Get Support
Recently active
Hi! I've been asked to create a configuration/policy/etc that allows full access to the Mac, but also deletes all stored files upon logout and becomes a fresh OS install. Guest Mode only allows access to safari, which is insufficient for our needs. I've been looking around online for a while but perhaps I just don't know the correct search terminology. Anyone created a policy like this before that creates an account on the Mac that wipes itself of stored files and cookies etc when you log out of it?
The last two versions of Cisco Secure have had caused a weird issue in our environment. On random machines, we're getting a popup message (that locks up Finder until acknowledged) with the text "The VPN client agent was unable to create the interprocess communications depot" every 30 seconds. Looking around online, we found this was caused by Internet Connection Sharing (ICS) being enabled. Thing is, we don't enable ICS, and the machines we're seeing it on don't have ICS enabled. My first thought was our installer was bad, but we're just doing the standard choices.xml for the install and applying their provided temp workaround for the macOS 14.2+ launchagent issue. /usr/sbin/installer -pkg ./Cisco\\ Secure\\ Client.pkg -target / -applyChoiceChangesXML ./Cisco-Secure_choices.xml# Temp fix for macOS 14.2 and 5.1.0.136if [[ "$( sw_vers -productVersion | awk -F '.' '{print $1}' )" == "14" ]] && \\[[ $( sw_vers -productVersion | awk -F '.' '{print $2}' ) -ge 2 ]] && \\
We are attempting to implement the Australian Government’s ISM controls and we are required to satisfy these:1171 Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters.649 Files imported or exported via gateways or CDSs are filtered for allowed file types.Can jamf do either of these? If so, please point me to a page/link that explains how.
Hi All,I'm still gaining my footing as a person in the security sector while trying to manage Macs in our environment with Jamf Pro. We have protection software such as CrowdStrike and Rapid 7. I tried searching through the community, but I'm not finding clear examples of what I'm looking for, yet. Is there a way to prevent administrators of Macs from tampering with software like CrowdStrike and Rapid 7? Specifically, after the programs are installed I want to prevent them from being able to disable it. I thought something like a configuration profile would do the trick, but I'm not quite seeing what I'm looking for as I go through them. I would appreciate someone pointing me in a potential direction to look.
Hello does anyone have a terminal command or script that we can use in Jamf to uninstall the canon uniflow app from users mac devices?
Hello, we have multiple Admin accounts on the macs. I would like to know how to rotate admin passwords using LAPS? Is that possible?
Hi What is the simplest and easy way of getting Office 2016 updates pushed to my environment without the end user having to seek an admin to put in their creds. Ideally we just want it to check the device and if it finds an update, then for it to do it in silent mode. Probably been asked plenty of times but would like to see peoples experiences on this.
from the JAMF Pro web interface I'm uploading the recent version of the Big Sur 11.5.2 install assistant.pkg and when it reaches the end of the 'uploading' progress bar 100% it just sits there. The cancel and save buttons still showing just like i havent uploaded it yet.Other pkgs I upload reaches the same 'uploading' progress bar 100% and the screen refreshes and you know that the pkg was uploaded and it will be available to use soon. the 11.5.2 pkg is like 12GB but i had no problems with the 11.5.0 Big Sur install assistant.pkg uploading successfully.I've had this uploading issue with versions 11.5.1 and now 11.5.2anyone have a clue as to what is happening and why? any other pkgs i upload have no issues completing (but those pkgs are not nearly this size).
Hi JAMF Nation,Did anybody here find a fix for the Microsoft 365 problem with JAMF? I tried all the possible combinations, but without turning off security defaults, it just does not work well. How did you guys go about it?I also tried using AWS SES but to no avail, practically a wall at this point.
Any hints on troubleshooting a policy that is configured to run at login but appears not to?The policy is set to run a script that simply populates the User and Location > Full Name field, and works perfectly well when running jamf policy but the value is never populated when a user logs in.The policy is set to trigger on Login and Settings > Computer management > Check-in > Create login events > Check for policies triggered by login has been enabled.
How do you do?We have just started testing the roll-out of BYOD and have discovered that the profile for personal devices has an .html extension.This means that we cannot install it.We have the problem on different iOS devices with different browsers.
Am I right in believing I have to change the setting for "autoDeployEnabled" to true before I will be able to see the password of a local admin? At the moment if doesn't appear to do anything even though it will pop-up a message saying viewing the password will cause the password to rotate in 1 hour.Currently just looking to see what/how this feature actually does.
Hi I am unable to login to my JAMF school account as it wont accept my verification code. How do i turn this off
Hi All,Anyone Send the script for Tailsman Installation in Default path /users/user_name/.tailsman/bin
Hello, Jamf Nation! I’m excited to share a project that I believe could bring significant value to our community—App Auto-Patch. Designed for macOS application management, this tool leverages the power of swiftDialog and Installomator to streamline the application patch management process, ensuring your Macs' applications stay up to date effortlessly. Key Features: Local Application Discovery: Automatically identifies applications installed on Mac computers that require updates. SwiftDialog Integration: Enhances user experience by providing clear, friendly prompts for update deferrals and installations. Flexible Application Management: New variables allow for customized handling of applications in the user's home folder, including conversion and ignoring options. Improved Deferral Window: Offers end-users clarity on pending updates with a resizable deferral window and updated messaging. Webhook Reporting: Enables status reporting to Teams and/or Slack, offering insights into patching
Hi Jamf Nation!I have some questions about what happened in a MacBook after it received the WIPE command, rebooted but without the firmware passcode being authenticated? Could the command be cancelled in any way?We have a MacBook Air (Retina, 13-inch, 2019) with Intel chipset running macOS 14.3. WIPE command issued and it is now stuck at the user login -> reboot to firmware lock loops."Clear Activation Lock" option was chosen when attempting the command, but it says activation lock not found, so the WIPE command was issued without. After the command was sent, the MacBook immediately rebooted into the Firmware lock, which then we realized the passcode is unknown. Attempt to boot or reboot the machine will first goes into the user login page, and ended up at firmware lock after user authentication. We did not reach the steps to enter the 6 digits arbitrary passcode.I read this from the previous post:@talkingmoose wrote:If the computer has been protected with a firmware passcode,
Hello everyone,I've noticed something that I believe many of you might have experienced as well. We've set our devices to automatically update to the latest version through Jamf App Catalog settings for patch management purposes. This is working great! However, the updates for these apps are often made simultaneously, causing all 500 devices to try and get the latest version through our 500Mbps internet connection. This is causing significant bandwidth issues.I understand that this issue should be managed by shaping the traffic, but unfortunately, my current firewall solution won't do it with great success.So, my question is, is there an option similar to packages where I can store them locally on a file share distribution to alleviate the sudden influx? Additionally, is there an option to spread the updates over a week instead of all at once without doing it manually?
hi,at my organization, we are wanting to downgrade all user accounts from administrator level to standard level per our new security policies. eventually, we will add MakeMeAnAdmin in order for users to temporarily gain access to admin level privileges. what is the best way to downgrade users on a large scale via jamf pro rather than visiting each computer one by one to change them to standard accounts?thanks!
Hi! I decided to test using the Inventory Preload option on to PreStage enrollment of one computer. I got the CSV file completed and uploaded it successfully and it shows up as the Active data. After doing the PreStage enrollment (no previous record of this device), I don't see that it applied the preload data. I did only complete the serial number, department, and building fields in the CSV file since those were all I needed. My question is, does anyone know if certain fields (besides serial number) are required for this to work? Has anyone else had this happen or something to try? Thanks!
When you look at the Devices > Updates page, there is a tab list of various OS flavours that could be updated.There is a filter above this tab view.When you change the tab to a different operating system, the filter is cleared / reset.This is very frustrating. From a UI perspective, a top down hierarchy of dependencies typically works. Items below shouldn't change the state of those things above. This screen breaks this principle. The workflow to change tabs whilst requiring the same filtering parameters is quite common, especially because the variants of an OS are split into different tabs. Right now I can see tabs for 17.3.1, 17.3, 17.2, 17.1.1, 17.1, 17.0.3. I'm looking at filtering for iPads that are 9th gen that belong to a particular group. Every time I click a different variant of 17.x the filter resets. I have to go back to change the filter back to match my query.Really time consuming.Also confusing since it isn't generally possible for devices to update to anythi
I am getting an error message "The operation couldn’t be completed. (com.jamfsoftware.task.errors error 5.)" on the logs of a policy for only one endpoint. All that the policy does is to remove the EFI password. How do i fix that?Is there a way to check through jump maybe that error is caused because the endpoint has no EFI password at all?
Hi,We currently deploy Xink software to our mac users via Jamf. 95% install successfully however we have a few because they've missed the prompt "Jamf" wants to access to control "System Events". Allowing control will provide access to documents and data in "System Events", and to perform actions within the app. When signatures are updated - we get the error: "Not authorized to send Apple events to Microsoft Outlook". An error occured while updating the signature 'Signature 1' in Outlook. Has anyone else come across this and now how to resolve as Xink support has been really poor. TIA.
We're testing out the new update and it's updating AnyConnect just fine and connecting. The only issue I'm having is some of our test users are getting the prompt to allow csc_iseposture to Desktop, Documents, Reminders and Downloads. I created a new config profile for the new agent using.Identifier: csc_iseposture, BundleID with Code requirements for csc_iseposture. I have the above folder selected and set to allow. I see in our old Anyconnect profile, it has the same including policyallfiles. I did try adding policyallfiles, but still got one prompt to allow for desktop.
We recently updated to iOS 17.3 on our iPads, which required us to re-sign in to the students' Apple IDs. During the sign-in process, some of them encountered verification failures. In the past, we would resolve this issue by deleting the account in Apple School Manager, and overnight, the account would be recreated. However, recently, this method has not been effective. Currently, we have 5 students without Apple IDs. We contacted Apple about this issue and was told this was a problem with JamF.
Reposting this from my personal website to gain some visibility. UPDATE 1: I'm being told now that this change IS RETROACTIVE. Meaning your dozens/hundreds/thousands of endpoints that have been configured with Prestage enrollment, and an admin account created in that process, will have that password randomized. Which will break Secure Token/Volume Ownership/etc. Maybe you're okay with this, but if you're not, you NEED to reach out to your Jamf Representative and tell them. I wanted to bring up that a big change is coming to Jamf soon and they (Jamf) seem to think it’ll be well received all around: forced LAPS for Prestage (ADE/DEP) admin accounts (See bullet 2 here, https://learn.jamf.com/bundle/jamf-pro-release-notes-current/page/Deprecations_and_Removals.html, “Functionality to specify the local administrator account for computers in a PreStage enrollment”). And to start with, I applaud Jamf for working on a LAPS solution. All we've ever asked in this whole
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!