Get Support
Recently active
Hi everyone, I'm having a somewhat urgent issue with 46 instructor desktop machines at our college. Somehow a configuration profile that was scoped to these machines created another random profile called 'General' that keeps replicating over and over, reaching 3900 unique ID installations of the same profile name on each of the desktops. I've never seen this before, and other than removing the scope I haven't been able to stop it trying to create more and more General profiles. It's causing users not to be able to log in, and reboots are taking 15-20 minutes even on new M2 Mac desktops. It's happening on Monterey and Ventura OS, Intel and Silicon. Anyone seen this before? Hoping I won't have to rebuild each of these machines.
Hello, Has anyone discovered a way to enable this setting for exchange accounts? This would be helpful for all shared mailbox access but also for manager access of termed employees. Attempted a simple AppleScript with no joy. Thank you,
This is sort of in regards to the issue of being unable to upgrade Shared iPads seemlessly to iPadOS 17 as per https://support.apple.com/en-ca/105058. I'm looking into how iPads by default receive and apply updates. I understand there is a restriction profile that can be applied to defer software updates for up to 90 days according to https://support.apple.com/en-ca/guide/deployment/depd30715cbb/web. The way I read it is that the 90 days takes effect from when the software update, in this case iPadOS 17, is released and not from when the deferral policy is pushed out. iPadOS 17 was released September 18, 2023 so 90 days from that date would be December 17, 2023. So I'm wondering what's going to happen in regards to our Shared iPads updating. After December 17, 2023 will iPads automatically start updating on their own? What will happen if I apply a deferral restriction configuration profile? Will it even make a difference? We are sitting down this coming We
Hi guys, We have has a couple of users determine that company portal stated "device is not managed" when they were on macOS 14.1.2.... BUT when they updated to 14.2 they were fine. Our compliance in jamf is set to 14.1.1 and above so that isnt the issue here. Has anyone else seen this? it would help greatly!
I’m trying to push a default browser as an initial setting for the first time that a user logs into their machine. I’ve currently got a package working that installs a preconfigured com.apple.launchservices.secure.plist to each user’s ~/Library/Preferences/com.apple.LaunchServices directory. Right now that package works properly to set the default browser once each user has logged out and then logged back in but I haven’t been able to figure out which service I need to reload in order to get this to work as soon as the .plist is first installed. Ideally the sequence of events would be:1) User logs in for the first time2) My preconfigured .plist is installed3) A postinstall script loads the newly installed .plist and sets the default browser immediately I pulled the command :/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -kill -r -domain local -domain system -domain userfrom this script https://gi
Subject really says it all. None of my apps will install anymore. Other remote commands work just fine (e.g. wipe device). Any insight?
Hello I am dealing with a strange issue. We are testing Jamf Connect and on my test machine when I get up to the step that says "your okta password does not match your local account" It does not take my new Okta password I just had created for some reason it is taking my old Okta password.
Hello Jamf Nation! We recently released tamper prevention for Jamf Protect. Tamper prevention safeguards the Jamf Protect application from being modified, disabled, or deleted without authorization. Product Documentation For additional information, see Tamper Prevention in the Jamf Learning Hub. Thank you,The Jamf Protect team
hello all, im trying to fix a compliance error from jamf protect where you need to enable filename extensions does anyone know of a way to do this using a profile/ policy.
We are using Dockutil along with this script to place an smb file share icon in the Dock. This is working just fine/usr/local/bin/dockutil --add smb://fs1.vcs.local/File Shares --label "File Shares" --position end What I want to do is check whether this item is in the Dock or not before running this command. Is there an Extension Attribute (along with a Smartgroup) to check if an item is already in the Dock?
Some of my employees are using Chromium based browsers like Arc or Brave.I'd like to have the ability to push browser extensions to all browsers used by my employees.Do you know if I can push extensions to Arc or Brave? If not, is it planned?
I've taken the introductory classes on Jamf Protect / Radar and gotten it setup. So far it seems okay, I have it on about a dozen machines. It shows installed, they show up in protect as active, seems to be working. Today on my main test unit, I've noticed I can hit I can't hit our print server due to being unable to authenticate. I also then see I can't see our network printers. I've seen it happen where its lost its trust relationship with AD, so I remove from domain, then try to rejoin. But it can't authenticate there either. Multiple reboots, different browsers, different accounts. Same thing.I start to assume maybe its Jamf Protect, but I connect to another unit that has it, and I'm able to hit the website and see the printers. So it seems just the first device affected. I try using VPN, connecting to wifi instead of ethernet, yet still same issue. No website, no joining domain. I device to wipe and rebuild, once protect is on it, same issue again. I then remove Jamf Protect. I'm
I work for an MSP and one of our clients is a school with around 150+ iPads over multiple campuses.We've recently made the move from Meraki to jamf and with 115 of them sitting in various states of OS versions, I don't seem to be able to get them past the update scheduled stage without getting hands-on with it and manually installing it.They're set to allow automatic checking for updates and scheduled times are outside of school hours. Pushing the install doesn't seem to override this and in a lot of instances, the OS doesn't seem to autonomously update as expected during the set time frame.
Why or how does the “Clear Parent Restriction” work?We have found that as soon as the function is triggered via Jamf Portal, the student iPad loses the set restrictions of the parent app, but shortly afterwards the set restrictions of the parent app on the iPad apply again.And then you ask yourself, why doesn't the information arrive on the parent app that the "Clear Parent Restriction" command has now been triggered via Jamf?This means that the restrictions of the parent app always intervene.Is this a bug or was it not thought through? Or thought differently?What experiences have you done? Would that be a feature request?CheersPeter
I am having a very strange issue with an AD bound Mac that I am not sure why its happening or how to fix it. We have a user running a 2016 MacBook Pro 15" running 10.13.3 that is bound to our AD domain using the directory bind utility and up until recently have had no issue with it. But in recent weeks anytime this user reboots the machine, whenever he attempts to login to his AD account from the login screen his password is not accepted. But strangely after logging into a local account and logging back out the user is able to type in the same password that wasn't working before and it will allow them to authenticate. This happens regardless if the user is connected to the network or not. Their network account is configured as a mobile account so they didn't need to be connected to the network in order to login. They are also added to the FileVault user list of people that can unlock the drive. We are not sure why this is happening and cannot find anything definitive in the system logs
Purpose: I want to name the iPads to the users real name.I have "Enforce Mobile Device Names" checked in prestage. I run an API script which changes the iPads name in JAMF. The mobile command is sent to the iPad and the name is changed locally on the iPad. So far so good... but.. At the next inventory update the iPads name reverts to the standard name defined by Pre-stage. Is this really expected behaviour? I thought that the name set in JAMF was the master name. Any ideas, grateful for all/any help.
I would like to add URL's to self service to be on the left hand corner of the page when a user opens self service is there any way I can do this on Casper? Thanks!!Nicholas
We had a number of users who came in with the same issue. After inputting their password they get stuck with the loading bar and never progresses (image provided). I have been thinking it is a Filevault related issue? Has anyone encountered something similar to this? \\\\
Hello everyone! I can't seem to find information on the subject and I would like to better understand mobile devices that are Personally Owned versus Institutionally Owned. Thank you all.
Does anyone know if there is a way to turn off the keychain so it doesn't prompt users to save passwords or offer to generate passwords when they are in web browsers? We have some shared lab machines and classroom machines that have to be accessed by many and we don't want people to accidentally choose to save passwords for their o365 or other web-based logins. it would be a happy place if that little lock just wasn't there at all in Safari, Chrome, Firefox, etc. Are there any MDM settings or tricks we could use to deploy soemthing to acheive this.
Hello,can someone confirm that the "web content filter" is broken in IOS 16.4.1?Only Blacklist seems to work.(My testing device worked fine on iOS 16.x before the update)Edit: Device = iPad 8. Gen 128G/Wifi/cellthanks,-Sebastian
Guys, is there a script to remove the "old" microsoft teams from the macs using jamf? Is there a script? Or a removal tool?
I need to remove a lot of scripts from my Jamf Pro server. I inherited this Jamf Pro server from the person who held my position before. He didn't leave behind any documentation. To speed up the process I need to find out what scripts are actually in use. I want to remove all of the unused scripts. I will save them somewhere in case any of them are needed later. I looked around for some ideas but none that I could find posted here worked. Does anyone have a good way of doing this?
Hi, I'm seeing a very odd issue when using JAMF Connect with Azure/Entra accounts with Uppercase letters in the UPN. Users with a UPN that is in a format like User.Name@Microsoft.com will be prompted to enter admin credentials to setup touch ID and some other setup assistant items which they can't as they are standard users. Also any scripts that need to be run as the user, for example a dockUtil script, will throw up errors that "user.name is not in the sudoers file" and the script will fail. Users with a UPN like user.name@microsoft.com work absolutely fine. Setup assistant runs fine and all and any scripts run perfectly even with the user being a standard account. Has anyone else seen issues like this? A work around is to set all UPNs to lowercase and the problem goes away but I want to know why this is an issue?! All user details are created exactly the same if logging in with upper or lower case so theres no clear difference between accounts created with upper or lower.
We are trying to enable Remote Assist, but it's generating an error. "An error occurred while saving the changes. See JAMFSoftwareServer.log for more details."Examining the log file only shows the following information:023-12-04 16:33:05,305 [ERROR] [hread-18473] [HTMLResponse ] - An unhandled exception occurred during a save operationjava.lang.StringIndexOutOfBoundsException: begin 0, end 2, length 0at java.lang.String.checkBoundsBeginEnd(String.java:3319) ~[?:?]at java.lang.String.substring(String.java:1874) ~[?:?]at com.jamfsoftware.jss.objects.computer.ComputerHelper.isSelectedOSOrLater(ComputerHelper.java:5053) ~[classes/:?]at com.jamfsoftware.jss.service.predefinedprofile.install.PredefinedProfileDao.mapRowIfCorrectBuildNumber(PredefinedProfileDao.java:43) ~[classes/:?]at com.jamfsoftware.jss.service.predefinedprofile.install.PredefinedProfileDao.lambda$findComputersWithoutProfile$0(PredefinedProfileDao.java:32) ~[classes/:?]at org.springframework.jdbc.core.RowMapperResultSetExtr
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!