Get Support
Recently active
Hello!I am building a package to install FortiClient vpn (the free vpn standalone client) for our users.After several tests, a policy authorizing the security extension is indeed present and allows to avoid blocking it during installation, but a popup asking me to authorize the addition of VPN configuration appears right after the installation.This popup is generated by the "FortiTray" binary and after several tries and I don't know how to authorize it ahead of time so that the installation is totally invisible.It says that ""FortiTray" would like to add VPN configurations"Any idea on how I can authorize this or setup ahead of time ?
Hello everyone,I'm one of our Admins (jPRo) and I work for a very large hospital chain and I've been tasked with exporting all of our mobile devices and asked to create a spreadsheet and a PDF file for presentation for our leadership team to review in their budget meeting coming up soon so they may plan on what we need to purchase as far as EOL devices are concerned.I don't know why, but I seem to be struggling with making this list based on exporting all of our devices which come out to 5,077 devices. I attempted to report my spreadsheet into AI and asking you to make me a list of EOL devices, Near-EOL, and future EOL devices. Well, the numbers that I ended up sending to my manager to review or not accurate, and I looked like a fool and was very embarrassed.Have any of you been tasked with this before and if so, how did you do it and do you have any advice on what the best way to go about doing it is besides trying to use AI. Or, if any of you have been successful in doing this using
Long ago we distinguished between our Staff and Student Macs by “installing” a DMG that just created a folder. We used the search term of “Packages Installed by Jamf Pro” with that DMG name. This has worked fine for us for the past 10+ years. We installed this package on Student Macs and didn’t install it on Staff Macs. If we needed to convert a MAc from Student to Staff, we just used the Jamf Pro capability to “Uninstall” that package. That removed it from the list of “Packages Installed by Jamf Pro”. It seems that with the (no longer recent) removal of Jamf Admin and the ability to index packages, the ability to “Uninstall” packages and DMGs has gone away as well. So we can still install that DMG to tag the Mac as a Student Mac. However, we can no longer “Uninstall” that DMG. Which brings me to my question: How do I remove an item from the “Packages Installed by Jamf Pro” list? This isn’t the same as the package receipt list that you get from running pkgutil --pkgs. I am hoping tha
We use Apple TVs with Playlister throughout our sites, and we’ve been having some audio/video sync issues that are resolved by rebooting the Apple TV. From what I’ve gathered, the only way to reboot all Apple TVs in a group is to manually navigate to the smart group in Jamf Pro > View > Action > Send Remote Commands > Restart Device. This is not ideal not only because it isn’t a process that can currently be automated, but because we would like to have these Apple TVs reboot outside of operating hours.
I’ve had people complain about not being able to get admin rights. It turns out they’ve hidden the Self Service plus app which Tahoe allows. It’s a stupid thing but is it even possible to prevent folks from removing certain apps from the menu bar. And if it’s possible, how do I do it?
The devices that I am managing Shows as MacOS 15.3.1 and shows as up to date. I don't have any restrictions on MacOS update. somehow users are unable to see any new MacOS update? When I try pushing the update through Software update, it's failing. possible it's because these devices were user enrolled. I am trying to get a MacOS 15.5 Pkg and make users download from Self service and update. How to get the latest Pkg or any script that i can use. It's been 2 days of me trying all sorts of scripts and nothing works. Thanks in advance
Fortinet's recent FortiOS 5.4.1 release for their FortiGate security appliances prevents any version of FortiClient prior to 5.4.1 from registering to the appliance. Users may even get a "FortiClient is being actively blocked from registration" which can cause panic and confusion. The problem is that, as of this writing, FortiClient 5.4.1 has yet to be released. Talk about putting the cart before the horse. So let's say that you don't want to have a few hundred upset users and would rather uninstall FortiClient discretely, en masse. Fortinet's documentation tells you to run the FortiClientUninstaller GUI app to uninstall FortiClient. But here's a more streamlined and scriptable method: /Applications/FortiClientUninstaller.app/Contents/Resources/uninstall_helperrm -rf /Library/Application Support/Fortinet/ Optionally, check for the existence of the following file and delete if it exists/private/var/root/Library/Preferences/com.fortinet.FortiClientAg
Does anyone have any guides for getting the dev environment setup for Jamf platform? I want to run a set of platform APIs to verify a user case.
I am looking to report the status of Location Services on our fleet. I found the following script online and tested it but it only reports back disabled even when LS is enabled. Does anyone have a working extension for this? Or can some assist in making this one work? #!/bin/bashuuid=$(system_profiler SPHardwareDataType | grep "Hardware UUID" | awk '{print $3}')domain="/var/db/locationd/Library/Preferences/ByHost/com.apple.locationd.${uuid}"plist="${domain}.plist"if [[ -f "${plist}" ]]then status=$(defaults read "${domain}" LocationServicesEnabled) if [[ "${status}" == "1" ]] then result="Enabled" else result="Disabled" fielse result="Unavailable"fiecho "<result>${result}</result>"
Recently, the ability to manually type in strings to smart group criterion has changed. Now, you have to hit the ellipsis (3 dots ...) button to match your entered string to a smart group before it is accepted and can be saved. Previously, I could just type in the name and if the name matched a smart group, I was able to save, otherwise, the UI would give me an error saying that group name couldn’t be found. But it was easier and quicker because I didn't have to deal with the lookup process.Has anyone else seen this? I submitted a support ticket on this and was told by multiple reps this is now the only supported option and is the expected behavior. Therefore, I have filed a feature request to bring back the old entry method so I (and you) can manually type in a group name. Please look at the request and upvote to get Jamf’s attention on this.https://ideas.jamf.com/ideas/JPRO-I-2243Thank you.
What is learning and do you like to learn?Do you know what content would be relevant for you?Hey, I thought you are here to teach me and not to ask questions.Yes, but questions are a method of teaching and I have a bunch of those.But what about learning, how do we learn or more precisely:What type of learner are you?Auditory / Visual / Read&Write / Kinesthetic(more acronyms, just like a Jamf Class on day one)"So let’s explore."Learning something new has so many options today, not all of them are made for you and me and sometimes I need multiple choices. Not because a resource is wrong, just it connects better with my brain. I remember teaching ski lessons to a bunch of teenagers and I was stuck with one of them on day two. No progress, tried it all, nothing clicked. So we decided to switch training groups. And it clicked, I saw them going down hill super nice. I asked my fellow ski instructor what he did, "same as you before" he said, "maybe just another perspective".While we can’t
I’ve been using iCloud Mail ever since, and I still can’t understand how a mail app can be so frustrating when it comes to basic things like text formatting, copy pasting and handling email attachments, working notifications,…On iPhone, the mail attachment is really horrible… If I want to attach an image the image, it is not separately attached as an own attachment but just lies below the text I wrote… Why??I’ve tried a few other mail apps, but either had security concerns or didn’t want to pay for the Pro features.So this is partly a rant and partly a question: how have you guys managed to make Apple Mail work for you? And if you’ve switched to another mail client that you really like, I’d love to hear your recommendations.
On Aug 18th, I changed over to the SSO integration in Jamf Pro Cloud. I have always had my SMTP server settings configured for email notifications on Smart Device Group Membership changes. I no longer receive those emails even though the box is still checked to do so. In the SMTP settings in Jamf Pro, I can send a test message and I DO receive that but just not any of the membership change emails that I want to. Is this a known issue or is there something I am missing? Any and all help will be appreciated.
We have a few iMacs running Sequoia 15.5 and Jamf Connect that are going to black screens after you log in. Both local user accounts and IdP accounts are affected, but I can see the user folder is being created when we log in against our IdP, I get the account creation message but it just hangs on the black screen. Local admin account is having the same problem. I’ve tried uninstalling, restarting, and reinstalling Jamf Connect, but the problem persists. Uninstalling and logging in as a local admin user causes a beach ball to spin, but it sits there and doesn’t not progress. I’ve checked the config profiles and license and they’re all valid, and this isn’t happening fleet wide, just randomly.if I create a new user through Jamf, the user will create, but I can’t log into that account, it immediately dumps me back to the JC login window without any feedback. I can see the new user’s account by running dscl . -list /Users UniqueID but it still hangs. Resetting authchanger doesn’t help eit
Hi everyone, I. HATE. PRINTERS. That being said, we have to work with them. and... Canon does not make it easy. Here is what I was able to find out from several places online, in order to get this "installer" to actually work. So let's jump on to our Macs and get this over with.Downloading the "Installer"1. Log into your Uniflow Online (web)2. Start Printing (Side Bar)3. Install Printer Driver > Click [Download macOS printer driver] Navigate to Download FolderOpen SmartClientMac.iso > Open SmartClientMac Volume > Notice here you only have 1 file. But actually there are 4. 3 are hidden.On your Keyboard us the show hidden files shortcut: Command+Shift+.(Period)Getting Files in the Right LocationYou will now see 3 other files. We only need the SmartClientForMac.pkg and tenantcfg.plist files.Next, Go to Finder > Go > Go to Folder (Shift+Command+G)Enter 'private/tmp'Next create a new folder called 'uniflowclient'Which is now located in private/tmp/un
I've got an issue with Screen Sharing on to a lab of Macs where the screen is completely black apart from the cursor moving being visable. Using Screen Sharing via Finder or using the Apple Remote Desktop application presents this issue. The only fix I've found so far is to send the "Disable Remote Desktop" command from Computers > Management > Management Commands, force the device to check into Jamf Pro, then send the "Enable Remote Desktop" command to the device. After these steps, the black screen issue is resolved and screen sharing/ARD works as expected. When this issue occurs, I can easily log into Jamf Pro, send the management command to a smart group of my lab Macs, another management command to force them to update inventory, then a third command to force them to re-enable Remote Desktop. Is there any way to automate this process into a policy so an engineer doesn't need to log in and manually run the commands?
I am using the “Mac Apps” to install and maintain a couple of apps. This includes Chrome.I noticed something weird there. For colleague X “Mac Apps” says her Chrome is up2date. But looking at her Macbook and at “Patch Management” she is a whole bunch of Chrome updates behind. Any idea where this comes from?
Hi,i ran into a deadend, where i need your help =) We are currently trying to setup the content cache with parent-child config.A simple ping and netcat are succeeding.I have declared the settings as followed for example:parent: 172.10.10.1child: 20.20.20.1 While reloadSettings it is showing my parent as reloaded. But with “AssetCacheManagerUtil status”i get the output:Parent: (none)i actually cannot get it running.
Hi everyone,We manage approximately 330 student iPads with Jamf School and have used Time Filter-based Safari restriction profiles for a long time.During the semester, we normally restrict Safari from 7:30 PM to 8:00 AM, and this setup had previously worked reliably across almost all student devices.The issue started after our summer break.During the semester, we used our normal Safari restriction profile. When summer break began, we switched to a different Safari restriction profile with the same restriction settings but a different Time Filter schedule.We used that vacation profile for about six weeks, and when the new semester began, we switched back to the original semester Safari restriction profile that had worked reliably before.That is when the problem suddenly started.At first, some grade-level groups were showing only about 4–11% Installed during the active Time Filter window.We are now seeing several different behaviors:Some devices have recent check-ins and successfully ack
After wiping and re-enrolling lab machines, approximately 23 out of 29 are showing the native macOS username/password login window instead of the Jamf Connect Login OAuth window. The remaining 6 machines show the correct College branded Jamf Connect login screen. What I've confirmed on the broken machines:JamfConnectLogin.bundle is present in /Library/Security/SecurityAgentPlugins/ Jamf Connect Login is fully registered in the authorization database (security authorizationdb read system.login.console shows all JamfConnectLogin entries) Jamf Connect Login v3.10 and Jamf Connect v3.10 configuration profiles are both installed A StagedPlugins folder appears in /Library/Security/SecurityAgentPlugins/ after every restart but is always empty No autologin configured A conflicting LAB: Login Window Settings profile (com.apple.loginwindow payload) was previously scoped to these machines and has since been removed but this did not resolve the issueHas anyone experienced Jamf Connect Login silent
Hello all, We have been having huge issues with the standard account; cannot update software(Chrome), cannot add personal network printers, cannot add WiFi, etc. So it was the consensus to promote the standard account to an Admin account. I am hoping there is an script to perform this very act, because updating 900+ devices is a little daunting. I see there is a script to demote and we have it in the wings for deployment should this entire Admin rights thing go South. I am no scripter, but know enough to follow through what will happen when things are run. So any and all help is appreciated.
So It seems Apple has removed some MDM control of macOS updates in macOS 27 and they are only allowing using DDM commands to do this.Wanting to know if the Defer Major macOS updates MDM profile setting will work in macOS 27 or is this gone too? (I would assume that deferring upgrading to 27 will still work since older versions of the OS still support MDM update control. This is more about the future) I see with Jamf 11.29 that the download & schedule install is now DDM and works on prem but what we are really looking for is a way to continue Defer Major macOS updates for 90 days. We are not in Jamf cloud and not really looking to move.
Hi everyone!We recently ran into an issue with our push certificate renewal on our Jamf Pro instance that I wanted to share, along with the workaround we found — in case it helps someone in the same situation.The problem:We had renewed our push certificate several times using different Apple accounts instead of the one originally used. This caused the Topic ID in Jamf Pro to no longer match, which broke our ability to send commands to our devices.It took us a while to notice, and by the time we did, MDM had expired on a large number of our Macs since no commands were getting through anymore.To make matters worse, we had disabled the ability to manually remove the MDM profile on the machines, so we ended up with a fleet of Macs stuck with an outdated/expired MDM profile that we couldn't remove or replace.We contacted Jamf support, and the only official solution was to recover the correct Topic ID by renewing the original certificate — but that wasn't possible for us since we no longer h
We are currently in the process of implementing Jamf Pro in our company environment. So far, we have successfully integrated several scripts, SMB shares, and other configurations, and everything was running smoothly.As the next step, we attempted to set up Jamf Connect in order to integrate a SAML authentication flow via our Entra environment. The goal was to allow users to log in with their Entra credentials during a fresh macOS installation.However, after configuring Jamf Connect, we started encountering a critical issue. The Microsoft 365 login window appears as expected, but after a few seconds, the entire Mac screen goes black and becomes completely unresponsive. The only way to recover from this state is by manually restarting the device.Additionally, since this issue started occurring, our previously working scripts and configurations are no longer functioning as expected.Has anyone experienced a similar issue or has any suggestions on how to troubleshoot or resolve this problem
Hi Nation,Product Office Hours #2 - Jamf @ Jamf Perspectives on AI Governance Next session: Thursday, 20th August - 9am CDT / 3pm BST / 4pm CESTSpeakers: Sam Johnson and Emily Kausalik (@dr_k)Register here: https://jamf.it/ProductOfficeHours 🧵 Got a question? Drop it in the comments below ahead of time if you want it on our radar, though you don't have to. We'll be taking questions live on the call! Anything we don't get to, we'll follow up right here within 24 hours.See you Thursday 20th!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!