Get Support
Recently active
Hey guys, I noticed that wiping our Macs reverts them to Ventura from Sonoma and was wondering if this is expected behavior. If it is, does anyone have recommendations for how we can get them updated as soon as they've restarted? If this is not expected behavior, does anyone know of a proper fix?
So I'm tasked to present the differences between Jamf Pro and Jamf School of my employer, a school (university).On the Jamf site they promise that functionality and management options are similar.What is your experience? Do you mis anything from Jamf School?What I mostly use of Jamf Pro is: app catalog & patch management, software update via MDM commands, wipe and application installation.I'm sorry, I'm only familiar with Jamf Pro, and my request to demo Jamf School is denied unfortunately (not enough time because of understaffing).
Hello,In our company, we automatically sync certain folders from a sharepoint site to all Windows devices via OneDrive.Now I am looking for a solution to solve the whole thing with JAMF on the Macs.
Good morning,I am having trouble deploying the custom dock, https://github.com/bluemoosegoose/Build-a-Custom-MacOS-Dock. I am able to get it work in my test environment (vm), my work computer and another's tech computer. When we run the policy from self service on either three of the machines it works, however, when we run it on a new machine during enrollment nothing happens. We have tried using self service to run it but we get the same error. The logs show that it went through but none of the icons are removed.
I have been stuck on this for the longest time. I am unable to do an iPhone to iPhone migration. The new device is enrolled in DEP/ABM and my current phone is not. The setup assistant shows up, I take my old phone and scan the blue globe. At this point I only get the option to do iCloud backup/restore to the new device. I no longer get an option to go device to device. Has anyone else experienced this issue before? Apple support is stating that it could be an issue with DEP/Jamf not allowing the Device to Device option. If I remove the device from Jamf/DEP, that would essentially throw away the reason to even have these devices in jamf or pre-stage. As the screenshot shows, I am not blocking any of the Setup Assistant steps or auto advancing. What I did is I went into Apple Business manager and removed the new phone from hitting any MDM server. I wiped the device and attempted the Setup Assistant with my old iPhone next to it and that gi
I am getting an issue on Mac mini (Late 2014) after upgrading it from 10.14.6 to macOS Monterey 12.7.3 through downloading installer from App Store. It says it cannot open a perl script. I've given the full disk access to terminal, sshd-keygen-wrapper. I am still getting the same issue. I am able to run the script directly from my ssh terminal but when automation tool (through ssh) tries to run the script the error is getting. /NFSmountDir is actually /System/Volumes/Data/NFSmountDir
We have some tools in Self Service only available to Jamf admins. Like a Microsoft uninstaller. I remote into user's computers and try to log in to Self Service to get to my admin tools but whenever I click on the log in button, it is already trying to log in with the local user credentials and I can enter my admin credentials. Is there a way to prevent that from happening?
We are currently using Pulse Secure v9.1.x and need to upgrade this to the latest offering from Ivanti, Ivanti Secure Access v22.2 in preparation for Ventura.We have done many Pulse to Pulse upgrades in the past, all PPPC's and System Extensions have been accounted for.However, going from Pulse to Ivanti, when it is removing/upgrading we are getting a pretty generic popup that we felt could be accounted for with either a new PPPC or addition to existing.At this time, nothing we have done will stop this particular popup from showing up.Looking for any info/guidance from anyone that has possibly already gone through this upgrade or similar?
I'm in the process of testing out jamf installers for Box Drive and Workspace and I checked the Install supporting configuration profiles box, which from reading should disable the autoupdating. It did update both applications, but I noticed it added the autoupdater files. My question is, even though it added the files, will it still disable the updates with that option checked?
I recently had Jamf Pro update my MacBook to 14.3.1 from Ventura. The computer is AD bound and we have the Domain Admins and another group we use set so they should be computer admins. Before I pushed the upgrade my account was listed as "Mobile, Admin" but after the upgrade it just say "Mobile". I logged out and logged in as another account from our admin group and it didn't give that account Admin status either. At this point I suppose my next step would be to try to rebind the Mac to AD and hope that corrects the issue.Has anyone else seen this happen?
Hey Jamf people We are working to push more and more of our standard apps out via the Mac Apps section (either 'App Store' or 'Jamf App Catalog'). Slack, Zoom, Chrome,etc. The part I'm confused about, is when they require Configuration Profiles to be installed with them. It looks like they're only if you want to suppress the developer updates so you can control updates yourself? Or is that wrong.Separately, is there a way to control the Config Profile deployment so it automatically gets installed when the app is installed? For a few forced apps, this isn't an issue because we can use the same Smart Group for both the app and the config profile installation, but if we have an app 'Available in Self Service', how do we ensure the config profile is installed after the user installs via SS? Creating a Smart Group that checks for installation of that app isn't too trivial but it's just more work when it seems like there should be a setting in the settings for each Mac App that say
Hey all,I'm looking to offboard a few devices from our JAMF Pro environment completely and would like some clarification. I've ran the 'Remove MDM profile' on all devices, and had users run the 'sudo jamf removeFramework' cmd to ensure that there is no underlying Jamf connection remaining. I've also removed JAMF as their connected MDM server in ABM, but noticed that even in Jamf the PC still checks in.Same with FileVault 2, it is still active and the recovery key remains in JAMF. If I delete the record after these steps, what is expected to still remain on the device? (other than service accounts or apps that I haven't removed)? Is there a preferred way to completely remove JAMF from the device?
Hello, we currently distribute ipads to users and then walk them through entering Vantagepoint server info and registration. We also do the same for apple id registration. I was wondering if it is possible to automate this info using Jamf? Like for example, once a user is assigned to an ipad in Jamf, is there a way for Jamf auto sign into their icloud account?For Vantagepoint, would their be a way to prepopulate server info? Thank you!
Hello, Jamf Nation! Thank you for being a part of our community. We appreciate your feedback as we continue to work to enhance your experience with Jamf. March 1-2, 2024, Jamf ID will be receiving exciting improvements and security enhancements. As a result, all Jamf ID users must reset their passwords after the update. There is no action required today and further instructions will be provided in March.
Students figured out if they change DNS settings to manual, they can bypass OpenDNS rules. any suggestions?
Hello all, My company has transitioned away from Chrome and now use the Island app as the main corporate managed browser. Island is a Chromium based browser that we have more control over. Our Jamf Connect is configured to use Chrome and we can only change it to Safari. Does anyone know how we can make it accept this new browser or if that is even possible?
Hi All. I have a bunch of Mac Studios that came with macOS Monterey and I'd like to upgrade them all to macOS Sonoma before proceeding to provision them with JAMF autopilot.With Intel Macs, one could boot while holding [OPTION]+[COMMAND]+R and then be presented with the latest compatible OS as the installable option, but with Apple silicon when you boot into Recovery mode you are only offered the OS that is already installed.Does anyone know how to boot into the latest OS in Recovery mode on Apple silicon Macs?
Hi,We are starting to see issues where installing locally via the payload file and postinstall.sh works fine but installing it after being packaged (either via Packages or PKGBUILD) results in the following error when launching the application (Pro Tools 2023.3.0 as an example here)...' "Pro Tools" is damaged and can't be opened. You should move it to the Bin.'Following the help icon opens a page stating, "The app has been modified, and its code does not match the original signed code."In Privacy and Security we can go ahead and choose to "Open Anyway" but this is not a viable way forwards for applications that we are trying to deploy hands-off.It feels like the packaging process is stripping some attributes from the files. I have tried to use xattr to re-add "Date Downloaded" data but that doesn't resolve the issue.In the case of our Pro Tools 2023.3.0 package, it copies a DMG to /tmp (we've tried other areas in case this was the problem and we're trying this way due to th
I have MacBooks and iMacs (both M-series and Intel) ranging from macOS 12.3 up to 14.3. We have lab computers and do not want students signing with Apple IDs or using the App Store. I've created a Restrictions config profile with both "Apple ID Preference Pane" and "App Store" disabled. I login with a local admin or standard account and it will show it locked down (sweet!). Then you close system preferences/settings then re-open it, and there is the ability to login, as if the configuration profile isn't even there. Reboot and do it again, then its back to restricted... then not. This is clearly broken. The App Store also opens right up every time... So what's the fix?
My org has set up Jamf Connect to sync passwords between my local account and IdP. I do not understand the rationale here, as the 1st rule I ever learned about passwords was to not share them between accounts. Can someone either explain the logic or perhaps link to some relevant docs on why this is a good idea?
Hey everyone ...trying to install a package to all my fleet, it got installed successfully on all of them except 1 Mac !!"Installation failed. The installer reported: installer: Package name is XYZinstaller: Installing at base path / installer: The install failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurred while running scripts from the package “zyx.pkg”.)What does that mean? why only that endpoint!?
When typing serial numbers that almost match a real word, Safari autocorrect jumps in and makes the correction. You end up not finding the device you are searching for and have to go back and make the correction. Possibly hitting ESC to avoid the change.Also happens when typing student names that might have variations on spelling.Frustrating because are typically focused on the left side of the screen after typing the search text and don't notice. Sometimes you jump into the habit of hitting escape to avoid the issue. But most of the time, you don't.There is a way to load the HTML field so that auto correct is turned off.It would be great if Jamf School turned off autocorrection in search fields, especially if they could be capturing serial numbers.input autocomplete="off" autocorrect="off" autocapitalize="off" type="text"
Jamf Pro 11.3 makes LAPS easier to use via the Jamf Pro interface, introduces support for Account-Driven Device Enrollment on computers, and brings improvements to the Jamf App Catalog experience for administrators and users alike! Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements. Thank you for your continued support and feedback!
Greetings all,Is the Jamf One app for iOS obsolete? I hadn't used it in quite a while, and when I tried today it gives a network connection error. In investigating, I don't see it on the App Store anymore either...
We want to manage New Users with a script upon enrollment and disable iCloud Drive in the Finder Sidebar. Does anyone know the defaults write command for that? No command works for us. Thanks a lot
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!