Get Support
Recently active
Not sure what I am doing wrong here. I have created a Supervision Identity in JAMF Pro. But when I try to add it to my keychain, the password I provide is invalid. I've deleted and recreated the identity many times. Any idea what is going on?
Hey all, got an issue that I can't find answers to. I have no restrictions on anything in ABM and JamfNow in terms of app store access. Users can log into the app store but can't download anything. What am I missing?
Hi All,Do we have the .pbit for the Jamf Pro.I have referred to the this link,But unable to find the JAMF Pro .pbit help me if anything is already there ? https://github.com/jamf/powerbihttps://www.youtube.com/watch?v=DDbDbOfABTM
Since the JAMF Cloud update over the weekend, I see all clients now have the JAMF Remote assistant binaries / apps etc installed and a launchdeamon running.. We do not have it enabled in JAMF.We cannot have remote access apps / binaries installed without testing and passing security etc. There is no way to disable this 'functionality' of auto installing (I've asked)There are no official uninstall processes at the moment (I've asked) This is a very very bad idea installing this automatically.
Hello All. I've been installing a configuration profile that sets up our wifi SSID and associates it with a machine certificate via the AD Certificate section. It associates the cert with the wifi config (so the user doesn’t get prompted) and overall has been working fine for quite some time. I have one issue though. New networks place the network at the end of the preferred network list. Simple fix: should be to re-install right? Nope. The configuration profile places the network at the end of the Wifi Preferred Networks. I want it to be first. There doesn’t seem to be a way to re-order it unless I remove the wifi network, then re-add it. That's fairly trivial to script, but that breaks the association with the computer’s certificate and the user now suffers. Does anyone know how to programmatically re-order SSID preference without breaking the cert association OR how to add wifi and associate it with an existing machine cert so that the user isn't prompted? Th
I have seen several discussions on this topic but so far following them I have not been able to get rid of the Cisco AnyConnect Socket Filter PPPC pop. I have a few configuration profiles for AnyConnect following other people and Ciscos generic documentation and it looks like they have installed correctly. However the popup persists. Anyone got any ideas? https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect49/upgrade/AnyConnect_macOS_BigSur_Advisory.html#_Toc52277857
Pretty much as the title states (I have opened a ticket with support this morning just in case). Here's what I know5 ipads migrated to jamf pro in the last weekconfig profiles are not being pulledthere is a pending "device update" commandAll device records in Jamf (e.g. apps, management) are simply blankThese ipads are in ABM, and are assigned to jamf proI have successfully migrated <10 other ipads within the last week and had no problemsInitially, these devices were not erased from jamf Now and were still checking into JN despite being assigned and pulling info from JPNo amount of factory resets changes anything Any thoughts/ideas/pointers from the community?
We are just getting set up with Jamf Protect and are running into an issue with deploying Airtame. We are using Jamf Pro and following the instructions here https://help.airtame.com/hc/en-us/articles/5213653434909-Mass-deploy-the-Airtame-app-on-macOSThe package seems to be running a script to install the audio drivers that is being blocked by Jamf Protect. When we disable Jamf Protect the audio drivers install fine. Can someone point us in the right direction to whitelist this process?
Today we released Jamf Connect 2.31.0. This release includes the following changes and improvements: Removal of Support for macOS 11.x Jamf Connect no longer supports macOS 11.x. Computers with macOS 11.x or earlier will be unable to install Jamf Connect version 2.31.0 or later. Any automatic update workflows configured in your environment will no longer apply. Other Changes and Improvements Users can now enroll their mobile device with Duo Universal Prompt via Okta Identity Engine in the Jamf Connect login window web view. Users who authenticate locally with a Kerberos ticket will no longer experience logs that indicate the Kerberos authentication is incomplete prior to beginning network authentication. Resolved Issues [PI112919] The Tenant ID (OIDCTenant) and Custom Okta Authorization Server (OIDCAuthServer) settings now appear as intended when a Jamf Connect login window or menu bar configuration file with these settings configured is imported to Jamf Connect Configuration. [PI1
Does anyone know if there is a way to determine if a system extension is user-approved versus one approved by MDM? We'd like to remove some applications that have a mix of ways the system extension has been approved during/prior to installation, and would like to craft different uninstall methods to make sure we remove each type.
Hello everyone is there a script out there that determines the user's log-in time for when they have successfully logged into Jamf Connect? I believe I would need to create an extension attribute for this sort of request. After I have created the extension attribute, We would then want to create a smart group in Jamf based on the created Extension Attribute.
After the authorized reseller successfully enrolled the iPads into my Apple Business Manager account, I proceeded to release them to the Jamf Pro Cloud server. However, I am currently facing an issue as the iPads are not appearing on the Jamf Pro server, indicating a synchronization problem between Apple Business Manager and Jamf Pro. I've used the same server for other iPads that were manually enrolled, and they appeared on the Jamf Cloud without any issues. Any guidance on resolving this syncing discrepancy would be greatly appreciated.
Hello, I am working on standardizing and limiting distraction of our end users by removing most of the Apple Bloatware from the dock. Which I have limited access to what apps can be used so they are useless being on the dock too. I'm stuck on getting some default apps removed from the Dock. So in the management setting I have set dock items with their path for example: (file://localhost/Applications/FaceTime.app/)Here a list of apps I removing:FreeFormNewsRemindersApple TVFaceTimeMapsMessagesI was able to have it successfully add Google Chrome and Drive to dock but not remove Default Apps. What I have currently handling the removal is a standard jamf policy listening to login events. I am using the built in "Dock Items" payload. To figure out what was going on I pushed the policy manually with verbose and it is pushing out a bunch of errors of "No Dock found"verbose: No dock found in //System/Library/User Template/English.lproj/Library/Preferences/verbose: No dock found in //Syste
Hey everyone. So we're finally in the process of getting our fleet upgraded from Monterey to Sonoma and we have certain developer tools we use from HomeBrew for our internal code/projects. When the tools are installed, we've got a couple of errors that the tool "was blocked from use because it is not from an identified developer". The tools in question are:heptclibzmq-local.dylibtrilIn addition to those being blocked, trying to open Tril triggered another warning of that "tril cannot be opened because the developer cannot be verified. macOS cannot verify that this app is free from malware". And then the only options that appear, unless you right-click on the app, are "Move to Trash" and "Cancel". Is there a way to get an identifier from these tools like those ".com" hidden files so I can whitelist them for our users? Like how you can use a configuration profile to verify certain system extensions? Thanks!
Hello, I need to run a command for current user. I tried with script but it work for root account. I need the run this command for current users.defaults write com.google.chrome IncognitoModeAvailability 0
I recently got a Jamf Pro trial, it tells me that in order to create push certificate, I need to sign a CSR using my Jamf ID, but when I click on the link it just says that I don’t have any products on my account. Any solve for that?
Hey I seem to be having issues with end users being able to install osx updates on their macs managed by jamf, the users are prompted for the password to upgrade to 14.0 but won't accept the user's password when being prompted is anyone seeing this or have we set this somewhere in jamf pro. I am having to log them out login as admin and update the mac Thanks
We have around 60 devices that are missing a bootstrap token. I was hoping to script it. My scripting knowledge is somewhat basic I was hoping someone could point in the right direction. Do some searching on here I found this Would I be right in saying I would pass my admin account username and password in parameter argy 3 and 4 Assume that should parameter 4 & 5 in Jamf right? Has anyone sucessfully been able to script this with out putting the username and password in the script #! /usr/bin/expect# Get required variables. Note that in EXPECT scripts, the variable arguments are one value lower (thus $argv 3 is actually $4).set adminName "[lindex $argv 3]"set adminPass "[lindex $argv 4]"#This will create and escrow the bootstraptoken on the Jamf Pro Serverspawn /usr/bin/profiles install -type bootstraptokenexpect "Enter the admin user name:" send "$adminName\\r"expect "Enter the password for user '$adminName':" send "$adminPass\\r"e
Does anyone have some EAs for Carbonite like when the last backup happened and the status of the backup? I have the one to just see the status of Carbonite but can't find any other data. #!/bin/sh carbState=$(/Applications/Carbonite\\ Endpoint.app/Contents/DCProtect/DCProtect.app/Contents/MacOS/DCProtect -getClientStatus | grep Client | awk '{print $3}' ) echo "<result>$carbState</result>"
I was just wondering if it was possible to release devices in Jamf Pro instead of doing it through Apple School Manager?I don't see a way to do bulk releases in Apple School Manager.I noticed under the connection to Jamf in ASM (Settings > MDM Server Info) - we have 'Allow this MDM Server to release devices.' checked.Just wanted to see if there was a way of bulk-releasing devices in Jamf. Otherwise I will do them one-by-one in Apple School Manager.
Hello! I'm a relatively new user to JAMF and am so far very much liking it. One thing I'm scratching my head about though is the installation of Adobe CC plus-ins. I manage a bunch of college teaching labs and have been requested to install LottieFiles After Effects plugin as well as LottieFiles Animate Plugin. I've found this support document from Adobe but I'm having a difficult time determining how to make this work with an MDM. Any ideas?
When initiating a user enrollment it prompts for the device to Assign to user. Though I have created a number of users under Settings > User account and groups entering the username, full name or email address of any of the users is never accepted, and selecting the search option, i.e. the magnifying glass, the resulting drop-down list has no users. What value is meant to be entered in response to this prompt?
Hi Everyone, I am not sure if i am looking in the rights places or not, but i am trying to figure out if there is a way to have multiple users be supported/configured on one Mac Machine, with Jamf. Anyone have suggestions?
Is there a macOS command-line tool available for JSON that provides parsing functions like xmllint?I seem to be able to find lots of validators and pretty-printers. But I need a tool I can run inside shell scripts to parse output responses from Jamf Pro's API.
Feel like I have to be missing something obvious here... but I can't seem to get this to behave. Trying to make an extension attribute that checks if homebrew is installed, and outputs the result of "which brew" if so.... pretty basic. This works perfectly from terminal both as my standard user and as root... but when jamf runs it... all that's returned to the extension attribute is "Installed: " with no file path listed.From terminal, i get what seems to be a proper output jamf should be happy with:sh-3.2# ./test2.sh <result>Installed: /opt/homebrew/bin/brew</result>Extension Attribute Code:#!/bin/bash if [[ $(which brew) != "brew not found" ]]; then brewstatus="Installed: $(which brew)" else brewstatus="Not installed" fi echo "<result>$brewstatus</result>" exit 0
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!