Get Support
Recently active
Does anyone know if it is possible to enable MFA authentication to also disable screensaver lock (without touchID)?Normally the user has to enter their account password (local or idP Password) or their touchID (within 48 hours) to disable the screensaver lock. Is it possible to enable MFA authentication in addition to login after the screen lock? I ask this because it is important for security reasons. MFA authentication should provide a "second" layer of security in case the account password is hacked or stolen. If the computer is in screen lock mode, a malicious person can unlock the computer with the user's stolen password without a second check.It would be good if the OTP pin, already configured with offline MFA, would be also requested for screen lock mode.
I have been using krypted's MakeMeAnAdmin script. It works great for elevating standard users to admin users and demoting them back to standard users. I cannot get the script to generate a log. Does anyone have an updated fully functioning version of this script available?
Users cannot log in to their device after logging out or rebooting. Sometimes the login works, but currently it happens very often that users receive the message Invalid Response Code 401. The Sign In Logs in Azure looking good too. Did any of you had this problem already and if so, how did you solve it?
Hi, I am relatively new to Jamf, but just dabbling in some Plists to force a Google Chrome homepage. I have got this working, but the issue I'm having is that it only works once the app has been force quit. (So if I normally cross off Chrome and reopen it, it opens on a blank Google Search page. Then if I manually force quit Chrome and reopen it, it works as I want it to).Is there a way to make it so that apps automatically force quit once they are just normally crossed off or even so that they automatically force quit when a user logs out? Students won't listen and go the long way around of manually force quitting - so this would be an ideal solution.As well as this (similar query) is there a way to completely disable the option to 'reopen windows when logging back in'? I believe this would be a big help to this issue. Many thanks
In Sonma the default behavior when you click on the Desktop is to show Stage Manager. This is going to cause a lot of calls to our help desk. I'm writing a KB article for them, but a Config Profile to change the setting from the default "Always" to "Only in Stage Manager" would help, a lot. Never created a custom profile before but I'm looking through documents now. Anyone already done this though? or faster at it than I? We probably won't be deploying until end of the month at the earliest (Netskope won't have a compatible release for at least another 2-3 weeks).
Is there anything more you got to install/upgrade before moving from jamf pro 10.46 to 11.2. When i'm reading https://learn.jamf.com/bundle/technical-articles/page/Incremental_Upgrade_Scenarios_for_Jamf_Pro_10-0-0_or_Later.html i cannot find anything that we have to do. Kind regards Joachim
I can and a macOS App to JAMF just fine using Apple Business, but iOS Apps do not show up. I can't even see it in Global\\Volume Purchasing\\company\\Content. I can't add anything new and I increased a products count by 10 and the product shows the original number of licenses in JAMF. Updated the Service Token hoping that would kick things off but still nothing is coming in.
I can provide more detail if needed, but I'm noticing a good amount of devices with last inventory updates of months ago or over 1 year ago. Is there a common theme to this sort of reporting issue or could this be due to a number of different things?Before I dive in to this issue I wanted to ask the world instead of reinventing the wheel and wasting time. Troubleshooting has been minimal, I've just been correcting it with using scutil to set device names sudo profiles renew -type enrollment, sometimes I have to sudo jamf -removeFramework to re-enroll.Thank you guys!
Hi, Has anyone come across this issue? Since updating safari to version 17.3 on M1 iMacs, no matter what site we navigate to it just showing a black screen. Safari loads and it seems the pages are loaded too but everything is blacked out. Any ideas? thanks
Good afternoon JAMF Nation. Just want to get your professional guide/advice on how to install the SentinelOne agents in our MacOS devices using JAMF. I have the PKG file needed but when I tried installing it as normal, it failed. Looking for a friend, TIA!
We have recently trialed using Classroom & Classwork (schoolwork in the US) on our student iPad fleet but are having issues with students being stuck in "Authorising" on the teacher iPad in the Classroom app. I thought that it may be an issue with the student a teacher profiles we use, but I have made sure that all the toggles for auto prompting have been set to allow in the configuration profiles. Classroom to perform AirPlay and screen observation without prompting - AllowClassroom can lock student devices or apps without prompting - AllowAutomatically join Classroom classes without prompting - Enforce The strange thing about this is that it is not consistent across teacher devices. We ran up and identical iPad for one teacher as a test, same teacher, same config profiles, same students and class. Yet one iPad has no students working and the other only 4 worked out of the whole class. All Students have the same profile as well, so I am baffled why two otherwise identical iPad
Hey guys, powershell has worked great for me in the past with classic API, but it is giving me fits while trying to use the UAPI for the first time. I need to script swapping computers between prestage scopes, but this is not available in the classic API. This is my code so far: function getAuth() { $url = "https://mytenant.jamfcloud.com/uapi/auth/tokens" $creds = Get-Credential $call = Invoke-RestMethod -Method Post -Credential $creds -Authentication Basic -Uri $url -ContentType "application/json;charset=UTF-8" return $call } $token = getAuth $token = $token.token function apiCall() { $url = "https://mytenant.jamfcloud.com/uapi/v1/computer-prestages/4" $headers = @{ Authorization = "Bearer $token" } $api = Invoke-RestMethod -Method Get -Uri $url -Headers $headers -ContentType "application/json;charset=UTF-8" return $api } Same exact thing works fine with bash, but I get errors with
Hey all together,im pretty new to Jamf Pro so be a little bit patient with me. ;)Our company wants to enroll the devices in the BYOD context.For my understanding it was needed to configure the user initiated enrollment - personally owned.So far, so good. I can access the /enroll URL and sign in with my connected SSO / EntraAfterwards i log in with my fresh created managed Apple IDEverything seems to work fine... but know my understanding problem:Its installing two MDM profiles. One is called "MDM profile" and the one i created.But its not applying my for example code restrictions i set in the configuration profile.So im just confused where im doing the mistake.Don't know if there is a coherence:I saw, that there are two different "methods" if we are talking about the BYOD mobile device connection. But i dont have to host a webserver on my own for this right? Hope you can help me through the Jamf jungle.
We are noticing the Departments in User and Location inventory getting removed automatically for Mobile Devices. We manually update the Department in User and Location but it gets removed as soon as the device updates inventory. We are not noticing this in Computers. Thanks.
We recently upgraded our Meraki Wireless APs and now have the capability to run Wifi 6 for faster network performance.My understanding is that to use Wifi 6 (or 6E) you need to use WPA3 Enterprise (with EAP-TLS). This shouldn't be an issue for us as we're currently running WPA2 Enterprise with EAP-TLS however i cannot see any documentation on setting up WPA3 Enterprise on Jamf Pro/Cisco Meraki, does anyone have an guides or info on setting this up? TIA.
We are using Ivanti Secure Access for VPN on our iPhones, and we configure it with a config profile. I have noticed that if the config profile is pushed before the app has installed, the app wont see the settings, even after a restart. The settings config profile must be pushed AFTER the app.But when deploying a new iPhone out of the box, all the "apps and profiles install in a big dump and you dont really have control over them. We even tried scoping the profile to a smart group "Ivanti app installed" but it still sometimes gets overeager... it sees the app before it has finished installing, and pushed the profile too soon.How do we ensure the profile installs after the app? or are we solving the wrong problem and theres a way to make Ivanti see the profile regardless of when it was installed?
I'm in the process of building the latest Cisco Secure client for deployment. I am building it using Stephane Sudre's Packages app (1.2.10). I have the Cisco Secure pkg (pulled from Cisco directly) and the Choices.xml added in Scripts > Additional Resources. The post-install script is very straight forward and just runs /usr/sbin/installer -pkg ./Cisco\\ Secure\\ Client.pkg -applyChoiceChangesXML ./Cisco-Secure_choices.xml -target / This works every time I run it on a clean install or if I run it locally on a machine with an older version of Cisco Secure. If I try to deploy this package via Jamf policy to a machine with an older version of Cisco Secure installed, it fails 100% of the time and uninstalls the existing install. The Jamf policy log just gives the standard unhelpful "The Installer encountered an error that caused the installation to fail." message. The install.log tells me that the error was with the post-install script, but that is so strai
Has anyone recently updated their JSS to Jamf Pro and find that loading policies and management tabs takes forever???
Looking for a way to script turning off Low Power Mode on our laptop fleet once a week. Students have been not charging and then come complaining to tech support to disable low power mode since its locked behind admin credentials (faculty can temporarily elevate to admin, students can't).Looked through here, but didn't see anything applicable. Any suggestions? I didn't see it in config profiles either.
K so i have an issue with wireless icons in osx. The laptops are all OSX 12.1. Issue is as follows. On a cold boot or reboot, the initial logon screen, there is no wireless icon up by the time. The machine is connected to wireless though, as it allows domain logins. When you get into the system, the wireless icon is there. When you log out and attempt to log in as another user, the wireless icon is there at the login screen as well. Its only the one initial time, from a full reboot, that the wireless icon does not show... God why? like why do macs have so many stupid problems like this.... Does anyone know how i can make the wireless icon show from a cold boot/reboot? Is it just a bug? Do they do this on purpose? Can it be configured? I see some other threads about hiding the icon, but i dont see any about making sure its there at all times. Any help appreciated. Because for me, I have to log into every single one to see if it has wireless or not. I would lov
I want to shout out this awesome project.https://github.com/Macjutsu/superI've been beating a dead horse trying to figure out a way to keep the new M1s updated with little to no user interaction, not let them be able to access the Software Update portion of the settings panel since, let's admit it, end users are going to click on the shiny new OS Upgrade and not the tiny blue button all the way down at the bottom.I was able to set this up in a day and configure all settings and testing has been amazing. It only downloads the updates and not any upgrades, unless specified in the configuration, BEFORE prompting the user for a restart so it's 99% transparent to the end user, let's me setup deferment time and amount, custom branding to make sure it looks authentic to users, auto updates things like Safari that don't need a restart to update, and most importantly can authenticate as an admin account with a secure token instead of needing the user to be a volume owner!If you're looking
Good Morning,Is anyone deploying/using Maxon. They provide a command file and a .plist file to automatically run the command file, but I am having a problem getting the command file to launch properly. I was thinking I could generate a login script, but I am not great at scripting, would anyone out there be willing to take a look for me?The command is:/Library/Application\\ Support/Maxon/Tools/mx1 user login -u software@quinnipiac.edu -p PASSWORD Maxon instructions
Very new to Mac management and JAMF. I've been using a test Mac to test my enrollment and policies and noticed that if I reinstall OSX to test the OOBE, the policies I have set to "once per computer" don't seem to re-run.Looking here, I see that there is a command to flush the policy history and effectively "reset" the computer. So, I ended up creating a script to run that command, set it to trigger upon enrollment and set the execution frequency to "ongoing". I also set the script priority to run before other actions.I assume this should mean that when the test Mac has OSX reinstalled, when it completes enrollment, that script should be the first thing to run and the policy history should be cleared and all of the other policies set to trigger at enrollment and run once per computer should run, but they're not.If I pull up the computer in question in JAMF Pro inventory and look at the policy history tab, I can see that the policy flush did run, but for whatever reaso
I always download the monthly mid-month updates of MS Office from macadmins.software and there is sometimes a day or two delay. However the January updates are still missing from the site. Is Microsoft no longer maintaining that site?
Hello,what happens if you copy a jamf-enrolled device to a new device via QuickStart?Is that even possible? And will the new device still be enrolled and the business data also copied?And what happens to private data?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!