Get Support
Recently active
Have an application that I want to use with that (EndNote) but it needs some extra scripts to run (with SmartGroups) after installation but I cannot find the "Update Inventory" option after this application is installed. (manually) is that not available if you use Mac Apps ?thanks
HiAfter upgrading MacOS to Sonoma 14.4.1 Jamf Connect: Request Admin Privileges has stopped workingI got this error:User is blocked from further elevations due to system time tampering.
Can one display what site a Jamf deployed computer is in from the Terminal application on the client?
We have found ourselves in a situation where a user created an AppleID for the purpose of logging in to the Mac App Store to install some apps.When he did that, the Mac latched on to that AppleID and enabled all the goodies that AppleIDs can use - including Find My Mac. The problem is that the user's Mac has died and needs to be repaired. The user has no idea what his AppleID password is and he's locked the account. Account recovery apparently takes 3 weeks to complete. Since Find My Mac is enabled and the user has no way of logging in on the computer nor on iCloud.com we can't disable it or remove the computer from the account. We may have to write this computer off and move on. (Another similar situation that you may find yourself is that a former employee logged in with their AppleID, but didn't remove it from their account when they left and now the computer needs repair while that user is 100% unreachable)What I would like to do is identify all Macs that have an AppleI
I purchased and app through ASM that is compatible with macOS and iOS. I want to deploy it to our macOS devices via Self Service but it only shows up as a Mobile Device App and not in the Computer side. How can I make it available to the computer side?
I am attempting to install AndroidStudio 2023.2.1 on systems that are currently running 2023.1. I am using the patch management system to deploy these updates. I have taken the dmg file from Google and converted it to a pkg file with composer. However when I push it through patch polices I get an error stating that the program is trying to install to the system volume. See error below. Any help would be appreciated. installer: Package name is AndroidStudio - Iguana | 2023.2.1 Patch 1 installer: Upgrading at base path / installer: The upgrade failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. The package is attempting to install content to the system volume.)
I've been down the rabbit hole of deploying Cisco's new Secure Client and I am running into an issue that I cannot find any documentation on. Some context: we only need the Umbrella Module for our school and nothing else that is loaded within Cisco's PKG. I have been successful with deploying the choice XML file, but I get the following pop-up in the installation: I would like this permission to be enabled within the config profile I built in jamf, but I can't seem to locate any of the info I need to do so. I already have gone through Cisco's docs and pushed out the System Extensions payload, but that seems to be just for the Cisco Secure Client itself and not this "AnyConnect VPN Service." If I manually toggle it on, the Umbrella Roaming Module will activate and work as it should, but if this is not toggled on, then the roaming stays inactive. Any ideas? I am assuming there is something I am missing in the System Extensions payload, but I could be wrong...
Hello ,Need a suggestion with the macOS patch management.in our environment we are managing different OS version.Eg: we have 100 device with macOS 12 , 100 device with macOS 13 and respectively 100 device with macOS 14If we need to update patch in macOS 12 to latest 12.7.4If we need to update patch in macOS 13 to latest 13.6.6If we need to update patch in macOS 14 to latest 14.4.1What is the best practice we can follow , thank you
Our mac users work off multiple servers we have. We just got them set up all on jamf a few weeks ago. They are testing out their new macs with Jamf. Whenever they make changes on one of the servers they mount, whether it is creating a folder or deleting something. They will get a prompt asking for admin credentials on this mac. Is this anyway to disable this?
Thank you @DFree & @MikeF - This worked nicely - I did some editing:Use directory: cd /Library/Application\\ Support/tmpDownload anyconnect-macos-4.10.03104-predeploy-k9.dmg from Cisco (or your vendor) and open it via installer (Double Click it in finder).Drag the AnyConnect.pkg file inside the .dmg to your tmp (for simplicity) and then do @MikeF's steps (4-9 below):Open Terminal and cd /Library/Application\\ Support/tmpPkgutil --expand AnyConnect.pkg AnyConnectVPNWent to the tmp folder, opened the AnyConnectVPN folderopened the AnyConnectVPN/Distribution fileLook for <choices-outline> <line choice="choice_vpn"/> lines starting around line. Delete the ones you don't need, and Save. (I Used Xcode to edit the file)pkgutil --flatten AnyConnectVPN AnyConnect_4.10.03104.pkgUpload that pkg file to JSS and go from there in however you want to deploy it.
Hi,We are in the process of setting up Jamf Pro and added our Azure tenant as a cloud IDP. Jamf Connect has been setup so we are able to sign into the device with our AAD credentials and the account is synced with a local account on the device. This is working as expected. I am slightly confused as the User and Location information is missing from the device inventory, should this not be pulling the information from our Azure cloud IDP? Also is it possible to target applications/policies and configuration profiles with AAD groups?Apologies if this is a simple answer however we are new to Jamf coming from a Windows background so slightly confused at the moment!TIA.
Hi All,We presently have behaviour where devices which are registered and marked as compliant in Entra using partner compliance are showing as unregistered and failing. These failures appear to be sporadic and some devices are showing as successfully bypassing the CAP with the same apps and registration status. Re-Registering doesn't seem to fix the problem.Has anyone else had this? We think this may have occurred after turning off partner SSO last week and requesting people re-register for compliance as it hadn't come up in testing prior to this.Is anyone else still having issues with conditional access policies.
For some years now we've been encountering the odd mac where even though newly-enrolled, the local admin password does not work. With no way to login, we were reduced to Recovery Console, wipe and re-enroll. To mitigate this we created a backup admin account to allow us a way in, but with the advent of Secure Token things have got weirder. Has anyone experienced this? Here is our setup:1. Our student macs are enrolled with a prestage where a single local admin account "Admin1" is created before setup assistant.2. A Jamf policy then creates a second admin account, "Adminbak". 3. Setup assistant does NOT create a local account, instead we later bind the macs to ADS and network users then logon. Adminbak was created to be the first account created after setupassistant, so it would get Secure Token. Our onsite techs can then logon to each machine with Adminbak to enable bootstrap.Here are our symptoms:4. We are finding that Admin1 has Secure Token instead. We don't k
Curious how everybody is remediating that new supply chain vulnerability for XZ. My security team sent me this link - xz-backdoor-attack I'm guessing an EA to locate non-patched versions, but what about deploying/updating the version? I'm guessing a lot of them were done using brew.
With the loss of the Teacher WebApp, 50% of our teachers can't control our student devices. This is a really big problem!We need a device-independent control for teachers! So please bring back the Teacher WebApp.
Does anybody know what field the "Display Name" attribute in JSS MUT maps to in the JSS? Is that the Computer Name? Thanks.
We are new to JAMF. Our JAMF instance is on Cloud and we have Infra Manager. Firewall ports are opened to connect to Inframanager. However we are not able to query any users. If we do a test. Below is the error message. Any suggestions are appreciated. ERROR:Unable to connect to the LDAP Server. SUGGESTION:Ensure that the username and password provided are valid. Infra log is as belowClosing connection because of SSL problem: Remote host closed connection during handshake.
Anyone has a reboot script that Allows deferral and uses Jamf Helper?. Would like to attach it to an apple updates policy. After the policy runs, it should prompt the user to restart the machine. The user should be allowed to postpone that reboot at least once before it reboots on its own. I have seen some that uses CocoaDialog. We cant/wont use Cocoadialog here at our company.
A few users updating from 13.6.4 to 13.6.5 have run into an issue where all the background applications have been removed. There is also trouble running some supplemental apps like the 1Password desktop app and Privileges app. It doesn't seem to matter if the background application was associated with an MDM payload. Even the jamf processes end up not running. Has anyone else had this issue? The users can log in, but since all the background services are wiped out many things like VPN, Jamf and Security software no longer function. I guess it isn't a black screen this time, but still.
Hey everyone, I notice that on one of our tests machines in the policy logs it shows that there are two deps running. I looked at one of them in the policy and I see it is scoped to a smart group. Would it be easy as removing the scoped smart group and have it only scoped to one DEP?How can I have only one DEP run?
Hi all,I'm new to Jamf Connect so I might be doing something wrong, or forgot a step somewhere. Whenever a user is logged out and they want to login again, they see the Windows login screen. How can I disable that so they only see the local user that Connect created? Is that even possible? Now they have to type in their email and password, and knowing the end users, they might see that as too much work or confusing :)Bit of background info; I'm using Jamf Connect in combination with Jamf School. If you need more, let me know!Thanks!
Hi everyone, We just implemented Jamf Connect and are still testing it. We had issues with devices randomly getting kicked off AD, so since we are on AzureAD now, we decided to get Jamf Connect. When we set everything up when a user logs in, we can reboot the machine, and someone else can log in. Now, after a reboot, no one else but the last user can log in. How can I get out of this? What are your best practices for using Jamf Connect in a lab environment? Thank you
Has anyone figured out a way to push a config yet to File Maker Go 19? We will be using FM Go 19 to connect to a database on a host server on multiple iPads and I'd rather not configure each iPad. I heard of webclips being used but anyone else has a better suggestion on how they pushed out a config, please share your experiences. If you did use webclips, please share.
Hey guys,I actually fixed this issue thanks to Jamf's support, but I wanted to make a post in case anyone else out there Googles the issue I had.I was attempting to install the AD CS Connector on a brand new server (Windows 2022). When running the Deploy script downloaded from the Jamf website, it would go through the script and finish with no errors, but it would not generate the two certs it was supposed to. The last line produced in Powershell was "Adding Windows Firewall rule to allow inbound TCP traffic", then the script endedAfter talking with Jamf support, it seems that the AD CS Connector version 1.1 has some settings turned off that are need to be on if it's your first installation. What I did was right click the deploy.ps1 script -> Edit, which opened it in PS ISE, then changed the Parameters listed in the first bunch of lines to this:param ( [switch]$help = $false, [string]$archivePath = ".\\adcs.zip", [string]$installPath = "C:\\inetpub\\wwwroot\\adcsproxy",
Is there any benefit or drawback to installing config profiles through prestage (where it says "Use this section to add configuration profiles to the PreStage enrollment") vs. after enrollment (a config profile scoped to all computers)?If the former is advised, would I then remove all scopes in the actual config profile(s)? As it stands, right now we don't install via prestage. Rather it enrolls, it does its thing, then installs policies and config profiels.Thanks folks! :)
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!