Get Support
Recently active
Push certificates are being set up at https://markany2.jamfcloud.com/.When processing using Cloud Services connection, I entered jamf-mdm@markany.co.kr in the Jamf ID Email Address field, but the error "No assets found for this account" is occurring.
Hello Jamf Community! I'm making an extension attribute that basically tracks if a local user is at the Standard level or Admin level. I've ran the script in 2 test macs in our environment where one Mac is a Standard account and the other is an Admin account. For whatever reason, the extension attribute will always resort to "Admin" as the result. I've tried several things to trouble shoot this. Here's what I've done. Originally the elif statement was an else statement I've switched the if statements where it would be != 'Yes', is_admin would be No. and vice versa. I've ensured these script worked by running the script in terminal for both test macs, and they should work. Not too sure what is going on and I'm thinking it's just my jamf environment now. Does anybody have suggestions on what might be going on? #!/bin/bash result='' # Get the current logged-in user current_user=$(whoami) # Check if the current user is an admin is_admin=$(d
We've just encountered an issue where end users are able to delete Self Service from our fully managed iPhones and iPads, despite the option to do this being disabled in the Jamf Pro console. Has anyone else experienced this?
Our MDM profile is current and in date, however we seem to be having issues on enrolment of devices that are being enrolled manually by end users who are not local. Has anyone seen this message before? Checked all local JAMF Pro credentials associated with our JAMF pro instance and nothing jumps out or seems obvious.We incorporate ABM, however some devices we have are purchased outside of Apple and ABM this is one of those any thoughts would be welcome. Thanks
Hi, We have been asked to look at the possibility of supporting Mac Bring Your Own Devices. Phones are easy enough, but how are people supporting Mac Bring Your Own Device? Most users will have admin rights on their own account. What stops them installing software, changing setting when it is a Bring Your Own Device on our network? Best wishes Michael
Blackground :We deal with lots of designers and video editors at my company and they can't do a proper white balance with True Tone. As far as I know, there is no MDM key to manage this setting. Solution :I created an Apple Script (embedded in a bash script) that will open and automatically click the right menus in order to turn off True Tone and Auto Brightness. It only works with an English UI but you'll find a French version on my website. It was written for macOS Monterey and Ventura. Scripts : disable_truetone_english.shBlog post : https://clementine.la/scripts/desactiver-true-tone-par-script/ #!/bin/bash ### # # Author : https://clementine.la # Created : 2022-09-09 # Last Modified : 2022-10-24 # Version : 2.0 # Tested with : macOS 12.6 / macOS 13.0 # ### # Read logged in user loggedInUser=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print
I've configured Jamf Connect on my test machine following the Jamf documentation. However, during the login process, I'm not encountering the IDP login page to input the Azure Credentials.
Hi Team,How do i disable Firefox's diable HTTP/3 (network.http.http3.enabled). I have to create a configuration profile and push it via JAMF to all of the end users. Can someone give me an XML template for this? i couldn't find it anywhere
I'm in the process of trying to make our 3rd party updates easier in our QA environment. We currently have 12 smart groups setup for 12 apps. It's set to Patch Reporting - Less Than and the version we're deploying, and that group is set to the scope in the policy. We have 3 test groups we use, alpha, beta and uat. For each deployment date, we have to add to go in to each smart group and adjust it to add the group and then on the prod deployment, we remove all the test groups. I created a smart group that as all 3 test groups and labeled it deployment users, just set the operator to member of for the group I want to deploy to. I then created another group and added the criteria to member of the deployment users and then added the 12 packages below it. I set that as the scope for each policy, but when doing that, it shows my test mac pending for all the apps, but none are installed except Firefox which I'm testing with. I'm not sure what I'm doing wrong, but I would think it work. Just t
We're moving off this to Jamf Connect, however I have continue binding for at least the next quarter. The device must exist in AD - part of the requirement to get past ISE on the internal wired & wireless network. The org runs a hybrid setup with on-prem AD syncing to Azure. Can't bind in prestage because it can't reach the controllers since the computer is off-net. We have situations where the bind policy fails on the first runs - because the device hasn't yet connected to the VPN. Once per computer with rerun on failure. Configuration profile throws errors because it can't bind with the system off-net. I'm over thinking this and can't find a way to effectively bind a new out of box system. I appreciate any input.
Hello!My company is going through the early stages of a merger and we're looking at bringing the other company's Macs into our Jamf environment. This is a little premature since we haven't yet combined our LDAP or ABM but the powers that be are requesting it. I wanted to see if anyone has had any experience with having a second LDAP provider and ABM account connected to their environment or if what we're looking to do is not possible.
Hello everyonelooks like Jamf Pro iOS pre-stage didn't have the option to skip the appearance during the automated enrollment. Does any have this issue?
A couple of things are no longer working correctly during enrollment via DEP. My prestage enrollment is set to skip everything except for Location Services. I then have a policy triggered by Enrollment Complete to run a script prompting to enter a computer name. This usually pops up while sitting at the Location Services setup. It then goes ahead and creates the local admin account and kicks off another policy to bind to AD.With Ventura, my script to prompt for a computer name fails with "Logged in user is not _mbsetupuser" Has the setup assistant changed to use a different account?My other problem is that it doesnt sit and wait at the Location Services screen. It gets skipped and Location Services doesnt get turned on.Everything else, as far as I can tell, seems to be working. It gets enrolled, created the local admin account and binds to AD. I've searched Jamf Nation as well as other sites but couldnt find anything about _mbsetupuser being deprecated but I did come across
Hi Everyone, I have written a script to download the Mac OS update in background but its suck on admin password and followed by the user interaction to save all file and click on restart button to install the update. but somehow script works till popup message display. below is the script to update update os #!/bin/bash loggedInUser=$(stat -f%Su /dev/console)jamfHelper="/Library/Application Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper"windowType="hud"description="There is a critical security update available for your Company issued computer. To perform the update, Click on 'UPDATE' below and the security update will begin to run. This update can take upwards of 45 minutes. NOTE: Before clicking on 'UPDATE', save all working documents and Connected the Charger. If you require assistance, please contact ********** on Slack or by email at." button1="MacOS update"icon="/Library/Application Support/JAMF/logs/********
It has been many years since I used Jamf and I am trying to determine the capabilities of Jamf Now. Can Jamf Now be used to deploy Sentinel One agents?
One of our users complained that his machine is running slow after Jamf enrollment. "Hi there,Might just be a coincidence, but the performance of my Mac has massively slowed down and become very laggy since the Jamf install. During a call earlier my laptop just restarted." Unfortunately this is not the 1st person to complain about that. The specs are : MacBook Pro (14-inch, 2021)Processor Type: Apple M1 ProNumber of Processors: 1Total Number of Cores: 10Apple Silicon: YesArchitecture Type:arm64Operating System Version: 12.1.0Operating System Build: 21C52 As admin are there any troubleshooting steps I could follow and check what is wrong with his machine ? I want to stress that this user hasn't complained at all before the enrolment.
Hello,We have some document cameras that we issue to our users. There is a software that is recommended for the document camera here https://www.inswan.com/en/downloadWhat would be the best way to push this software to users laptop? Creating a PKG and adding it to a policy? What would be the steps to do this?Thanks
Alright so I am trying to set up Dropbox for a board meeting on a bunch of iPads, I am wondering if there is some sort of configuration that I could use to automatically have them sign in? Each device will be using the same account and it would be nice if I could skip the part of physically signing in to each device! Any suggestions!?
has anyone seen this error when configuring the google cloud ldap integration"Cannot verify cloud identify provider domain name"My keystone is showing as accepted and populated but I cannot save the config due to this error. Using LDAPS as the connection type.
Hi, Is anybody having an issue with prestage enrolments not syncing for the last 4 days. Our devices can be added to the prestage but do not enrol when the device is turned on and connected to the wireless. Our DEP program is working, and devices are showing in Jamf. Any ideas? ThanksSimon
Hi,We use EntraID for single sign on purposes are my organization. We use JAMF connect to serve our SSO login screen to users when logging into their Macs, and we also use passthrough authentication to streamline the process a bit. In our JAMF Connect config profile, we have OIDCPassthroughAuth set to true and OIDCNewPassword set to false, as per the passthrough auth instructions for EntraID. Here's the issue: we have a password rotation policy in our organization. When the a user's org password rotates, the SSO password they use no longer matches the local account password on their mac, and after the SSO challenge they will have an "incorrect password" error when signing in. Is there a way to make it so that when their organization password rotates, it updates their local account password on their mac? Thank you.
Hello Team,MS Teams is consuming high CPU utilization and mac is becoming very slow.Second one is, some times audio is not working in Teams call any solution will be appreacied.I can see MS is pushing new teams and it is causing issue, so please give me the solution for new Teams.
I forget the origins of this, but posting since it's extremely useful...You can do an Advanced Computer Search on Applications to list all of the different versions of an application installed on managed Macs, but as of this writing there is no mechanism to export that report.You can do an Advanced Computer Search on Computers with Application Title and Application Version criteria, but that just selects the computers that match the criteria and doesn't list the version numbers in the report.Here's the ProTip...If you create a Smart Computer Group with an Application Title criteria and Operator "is" clicking View will show you a report of all Macs with that application, but notice there is no version information displayed. However, if you click Export (it doesn't matter if you select Comma-Seperated Values or XML) the exported report includes an Application Version field.
Everything I'm reading states we should be able to deploy the anyconnect package with only the Umbrella and Dart portions. We don't need the VPN (if this is needed we can still deploy it) or any of the other pieces. But the xml I am trying to deploy keeps failing. I am also using a script. Any assistance would be appreciated.Choices XML:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><array><dict><key>childItems</key><array><dict><key>childItems</key><array/><key>choiceDescription</key><string>Installs the module that enables VPN capabilities.</string><key>choiceIdentifier</key><string>choice_anyconnect_vpn</string><key>choiceIsEnabled</key><false/><key>choiceIsSelected</key><integer>1</integer><key>choiceIsVi
What is everyone's thoughts on using Jamf's Mac Apps for patching Office apps vs Microsoft Auto Update (MAU)? I know MAU gives you more channel options, but I see a fair number of machines that aren't up to date using MAU and I have to assume it's because they aren't quitting out of the apps that need to be updated so MAU can do the update. Mac apps on the other hand seems to only give you one version to patch for (The most current), so I'm trying to get a grip on best practices for patching. Any help is appreciated!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!