Get Support
Recently active
We are relatively new to the Jamf / MDM scene. I have a weird issue that I thought maybe someone could explain.I deployed a staff member into a Mac with Jamf Pro. We have his machine in a static group, and there is a configuration profile for a hidden wireless network that we push to our non-Windows devices that we scope for that group.This new staff person randomly was not getting that profile for the wireless network pushed all of a sudden. Other profiles we have set up for that group were still pushing, but not that one. It worked for a week or so, then yesterday it stopped.After inventory updates, etc it still wouldn't push. I was only able to fix it by specifically excluding that machine then "unexcluding" it. When I removed the exclusion for that machine, it immediately connected to that network again.Is this just a bug / quirk? A known issue? Something we are doing that isn't best practice? Just curious what those that have been using this longer could do to explain.Thanks!
I'm pretty new to Jamf, and I've never set up iPads for a school before. I'm wondering how I can set up Jamf to let students and staff use their Google credentials to log in to the iPads.My idea is to have students and staff log in using their Google info. And for the staff, I want to give them extra permissions to manage the iPads that students use in class, like locking the screen and sharing the screen with the Student iPads.Right now, I've already enrolled the iPads with Jamf and Apple School Manager. Any tips or advice on how to move forward would be greatly appreciated!
We're currently in the process of going away from using Umbrella with Anyconnect. We use the Choices Packager 1.0a1.scpt to create our pkg's. Everything works, but the only thing I notice is that throughout the day, the client does a reconnect. When I'm in the office I'll notice popups throughout the day saying it's reconnected. I'm plugged in to the LAN and not wifi.
Hey all!Wondering if there is currently a way to disable Sensitive Content Warning in Privacy & Security specifically. The setting is turned off by default but we're looking into not allowing users to toggle it completely. Is this possible?
Hi All,looking for some advise when it comes to patching MS Office and quickly - Currently I have a config profile deployed to the org to help manage this but it seems to be slow..Im also looking at "Installometer" and currently going through testing but ... Im just looking to see if there is anything else out there that can help me update MS office quickly and easily on the mac.. ThanksRob
Is anyone else seeing an increase in clearing teams cache to get it to open? it started a month or so ago, and has only gotten worse. clearing the cache takes a few seconds, and ive even added an app in self service for my users.
Today we are releasing Jamf Pro 10.48. Highlights of this release include: Conditional Access to Device Compliance MigrationA migration path from the legacy Microsoft Partner Device Management API (macOS Conditional Access) to the new Microsoft Partner Compliance Management API (macOS Device Compliance) is now available. Jamf Pro Dashboard RedesignThe Jamf Pro Dashboard is refreshed to improve the user experience and includes several accessibility improvements. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud
When I upload connect login config profiles from the configurator app the profiles are blank.They still see to work but I was wondering if there is any advantage to uploading plist in application settings.
Hello,Is there download URL for Safari 17 for Ventura? Thanks!
Does anyone know how to disable the macOS Sonoma Large Clock via Jamf Configuration Profile or Script?
Today we released Jamf Connect 2.28.0. This release includes the following changes and improvements: The Secondary Access Group (OIDCSecondaryAccess) setting for the Jamf Connect login window is now available in the Jamf Connect Configuration app. The user experience for computer logins with a Jamf Connect one-time password is improved. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Thank you!The Jamf Connect team Updated 04 October 2023: This post was revised to remove the reference to the login window redirecting users to the Local Login screen when computers are not connected to the internet.
During our deployment we utilize jamf connect for account creation and for password sync thereafter. We don't use connect for login AFTER deployment (we have a policy in DEPnotify that resets authchanger). All is well and good until a macOS update comes along and machines revert authchanger to jamf connect. We have contacted jamf and were told it's a product issue. Now, to fix the issue so it doesn't keep happening. The idea is to place a dummy file on machines DURING enrollment with an extension attribute to verify the file's existence (report a value of true or false) and pull the configuration profile for jamf connect login (excluding a smart group with membership based on extension attribute data). The file/policy is done. The extension attribute is done and reporting correctly. The issue is I can't figure out how to scope a smart group based on the given data. Has anyone done this? Is it possible? Is there a better way to do it?
Hi,I'm using Jamf School and ran into the following problem:Upon installing macOs (Macbook Pro M1), I am receiving an error:Enrolling with management server failedUnexpected errorMDMResponseStatus: 401I have tried to move device to trash or unmanage it, but nothing works. If I wipe macbook and try again - problem happens again.This is how the macbook shows in Jamf School: Anyone can help?
Has anyone figured out how to configure the Camera and Microphone options programmatically? The configuration for "When visiting other websites" under "Camera" and "Microphone" do not appear to be stored in ~ com.apple.Safari. I'm guessing they have been tucked in some sqllite3 db somewhere. I disabled SIP so I could run opensnoop ,hoping to witness the file modification while changing the preferences but came up with nothing. Has anyone come up with a way to set "When visiting other websites" other than manually?
Just curious if anybody has ran in to this before. We switched our office update pkg to include Teams and we didn't remove the autoupdate portion. Now that we switched to it, we're getting quite a bunch of users where teams doesn't open or when they open it, there is a message at the top(screen shot below). For some of the devices, it's auto-updating to the latest version. I'm doing some testing on my mac that removes all the office/teams files and plists. For some reason, my device is still trying to update Teams. I'm testing with the screenshot below. It looks like it's removing all the files, but not sure why it keeps trying to run the update.
Hi Team We are getting this Error for all the users after upgrading the Jamf connect.
Hello, I use the Erase-Install to update/upgrade our Macbooks. But i have a problem. Task is works, macbooks download and install the package then reboot the device. But after reboot erase-install task start again then it dowload the same package again. And when i check the logs from jamf pro, it is "Pending" stiuation. Can you tell me what is wrong?Thank you.
HiWe have a customer with managed Apple MacBook Pro 16" (M2 Pro, 32GB, 512GB).As a backup solution they use the Synology Active Backup for Business solution with the Mac agent.I face problems with the creation of the hidden user, which is need for backup tasks, etc.URL: https://kb.synology.com/en-me/DSM/tutorial/Backup_failed_because_of_hidden_user_issuesThe creation of this hidden user fails, when the password of a filevault enabled user is needed. Steps I tried already are:- Changing the user password to a simple one (No special characters only letters and numbers)- Used administrator account with filevault transfered token.- Tried the root account with filevault transfered token. I didn't disable Filevault, as this would be my last option. Did somebody faced this problem or a similar one? Does someone has a suggestion? Thank youKind regardsDaniel
OK hopefully somebody can help or explain. Let's say we have the following setupA Jamf Server on premise with 2 Distribution Points also on premise only.Distribution Points setup:Public DP = FailoverUS DP = PrincipalNetwork Segment192.168.1.1 - 192.168.255.255 = use Public DP10.0.0.0 - 10.255.255.255 = use US DPok so now we have devices that work outside the LAN at home office. In Jamf I can see for example last reported ip 192.168.1.10. Meaning since he in the range of Public DP the computer should use the public DP. But if I start to install an app from self service I can see in the log file that the device tries to mount the US DP first then fails and then switches over to the failover DP which is the Public DP.My question now why is the device not taking the Public DP as the 1st try since the device is in the range of ip addresses from that network segment Public DP.Can somebody explain this behaviour to me or what am I doing wrong?
HI , I've been trying to get new recovery key and store them in JSS with no luck .I set it as it says on manuals :it get it fails but no errors and no key : anyone made it work? there is a bug I'm not aware of ? Regards ,Meir
Hi. New to jamf, so forgive me if it’s a stupid question.We already have an mdm set up up in ABM with Jamf pro for our company iPhones. We are now moving our Macbooks into jamf pro also. Would it make sense to create a separate mdm sever for the MacBooks. Or should I just use the current jamf pro mdm server, and add the MacBooks onto that on ABM. Thanks.
I package the erase install .pkg running the latest version of swift dialog and input the command /Library/Management/erase-install/erase-install.sh --os 14 --update --reinstall --confirm to update a test machine in Jamf Pro, it is scoped to self service and when I do run it nothing happens, logs show that the password is incorrect and a parse error, I never got a dialog box to enter a password for it to be wrong and also the parse error, does anyone have any insights?
I've got a strange one. I had played around with trials of Jamf Protect and Jamf Connect back in March of this year but ultimately removed them. I must have done so incorrectly (likely deleted the Profiles from the Jamf tenant rather than un-scoping my machines and THEN deleting the profiles). Regardless, I have clicked the "Remove MDM Profile" button under Management and everything leaves the Mac. Then I ran sudo Jamf removeFramework to start with a clean slate. When I run sudo profiles renew -type enrollment, these phantom profiles somehow come back. (This is a DEP machine, my personal 2020 M1 MBP). They are NOT anywhere in the Jamf tenant, I have no clue where they are coming from. BTW these same phantom profiles are not in the list of scoped Profiles in the Management tab. FWIW, I did a test on an older 2017 Intel (non-DEP laptop I use for testing. I wiped it and user-approved Jamf. Same result...these non-existent Profiles reinstalled themselves. They are not user or admin removab
Hi there,We're currently getting an influx of users who need to "update" simple apps like Keybase but those updates require admin permissions. To work around that requirement I add an update script to the Self Service portal which gets the job done but is there any way to maybe create a PPPC policy that will permit the user to update a version of software, I'm not sure what type of access is needed i.e full disk access or system file access that is being prompted in the admin credentials since it's non-descript.I know there are also other solutions like Admin By Request that allows on-demand access to user elevation.
Does anyone have an idea or experience with this issue?When you try to log in to the JAMF PRO it's stuck on the login page not giving any error URL being accessed -: https://Mycompany:8443/ Username/password - my company credentials (SSO)JAMF Pro runs on a server 2019Tried to access the JAMF Pro using the above link Enter my username and password no response from the page.Tried with the wrong username and password to check still no response/error from the page.Restarted the Apache and the Windows server still had the same issue.Could someone help?Thanks in advance
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!