Get Support
Recently active
Hello all, My company has transitioned away from Chrome and now use the Island app as the main corporate managed browser. Island is a Chromium based browser that we have more control over. Our Jamf Connect is configured to use Chrome and we can only change it to Safari. Does anyone know how we can make it accept this new browser or if that is even possible?
Hi All. I have a bunch of Mac Studios that came with macOS Monterey and I'd like to upgrade them all to macOS Sonoma before proceeding to provision them with JAMF autopilot.With Intel Macs, one could boot while holding [OPTION]+[COMMAND]+R and then be presented with the latest compatible OS as the installable option, but with Apple silicon when you boot into Recovery mode you are only offered the OS that is already installed.Does anyone know how to boot into the latest OS in Recovery mode on Apple silicon Macs?
Hi,We are starting to see issues where installing locally via the payload file and postinstall.sh works fine but installing it after being packaged (either via Packages or PKGBUILD) results in the following error when launching the application (Pro Tools 2023.3.0 as an example here)...' "Pro Tools" is damaged and can't be opened. You should move it to the Bin.'Following the help icon opens a page stating, "The app has been modified, and its code does not match the original signed code."In Privacy and Security we can go ahead and choose to "Open Anyway" but this is not a viable way forwards for applications that we are trying to deploy hands-off.It feels like the packaging process is stripping some attributes from the files. I have tried to use xattr to re-add "Date Downloaded" data but that doesn't resolve the issue.In the case of our Pro Tools 2023.3.0 package, it copies a DMG to /tmp (we've tried other areas in case this was the problem and we're trying this way due to th
I have MacBooks and iMacs (both M-series and Intel) ranging from macOS 12.3 up to 14.3. We have lab computers and do not want students signing with Apple IDs or using the App Store. I've created a Restrictions config profile with both "Apple ID Preference Pane" and "App Store" disabled. I login with a local admin or standard account and it will show it locked down (sweet!). Then you close system preferences/settings then re-open it, and there is the ability to login, as if the configuration profile isn't even there. Reboot and do it again, then its back to restricted... then not. This is clearly broken. The App Store also opens right up every time... So what's the fix?
My org has set up Jamf Connect to sync passwords between my local account and IdP. I do not understand the rationale here, as the 1st rule I ever learned about passwords was to not share them between accounts. Can someone either explain the logic or perhaps link to some relevant docs on why this is a good idea?
Hey everyone ...trying to install a package to all my fleet, it got installed successfully on all of them except 1 Mac !!"Installation failed. The installer reported: installer: Package name is XYZinstaller: Installing at base path / installer: The install failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurred while running scripts from the package “zyx.pkg”.)What does that mean? why only that endpoint!?
When typing serial numbers that almost match a real word, Safari autocorrect jumps in and makes the correction. You end up not finding the device you are searching for and have to go back and make the correction. Possibly hitting ESC to avoid the change.Also happens when typing student names that might have variations on spelling.Frustrating because are typically focused on the left side of the screen after typing the search text and don't notice. Sometimes you jump into the habit of hitting escape to avoid the issue. But most of the time, you don't.There is a way to load the HTML field so that auto correct is turned off.It would be great if Jamf School turned off autocorrection in search fields, especially if they could be capturing serial numbers.input autocomplete="off" autocorrect="off" autocapitalize="off" type="text"
Jamf Pro 11.3 makes LAPS easier to use via the Jamf Pro interface, introduces support for Account-Driven Device Enrollment on computers, and brings improvements to the Jamf App Catalog experience for administrators and users alike! Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements. Thank you for your continued support and feedback!
Greetings all,Is the Jamf One app for iOS obsolete? I hadn't used it in quite a while, and when I tried today it gives a network connection error. In investigating, I don't see it on the App Store anymore either...
We want to manage New Users with a script upon enrollment and disable iCloud Drive in the Finder Sidebar. Does anyone know the defaults write command for that? No command works for us. Thanks a lot
Hey guys. I have a website we use that asks for a client certificate from the users. I'd like to auto-accept it in Safari and are pushing these custom settings with the SCEP certificate, but it wont work in Safari. We are using this documentation and it works for the TENANT.vmwareidentity.eu. I can get Google Chrome to auto-select the certificate. This is the custom code that I'm pushing <dict> <key>Name</key> <string>WEBSITE HERE</string> <key>PayloadCertificateUUID</key> <string>UUIDHERE</string> <key>PayloadUUID</key> <string>UUIDHERE</string> <key>PayloadType</key> <string>com.apple.security.identitypreference</string> <key>PayloadDisplayName</key> <string>Identity Pref</string> <key>PayloadVersion</key> <integer>1</integer> <key>PayloadIdentifier</key>
Hello Everyone, I am testing out a new enrollment process and testing different use cases.I seem to run into an error every time when I enroll a device with a user who DOES NOT have a Jamf Pro Account, within the Jamf Pro Console (Account Users and Groups setting). I able to enter my SSO credentials and complete MFA, but after that step, the enrollment Management Screen just hangs, doesn't move forward in the process. Is this expected? I was previously told by Jamf Support that the Jamf Pro Console account should not be a factor, but it looks like it is? Any help would be appreciated, thanks! James Rodgers
Hello.I'm trying to ensure teams is closed prior to updating app and getting errors when trying to force close it. killall "Microsoft Teams (work or school).app" Works fine with Classic teams i'm sure it's something about work or school part getting lost in code just don't know how to fix it. Thank you for your time.
Hi there, Does anyone know of an app (preferably tied to Jamf) that is capable of hardware diagnostics? i.e temp, storage limits and general performance related variables.
OOI, does anyone know of a way of deleting existing icons uploaded when creating Policies?Have a couple of duplicates/redundant icons that I'd like to just tidy up.
hello all, does anyone know how to disable remote login using a profile/policy
We are having an issue with Secure Tokens.JAMF creates an admin account by default, which is created before setup assistant and almost always the fist account we log into. From my understanding, the fist logged in account is the one that gets the secure token. However, in many case (not always) a generic standard account we push through policy is the one that gets the token. This causes issues with running updates and changing passwords. I am able to resolve it through a series of terminal commands but wondering what is causing in the first place. I originally thought it was an issue with Catalina but am still seeing it currently with Ventura.
Here everyone - please go and vote for this in the feature requests. It is annoying to have to spend 1/2 the day logging back into Jamf and waiting for the page to load. https://ideas.jamf.com/ideas/JN-I-27272
Dear allI have created some guidelines in Jamf.These also work, but unfortunately only when you click on "Install" in the Self Service Portal.Is there a way for such policies to be installed automatically without having to proactively click on Install?Information about a policy:Policy: Disable IPv6- General:Trigger: Enrollment CompleteExecution Frequency: Once per computer- Restart Options:Reboot Method: Standard RestartStartup Disk: Current Startup DiskNo User Logged In Action: Restart if a package or update requires itUser Logged In Action: Restart if a package or update requires it- Files and Processes:Execute Command: networksetup -setv6off "Wi-Fi"- Self Service:Button Name: Install Do you have any ideas?I would be very happy.Best regards
Here is the script I started using from Jamf Nation: Parameters: Error: I found the Waiting Room and I had to give myself permission to view the folder because I don’t have access The agent file is there. But it fails to install. Is there anything I should do? It is failing on all of our organization's Macs.
We have 100 MacBooks that we manage with On-Prem Jamf Pro. We have seven (7) different VPN servers that our users can choose from to connect to the company's network. Jamf is working normally on all machines EXCEPT for the MacBooks connected to our NY VPN server. For the 5 people on the NY VPN server, they all have Pending Management Commands stuck for weeks, maybe months. I clear them out, but they come back and go Pending indefinitely again. Even the built-in commands (like InstalledApplicationList, SecurityInfo, ContentCachingInformation, ContentCachingInformation, CertificateList) are stuck Pending as well. I cannot send any Configuration Profile to any of these machines on the NY VPN. But the same Config Profiles work everywhere else. I don't think that re-enrolling them in Jamf is an option since they are all working from home and also because the "Allow MDM Profile Removal" was not checked in the PreS
Just updated our jamf cloud to 11.3 and noticed that I have a whole load of config profiles now in 'No category assigned' Prior to the upgrade all our config profiles where in the correct category. As we have a pretty robust naming convention this took only a little bit of work to get them back where they should be.. but... better things to do! Any one else?
I'm testing management of mobile devices in Jamf Pro and have just user enrolled a mobile phone. Looking to test the remote lock feature if a device is lost/stolen, which worked flawlessly, but now I can't find any way of unlocking the device. Would have expected the Lock Device button to switch to an unlock option, but that hasn't happened, and I'm not finding any documentation on how to unlock a lost/stolen device should it be recovered.How am I suppose to unlock a locked mobile device in Jamf Pro?
Has anyone attempted to perform policy updates or installs to computers that are in cart(s) asleep and lid closed? I notice the computers check-in while in this state, therefore, why not push updated policy at night when no one is around?
Hello,Has anyone successfully been able to connect to an 802.1x wireless network from the Jamf Connect Login screen while being unbound and using the ADCS Connector? If so, please share your Network/Certificate payloads. Edit: After configuring this myself and helping many others with this issue, I've created a simple guide for those of you that need help below:1. Configure one of the following:A. ADCS Connector (expensive)B SCEP PKI Cert (inexpensive)2. Add the PKI Cert to your Jamf Pro Server.3. Learn how your Radius server authenticates. (username, hostname, serial, etc)4. Configure a Wireless configuration profile that contains the chain of trust for your radius server the ADCS/SCEP cert and trust these certs. The profile most also contain your wireless payload.5. Deploy the profile. How to configure ADCS: https://youtu.be/oRkpkN1Z3aIHow to configure SCEP: Integrating with DigiCert Using Jamf Pro - Integrating with DigiCert Using Jamf Pro | JamfOpen a tick
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!