Get Support
Recently active
Hello all, I've tried difference scripts (bash and AppleScript) but none seem to work for me. Basically, (and I see this has been asked a lot but varies), I would like for any user that logs into the Macbook, connect to their smb share AND place that drive as a shortcut in either the Locations (in Finder) OR Desktop. Users should not be prompted for their username and password. Here's what the smb path looks like:smb://servername/Userdata/UserName/My%20DocumentsWhere UserName can be any user that logs in to that Mac device. But do not prompt for username and password if possible. If password is a must, then I'll take whatever I can work with.
Hi, I came across a new feature in iOS 11 yesterday enrolling a new Student iPad. It seems Apple added a new Settings option under the 'General' tab which is "Multitasking & Dock". in here you are able to allow / prevent the following: -Allow Multiple Apps-Persistent Video Overlay-Gestures and for the Dock-Show Suggested and Recent Apps Unfortunately I haven't found any payload in the latest Jamf Version to disable the Dock feature, as it expands the Dock with the last used Apps, nor the other ones. Does anyone else came across this, or better, has a solution to switch them off on student iPads??
Hi Everybody,The plist housing the settings for the keyboard shortcut for VoiceOver has been moved to a different plist since it was last addressed in this post. Anybody know which plist houses the Cmd+F5 shortcut for activating/deactivating the VoiceOver in macOS Ventura? I have obnoxious kids that like to constantly toggle it, and I'm not seeing an option for it in the configuration profiles.Thanks In Advance,-Rob
We're trying to figure out how to set the color profile (to Adobe RGB) for all displays in one of our labs. I've seen different posts on here, but no solutions. Any thoughts on how to set this up with a script or, ideally, a profile?
Greetings, Does anyone know (perhaps using an extension attribute) how I can identify which clients on my network have 802.11n NICS? I'm trying to see if I can safely turn this frequency off on my network. Thanks in advance. Andy
It’s that time of year again. You and your team have finished or are about to finish all the big summer projects, but what might you have missed in the shuffle? Here are a few things we re-check at Brewster just before students arrive for the winter term. Certificates Certificates are something you should have well handled and probably on a team calendar for renewals. After all, there are plenty of them across many services, and missing one could have dramatic consequences, especially at the beginning of the school year. So double-check even if you’re sure you’re all set. Apple Certificates such as Developer and Deployment ID certificates - require yearly renewal. In JAMF Pro, double-check your Push Certificates, PKI Certificates, and your Apple School Manager/DEP integration to make sure everything is syncing properly. Software Updates It’s nearly universal that educational software developers have this tendency to release new major updates in the weeks leadin
So today our lab cart was being used for a test. These machines are always on or supposed to be. I installed a Firefox patch (version 57.0) the other day. When these machines came online there was the 15 minute message about having to shutdown to install the update. The issue is this was during a test. So some computers had the browser shutdown and they had to re-login. Another issue was Word also had an update and several users were in the middle of a document when the warning went out to shutdown and save their work. What if they had left their machine to go to the bathroom or something? We are going to instruct people to use Safari but how do people get around these Patch Management issues? I could make everything self service but I like the idea of pushing patches. I can make the time longer I guess. Suggestions?
Hello, So we are having a bit of a struggle here, since the begining I've never wanted to use the Patch Management feature because there was only a defined set of apps usable, and thus you had to have apps in here, and the unsuported ones in the policy section. I didn't like that so I went for a full policy updating workflow.It actually works pretty well, I even created some scripts so you can easy add any type of pckage you want and you just have to tweak thhe paramters to control the installation process, very handy.But the problem we have is that it seems impossible to filter computers in smart group by "less than" for a software version. It's a nightmare, so we've been updating as soon as possible the precise version in these groups and update de package as sson as possible. But if for some reason an update gets released and we don't react fast enough some computers might auto update some stuff, and then jamf would then downgrade the app, cause it doesnt match our policy.....&
requirements: OS X updates for "shared" machines in an Educational environment will be deployed during a scheduled maintenance window when labs are closed. At no point shall a student or teacher ever be prompted for any action re: updates. The SLA for shared/public workstations is that machines are patched by IT--this process must be fully automated so that IT staff doesn't have to run around logging into machines to patch them. What is the current thinking on how best to accomplish this? The environment is full JAMF Pro with an established team to support it. Most of the Macs in the overall environment are 1to1 deployed, and assigned users are encouraged to respond to prompts to update --it's part of their responsibility. But there are still plenty of computer labs/teaching stations where asking end users to participate in keeping the machines updated is not practical. Our current scripted solutions don't seem to work reliably in Big Sur and abov
I've seen several posts about this, and have been struggling with it myself, but I finally found a way to create a sort of maintenance window for Patch Management policies. For our faculty and staff computers, we distribute patches through Self Service patch policies, which is fine. It leaves it to the user to patch when convenient. But for our lab and classroom computers, we don't want to rely on our students to push patches, so we use the automatic installation patch policies. They work fine, but unless the admin updates them during regularly scheduled down-time, the students are forced to quit any applications that need updates shortly after the patch policies are revised. I wanted to find a way to be able to update my patch policies, but not have them trigger until a certain time. Ironically, regular policies have an option to set up a scheduled time using the Client-Side Limitations. Sadly, patch policies do not have this option, so I set about finding a way to emulate this functi
Aside from not seeing the Jamf Connect screen after reboot (separate issue), we are also seeing Guest wifi not popping the acceptance splash screen during the Jamf Connect login. Does Jamf Connect create a blocker for this?
Hello Jamf Nation, We are looking into changing the way we release software updates through Self Service. Currently we utilize AutoPkgr and we have it setup with several custom scrips to automatically upload and attach packages to our policies setup in Patch Management every friday. We are currently looking into switching over to the "Mac Apps" in JAMF with titles managed by JAMF in the JAMF Software Catalog (we have about 30 that can be switched over). After some testing, we love the functionality and the capabilities available in the Mac Apps area with the exception of being able to customize/schedule WHEN software updates are pushed. Again, we currently have all software updates pushed to production every friday but I'm not seeing any way to be able to do that in the Mac Apps area or utilizing Mac Apps in conjunction with Patch Management. Am I missing something? Does anyone know of a way to accomplish this?
We have iPads that we restrict to specific apps and do not allow Safari, but some apps can launch web pages and YouTube from with the app. For instance an App has a menu with an "about" that has a link to their site which has a link to YouTube and the student can watch YouTube videos and it is all through the App they are using and does not open Safari. I have been unable to find a way to block this and wondering if anyone else has come across this problem and found solution?
I am trying to defer macOS Sonoma from showing up in Software Update. I have the deferral set for 90 days. Some Macs continue to show Sonoma in Software Update. I was using a profile that used JSON for the settings. When this profile appeared to not be working properly, I created a new profile using JSON that I got from Jamf this morning. The JSON is below. I was advised to create two profiles. One delays minor updates. The second delays major upgrades. Most Macs seem to work with this profile correctly but there are a few that don't. There seems to be nothing special about these Macs. Has anyone else ran into this issue? I would appreciate some advice on this.{ "title": "com.apple.applicationaccess", "description": "", "properties": { "enforcedSoftwareUpdateMajorOSDeferredInstallDelay": { "title": "Enforced Software Update Major OS Deferred Install Delay ", "description": "", "property_order": 5, "anyOf": [ {"t
A few of my users have been unable to open some apps via self-service since updating to Sonoma.The affected apps are iMovie 10.3.9 and Xcode 15, is this normal?
Hi,due to some unlucky timing with vacation I am now in the situation that I renewed my Jamf built in CA only a week before it expired. Due to this I will have a lot of computers and devices with expiring MDM Profiles. I am trying to renew as many as possible, but is there any way of renewing the profiles of the macs after the profile expires? Would it help to reenroll the macs via the terminal?Kind regards
Split View for Jamf Teacher on iPad please?
Hi there,I wanted to try and avoid reinventing the wheel and thought best to ask here!What are peoples approach to testing the latest OS before releasing to their company?I know theres a short deployment limbo in that machines out of box dont immediately ship with the latest OS, so to my knowledge you cant test that immediate zero touch process, but what about existing machines that are upgraded in place and testing their suitablitilty for the general app estate you have?I know it will be somewhat bespoke to your company, but short of just upgrading, then opening as many apps and loading websites/tools as possible there was a more structured/automated way? Cheers!
Hello Jamf Admins,We've recently found new enrolments not getting Jamf Notifications profile automatically anymore - both DEP enrolled and user-initiated. Tested in Monterey and Ventura - all other profiles are coming OK (Privacy policy control, MDM itself and JAMF Login items for Ventura), however Jamf Notifications is missing.Nothing was changed in Security settings - it's still ticked to install it automatically. Nothing else was changed. Kind of confused now.Of course I can just manually create similar profile and scope it against all devices, but I would prefer JAMF to work as intended.Has anyone seen this issue? Thanks.
I need to script the uninstall of CrowdStrike on Macs. While deploying CrowdStrike this past week, I realized that we may need to push out a policy or make one available in Self Service to uninstall the software. The uninstall command to do this is: sudo /Applications/Falcon.app/Contents/Resources/falconctl uninstall --MANAGMENT TOKENThis command would work perfectly in a script. The issue we have ran into is that using this command sometimes fails. We have not yet gotten a solution from CrowdStrike. The other command that will uninstall the software is:sudo /Applications/Falcon.app/Contents/Resources/falconctl uninstall -tUpon entering that command, we are prompted to enter the management token. The prompt is:Falcon Management Token:I remember several years ago working with some scripts that would respond to password prompts and enter the password needed. Unfortunately, I didn't write those scripts and I don't have them on hand to modify. Does anyone know how to script this
Hello,i have troubles to reset the PW of a hidden Admin account we have on our local clients. I got the message that the password could not be reset because the old password is needed. In this case i delete the user and recreated it again, this now returns the same message."Local admin user exists. Resetting password... An error was encountered while attempting to change the password. /usr/bin/dscl exited Permission denied. Please enter user's old password:<dscl_cmd> DS Error: -14090 (eDSAuthFailed) passwd: DS error: eDSAuthFailed."Is it possible to do a "hard" delete of the user without knowing the password?
Hi Team, Operating system crashing post upgrade form Ventura to Sonoma, happening for multiple endpoints. is there any fix.
I was wanting to see if this is possible before I sign up for JAMF NOW for my home devices. Are you able to use JAMF NOW to turn off the Hotspot feature on a managed iPhone? So, for example, I have a person that I have restricted access to certain sites, but they have gotten around that by using their Hotspot on a phone that I am providing. If I put the phone on JAMF NOW, can I turn off their hotspot functionality? Thanks.
Just wondering if anyone has come up with an extension attribute for Intune integration. Looking to use a smart group to keep track of devices (or users) not yet enrolled in intune.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!