Get Support
Recently active
Few macs are not encrypted as per JAMF console but JAMF is showing me their individual recovery key, how it is possible, do you think those are false key for those macs or macs are encrypted but showing me false info as not encrypted? In this case what is the solutions?
(Apologies in advance for the long post) Upon seeing the news of Jamf Pro 11 and the new versions of JAMF 200, 300, 370, and 400 classes and certifications, I have a bunch of thoughts and questions. For further context, I currently have Jamf Pro 10 versions of my Jamf 100, 200, and 300, also a flavor of 170 that still has the resulting certification named as "Jamf Certified Endpoint Security Associate" and (with my certification stored in SkillJar and not Credly). First off, while I appreciate that validity periods make sense for a product that (even throughout version 10, alone) was and is constantly evolving, spending $2500 every three years on keeping certifications current seems like a hard sell in this economy. I can't even fathom $4500 for the training pass every three years (whereas it was a no-brainer the last time I did it). Does anyone know if there will be (more affordable) renewal courses or exams that one can take shortly prior to the end of the
I work for an MSP and one of our clients is a school with around 150+ iPads over multiple campuses.We've recently made the move from Meraki to jamf and with 115 of them sitting in various states of OS versions, I don't seem to be able to get them past the update scheduled stage without getting hands-on with it and manually installing it.They're set to allow automatic checking for updates and scheduled times are outside of school hours. Pushing the install doesn't seem to override this and in a lot of instances, the OS doesn't seem to autonomously update as expected during the set time frame.Is there a command or function to FORCE/override the scheduled update for the installation of new OS? It's school holidays, I don't want to spend the next 2 months checking the portal daily, taking inventory of what refuses to work.
Hi,I have recently generated and pushed a new Local Admin account which successfully deploys however I am unable to immediately sign in with this account until I manually enable filevault access.The account is being pushed to an already setup device and in the Policy I have enabled Allow user to administer computer and Enabled user for FileVault 2 however this does not appear to apply the FileVault access I need and no error appears in logs to indicate why.Can anyone advise on what I may of missed or should try next?
Saw this in the changelog for the Jamf Pro API -- anyone know what this is? I tried googling "Jamf Pro Scheduler," but the only results were bringing me back to the API documentation.
Greetings. Wanted to know if anyone was able to install Microsoft Visio through JamfPro?
I'm using Jamf Pro with some Macs and for some reason I have trouble getting a few M365 apps to update; specifically the Mac App Store versions of Microsoft Word, Excel, and Powerpoint. Interestingly, the Mac App Store versions of Outlook and OneNote update fine. I know the apps having issues are larger sized, but they should still work. I have tried removing and adding the apps to Jamf, removing the VPP option, and a few other things. I have also read about others having the same issue with Mac App Store M365 apps not updating.Anyone experiencing this issue? Any suggestions on how to solve the issue?
Are you loving the Jamf Learning Hub but would like to learn how to use its features and dive deeper into why this is an excellent resource for our product technical content? Well, look no further! This short video will show you how to use the basic and more advanced features of the Jamf Learning Hub. And for those who did not see the recent announcement, The Jamf Learning Hub provides technical documentation, learning opportunities, and resources for all of our Jamf products.
Congratulations, India Mac Admins user group and group leader @Samstar777, on their first anniversary! This is an outstanding achievement, and your success in hosting engaging meetups and cultivating an active group on Jamf Nation is no small feat. Well done, @Samstar777, and all India Mac Admin user group members! If you would like to create a user group on Jamf Nation, you can request one here or message me, and we can chat about how to get started. 😀
Hello this is my first posting.I have an issue on one of our iMac, I tried to re-enroll and install MDM profile but says cannot install the profile. tried to remove is using "sudo JAMF removeFramework" but says "command not found!" tried to checked the but no "JAMF" folder exist. MDM profile exist in System Preferences.Is there a way to manually remove the MDM Profiles?
Hey All,First time poster so be kind :-)Setting up a Jamf Pro solution whereby we are setting up ADE enrolment for new device but also migrating devices from a different MDM vendor solution. Solution Jamf Pro integrated with EntraID/Azure for cloud IdP and also SSO to entra, Jamf Connect is being used. Devices are off corp network and have no direct sight of on premises AD i.e no Kerberos.Migrated device have local mac accounts that use the sAMAccountName (which is being mapped to EntraID (OnPremisesSamAccountName). I have configured the SSO and Cloud IdP Entra Mappings for the migrated devices so that during enrolment the device populates the User and Location inventory with all the user info. As most devices will migrate initially this is currently more important than the workflow for new device enrolments. We are migrating Macs using Jamf Migrate tool as an FYI.However, so the issue we face is with new enrolments in that they take the email/UPN as the local account name firstname.su
So I have an App that needs deploying on a group of shared iPads used by our students, within the plist file xml that's added to the apps respective config tab, there's a UniqueDevID key which I would want to pass a variable to at install.The most obvious variable would be the devices name as specified in Jamf. How could achieve this?
Hi all,I've got someone with a 2015 iMac with Monterey 12.6 installed, trying to install MDM on it. We are able to download/install the CA profile but when trying to install the MDM profile it errors (profile installation failed an error occurred while trying to import the certificate or identity). It had been up for a fair few weeks and I thought a restart would fix it as it usually does but it didn't. It has Sophos installed, we disabled it and tried again but still no go. We updated to Montery 12.7.1 which I think is the highest it will go. Any ideas why it won't install?
we have been deploying new M1 macbook air machines since July. we changed our deployment workflow this year to use a workflow in MDS to deploy the os (big sur) and packages (instead of pushing packages/policies over the air through JAMF). we skip the setup assistant and enroll into mdm through user enrollment.we haven't had any issues except that recently our users started getting the device enrollment notification saying that our organization can automatically configure their mac... even though they have the mdm profile installed and we're actively managing machines through JAMF. has something changed in big sur where this is now expected behavior? i should hope not... any insight would be appreciated.
Hello everyone,I am wondering what they proper way is to set up the following....I'd like to allow folks to login with their personal Apple IDs to use iMessage and to be able to connect their AirPods to their MacOS computers but then restrict everything else in iCloud (iCloud Photos, iCloud Drive, Find My, etc.). I see where you can apply iCloud restrictions via Configuration Profile but not sure if applying these also conflict with allowing the aforementioned items I'd like to leave open. Thanks in advance.
Hey Everyone, I know how secure tokens work, I know how to give them out. I have a particular question about having them automatically enabled without having to log into the account manually on each machine. I have it enabled so that every account can have a secure token, when they login. The issue I'm having, is my Local Administrator account.I have my management account as JAMFADMIN, and my local administrator is just "administrator". That's the account I use to reimage machines and do maintenance/updates. As we know, M1 machines need to have the account doing updates/OS installs to have a secure token. I have this account being made on Enrollment, so it should get one. The account is on the machine, but if I do a remote command to do an update, the secure token isn't enabled until I physically go to the computer and log into the account. Then it's available. Does anyone know how to make this token appear, without logging in?If anyone needs any other information, pleas
I just got autopkgr installed and it's copying the built packages to my distribution point. What it's not doing is creating a policy. I've checked that the account has the privileges specified in the readme. I don't see anything helpful in the logs. Anything else that I can check? The category already exists in Jamf, so it should just show up in the category?
Am am trying to secure our jamf pro portal but cant seem to find any documents on this and cant see anywhere to add it in JAMF pro, has anyone secured there logins with 2fa
I have a script that will do the following: Create a local account based on admin pop-up box and rename the mac to this username-last4ofserial#. The account that is created is in LDAP format and is the user that I would assign in JAMF console in the user location field. I have LDAP fully set up in JAMF pro how can I make an API call to grab the username from the user account or the computer name and update the user location fields in JAMF pro console?
As it is the holiday season, I wanted to offer up a little gratitude in the form of boilerplate code related to topics that come up in the macadmins #scripting & #bash channels again & again. I hope people find it here & find it useful. 1) Logging is always a hot topic. "How do I create a log for my script?" "Where should I write log output?" etc. Without saying this solution is definitive, the script below has a pattern that I have used over & over. In fact, I paste this block exactly into any script I create that needs logging. It uses tee along with exec & with a named pipe. Why? Well, I find this works in all situations to capture all foreground & background processes executed by the script & it creates a dedicated stream / file for the log output regardless of what the script is trying to do. 2) Jamf API. I said in an earlier post I had come up with the shortest, bestest version of making an API call with token auth. I was wrong. I made it shorter
Hello,Posting to the Jamf Community for the first time so I hope I'm in the right place :) We use Jamf Pro to manage MacBooks and iPhones. These devices are corporate devices and registered with Apple Business Manager. The MacBooks and iPhones have been successfully registered and they now also appear within Microsoft Entra as 'Entra Registered'. This was achieved by getting the staff member to log into the Microsoft Entra app on their iPhone and MacBook.Is it possible to have these iPhones and MacBooks appear within Microsoft Entra as 'Entra Joined' instead of 'Entra Registered'.'Entra Joined' means they are corporate owned devices.'Entra Registered' means they are personal/BYOD devices.
Good Morning/Afternoon,I'm trying to add a Sub-Menu with some common links that our staff and students use. I got the menu to show as "Actions." Shouldn't I be able to name it "RBS Links" using the MenuText key? Am I not placing it in the correct spot?See plist:<plist version="1.0"><dict><key>Actions</key><array><dict><key>Action</key><array><dict><key>Command</key><string>url</string><key>CommandOptions</key><string>REDACTED</string></dict></array><key>Name</key><string>Launch LMS</string></dict><dict><key>Name</key><string>separator</string></dict><dict><key>Action</key><array><dict><key>Command</key><string>url</string><key>CommandOptions</key><string>REDACTED</string></dict></array><key>Name&l
Hi,I'm reaching out to see if anyone has found a way to enforce the Do Not Disturb feature while driving. We are trying to limit employees from texting or emailing while driving. Does JAMF Pro allow for this? If not, have you heard of other apps that would reach the same results?
Hello everybody,I’m quite new to all this JAMF settings and configurations.In the next weeks I will have to roll out new iPads to our teachers to replace their 5 years old 32GB iPads with the newer 64GB devices.Old and new devices are/will be managed with JAMF School.Is it possible to setup the new iPads by using proximity setup as you would do on a private iPhone when switching to a newer iPhone?Thanks for your helpGerard
Dear allWe have been using personal iPads for students for a couple of years now, managed with Jamf School. Lots of teachers regularly restrict the functionality of student iPads, especially during tests. However, during exams, things are organised differently: students are put together in large places, such as the sports hall. In those circumstances, restrictions are sent to more than 250 students, with a time limit of several hours.While this procedure works in smaller groups, there are lots of delays and failures in larger groups. Furthermore, the time limit is not always working: often we receive calls or mails from students at home, complaining that their device is still restricted.Does anybody know of any limits to the number of iPads/devices to restrict with Jamf Teacher? Are there best practices you know of, that might impact this situation?Thanks!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!