Get Support
Recently active
I am posting yet another trying to pass the CIS audit message! This time I have and issue with Jamf Pro and the plist processing. It took me some time to figure out, but the CIS PDF "CIS Apple macOS 12.0Monterey Benchmark" v3.0.0 makes for some hilarious reading on this and the other Safari controls. The main issue seems to be that my profile is quoting special characters in the keys, but the checks aren't expecting them. I used the Jamf Pro console to edit a plist scoped to com.apple.Safari and verified the settings are applied using System Preferences and the Safari UI. Still couldn't get all of the checks to pass, but then I realized all the checks that were failing used keys with a "." in them, which get quoted for some reason on the end-user mac and break the CIS regex match. Here is the content of my "Upload" text box for the Jamf Pro profile:<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyLis
I've fought to get off binding and I can do so next year with Jamf Connect.. In the meantime - do you bind using a Configuration Profile - or policy with the directory binding option? Which is better? Doing a profile now and it continues to fail on about half the fleet. We use machine based certificates so I'm hesitant to change anything - but for those still stuck with this - do you via a policy?
I found some iPad’s used in our department that are in Apple School Manager but in Jamf they are unmanaged but supervised. I need to wipe them out so we can use them elsewhere, but they are locked with a pin # and the PIN I was given does not work. If I reset them via DFU they will not reset, it will go through the process but never do anything, when it reboots it goes back to the lock screen. Is there anything I can do as far as wiping them or will I need to contact Apple? I read that Apple will not mess with devices that are in MDM, while the devices are supervised by our MDM they are not enrolled, will Apple consider that as enrolled?
My ADE configuration installs Jamf Connect in the pre-stage enrolment, so that when the setup wizard is exited the user is presented with the JC login screen, and can sign in through IdP.Jamf Connect creates the account, as there's no account creation done during the ADE setup. This works fine with JC v2.28, however when recently trying to enable the auto-update of JC, and installing v2.31 (and again since then v2.32) the same configuration no long works, and an account is not created.The JC screen will accept credentials, prompt for MFA, and then loop back around to the login screen. Using PingFederate as the IdP, and therefore OIDC connection within the JC setup. Anyone had a similar issue? How did you resolve it?I can't see anything on the release notes for known issues, or resolved issues in previous versions that might point towards the root cause.I do have a case open with Jamf Support for this, but also wondered if the community might have some first hand experien
I have noticed that ever since our JamfCloud instance was upgraded to 11.1, scrolling in Jamf Pro frames using 2-finger scrolling or a scroll wheel on a mouse rarely works. It seems to happen at random in some pages, but the one place I can replicate it 100% is Computer record > History > Policy Logs. I can NEVER scroll down the frame in the page using 2-finger scrolling or a scroll wheel. I have to either manually drag the thumb up and down or I have to use my arrow keys. I use Safari exclusively, so I don't know if it happens in other browsers. This seems to be too specific to be a system issue. Scrolling works everywhere else in my browser and the OS. Has anyone else noticed this too?
Hello All!Our Management Team is wanting to align our Mac Update process with our Windows Update process. For Windows we use Intune Update rings to check for updates on the devices once a month, download the updates and then give the user's 3 days to install them before forcing a restart. The users get prompted daily to either Restart Now, Schedule a Time, or Remind Me later. I understand that we may not be able to do the exact same process using Jamf on a Mac but what would be the closest option to that? We have intel and Apple silicon macs. I am in charge of Jamf but I am not a Jamf or a Mac expert. I'm a Windows/Intune/SCCM admin who was instructed to take over the Mac support as well so I'm having a tough time figuring this out.
When you create real-world school setups you are encouraged to separate out Profiles with specific payloads. So you can end up with lots of small / atomic Profiles. One of the big management challenges is "which payload is store where?"One of the ideas I had a while ago (before Jamf Nation was taking feature requests) was to have the payload icon visible at the top level of the profiles so you could see which payload was defined in which profile.Just had another idea, that is probably simpler to implement programmatically and that is to include in Profile search field a way to find by payload name. Type in "cert" in the search field and you see the profiles that have the name "cert" but also show (perhaps in a different section) the ones that have payload names matching.Propagating the icons would be helpful.This would be super useful for when you are taking over the management of another site. Others do things differently and it is difficult to find subtle payload configs in plac
We're in the middle of a large upgrade to Big Sur and we're discovering the Dymo Label Software no longer works on Big Sur, and the app to use instead is Dymo Label Connect. The new Connect app isn't great, and the biggest problem for us will be that it no longer can use a local address book, which means our users will lose years of contacts they've been building in the Dymo Label Software app. We have hundreds of Dymo Twin Turbo 450 printers, so this is a big headache...Does anyone else use Dymo Labelwriters and deploy the Connect app through Jamf Pro? The Connect app doesn't seem like a straightforward deployment, and it looks like I'll have to account for its helper tool and permissions needed, so any advice there would be appreciated. Like I mentioned above, even after I have it deployed, the new Dymo Connect app is a huge problem for us, mostly because of how it handles contacts/saved addresses. Maybe there is a better option than the Dymo Connect app for printing labels with Dymo
Hello,Over the past few weeks, I've noticed the following behavior on several computers:approximately every 1-2 minutes, the screen of their computer goes black for 1 second and then the display comes back.This started when I deployed the Jamf PaperCut Print Deploy Client on the computers. Having a machine with the problem on hand, I scanned the system logs and every time the screen went black, I had this in the logs:jamfRemoteAssist[15726] triggered unnest of range 0x7ff85c600000->0x7ff85c800000 of DYLD shared region in VM map 0xc3e4dd3aacf1a315. While not abnormal for debuggers, this increases system memory footprint until the target exits.system.log However, Jamf Remote Assist was activated at the end of November and the problem appeared in mid-December (PaperCut deployment). I then deactivated Jamf Remote Assist (Settings -> Computer Management -> Security). 15 minutes later, the machine took note of the change:Checking for policies triggered by "recurring check-
A really frustrating feature of this table is the use of "Keep Existing Owner".This is a goto table for checking devices. At the same time you need to confirm the owner of the device.Nowhere in this page can you actually see who the existing owner is. You then have to go back to devices to check who is the current owner.Perhaps use a symbol to show that we are keeping the existing, but be redundant and show the current name as well. In the UI / psych world we call this split attention.
Here are the download URLs for the standalone Safari 17.3 update for macOS Ventura and macOS Monterey... Safari 17.3 for macOS Ventura: https://swcdn.apple.com/content/downloads/63/16/052-37298-A_XN59PDU2GI/0rqxiyieo4zwzxxbjo97kd2zgan9ng0274/Safari17.3VenturaAuto.pkg Safari 17.3 for macOS Monterey: https://swcdn.apple.com/content/downloads/36/50/052-38948-A_Q3I2HFP5N7/iwb00hgsqv3gykdzv54gupbx54bt2r3prg/Safari17.3MontereyAuto.pkg
Hi folks, please forgive my lack of knowledge in advance. I am very new to Jamf Pro and have been slowly making my way through the mountain of training but also need to be able to utilize it dailiy, for my current position.In our environment, which I inherited, We have exactly 5 items available in self service. 2 of which I created, 2 that relate to existing packages and 1 that I cannot find in Policies (or anywhere else for that matter.) I've tried to look up possible package locations, as well as the app itself, to no avail. I'm trying to figure out what it does... I'm guessing it's a script of some sort, created by my predecessor, but I'd like to investigate the script, to see what it does, and remove it or update it if necessary. If you're wondering, yes, I've run it. It did not give an error message or any other type of message. It seemed to run through it's process and stop. My question is: How to I locate the package?&nbs
Hi everyone, i can for the life of me work out how to efficiently deploy updates to my devices. I have been testing with Sonoma 14.0 as a baseline and JAMF 11.2 in the lab.What i want to achieve is deploy an update and allow the end user to defer it by a number of days. I have tested deploying an update and installing immediately and it works. In JAMF, Computers > Software Updates > i can target a group with the option : Download, install, and allow deferraland i can specify a number. Apparently these are the deferrals i can allow the user. How do i specify the days i want the user to be able to defer? Do i need a config profile?Is software updates solely from JAMF really achievable ? I think i am wasting my time here. Will Nudge or any other script help with that? I am at my wits end with how updates work on Macs.Any insights would be appreciated.
Hello Guys, I have a rare instance where I have users that Have macs and will be switching back to pc... Long story but The powers the be want this so I have to assist. Anyone know of a simple way to convert the Mac data from outlook back to a windows PST format? I have done other work arounds in the past where I have my exchange admin make the users mailbox very large and just upload the data to exchange then bring it down into a PST on the windows side. but Id rather have a less involved option.
This pop-up started 02/06/23 and has been hit or miss with different users reporting it goes away and some stating it shows up every 30mins. What has changed for this to take place?
Hi folks, is there an overview which variables are available from computers and mobile devices that can be used in scripts?Greetings Frank
I have had users follow the Apple procedures to enable FileVault 2 but on a few the Partition Encryption State still shows not encrypted even though than the users ID is showing as a FileVault 2 Enabled user. Also of note there are no other local accounts on the system. Any thoughts on what might be causing this?
Good morning,I've been having an on-going issue with Apple TVs dropping WiFi on tvOS 17.x.I had a random device that show up on my automated nightly report that wasn't on 16.6, thought it was odd it didn't check in for over 24 hours. I know it's plugged in.Saw the MDM profile expired. Alright, no biggie, it's a Apple TV 4th Gen. USB-C port, reset, go about my day.I created a Smart Group that emails me when Apple TVs have an expiring MDM profile within 30 days.20 devices show up on it. I sent a Renew MDM profile command... errors out. They're on the network, updating inventory. Command won't go through.
This is kinda complicated, but the Mac is not checking in every 15 minutes. In fact, it hasn't checked in since Mid-December, but a few management commands have run. Is there a way to remote force a check in without removing in and running the sudo command? It would seemingly have to be a configuration policy? Since it is only one user, I should be able (if responsive) to remote in and run it the terminal, but if the user isn't responsive, I still want it to check in since there have been updates that need to be installed.
Hello In my network is an AirPrint Printer from an UniFlow Server (on-prem, not cloud).When i'm installing this AirPrint Printer manually, the finishing settings are completely wrong.But anyway, at the end i want to install this printer automatically. 1. So then i've configured under "Computer management > Printers" a new Printer. Correct Device URI etc.2. But when the printer is deployed, it takes the "Generic PPD" file. 3. So i copied the PPD file from the manual installed printer & modified it (location: /etc/cups/ppd)4. unchecked the "Use generic PPD file" & uploaded my modified file --> But it still uses the "Generic PPD" file what i'm missing?
Hi All, Is there a script that automatically email us when we reaching certain limit of Jamf Pro license (or jamf connect)?Currently, i checked our Jamf Pro license Usage on a monthly basis - im just wondering if this can be automated.
Is there a way to disable downloading email attachments in Mac . Thanks
Do the 'Start Screen Saver after:' and 'Use Screen Saver Module at Path:' settings still function properly for the 'Login Window' configuration profile (JAMF Pro 10.46) in macOS Ventura? We attempted to apply both a custom screen saver and one of the built-in options but are not seeing any of the desired results.Curious if I'm missing something.
I'm having trouble getting Jamf AD CS connector to work flawlessly, and wondering if anyone else has a similar use case, and if they managed to solve it. Recently procured JamfOn-Prem ADAD CS setup in a different domain, but there is a trust relationship (and it works for other MDMs and bound clients)Using a domain user account, instead of the local user (AdcsProxyAccessUser) created by the .\\deploy.ps1 The domain account has been configured on both the AdcsProxy site configuration, for oneToOneMappings under system.webServer/security/authentication/iisClientCertificateMappingAuthenticationIt's also been modified to be the Identity for the AdcsProxyPool. Certs issue successfully, but only if the same user account is a member of the administrators local group on the server.Jamf Support are saying this shouldn't be the case, but cannot get to the bottom of which permission it needs that's granted by Administrators, that it needs to successfully issue cert
I was looking everywhere for this info so hopefully this will help some of you too: With the new v70 of Firefox, DNS over HTTPS is turned on by default. Our Network and InfoSec dept do NOT like that and asked us to disable and block this. After some research I have found that a policies.json file with the following text will disable and grey out the DoH setting in Firefox. { "policies": { "DNSOverHTTPS": { "Enabled": false, "Locked": true } } } Tested in ESR and normal FF, v 68 and up. This file has to be in Applications/Firefox.app/Contents/Resources/distribution to work and it is global not user based, which is a good thing. The distribution folder is not there so you will have to make it and add the json file It does require a restart to FF after the push There are a number of ways to deploy this: use a script to mkdir and write the file, create an ongoing policy to deliver the file from a dmg with smart group or Extension Attribute to scope,
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!