Get Support
Recently active
Hello all,I have an issue showing up at random with only a select few of the iPads I manage. A certain app will not install but will show up on the device grayed out and typically says Waiting (it is properly scoped and we have enough licenses). When you click on the grayed-out app, it either does nothing or prompts to be installed via the App Store.I'm also not able to install it through Self Service. The "Install" command is non-responsive and JAMF shows the command as failed, citing that the app is already scheduled for management. I am not able to delete the grayed out app because it's not installed. I supposed I could install it through the App Store but I shouldn't have to. The iPads are 7th gens running the latest iOS and have enough storage available to install the apps.Thanks!
Hello,what is the best way to remove Jamf Trust from the devices (macOS)?The configuration is quickly deleted, but what about the app? We have rolled it out via the App Store using VPP licences. Thank you
Hi,Jamf is supporting default scripts for checking time machine backups. But with new versions of mac os this won´t work beuacse diskutil is using PlistBuddy. This has no disc access. If i enable Terminal in full disk access those scripts are working again. Without disc access With disc access How can i set Terminal do full disc access via configuration profile? Greets Frank
Wondering if there is a way to change the default shell for all users?I see that a user can themselves type chsh -s shellnamee.g. csh -s zshbut they have to authenticate. I could run a script at login, once, but not sure how to tackle the need to provide their password.Also, I'd like to change the system so that new users have the newer shell (zsh)
Hi , we are trying to setup SSO and ran into an issue where users in an ldap group are not recognized and get access denied. Only ldap users directly added to JSS are recognized and signed in. Any idea how this can be solved ? thanks
Hi. What is the preferred/best way to create a custom PKG from the developer's PKG? An example is Cisco AnyConnect. If I run the installer for Cisco AnyConnect manually, I get the options to deselect certain things, such as Web Security or ISE Posture. If I were to deselect these options, how could I make sure those options get deselected for everyone else when deploying via Jamf? (since it will install without a GUI) Would this be done via Automator? Thanks!
Sorry if this is a simple one but couldn't find an answer elsewhereAfter I upload a package to Jamf, is there a way to download it? Giving I don't have the original package and it's not in Composer. I need this to be able to push the package through Munki and/ or Deploy studio Thanks!
Hi everyone,I am testing Jamf Connect for our environment. Our setup is to have a local admin account as the first user created. When we add another user via Jamf Connect they are not getting secure token. This only happens if the user account was not already on the Mac. Has anyone found a work around for this?
With the help of support we did find out how to prevent students from deleting history with Safari.It is in the profile under Web Content Filter and then "Enable web content filter" and "Enable Automatic Filtering". This successfully removed the option to delete history in the Safari app, and also removed the ability for the student to do private browsing.We also need to see if this is possible in Chrome. We have contacted Google support but without much luck so far. Has anyone gotten a profile payload to work with Chrome that might accomplish something similar?
Hi,We have an on premise Jamf distribution point. It appears to have MySQL and Java installed. I don't believe these components are necessary for a distribution point but have been struggling to find a definitive answer. Does anyone know if I can just uninstall these without affecting the DP Many thanks
Hi, happy new year to all of you first 🤗 !! To start this year, I have an issue on our Macbook Pro M3 during enrolment setup. User tried to enroll device but nothing appears : no step configuration, no DEP. It gave her this screen with no local account created. Device exists in Jamf with no local user account created and named MacBook Pro. Seems that the device has no completed the config setup...We had in the past the PI-111120 issue where it seems to be resolved in the Jamf 11.1.1 : https://community.jamf.com/t5/release-info/jamf-pro-11-1-1-now-available/ta-p/305751To test, Transfer Information is uncheck in PreStage : I have already formated 3 times the MacBook Pro... and tried different network connexion. Someone knows much about this strange behaviour? Thanks you a lot ... :'(
Hello All, I'm stuck. I hope anyone can help me :)I need to check all apps status on full disk access. Is there any command to find status or other way? My manager want to know 2 things. 1. Is XXX.app added to full disk access ?2. Is XXX.app open on full disk access ?Thank you.
Looking for same help with Okta SSO into Jamf Admin. We have it working for Admin accounts that already existed in Jamf and for directory users, but I want to transition to the correct way of controlling access to Jamf Admin using User Groups. I've tried both Standard Group and Directory Service Group, matching the name to the group name in Okta. I've captured the SAML assertion and it is listing the group name, I've done group membership lookup in ldap test and it sees the user in the group, but when a user in the "Jamf Admins" Okta group who doesn't already have a Jamf Pro admin account attempts to log in via Okta they get an "Access Denied" error. Any ideas?
Anyone know of a resource for this?
Hello !I have a script that helps me to reconfigure printers and sets them by default depending of their location, department, etc...The problem is that I can't set the ~/.cups/lpoptions by using lpoptions -d default_printer. To run the command, I use a function that I found and that executes it as the logged user.runAsUser() { if [[ "${loggedInUser}" != "loginwindow" ]]; then launchctl asuser "$userID" sudo -u "${loggedInUser}" "$@" else echo "No user logged in" exit 1 fi}If I execute the command as test:launchctl asuser 502 sudo -u myuser /usr/bin/lpoptions -d default_printer, it does nothing. The lpoptions file is not populated. Even if I run the command line locally, it doesn't work. It only works if I run the script or the command line as the specific local user.Any help is welcome !
Recently we have noticed that the System Preferences keeps popping up no matter how many time you turn it off or close it. I have checked the login items and nothing is selected. Any advise?
Had a more experienced Jamf admin show me around the "Software Updates" section of Jamf Pro.Showed me how to select one of the Smart Groups listed in "Software Updates", then click "Update 1 selected" in the top-right of the Jamf Pro window, which brought up a list of options like "Install action" and "Target version".We made our selections, then saved.Is there a way to review those settings that we just made earlier today? If I go through the steps outlined in my second paragraph, it appears that nothing has already been set up, so I'm curious how I'd know that someone else had already gone through the process, or how I'd review existing settings (in the event I thought I'd made a mistake with the Forced Install Date, just for an example).
Hi all!Wondering if anyone has seen this, I generally have 2 local accounts on our MacBooks, one standard user and one administrator, both have secureToken. The MacBook is idling in the logon screen (took logoff from the OS), connected to network, Jamf Remote enabled from the Management -page of computer details.If I start a Jamf Remote session the logon page opens nicely and I can try to logon. I am not however able to logon with my administrator account. The error I get is, that I have an incorrect password (see screenshot), but as you can imagine, I'm quite 100% that I have it correct. I am able to copy paste it from the password management to the window, and I am also able to use the same password if I logon from the keyboard the MacBook itself. So something else if happening here, but I'm a bit lost what it could be.Note, that I can logon to the same machine into an unattended session with my standard user account without any problem from the same window. I am also able to lo
I am setting up Device compliance through JAMF using IntuneEverything seems to work fine on the Mac. The iOS won't seem to complete the registration properly. The device shows up on the user in the in Entra, but never shows up in Intune. It shows the device is compliant.When I go to register, it takes me through Edge on the iOS device then prompts me to sign in again. Then it wants me to add a profile. Nowhere in JAMF instruction does it reflect needing to do this step. I can't get resources to the device currently.This is happening with both test phones I am using.
Jamf's "Learn in Class" page says: Due to the COVID-19 outbreak we have paused the scheduling of in-person courses. Visit our Learn Online page for remote training resources. It's been more than two years since most business offices re-opened. Jamf should bring back in-person training. Benefits of in-person training: Coworkers don't bug me when I'm out of town for training. If I'm in-town, coworkers think nothing of reaching out to me for help. Even when they know I'm in training. Even if I "attend" training from my home. Get to socialize with other Mac / Jamf admins, which leads to Informal knowledge sharing (which has been totally absent from almost all online training I've had) I've been out to Jamf's Minneapolis HQ twice for training, and now that I want to get my 400 cert, I'd like to go back. Here's a photo I took of their building, as seen from the Minneapolis Skyway:
Hi all, We are pushing a script to allow users to change date and time as below:##Allow User to Change Timesecurity authorizationdb write system.preferences allowsecurity authorizationdb write system.preferences.dateandtime.changetimezone allowsecurity authorizationdb write system.preferences.datetime authenticate-session-owner-or-admin This was working fine until now, but it stopped. Did apple changed the preference settings?
We are replacing our end users Macs and are testing out some things.So when we first start up our Mac, we have a local admin password on Jamf Pro that has a password that rotates every six months. When I sign in with the password it works. However when I then sign into Jamf Connect using the end users account and then sign out, this admin password changes to the users entra password and the password on Jamf Pro no longer works.Not sure if this is supposed to be this way? Our Admin account is supposed to rotate passwords every six months. Why is the password changing to the end users account after they sign into Jamf Connect for the first time?
Hi there, How are some of you handling privilege escalation for temporarily escalating local Standard accounts to Administrator accounts then back down to local Standard accounts?Currently we have groups set up in Okta that we use to escalate an account, the user has to sign out and log in with NLA for the group change to be read and thereafter they have to signout and back in again with the Administrator group is removed.Is there no better streamline approach to this that preferably has some sort of logging? Even paid solutions.
Following the instructions listed here: (https://learn.jamf.com/en-US/bundle/jamf-school-documentation/page/Google_Sign-In_Setup.html#ID-0000ce70) we created a Google Console project. For devices that are already in Jamf School (we own them) with the appropriate ADE assigned to them it works.I wipe a device it comes back up and asks to be logged into using Google credentials and it works. So Jamf School and Google are talking to each other. Delightful. For BYOD, iPads we do not own, I'd like to do the same thing. Using the Redirect URI's that are listed under Org-Settings-Enrollment (and confirmed they are the same in the Google cloud console project) all i get are error messages (see attached images). I've had trouble in the past with this on iPad Minis, but I'm using an iPad Air 3 all updated and everything. No luck. What can I do to get outside devices to be accessible in our Jamf School instance using Google as the vehicle for authentication? Wh
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!