Get Support
Recently active
I was looking everywhere for this info so hopefully this will help some of you too: With the new v70 of Firefox, DNS over HTTPS is turned on by default. Our Network and InfoSec dept do NOT like that and asked us to disable and block this. After some research I have found that a policies.json file with the following text will disable and grey out the DoH setting in Firefox. { "policies": { "DNSOverHTTPS": { "Enabled": false, "Locked": true } } } Tested in ESR and normal FF, v 68 and up. This file has to be in Applications/Firefox.app/Contents/Resources/distribution to work and it is global not user based, which is a good thing. The distribution folder is not there so you will have to make it and add the json file It does require a restart to FF after the push There are a number of ways to deploy this: use a script to mkdir and write the file, create an ongoing policy to deliver the file from a dmg with smart group or Extension Attribute to scope,
Hello All, In my company's workday portal, normaly Windows device doesnt ask company's user name and password if user visit the workday from company's LAN, but in case of mac device it is asking username and password every time user visit the workday portal, and it is for all browsers,(GC,Edge, Safari), what might be the cause or what is the resolution?I already check the to turn on the autofill password feature and also pushed a confog profile to turn on SSO/bypass credential for workday URL but still no luck, any idea will be appreciated.
I want to create some device provisioning videos. Back in the day we could use VMware fusion to create a blank OS and go into the settings file and add the model and serial number.From my understanding you can't do that with the M series devices, which is fine, I have an Intel machine here to use., but I realize that those days are numbered.Has anybody found a new method or way to do record the whole process?
Hi Mac Experts,I have an end user who started the Sonoma upgrade and powered their laptop off during the upgrade process. When they powered it back on, it finished the upgrade, but they can't login with their main account. My tech team was able to login with our admin account. I also was able to create a new account for them on the computer, which works fine. I know I can just migrate their data over from the corrupt account to the new one, but I really want to fix the old one. So here is what happens:They boot their laptop.At the login screen they enter their original username and passwordIt starts loading their profile and they see the new Sonoma desktop background.Then it gets stuck, nothing else loads, you can't control the computer with either your keyboard or mouse. Their only option is to power cycle the machine and log in as another user.So from a MacOS technical prospective, what items are necessary for a profile to work correctly? What parameters, plists, etc
Hi,After upgrading a suite of iMacs from Big Sur to Sonoma, the dock now has ? instead of applications. They do not work when clicked on.I have read some posts on here but nothing has helped me understand where the problem is.To be upfront I am new to Jamf Pro and this system was already setup before I looked at it.I have gone to Settings, Computer management, Dock items. In there are entries for the dock items. Each one is currently in the same format and here is Google Chrome as an example:file://localhost/Applications/Google%20Chrome.app/ Is this entry correct? Is there something else that controls that Dock that I am missing? Adam
Hi all,I have a question about using both JSS and MS Intune together with Apple Classroom. The (student) iPads will be managed with JSS and the (teacher) MacBooks will be managed with Intune. Will it still be possible to use Classroom? Thanks in advance!J
We currently have a Chrome extension, which is force installed on all Devices. We also have a website, which all employees use daily, but unfortunately, that extensions gives annoying pop ups on that site, which are not needed. Question is, is it possible to disable that Chrome Extension, just for that 1 website, but have it working for all other sites? Thanks in advance.
We're in the process of getting ready to roll out OneDrive, so I've been tasked with creating a plist for Mac. Trying to limit the prompts that come up. I thought I had the plist setup correctly. 1. Prevent the logon screen from coming up an auto logon? It's populated with the email address and I then have to enter password. Trying to match it like our Windows side. 2. I have a default folder path, but still getting prompted to choose and I can change location other then onedrive. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>DisablePersonalSync</key> <true/> <key>DisableTutorial</key> <true/> <key>DefaultFolderLocation</key> <array> <dict> <key>TenantID</key> <string>tenantID</string>
We already have a database that controls what to do with damaged iPads.However it would be cool if that database could, through api calls, create an incident in the jamf school for that serialnumber.however, strange enough, incidents are not part of the API. I am sure im not the only one, using incidents and some outside JAMF School tool to manage these incidents
Hi Everyone, kindly raise your hand who willing to make one to one conversation to share knowledge of Jamf Pro from you. If you guys interested kindly reach me through yogeshnk92@gmail.com
Hello,I have 2 ADE Server integrated in my Jamf Prof.Is it possible to group these devices into smart groups based on their ADE server or on the PreStage profile that the devices have used? I already use the different ADE servers in the PreStage profiles.
Hello.We use Google Drive for Desktop to backup users folders on Macbooks.I'm looking for a way to automatically deploy this configuration on all workstations.Today we do the operation by hand and I want to avoid human error.Do you have a solution or an idea for this?Thank you!
Hello,Wondering if anyone else has seen this before and looking for some guidance. I am experiencing an issue with Privacy Preference Policy Control (PPPC) Configuration Profiles in our Jamf Pro environment. Any time I create a new PPPC profile, paste in the code requirement, and hit save, I notice the pasted text only shows the 'identifier' component of what I pasted.For example, here is what I paste-in for Microsoft Teams:But after clicking save, I only see this:Variations of this same issue apply to other PPPC profiles as well. Here is an example of what I paste-in with Pulse Secure VPN:Versus what I see after clicking save:I am curious if this is intended behavior and if anyone else experiences this in their environment. Another strange issue that is potentially related; if I make any change to the PPPC profile, (including modifying the Macs the profile is scoped to) the profile will fail to deploy until I manually re-paste the code requirement in its entirety. Once re-pasted,
We have an application, Coginiti Pro, that requires a user to have elevated rights before installing on the Mac, or else the install doesn't work correctly.We use Jamf Pro, and currently I've added some text to the Self-Service installation page telling users they need to elevate their rights before running the install. We use the Privileges app for temporary rights elevation.I was wondering if I could script this. The current Coginiti Pro install we use is a script rather than a PKG. I'd like to add some code to the script that says "check if the current user is running as a standard user". If so, I'd display a message reminding the user to elevate their rights before proceeding.Is something like that possible?
We are doing some testing on the office 2019 update issue and we setup a test policy to fix this. We are trying the startup trigger policy as that will confirm all office apps are closed but are seeing sometimes this policy never executes (says pending in the policy) even after multiple reboots. Is the startup trigger not reliable?
Am I able to stage a .sh file on my user's computers?This script contains a sudo command but I want to be able to run from the user's account. This will be a break glass script to fix the stupid Sonoma Time/Date bug. What file permissions would I need to assign as well?
Hi All,Does anyone know why the Management Command tab (See the attached image -02) is missing from some iMacs on the JAMF? Imac is communicating to the JMAF server but I can not push any software or any commands.Help will be much appreciated
Hi All,I'm trying to install the app using a Self-service on iMac. I can see the app on the Self-service portal but When I click on the install button I get the error Cannot reach a JAMF MDM serverWhen I check the device on the JAMF server it communicates with the server This is the error that I get When I click on the install button Help will be much appreciated
We have a pool of machines that are in a remote site. Had users sitting at the desks with their computers, this week they have moved to a different building and are now remoting in. A few of the users have developed the habit of shutting down their machines when they are done for the day. First day in the new office, and they shut off their machines on the way out. Neat! I see there's a setting in the Configuration Packages > Finder > Commands tab that should disable shutdowns from the Finder dropdown menu, but it doesn't appear to do anything. And I'm also looking through many forum posts dated back to 2016, from other people encountering the same thing. We have this command that we have successfully to disable sleep: Run Unix command 'defaults write /Library/Preferences/SystemConfiguration/com.apple.PowerManagement SystemPowerSettings -dict SleepDisabled -bool YES' We have tried the following command to disable Shutdowns, but it i
I have an iPad in Lost mode. I am unable to connect the device to our WiFi to get it out of Lost mode. Please help.
Hi, I know there are some similar posts notably this one here: https://community.jamf.com/t5/jamf-pro/popup-user-notification/m-p/235439/thread-id/223319 but I'm relatively new to jamf pro and just looking for a bit of similar more tailored advice. I want to be able to set up a 'notice for a new user' policy that pops up only once on a Mac for the first time a user logs in, which has an accept button that the user must click for it to disappear.(a bit similar to accept terms and conditions before downloading a new program I guess). If the user does not click accept, then the policy stays on screen/ keeps being presented until accepted. Is it possible to do something like this, maybe using some of the ideas presented in this thread above? I'm up to Jamf 200 but not had much experience with creating policies or with scripting yet, but I'm fairly confident I could hopefully follow along some tips or any advice given here, thanks.
I have a few examples now and can confirm, "in my environment", Mac OS Sonoma is causing authentication issues in my offices over Wi-Fi. I have my networking team assisting me trying to find the solution. Most of my Mac environment is on Monterey, Catalina, with a few new devices running Sonoma. All Sonoma devices are not receiving an internal ip and forcing them to a 192.168 external IP. We do have a network access control system in place - ClearPass - we are using this to block external devices on the network. ClearPass provides complete visibility into users, devices, and applications across the entire network. This allows for the creation of detailed access policies that provide granular control over which users have access to which devices and applications. Does anyone know if Sonoma OS causes changes to the network settings, configuration, authentication, etc. on the device? I had a device that was profiled in clearpass running Monterey and the mome
I'm trying to establish the last time a user actually logged in to their laptop. I have, therefore, created a Computer Extension that runs a simple script that is supposed to display a String result in User and Location:#!/bin/zsh/usr/bin/last -1 -t console | <result>/usr/bin/awk '{print $4, $5, $6}'I added the Computer Extension to the Configuration Profile under ALLOWED EXTENSIONS but nothing ever seems to be displayed. How are Computer Extensions actually meant to work, i.e. how am I meant to actually see the data that is gathered???
Dear all.Is anyone of you aware of a way how to prevent the auto-starting of Teamviewer (and with that, the basic setup assistant) after the installation?I have seen that there are quite a few Launch agents and Launch Daemons included in the installer package, but I don't really know how to manipulate the portions in there to just block the auto start after installation.Any idea? Thanks a million.CheersChris
I'm trying to deploy FortiClient 7.0.2, and I have some questions about order of operations and whether this is going to cause trouble on specific OS versions. I still have some more testing to do but it seems to work on the one I tried, but maybe it was a fluke. I can post configs as necessary, but I suspect that they aren't needed for these questions as it's more about how these functions work.I have a script that grabs the file from our server and installs it. That works. I need to get curl to fail out of the script if the download fails, but I haven't looked into it yet so I'm sure I can find a way.Unfortunately though, FortiClient needs users to make tons of changes to System Prefs. Full Disk Access, requests for VPN connections, and request for System Extensions.I used PPPC to grab those Full Disk Access settings from an install and make a config profile.Will it cause a problem if I deploy those before the policy for the install, when the filepaths and apps don't exist yet? It se
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!