Get Support
Recently active
When a user with a managed iPad starts Self Service, the app complaints it should be linked to a Jamf Pro-server. And you can't do anything with the app. See screenshot (Dutch localization):This is weird, because the iPad is listed between the devices in Jamf Pro.I do notice two pending commands from yesterday and the day before yesterday (inventory update and a time zone settings update).I tried to quit self service and relaunch: did not work. I also switched the iPad off and back on.What could be wrong? Edit: could it have to do with the license? I get this notification now (I'll ask my boss about this):Device count exceeded Purchase additional licenses.
Greetings,Just inquiring about User and Groups in Jamf Pro. I am getting around to creating groups for the few users we have in Jamf Pro, no we have not hooked into our AD or Azure AD instance due to convoluted issues which at some point I hope to deal with... Anyway, in terms of permissions if a User Group has tighter permission set than the user assigned to the group, I am assuming the tighter permissions wins out?So as an example if a user has the ability to edit Smart Groups but the group they are assigned to denies that, then the user will not be able to edit Smart Groups?Thanks,-Andrew
In an effort to document our environment, I'd like to get an export of the config profiles and what settings are in place and pull them into an excel document or something similar for reference. Does anybody have any thoughts on how to do this?
since implementing jamf connect, we keep randomly getting 403 forbidden errors after trying to login (we use azure). has anyone else ever run into this before? we're not sure if it's on the jamf side or the azure side that's causing the issue.
I am experimenting with shared iPads and ran into the following issue that I get the message that it doesn't have any free space. Doesn't matter if I give a user 50 GB or 1 GB. During the last try it actually locked me out telling my I can't sign in because admin has to assign new free space. The only option I found sofar is in the MDM profile where I can assign new space but to make that change work I always had to erase the device.Also I couldn't log in with a user I created. Always got the message old password please contact admin.Thanks in advance
Hi,I am currently budgeting for next year, and in the coming months we'll start using Jamf School more. I might have some money over, so I am thinking about getting the Jamf 200 cert since it looks like the one that has the most value of 200 and 240.We are a education customer (bought Jamf School from education reseller) and I was wondering if someone knew about the discounts that Jamf informs about on the site for education customers?
Hello,We have numerous printers that are in Self Service and install correctly. Once the computer has installed the printer the printer disappears from Self Service and is no longer an option for the user to install or reinstall. Currently it is set to "Once per computer".I can see that you can change the frequency of the printer install to once a week, day and so on, but I am not keen on the printers being constantly installed.Is there a way for the printers to still show in Self Service even though the printer has already been installed on the MacBook? I would like to keep the printers there just in case someone deletes it or it needs to be reinstalled. Thanks :-)
We have recently started using Apple Classroom on our student MacBooks. The students have already figured out that disabling bluetooth interferes with classroom working. Has anyone figured out a way to force bluetooth on or check to see if bluetooth is disabled and turn it back on? I know that there is an option in configuration profiles to restrict bluetooth on iOS devices, but have not found this option for macOS devices.
We have encountered a situation with a company Mac that a previous user was using, they left the company some time ago. The issue at hand is that the user's Apple ID is still associated with the device. Additionally, it appears that a firmware password has been set on the device, which we do not have access to. This has rendered the Mac unusable.In my current role at Jamf, I am relatively new, so I appreciate your patience if this is a basic question. Is there a method to discover or reset the firmware password? We do have access to the ex-employee's computer account as a local admin.Additionally, how can I prevent such situations in the future? Can Jamf store firmware passwords, if yes, how? The Mac model in question is a MacBook Pro (13-inch, 2020, Two Thunderbolt 3 ports) with an Intel i7 processor.Thank you everyone in advance.
Anyone able to set screensavers on Catalina. I had below script that worked fine for Mojave - but for Catalina it does not #!/bin/sh # Get user logged into console and put into variable "user" user=`ls -l /dev/console | cut -d " " -f 4` osMajor=$(sw_vers -productVersion | awk -F"." '{print $2}') osMinor=$(sw_vers -productVersion | awk -F"." '{print $3}') sudo -u $user defaults -currentHost write com.apple.screensaver CleanExit -string "YES" sudo -u $user defaults -currentHost write com.apple.screensaver PrefsVersion -int 100 sudo -u $user defaults -currentHost write com.apple.screensaver showClock -string "NO" sudo -u $user defaults -currentHost write com.apple.screensaver idleTime -int 120 if [[ $osMajor -eq 14 ]] && [[ $osMinor -ge 2 ]]; then sudo -u $user defaults -currentHost write com.apple.screensaver moduleDict -dict moduleName -string "iLifeSlideshows" path -string &#
So, here's a weird one. And of course, it's my luck it happened to our CTO. Brand new M1 Pro Macbook Pro, out of box, hits our PreStage. He provides credentials, accepts TOS (provided using an Enrollment Customization), then it starts downloading and installing Profiles at the Remote Management pane in Setup Assistant. It's here he claims the Mac just rebooted and came back to a login screen. Of course, since no users were created, no credentials will work here. Soft-bricked. I see the machine in inventory. MDM stuff all seems to be working fine, but no Check-In times, no Policy logs, nothing that would be provided by the Jamf framework. We're on 10.35, Mac is on 12.0.1. Thankfully not having a SecureToken user isn't the massive PITA it was in Big Sur, so it's at least not impossible to get back to start after this, but any ideas as to what might have happened? macOS kernel panic during some profile installation?
Hello All, I was looking for an answer if Venture 13.6.2 is having any issue to connect wifi. Specially for MacBook Pro (16-inch, 2021) Any help will be appreciated.
You're invited to join me this Friday, 1-Dec, noon MST for Rocketman's monthly LaunchPad - The Jamf Admin Meetup.We'll be discussing Setup Your Mac with SYM-Helper.app.
So here is what I am trying to do; let's see if I can get some assistance because I don't think it is working correctly.Background InfoStatic Computer Groups:1 - Name > This group has X computers assigned.2 - Name > This group has X computers assigned.3 - Name > This group has X computers assigned.4 - Name > This group has X computers assigned. Smart Computer Groups:Created a couple groups to look at these Static groups; Members of 1 but not in 2,3 or 4.Members of 2 but not in 1,3 or 4.Members of 3 but not in 1,2 or 4.Members of 4 but not in 1,2 or 3. So the logic I was using is the following; but not sure if it is outputting correctly. AND/OR CRITERIA OPERATOR VALUE(Computer Groupmember of1andComputer Nameis2)or(Computer Groupmember of1andComputer Groupmember of3)or(Computer Groupmember of1andComputer Groupmember of4)Not sure if that makes sense; tried to export it, but the paste is over 20k characters.
I need to setup a new config for single app mode kiosks. These will be locked into a single app. I need to build in this config a process for performing maintenance, App update, OS update etc. In the past I ran into issues with apps not updating if locked into single app mode or not upgrading the OS pretty much ever. I would like this to be as automated as possible. Any recomendations?Is it possible to have a smart group based on time of day? Maybe it removes and readds the app lock profile based on time of day?
Hello! I am new to Jamf platform and my knowledge to Jamf administration is not enrich. I'd like to see the advises from experienced and excellent members of the Jamf Nation for the following case in my current company. I'd greatly appreciate any recommendations or insights or alternative solutions you might have regarding our situation.We're working on implementing Jamf for our staff who are based overseas. To do this, we're considering providing MacBooks to them. However, we've run into a problem while trying to figure out how to deliver these MacBooks due to import restrictions and regulations in different countries. This obstacle is making it difficult to send MacBooks from Singapore to the destination countries.As an alternative, we're exploring the idea of buying MacBooks directly from local IT vendors in those countries. These vendors shall handle everything from purchasing the MacBooks to setting them up with Jamf MDM and decommissioning them when needed. Thank y
Hello All,I can see one configuration profile is there in my JAMF Pro console which is read only and signed(It is doen by previous SME), and I can't read the payload of the configuration profile, if I click on Edit button it is asking me to remove the signature, please let me know if I click on "Remove Signature" and see the payload and modify as per my requirement and save it to rdeploy all computers with new changes made then it will create any issue? May I know how to sign such configuration profile from scratch level and what is the purpose to sign it?
Hello,We have been working on upgrading Sonoma, but we have encountered an issue. We are unable to assign volume ownership to the local users. As a workaround, we are considering making them local admins through silent actions. We are wondering if it is possible to elevate standard users to admin accounts using configuration profiles?Thanks!
I have an issue where Macs (ARM and Intel) on macOS 13.5 do not get the Jamf binary after enrolling (ADE or manual) and appear unmanaged in Jamf Pro (on-prem 10.48.2). Macs on 13.4.1 and below (inc latest Monterey 12.6.8 have no issues at all). MDM commands are fine, no issues.The Macs effected do not have the ‘Allow Jamf Pro to perform management tasks’ checked. Enabling this and rebooting the Mac can, on a few instances get the binary installed (after about a 15 min wait ) and run my post DEPNotify policy (enrolment complete trigger), but not always. Looking at older forum posts, I see in the past people have experienced similar issues.Tried the following...Enable user-initiated enrolment - (already enabled) have tried with it disabled, still the same.Checked sysdiagnose logs – I do see this but confirmed we have no Restriction Config Profiles with ‘Require admin password to install or update apps’ checked.[com.apple.appstored:AppInstall] [MNFE60849E9/com.jamfsoftware.enrol
We are moving from on prem to Jamf Cloud soon and I would like some sort of infographic that shows the differences between the two and why we are moving. I've looked here and online but haven't found anything. Does such a thing exist? Thank you
With the recent package apocalypse I wanted to check that our clients had installed all Apple software updates and not just the ones listed in our local SUS. It was mentioned in the #osx-server irc channel that you can use the --CatalogURL parameter with softwareupdate command. So I wrote the following simple extended attribute that uses softwareupdate -l and the --CatalogURL parameter to directly query Apples update servers and not the software update servers specified by MCX/JSS etc. #!/bin/bash sucheck=`softwareupdate -l --CatalogURL "http://swscan.apple.com/content/catalogs/others/index-lion-snowleopard-leopard.merged-1.sucatalog" | grep -c "Software Update found"` if [ $sucheck -gt 0 ]; then echo "<result>Updates</result>" else echo "<result>None</result>" fi
I recently upgraded to the Jamf Pro 11.1.0 Beta version and have come across a few issues that I'd like to discuss and seek assistance on. Here are the problems I've encountered:After the update, I noticed that some configuration profiles are not applying correctly to devices. Has anyone else experienced similar issues? The inventory updates seem to be delayed after the upgrade. Previously, it was almost instantaneous, but now there is a noticeable lag. Is this a known issue? I appreciate any insights, tips, or solutions that the community can provide. Let's collaborate to make this beta version as smooth and efficient as possible.
I would like to enforce being locked to a single Wi-Fi. The issue is, each device is going to be on a different network. Can I manually set up to lock each device to a single network I specify?
I'm looking at the macOS onboarding tool and wondering what the major differences are between this and prestage enrollment. thinking it might be just the fact that we can control what apps, profiles and policies get installed AFTER enrollment. Am I wrong?
Hey everyone,I want to setup auto-selection for a client certificate in Safari.I already figured out how do auto-select in chrome and firefox but from my research, seems like there isn't a simliar, easy, native way in Safari.I saw that setting an identity preference between my client cert from keychain to a url/dns/service is possible.Basicly my goal is for safari to select automatily the ame client cert for all of it's traffic.The best solution I found was using TLD's: "*.com", "*.net" but it requires quite a a lot of objects and inefficient.I have tried the following but all of them didn't work: security set-identity-preference -c <CN name> -s "*" security set-identity-preference -c <CN name> -s "*.*" security set-identity-preference -c <CN name> -s "https://*" security set-identity-preference -c <CN name> -s "https://*/" security set-identity-preference -c <CN name> -s "https://*/*" P.S: I know it isn't very secure but i still want to
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!