Get Support
Recently active
Hello All, I am looking for a solution to display end user's account after restarting the mac, we have total three local accounts including user's account, I want to make the end user's account at display login screen so when user will restart the mac user will put his password only to login. Others two accounts will be hidden in login screen, any way is there in JAMF? User's account is having 503 UID others two are UID 501 and 502
Hi, I would like to confirm if my settings are correct?I have choose the defer to 90days and I uncheck App Updates and Software updates.My assumption was my devices will still be able to update to 13.6.2 but not Sonoma but it seems most of them detect Sonoma.Am I doing something wrong?
The TItle says almost all of it.Hello people,After I converted the Slack application, which does not offer native PKG format, using composer, I get the following error:installer: The installation failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. The package is attempting to install content to the system volume.This Policy works fine on my PC but does not work on colleague's. I will take a look at more details tomorrow from /var/log/install.log, and will post them here. We both use M1 chip, but mine is MacBook Pro, and she has MacBook Air. Not sure if this makes any difference. The latest OS and updates are applied.Anyway, if anyone has any idea in the meanwhile why this does not work, I would appreciate the help, because I have lost 2 days trying to make this work. :)Thanks in advance!
I'm using Jamf Pro, and from what I've read online, the Jamf Management Account is optional, i.e. we only need it if we want to enable FileVault using policy (we don't). But then again, the documents say that the management account is needed for Macs to considered managed by Jamf Pro. I want to manage Macs via Jamf Pro, but I don't need to enable FileVault using policy (we do it via configuration profiles) - so do I still need to create management accounts, or not? Additionally, some of my managed Macs seem to have the management account password gone out of sync with the Jamf server. Running the Jamf Management Account password rotation policy fails.Does it have any actual impact, if I don't need to use the management account (i.e. enable FileVault via policy), and I can just leave it be?If not, what's the right way to get the management account password in-sync with the Jamf server again?
Hi everyone, I am stuck at this step: https://www.youtube.com/watch?v=4vCzG_Zdelkuntill 04:19 everything is allright. (Server token is uploaded and in: (Settings/global) Automated device enrollment I see the MDM server and also 2 computers assigned.But when I go to: Devices -> PreStage Enrollments (See 06.48 of the video) I dont see the same. I see: I am new to JAMF Pro and am stuck at this point.I hope someone can explain why I am unable to do the steps shown in the video.kind regards
I need to run an activation script as administrator after my pkg installs. I've successfully created the install pkg, in the self service center, it runs, executes, then fails. I've been able to run the pkg and the script manually on the mac, it prompts for the su administrator pwd. Not sure how to script the pwd prompt. Any help would be greatly appreciated. script:su administrator sudo bash -c " if [[ -f /usr/local/qualys/cloud-agent/bin/qualys-cloud-agent.sh ]]; then /usr/local/qualys/cloud-agent/bin/qualys-cloud-agent.sh ActivationId=##### CustomerId=########; else /Applications/QualysCloudAgent.app/Contents/MacOS/qualys-cloud-agent.sh ActivationId=##### CustomerId=#####; fi"
Hi All,I am just thinking if there is a way to manage macOS Virtual Machines hosted on AWS by Jamf Pro?Also, what all the possible way to have macOS VMs and its management by Jamf pro?Thanks,Piyush Verma
Good Morning jamf Nation, We are rolling out SentinelOne agent to Macs. I have the policy set, but I need some assistance with "pre-approving" the SentinelOne Agent kernel extension. The S1 setup guide gives a parameter to enter in the policy: Kext Bundle ID: com.sentinelone.sentinel-kext Developer ID: 4AYE5J54KN I just don't know where to put the parameter. I tried copying and pasting it into Execute Command under Files and Processes, but that change doesn't 'approve' the agent. Based on the log file, it looks like it's trying to run the parameter, but then fails? Any ideas?
I've been tasked with setting up AD Certificates for Macs and after working a bit on it I now have it working where the computer gets a config profile installed that then requests from AD a certificate. Everything is working fine, but now I am at the point where I am not sure what needs to be done when the certificate expires 1-year from now. I need some type of workflow for renewing these as it will be impossible to keep track of all the expiration dates. After doing some searching on JN, there are some posts a few years old where users recommend scripting this, but there was no one that could get it working. There is also a feature request to have the JSS auto renew, but that is from 2013 and I don't think that will happen. If anyone is out there who has put together a workflow for getting this to work I would love to hear about it.
I find the progress... circle(?) doesn't give users much feedback as to where a self service policy is at in terms of completion, other than just waiting for it to stop and a quick done over the button. It would be great if the policies could have an actual progress bar, even if it's not super precise. Would anyone else find this useful?
We've been noticing a good amount of students downloading and launching .app files from their Desktop and Downloads folders. Is there a good way to prevent .app files from launching from these folders? I have been using Restricted Software, but it is a large amount of work to up keep. I am now messing with Configuration Profiles with Application Restrictions, but it doesn't seem to be working as I hoped. Right now I have ~/Users/Desktop and ~/Users/Downloads in the Disallow Folder. Nothing is currently set in Allow Apps or Allowed Folder. With these settings it seems as if every app no matter the location is being blocked. Are the Allow Apps or Allowed Folder options required when messing with these settings? My main goal is to prevent applications from running in a users Desktop or Downloads folder. This seems to be the typical location that students have been saving/running from. We are running 9.6.1 of the JSS. Thank you in advance!
Hi Everyone, I'm reaching out in the need of assistance. I'm currently working on the migration of 300 AD bound macs. The scenario is the following: -All 300 Macs are joined to old domain with network accounts and need to be migrated to the new domain without deleting their user data and making sure it has the correct permissions. -Currently their is no FileVault enabled. -I've been looking into scripts or some sort of automation that could help me un-join from the old domain, re-join to the new domain and move the user's profile with the same naming convention over to the new domain. Any help on this would be greatly appreciate it, as I would like to publish this script on self service to do this on all the Macs that need to be migrated. I'm no expert in JAMF, but I understand the concepts and have been using it for a while now. So detailed explanation would be greatly appreciate it. Thanks for everyone's time on this threat, thanks in advanced. Please feel free to have any
Hi,Is there a way to make OSX auto-trust Microsoft Remote Desktop Connection (to specific addresses) regardless of certificate in JAMF? I know the client can hit view certificate and click always trust but is there a way to automate this or have a policy that always allows this?Thanks
Hi Everyone,I want to be able to block USB Storage devices via JAMF does anyone know if this is possible with JAMF?I can see there's a restriction setting when creating a config profile but this is now depreciated... Thanks in advance for any advice!
Hi all,Looking for advice with my 'Off-boarding Script'Description:This script (below) is crafted for system administrators utilizing Jamf Pro to facilitate the remote off-boarding of Mac devices that end users have purchased. It performs several functions to ensure the device is no longer managed or configured for enterprise use. The script automates the removal of management settings, promotes the current user to admin, creates backup accounts, and eliminates no longer necessary accounts and management software. Furthermore, it updates the device's details in Jamf Pro's inventory, sends essential information to a Google Sheet, and concludes by removing the Jamf management framework, making the process as hands-off as possible. #!/bin/bash # Functions removePolicyBanner() { if [ -e "/Library/Security/PolicyBanner.rtfd" ]; then echo "Found PolicyBanner... Removing PolicyBanner" rm -rf "/Library/Security/PolicyBanner.rtfd" else echo "No PolicyBanne
My 30-day deferral of Sonoma in my Jamf Pro Restrictions profile should have lapsed by now (October 26th marked ~30 days since Sonoma dropped, right?), but my Macs that are scoped to a 30-day deferral still dont see Sonoma in the SU Settings pane on Ventura 13.6.x or softwareupdate cli tools. Any thoughts on this? Anyone else experienced this?
I'm experimenting with patch management and I've set one up to be available via self service. My only problem so far is that the name I've set in Jamf Pro is not matching in self service. I'm not sure where it's pulling this name from, except for maybe the repository from Jamf. Has anyone else seen this?
Hi fellow admins,It's the first time I have to update our iPad inventory since the release of Version11.0.1-t1698068630 and I'm encountering a problem:It applies changes to the information, such as username, but won't remove the iPads I had deleted from the list. There are no error message concerning the .csv upload. I've tried several times, with different browsers to no avail.Is it a known issue and is there a workaround?Thank you Suzane
I created a free tool to get the LAPS password for a Mac. This is designed for IT admins or Helpdesk staff.Check it out here https://github.com/kylejericson/Jamf-LAPS-Bootstrapper
I created a custom patch title for Egnyte Connect, but for some reason, it still won't pull info to start patching. I have checked Macs and the custom extension attribute has run and gotten a value for a few Macs.
All, I've been searching for a way to remove Office 365 which included Word, Excel, PowerPoint, Outlook, OneDrive, Teams and MAU from macOS.I'd came across these two script office-2016-removal-script and post by sbirdsley.Below is their script that I've add Teams and OneDrive, Let me know if I'm missing anything. #!/bin/bash USERNAME=$(ls -l /dev/console | awk '{print $3}') if [[ $EUID -ne 0 ]]; then echo -e " ROOT PRIVILEDGES NEEDED! You have to run this script as root. Aborting... " exit 1 else echo -e " ################################### Office 365 for Mac uninstaller ################################### " sleep 4 echo -e " ------------- WARNING ------------- Your Outlook data will be wiped. Press CTRL+C in 5 seconds to ABORT ----------------------------------- " sleep 6 # commands out of the official guide from microsoft # source https://support.office.com/en-us/article/Uninstall-Office
Is there any way to manage Screen Time/Downtime settings through JamfPro. I work at a school with a 1-1 MacBook Air program and our we want to set the computers to be unavailable during late night hours. I used to be able to manage this with a parental control config profile, but those don't seem to work under Ventura/Sonoma. Has anyone figured out a way to setup downtime hours on MacOS through Jamf Pro? Thanks!
Hello Everyone,As part of providing solution to a use case, we wanted to prevent user to create new profile in Safari 17. As per attached image, is there any setting in MDM using which we can disable this 'Start using Profiles' button ? Thanks in advance !
I'm testing RealVNC Server for some of our users.When I install the Server App it asks for a bunch of approvals for pppc settings things like Accessibilty, and Screen Recording and when I look in there I see that these have been given to vncagentI used the PPPC utility to get the info for Identifier and Code Requirement and made the settings in a Jamf Configuration profile but it didn't seem to effect the computer as when I install it still prompts me for those settings.So, I created a configuration profile with PPPC Utility, and used the upload feature in Jamf Pro configuration profiles area. That profile looks the same as mine but again still not working on the client as I still get promptedHere's screen shots of the Configuration Profile in Jamf Any ideas on what might be the issue?
I've setup the latest integration between Jamf Pro & inTune for Device Compliance.This is working as I can see the device in Azure as showing as compliant when I check the users devices.When I create a conditional access policy to grant access to compliant devices and one of these compliant devices tries to connect, the conditional access policy is showing as "Not Satisfied" "Require compliant device".Has anyone setup the jamf & inTune device compliance and have conditional access policies in place which are reporting that the mac device is indeed compliant, more than likely a issue with Microsoft but just want to check at least someone in the world has all this interaction working correctly & successfully with conditional access policies ?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!