Get Support
Recently active
I have 7 devices that I am trying to push Logic Pro to via self service. We have enough licenses so I know that is not the issue. Looking at the console logs I get the below. default 15:07:16.234430+1300 appstored [DIS1962A88F/com.apple.logic10:634148309] Waiting for installation to completeerror 15:07:16.250534+1300 authd credential: failed to get user uid -1error 15:07:16.256192+1300 authd credential: failed to get user uid -1error 15:07:16.261858+1300 authd credential: failed to get user uid -1default 15:07:16.266027+1300 authd Validating session owner invalid (-3) for is-appstore (engine 116)default 15:07:16.266052+1300 authd session owner -3 invalid (does NOT satisfy rule) (engine 116)error 15:07:16.266540+1300 authd Fatal: interaction not allowed (kAuthorizationFlagInteractionAllowed not set) (engine 116)error 15:07:16.266747+1300 authd copy_rights: authorization faileddefault 15:07:16.267709+1300 appstored Requiring admin authorization for software install by managed prefer
Has anyone successfully implemented SUPERMAN for their MacOS patching? I've got in place the Config for the settings I want, I have the API set and an policy to deploy out SUPERMAN. Question now is that if I set everything through the config file and deploy out SUPERMAN does it's own thing in the background and from a management standpoint I don't know what its doing. The first time deployment I can see that its pulling the device info, can see its authenticating with the API and then says that Jamf is the parent process, restarts super in LaunchDaemon then Jamf gets nada after that. The local log shows exactly what its doing. At the end of the log it restarts all deadline counters and the workflow schedules itself to relaunch after the time I set.So my question is, has anyone been using Super and figured out a process to see the logs of what its doing on the devices? I'm still in the testing phase as I want to know what to expect before pushing it out to actual user devices. I'd also
While uploading any PKG, I'm getting the message There was a problem uploading the package to Jamf Cloud.Connection failure: "The operation couldn't be completed.(error 500.)" , so please reply to me with the solution.
https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/Jamf_Push_Proxy.html In our JAMF Pro server logs hosted in jamfcloud, there are a lot of proxy push errors. We've had Jamf Pro for seven years. This has never been setup. Should it? Is it important? I'm not aware of any real issues occurring, just these errors in the log over and over. Doug java.lang.Thread.run(Thread.java:829) [?:?]2024-03-18 19:01:41,645 [WARN ] [@Async-1 ] [NotificationEventListener] - Exception occurred when trying to add macOS Self Service push notification to queuecom.jamfsoftware.jss.exceptions.pushnotification.PushProxyConfigurationException: JAMF Push Proxy is not configured
Has anyone begun migrating Cisco Umbrella client to Cisco Secure client yet?I have Cisco Umbrella client distributed with Jamf Pro, now it is announced as EOL in 2024, with Cisco Secure client as the new client.Is there someone out there that has tried migrating? Looking for caveats or something worth thinking about before getting hands on upgrading my workflows and enrollment profiles.
Today we released Jamf Connect 2.33.0. This release includes the following changes and improvements: Privilege Elevation using Jamf Connect The Jamf Connect menu bar app allows standard users to initiate a temporary promotion to a local administrator. Upon activation, a timer will appear in the user's menu bar for the duration of their promotion. When the timer ends, the user will be reverted to a standard user. This feature can be added to your Jamf Connect configuration with the Temporary User Promotion (TemporaryUserPromotion) setting manually or via the Jamf Connect Configuration app. For more information, see Privilege Elevation for Local Accounts. Other Changes and Improvements Jamf Connect Configuration no longer displays the deprecated Azure v.2 option in the Provider menu. Jamf Connect Configuration now provides a notification with information on new features included in the currently downloaded version of the application. To access new versions of Jamf Connec
Is anyone else experiencing devices falling out of registered status and thus being marked non-compliant in Microsoft Entra when using the Jamf Pro Device Compliance integration? The users are still within the "Compliant" Smart Group in Jamf Pro but they fall out of registration. The Jamf AAD plist is missing and there is no MS-ORGANIZATION-ACCESS entry in Keychain. If I have the users re-register using Self Service/Microsoft Company Portal it will be fine for a while and the Jamf AAD plist and Keychain entry will reappear but then after a couple of weeks the same thing happens all over again. Jamf Pro version is 11.3.0 so it shouldn't be related to the recent product issue.
Hello,I would like to get all of our Macs up to date and create a plan to maintain this. I would like to use the ScheduleOSUpdate command with the InstallLater command as described in Use MDM to deploy software updates to Apple devices - Apple Support My questions are:Can these apple commands be used in a configuration profile that gets deployed via Jamf Pro? I am having trouble finding an example or specific guidelines.Or are these commands intended only for a Mass Action Command as indicated Introduction - Technical Paper: Deploying macOS Upgrades and Updates with Jamf Pro 10.34.0 or Later | Jamf ?How can I see the status of a Mass Action Command after I send it to multiple computers?I would love to hear your experiences if you have tried the ScheduleOSUpdate or if you have other suggestions. One more question on a similar topic. I created a Configuration Profile (in Jamf) for software updates. Does the Software Update Server need to be filled in if
Our students have discovered the password to our "vendor" network, which is unfiltered, and have been putting both their personal devices and their school devices on this network. We are working on dumping all connections and changing the password, but I am wondering if there is a way for me to block this network from being joined on our student devices? I had thought initially that I could push this network out to all devices with the wrong password associated with it. This does work but it also is interfering with our student network and causing an error with not being able to join that network either. Thoughts? Suggestions? TIA
When the machines have been started this morning, compliance issues were found and the Company Resources were unavailable. In the Company Portal application which is also connected to the Jamf Pro, there were two different devices with the same serial number: one was marked as compliant and the other as non-compliant. Upon refreshing and the status, the same device had still two entries: one entry showed as compliant and the other one as non-compliant. As a solution for Compliance issues, we have the dedicated procedure as seen below:Restoring ComplianceIn the event of non-compliance, users can follow these straightforward steps to restore their MacBook's compliance. Click on the respective button on the right to open the respective guideline in your support app.1. Install System Updates:Make sure that all relevant system updates are installed on the MacBook.This ensures that the device is up to date. Install Updates2. Executing Policy Updates:Implementing the latest policy updates ens
We are new to JAMF Cloud and would like to integrate our Google G Guite as our identity provider with our JAMF Cloud instance. We got the following linkhttps://www.jamf.com/jamf-nation/articles/440/configuring-single-sign-on-with-g-suite-google-apps Followed the steps, but got app_not_configured_for_user 403 SAML2 error. Anyone has a sample config template that works? Thanks for your help.
We need to downgrade a bunch of machines back to safari 17.3 from our recent update to 17.4 as the devs need it for their contract work with our clients, any ideas on how to do this?
Good afternoon, I am at a loss in an improvement that I am trying to make to speed up our student enrollment process.Current Situation - We have 2500-3500 students that enroll in our Further Education establishment yearly and each one of these students receive an iPad. In our current setup, we have it that the iPad is freshly wiped and the students will have to go through the process of; Signing into Wi-Fi (This is a pain because the students password is set to change on first login, they cannot authenticate to our Wi-Fi before they change their password. So typically, they will have to use a secondary device to go to Office365 to update their password first.). Using their Active Directory account and credentials to enroll the iPad. Signing into their managed Apple ID. Agreeing to Terms and Conditions, etc. and turning on Location Services.This is a time consuming and tedious process when you're running four enrolment sessions over four different zoning areas per day of 20-30 stud
Hello, I need a daily report. Our security team want a daily report like this. Does Last users has admin rights? How can i do that? I need your help. Thank you.
Just in case anyone needs this I wanted to post it for an updated resource.#!/bin/bash # Script Name: Disable Slack updates.sh # Author: [Michael Cleveland] # Created On: [Creation Date, e.g., 2023-10-31] # Last Modified By: [Michael Cleveland] # Last Modified On: [2023-10-31] # Version: 1.0 # Description: # This script modifies the Slack application's preferences for the currently logged-in user on macOS. # It specifically sets the 'SlackNoAutoUpdates' key to 'true', which prevents the Slack app from auto-updating. # Usage: # Ensure that Slack is not running or is restarted after this script runs to apply the changes. # Note: # This script uses PlistBuddy for editing plist files, as it ensures the file's integrity. # Be cautious when editing plist files and always ensure backups are made before script execution. # [Here starts the actual script code] echo "Starting the update of Slack preferences..." # Get the current logged-in user USER=$(stat -f %Su /dev/console) # Path to t
Hello all,I have an issue showing up at random with only a select few of the iPads I manage. A certain app will not install but will show up on the device grayed out and typically says Waiting (it is properly scoped and we have enough licenses). When you click on the grayed-out app, it either does nothing or prompts to be installed via the App Store.I'm also not able to install it through Self Service. The "Install" command is non-responsive and JAMF shows the command as failed, citing that the app is already scheduled for management. I am not able to delete the grayed out app because it's not installed. I supposed I could install it through the App Store but I shouldn't have to. The iPads are 7th gens running the latest iOS and have enough storage available to install the apps.Thanks!
Hello,what is the best way to remove Jamf Trust from the devices (macOS)?The configuration is quickly deleted, but what about the app? We have rolled it out via the App Store using VPP licences. Thank you
Hi,Jamf is supporting default scripts for checking time machine backups. But with new versions of mac os this won´t work beuacse diskutil is using PlistBuddy. This has no disc access. If i enable Terminal in full disk access those scripts are working again. Without disc access With disc access How can i set Terminal do full disc access via configuration profile? Greets Frank
Wondering if there is a way to change the default shell for all users?I see that a user can themselves type chsh -s shellnamee.g. csh -s zshbut they have to authenticate. I could run a script at login, once, but not sure how to tackle the need to provide their password.Also, I'd like to change the system so that new users have the newer shell (zsh)
Hi , we are trying to setup SSO and ran into an issue where users in an ldap group are not recognized and get access denied. Only ldap users directly added to JSS are recognized and signed in. Any idea how this can be solved ? thanks
Hi. What is the preferred/best way to create a custom PKG from the developer's PKG? An example is Cisco AnyConnect. If I run the installer for Cisco AnyConnect manually, I get the options to deselect certain things, such as Web Security or ISE Posture. If I were to deselect these options, how could I make sure those options get deselected for everyone else when deploying via Jamf? (since it will install without a GUI) Would this be done via Automator? Thanks!
Sorry if this is a simple one but couldn't find an answer elsewhereAfter I upload a package to Jamf, is there a way to download it? Giving I don't have the original package and it's not in Composer. I need this to be able to push the package through Munki and/ or Deploy studio Thanks!
Hi everyone,I am testing Jamf Connect for our environment. Our setup is to have a local admin account as the first user created. When we add another user via Jamf Connect they are not getting secure token. This only happens if the user account was not already on the Mac. Has anyone found a work around for this?
With the help of support we did find out how to prevent students from deleting history with Safari.It is in the profile under Web Content Filter and then "Enable web content filter" and "Enable Automatic Filtering". This successfully removed the option to delete history in the Safari app, and also removed the ability for the student to do private browsing.We also need to see if this is possible in Chrome. We have contacted Google support but without much luck so far. Has anyone gotten a profile payload to work with Chrome that might accomplish something similar?
Hi,We have an on premise Jamf distribution point. It appears to have MySQL and Java installed. I don't believe these components are necessary for a distribution point but have been struggling to find a definitive answer. Does anyone know if I can just uninstall these without affecting the DP Many thanks
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!