Get Support
Recently active
Hey JAMFs!I try to automate the creation of Smart Computer Groups by API (within Powershell) based on the installed Apps criteria.I'm a bit confused as I don't find anything in the API-documentation fpr smart-computer-group with method POST.I already have a filtered list of all required groups with app name, path and name for the group.
We have noticed a strange bug with iPads running iOS 17. We use a content filtering Configuration Profile on all our student iPads to ensure that they are not able to delete their Safari history. The Clear History option within settings is still greyed out as well as the Delete option with in the History tab. However students are able to slide from right to left over their History to delete it now. Has anyone found another way to block deleting Safari history that would also block students from this method?
Hi All,So admittedly I am a little new to Jamf Pro, but I have gone through the Jamf Pro 100 course. My question is, I have a few iPads which their MDM certificates had expired, and I had that the only 2 ways to re-enroll them were via web re-enrollment OR having to completely reset and clear all data from the iPads. I tried web re-enrollment and no luck there, so I reset the iPads. And now they have valid MDM certs, so thats good, but now when I try to send management commands, here is my issue -- commands like "enable/disable bluetooth" work just fine, but when I try to send commands like "Update Inventory", it doesn't work. Why do some commands work and others don't reach the iPad?
Hi,Recently our VPP token and ASM token expired, I went through and followed the renewal steps and got this all back to working order, the problem I am having now is that devices dont seem to be communicating back to JAMF.I went through to deploy a free app to a smart group, which on JAMF is showing that the command has sent, but is pending on the device. It even shows that it has taken 2 licenses from the ASM/VPP side of things.Please help.Kind regards
So I recently updated the server token in jamf pro for our ABM instance as it expired on the 1st. Both jamf pro and ABM show that they are sync'ed and communicating with each other, however, in jamf pro, when I go to check our existing prestage enrollments, they are all showing 0 devices available.
Hi GuysI’m looking for a solution for this unusual situation. I’ve spent few hours searching for it but all I found was few posts “how to avoid connecting MDM servers”MacBook Pro 13, M1 2020Ownership is clear, bought new by company where I’m employed. MDM profile was installed on Monterey in 2021. There were no issues after updating to newer versions till Sonoma update.the story in points I’ve asked IT colleagues for letting me to switch off the MDM as it was required by Apple for screen replacementAfter repairing I’ve asked my IT colleague if it’s fine to update the system to Sonoma as it was not possible when the MDM was runningReceived green light, clicked update button.First start, logged in with my credentials (Mac admin) and shortly after connecting the network a full screen enrolment window popped outIt will be fine to go forward but the company details appearing on the screen are completely different as they supposed to be. This is saying that MacBook is owned by another c
Hello,I am trying to determine if there is a way using Jamf for me to restrict particular users to only being able to log into specific machines.Example, a student worker account can only log in on the designated student worker machine.The challenges I see with this are: We use Microsoft Entra with Jamf Connect for authentication and we do not have users with Apple IDs in Jamf.Can this be done?
I am trying to configure our profiles so that supervised Ipads will get apps of our choice pushed out to the Ipad at the beginning of the installation and also have the possibility to do it after OOB installation. I am currently having trouble doing this without having to be logged into the app store with an managed applied. The reason for this solution is that we want the users on premise to be able to use in app purchase with non managed appleids. Does anyone have a solution for this using device groups for an example? I cannot find documentation for this and i am starting to think it might not be possible.. Thank full for any suggestions!
Is there a possibility to disable the new feature in macOS Sonoma *Video Reaction* by default with a profile?It leads already with us several times to the fact that in an important meeting from the nothing e.g. balloons came. This is not very professional.Would there also be the possibility that the users (if they want it) can activate this feature again?Thanks for any advice on how I can disable this.
Is there a way for me to deliver my organizations certificate for our wifi without configuring the Wifi payload with a configuration profile? The reason for this is due to the way our Wifi is configured, I can't preload the $username wild card without requiring the end user to log in every time they connect to the Wifi.
Hello to all. My Security Team wants to link Hyperproof Hypersync to our JAMF system. Has anyone heard of this and/or have had success getting this to work? I'm providing the link to HH documentation. https://docs.hyperproof.io/admin/en/hypersyncs/connecting-jamf Thank you for any help with this.
How do I locate my stolen tablet
Hi there, We've just begun testing Jamf Connect in our environment and noticed that the Jamf Connect login window doesn't allow the use of WPA-2 Enterprise authentication against a RADIUS server. How do we navigate around this? We use UniFi OS with RADIUS configured on a USG.
Hi again,I have solved my previous issue - now just wondering if there is a json or plist file which I can use to force this highlighted setting to be toggled 'On' by default for all users by default. I have looked in the general settings on the configuration profile and not been able to find anything related to this. Many thanks again for any suggestions!
Provide users more detailed feedback when updating inventory via Jamf Pro, at durations you specify Background Fall 2022 In the fall of 2022, while conducting some internal training, one of our TSRs asked: “Is updating inventory where the blue circle just spins and spins but doesn’t appear to do anything?” “Yes,” was my deflated reply. Shortly thereafter, we implemented Inventory Update Progress with swiftDialog. Later that same year, we introduced Jamf Pro Self Service racing stripes when using Installomator with swiftDialog. All was right with the world. Groundhog Day 2024 Fast-forward to Groundhog Day 2024, I logged into a test Mac mini to update its OS and was greeted by not one, not two — not four — but three pending updates: Mozilla Firefox Google Chrome Adobe Acrobat Reader I watched as inventory was needlessly submitted after each and every update, just like I told it to. Hopefully after implementing this approach, you’ll never have to be asked the above question or exces
Is it possible to give full disk access to apps like cron, sshd-keygen-wrapper and terminal (other apps as well) through the ssh terminal session of a M1 MAC
Hey, not sure if this is a particular DEP issue or more so to do with macOS but I'm wondering if you've seen the following. I'm starting to get a lot of new Macs shipping and while they are added to a particular PreStage, they do not immediately pick up that it's required. The issue goes like so: New employee opens sealed laptop Starts running through Setup Assistant and is prompted to connect to wifi Mac connects and the next screen is the Migration Assistant screen NOT DEP page informing employee that the Mac is to be managed. If the employee continues, they can successfully setup their Mac without the DEP PreStage being completed or being enrolled in JAMF. In order for the User to be presented with the DEP Setup Assistant page they must do the following: Start Mac and proceed through Setup Assistant Connect to wifi and click Continue On Migration Assistant page click Back button Connect to wifi again (can be same or different network), then click continue Now they see DEP S
We have been running Jamf on our computers since the launch of our company three years ago. From time to time we have computers that need to be removed from our system and I would like to know the best practices. Up to this point all my attention has been on getting computers enrolled.All our computers are in Apple Business Manager (ABM) and they are enrolled in Jamf using PreStage enrollment. This works well.When an employee leaves the company I lock the computer in Jamf before the computer is shipped back.When I receive the returned computer, I use the unlock code from Jamf to unlock the computer. I then release it from ABM. Next I select Remove MDM profile. Once I confirm that the profiles have been removed, I then delete the computer from Jamf.Is this the best, or at least, correct way to do this, or is there a better way?
My company is in the process of getting users to self-enroll their existing MacBooks but we have a few individuals who are reluctant to do this, site various reasons why they won't.One is a concern regarding the amount of CPU/memory consumed by Jamf. Having looked at the processes running on my MacBook I can't readily identify which are associated with Jamf Pro. Is there a list somewhere of the processes that can/do run on macOS once registered with Jamf Pro.Another is that a user has highlighted a somewhat dated blog that casts doubt on the security of Jamf Pro. While I'm in the process of reading through the article and trying to establish if any of it is still relevant, if anyone has comment/view on it that they wish to share I'd like to hear it.https://labs.withsecure.com/publications/jamfing-for-joy-attacking-macos-in-enterprise
What is the recommended workflow for deploying MS Office to shared devices such as lab macs? We have been using the BusinessPro package along with the 2019 serializer but this seems to no longer work with the latest versions. We can switch to O365 licensing for computers used by only one person, but this is not ideal for lab machines as users will quickly hit the device limit for their Microsoft 365 accounts. Is there such a thing as Microsoft 365 license for shared devices like what is available on the Windows side? TIA
While going through JAMF 100 Course, i just came to see Jamf offers suites of application. Later saw a pic of somebody who has installed Jamf Pro as App which further had composer and 1 more application. Does someone know where these apps can be found and installed, it must have some .dmg file. Looking forward to hear from someone.
I'm seeing this popup on some of our users devices since the upgrade to Monterey, but I'm not entirely sure what it's trying to do, and it seems like I need to know in order to prevent it from popping up by automating what it's trying to do. I think this is from trying to install FortiClient, but I'm not positive. How can I tell what it's doing so I can make this easier on our users?
Hi,I'm deploying JamF connect using Intune and struggling to get the login screen to appear at start-up. If I log in using the local user and then log out, the Azure login screen appears and it all works fine. What I can't get to happen is the login screen to appear at start-up.Where I'm at now is that at startup the regular macOS login screen appears and I can enter my credentials.Then the Azure login screen appearsThen the screen goes blank for 20-30 seconds and the Azure login screen appears again.Then I can log in, do MFA and I'm at the desktop. What setting might be triggering the initial macOS login screen so I can remove it and boot straight to the Azure login screen?Many thanks!
One of our educational app vendors fixed some bugs today on their IOS app.Their new version 7.6 shows at the App store, but 7.5 is still showing onJAMF at ...jamfcloud.com/mobileDeviceApps.html on the Mobile DeviceApps page. How long does it normally take for the app updates to transferfrom Apple to JAMF? Overnight?Tim
Greetings programs!If your org adopts OneDrive for managing user Desktop/Documents, you may run into issues of filename compatibility. I’ve written a couple scripts which replace forbidden characters with underscores (_). This approach uses zsh file globbing and the zmv function. Also included are updating file dates to align with issues with the FAT file system and Windows Explorer.https://github.com/atlauren/OneDriveKFMEnjoy! PRs welcome.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!