our network administrators:tell application "System Events"set macUser to name of current userend telltryset FortiDir to POSIX file "/Users/Shared/Fortinet/Forticlient"set ztnaConfig to POSIX file "/Users/Shared/Fortinet/Forticlient/ztnaconfig.json"set FortiDir to POSIX path of the file FortiDirset ztnaConfig to POSIX path of the file ztnaConfigdo shell script "chown -R " & macUser & " " & FortiDir with administrator privilegesdo shell script "chmod 755 " & FortiDir with administrator privilegesdo shell script "chmod 644 " & ztnaConfig with administrator privilegesdisplay dialog "BW FortiClient permissions patch successful"on error theErrdisplay dialog "File permissions update failed for " & FortiDirend tryI tried to deploy it as a shell script in Jamf like this:#!/bin/bash
I feel like I'm just missing this somewhere, but is it possible to query the api to find the Jamf pro management ID? I know where it lives in the console but I would like to programmatically send a wipe computer command to device through this endpoint: https://yourserver.jamfcloud.com/api/v2/mdm/commands and that requires the Jamf pro management ID. If there's a better way to wipe a device other than this endpoint, I would also like to know. Thanks!
Not directly related to Jamf, but for those of you working in Colleges and Universities, what are the benefits of managed Apple IDs for your users? This is via SSO/Federation in Apple School Manager.
I created a policy to create a local account. The account gets created successfully with the policy but for some reason the password I set in the policy does not work. Has anyone run into something like this? It is not working on a specific laptop cart that uses 2017 MBAs that were manually enrolled. Not sure if that has something to do with it, but it is working on other devices. Any ideas?Thanks
I'm looking for a way to run a script to log any active users out of 0365 or Microsoft Office apps without removing the license from the Office apps. Log out Office, O365, OneDrive. Use case: A classroom that has many teachers using one computer. I want to run clean up on restart of that Mac to make sure it is ready for a new day and not logged into any specific accounts.
Wir arbeiten als Schule mit JAMF School. Unsere Schüler-iPads haben ein Profil laufen, dass morgens um 7:30 Uhr Apps ausblendet. Die Zeitschaltung ist von 7:30 - 13:30 Uhr aktiv.Leider melden mir Schüler zurück, dass dies oft nicht funktioniert. Teilweise beginnt die Sperre erst um 08 Uhr und endet auch erst um 15 Uhr. Das sorgt für Unmut. Gibt es ähnliche Probleme an anderen Schulen? Wie kann der Fehler behoben werden? Welche Einstellungen werden für Schulen sonst generell empfohlen?Danke.
Hi,We are having trouble with some students, they are taking off the WiFi at the first hour in the morning, and the profiles do not enter, I am doing a re-push manually to try to catch them, but it's annoying, is there any script I can use to re-push a profile? Thanks a lot.
We used to use JAMF Composer to be able to deploy files to our Macs using package files. For example, I have our JAMF Connect login screen and icon deployed to our machines using a package I built in Composer installed at enrollment by JAMF Pro. For some reason, my JAMF Composer stopped working, even after a reinstall. Therefore, I am looking for an alternative for package building where you can add and remove files from a package. Any suggestions? Thank you!
I'm looking for the best way to prevent all Mac users with local admin privileges from removing a wireless/wired profile and SSID configuration for a specific wireless/wired network.The goal is to ensure that the wireless network settings are enforced and cannot be modified or removed by the end-users, even if they have admin access on their Macs.Is this possible?
I've been tasked with the pain staking job of documenting JAMF, how each policy works, what are it's dependancies like Smart Groups, EAs, Packages etc. I'm intrigued how others have done it and whether anyone would be willing to share a template perhaps? Obviously we use Code commit which is fine for techies but I need to cater for non techies too.
I recently added 20+ Apps and the Apps are going to be assigned to the same exact group of carts for a school. Is there a way to select multiple apps and scope out to devices/groups without having to click on each single App name--> Edit -->Scope --> Save --> Done (Rinse & Repeat) one by one? It's very time consuming let's just say that you forgot to scope out a group or a single device for those 20+ Apps. You have to go back and Edit the App scope for each single app. This may be a feature request but I haven't seen anyone requesting it. My vision would be a checkbox next to every single app and then you can define a scope to a that select group of Apps. [Thanks Everyone]
Sharing for awareness. If you are experiencing the looping Data Notice after updating MS AutoUpdate to v4.70 it is probably due to using a deprecated setting in your profile to configure MSAU. See release-history-microsoft-autoupdate. If you have the RequiredAndOptionalData value selected in your profile it will created the looping issue since the key is locked in the profile but the setting no longer applies. So even if the user clicks OK the acknowledgement will not be set in the preferences and the notice will appear again creating a loop. Issue can be resolved by changing AcknowledgedDataCollectionPolicy value to RequiredDataOnly and redistributing the profile.
Posting on here since Sophos has been less then helpful, We installed Sophos endpoint wither their Ventura Config profile and it looks like it works and is functional. However when I go to do an update on the computer while logged in as the local admin no password is accepted. Also when I go to More info and then install through that window it locks SophosEndpoint as the user name and no password I try works there. I've attached a screenshot of the weird login window I haven't seen before
i would like to push bookmark in safari using jamf pro config profile.I know we can push bookmark in chrome using jamf pro config profile (you just push it in xml).But does anyone know/have config profile for pushing bookmark in safari ?
Hi there, I've been trying to find a way to get an extension attribute in Jamf to look at "/Library/Management/super/super.log" for a line: Parameter Error: You can not use both the --deadline-count-soft and --deadline-count-hard options at the same time. You must pick one deadline count behavior. And report the result of true/false. I have a policy setup to uninstall and reinstall super from there.
We are looking to mass remove Teamviewer via a script as on deployment we made the mistake of just deploying through a pkg file and not indexing with a dmg file. I have tried 2 other scripts that I've found on Jamf forums but none of these have worked. The Teamviewer versions are v15 full on some and v15 host on othersDevices generally all running Big Sur but there may be some running Catalina Any assistance would be greatly appreciated
Hello All, after installing a bank app on a shared iPad, I am unable to launch the app and get the above error. This same app works fine on a single user iPad so I have a feeling it has to do with it being a Shared iPad.Has anyone run into this or have any ideas?
Hi there, Has anyone managed to get their historic backdoor local admin accounts that was created in prestage (not the management account '_jamf') working with LAPS? I currently have the p/w to all of the accounts and would like the passwords to start rotating. Reading the LAPS docs I haven't seen anything related directly to historic local accounts.
Hello everyone,Anyone know if there is a good comparison between Jamf and Intune somewhere - what each environment can/can't do and how long things take to accomplish in the different environments?In this case, it applies primarily to Mac. But iOS can also be interesting.
Vendor-provided Overview Thycotic Privilege Manager is an endpoint least privilege and application control solution for Windows and Macs, capable of supporting enterprises and fast-growing organizations at scale. The two major components are Local Security and Application Control. Using Privilege Manager, administrators can automatically discover local administrator privileges and enforce the principle of least privilege through policy-driven actions. Those policy-driven actions include: - blocking, elevating, monitoring, allowing - application quarantine, sandbox, and isolation, - application privilege elevation, and - endpoint monitoring Continue reading … See also Privilege Manager 10.8 Customer Demo macOS Agent Installation Agent installation is well documented and straight forward, however "it will take 15-30 minutes for newly installed agents to register in Privilege Manager." (As of this writing, the vendor's link to Terminal Commands to speed up the process appears to b
Hi all, does anyone have a working PPPC for this DLP application? We are not seeing FDA enabled as required using the PPPC configs currently out there ( not even the one the company created) TIA
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!