Get Support
Recently active
We have Office365 federated with Okta. When I use the Jamf Connect Configuration app with my Azure application everything works fine. I get tokens. However now that I've deployed it using a machine that's not a fresh install I enter my credentials at the Jamf Connect window and I don't get sent to Okta then it says my credentials are incorrect. Is this expected? Will this only work with a freshly wiped machine like in the Jamf connect training? Edit: It seems Jamf connect is unable to handle federated Azure so I'll likely be switching to Okta.
Hi, I have an issue with one specific app (Flash Academy) that I am trying to roll out in my schools network. When a user tries to load flash academy it immediately crashes and sends them back to the home screen. The app doesn't work on any iPads, both the app and iPads are fully up to date. No issues occur with any other app. The app works absolutely fine when I remove the JAMF profile from the device. Any ideas?
How long does the alert play when you use the Play Sound command in JAMF School for a device in Lost Mode?
The last time I had to follow the article for integrating GSX into Jamf Pro, I found the instructions quite lacking. I'm referring to this article: https://docs.jamf.com/technical-articles/Integrating_with_Apples_Global_Service_Exchange_GSX.htmlI worked on my own documentation and figured I'd share it with the community. I won't necessarily keep this up to date, but hopefully it helps people that might be looking to do the GSX integration with Jamf Pro. Hopefully Jamf will integrate these details into their technical document I linked above.==============This article explains how to create a GSX account and obtain an Apple certificate. You can integrate Jamf Pro 10.15.0 or later with Apple's Global Service Exchange (GSX).Note: As of October 1, 2019, Jamf Pro 10.15.0 or later is required to integrate with GSX. If you are using an earlier version of Jamf Pro with a GSX integration, you must upgrade to Jamf Pro 10.15.0 or later to continue integrating with GSX.General RequirementsBefore y
Hello everyone,I wanted to update our Cisco client which works without any problems. But unfortunately the following messages appear in the Cisco client:Has anyone had this problem before?
we have an issue lately with devices enrolling with Intune.. many devices are getting a sign in loop after a few days. This issue started after migrating to Jamf Connect, it's most common with Ventura and Sonoma. We used to fix it by removing stale device records in both Intune and ME-ID (AAD), or removing stale ADAL cached passwords from Keychain. Unenrolling from Jamf to fix Intune enrollment is not helping... removing plist from library preferences is not helping as well. The only option is to rebuild the device. Any ideas? I'd really appreciate anyone's help!
Sorry for the long title.We were doing some testing with Nudge and found out that once you hit the deadline and Nudge enters aggressive mode that it still pops up even after you click to update the device. My manager said when he waited and got to that date he was unable to use his device while it updated since Nudge kept popping back up. Is there a way around this? I just added a long refresh cycle in the user experience tab to test but wanted to check here in case that is wrong.
We currently use DEPnotify to deploy apps and settings when a user logs in for the first time on a new/newly wiped computer. Works great but its no longer being updated so when Jamf announced macOS Onboarding at JNUC we were really excited. Looking at Jamf 11.1 and the onboarding feature and its pretty disappointing. First you need self server enabled (which we do not).When you enable macOS onboarding this fun event happens:"Important: When you enable macOS Onboarding and add the items to be deployed, the onboarding workflow initiates for all computers in your environment. This includes newly enrolled computers and those that were previously enrolled." So does this mean already enrolled and in-use computers will get these applications/config profiles installed?Also there does not seem to be a built in way to ask users questions like what they want the computer name to be, what the asset tag is, what department etc..If find it odd that the company that wrote DEPNotify which is stil
Hello Jamf Nation! Jamf Protect has released an update to the compliance feature. Compliance baseline now includes scoring metrics to assist you with achieving total compliance for your fleet and for individual computers. For additional information, see Compliance Baseline Summary in the Jamf Learning Hub. Thank you,The Jamf Protect team
I am having an issue with Jamf having "Start screen saver after" unchecked within a configuration profile, yet after 20 minutes each one of the iMacs run their screensaver. Does anyone have a workaround to changing the screensaver time from 20 minutes to never without me having to apply it individually per workstation?
Hi, I have trie couple cmd through terminal and still not able to remove DG from Mac os X tried : rm -rf sudo uninstall file://but no luck and even kind find where is the Digital Guardian file is located Thanks
We are in the process of recreating policies and configuration profiles in preparation for a new lease cycle later this year and I have been testing on a couple of M1 machines using my login and have had good results. I just set up one of those MacBooks for another user and even though the screensaver is disabled it will still eventually come on and when it does it will close out of any browser that he has open. Has anyone seen anything like this before? We haven't found that any other app behaves this way, just browsers...
Can someone post how I add two dictionary items together? From here, Troubleshooting_Microsoft_Azure_Login_Using_JamfAAD . I don't know if I need an array added for both. Also, can I add 2 of the same Preference Domain in a Configuration Profile? An example of the below would be appreciated. Thanks in advance!! <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>tokenRetryCount</key> <integer>3</integer> <key>tokenRetryWaitTime</key> <integer>42</integer> </dict> </plist>and <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>useWKWebView</key> <true/> </dict> </p
Hello everyone,We're going over to Outlook/M365 next week and we're gonna set Outlook as standard mail app but just in case anyone badly want to continue with have mail as befor in Apple Mail I'm trying to set it up so you can install the Outlook profile from Self Service.The device I'm testing on gets the profile and asks for the account password but it doesn't accept the password.Does anyone have any idea why it doesn't accept it?
Hi all,I go for the Jamf 300 cert in March. I passed the 200 with a 100. So I’m not too worried, just wanted to know if anyone has any tips, tricks or advice to be on the look out for?My support role has been more on the endpoint side of things. Ie, troubleshooting failed enrollments, self service, onboarding ADE, etc….This year my goal is to lean more on the Jamf Pro side of things. Configuring integrations, creating and implementing maintenance scripts, etc….Any advice for the 300 is greatly appreciated.
I have tried downloading the tool from here AcroCleaner — Acrobat Desktop Tools and Utilities (adobe.com)There are instructions for Windows but nothing for mac. Does anyone know how to run this silently?
Hi all, hope I am doing this request the proper way for the firat time.I am looking for a method to display/report all installed Apps on our Macs that are NOT installed through the Apple App Store or VPP.I need to see which apps are installed on our Macs, which version they are and if they need to be patched or possibly deleted.I found this topic with a solution below:Sadly a 404 from the solution/topic link (https://jamfnation.jamfsoftware.com/discussion.html?id=20882)https://community.jamf.com/t5/jamf-pro/searching-for-apps-installed-via-the-mac-app-store-by-the-end/m-p/163077#M152048Hope someone can point me in the right direction.Cheers.
Good morning,I am getting acclimated to JAMF and unix scripting - Im looking for a way to have a tiny pop-up gui that shows during enrollment where I can easily set the device name. Ideally, what I type in would kick off:set --HostNameset --LocalHostNameset --ComputerNameWe do not utilize zero touch enrollment at this time, we dont have enough devices to really justify it. However, having a tool like this would really improve my process.Thank you for any help!
hi all,is there a way to enforce the setting "Private Address" turned off?We actually have a Cisco ISE in our internal network that uses mac address to detect if it is an iPhone (we push mac addresses in a specific group) and then moves the iPhones to another network. Since Private Address is on, it transmits to the network controller a different MAC address and breaks our rule.
Hi everyone,I'm looking for some help and/or critique on the script below. I would like to mention that I'm still pretty new to scripting and use shellcheck and explainshell pretty heavily. If anyone has any other resources I could add to my arsenal, it would also be much appreciated.Now that the PSA is out of the way, I want the script to check if the policy banner has been modified or deleted and if so, display a message and run the policy -event policybanner. #!/bin/bash loggedInUser=$(stat -f%Su /dev/console) # Path to the file you want to monitor file_path="/Users/$loggedInUser/Library/Security/PolicyBanner.rtfd" # Get the initial modification time of the file initial_mtime=$(stat -f %m "$file_path") #changes permissions of after the packages is installed chmod -R o+rx /Library/Security/PolicyBanner.rtfd while true; do # Sleep for a short duration (e.g., 1 second) sleep 1 # Get the current modification time of the file current_mtime=$(stat -f %m "$
I need some help fixing an issue. During testing of Jamf Compliance Editor we applied a configuration for the login window to show username and password, versus the normal choice of being able to select the username. However, we have one user, who was erroneously enrolled, and we deleted that policy instead of removing the MacBook from the scope (rendering the policy still applied but unable to be removed from scope). Once the policy was deleted, we are unable to set the login screen back to defaults. I have attempted to create the policy again in Jamf Compliance Editor and apply to the MacBook, and while the logs show it applied, removing it does not restore the ability for the login screen to show the users. Is there something else I should be doing to restore the login screen icons? Is there a terminal command that can be run? Note that all of the other policies for Jamf Compliance have been removed successfully from the MacBook by removing t
Hello, help would be appreciated with some configuration / inventory items in JAMF Pro. Im a bit of a newbie with JAMF.I am looking to do the following:1. Inventory script(s) that return whether (1) "AutoFill Password and Passkeys" is enabled and (2) "Use Password and Passkeys from Keychain" is enabled.2. A configuration item or script that would force enable the above settings Thanks!
Hello,I am attempting to configure the Single Sign-On Extension Config Profile, but opening it up I am immediately at a loss for how to do so.What is the difference between the Payload Type SSO and Kerberos?Are there instructions somewhere for how to configure both? Depending on which we choose to use? Any guidance on how to configure this is greatly appreciated. Infrastructure information:We are hosting Jamf Pro on premises.Our Mac Computers are bound to AD.
I circulate MacBooks in a library context, so multiple users use the same machine throughout the day. I'm required to have my MacBooks disk encrypted, and I need my users to be able to login to these MacBooks wirelessly with their Active Directory accounts. But I think FileVault prevents users from authenticating to the network before they login to the MacBook, is that right? Is it possible for users to login to wifi before they login to the FileVault-enabled MacBook?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!