Get Support
Recently active
Hello,what happens if you copy a jamf-enrolled device to a new device via QuickStart?Is that even possible? And will the new device still be enrolled and the business data also copied?And what happens to private data?
If I create a hidden account with the JAMF binary below, how can I delete the account or how can I unhide it? This is how I create it: sudo jamf createAccount -username localadmin -realname Local Admin -password P@ssw0rd -admin -hiddenUser This creates an account in /private/var/localadmin I have then tried to change the ID and or deleting it with DSCL, but I keep getting an error. sudo /usr/bin/dscl . -delete /private/var/localadmin delete: Invalid Path <dscl_cmd> DS Error: -14009 (eDSUnknownNodeName)
Three of my remote MacOS users with AD accounts are unable to sync their filevault and AD creds. Typically we have users log into the VPN and then change passwords locally in syst prefs. In a couple of cases I have users who can’t seem to authenticate to the domain from their login screens. We have another local account on all our machines that is just a non-admin VPN access account. The current work around is to log in there, get on the VPN and switch user (which only then takes their AD creds). This is a temporary fix and reboots prompt the issue to return. I’ve checked and they both have Secure Token enabled. Is there a good fix for this? I had someone suggest FDESetup commands in Terminal but sounds messy. Does anyone have a Jamf solution? Or any solution?
Over the last 2 weeks several of our managed iPad have received the following message: "Some icloud data isn't syncing." When it is selected the message reads: "Your end to end encryption data stored in iCloud can't be accessed...." There is an option to "Resume Syncing." When it is selected the wheel spins and nothing happens. The same message is still there. I tried removing the device from the static group so that I could verify their account information, but that didn't take care of it either. Any suggestions would be greatly appreciated.
Hey all,Thanks in advance for taking the time to read this post.We are using Jamf Pro and trying to start the process of getting MacOS 14 rolled out--we're currently on MacOS 12 in our district. We'd like to restrict access to some things in System Settings (seemingly still called System Preferences in Jamf Pro). For example, we would block access to Software Update and Sign In with AppleID, among other things. However, the options available in Jamf Pro under Computers > Configuration Profiles > Restrictions > Preferences > Restrict Items in System Preferences don't seem to match what's available under System Settings in MacOS 14. I am wondering if this just hasn't been updated on the Jamf Pro side, especially considering that the names don't match?I also think I saw somewhere online that we won't be able to block access to AppleID sign-in with MacOS 14. Can anyone verify?Thanks again and best regards.
I have an existing site (call it site1) and created 2 new sites ( site2 & site3). I don't want to create duplicate policies, smart groups, etc... for site2 & site3 since all 3 sites will basically use all the same. Is this possible? Basically macs from Site1 will be moved/assigned to Site2 and Site3 Example: Site1 currently has Self Service policy1. Can I use that same policy1 in site2 & site3 without having to create the same policy for both new sites? Site1 currently has Smart Group 'has zoom version 17' Can I use that same smart group in site2 & site3 without having to create the same smart group for both new sites?
We are pushing out Google Hangouts Meet to our managed iPads (VPP licenses), wondering if we can push out variables or anything else to pull the user account into the app as well?
I have set up Google Chrome as an app from Jamf App Catalog as a Self Service option.As a user, I have installed this app, and within Self Service, it then says "Open".I have now deleted the app locally and run a recon, but Self Service still says "Open". It seems there is no way for me to re-install this app. And also "Deployment status" in Jamf Pro thinks that I still have this installed.Is this expected behaviour?
Hi All,We have implemented JAMF compliance Entra integration and have now come to implementing personal enrolment of BYOD macOS devices in Intune. It seems that once the compliance policies have been setup this disables users from being able to the personally enrol a Mac in Intune. Has anyone overcome this problem? Do we have to have the users temporarily added to the Entra exclusion group temporarily to allow the enrolment of a personal device? Whichever way I look at this it seems cumbersome and service desk impacting.
After our cloud instance was updated to version 11 this past week, our team that uploads app packages gets an "Upload fail: undefined" error. It turns out there was an update to permissions that I can't seem to find any documentation on, so I figured I'd put it here in case anyone else runs in to this. If you have accounts that don't have full admin rights and need to upload packages, they also need CREATE on the "Jamf Content Distribution Server Files" permission.
Hi,Just wanted to know why the index page of JAMF will refresh when you have it open in Google Chrome but doesn't do this when using Safari (or Firefox).Also, it would be even better if the page did ajax refreshing, rather than having to refresh the entire page.
I have an Intel-based Mac that will not enable FileVault. A user left the company so I wiped the machine back to defaults and upon startup, re-enrolled in Jamf. Everything enrolled properly but enabling FileVault fails on every level. The Config profile is installed. When I restart it attempts to turn on FileVault, asks for password, I enter and then it says there was an error. It restarts, I login and try to manually enable through System Settings. It prompts for password, I enter and then nothing happens. It accepts the password but nothing happens.I ran the command fdesetup enable in terminal and it prompts for credentials, I enter and it stalls for a moment and then says "Error: A problem occurred while trying to enable FileVault. (-69550).I have wiped this machine twice now and same result. Ran disk utility and it found no issues.I'm at a loss. Any ideas?
I didn't see this one in the resource kit, and it took me some tinkering toget it just right. I hope some of you get some use out of this script (I'mattaching a zipped file just in case your mail reader, or any mail serversbetween you and I, mangle the text below).This script can be part of a configuration (make sure it's run "at reboot"),a policy for already-deployed systems, or run ad-hoc out of Casper Remote. #!/bin/bash ##### HEADER BEGINS ###### scr_sys_turnOffIPv6.bash## Created 20081222 by Miles A. Leacy IV# miles.leacy at themacadmin.com# Modified 20081222 by Miles A. Leacy IV# Copyright 2008 Miles A. Leacy IV## This script may be copied and distributed freely as long as this headerremains intact.## This script is provided "as is". The author offers no warranty orguarantee of any kind.# Use of this script is at your own risk. The author takes noresponsibility for loss of use,# loss of data, loss of job, loss of socks, the onset of armaged
Hi everybody, would like to share this short guide to help other users out using gmail as official server to send email.it works in both cases with @gmail.com domain and google managed one @MY13_2_domain.tld CONFIGURATION Server and Port: smtp.gmail.com : 587 Encryption: TLSv1.2 Connection timeout: 30 sec Sender Display name: JAMF Software Server Sender email address: ______@XXXX //your domain, gmail o gmail-managed Username: _______@XXXX //your domain, gmail o gmail-managed check AUTHENTICATED CONNECTION.use same email and password we used for the SMTP account. IMPORTANT NOTE:Less secure app option should be turned at ACCOUNT LEVEL, not at organization one. as a console admnistrator I wasted hours debugging this issue and realized just now that the option must be on at account level, not at organization one. Less secure apps & your Google Account hope this will help! brgds.Arkage.
I know I'm doing things the hard way. When a user gives up their Mac and it is still a viable machine, we would like to be able to use it again. Finding that getting a machine wiped and ready for redeployment to be an excruciating task. This is what we are doing now - and this is only because we obviously don't know any better:Get the Personal Recovery Key from Jamf ProBoot in RecoveryReset the user passwordLog in as the userUpgrade to the latest macOSBoot into internet recoveryWipe the driveInstall from internetThat all takes hours and I am sure there is a better way to do this.Would love to just boot off a USB disk and wipe the machine with the latest macOS supported for the hardware.I feel like that used to be a thing. Now I try and do that and cannot boot from USB, try to enable boot from USB and get Authentication Needed - Enter macOS Password - Recovery is try to change system settings. No administrator was found.As far as I know, there is a local admin set up as part of the poli
Hello. Not sure if others have had this issue, but escrow buddy is not working for us. I followed the deployment guide on the wiki, and made sure to double-check everything, but no luck. Had the user log out and log back into the MacBook (after the Policies completed), and the key is still not escrowed into Jamf. I also opened an "issue" within their GitHub, but I was curious if anyone here has experienced the same problem. https://github.com/macadmins/escrow-buddy/issues/8 Not sure what I am missing here 🤔 🤔
Hi everyone, I'm a bit confused on this one. The MDM profile on the user's machine was about to expire so I manually sent out a "renew MDM profile" command.It worked with the exception of the SCEP cert. I'm honestly not sure what to do for it at this point. Any ideas?
https://download.mozilla.org/?product=firefox-pkg-latest-ssl&os=osxhttps://download.mozilla.org/?product=firefox-esr-next-pkg-latest-ssl&os=osx Reference:https://bugzilla.mozilla.org/show_bug.cgi?id=1617992
I am looking for a way to find all Aliases which link to the "OneDrive-MyCompany" folder in ~/Library/CloudStorage When I use mdfind -name "OneDrive-MyCompany" It only finds the original folder but not the Alias which is in "$HOME". mdfind "kMDItemKind == 'Alias'" Does not show any output ...
I am trying to get a basic report of macOS versions and the count of Macs with that version. This seems like an easy report to generate but I can't seem to find a way in Jamf to display this. Am I missing something? If not, how do you all report on OS counts?
Microsoft Enterprise SSO plug-in for Apple devices - Microsoft Entra | Microsoft DocsHas anyone gotten this to work with Firefox or Chrome? I only see examples where Safari works, but I have a requirement for the other browsers.I've installed the latest version of company portal, made the configuration profile as explained in the link and added the plist file for the options: browser_sso_interaction_enabled and disable_explicit_app_prompt. I even tried adding the bundle names for chrome and firefox, but when I go to office.com I am greeted with a sign in prompt in the browser. In the azure ad sign in logs, I don't see anything unless I go ahead and log in.Edit: This is working for chrome and firefox on our windows machines.
We have been using Jamf for some time, without classes and log ons and its been brilliant.However, we are moving towards using classroom logins.At the login screen the brightness is too low and the pupils can't see to log in. They can change it once logged in.Is there anyway to turn off true tone so that the screen is bright enough for the pupils to log in.I logged on to the ipad with an instructor account and turned off true tone but as soon as it went back to the login screen it was very dim again.
Ran into a first for me. I have a number of devices in JAMF, through ABM. All good, works great.User ends up loosing it in Airport, in airplane mode. No cellular, so likelyhood of it being online is slim.That said, its in lost mode now, etc. But, with the future of this ever seeing the light of day, Ill have to keep it in JAMF forever, and therefore paying for a license for it, in the event of it ever coming back on line.OR? Am I missing something? Ive never had to see this one before...
Does anyone know if it is possible to disable iOS Government alerts via a configuration profile?We have 4000+ iPhones used in a hospital setting and when the alerts go off it often occurs in and around patients that maybe trying to get rest. I'm looking for a way to do this via profile as to not have to disable each one manually.I see the notifications config setting, but that appears to be restricted to managing individual application alerts.
If any of you are tired of your users receiving jamfAAD pop-ups, I would highly recommend transitioning to device identification using certificates. This method of conditional access allows you to control conditional access directly from your Jamf Pro server. Access is simply determined by the presence of your certificate. (This does require your users to have E5 licenses)The certificate is deployed via configuration profile...so no more manual registration either. Perfect for zero-touch deployments. To stop the pop-ups unload or delete any launchAgents related to the jamfAAD Agent. You can read more about this process here.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!