Get Support
Recently active
Hi everyone,i am trying to bind the home folder for our users automatically but we don't use the typical home folder field in AD.We instead have a folder in a share called like the user login name.I have seen the NoMAD Shares help site https://nomad.menu/help/nomad-shares-menu/ and it list some variables which are supported but doesn't clearly states what they do and I did not found a way to print the variables to see what they actually refer to. this is my config:<dict> <key>PayloadDisplayName</key> <string>NoMAD Shares</string> <key>PayloadIdentifier</key> <string>com.github.erikberglund.ProfileCreator.15379620-191B-4449-BAB1-513D17129D0D.menu.nomad.shares.EBFEE259-96B4-4782-A77C-F8ECE6BD6677</string> <key>PayloadType</key> <string>menu.nomad.shares</string> <key>PayloadUUID</key> <string>EBFEE259-96B4-4782-A77C-F8ECE6BD6677</string> <key>PayloadVersion<
Hi Chaps, I have a need to disable the Defender AV socket filter.'mdapt system-extension network-filter disable'The above works fine when i run locally albeit with a Sudo command.Jamf scripts is unable to run this, Is anyone doing anything similar or have any thoughts on this.I've tried to invoke a currently logged in user prior to running the command without any success Thanks,M
Hello all! Access to the personal Beta instances you are able to request when you join the Jamf Pro Beta Program will be unavailable for an extended period of time over the coming weeks for maintenance. We'll let you know when they're back online! Thanks as always for the feedback provided and participation in the program!
Hi all,I am currently facing a challenge and would appreciate your assistance. I am trying to identify which clients have iCloud Drive activated, specifically with synchronization of desktop and documents.I have conducted extensive research online and within this forum, but it appears that the solutions provided are not applicable to the newer versions of macOS.Could anyone provide guidance or suggest a method that would be effective for the latest macOS versions (Ventura, Sonoma)? Any help would be greatly appreciated.
Hi All,We successfully deployed Jamf Connect with the onboarding help from Jamf. We will deploy in full this summer. We've been using Jamf Connect on about 20 faculty and student loaners in the meantime.I also configured Jamf Connect to update automatically and it worked for a time. The Deployed version is 2.19.0. Most of our devices got that version, but it hasn't updated since. Anyone have any ideas? I setup automatic updating in Settings -> Jamf Apps -> Jamf Connect. I was unaware if I have to do anything additionally like download the app or do something in Patch Management. My understanding was set it to automatically update and that's it.
Our organization had an issue with our certificate expiring, but it was tied to an applie ID for an ex-employee so we had to create a new certificate under a new ID. Then the trouble began... We were able to renew the certificate, then push out to our devices (iPads) to re-enroll them. Some accepted it, others did not. For the devices that did not accept it, they are now unable to communicate with the JAMF server to push updates, apps, etc. Our organization is a bit different as we manage the devices by serial numbers, not Apple ID's (we have high turn over) I have tried soft and hard reset the devices in the hopes they would come back online, but no luck. We have been in contact with JAMF support directly, and they have recommended for us to wipe the devices via the device and then have them re-enroll. Because our company uses these devices for mission critical applications, we cannot do this easily and have a workforce that is spread out geographically
HI All, i am using Composer 10.46 and macos is on Ventura. while i convert pkg to source it gives error failed to convert source. anyone facing same issue ?any help is appreciated.
Hi folks, struggling to find an answer for this.We have a number of machines unable to run Big Sur, so I wish to deploy a script on all of these devices that remove these devices from support. I've achieved similar in the past where I can actually remove all the local jamf components, licensed apps etc.. and also delete the JSS record for the specific device using an API call. However, looking forward, I'd like to keep the JSS record available as they may contain encryption keys that we want to keep a hold of.Basically, I'm looking for a way to "Unmanage" these devices by unticking the "Allow Jamf Pro to perform management tasks" checkbox for each machine through the API, as I believe this will free up licenses:I've had a look online, and found some instances that I believe provide a resolution but I can't get anything to de-select this checkbox. For example :https://community.jamf.com/t5/jamf-pro/script-to-remove-management-through-api/m-p/233611https://community.jamf.com/t5/jamf
Good day! I need to uninstall Crowdstrike Falcon Sensor from some of our Macs. Crowdstrike's instructions to uninstall via Terminal are as follows: sudo /Library/CS/falconctl uninstall --maintenance-token Terminal prompts for user password. Password is entered. Terminal then prompts for "Falcon Maintenance Token". Falcon Maintenance Token is entered. Crowdstrike Falcon Sensor is uninstalled. I'm a script noob and can't seem to Google-fu my way to finding how to:1. Prefill a separate local admin user & password2. Add syntax that would allow the script to enter the Falcon Maintenance Token after it's prompted Is this even possible? Thanks so much!
Hi OTHER storage is currently at 130GB (half the HD size) But it's not clickable so not sure how to clean up. Is there a way to clean it up so we can recover some space? thanks
I'm looking for advice on getting homebrew on new employee machines automatically. We have a work flow we would like to keep to as few clicks as possible. I am trying to get the process of pulling down XCode CLI, installing homebrew, adding cask, and then installing third party apps for new employee machines. I have the XCode CLI component down but having problems with installing homebrew and adding cask. Curious if anyone has a working script to make this happen. I am deploying this process through self service.
Hi all,I'm having an issue with an app that just does not want to install. I'm going to try to be SUPER detailed with this post, so please bear with me.The iPads we are using are company owned, and there is no Apple sign-in allowed on the devices. The app is Therap version 23.9, and its description says it's for both iPad and iPhone. It's a medical documentation app. The app works if it is installed on other iPads through the regular App store. I also had a similar problem installing the Zoom app, but I removed it from the blueprint and added it again, and it now works fine.The Jamf Now dashboard shows the app as being installed and managed. It does not fully install on any of the iPads we manage. The app does not show up anywhere on the iPad, even in settings, while other apps do.This happens every time, no matter what troubleshooting steps I have taken: when the device connects and syncs, the Therap icon on the iPad shows as installing (it does the faded icon "circle sweep" thing), t
Hi all,I need to update our local admin account password. I have heard of weird things occasionally happening where it will update for the OS, but not for FileVault. Has anyone else experienced this and have you found a solution or workaround? I have used this command on some test machines:jamf changePassword -username btr-itadmin -password 'NEW PASSWORD' -oldPassword 'OLD PASSWORD'I haven't run into any issues, but I just want to see what everyone else has done for a situation like this.
In 10.46 Jamf released the LAPS feature. This is currently only available via the API. With this bookmarklet I created you can get the LAPS password for a specific computer from a specific LAPS account from the Jamf Pro WebUI. Follow the instructions to add the bookmarklet and then run the bookmarklet after you've browsed to a computer record.Let me know of any feedback or issues you have.
Hi everybody,An app was broken on my machine, so I deleted it manually (perhaps that was a mistake).Now, if I go this way:Computers > Search Inventory > my MacBook > History > Mac App Store AppsThe app still appears under the list of "installed apps," even though I deleted it. How can I update that list?Best regards,Floh
I am attempting to utilize the built-in JAMF Pro connector available as a data source type in Power BI Desktop. I have entered the instance URL and service account credentials, and I am able to view the available tables.However, when I attempt to select a table, I receive an error message stating "unable to connect to the remote server." I have been informed that the service account has full read access. Should I investigate the roles assigned to the service account in JAMF?Alternatively, could this connector be known for having reliability issues or being faulty?
I have a policy called "Dock CleanUp" triggered at login, once per user per computer.Script works as expected except I always briefly get question marks for missing apps until thekillall Docksleep 5killall DockThen after the sleep the dock appears as desired.The apps are present before the sript is run. Is there anything obvious I'm missing? Thanks in advance for taking a look. Cheers Script is below:#!/bin/bash########## Clean Dock Up ###########sudo -u $(ls -l /dev/console | awk '{print $3}') /usr/bin/defaults delete com.apple.dock persistent-appssudo -u $(ls -l /dev/console | awk '{print $3}') /usr/bin/defaults delete com.apple.dock persistent-otherssudo -u $(ls -l /dev/console | awk '{print $3}') /usr/bin/defaults write com.apple.dock show-recents -bool false########## Add Apps to the Dock #########sudo -u $(ls -l /dev/console | awk '{print $3}') /usr/bin/defaults write com.apple.dock persistent-apps -array-add '<dict><key>tile-data</key><dict>
Hello all I am tasked with seperating our onboarding process for Contractors and Full time employees. We are using Onelogin as an LDAP server just as background info. I would like to use Smart Computer groups to achieve this What workflows or methods does everyone here use to seperate onboardings for employee types.
We're wanting to roll out activation lock to our devices so that if any devices are stolen and wiped the laptop is useless unless returned to IT and the bypass code entered.The documentation (https://learn.jamf.com/bundle/technical-articles/page/Leveraging_Apples_Activation_Lock_Feature_with_Jamf_Pro.html) states that:"The Set Activation Lock command allows you to enable Activation Lock on a currently enrolled device. This command can be sent to a single device using a remote command or to multiple devices using a mass action.". However upon reviewing the mass action commands available for a test device, it only allows the user to enable activation lock?We've been able to add this to our pre-stage profile so any newly enrolled devices are covered.Is anyone able to advise on this?
Jamf Pro 11.1 introduces Jamf Remote Assist, macOS Onboarding, and a summary view for App Installers. Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements. Take the quiz below to check your knowledge. Thank you for your continued support and feedback!
Hi Jamf Nation, We’ve just released Jamf School 9.2.21 with exciting updates, bug fixes and enhancements including Support for Bootstrap Token Functionality. Jamf School can now automatically escrow bootstrap tokens sent by computers with macOS 11 or later during enrollment and computers with macOS 10.15 or later after enrollment. Bootstrap token eliminates the need to request additional authentication information when a network user logs in to a computer with a mobile account and the account does not have a SecureToken associated with it. After the bootstrap token is escrowed, it is requested from Jamf School each time an eligible mobile account logs in to a computer. The computer then automatically generates a SecureToken for the mobile account. After the user is issued a SecureToken, their account can be used for macOS services that require cryptographic privileges, such as FileVault authentication. In addition, if an Automated Device Enrollment profile
Here's hoping someone smarter than me can answer this:I have a client whose in-house developers have created a system of printing shipping labels from their intranet system. It uses Zebra label printers connected to the Mac Mini stations via USB and an application called QZ Tray by QZ.io. To deploy the app, one has to include a self-signed certificated called 'override.crt' embedded in the app bundle's Resources folder. Then when the app is launched for the first time, the logged in user must enter their password to accept the certificate. You can not change the username to use a different (hidden admin) account instead. It must be the username and password of the launching user. It should be noted that at no point does the cert show up in Keychain Access before or after this.I have tried using openssl to covert the .crt file to a .cer file and deploying it via a Configuration Profile in Jamf. When I do, the cert shows up in Keychain Access and the serial and signature match the f
good morning. we have an employee who was recently deployed a replacement laptop (it's enrolled into our jamf pro) after using migration assistant to transfer files over to this machine, it restarted on her but now is stuck in start up loop, where the apple icon will load to a certain point and restart. I've tried having her go into recovery mode, but once she gets there it asks for the device recovery key. Is this device unrecoverable because of this jamf error? please advise.
this morning it seems we cannot log into jamf pro. Even tried our local account and not able to login. I tried on my company network and on wireless(verizon) network as well and still not able to login. are there any issues logging in?
Hi,Working with the Jamf Compliance Editor for the first time with Sonoma. Got a dumb question.If we are modifying "ODV" values, do we just need to replace the $ODV entries with the number we want in all the fields?So for example, if we want 10 days for this 1.7 Control, it'd look like this?Mobileconfig com.apple.applicationaccess:enforcedSoftwareUpdateDelay: 10
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!