Get Support
Recently active
Hello,As an intro to myself and my level of Jamf/scripting - I am a 200 level tech who took the 300 and did not pass. lolWhat I am trying to do is get notifications sent from Jamf connect when someone 'requests admin privileges' to be sent to a Microsoft Teams channel.The Mac admin guru at my workplace set this up: https://snelson.us/2024/02/setup-your-mac-1-14-0-under-the-hood/ it is a way to auto setup a Mac and it also includes a Teams channel set up guide using Webhook (an app within teams) to notify us when someone has completed the "setup your Mac" portion of their first time set up.I would like to do something similar to this but again just for when someone clicks on requesting to become an admin on Jamf connect. I have the script for setup your Mac but I think this will require an agent and obviously its own script. Is there anyone out their willing to help me out with this? I might need my hand held a lot through this process to be honest lol. Thanks in advance!
I created a policy to install a package (minecraft education). I put startup and login as the triggers. When I check the logs i see the message below "Installation failed. The package could not be verified"Any ideas how to fix this error? Thanks
I'm trying to install network printers without binding my Macs to AD. I'm using Jamf Connect for passwords and for network drives. Those work great. It's the printers that I'm getting hung up on.I created a policy that adds the printers and the drivers. The printer will install, I just can't print to it. The printer hangs in a "printer is in use" message. Here is the script that I'm using. lpadmin -p Ricoh_Second_Floor -E -o printer-is-shared=false -v smb://Printer IP/Printer Name -P "/System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/PrintCore.framework/Versions/A/Resources/Generic.ppd" -o ColorModel=RGB -o ColorDevice=True -o auth-info-required=negotiate
Has anyone tried getting their advance search from the API in json rather than xml? When I do this, the computer groups will only return 1 group in JSON but when I get XML, all groups are listed. Anyone know how to get all groups as well?
Hello,We have enabled Device Compliance in Jamf.Everything went well.The enrollment of the devices, the computers appear well in Azure AD as compliant based on the Jamf compliance smart group, if I change the criteria of the Compliance smart group, it goes well into non-compliant in Azure AD, etc.But the problem I'm having now is when I create a conditional access policy in Azure AD and check "Require device to be marked as compliant", it even impacts computers marked as compliant in Azure AD.For example, I created a policy that blocks the ability to authenticate on Adobe applications for non-compliant computers, this affects compliant devices.As soon as I uncheck "Require device to be marked as compliant", it unlocks the situation (on non-compliant computers too...normal).Do I need to configure anything else?Thank you for your help
I am testing Software Updates (Beta) in my environment, and I am seeing mixed results. So, I started with a Monterey 12.6.6 and sent a request to update it to 12.6.7 which was successful. Then I send another request to update the same machine to 12.6.8, locked the machine and left it overnight. The machine did not update. I researched and checked for anything I could find to see if the machine got the instructions. I looked at the install.log and nothing stands out. I ran the update command again, still no update. Can anyone tell me if there is a certain time frame that it waits or a location or command at the machine can be checked. Any help or information would be greatful.
I’m struggling with wifi on the Jamf Connect Login page.We use two networks - ENT and DEV. ENT is Enterprise, DEV is PSK.ENT is for all users to login to and gives access to printers, fileshares, etc. Users need to login to this network with their network username and password.DEV is more of a backup being pushed out via config profile, auto-join disabled. I can confirm the computers I'm testing on have this profile.Jamf Connect Login lets you connect to DEV if you know the password.You log in through JCL, and once you hit the desktop you need a printer so you swap over to ENT.You log out for the day.Now the JCL page needs the password for DEV again, even though it knew it before, and it's being pushed out by a config profile, and it hasn't been Forgotten by the user.Can I force JCL to use a specific wifi network, or feed it connection info or something? This seems like it's broken or something.
Hello,We have recently got this situation. Little bit about our infra. We have On Prem AD and Azure AD. We have MAC which are managed by Intune.We recently setup our Azure AD and On Prem AD Sync, we started to see an issue where if a person reset there password then on MAC they start to get prompt for there on prem file server mapped network drive for password. Even if they key in Password it do not work and it keep prompting. Only solution which work is where users must remove any credentials that’s saved in their Keychain related to they on prem file server.. Once the saved password(s) are deleted for On prem file server, reboot their MacBook. Once it’s booted and signed in, the system would prompt them to enter their updated credentials the next time they open their network folder.Unfortunately this is not a good user experience so asking if JAMF has any solution or any other solution that might work.,
My company users Global Protect to keep all of us connected when we're not in the office. For the most part, Global Protect works well. The way we're setup is if GP is not connected we have no internet access. This results in any policies that I setup to run at startup to fail. The Jamf log will show "Connection failure: The Internet connection appears to be offline." I asked one of our firewall guys to add an exception to allow Macs to connect to the Jamf Pro server whether GP is connected or not. This doesn't appear to be working so I want to get some advice on an idea that I have. I want to create a launch agent to ensure that an inventory is ran right after the user is logged in. Also, after my zero touch provisioning process is finished, and the user reboots, I want the first policy that runs after the user logs in to be the one I have setup to check to make sure that all of the apps that should have installed through ZTP did install and then install any that are missing. The way
Hey Nation!I created a config profile for Microsoft AutoUpdate to automatically update apps in the current update channel with notifications disabled. For the most part, it seems to work just fine. However I had reports from a couple of users that they were seeing this popupI even tried creating my own plist as shown in this Nation post https://community.jamf.com/t5/jamf-pro/microsoft-autoupdate-app-notifications-settings/m-p/234536#M222449Has anyone ever had this happen even when disabling the notifications? Any help would be appreciatedThanks!-Frank S.
somehow the microsoft icon was renamed to Microsoft Defender under Application.how to safely rename it back to Outlook .
Hey everyone, We are currently testing Jamf Connect and one of the issues we are facing is that we see the FileVault login screen. This has not happened to us before just started recently.Our Jamf rep has told us that this is expected behavior, Is there a way we can bypass that login screen entirely and still have the device encrypted?If it is possible can I please know the steps so I can do them.
We're just in the process of setting up Jamf Connect, and I'm finally at a point where I felt comfortable testing on my own machine as opposed to test devices.As I already have a local account, I installed Jamf Connect and logged out and tried to sign in using the SSO login. I only have two usable local accounts on this device, my account and the local admin we use for our tech team - which is hidden during migration based on the config profile.I get through the SSO, and Jamf Connect asks me to re-enter my Entra ID password. After that, it tells me my Entra ID password and local password are not the same, and to re-enter my local password. However, it's telling me it's wrong, and I've made certain that it's not.I've reverted to local login for now, and checked the Jamf Connect logs, but I can't see any glaring issues. How should I fix this?
Does anyone have a script that can repair or remove CyberArk EPM is the agent is disconnected from the console and there is a tamper protection enabled preventing the agent from being uninstalled manually? I am pushing an upgrade from Jamf and have a handful of computers that are failing the upgrade because they can not contact the console to validate the token.
I'm testing a script, but looking for a better suggestion that runs silently without any user invention. Running the uninstaller app isn't ideal. #!/bin/bash# Path to the uninstallation appsUNINSTALL_APP="/Applications/Cisco/Uninstall Cisco Secure Client.app"DART_UNINSTALL_APP="/Applications/Cisco/Uninstall Cisco Secure Client - DART.app"# Check if the uninstall app exists and execute it with sudoif [ -e "$UNINSTALL_APP" ]; thenecho "Uninstalling Cisco Secure Client..."sudo open "$UNINSTALL_APP"elseecho "Cisco Secure Client uninstallation app not found."fi# Check if the DART uninstall app exists and execute it with sudoif [ -e "$DART_UNINSTALL_APP" ]; thenecho "Uninstalling Cisco Secure Client - DART..."sudo open "$DART_UNINSTALL_APP"elseecho "Cisco Secure Client - DART uninstallation app not found."fi
Hi Jamf Nation Users,We wanted to let you know that starting tomorrow, March 20th at 9AM CET (2AM CT), we will be making some changes to the Jamf Nation Feature Requests portal that will require us to temporarily take down the space. We expect to be back online by Friday, March 22nd, at 4PM CET (9AM CT).During that time, we’ll perform some maintenance that will make the Jamf Nation Feature Request portal a more intuitive place for users when creating new ideas (or browsing existing ones). This change will also make it easier for the Jamf Product team to review your feature requests and communicate with you about your ideas on a regular basis.We’ll make sure to post here when things are back up and running.Thanks for your understanding,The Jamf Team
Is there a way to view what apps are installed on all devices? I know you can view them individually but I want to see a report of everything. Something like Smart Groups where I can view the number of devices that have this particular application. This way I can get automated patching done on these apps.
Hey guys. New to JamfPro line-up but I've gotten the hang of it pretty well. During the integration between Jamf Trust (Security Cloud / Wandera / RADAR / Please setup a naming convention), and Jamf Pro as the UEM, you have the option to either authenticate with Basic Authentication (Username, Password), or with OAuth, utilizing an API client in Jamf Pro with the appropriate permissions. The permissions are listed here, under the Requirements section. This Requirements section is the same for all versions of the Jamf Trust (Security Cloud, Security, Safe Internet, Wandera, RADAR, Please setup a naming convention) documentation, even the deprecated ones.https://learn.jamf.com/en-US/bundle/jamf-security-cloud-setup-guide/page/UEM_JamfPro_Establishing_UEM_Connectivity.html#task-6779 A Jamf Pro API Role and Client with the required permissions. For more information about API Roles and Clients with Jamf Pro, see API Roles and Clients in the Jamf Pro Documentati
Basically I'm running an ldapsearch command to grab the AD info for a computer record. I want to then grab the dn: line so I can feed this to ldapdelete to remove the Macs AD entry before trying to reimage it. I want to capture this entire line into a variable - dn: CN=faimd-a01392,OU=Macintosh,OU=Computers,OU=plantname,OU=Plants,DC=domain,D C=company,DC=com but piping it to 'grep dn:' gives me this: dn: CN=faimd-a01392,OU=Macintosh,OU=Computers,OU=plantname,OU=Plants,DC=domain,D. How can I get it all on one line?
I've been playing with some more robust ways to run softwareupdate than the built in implementation in Casper and came up with this. Modify as you like to make it work for your environment, it currently only works with 10.8 because 10.7 uses a slightly different structure for index.plist (and I just didn't have time to modify for it). Basically it checks if you are on 10.8, then if you have any updates, and if you do and they requires a restart, download them all and modify the proper files so that when someone does go to Apple - Restart, it'll bring up the built in Apple environment to show them a pretty progress bar on how their updates are going, and if there are updates but none of them require a restart, install them silently. This can be used in conjunction with a Policy so that you can warn users that it's running, that if it finds updates that require restart that it'll install those updates when they restart the computer, etc. etc. etc. Enjoy! #
We're testing Jamf connect for our Macs. I haven't bound our Macs to AD. I know people say that is usually a bad idea. However, I've ran into issues with our network printers. The Macs can't see the printers. I can try to install the printers, but I end up with the print job hanging with a message stating that the printer is busy. Any ideas on how to map these printers without binding to AD?
Hello, I've found this script and it is working fine (to create the file). But when trying to open the actual file [link] from the desktop, it gives an error. I noticed that the permissions show this file as being owned by ROOT, since it is populated through a script via Jamf, but I'm not sure if that's the issue. If I try to create my own webloc file by dragging a webpage from Safari to my Desktop, that works just fine. But not one created by this script.
Hello everyone,I have a strange issue happening on the M2s and it is running me nuts, I hope that someone can help. I have not open a case with Jamf support yet, that will be my last resort.Long story short, I have an SSO Authentication customization that is supposed to happen during the PreStage enrollment so that our users can authenticate via our IdP (OKTA) so the macbook gets automatically assigned to the user enrolling and go through the provisioning process. Well this is working great for Intel and M1 macOS devices, but when we are deploying the M2s in somehow the SSO authentication window does not appear, and it goes through the enrollment process and stops at the Account Creation setup assistant, where the User details will need to be punched in manually instead of getting them carried over from the assigned user.Obviously the config works on the older macbook, I cannot figure out what would be so different on the M2 that could prevent that SSO window to come up at the enrollme
Hi,Is it possible for an organization to disable the factory reset option on an iPhone? Alternatively, is there a policy or script that can accomplish this?
I seems I cannot remotely clear the Safari cache on non-shared iPads, but I'm close to finding an alternative solution.Ojisan Seiuchi has found that when iOS Safari is presented with a URL in a certain format, it will execute preference settings on the device. Settings → Safari → Clear History and Website Data has its own URL and by loading that URL through an iOS Shortcut created using the Shortcuts app, you can quickly clear Safari. This worked immediately for me.Now I'm looking for a way to deploy that shortcut via JAMF Pro. Any suggestions will be gratefully received.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!