Get Support
Recently active
We've been testing Jamf's return to service and Remote Wipe mass action commands on our iPads and we run into some kind of bug where apps that are set to "auto-deploy" are being installed and removed multiple times during enrollment. This takes what should be a process that takes a few minutes to 20 minutes. I'm not sure if We've boinker something up in the scoping or if this is just a by-product of handling this through MDM. I don't notice the same behavior if we do a recovery mode wipe of the device through Finder.
I am testing the JAMF Safe Internet, and so far it is good.. except I need it to do something that I'm not sure it can do, or I'm not configuring it correctly.My Pre-K through 2nd students only need to access allowed websites. So if I block everything, and then put in custom rules for the allowed domains, that should work, right?Not the results I'm seeing. Things are still getting blocked by the default rules, which should be overridden by the custom allow rules?
Anyone know how to implement these from Apple? https://developer.apple.com/documentation/devicemanagement/schedule_an_os_update Any working advice would be appreciated please. Not sure if these commands are to be used in a config profile, that's my guess, but I have been unsuccessful so far. There are command and response, not sure how all this gets implemented. Please advise. Thank you ;-)
Hello All, I am very new to Jamf pro. Getting trained on it. I am looking for a policy or configuration profile which can demote the local admin user/ account to a standard one. We do not have AD. Everything controlled by Jamf proAny help would be much appreciated!!! Thanks!!
I've been having some trouble updating the iMac's to the most recent macOS patch 13.6.2 with JAMF. I usually restart the computers just before I send the remote command and I do see the series of commands queueing and completing in the computers history but then the update never goes through. I did this for around 16 of our computers that we have and its the same problem for all of them and they just never get updated. Any solution?
Hello, We are trying to deploy 80 Gen4 Apple TV's and want to use single app mode to display our logo. Are there any resources or guides on how to develop an in house app that would display a white background with our logo in the middle? I'm not an app developer so anything that I can read to help guide me to my goal would be fantastic. Thank you,Nicholas
Hello !I didn't find a suitable answer anywhere, but found the same subject: app store apps don't update on some Mac computers. What I would like is to know how can I check what happens and how Mac Apps App Store work to install and update apps. Where are the logs, when does Jamf checks an applies the updates or installations, etc... Recently, I have the problem with NFC Tools for Desktop and Microsoft Office 365 apps.What I tried is: disable then enable the Mac app, remove the scope then add it back, disable the assign content purchased in volume then enable it back too and of course a mix of everything. Of course, I save after each modification. I even tried trough the Self Service but if the app is installed, it only shows open, not update. But I think that it's how it works. And if I delete the app, it doesn't install back when I click on the button in Self Service. The scope is correct because the app appears if I switch from automatic install to Self Service.And if I let it to in
When comparing Jamf Pro with Intune, what do you miss the most about scripting when using Intune?We are a small shop and management want us to go to Intune.We do a lot with smart groups, self-service tasks and variables via policies with scripts.This won't work if I read it correctly.Any other caveats or down sides?
We are using Jamf Device Compliance with InTune.Following this tech paper we have it working fairly well. Technical Paper: Integrating with Microsoft Intune to Enforce Compliance on Mac Computers Managed by Jamf Pro 10.43.0 or LaterWhen the end user goes through computer registration and JamfAAD opens they are prompted to "Always Allow" "Microsoft Workplace Join Key". This is expected and documented here. (Although it would be great to have a smoother workflow)Our issue is the certificate in the login keychain for Device Compliance is not trusted for some reason. (See attached image)The cert seems to be issued by "MS-Organization-Access" I don't have that CA and our Azure folks don't seem to know about it either.Thoughts?Eric
Hello Everyone,I am at my wits end here and might need some more brains to figure out what the issue is. I am not fully sure if this is the right forum for this topic either, but I am giving it a try... We have set up the Device Compliance in Jamf Pro for several weeks/months now and started to slowly onboard our macs.What we did: We have a mac user group in our AD which is being synced to Azure. Created a Mac App via Jamf Catalogue to roll out the company portal to specific devices onlySet our two Smart Groups for Compliance and Applicable Macs. This checks if the Company portal is installed and applies our Configuration Profiles and Policies. Policy: run Jamf manage and apply the Microsoft Device Compliance Configuration Profile: Applies the web view (According to: https://community.jamf.com/t5/jamf-pro/jamf-intune-macos-device-compliance-mac-not-being-added-to-intune/m-p/292367/highlight/true#M260024)We also have a Microsoft SSO CP in place.&n
I would like to change the current user account name from "Administrator" to "Robert" in one mass command to all MBP's (preferably silently in the background). I think a config profile could do this but not sure how. JAMF PRO 11.1
Hello, I've created a script to to see if any employees have more than 1 mac and then tie it to an extension attritubte. I've done an API get curl to pull information from a computer advance search I've made and then assign it to a list. The list then compares to another list that pulls google chrome emails that is tied to their work email. The script is working on my end, but it does not post anything to the extension attribute. Is there anything in my script that is preventing to post? If a user has more than 1 mac, I just want it to say "yes" in the extension attribute. Any input is appreciated! Thanks in advance to everyone. user_list=() ########################################################################################## # Curl command only retrieves the email addresses of this advanced search group. # Command will api-GET the contents of the Advanced search EmailList=$(/usr/bin/curl -X GET -s -H "Authorization: Bearer $api_Token" "$jssURL/JSSRes
I have a random MacOS popup that has started.I have tried watching the mail log file to try to figure out what is causing it but nothing shows up.I have verified I do not have a virus or malware.It pops up 3 times in a row then goes away for awhile if you keep hitting cancel....but it comes back.Where else, other than the system.log can I look to figure out why this is happening?
We pushed out the standalone installers to people that didn't run the update themselves, and on some machines we noticed that Jamf is reporting it as a version lower than 17.1.2 despite the install being successful and when checking "About" within Safari it in fact shows it as 17.1.2 (or 17.2). I have an extension attribute that checks CFBundleVersion in /Applications/Safari.app/Contents/Info.plist and even that still reports the older "17615.1.26.101.8" number associated with 16.4 on Ventura.
We are having intermittent connection in Jamf today. Sometimes we get a message in Self Service that it cannot connect to the MDM server or sometimes we get an invalid username or password when logging in to it. We are also intermittently not able to see policy history in the Computer record. Anyone else reporting this?
Today we received an unexpected app drop from Cisco ID'd as "Cisco Orbital." So I'm racing to test a config profile in order to trust it in security & privacy so that doesn't prompt my end-users. Found this link which contains the info Cisco provides after taking time around mid-day today: https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/216089-advisory-for-amp-for-endpoints-mac-conne.html#anc9But I haven't had time to build it yet. If anyone out there has run into the same issue, would appreciate the feedback.
I've learned that it's possible to inject new configuration to MDM managed application using MDM so that the managed app configuration changes that are pushed down from an MDM server appear in NSUSerDefaults.This capability is described here : https://developer.jamf.com/developer-guide/docs/application-and-custom-settings Then I can add an observer to be notified of any changes occurs in NSUserDefaults.The app configuration will be stored in the following key:com.apple.configuration.managed A usage example can be look like this :if let managedConf = UserDefaults.standard.object(forKey: "com.apple.configuration.managed") as? [String:Any?] { if let serverURL = managedConf["serverURL"] as? String{ return serverURL } }However, what prevent another entity from modifying the configuration outside the MDM... as I understand NSUserDefaults are writable even from terminal so there's no limitation to just push new configuration which are unauthorized.an example of
Hi everyone, I am having some problems on Configuration Profiles for 802.1x EAP-TLS. I would really appreciate some suggestions. Currently, we are using two Configuration Profiles for the same SSID.CP1: A "Computer level" profile that obtains a computer certificate from SCEP, obviously the computer certificate is stored in the system keychain.CP2: A "User level" profile that obtains a user certificate from SCEP, which is stored in the login keychain. Before a user logs in for the first time, CP1 is used to connect to WiFi. After a user logs in, CP2 installed and authenticate again using user certificate, which changes the IP address to another vlan according to user group in AD. The problem is after reboot, there is no more WiFi connection at login window. Seems CP2 overwrites CP1 so at login window, the computer is trying to apply CP2 which uses user certificate in the login keychain that is not available before user login. I have tried the following but no luck:1. tick the box "
I'm watching the release video, I am reading the release notes, I am reading the Jamf Pro documentation page and I still don't get it - does macOS onboarding replace the current workflow for installing and running Policies, Configuration Profiles and Applications, does it delay their installation until after Self Service has started? I have some pretty...fragile workflows all depending on each other, like the installation of Company Portal and Jamf Connect at Prestage, and configuration profiles for most managed applications. Does "macOS onboarding" just toss all that out and replace it, or is this yet another way to install and launch policies, configuration profiles and applications? Or have I misunderstood completely?
Currently implementing Jamf Connect and have encountered an issue with Conditional Access. When logging in Jamf Connect displays the below error message."Access has been blocked by Access policies. The access policy does not allow token issuance."After speaking with our Azure Administrator, I'm being told the Mac is being picked up by a CA that prevents Unknown devices from connecting. The policy does allow Android, iOS, Windows and macOS devices to connect. We're seeing the Mac having no "Device info" under 'Activity Details: Sign-ins'.Device ID, Browser, Operating System are all Blank.Has anyone else seen this?
I have 2 macs that do not have the FileVault key showing in their Disk Encryption page. I set up a policy to renew these keys. When it was done executing I ran sudo jamf policy command and this error popped up. What did I miss in the policy that prevented the authentication error? Any help greatly appreciated! ?
My org has setup persistent alerts for JAMF so critical alerts (such as "You are no longer enrolled in MDM") are not missed; however we have thousands of employees getting daily persistent alerts for Chrome/Slack/Grammarly/Skype/etc app having an update available. This is a huge productivity hit in aggregate and I expect all JAMF customers are hitting the same issue. Is there any feature to be able to separate between Critical alerts and random notifications from JAMF ?
I've got a few weird things happening in JAMF, I'm assuming this is not by design. Say I create a new smart group, I give it a name, I don't scope anything to it, then save it, when I go back to the list of smart groups, the membership count is automatically 200 or more devices. That does not seem like a feature anyone would ever want, atleast by default. I've got another weird issue going on also, but we can start here.I appreciate your time and help! Have a great morning!
How are you guys handling this situation User a has a Macbook and creates Time Machine backup of all his data. This computer is enrolled in Jamf.User a gets a new MacBook and wants to transfer all of his data and settings to the new computer from his Time Machine backup. Normally (before having Jamf) he would use migration assistant to transfer his data from the old to the new computer. As far as I know with jamf it would cause to mess up the MDM profile.How do you guys handle this situation? After migrating the data just do a new self enrollment?
Hello can someone please send me pictures of how your erase-install script is set up inside of Jamf Pro. I can get the script to execute locally on the test machine, but when I try to add it via self service it will not execute.. I have the Package downloaded and added to a Policy as well as the script attached and the Execute command of: /Library/Management/erase-install/erase-install.sh --update --reinstall --cleanup-after-use --check-power ...I have tried it with just the package, I have tried it with the script and the package, and the script alone and still no success. I have read the Jamf Pro section of the script GitHub about 30 times and still can't find a solution trying to execute it on a computer with Sonoma 14. via the self service... the icon will show but when click nothing happens If you have it running Properly I would appreciate if I could get pictures because Im stumped.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!