Get Support
Recently active
Hi all,how can i set the default phone app in facetime settings via bash script? We need to change this setting to a custom app for all managed computers after installing the custom app via policy.Facetime -> SettingsgreetingsFrank
Help me to Keep safari on up-to-date in monterey/ventura/sonoma using Patch management in Jamf Pro.
Hello! We had an iPad stolen by a staff member. I disabled the iPad and was able to get the location. This helped HR retrieve the iPad and I now have it back. HR wants to know what is on the iPad. Unfortunatly the iPad went dead while it was missing and now I cant take it out of lost mode as the ipad will not grab a network connection to grab my disable lost mode command. Is there any way to disable lost mode without wiping the ipad? Thank you,
Having a weird issue on a macOS 14.0 system. I had the system enrolled in our production server and wanted to to move it to our Dev server for some testing. Removed mdm profile, removed it from Production pre-stage and deleted it from jamf. Re-assigned to dev MDM in ASM and added it prestage on Dev. Ran sudo profiles renew -type enrollment, got the enrollment prompt but then received and error "enrolling with management server failed NSCocoaErrorDomain:3840". So I removed it from the Prestage, then unassigned it in ASM but I am still getting the enrolment popup even after multiple reboots. I can see its still trying to enroll into our Dev server as its showing the dev pre stage in the learn more about remote management. Wondering if there is a file to remove that can clear this?
Hi,Unfortunately, we have a problem installing an app on a few devices.An error message AMSErrorDomain 203 appears.Unfortunately, we can't do anything with this message. It is also strange that it only affects some devices:"AMSErrorDomain erreur 203. / The operation could not be completed.(AMSErrorDomain error 203) I No server with the specified host name was detected.detected. The operation could not be completed. (kCFErrorDcmainCFNetwork erreur -1003.)"What does that mean? Where can we find the problem?Regards and thank you very much in advance.
Due to security restrictions within my environment, I have spend an considerable amount of time to install JAMF without having an internet connection to my server (it took me a long time as I was not well-versed in linux as well but it was one of the project's requirement). I would like to share it here so that others will not have to go through the same experience that I did and benefit from this post. Operating System: RHEL 7.7ISO Used: rhel-server-7.7-x86_64-dvdJava Version: openjdk 11.0.6mySQL Version: mysql community server 5.7.28JAMF Version: 10.17 RPM Needed For mySQL Installation:mysql-community-libs-5.7.28-1.el7.x86_64.rpmmysql-community-common-5.7.28-1.el7.x86_64.rpmmysql-community-client-5.7.28-1.el7.x86_64.rpmmysql-community-server-5.7.28-1.el7.x86_64.rpm mySQL InstallationStep 1. look for existing mariadb by executing:rpm -qa | grep mariadb-libs Step 2. Remove mariadb by executing:rpm -ev --nodeps mariadb-libs-xxxxxx Step 3. Install mysql-community-common by executing
Hi, How do I create a report of the publisher of each app on every device?
Hi, How do create a report of the publisher of each app on every device?
Wanted to see if anybody had an extension attribute that would report the Webex teams version. Seems that Teams reports under applications the version that was originally installed. We leverage auto updates through the application and trying to find best way to report on that.
Hi All! I finally figured out how to enable (show) private data in Unified Logs in 10.15.3+ now that cmdReporter's private API tricks have been disabled and thought I should share. You can load this config profile locally with no issue, but this config profile needs to be signed before uploading to Jamf with something like: /usr/bin/security cms -S -Z "$SIGNING_CERTIFICATE" -i "$UNSIGNED_PROFILE_PATH" -o "$SIGNED_PROFILE_PATH" Testing: log stream --predicate '(subsystem == "com.apple.AccountPolicy")' Unlock a system preference pane, you should not see any "<private>" entries and see full details about user and record type. And here is the actual profile: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>P
We are about to make a major push into encrypting our Macs with FileVault 2, starting with 10.8.x devices and moving down to 10.7. I've followed the whitepaper on Administering FileVault 2 on Mountain Lion and have it working OK in the lab, but I did notice that if a user reboots his/her Mac and does *not* enter in their password (using Current or Next User setting) to begin the FileVault process, that the machine simply reboots. FileVault 2 encryption never beings, and because the policy set to run only "once per computer", it never runs again. I am wondering if there's away around this. Specifically, how can I configure the policy to reapply itself on machines that are not encrypting or that are not encrypted? Is setting the Execution Frequency to "Ongoing" the proper course of action? Is there anyway to remove / hide the "Cancel" button when the user is prompted to encrypt? thanks,mike
One of our enrollment technicians has come across an error where scoped apps won't install. The error message that is under the failed command is "Couldn't communicate with a helper application" Its an iPad and it's trying to install the Gmail app. See the attached screenshot. What could cause this? What can be done to prevent it?
There is a user who has an unencrypted internal drive. His jamf profile should be requiring him to enable FileVault. However, we he restarts or logs out of his device, he is not prompted for FileVault to be enabled. He is already enrolled in jamf but the "Install Configuration Profile Disk Encryption" is stuck as pending. I've tried sending a blank push. Is there a way to push this policy so they are encrypted without having to unenroll and re-enroll their MacBook? They are on an Intel Mac.
Jamf Nation- The privacy of our customers' data is of the utmost importance to us. Yesterday, we learned of an issue in the Jamf Nation Feature Request portal related to the exposure of limited user data. This was limited to Jamf Nation user data, did not include password data, and did not impact any other products or user data outside of Jamf Nation. This issue is now resolved. We will provide updates as they become available and we complete our investigation. Thank you for your continued patience in this matter and we apologize for the inconvenience that this has caused. Jake BernardyVice President, Global Customer Success @ Jamf
Just had to rebuild the installer package for the Cisco Secure Client. Dumped the choices and attempted to deploy. The deployment would not install. Turns out the dump from installer of the choices xml file is malformed. I was able to put together a working xml from my 4.10 package. We are only installing the VPN module but all the others are there to enable. Here are the contents<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><array><dict><key>attributeSetting</key><integer>1</integer><key>choiceAttribute</key><string>selected</string><key>choiceIdentifier</key><string>choice_vpn</string></dict><dict><key>attributeSetting</key><integer>0</integer><key>choiceAttribute</key><string>selected</string><key>choiceI
With injection add-ins for Outlook being removed in May we would like to know what Outlook Add-ins users may of installed. Is there a Jamf EA or script to find this out
Hi everyone, Have you ever tried to update a PreStage Enrollment through the v2 API?I'm trying to create a python script that will update the customPackageIds of said PreStage Enrollment when certain packages have a new version available. This always gives me error 500, internal server error, I think. It would be something like this: import requests payload = { "customPackageIds": "110" } headers = { 'Accept': 'application/json', 'Authorization': 'Bearer XYZ', 'Content-Type': 'application/json', } response = requests.put('https://XYZ/api/v2/computer-prestages/3', json=payload, headers=headers) This is my first time doing something like that with python and JSON and I would gladly use python-jss for this but as far as I know it can't handle PreStage Enrollments. What's your take on this?
Hi Guys,I've been trying to add remote desktop bookmarks from https://soundmacguy.wordpress.com/2020/06/14/managing-microsoft-remote-desktop-10-bookmarks-with-handy-jamf-scripts/comment-page-1/?unapproved=15565&moderation-hash=52675532c055e57029dc4ae44a7da447#comment-15565 and when i run the script i get this error below Executing Policy Add Remote Desktop H&LRunning script msrd10-add-remotedesktop...Script exit code: 132Script result: User: staff is logged in...Username specified, Creating bookmark for: sysnet Domain not specified, username will not be prefixed... Creating bookmark: H&L /Library/Application Support/JAMF/tmp/msrd10-add-remotedesktop: line 98: 7252 Illegal instruction: 4 sudo -u "${loggedInUser}" "${msrd}" --script bookmark write $(uuidgen) --hostname "${hostname}" --friendlyname "${friendlyname}" --resolution "${resolution}" --group "${group}" --username "${username}" ${extraArgs} 2> /dev/nullError running script: return code was 132. 
create a policy, on the left pane enable the Restart Options. From there set if you want set it to restart immediately with or without a user logged in. i understand the above can be used to configure the policy but how to call that policy ? sudo jamf policy restart ?
Greatly inspired by this thread, I re-wrote a Ventura-ready script prompting the end user to enable Screen Recording for a given app. The Privacy & Security window will open automatically and the popup/gif loops until the user grants access.In my company, the script is deployed at the end of the enrollment so the support team doesn't forget to enable screen recording for Google Chrome. This way, the user won't have to restart his browser the first time he wants to share his screen to somebody.Script : enable_screen_recording.shExtension Attribute (Optional) : enable_screen_recording_ea.shRequirement : IBM NotifierBlog post (French) : Autoriser l’enregistrement de l’écran (TCC/PPPC) à l’aide d’un popup tutorielIf you test the script in your Terminal, give it full disk access so it can read the TCC.db file.
Hey everyone, We are testing jamf connect and we are noticing that upon 1 restart we see the jamf connect login window upon 2nd restart the window disappears not sure what is wrong but upon 1 restart the authchanger should kick in but it is not it is kicking in on the 2nd restart.
Hi Everyone,First time posting here so please forgive any lapses in etiquette! I've recently inherited a Jamf estate at my work place and whilst I've recently been trying to deploy a .pkg out, keep running in to this particular error message and I don't have the skills/knowledge to resolve it so was hoping that one of the gurus here could lend a hand. Payment would be in eternal gratitude.My Error Message:Downloading myApp.pkg...Downloading https://euc1-jcds.services.jamfcloud.com//download/9c26e394fec944e1a7dde6f5aa5e7537/myApp.pkg...Error: Package was not successfully downloaded. 400The network connection was interrupted while downloading the package from https://euc1-jcds.services.jamfcloud.com//download/9c26e394fec944e1a7dde6f5aa5e7537/myApp.pkg. Attempting to reconnect...Downloading myApp.pkg...Downloading https://euc1-jcds.services.jamfcloud.com//download/9c26e394fec944e1a7dde6f5aa5e7537/myApp.pkg...Error: Package was not successfully downloaded. 400Error: myApp.pkg is not availa
For those of you using Jamf Cloud instances, I'm curious if you've ever run into issues with policies downloading large ( > 5GB) files when using the "Each computer's default" distribution point rather than the "Cloud" distribution point. I have one policy using "default" for a .pkg file over 12GB that works fine, but another with a 8.25GB .pkg file that kept failing until I switched it to "cloud distribution". The error message was "Error: The package is not found on the server" even after re-uploading the file.For our Jamf Pro instance, we have no File Share Distribution Points, and use AWS for our Cloud Distribution Point. We have the "Use as principal distribution point" check box ticked for the Cloud distro, so my understanding it that is shouldn't matter whether the distribution point option in a policy is set to "default" or "Cloud" because either one should still be pulling from AWS. But for some reason as yet unknown to me, it does make a difference for second policy a
Greetings. Looking to the Nation to see if anyone has this issue and a resolution. We are in the process of removing existing separate installs of Cisco AnyConnect and Umbrella roaming client and installing a bundle package with just VPN and Umbrella client. The uninstall Policy to remove works, but the end user will get a popup to respond ok to the following: "vpnagentd" wants to access to control Finder. Allowing control will provide access to documents and data in Finder to perform actions within that app". I've been working with a PPPC but no luck yet. Thanks. in advance
Hi there, Recently we purchased a number of iPads for our elementary school students. We have 20 iPads available for students to use and 1 teacher’s iPad with a single Apple ID used by all teachers. The students’ iPads do not have an Apple ID and or not configured as shared iPads. We would like to utilize Apple Classroom on the teachers iPad where Apple Classroom is properly installed (we pushed this with Jamf School). However, on the teachers iPad, when we manually create a new class and click on ‘add students’ the expected four-digit pincode does not appear.I also attempted to install Apple classroom on the students iPads, to see if it would work without an Apple id and with another profile installed via Jamf School. Weirdly enough, I did receive a four-digit pin. Quite strange! Has anyone else experienced this issue and managed to resolve this? Thank you in advance! Model: iPad 9th generationiPad-OS: 17.4MDM: Jamf school Kind regardsAn elementary school in B
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!