Get Support
Recently active
How do you do?We have just started testing the roll-out of BYOD and have discovered that the profile for personal devices has an .html extension.This means that we cannot install it.We have the problem on different iOS devices with different browsers.
Am I right in believing I have to change the setting for "autoDeployEnabled" to true before I will be able to see the password of a local admin? At the moment if doesn't appear to do anything even though it will pop-up a message saying viewing the password will cause the password to rotate in 1 hour.Currently just looking to see what/how this feature actually does.
Hi I am unable to login to my JAMF school account as it wont accept my verification code. How do i turn this off
Hi All,Anyone Send the script for Tailsman Installation in Default path /users/user_name/.tailsman/bin
Hello, Jamf Nation! I’m excited to share a project that I believe could bring significant value to our community—App Auto-Patch. Designed for macOS application management, this tool leverages the power of swiftDialog and Installomator to streamline the application patch management process, ensuring your Macs' applications stay up to date effortlessly. Key Features: Local Application Discovery: Automatically identifies applications installed on Mac computers that require updates. SwiftDialog Integration: Enhances user experience by providing clear, friendly prompts for update deferrals and installations. Flexible Application Management: New variables allow for customized handling of applications in the user's home folder, including conversion and ignoring options. Improved Deferral Window: Offers end-users clarity on pending updates with a resizable deferral window and updated messaging. Webhook Reporting: Enables status reporting to Teams and/or Slack, offering insights into patching
Hi Jamf Nation!I have some questions about what happened in a MacBook after it received the WIPE command, rebooted but without the firmware passcode being authenticated? Could the command be cancelled in any way?We have a MacBook Air (Retina, 13-inch, 2019) with Intel chipset running macOS 14.3. WIPE command issued and it is now stuck at the user login -> reboot to firmware lock loops."Clear Activation Lock" option was chosen when attempting the command, but it says activation lock not found, so the WIPE command was issued without. After the command was sent, the MacBook immediately rebooted into the Firmware lock, which then we realized the passcode is unknown. Attempt to boot or reboot the machine will first goes into the user login page, and ended up at firmware lock after user authentication. We did not reach the steps to enter the 6 digits arbitrary passcode.I read this from the previous post:@talkingmoose wrote:If the computer has been protected with a firmware passcode,
Hello everyone,I've noticed something that I believe many of you might have experienced as well. We've set our devices to automatically update to the latest version through Jamf App Catalog settings for patch management purposes. This is working great! However, the updates for these apps are often made simultaneously, causing all 500 devices to try and get the latest version through our 500Mbps internet connection. This is causing significant bandwidth issues.I understand that this issue should be managed by shaping the traffic, but unfortunately, my current firewall solution won't do it with great success.So, my question is, is there an option similar to packages where I can store them locally on a file share distribution to alleviate the sudden influx? Additionally, is there an option to spread the updates over a week instead of all at once without doing it manually?
hi,at my organization, we are wanting to downgrade all user accounts from administrator level to standard level per our new security policies. eventually, we will add MakeMeAnAdmin in order for users to temporarily gain access to admin level privileges. what is the best way to downgrade users on a large scale via jamf pro rather than visiting each computer one by one to change them to standard accounts?thanks!
Hi! I decided to test using the Inventory Preload option on to PreStage enrollment of one computer. I got the CSV file completed and uploaded it successfully and it shows up as the Active data. After doing the PreStage enrollment (no previous record of this device), I don't see that it applied the preload data. I did only complete the serial number, department, and building fields in the CSV file since those were all I needed. My question is, does anyone know if certain fields (besides serial number) are required for this to work? Has anyone else had this happen or something to try? Thanks!
When you look at the Devices > Updates page, there is a tab list of various OS flavours that could be updated.There is a filter above this tab view.When you change the tab to a different operating system, the filter is cleared / reset.This is very frustrating. From a UI perspective, a top down hierarchy of dependencies typically works. Items below shouldn't change the state of those things above. This screen breaks this principle. The workflow to change tabs whilst requiring the same filtering parameters is quite common, especially because the variants of an OS are split into different tabs. Right now I can see tabs for 17.3.1, 17.3, 17.2, 17.1.1, 17.1, 17.0.3. I'm looking at filtering for iPads that are 9th gen that belong to a particular group. Every time I click a different variant of 17.x the filter resets. I have to go back to change the filter back to match my query.Really time consuming.Also confusing since it isn't generally possible for devices to update to anythi
I am getting an error message "The operation couldn’t be completed. (com.jamfsoftware.task.errors error 5.)" on the logs of a policy for only one endpoint. All that the policy does is to remove the EFI password. How do i fix that?Is there a way to check through jump maybe that error is caused because the endpoint has no EFI password at all?
Hi,We currently deploy Xink software to our mac users via Jamf. 95% install successfully however we have a few because they've missed the prompt "Jamf" wants to access to control "System Events". Allowing control will provide access to documents and data in "System Events", and to perform actions within the app. When signatures are updated - we get the error: "Not authorized to send Apple events to Microsoft Outlook". An error occured while updating the signature 'Signature 1' in Outlook. Has anyone else come across this and now how to resolve as Xink support has been really poor. TIA.
We're testing out the new update and it's updating AnyConnect just fine and connecting. The only issue I'm having is some of our test users are getting the prompt to allow csc_iseposture to Desktop, Documents, Reminders and Downloads. I created a new config profile for the new agent using.Identifier: csc_iseposture, BundleID with Code requirements for csc_iseposture. I have the above folder selected and set to allow. I see in our old Anyconnect profile, it has the same including policyallfiles. I did try adding policyallfiles, but still got one prompt to allow for desktop.
We recently updated to iOS 17.3 on our iPads, which required us to re-sign in to the students' Apple IDs. During the sign-in process, some of them encountered verification failures. In the past, we would resolve this issue by deleting the account in Apple School Manager, and overnight, the account would be recreated. However, recently, this method has not been effective. Currently, we have 5 students without Apple IDs. We contacted Apple about this issue and was told this was a problem with JamF.
Reposting this from my personal website to gain some visibility. UPDATE 1: I'm being told now that this change IS RETROACTIVE. Meaning your dozens/hundreds/thousands of endpoints that have been configured with Prestage enrollment, and an admin account created in that process, will have that password randomized. Which will break Secure Token/Volume Ownership/etc. Maybe you're okay with this, but if you're not, you NEED to reach out to your Jamf Representative and tell them. I wanted to bring up that a big change is coming to Jamf soon and they (Jamf) seem to think it’ll be well received all around: forced LAPS for Prestage (ADE/DEP) admin accounts (See bullet 2 here, https://learn.jamf.com/bundle/jamf-pro-release-notes-current/page/Deprecations_and_Removals.html, “Functionality to specify the local administrator account for computers in a PreStage enrollment”). And to start with, I applaud Jamf for working on a LAPS solution. All we've ever asked in this whole
Intermittently our DEP/Auto-Enrolment devices do not complete the enrolment process. The MDM profile and cert is applied, Config Profiles apply and the device appears in JAMF Inventory however Policies never kick off and Self Service is not installed. We've seen similar issue to this over the past few years but never seem to get a solid answer from JAMF support, now we are seeing it on some of our new M1 Macs. It's seemingly completely random, I'll enrol 4 identical devices, 3 will complete as expected and the 4th will do as described above. All on the same network, same model, same Pre-Stage...Why is this issue so difficult to solve? Why does it keep happening? When can we expect it to be resolved?
Hey all,I need to somehow be able to set the default backup folders for google drive, and while I was looking through the app config plist files, I was able to find that in the "com.google.drivefs.plist" file, there's a key called SyncTargets, which contains an encrypted <data> field, which has the folders that you want to backup to google drive.Has anyone been able to override or preset this value before?Thanks!
I've run into an issue with signing back into a Mac (macos 14.2.1) and I'm not exactly sure if it's related to JamfConnect. Our fully configured Mac is running Jamf Connect 2.29. I'm logging in with an administrator account created during PreStage enrollment. After no input for a while, the Mac goes to sleep or screensaver. If this state remains for too long, the mac won't complete the login. I can enter the credentials but it just give me the thinking circle and never completes the sign in. All input becomes disabled and I have to force reboot it. Afterwards, I can sign in again without issue. Troubleshooting is nearly impossible because I can't get response from the system while it's having the issues. Can anyone point me to logs or files I can reference afterward? Has anyone else seen this with Sonoma?
Afternoon AllIm aware that you need to run this command /usr/local/bin/authchanger -reset jamfconnect. Normal after a software update to authchanger the jamf connect login window. This has been configured in a policy since we installed Jamf connect some months ago. However recently its become unreliable. In the same policy I have restart script which I understand is also required, if no one is logged in the device will restart this doesn't seem that reliable either. While the logs suggest that all is fine the jamf connect window doesn't seem to get reset after a restart. A few questions Aren't these key suppose to stop this from happening, they appear to been ignored?<key>DisableUpdateWatcher</key><true/><key>DisableRSRWatcher</key><true/>If policy runs while someone is logged in it seems fine on log out. Is there a different command to run if the machine is at the login screen?Has anyone else had a similar issues?Than
I have a user that needs to use her school gmail account on a school ipad. I've deployed the app to self service on her ipad but when going in to the app it wants her to sign in to her itunes account. We do not allow itunes on the ipads. Is there a way for her to login to gmail?
Is there a way to block the scrolling previews at the top of an Apple TV? I've blocked other apps such as TV, Movies, etc but I can't seem to get rid of the featured items at the top.
Can anyone provided details on what this feature does and how to configure it, as I'm not find the documentation very clear. I'm hoping that using it will allow a standard user to enable System Settings > Privacy & Security > Screen Recording & System Audio for Slack, but I can't work out what value is suppose to go in the Code Requirement field.
Hey everyone, Anybody is using a script to rotate the EFI password on Intel Macs? I think having the same EFI password for all Mac fleet is not a good procedure!? Any tips are very appreciated.
Hello Jamf Nation! This release is in support of the Apple Spring release. We have several exciting new features including beta MDM support for Apple Vision Pro, Self Service initial app detection, Support Digital Market Act app restriction, and more! You can find more information in the release notes when you enroll.How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum, click "Join this group Hub" to gain access. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
When creating a Settings > Global > Enrollment customization the Branding and Preview page shows the text box displayed with a scroll-bar, which is to be expected given the amount of text entered. However, during the enrollment process the user does not have the ability to scroll through the text so only sees the first part of what they are, in effect, agreeing to. Why is this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!