Get Support
Recently active
Hello Jamf Nation, Right now, the majority of our users are non-admins but are still able to install any extensions they want. We are looking for a way to only allow approved extensions and require an administrator to install any other for Firefox and Safari. Google Chrome has a nice way to do it via sort of a "Self Service" method but it's proving to be a little more challenging for FireFox and Safari. Does anyone have any thoughts or ideas on how this can be accomplished?
Hello all,I was seeing if all MacOS devices had to be enrolled in Azure AD to get a Defender antivirus policy that is setup within Intune and be able to report.
Hello from Jamf, The Product Design and Engineering teams have made great strides this past year to improve the accessibility of our products. Our goal is to achieve WCAG 2.2 AA compliance for our products by delivering improvements incrementally to attain 100% adherence to those standards. Here are a few highlights we wanted to share with you regarding the work we have done in 2023: Self Service, the gateway to purchased apps and books for your end users, is 100% WCAG 2.1 AA compliant. Jamf Pro 11 series introduced quite a few enhancements to our product accessibility: Improved color contrast throughout the product, most noticeably in the side navigation area Keyboard navigation has been updated to support navigation to elements in the top bar, such as Notifications and the user avatar menu. Keyboard navigation issues with the side menu have been fixed Added a “Skip to Main Content” action, visible only when using keyboard navigation, to facilitate skipping
Hello together,I run into an issue when I want to register a mac M1 with macOS Ventura to our Jamf Pro management. While installing the MDM profile, the installation stops with a message "mdm profile could not be installed, ssl failure" (I hope, this will be the right translation from German to English).I tried to deactivate the ssl check on our Jamf Pro, but without any success.All clients with macOS Monterey (version 12.6.1 included) can be registered and the MDM profile will be installed without any issues.Has anyone an idea, where I could configure the MDM installation on mac M1® (and oder INTEL®) under macOS Ventura® ? At this time, we are running Jamf Pro 10.41.0. Because of the certificate theme, I did not update to 10.42.. I would be glad for some thoughts :)greetings,NOVELLUS
Air print is no longer working in my environment for air print on iPad OS 17 configured devices, 16 and below still working as expected, our printers set on a seperate vlan, as does our print server, running paper cut with mobility print with dns printer discovery configured. I am yet to reach out to paper cut to see if they are aware of the issue.
I'm encountering an issue with enrolling a users M2 MacBook Air. Following profile enrollment, I've hit a roadblock—I can't mount the disk, receiving an error message (-69842): "couldn't mount disk." Consequently, I'm unable to use Time Machine for backups as the drive isn't selectable.Steps I've taken:Enrolling a different Jamf profile works fine.Backing up to an external drive using an unenrolled, fresh device also works fine.While there are some policy differences, the setups are generally similar. What could be causing this discrepancy? I've tested the Jamf profile of this user on two separate MacBook Airs with different drives and both fail to mount disks after enrollment, ruling out a hardware issue.Interestingly, the problem seems confined to this specific user—other user accounts function without any issues. Additionally, backups on their old Intel MacBook (currently enrolled in Jamf) work perfectly. Everything else with the new device is fine, it's just unable to mount externa
I'm hoping I'm missing something obvious but I'm stumped. I want to have a number of policies available in Self Service that are only available when a member of the IT team is logged into Self Service on that computer. For example, if an employee is having problems, we can log into Self Service and run an policy to gather diagnostics and save it to Jamf. But these policies should not be available all the time. So the goal is to have them scoped to "All Computers" but use Limitations for specific Jamf Pro admin users. But... when I go to use one of these tools, they start and then disappear and say "This item is no longer available." If I take away the user limitation, they work just fine; but I can't have these laying around all the time. What am I doing wrong?
Hi everyone, pls bear with me for this beginner question since I'm new to jamf.During the User initiated enrollment, I check on Create Management Account. However, it only let me pick the username but not the password. Do you know How I can pick a password or update it? Thank you! Below are the only options available:Settings/ Global/ User-initiated EnrollmentManagement AccountAccount to be used for managing computers enrolled via a PreStage enrollment or user-initiated enrollmentUsernameCreate management account Create the management account during enrollment if it does not already existHide management account Hide the management account from users Allow SSH access for management account only Make the management account the only account that has SSH (Remote Login) access to computersEnsure SSH is enabled Enable SSH (Remote Login) on computers that have it disabledLaunch Self Service when done Ensure that computers launch Self Service immediately
Hello All,My current company is mandating that I install JAMF on my personal laptop and iMac due to "compliance requirements." While I am inclined to reject this request based on principle (since these are my personal devices), I am enjoying my job and do not plan to challenge it.However, since my personal devices contain sensitive information such as my banking credentials and personal data, I am concerned about the extent to which JAMF can access them. The IT team has stated that they will not be able to view any personal data and that I can continue to use my personal AppleID. Nevertheless, after researching the topic online, I am starting to have reservations about these assurances.
Hello Jamf Nation! I'm happy to announce a new open-source tool from Netflix called Escrow Buddy focused on helping IT/security administrators ensure all their Macs have a valid FileVault key escrowed to MDM.Check out the announcement on the Netflix Tech Blog, and see the GitHub repo for documentation and the latest release.I hope many people will find Escrow Buddy useful!
I am having troubles allowing non admin users to change the Date and Time on their Macbooks. There are quite a few teachers who let their Macbooks battery drain over the holiday break and when they got back in district their date and time were wrong and they could no longer connect to WiFi. We had previously enable Non Admins to change their date and time settings with the following command: #Allow Date/Time Change security authorizationdb write system.preferences.datetime allow This unlocks the date and time section within system preferences for non admin users but for some reason when users try to change their date and/or time it reverts back once they click save. For example if the year says 2018 instead of 2020 the staff member changes it to 2020 and clicks save, then the year will change itself back to 2018. (Settings that set the time automatically have been turned off at this point.) We can successfully change the time when logged in as a local admin account but our users are
just upgraded to 11.1.3 and when i go into a computer details management tab, theres no remote assist button
New to Jamf Pro and just looking to get things set up before rolling out company wide, and testing the initial configuration on my MacBook things haven't quite gone to plan.Have in the Configuration Profile set a Banner message and cleared the tick-box for Show "Other...", but after I enroll my laptop they doesn't appear to be any banner message, i.e. there is no message displayed above the login prompt, and I am able to select Other on the login window which then prompts for a Name and Enter Password.What am I doing wrong or not understand?TIA.
I use the block USB policy with Jamf protect, but it is still not working. Some USBs are working, and some cannot be used to move data.
Hello,is there any way to disable to option? Regards
Is there a way to pull the battery health information? cycles and max charge info.
Hello,I hope you are well, I am new using jamf pro, we want to launch a policy with a script to uninstall Malwarebytes from all Macs, I found the following script https://github.com/eth-its/autopkg-mac-recipes-yaml/blob/main/Scripts_for_Uninstallers/Application-uninstall.shWe ran it on some laptops as a test, and it does remove the Malwarebytes application from Applications, but the icon still appears in the top bar, and if I click on it, it asks me if I want to restore or uninstall Malwarebytes.Can you please help me to supplement the script to make the uninstallation completely and not give users a chance to restore malwarebytes.
Does anyone know of a way to record when a mac is wiped for auditing purposes? Like SOC?
Greetings everyone,I'm curious to know if any hospital institutions have implemented Epic's MyChart or MyChart Bedside for the purpose of facilitating the signing of preoperative and postoperative consent forms.
Hey, I have a problem with my TeamViewer Installation script.The download and installation part works great, but the assignment isnt working reliable.I have followed the steps from here: https://community.teamviewer.com/English/kb/articles/50739-mass-deployment-on-macos I have added a 'sleep' and increased the '-wait' parameter, both without success.Sometimes it works, sometimes it does not. Is there a more reliable way to assign the device in TeamViewer? Here is my script: #!/bin/zsh # # Downloads and installs latest TeamViewer Host with custom configuration # Runs the TeamViewer Assignment Tool after the installation # Provide configuration details via jamf parameter:# # Parameter $4 = Teamviewer configuration ID # Parameter $5 = Teamviewer assignment API token # # Created 16. March 2021 # # # # Precheck - configuration id if [[ -z $4 ]]; then echo "$(date): No teamviewer configuration id provided." exit 1 else tv_customID="$4" fi # Precheck - assignment api
Hi so i have APN certificates expiring with a former employee who setup our devices and I created a jamf distribution email /apple id for in the future we can renew easier and if I leave someone else will be able to renew.What happens to the devices when the apn certificates expire?Will I no longer be able to see devices until I re enroll them?Thanks
Hello and thank you for taking a moment to look at this. I will try and keep it short and sweet! I am running Jamf 10.4 and am having issues getting Patch Management to display any software titles. When I go into Patch Management > New I get the following error...(A connection error occurred while attempting to download software titles from this source.) Everything else is working as far s I can tell. However, I have not used this feature before, only glanced once or twice in the past and the software at one point did populate. Am I missing something easy here or has anyone seen this before at all? I appreciate any and all suggestions, thank you!
Edit: Replaced beginning with updated Mac Studio and M2 Mac details now that i've finally gotten some in my environment to confirm.Hi all, I've gone ahead and taken the liberty to modify the existing Regex from @talkingmoose to account for the devices that are currently being listed as compatible with macOS Ventura, along with a little bit of future proofing:(^Mac1[3-9]|MacBook\\d{2}|MacBookAir([8-9]|\\d{2})|Macmini([8-9]|\\d{2})|MacPro([7-9]|1\\d)|iMacPro[1-9]|iMac(1[8-9]|2[0-9]),\\d|MacBookPro(1[4-9]|2[0-9]),\\d)This can be used in a smart group or inventory report using the criteria item Model Identifier and then selecting "does not match regex" operator. Copy/paste the regex into the value and save the Smart Group to view all mac's that ARE NOT compatible with Ventura, or set the operator to "matches regex" to see devices that ARE compatible.Let me know if I made any mistakes. Thanks all!
Hi All Community Members,We are trying to setup JAMF Teacher for use with our Teaching Staff using am issued ipad, and students using shared ipad.We have created a Teacher Group and a Student Group for use by the Students and configured them as required by the Configuration Guide. The students seem to be able to log on to the Jamf School Student fine if they are sign in to the shared ipad with their apple id, but the Teachers Cannot log on to the Jamf Teacher app. nor can they log on to the site specified via the Jamf Teacher Online URL. when i try a password reset for the Teacher Accounts we simply get the error "InvalidAuthMethod"?Any help here would be appreciated.
When using #!/bin/bash in an Extension attribute script in Jamf Pro (10.46) Jamf will error when trying to save. Not sure this has been fixed in a later version. #!/bin/zsh works fine though.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!