Get Support
Recently active
Hi guys, We have has a couple of users determine that company portal stated "device is not managed" when they were on macOS 14.1.2.... BUT when they updated to 14.2 they were fine. Our compliance in jamf is set to 14.1.1 and above so that isnt the issue here. Has anyone else seen this? it would help greatly!
I’m trying to push a default browser as an initial setting for the first time that a user logs into their machine. I’ve currently got a package working that installs a preconfigured com.apple.launchservices.secure.plist to each user’s ~/Library/Preferences/com.apple.LaunchServices directory. Right now that package works properly to set the default browser once each user has logged out and then logged back in but I haven’t been able to figure out which service I need to reload in order to get this to work as soon as the .plist is first installed. Ideally the sequence of events would be:1) User logs in for the first time2) My preconfigured .plist is installed3) A postinstall script loads the newly installed .plist and sets the default browser immediately I pulled the command :/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -kill -r -domain local -domain system -domain userfrom this script https://gi
Subject really says it all. None of my apps will install anymore. Other remote commands work just fine (e.g. wipe device). Any insight?
Hello I am dealing with a strange issue. We are testing Jamf Connect and on my test machine when I get up to the step that says "your okta password does not match your local account" It does not take my new Okta password I just had created for some reason it is taking my old Okta password.
Hello Jamf Nation! We recently released tamper prevention for Jamf Protect. Tamper prevention safeguards the Jamf Protect application from being modified, disabled, or deleted without authorization. Product Documentation For additional information, see Tamper Prevention in the Jamf Learning Hub. Thank you,The Jamf Protect team
hello all, im trying to fix a compliance error from jamf protect where you need to enable filename extensions does anyone know of a way to do this using a profile/ policy.
We are using Dockutil along with this script to place an smb file share icon in the Dock. This is working just fine/usr/local/bin/dockutil --add smb://fs1.vcs.local/File Shares --label "File Shares" --position end What I want to do is check whether this item is in the Dock or not before running this command. Is there an Extension Attribute (along with a Smartgroup) to check if an item is already in the Dock?
Some of my employees are using Chromium based browsers like Arc or Brave.I'd like to have the ability to push browser extensions to all browsers used by my employees.Do you know if I can push extensions to Arc or Brave? If not, is it planned?
I've taken the introductory classes on Jamf Protect / Radar and gotten it setup. So far it seems okay, I have it on about a dozen machines. It shows installed, they show up in protect as active, seems to be working. Today on my main test unit, I've noticed I can hit I can't hit our print server due to being unable to authenticate. I also then see I can't see our network printers. I've seen it happen where its lost its trust relationship with AD, so I remove from domain, then try to rejoin. But it can't authenticate there either. Multiple reboots, different browsers, different accounts. Same thing.I start to assume maybe its Jamf Protect, but I connect to another unit that has it, and I'm able to hit the website and see the printers. So it seems just the first device affected. I try using VPN, connecting to wifi instead of ethernet, yet still same issue. No website, no joining domain. I device to wipe and rebuild, once protect is on it, same issue again. I then remove Jamf Protect. I'm
I work for an MSP and one of our clients is a school with around 150+ iPads over multiple campuses.We've recently made the move from Meraki to jamf and with 115 of them sitting in various states of OS versions, I don't seem to be able to get them past the update scheduled stage without getting hands-on with it and manually installing it.They're set to allow automatic checking for updates and scheduled times are outside of school hours. Pushing the install doesn't seem to override this and in a lot of instances, the OS doesn't seem to autonomously update as expected during the set time frame.
Why or how does the “Clear Parent Restriction” work?We have found that as soon as the function is triggered via Jamf Portal, the student iPad loses the set restrictions of the parent app, but shortly afterwards the set restrictions of the parent app on the iPad apply again.And then you ask yourself, why doesn't the information arrive on the parent app that the "Clear Parent Restriction" command has now been triggered via Jamf?This means that the restrictions of the parent app always intervene.Is this a bug or was it not thought through? Or thought differently?What experiences have you done? Would that be a feature request?CheersPeter
I am having a very strange issue with an AD bound Mac that I am not sure why its happening or how to fix it. We have a user running a 2016 MacBook Pro 15" running 10.13.3 that is bound to our AD domain using the directory bind utility and up until recently have had no issue with it. But in recent weeks anytime this user reboots the machine, whenever he attempts to login to his AD account from the login screen his password is not accepted. But strangely after logging into a local account and logging back out the user is able to type in the same password that wasn't working before and it will allow them to authenticate. This happens regardless if the user is connected to the network or not. Their network account is configured as a mobile account so they didn't need to be connected to the network in order to login. They are also added to the FileVault user list of people that can unlock the drive. We are not sure why this is happening and cannot find anything definitive in the system logs
Purpose: I want to name the iPads to the users real name.I have "Enforce Mobile Device Names" checked in prestage. I run an API script which changes the iPads name in JAMF. The mobile command is sent to the iPad and the name is changed locally on the iPad. So far so good... but.. At the next inventory update the iPads name reverts to the standard name defined by Pre-stage. Is this really expected behaviour? I thought that the name set in JAMF was the master name. Any ideas, grateful for all/any help.
I would like to add URL's to self service to be on the left hand corner of the page when a user opens self service is there any way I can do this on Casper? Thanks!!Nicholas
We had a number of users who came in with the same issue. After inputting their password they get stuck with the loading bar and never progresses (image provided). I have been thinking it is a Filevault related issue? Has anyone encountered something similar to this? \\\\
Hello everyone! I can't seem to find information on the subject and I would like to better understand mobile devices that are Personally Owned versus Institutionally Owned. Thank you all.
Does anyone know if there is a way to turn off the keychain so it doesn't prompt users to save passwords or offer to generate passwords when they are in web browsers? We have some shared lab machines and classroom machines that have to be accessed by many and we don't want people to accidentally choose to save passwords for their o365 or other web-based logins. it would be a happy place if that little lock just wasn't there at all in Safari, Chrome, Firefox, etc. Are there any MDM settings or tricks we could use to deploy soemthing to acheive this.
Hello,can someone confirm that the "web content filter" is broken in IOS 16.4.1?Only Blacklist seems to work.(My testing device worked fine on iOS 16.x before the update)Edit: Device = iPad 8. Gen 128G/Wifi/cellthanks,-Sebastian
Guys, is there a script to remove the "old" microsoft teams from the macs using jamf? Is there a script? Or a removal tool?
I need to remove a lot of scripts from my Jamf Pro server. I inherited this Jamf Pro server from the person who held my position before. He didn't leave behind any documentation. To speed up the process I need to find out what scripts are actually in use. I want to remove all of the unused scripts. I will save them somewhere in case any of them are needed later. I looked around for some ideas but none that I could find posted here worked. Does anyone have a good way of doing this?
Hi, I'm seeing a very odd issue when using JAMF Connect with Azure/Entra accounts with Uppercase letters in the UPN. Users with a UPN that is in a format like User.Name@Microsoft.com will be prompted to enter admin credentials to setup touch ID and some other setup assistant items which they can't as they are standard users. Also any scripts that need to be run as the user, for example a dockUtil script, will throw up errors that "user.name is not in the sudoers file" and the script will fail. Users with a UPN like user.name@microsoft.com work absolutely fine. Setup assistant runs fine and all and any scripts run perfectly even with the user being a standard account. Has anyone else seen issues like this? A work around is to set all UPNs to lowercase and the problem goes away but I want to know why this is an issue?! All user details are created exactly the same if logging in with upper or lower case so theres no clear difference between accounts created with upper or lower.
We are trying to enable Remote Assist, but it's generating an error. "An error occurred while saving the changes. See JAMFSoftwareServer.log for more details."Examining the log file only shows the following information:023-12-04 16:33:05,305 [ERROR] [hread-18473] [HTMLResponse ] - An unhandled exception occurred during a save operationjava.lang.StringIndexOutOfBoundsException: begin 0, end 2, length 0at java.lang.String.checkBoundsBeginEnd(String.java:3319) ~[?:?]at java.lang.String.substring(String.java:1874) ~[?:?]at com.jamfsoftware.jss.objects.computer.ComputerHelper.isSelectedOSOrLater(ComputerHelper.java:5053) ~[classes/:?]at com.jamfsoftware.jss.service.predefinedprofile.install.PredefinedProfileDao.mapRowIfCorrectBuildNumber(PredefinedProfileDao.java:43) ~[classes/:?]at com.jamfsoftware.jss.service.predefinedprofile.install.PredefinedProfileDao.lambda$findComputersWithoutProfile$0(PredefinedProfileDao.java:32) ~[classes/:?]at org.springframework.jdbc.core.RowMapperResultSetExtr
Hello all I am blocking Macos Sonoma beta with two different restricted software setups, one is Install macOS Sonoma beta.app and the other is "Install macOS 14 beta.app" Im using both just to be safe and make sure I catch the installer . With the production relase of MacOS Sonoma around the corner I was wondering if anyone has setup their environment to block macos sonoma already. Im looking for the process name Thank you again
Hey all,Is anyone else seeing this message when users try to add a new wifi network or change an existing wifi network? My only guess is a user is clicking through Control Center instead of just using the wifi menu drop down, but i've had 2 users show me this message so far. 13.5 is the MacOS version we are seeing this on.
hi,So we have a custom pkg file that is used to set up a common shared printer. we have no control over the contents of the .pkg file but it seems to need admin access when installed interactively.When we try to deploy the .pkg via self service (as a jamf policy), it fails and looking in the logs, it is complaining that it needs rosetta 2 to be installed. Unfortunately the mac itself has problems remotely installing rosetta (which is another issue altogether) but for now, is it possible to run and install this .pkg interactively via jamf or self service as admin inside/under the current logged in user's session?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!