Get Support
Recently active
Hi, happy new year to all of you first 🤗 !! To start this year, I have an issue on our Macbook Pro M3 during enrolment setup. User tried to enroll device but nothing appears : no step configuration, no DEP. It gave her this screen with no local account created. Device exists in Jamf with no local user account created and named MacBook Pro. Seems that the device has no completed the config setup...We had in the past the PI-111120 issue where it seems to be resolved in the Jamf 11.1.1 : https://community.jamf.com/t5/release-info/jamf-pro-11-1-1-now-available/ta-p/305751To test, Transfer Information is uncheck in PreStage : I have already formated 3 times the MacBook Pro... and tried different network connexion. Someone knows much about this strange behaviour? Thanks you a lot ... :'(
Hello All, I'm stuck. I hope anyone can help me :)I need to check all apps status on full disk access. Is there any command to find status or other way? My manager want to know 2 things. 1. Is XXX.app added to full disk access ?2. Is XXX.app open on full disk access ?Thank you.
Looking for same help with Okta SSO into Jamf Admin. We have it working for Admin accounts that already existed in Jamf and for directory users, but I want to transition to the correct way of controlling access to Jamf Admin using User Groups. I've tried both Standard Group and Directory Service Group, matching the name to the group name in Okta. I've captured the SAML assertion and it is listing the group name, I've done group membership lookup in ldap test and it sees the user in the group, but when a user in the "Jamf Admins" Okta group who doesn't already have a Jamf Pro admin account attempts to log in via Okta they get an "Access Denied" error. Any ideas?
Anyone know of a resource for this?
Hello !I have a script that helps me to reconfigure printers and sets them by default depending of their location, department, etc...The problem is that I can't set the ~/.cups/lpoptions by using lpoptions -d default_printer. To run the command, I use a function that I found and that executes it as the logged user.runAsUser() { if [[ "${loggedInUser}" != "loginwindow" ]]; then launchctl asuser "$userID" sudo -u "${loggedInUser}" "$@" else echo "No user logged in" exit 1 fi}If I execute the command as test:launchctl asuser 502 sudo -u myuser /usr/bin/lpoptions -d default_printer, it does nothing. The lpoptions file is not populated. Even if I run the command line locally, it doesn't work. It only works if I run the script or the command line as the specific local user.Any help is welcome !
Recently we have noticed that the System Preferences keeps popping up no matter how many time you turn it off or close it. I have checked the login items and nothing is selected. Any advise?
Had a more experienced Jamf admin show me around the "Software Updates" section of Jamf Pro.Showed me how to select one of the Smart Groups listed in "Software Updates", then click "Update 1 selected" in the top-right of the Jamf Pro window, which brought up a list of options like "Install action" and "Target version".We made our selections, then saved.Is there a way to review those settings that we just made earlier today? If I go through the steps outlined in my second paragraph, it appears that nothing has already been set up, so I'm curious how I'd know that someone else had already gone through the process, or how I'd review existing settings (in the event I thought I'd made a mistake with the Forced Install Date, just for an example).
Hi all!Wondering if anyone has seen this, I generally have 2 local accounts on our MacBooks, one standard user and one administrator, both have secureToken. The MacBook is idling in the logon screen (took logoff from the OS), connected to network, Jamf Remote enabled from the Management -page of computer details.If I start a Jamf Remote session the logon page opens nicely and I can try to logon. I am not however able to logon with my administrator account. The error I get is, that I have an incorrect password (see screenshot), but as you can imagine, I'm quite 100% that I have it correct. I am able to copy paste it from the password management to the window, and I am also able to use the same password if I logon from the keyboard the MacBook itself. So something else if happening here, but I'm a bit lost what it could be.Note, that I can logon to the same machine into an unattended session with my standard user account without any problem from the same window. I am also able to lo
I am setting up Device compliance through JAMF using IntuneEverything seems to work fine on the Mac. The iOS won't seem to complete the registration properly. The device shows up on the user in the in Entra, but never shows up in Intune. It shows the device is compliant.When I go to register, it takes me through Edge on the iOS device then prompts me to sign in again. Then it wants me to add a profile. Nowhere in JAMF instruction does it reflect needing to do this step. I can't get resources to the device currently.This is happening with both test phones I am using.
Jamf's "Learn in Class" page says: Due to the COVID-19 outbreak we have paused the scheduling of in-person courses. Visit our Learn Online page for remote training resources. It's been more than two years since most business offices re-opened. Jamf should bring back in-person training. Benefits of in-person training: Coworkers don't bug me when I'm out of town for training. If I'm in-town, coworkers think nothing of reaching out to me for help. Even when they know I'm in training. Even if I "attend" training from my home. Get to socialize with other Mac / Jamf admins, which leads to Informal knowledge sharing (which has been totally absent from almost all online training I've had) I've been out to Jamf's Minneapolis HQ twice for training, and now that I want to get my 400 cert, I'd like to go back. Here's a photo I took of their building, as seen from the Minneapolis Skyway:
Hi all, We are pushing a script to allow users to change date and time as below:##Allow User to Change Timesecurity authorizationdb write system.preferences allowsecurity authorizationdb write system.preferences.dateandtime.changetimezone allowsecurity authorizationdb write system.preferences.datetime authenticate-session-owner-or-admin This was working fine until now, but it stopped. Did apple changed the preference settings?
We are replacing our end users Macs and are testing out some things.So when we first start up our Mac, we have a local admin password on Jamf Pro that has a password that rotates every six months. When I sign in with the password it works. However when I then sign into Jamf Connect using the end users account and then sign out, this admin password changes to the users entra password and the password on Jamf Pro no longer works.Not sure if this is supposed to be this way? Our Admin account is supposed to rotate passwords every six months. Why is the password changing to the end users account after they sign into Jamf Connect for the first time?
Hi there, How are some of you handling privilege escalation for temporarily escalating local Standard accounts to Administrator accounts then back down to local Standard accounts?Currently we have groups set up in Okta that we use to escalate an account, the user has to sign out and log in with NLA for the group change to be read and thereafter they have to signout and back in again with the Administrator group is removed.Is there no better streamline approach to this that preferably has some sort of logging? Even paid solutions.
Following the instructions listed here: (https://learn.jamf.com/en-US/bundle/jamf-school-documentation/page/Google_Sign-In_Setup.html#ID-0000ce70) we created a Google Console project. For devices that are already in Jamf School (we own them) with the appropriate ADE assigned to them it works.I wipe a device it comes back up and asks to be logged into using Google credentials and it works. So Jamf School and Google are talking to each other. Delightful. For BYOD, iPads we do not own, I'd like to do the same thing. Using the Redirect URI's that are listed under Org-Settings-Enrollment (and confirmed they are the same in the Google cloud console project) all i get are error messages (see attached images). I've had trouble in the past with this on iPad Minis, but I'm using an iPad Air 3 all updated and everything. No luck. What can I do to get outside devices to be accessible in our Jamf School instance using Google as the vehicle for authentication? Wh
We have activated the checkbox in iOS PreStage enrollment that credentials are required.We have set up Cloud Identity Provider (Azure AD) in the Jamf settings.Every time a user now tries to log in to the iPhone setup, the message always appears that the data is incorrect.However, I don't see any entry in the Azure AD log that Jamf has tried here.Now I don't know what I'm doing wrong and what I need to do to make it work.
I am new to JAMF but not MDM in general. We are currently testing our profiles and would like to auto configure the Apple mail app for Office 365. I have created a profile, exchange active sync, with the correct variables and it pushes down to the device. In this case it is an iPad. We are prompted for a password but the app does not auto direct to exchange online for the user to login. Is there a good article on successfully setting this up? I have looked around but articles I have found have been a few years old. I have successfully set up auto config for Outlook and it works just fine. I understand a lot of organizations are moving to the Outlook app but we have a few cases where the Apple mail app is required. Any advice or a nod in the right direction would be appreciated.
need help converting script to user bearer token. script below:#!/bin/bash ## API informationapiURL="https://jamfcloud.com:8443"apiUser=“test”apiPass=“test”1234 ## Get a list of all sites and their IDsallSiteData=$(curl -H "Accept: text/xml" -sfku "${apiUser}:${apiPass}" $apiURL/JSSResource/sites | xmllint --format - | awk -F'>|<' '/<name>|<id>/{print $3}') ## Split out Site Names and Site IDs into arraysallSiteNames=("$(echo "$allSiteData" | awk 'NR % 2 == 0' | grep -v 'Provisioning' | grep -v 'Ground Control')") ## Prompt for a Site selectionchosenSite=$(/usr/bin/osascript << EOFtell application "System Events"activateset siteNames to do shell script "printf '%s\\\\n' \\"${allSiteNames[@]}\\""set namesForDisplay to paragraphs of siteNamesset chosenSite to choose from list namesForDisplay with prompt "Choose a Site"end tellEOF) sleep 5 ## Get the computer serial numbercomputerSerial=$(ioreg -rd1 -c IOPlatformExpertDevice | awk -F'"
I've recently run into the issue where machines upgraded to 14.4 have had all their printers wiped, and are no longer able to add new printers. A few posts i saw online linked it to defender potentially causing the fault with the new os. Im coming here to see if anyones run into the same issue and/or found a solution via jamf that could be easily sent to everyone on the newest sonoma version.
I have two connectors, primary and failover that are load balaced. The secondary is set up with the same server and client certs as the primary and they sit behind an F5. The both work individually thanks to input from @bradtchapman I'd like to fire as many CA requests as I can to ensuring timing works. Is Postman the best option? It's unrealistic to set a computer up and have it attempt to grab the cert. I don't have access to the CA. How can I send multiple requests to the connector to ensure functionality?
We recently had Apple's APNS support team transfer our APNS cert to a new Apple ID as we had lost the secret questions to the original account. They were able to help, after much paperwork was sent, and it was transferred.When this process was completed for us, we got a different serial number for the cert in the APNS portal, and I am getting worried that is going to break something when I renew it in Jamf. Can someone confirm that the serial number being different on the cert after Apple transfers it to a new account is okay? The topic and Subject DN are the same, but the serial number is different. I really don't want to have to reenroll a bunch of devices. Thanks in advance!
Hello! I am the technology director at a private school currently using Trend Micro Apex One for EPDR and we are looking to make a switch if it can provide us with cost savings or better protection. I am interested in learning what solutions you are deploying that you are happy with. I am considering evaluating Jamf Protect, but it can't protect my Windows devices or servers, so we need to maintain an additional agent.I appreciate any insight on the topic!
I'm wondering if there is a way to bring up a GUI (jamfhelper, cocoadialog, etc) to give a device an already created EA. As mentioned, the EA is created, I just need a way for a technician who is setting up the computer to assign it to the right EA so that it drops into scope for some policies to run based on the EA. The EA I created has the following characteristics: Data Type: String, Input Type: Pop-Up Menu . I then have a few items in the dropdown to choose. I'm hoping to be able to assign one of those dropdown items directly from the computer.
Today we are releasing Jamf Pro 11.3. Highlights include: Account-Driven Device Enrollment for ComputersYou can use account-driven Device Enrollment to enroll computers with Jamf Pro. Account-driven Device Enrollment allows you to enroll institutionally owned computers with Managed Apple IDs, simplifying the enrollment process. Account-driven Device Enrollment requires computers with macOS 14 or later. Viewing LAPS Passwords in the Jamf Pro InterfaceYou can view managed local administrator accounts and passwords in the Jamf Pro interface after enabling Jamf's managed local administrator password solution (LAPS) in the Jamf Pro API. Viewing a LAPS password automatically triggers password rotation according to your LAPS settings. All LAPS events, including password viewing and rotation, are logged. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account 
It's finally here!Hello everyone! I'm so excited to announce the release of MUT v6.0.0! MUT v6 is a collaboration between myself, a few other Jamf's and even a community member who submitted a PR on Github! MUT v6 includes code from a whopping FIVE (5) contributors now, and resolved eight (8) filed Issues on GitHub. As always with MUT, I strongly recommend trying out a small, test run of just a few devices before doing a massive update to your entire fleet. MUT is a very powerful tool, and while I've done plenty of testing, it is good to be careful, especially with a change as massive as this.Changelog:Added "Classic Mode" fallback when a Group or Prestage update failed due to CSV issuesAdded ability to leverage new API endpoint for enforcing and unenforcing Mobile Device Names (requires Jamf Pro 10.33+)Added ability to update Is LeasedVarious bugfixes and optimizationsKnown IssuesThere should be a more verbose feedback if a user attempts to enforce a mobile device name, but
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!