Get Support
Recently active
I’m curious to know how other organizations are handling OS updates. Not so much in terms of applying them but more so in terms of testing. How long do you typically defer updates in your environment? What is your testing methodology and criteria for deployment?
Hey folks! I am looking for some real-world architecture advice from people managing more segmented Jamf environments.In previous companies, my Jamf setup was relatively straightforward:- one main device type,- mostly shared configurations,- common app stack,- unified policies and profiles.Now I’m building a more segmented environment and trying to design it the “right” way before things scale too much.We’ll likely have multiple categories of macOS devices with different requirements, for example:- standard daily-use employee Macs,- security/guard team devices,- travel/restricted devices,- possibly more specialized fleets later.Each category may require:- different app sets,- different restrictions,- different onboarding flows,- different compliance/security baselines,- different Self Service experiences.I’m currently building around:- PreStage Enrollment,- Jamf Setup Manager,- smart groups,- scoped policies/profiles,The thing I’m trying to figure out is the long-term architecture stra
Running into these messages when trying to log into Self Service+ 2.21.0. No changes have been made in Okta or in Jamf. Its also saying my password isn out of sync when no changes have been made there either. Wondering if this is a bug considering 2.21 was just released 3 days ago and we just discovered it today.
Hi All, Is anyone else having issues with enrolling MacBooks in their Jamf Pro environments? Every time we've tried to enroll a new MacBook Pro this week we're getting hit with "Enrolling with management server failed. Unexpected error (MDMResponseStatus:502)". Jamf Support had me try a few things like trying a different Prestage Enrollment Profile or even removing some packages from Prestage but no luck. Any help would be appreciated. Thanks
Hello there, Im a bit rusty so any help would be appreciated.Im writing a script in jamf pro which uses the computers-inventory API to grab info on a specific computer. So far I have thiscomputerID=$(sudo jamf recon | grep computer_id | cut -f2 -d '>' | cut -f1 -d'<')computerInventory=$(curl -s "${apiURL}/api/v3/computers-inventory/${computerID}" -H "Accept: application/json" -H "Authorization: Bearer ${apiBearerToken}" -X GET)#EXTRACT managementID out of computerInventoryI have no idea how to extract the managementID field out of computerInventory. Im trying to avoid jq cause I dont want to deploy that to all the macs in the fleet.Any help would be amazing.
I'm looking for a way to send the 'wipe computer' command in bulk to our Labs so that they can be refreshed at the end of semester.I gather this will require use of an API client and secret.I'm wondering if anyone has come across a script that can do this?
There are hundreds if not thousands of Terraform examples and walk throughs on the internet today. Most of them start in a clean environment. They assume a brand new account. No history. No surprises.But that’s rarely the situation most of us inherit.More often, we’re working on something that’s been evolving for years:Resources created manually in a GUI Naming conventions that shifted over time Temporary fixes that became permanent Configurations that “just work,” but nobody is entirely sure whyApplying Infrastructure as Code (IaC) using Terraform in an existing, already-provisioned environment is often called Brownfield Terraform.You’re not building from scratch.You’re (very carefully) translating the current reality into code. What Does Success Actually Look Like?Before getting into mechanics, it helps to define the goal. In a brownfield migration, success is not:Rebuilding everything Refactoring immediately “Cleaning it up” on day oneSuccess is simpler. You run: terraform planAnd T
Everytime I try to delete an old smart group or static group that happens to be in scope of multiple policies I then have to go to each policy and remove it from scope first and then I'm able to delete it.There's gotta be a better way to do this.Is there a feature request or something that will allow me to delete it without having to remove it from a bunch of policies first?It's a big waste of time. Add a checkbox for the user to select to allow removal from any policy the group is in.
• iOS - 50+ CVEs patched• macOS - 60+ CVEs patched• link: https://support.apple.com/en-us/100100
Can't seem to find an answer to this so I suspect that there isn't (a satisfactory) one...Security and Privacy best practice says to disable iOS notification previews, especially when a device is locked. This is what I want to set using Jamf Pro.I know I can set Notification preferences per app, but the setting in the screenshot is global and can be set on the device, but is there a way to configure this device-wide setting with Jamf Pro?There is a specific Jamf article on this, from the UK NCSC (National Cyber Security Centre), which refers to this specifically, but does not reveal how to achieve this exactly.https://www.jamf.com/blog/updated-device-security-guidance-from-the-uks-national-cyber-security-centre/This is the relevant paragraph: Hopefully I'm just missing something 🙏
Hello,I’m currently using Lost Mode in Jamf Pro to disable iPads / iPhones that are not returned to the IT Helpdesk.Occasionally, when these devices are returned, they have either run out of battery or have been restarted while still in Lost Mode. After rebooting, the devices are locked down; No WiFi, Ethernet (with working adaptor) or not connecting to Mac via Apple Configurator.Because the device is still in Lost Mode, the passcode cannot be entered, and the device is unable to check in with Jamf to receive the “Disable Lost Mode” command.This leaves the device stuck in Lost Mode unless it is restored via Recovery Mode.Has anyone found a way to:Ensure devices reconnect to a network after reboot while in Lost Mode, or Remove Lost Mode without requiring a full restore?For context:Devices are supervised and managed via Jamf Pro Enrolled via Automated Device Enrolment No cellular connectivity for iPads (Wi-Fi only devices)Any advice or best practices would be greatly appreciated.Thanks i
Hello, For software updates and the type of install action, does “Download and Install” reboot the computer automatically or will it allow the user to restart on their own to complete the installation?If it does reboot automatically, how is it different from the option to “Download, Install, Restart”?
I have a script to lock a Mac via API. No issues with that. It works very reliably.I would like to use this script it to lock a Mac system when it has not updated inventory in over X days. Think of a Mac that has been shoved in a desk drawer for a while. This would force the user to contact the help desk to get it unlocked and explain why it has not bee online.This is an easy enough policy and smart group to build. Last Inventory Update more than x days ago.But testing is a pain in the butt. I have to wait 24 hours for “Last Inventory Update” to get to at least 1 day effectively test the policy.Anyone know of a way to change “Last Inventory Update”?
Looking for some guidance with Jamf Pro - PreStage Enrollment and FileVault.The issue: In PreStage, we pre-create and hide a local admin account. During setup, the workflow prompts for end-user account creation. FileVault is enabled immediately after the user account is created and the user logs in for the first time. As a result, only the end user is added to FileVault , the local admin account is left out of the FileVault enabled users list. I haven’t found a way to ensure the local admin is automatically included in FV2 during enrollment.Should this be configured differently in PreStage, or would scripting the local admin addition after FileVault is enabled be the right approach?
Up until Sonoma I was using this script https://community.jamf.com/t5/jamf-pro/wifi-switching-script/m-p/139275/highlight/true#M128353 But now I can no longer find something that will work. This was handy because it only worked when the school SSIDs were available.Does anyone have something they use in a school environment? Thanks in AdvanceMatt
All,We just signed up for Jamf pro and I am in the naming instance area during set up. Does it matter what I name this such as the company name? I am new to the setup area so just making sure as its not changeable afterwards.
About 75% of the apps I'm trying to push to an open enrolled freshly provisioned Macbook Pro aren't installing, I am using Jamf Now Plus and have test a variety of apps including Keynote, Numbers and Pages. I have "purchased" a pool (100 licenses) through Business Manager and they show up correctly in my Jamf portal. However when trying to install I am getting a "License Not Found" error dialog (with the Mac App Store icon) on the Computer and an "Installation failed. Will retry in 24 hours." error inside of the Device profile on Jamf. The odd thing is I've tried with some paid licenses such as Pixelmator and that worked and in some cases Pages work but Keynote and Numbers keep failing.
Hi All,I have noticed a strange issue after upgrading to 12.4. Post upgrade, automatically the device's registration status has been changed to "Unregistered". I tried registering the device from self-service portal and it got registered. However, compliance information is not getting updated in AAD and due to that unable to access office resources. I did force update of sending Intune integration logs from Jamf Pro --> Device's history --> "macOS Intune Integration Logs" and it's sending the update to Intune. Somehow the compliance is not getting changed.As part of troubleshooting deleted both the entries from AAD and re-registered the device but still the compliance is not getting updated. Any help is much appreciated.
Hi there,I have some machines with standard accounts and users are being prompted to install the helper tool which is frustrating them...I was under the impression that installing apps via polices / self service would prevent this from happening? The main culprits being ClickShare & Slack! My apologies if this is basic stuff, I'm a Windows guy transitioning over to Mac! Any guidance is seriously appreciated. Thanks in advanced,K
Hi all, After upgrading several of our Macs from older versions of the OS, we have started getting pop-up dialogs asking users to provide admin credentials to add helper tools for various apps (Skype, Brave Browser, Spotify, etc). Most users just click Cancel to dismiss the boxes but I'm concerned we're not staying updated. Also it's pretty annoying. Google led me down a rabbit hole with Skype that didn't fix the problem, and this seems to be happening to several applications. Has anyone seen these pop-ups and if so, what's the fix? Thanks!
Hi Everyone,!I am working with a client who renewed their APNs certificate using a different Apple ID. This resulted in a Topic ID mismatch within their Jamf Pro instance. While some devices are approaching their MDM profile expiration, a majority are set to expire by the end of the year. Because the current APNs certificate is inactive for these devices, the "Renew MDM Profile" command is failing with a "Topic ID mismatch" error. Does anyone have suggestions for automating the re-enrollment of devices that still have valid MDM profiles but are tied to the old APNs certificate? I am looking for a way to transition them to the new certificate without manual user intervention.!--tgqphd|[]-->
We had touch fail on an iPad so we purchased a replacement. The original iPad is for a special education student and has a lot of specialized and customized apps on it. Is there any way in Jamf that we can transfer the apps and their configurations over to the replacement iPad? Thank you!--a=1-->
Today we released Jamf Connect 3.9.0; this release addresses the following product issue:Fixed: WebAuthn authentication methods, such as passkeys and FIDO2 keys, incorrectly display as Duo Mobile in the Jamf Connect login window. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect.Product DocumentationFor additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hello all Apologies if this has already been asked and I have missed it, but has anyone got away of collecting the applications installed by home brew?
Hi. Started seeing this error on applications pushed to Macbooks through DeviceGroups during enrollment. Apps are set to automatic installation. Tried to resync licenses with ASM without luck. Trying to reinstall the app sometimes gives the same error, or it works. I have been unable to see any reason for when this is happening. It seems totally random, and happens on all sorts of applications.Update! This also happens on random OnDemand applications where students adds them from Jamf Student.Anyone else seeing this, or know how to resolve it? This is how it looks from the Jamf Student application. The students are not able to retry, the teacher is not able to redistribute the app. Only “solution” is to hope that a reinstall from the managment site works. This is hit or miss.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!