Get Support
Recently active
Hi Jamf Nation, We’ve just released Jamf School 9.2.21 with exciting updates, bug fixes and enhancements including Support for Bootstrap Token Functionality. Jamf School can now automatically escrow bootstrap tokens sent by computers with macOS 11 or later during enrollment and computers with macOS 10.15 or later after enrollment. Bootstrap token eliminates the need to request additional authentication information when a network user logs in to a computer with a mobile account and the account does not have a SecureToken associated with it. After the bootstrap token is escrowed, it is requested from Jamf School each time an eligible mobile account logs in to a computer. The computer then automatically generates a SecureToken for the mobile account. After the user is issued a SecureToken, their account can be used for macOS services that require cryptographic privileges, such as FileVault authentication. In addition, if an Automated Device Enrollment profile
Here's hoping someone smarter than me can answer this:I have a client whose in-house developers have created a system of printing shipping labels from their intranet system. It uses Zebra label printers connected to the Mac Mini stations via USB and an application called QZ Tray by QZ.io. To deploy the app, one has to include a self-signed certificated called 'override.crt' embedded in the app bundle's Resources folder. Then when the app is launched for the first time, the logged in user must enter their password to accept the certificate. You can not change the username to use a different (hidden admin) account instead. It must be the username and password of the launching user. It should be noted that at no point does the cert show up in Keychain Access before or after this.I have tried using openssl to covert the .crt file to a .cer file and deploying it via a Configuration Profile in Jamf. When I do, the cert shows up in Keychain Access and the serial and signature match the f
good morning. we have an employee who was recently deployed a replacement laptop (it's enrolled into our jamf pro) after using migration assistant to transfer files over to this machine, it restarted on her but now is stuck in start up loop, where the apple icon will load to a certain point and restart. I've tried having her go into recovery mode, but once she gets there it asks for the device recovery key. Is this device unrecoverable because of this jamf error? please advise.
this morning it seems we cannot log into jamf pro. Even tried our local account and not able to login. I tried on my company network and on wireless(verizon) network as well and still not able to login. are there any issues logging in?
Hi,Working with the Jamf Compliance Editor for the first time with Sonoma. Got a dumb question.If we are modifying "ODV" values, do we just need to replace the $ODV entries with the number we want in all the fields?So for example, if we want 10 days for this 1.7 Control, it'd look like this?Mobileconfig com.apple.applicationaccess:enforcedSoftwareUpdateDelay: 10
As the result of a technical issue with the Global Patch Feed used for the Jamf App Catalog, patch definition updates are unavailable until further notice. Do not attempt to add any new patch definitions to Jamf Pro during this time.Existing patch policies will continue to function as normal, and new patch policies may be assigned to existing patch definitions in Jamf Pro; however, new product versions will be unavailable.We are actively working on a resolution and will share an update as soon as patch definition updates are available. While we cannot give you an exact date, we expect the outage to last a few days.When patch definitions are available all updates will resume as normal.During this time, you may still use App Installers to manage software title updates in your environment. For more information, see App Installers in the Jamf Pro Documentation.
Hey Nation, we just started the Registration for our 250 Mac Devices to MS Endpoint Manager.Registration went successfully, I can see the Devices Compliant in Endpoint Manager.We just have 2 issues:1. most of our Users Sign In to MS Services, but it won't deliver a Device ID. Others do... 2. Some Users daily get the prompt for the Registration again (JAMFAAD). I understand JPRO and Endpoint Manager proof of the integrity of the registration, and the activity of the device. But, every Day seems a bit too much, I guess (?)Thanks for some ideas!
Users that have already properly enrolled into Intune and completed enrollment continue to get pop ups of jamfAAD. I have verified in Intune that the device is enrolled AND the policy was completed successfully in JAMF. This pop up continues to run and request users to continue. This sometimes disrupts end user workflows or presentations while on a zoom call. Is there a setting possible in the profile where I can set the retry option to 0 if already successfully completed. I've tried flushing the logs, delete the device from Intune, then re-enroll the mac back but users still get prompted. Even when I've un-scoped the policy from the user they still get the pop up. Possibly coming form the Intune side? I'm open to any ideas.
After installing Self Service (ver11.2.0-588) to managed iPad device, the app requests log in to JAMF Software Server.This happens iOS 16.6.1 and 17.1.1, then it's possible to access internet.Even after reseting iPad, reinstall App, it occurs.I have no idea to solve it.Help me.
I'm sure it's something simple I'm missing.I've downloaded the latest MSEdgePolicyTemplates and uploaded them into Jamf. I can successfully change settings so I know the profile is taking effect. I can.1. Set HomepageLocation and HomepageIsNewTabPage. So when someone clicks on the "Home" button it takes them to it.2. Set RestoreOnStartupURLs and have them apply when first opening Edge.3. Change RestorOnStartup to either Open the URL's as per point 2 above or restore previously open Tabs.What I'd like to be able to do is a hybrid of point 2 and 3. When Edge is opened it restore previous Tabs but also opens the home page. This would replicate our Windows environment.
Issue: Register with Microsoft on iOS just hangs with spinning wheel icon after self service app update 11.2 Before when we select "Register with Microsoft" on the iOS device it redirects to Authenticator app, which then require the prompt to login, once that is completed, will return to the Self Service app and it would say "Device Registered". This no longer happens and the Register button just hangs at a spinning wheel.
I am getting a dsconfigad: The plugin encountered an error processing request. (10001) when I attempt to use a Jamf policy using the directory option to bind a Mac to a new domain. The Mac was previously bound to another domain and was removed from that domain. The search field in directory Utility still retains the path to the old domain. Doing a dsconfigad -show does not come back with anything. I know this is an older error and I have not seen it recently.
HelloI have an issue with jamf Protect not linking to jamf pro, i have followed all the steps recommended in the training however jamf protect is not connecting with ANY of the computers within its scope, however it is displaying connected users in the audit logs, does anyone know how to fix this issue
Hi We're trying to deploy the latest version of Jamf Connect 2.29.0 to all of our users who are currently running a much older version of Jamf Connect. Please excuse the newbie question but how do I convert the Jamf Connect 2.29. DWG file into a PKG file? This guide is very useful if you already have a PKG file, Should I just follow this guide but not include any custom images (we're not bothered about custom branding), you don't need to upload the DWG file within this process so I'm unsure how the Jamf policy will know to install version 2.29.0 of Jamf Connect when I add it as a package?ThanksTom
After I was finally able to convince our InfoSec to open the proxy and firewall to allow VPP, I tested it by doing an automatic install of Slack, then a Self Service install of IP Scanner onto a couple Macs. it worked fine. Yesterday I decided to install both those apps onto a couple more Macs via the same methods. I scoped the computers to both apps (I have assignments to spare for each). However, both install methods are failing. With the automatic install, absolutely nothing happens. I can find no log entries on the local Macs to indicate anything at all has even attempted to happen. I enabled debug logging on the JSS and saw these 2 lines: Sending new 'InstallApplication' command to 'UserPushToken [ID=404, Name=cmcintosh]' computer: 'COMPUTERNAME' and Not installing MacApp [ID=12, Name=Slack] for Computer [ID=323, Name=COMPUTERNAME] because not VPP assigned So I read that to mean it is TRYING to tell the Mac to install but it thinks the app isn't assigned.... but it IS! I di
Hey Everyone, i am having issues with JAMF connect configurator i am trying to do it where a user will login with their company email and password they sign in then get presented with the okta login window so they can sign in and authenticate but no matter what i do that window does not pop up any ideas?
Due to an unexpected issue (PI115107) with the upcoming release of macOS 14.2, all customers must update to Jamf Connect version 2.29.0. For Mac computers with macOS 14.2 or later and a version of Jamf Connect earlier than 2.29.0, all users who start up, restart, or logout of their computer will encounter a black screen and be unable to continue using their computer. As long as the affected computers are connected to a network, policies can install the updated version of Jamf Connect and successfully restart the computer. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. For instructions on how to upgrade, see the Jamf Connect Documentation. Reach out to our support team for assistance if you have questions. Thank you,The Jamf Connect team
I have a profile that is just for setting a home screen on specific iPads, it worked initially but now when trying to apply it to a few new devices I get the following error:The profile “Home Screen (version:10)” is invalid. / The payload “Home Screen (version:10)” is invalid. / The field “Icon” is invalid.These iPads are running iOS 17.1. A couple of older iPads that I already had the profile applied to were on iOS 16 at the time. but they are throwing up the same error now they are updated to iOS 17.This profile also contains a webclip with a custom icon applied, could this be the issue?
We are managing iPads for Education and a small hand full of Macs as Caching Servers for our City Administration. We were thinking about doing some certifications but it seems the focus is on Jamf Pro. At least the Jamf 100 seems to contain things that could Help us managing Out growing number of devices. Any experience from other Jamf School admins in this?
Hi,I am new to Jamf Pro and have been asked by a school to come and administer their system. The previous IT manager had knowledge of it but that seems to have gone with him.We are having a lot of challenges but we suspect that our logins to not have the correct privileges. For example when going trying to create a policy and going to packages, if I select package settings, I get a 403 error. Equally in settings, computer management, I only see 'Inventory display', nothing else.Thanks for any input,Adam
Hi Guys, we recently just deploy exclaimer in our business. And I deployed Exclaimer Signature Agent for our macbook users. (our macbook users use outlook). my question is that how do we supress this pop up from exclaimer agent as most of our user keep getting this popup everytime they restart their macbook.
We have Garage Band available on Self Service. Non-admin users are able to download and install it just fine. However, the first time it is launched it pops a dialogue to download the "Essential Sounds Download" which our users also need. It downloads the package but then pops a security dialogue requesting an admin username / password to complete the install. Has anyone found a way to allow this to run for non-admin users?
We're loving the new features with MacOS Sonoma, Apple has for the most part fixed the broken update commands which were hit or miss before, we'd often have 30-40% of devices actually updating from the command.We have a small set of devices (approx. 10) that are currently on MacOS 14.0 but are not sticking to their MacOS 14.1 update deadline which was pushed out for an enforced date of a few weeks ago.The devices in question are checking in as normal and receiving new policies and providing inventory updates as expected. 95% of the other devices are working to the deadline and updating as expected which.Has anyone else experienced this before I open a case with Jamf Support?
FYI folks, the new Self Service seems to have impacted the "Register with Microsoft" process. When performing the registration process the prompts to "open authenticator", "open self service", and "you are now registered with microsoft" are no longer displayed. The registration is successful, but since the "you are now registered" is no longer displayed, your users may be confused and try to redo the registration process. I created a case for this just now. Thanks to everyone for posting the fix for the other issue (MANAGEMENT_ID) with 11.2 release of Self Service. That was super helpful in fixing our environment very quickly!
Hi everybody,Is there a way to automatically re-enroll devices after a wipe command that are not managed by DEP (so no preStage enrollment)? We have some older devices that are not managed by Apple Business Manager (unfortunately) and are enrolled through user invitation.Best regards,Floh
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!