Get Support
Recently active
its bad enough @jamf11 refuses to resolve this outstanding, imperative, massively insecure fault that has been acknowledged worldwide, but wha makes it even worse is the fact that Jamf claims to have security at the top of their list. their flagship product in JamfPro CANT ACCOMMODATE this feature request and its constantly being looked over. Jamf, YOU NEED TO FIX THIS AND NOW!!! https://ideas.jamf.com/ideas/JN-I-16171 has an. INSANE response from microsoft claiming that this basic auth isnt even going away. at least today it says that its "Planned" but this has been an ongoing issue for YEARS!!! fix yourself jamf!!!
Hello all, Here's the scenario, I want to install a script in /Library/Scripts on a computer and I want the script to work :-)What permissions do I need to set to ensure it will work?I'm aware of the chmod u+x terminal command to make it executable. After running that command the permissions were listed as -rwxr--r--However a different script that was successfully packaged and installed using the composer method has different permissions: -rwxr-xr-x Also the owner is root...Do I need to change/set the owner to root in Composer? And do I need to change the permissions?Added info for the specific script I had a plist file in LaunchAgents to call the script.
I'm working with a customer and they want to use Jamf Login/Connect. I got this all deployed and setup. The issue I see is since this creates a new user account on their Mac what can we do with the old account data. They want all the data that was on the old local account. Is there a script that would be good to run so they can migrate data over? This is a deployment with out MDM yet.
So I am watching the Jamf Training video to setup my new Jamf Pro instance. I get to the part where I set and confirm our tenant name, and create the instance for Jamf Pro. Success there, the Instance Status shows as 'Operational', and I move onto the next step as described in the video by clicking the "Log in" button to the right of the newly created instance.From what I see on the video, clicking on that button should take me to the newly created instance and pull up the Software License and Services agreement so I can continue on with the Jamf Setup Assistant process.... but instead when I click on the link, it shows me "404 Error" and says "You've cat to be kitten me right meow. This URL Does not exist on the server. Verify that the URL is correct." What on earth do I do???
Don´t know if this is the right forum to ask, but I have a issue I simply cannot solve - even it should be quite easy. For some reason, when sending mails and I want to send some pictures, the pictures is not attached anymore - but inserted direct in the mail I have googled a lot on this issue and some claim it is something with signature etc, but still it does not help anything. I have try and update to latest 11.2.6 IOS , but it is still the same issue Do any have a clue how to change such an "simple" setting
How does one go about calling data from the JSS for use in BASH scripts? For example, I have the following code: /System/Library/CoreServices/ManagedClient.app/Contents/Resources/createmobileaccount -n $username -h /Users/$username -S -v For $username I would it to equal "Username" from a targeted computer within JSS> ComputerName> User and Location> Username. My use case would be for users of Casper Remote who were to migrate Network managed users to Local managed users. They would select the target machine within Casper Remote and a script that basically performs the above. They don't really need to lookup who the user is because JSS knows what user this computer belongs to. So for them, this process is very easy because I am leveraging JSS's database.
In the computer lab where I work, we use a generic student user account for all students on our Mac computers, and for privacy reasons, all web browsers are set to run in private "incognito" mode. Recently, with the introduction of the new Microsoft Teams (Work or School) app, I observed a couple of issues related to user logins. First, users could automatically be logged in by simply clicking their names on the splash screen when Teams loaded. Second, sometimes a Teams user would remain logged in even when the macOS user had logged out. To address these issues, I conducted some research and found that Microsoft's recommended solution is to delete Teams login information from the keychain. However, they do not specify which keychain entries need to be removed. After spending some time investigating, I identified the keychain entries related to Teams. It's worth noting that some of these entries are stored in the "Login" keychain, while others are stored in the "Local Items" k
Links for the macOS Monterey and Ventura specific Safari 17.4 installers on Apple's CDN: macOS Ventura: https://swcdn.apple.com/content/downloads/30/42/052-59885-A_5IXDIWICU3/q9megna20yvg9mnjssbc92f9ogq8w5itbx/Safari17.4VenturaAuto.pkg macOS Monterey: https://swcdn.apple.com/content/downloads/08/43/042-52122-A_3QCC9W93M1/33p5cnqc6qjqbedklpbl7ssbjh7fkbrka6/Safari17.4MontereyAuto.pkg Upgrading Safari to version 17.4 on macOS Sonoma requires installation of the macOS Sonoma 14.4 update.
First Post!Started a new MacBook Pro from Prestage Enrollment yesterday morning, looked great at first. I pulled up the Applications folder and sorted by Date Modified (newest) so I could keep an eye on the Apps as they popped up. Just Protect popped up. The rest never did. Checked the progress in JamfPro (Cloud) and all the apps are in Pending status. Looked again this morning, still pending, Checked all the scopes and looks fine. Just for giggles I put together a .pkg, wrote a policy to push it out to that laptop and two others that had used same pre-stage successfully. Those two grabbed the .pkg almost immediately, the other didn't. Those two were scoped identically to the third that failed.yes - The computer is checked in the pre-stage enrollment in Jamf.no - it did not inventory much at all except the basics, did not pull in the user info, current apps list, etc, that you would expect to see when a Mac does that first inventory upon enrollment. A little bird to
After the update to iPadOS 17, our iPads show the *.jamfcloud.com certificate as expired.All iPads that show this error have stopped checking in to JAMF.Even though the expiration date is shown as March 2022, the iPads that are still on iPadOS 16.x are still checking in right now.Our profile doesn't allow resetting the iPads or adding a new MDM, and I can't push a changed profile because the iPads are not checking in.We don't have a device that can run Apple Configurator either, so we can't batch reset them.Is there any way this problem can be solved?
Is there anyone here who has successfully deployed Equitrac and printed using Xerox, deployed from Jamf Pro in their environment? I have it working intermittently, but the inconsistencies would be a nightmare for the service Desk and no doubt create endless tickets. I have followed instructions from their support service called Kofax, created a script, packages and PPPC's, run locally and deployed from Jamf Pro, but still the process of printing using Equitrac continues to encourage grey hairs at an alarming rate. We have tested on M1, M2 and M3 chips. Monterey, Ventura and Sonoma. The inconsistencies are never-ending. We have scenarios where the EQLoginCotroller.app, will not appear. Sometimes it will appear but give an error saying "Unable to connect to print server". Sometimes it appears, allows you to authenticate, but never sends the print to the server. Sometimes the print cost preview will pop-up, other times it will not.On a good day, it'll work consistently on d
Hello, I've been using Jamf Connect for a while to sync users account, but since (I believe) the upgrade to Ventura, the login screen for Jamf Connect is always skipped on reboot.We are using Filevault, so usually I would simply run the command bellow to set the Jamf Connect login screen back in. This worked for every MacOS upgrades since Mojave./usr/local/bin/authchanger -reset -jamfconnect But since Ventura, the Jamf Connect login screen won't show up after a reboot. Even if I use the authchanger reset command. I just updated Jamf Connect to 2.24 unfortunately resulting to the same problem.Did this happen to anyone else ? Were you able to fix it ?
I am attempting to get policy statuses for computers from the API. I found a few older posts (from around 2015) saying it wasn't possible, but I also found this post (https://community.jamf.com/t5/jamf-pro/extract-a-jamf-policy-status/m-p/252920) that gave me some hope. I connected with PowerShell and was trying this:$url = "https://domain.jamfcloud.com/JSSResource/policies/id/318" Invoke-RestMethod -Uri $url -Method Get -Headers @{"Authorization" = "Bearer $token"}I get a response, but without any information:xml policy --- ------ version="1.0" encoding="UTF-8" policyAny ideas on returning policy statuses with the Jamf Pro API?
Hello - we are just starting to roll out Jamf Teacher, and I believe we have Jamf Pro because the actions are fairly limited. If a teacher wants to block Safari, but still allow students to go to Google Docs (not the app) is this possible? If you put the website on the allowed websites, but disable Safari, does that work? Or do you need to allow Safari and put the allowed website? Thanks for your help!
Hello everyone, We are looking for a solution to deploy a configuration profile on a local profile (MacBook).We need a local "exam" account for our students, which would only allow access to a list of authorized URLs.We can set this up with a configuration profile (Parental Controls).The problem is that we want to apply it to a local account, is that possible? Thanks in advance for your answers!
I know this has been asked previously but want to know if there is any work being done to fix it apart from working directly on the affected Macs?The school has Jamf Connect synced with Google. If a student forgets their password it gets reset at Google but then they cannot log onto a Mac that they'd previously worked on as the old password is needed. Only fix is to login as a local admin on that mac and either reset the password or delete that user. This seems to be a known issue. Is there any work being done that can somehow sync passwords when the students are not logged in so we don't have to go around manually fixing it all the time?ThanksAndrew
Hey Nation, I'm using the ComputerAdded webhook to trigger an API call to my Asset Management System and return the Asset Tag of a device to upload to JAMF. By and large I've got this working, but in the process I got thinking that I could use the data from the webhook to sanity check MAC addresses in my AMS. Problem is, the ComputerAdded webhook doesn't appear to be providing the MAC address (nor do I appear to be able to view it in the GUI) which leads me to believe that data isn't being collected at all. {"webhook": {"id": 1,"name": "Asset Tag TEST","webhookEvent": "ComputerAdded","eventTimestamp": 1709810616365},"event": {"udid": "69C2B48D-****-****-****-266461B028B3","deviceName": "","model": "MacBook Pro (13-inch, 2018)","macAddress": "","alternateMacAddress": "","serialNumber": "C**********L","osVersion": "","osBuild": "22G90","userDirectoryID": "-1","username": "","realName": "","emailAddress": "","phone": "","position": "","department": "","building": "","room":
There are a couple of screens where you can update the OS for a device / iPad.Some times this fails to update. One of the reasons is because there is insufficient space on device.However, all of the places where there are update buttons there is no feedback indicating the amount of free space on the device. The suggestion is: where there is a device OS update workflow, make sure that the capacity of the device is clearly visible. Given that the OS update version typically has a size associated, it would be better to flag if the device isn't going to be able to accomodate the update.
On the main devices screen, the list contains the model of the iPad eg. 5th Generation.However, on the Automated Device Enrolment Page it lists the same device as iPad SPACE GRAY.The model pop up only has "iPad" too.I recall there being some period for Apple's lack of specific model labels for iPads. But somewhere Jamf School already knows this association.Why is this important? Trying to find all 5th generation iPads. This is somewhat tricky to do from the ADE page.
Hello, I encountered a problem that is not allowing me to add apps in "Home Screen Layout" configuration. I click "add" and select the app, after I try to add another one nothing happens, and it disappears after saving. New blank configuration without pre-settings. Can you help with it please?
How can I enable / disable the setting "Require an administrator password ... to access systemwide settings"?
Hello,I am attempting to create a custom Jamf Connect Menu Bar using the second example from Jamf's documentation (https://learn.jamf.com/bundle/jamf-connect-documentation-current/page/Custom_Menu_Bar_Action_Items.html). While on a brief call with Jamf about work arounds for the 802.1X PI, I was told to use the command of "open url" to the self service policy. I am referencing the install item URL template (https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Jamf_Self_Service_for_macOS_URL_Schemes.html), but I am struggling with the XML in the PLIST and it keeps telling me my formating is wrong because I don't know which commands to use exactly; if I'm even going about this correctly. Does anyone have any examples of a PLIST running a policy from Self Service from their Menu Bar?Thank you
Sorry for the weird/stupid question, but if I paid for Jamf training/certification, can I deduct the cost on my taxes? Just thinking this would fall under “education.” I don’t “need” it for my job, but it does help should I look for a new one
Hallo,Könnte mir bitte jemand erklären welche Funktion die hier im Bild markierten Punkte haben?Was beeinflussen die Genau und wie werden die appliziert?Handelt es sich um eine "feste" oder "temporäre" Einstellung?Wird die nur für diese eine App appliziert oder auf alle Apps?Sorry für die viele Fragen, blicke aber leider nicht durch wofür diese Einstellungen sind.Ich glaube jedenfalls dass diese Einstellungen Einfluss hatten auf die Deinstallation von Apps....Kann es sein dass die App sich erst deinstallieren liess, nachdem ich hier den 2. Punkt von oben (Zur automatische Installation wechseln für alle Gruppen) ausgewählt hatte. Konnte mehrere Apps nicht deinstallieren und glaube dass diese Einstellung etwas damit zu tun hatte.... Kann mir aber auch nicht erklären warum.Ich würde mich über eine Aufklärung sehr freuen.Vielen DankBeste Grüsse
we need to remove VPN Icon from menu barany idea how to achieve this via configuration profile?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!