Get Support
Recently active
Having a weird issue. After updating to macOS 12.3, right before the filevault login, I am presented with our PoilicyBanner, and I cannot click on the accept button. This is pre-OS right before FileVault login. I have to click the white text, tab, and hit return to get to my filevault login avatars. At this point, I can login and then am presented with the OS’s PolicyBanner. According to How to set up policy banners in macOS - Apple Support https://support.apple.com/en-us/HT202277 Expected behavior should be: If you use FileVault full disk encryption on your computer, the policy banner appears after the first user logs in, before the desktop appears. The first login is performed to unlock the startup disk. Present behavior: Computer startup boots to PolicyBanner that is stretched to the edge of the screen. You must click to focus and tab to Accept. Then we get FileVault login profiles. Enter password. Unit boots to PolicyBanner to check accept and continue, then to desktop.Anyone
Hi, A couple years prior to joining my current organization, they moved their On-Prem Jamf Pro to the cloud. While the JCDS is setup, it isn't the Master DP, with the master being an on-prem smb server shared between our two campuses. I plan on doing a replication and then making the JDCS the master. My question is, does it make sense to keep an on-prem distribution point?
Hello all! For many months now, the audit log for EVERY one of the computers on my instance show 'Viewed FileVault Encryption Key' with my username. I am somewhat new to JAMF but a moderate technologist generally and have recently taken over the System Admin role at my company under a lesser title. I have very rarely viewed any of these logs and it would be arduous for a human to view them as often as the logs display. To me, this log raises brows and I have reported it to my administration counter part who has a very high level title but the response is its probably just me and are not concerned at all (no reason for this, no background to share). I am planning on setting up monitoring on the instance's server with wireshark but I also plan to build a three story tree house and thought it might be a better idea to reach out here in the meantime ; -) The server instance has gone through at least three version upgrades in the last few months led by my administration counter part and unr
Hi, Is it possible to delete SSIDs via script that have not been connected to over 30 days? if so, can someone assist? We are trying to see if we can make a self service policy so employees can execute it as needed Thank you,
Trying to distribute an in-house app with a .ipa file. The salesman who pitched JAMF Pro assured us multiple times that we did not have to have a paid Enterprise Developer program with Apple. I'm starting to think they were wrong.Does anyone have any experience generating a provisioning profile without going through Enterprise? Will AD-Hoc distribution work?I am the developer for the app.
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 11.1.3 fixes the following product issues: Jamf Pro Server: Security Issues [PI115630] Updated the Jamf Pro installers to include Tomcat 8.5.96 to mitigate a known vulnerability (CVE-2023-46589). Jamf Pro Server [PI115037] When computers or devices are enrolled in environments with enrollment customization and SSO configured, the Click here to proceed with enrollment button on the final enrollment pane was replaced with a progress bar that says, “Downloading MDM profile”. This change prevents failed enrollments. [PI115634] Computer configuration profiles with a Security and Privacy payload no longer lose configured settings, causing blank or null values in the os_x_configuration_profiles database table. As a result, Jamf Pro no longer sends repeated configuration profiles with unique identifiers to the computers in scope. For additional information on what's included in this release, review the release notes
Hi all. We have a local Jamf Pro server. Anyone know what to look for in the log file to find the date and time a Jamf Pro update was done?
I've had some free and paid Mac Store Apps setup for distribution for a long time and for a long time they have worked just fine. Now, all of a sudden, they're not always installing on a newly enrolled iMac. Is there any way to trigger an automatic install of Mac Store Apps?
I am trying to set up Single Sign-On for Generic OpenID Connect using Duo Mobile. I have configured Jamf connect to talk to Duo and after logging into the MFA it asks to sync the network password with the local account but i get an error message that the requested grant type "password" is not supported. Has anyone got duo Mobile to work with Jamf connect?
Hi All!We are experiencing problems with access to the "VPN & Device Management" menu.We use an app called Zscaler that creates a VPN configuration to protect and filter all connections from each device (iPad).Our high school student users are breaking our settings by removing the VPN profile so they can freely browse outside of the filtering.We want to restrict the use of this menu to prevent users from being able to modify the security presets established for the use of educational devices.
looking to the community for recommendations on keeping tabs on Apple updates.My org is strict about keeping things up to the latest version within 30 days.What sites/ RSS feeds, etc do you use to track upcoming updates?
We are a school district with staff setup as standard users on their Macbooks. We do not allow the App Store because, by law, we have to approve apps to protect student data. I just found out today that our M1 Macbooks that have been updated to MacOS Sonoma are completely bypassing any "Restricted Software" settings in Jamf. So users that update are able to open terminal, the App store, etc. even though the restrictions are setup and were working on Ventura. We are on Jamf version 10.49.0 so I don't believe the update is the issue. Any suggestions are appreciated!
Hi All, I'm looking at deploying Android Studio through Self Service for non-elevated users. I've uploaded the dmg file, and written a script to move the .app file to /Applications on each users machine. The package is dependent on JVM, so I've also packaged the JDK and have deployed that. My current challenges are: Once deployed, users are prompted with a message that this application was downloaded from the internet. I've tried using the spctl to add a label but to no avail... #!/bin/sh spctl --add --label "Android Studio" "/Applications/Android Studio.app" spctl --enable --label "Android Studio" On the first launch of Android Studio, the application downloads and installed supporting artefacts. One of these requires elevated rights... Has anyone packaged Android Studio and is able to provide any tips? Thanks, Jaems
Hi there,Recently, I have to publish some pdf by using eBook module. I have done this before many times without problem. However, I got "availabiltiy pending" message under the eBook entry I've made and the pdf won't publish to the iPads that I have included in scope. The status keeps pending. Please help. Thanks.Gary
Hey Everyone,I am trying to disable Edge updates via MAU, but they keep going through MAU and its conflicting with Jamf App Installer updates, specifically around re-opening the app after an update. The process just hangs and never fully re-opens, you can't quit the app via the dock either, it needs to be Force Quit from the Menu Bar option. I am using the most recent MAU 2.0 and Edge isn't even an option anymore. I disabled the EdgeUpdater updates via keystone and set the MAU option to disabled on the Edge config profile. My old MAU profile had Edge Updates set to change freeze and they still occurred. Any ideas?
Hello everyone, I am just wondering if there is a script out there for iOS which I can roll out in the app config, which will auto fill the "hostname" for filemaker go 19? This would be a massive help if there is due to having over 1.7k devices on site. Or if anyone knows where i can get the plist config for filemaker go 19 I have gone to the location for it, but cant seem to find it! <home>/Library/Preferences/ Any help would be great CheersChris.
Hello,While testing Jamf App catalogs apps via self-service, I noticed that if the app is deleted from a Mac, the deployment status in the App catalog does not change, and it still shows as installed. While going through the FAQs, I noticed that it mentions that the app will not re-install, but when the new version is released, it will be installed back on.My question is, does that only apply to apps set to auto-install, or does it work the same way for apps installed via self-service?
Guys,We are using systrack for end point analytics on Macs. Post installation of Systrack agent, we configured profile in Jamf pro of lsiagentd to get allowed on full disk access. After successfully sync between Jamf and device, profile getting installed successfully, but under 'Privacy and Security' it's not getting enabled. Kindly advice.We tried with bundle id as well as path, no luck. Below is the code requirement we received from systrack.identifier "com.lakesidesoftware.lsiagentd" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = SQL6SRUA2Y
Hi All,I have created PPPC Utility as suggested in Systrack Documentation for giving Full Access to Disk.However, after pushing the configuration profile to the device I am see that the settings in the Security and Privacy - Full Disk Access - Isiagentd has not changed. Anyone can help me on how can I enable teh full disk access or what is missing in PPPC settings.Thanksrecommended setting by Systrack - Enterprise Deployment Through MDM (lakesidesoftware.com)Attaching screenshots from JAMF and device
Hey everyone, I recently got passed handling our Netskope deployment. My predecessor claims that with the v71 client, due to us using Azure AD for our IDP we cannot auto populate the tenant information. Basically once the install finishes we get a popup where we have to input our company name. I know there has to be a way around it, anyone have any familiarity with it?
Hi,Recently, I've been doing some cleanup work with our jamf pro instance and have gotten to printers. We have around 15 Konica Minolta BizHub 554e/754e's that our macs direct print to using LPD. Another admin has one giant AppleScript used to add all applicable printers, but I feel like there has to be a more efficient way. I've played around with Jamf Admin mapping, and it works fine; however, it seems like scripting might be the way to go. Does anyone have any advice or a good script they can share?
Hello, is there a way to sync Sharepoint online libraries in OneDrive on Mac computers using a script/jamf? Thank you!
Hello, I want to enable 'Lost Mode' for a lost device. I cannot find this option in 'Management Tab' for the concerned device. This option is also missed for other iOS devices. Any idea how to troubleshoot that? Thanks
How can I create a Patch Management Rule to distribute Safari for macOS Monterey and for macOS Ventura Clients? The Patch Management Policy does not offer an option for both systems. I created one for the Ventura Clients which is scoped to a Smart Group, but how can I setup a second one for the Monterey Clients?
Hell Team, I am looking for a solutions to get the recovery key in my JAMF console for those mac devices recovery key is missing, but user should be interrupted. I can see it has happened for both personal and institutional key. What is the main concept of personal recovery key validation, some time it is showing invalid or unknown but recovery key is there, strange! Please help to understand and also with a perfect resolution I am looking for. BTW device is getting encrypted by a config profile and to escrow the key in JAMF.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!