Get Support
Recently active
Hi there, Has anyone figured out a way to make the local admin account created in prestage into volume owner (post prestage)? The behaviour I've see so far lines up with Apple's documentation on this topic which is that the first user signed in gets the bootstrap token.I know it's possible to manually grant the local account volume owner status but that requires the current volume owner account details which in our environment is the local accounts created by Jamf Connect all as unique usernames and passwords so this cant be scripted and automated directly.
Bonjour tous,Nous avons quelques soucis de gestion réseau pour JAMF. Est ce que quelqu'un aurait l'intégralité des accès à ouvrir pour que Jamf version cloud fonctionne parfaitement. Il semble que des IP d'accès changent régulièrement ...Merci beaucoupPY
I am getting the message saying "Self Service is a component of Jamf Pro, developed by Jamf. This app must be associated with a Jamf Pro Server. Contact your IT administrator for more information." We use automated device enrollment and the iPads experiencing this issue are enrolled into our Jamf instance. Our Self Service app is set to be installed manually to avoid Apple IDs. I have already set up the app configuration as seen on the Jamf Pro documentation. Is there anything else that I am missing? Thank you!
I've currently got an iMazing Config profile and a Jamf Login Configuration profile that is restricting everything including these 2 items but despite both of them restricting the Apple ID and Siri prompt for login, new users are still getting this! Does anyone have any ideas?
What's the best way to silently uninstall Backblaze off people's computers? We've had it for awhile and recently decided to stop using it, as it wasn't being used and move people are just using OneDrive or Dropbox accounts we've given them. I know there's a guide from Backblaze itself, but it seems to require other steps: https://help.backblaze.com/hc/en-us/articles/115003602813-Silent-Uninstaller.
Hello!We already use Jamf School in our school.Now we would like to use the “Jamf School Student” app.We would like to prevent the request for data protection information and access permission for Bluetooth, notifications, etc. from being displayed when the app is opened for the first time.With a managed app configuration, we want to allow the corresponding access, etc. during installation.Maybe someone has an idea what the managed app configuration could look like?Thanks!DominikDeutsch:Hallo,in unserer Schule nutzen wir bereits Jamf School.Nun möchten wir zusätzlich die App "Jamf School Student" nutzen.Wir möchten verhindern, dass bei erstmaligem Öffnen der App die Abfrage zum Datenschutzhinweis und die Zugriffserlaubnis für Bluetooth, die Mitteilunge etc. angezeigt wird.Mit einer verwalteten App Konfiguration möchten wir die entsprechenden Zugriffe etc. schon bei der Installation erlauben.Vielleicht hat ja jemand eine Idee, wie die verwaltete App Konfiguration aussehen könnte?D
Hey everyone, I have three issues with Jamf connect and would love some guidance please. Issue 1: Everytime I reset my machine and login through the jamf connect login window it always reverts my admin account to a standard how can I have it not do that? Issue 2: Upon multiple restarts the Authchanger doesn’t kick in and the login window still appears and when it does work it will work on the second restart but we want the login window to disappear on the first restart Issue 3: We use our company logo for Jamf connect menu bar but once it launches it show the default menu bar then upon restart our company logo appears
Hello,I have enrolled a new macbook on the MDM server without PB.But I can't see it on jamf pro and I don't know why . Do you have any suggestion ?Thank you
Hello !Since the last update of Jamf Pro and the dark mode (Many thanks for that !!!), I now have the management interface switching back to french to each new login despite the fact that the account preference for the language is set to english. It's better for me to have the interface in english than french because most of the informations I need are in english and thus, it's easier for me.Is there a way to lock the language preference once for all ? I already removed the cookies and data for the website but it changed nothing...Thank you for your help !
So we're a Jamf Pro school with iMacs and iPads--iPads are for grades preK-3. All commands for all iPads are stuck at pending (no failures, just pending) and they haven't checked in since 3/31/2023. All devices have internet access, they're just not getting any policies or checking in at all.iMacs are fine. I don't believe it's a certificate or token issue, but not sure what it could be. I'll give Jamf Pro support a ring in the morning, but figured I'd throw it out there in case anyone has a quick fix. Devices are all running current or reasonably current iOS.
Hi All,I need to find a way to set MacOS to use Microsoft Edge as the default browser. Either by script or config profile. Alot of auth/token services do not work with Safari on Monterey so would like to avoid using it altogether. We would also like to give users the option to move to a MacOS device and a good attraction is the ability to sign into Edge (which they used on their Windows machines) and have their favourites, browsing history and cookies appear on the MacOS version of Edge. Any help would be greatly appreciated. Gavin
I am trying to create a smart group that will show me Macs that have been booted for more than 7 days. Many times, my team gets support tickets from users that would not have been necessary if they had rebooted their Macs at least once a week. I love that Macs can stay booted for a really long time. My record is 92 days, but to get there, I had to put up with some quirks and minor issues. I just wanted to see how long I could go between reboots. I don't want my users doing this, so I want to create a smart group for Macs that are booted up longer than 7 days, and then display a message asking them to please reboot soon. I have found extension attributes that will show me the up time, or last reboot, but when I go to create the smart group, the operator shows only is, is not, like, and not like. What I need it to show is something like "more than X days ago". Does anyone know how I get this? Maybe I'm using the wrong extension attributes?
The jamf profile description file is incompletely deliveredThere are 10 files, but only 5 can be installed
hi all, i need some advise input from anyone about my environment. we just recently build a new NDES Cert server and we use Azure App proxy pointing to our NDES to deploy 802.1x certificate to allow our azure joined windows devices access to our wifi (we use Cisco ISE for authentication and authorization). We currently have our macs bound to the domain to allow cert request (so it can request cert from the old CA if its in office). We recently got our Jamf Connect setup and have no reason to bind to domain anymore. I want to ask anyone advise of what is the best practice for us to deploy our 802.1x cert to our mac that will be Jamf Connect only? is it possible to integrate our Jamf cloud with our Azure app proxy for certificate deployment (just like intune - windows)?Or do i need to go with Jamf AD CS Connector? or do i go with setup Jamf SCEP so it can point to my NDES server (on prem)? i prefer not to do this as I want to limit the amount of network connection between my NDES servers
Hello, I noticed that "private navigation" is now accessible on Safari despite using a "web content filter" profile present on the devices. Deleting history is still impossible. Thx.Christophe
Hello everyone,I'm looking for help deploying AppleScript through Jamf Pro. I know the basics of bash scripts but almost nothing about AppleScript. I got the following AppleScript from one of our network administrators:tell application "System Events"set macUser to name of current userend telltryset FortiDir to POSIX file "/Users/Shared/Fortinet/Forticlient"set ztnaConfig to POSIX file "/Users/Shared/Fortinet/Forticlient/ztnaconfig.json"set FortiDir to POSIX path of the file FortiDirset ztnaConfig to POSIX path of the file ztnaConfigdo shell script "chown -R " & macUser & " " & FortiDir with administrator privilegesdo shell script "chmod 755 " & FortiDir with administrator privilegesdo shell script "chmod 644 " & ztnaConfig with administrator privilegesdisplay dialog "BW FortiClient permissions patch successful"on error theErrdisplay dialog "File permissions update failed for " & FortiDirend tryI tried to deploy it as a shell script in Jamf like this:#!/bin/bash
I feel like I'm just missing this somewhere, but is it possible to query the api to find the Jamf pro management ID? I know where it lives in the console but I would like to programmatically send a wipe computer command to device through this endpoint: https://yourserver.jamfcloud.com/api/v2/mdm/commands and that requires the Jamf pro management ID. If there's a better way to wipe a device other than this endpoint, I would also like to know. Thanks!
Not directly related to Jamf, but for those of you working in Colleges and Universities, what are the benefits of managed Apple IDs for your users? This is via SSO/Federation in Apple School Manager.
I created a policy to create a local account. The account gets created successfully with the policy but for some reason the password I set in the policy does not work. Has anyone run into something like this? It is not working on a specific laptop cart that uses 2017 MBAs that were manually enrolled. Not sure if that has something to do with it, but it is working on other devices. Any ideas?Thanks
I'm looking for a way to run a script to log any active users out of 0365 or Microsoft Office apps without removing the license from the Office apps. Log out Office, O365, OneDrive. Use case: A classroom that has many teachers using one computer. I want to run clean up on restart of that Mac to make sure it is ready for a new day and not logged into any specific accounts.
Wir arbeiten als Schule mit JAMF School. Unsere Schüler-iPads haben ein Profil laufen, dass morgens um 7:30 Uhr Apps ausblendet. Die Zeitschaltung ist von 7:30 - 13:30 Uhr aktiv.Leider melden mir Schüler zurück, dass dies oft nicht funktioniert. Teilweise beginnt die Sperre erst um 08 Uhr und endet auch erst um 15 Uhr. Das sorgt für Unmut. Gibt es ähnliche Probleme an anderen Schulen? Wie kann der Fehler behoben werden? Welche Einstellungen werden für Schulen sonst generell empfohlen?Danke.
Hi,We are having trouble with some students, they are taking off the WiFi at the first hour in the morning, and the profiles do not enter, I am doing a re-push manually to try to catch them, but it's annoying, is there any script I can use to re-push a profile? Thanks a lot.
We used to use JAMF Composer to be able to deploy files to our Macs using package files. For example, I have our JAMF Connect login screen and icon deployed to our machines using a package I built in Composer installed at enrollment by JAMF Pro. For some reason, my JAMF Composer stopped working, even after a reinstall. Therefore, I am looking for an alternative for package building where you can add and remove files from a package. Any suggestions? Thank you!
I'm looking for the best way to prevent all Mac users with local admin privileges from removing a wireless/wired profile and SSID configuration for a specific wireless/wired network.The goal is to ensure that the wireless network settings are enforced and cannot be modified or removed by the end-users, even if they have admin access on their Macs.Is this possible?
I've been tasked with the pain staking job of documenting JAMF, how each policy works, what are it's dependancies like Smart Groups, EAs, Packages etc. I'm intrigued how others have done it and whether anyone would be willing to share a template perhaps? Obviously we use Code commit which is fine for techies but I need to cater for non techies too.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!