Get Support
Recently active
Hello, So we are having a bit of a struggle here, since the begining I've never wanted to use the Patch Management feature because there was only a defined set of apps usable, and thus you had to have apps in here, and the unsuported ones in the policy section. I didn't like that so I went for a full policy updating workflow.It actually works pretty well, I even created some scripts so you can easy add any type of pckage you want and you just have to tweak thhe paramters to control the installation process, very handy.But the problem we have is that it seems impossible to filter computers in smart group by "less than" for a software version. It's a nightmare, so we've been updating as soon as possible the precise version in these groups and update de package as sson as possible. But if for some reason an update gets released and we don't react fast enough some computers might auto update some stuff, and then jamf would then downgrade the app, cause it doesnt match our policy.....&
requirements: OS X updates for "shared" machines in an Educational environment will be deployed during a scheduled maintenance window when labs are closed. At no point shall a student or teacher ever be prompted for any action re: updates. The SLA for shared/public workstations is that machines are patched by IT--this process must be fully automated so that IT staff doesn't have to run around logging into machines to patch them. What is the current thinking on how best to accomplish this? The environment is full JAMF Pro with an established team to support it. Most of the Macs in the overall environment are 1to1 deployed, and assigned users are encouraged to respond to prompts to update --it's part of their responsibility. But there are still plenty of computer labs/teaching stations where asking end users to participate in keeping the machines updated is not practical. Our current scripted solutions don't seem to work reliably in Big Sur and abov
I've seen several posts about this, and have been struggling with it myself, but I finally found a way to create a sort of maintenance window for Patch Management policies. For our faculty and staff computers, we distribute patches through Self Service patch policies, which is fine. It leaves it to the user to patch when convenient. But for our lab and classroom computers, we don't want to rely on our students to push patches, so we use the automatic installation patch policies. They work fine, but unless the admin updates them during regularly scheduled down-time, the students are forced to quit any applications that need updates shortly after the patch policies are revised. I wanted to find a way to be able to update my patch policies, but not have them trigger until a certain time. Ironically, regular policies have an option to set up a scheduled time using the Client-Side Limitations. Sadly, patch policies do not have this option, so I set about finding a way to emulate this functi
Aside from not seeing the Jamf Connect screen after reboot (separate issue), we are also seeing Guest wifi not popping the acceptance splash screen during the Jamf Connect login. Does Jamf Connect create a blocker for this?
Hello Jamf Nation, We are looking into changing the way we release software updates through Self Service. Currently we utilize AutoPkgr and we have it setup with several custom scrips to automatically upload and attach packages to our policies setup in Patch Management every friday. We are currently looking into switching over to the "Mac Apps" in JAMF with titles managed by JAMF in the JAMF Software Catalog (we have about 30 that can be switched over). After some testing, we love the functionality and the capabilities available in the Mac Apps area with the exception of being able to customize/schedule WHEN software updates are pushed. Again, we currently have all software updates pushed to production every friday but I'm not seeing any way to be able to do that in the Mac Apps area or utilizing Mac Apps in conjunction with Patch Management. Am I missing something? Does anyone know of a way to accomplish this?
We have iPads that we restrict to specific apps and do not allow Safari, but some apps can launch web pages and YouTube from with the app. For instance an App has a menu with an "about" that has a link to their site which has a link to YouTube and the student can watch YouTube videos and it is all through the App they are using and does not open Safari. I have been unable to find a way to block this and wondering if anyone else has come across this problem and found solution?
I am trying to defer macOS Sonoma from showing up in Software Update. I have the deferral set for 90 days. Some Macs continue to show Sonoma in Software Update. I was using a profile that used JSON for the settings. When this profile appeared to not be working properly, I created a new profile using JSON that I got from Jamf this morning. The JSON is below. I was advised to create two profiles. One delays minor updates. The second delays major upgrades. Most Macs seem to work with this profile correctly but there are a few that don't. There seems to be nothing special about these Macs. Has anyone else ran into this issue? I would appreciate some advice on this.{ "title": "com.apple.applicationaccess", "description": "", "properties": { "enforcedSoftwareUpdateMajorOSDeferredInstallDelay": { "title": "Enforced Software Update Major OS Deferred Install Delay ", "description": "", "property_order": 5, "anyOf": [ {"t
A few of my users have been unable to open some apps via self-service since updating to Sonoma.The affected apps are iMovie 10.3.9 and Xcode 15, is this normal?
Hi,due to some unlucky timing with vacation I am now in the situation that I renewed my Jamf built in CA only a week before it expired. Due to this I will have a lot of computers and devices with expiring MDM Profiles. I am trying to renew as many as possible, but is there any way of renewing the profiles of the macs after the profile expires? Would it help to reenroll the macs via the terminal?Kind regards
Split View for Jamf Teacher on iPad please?
Hi there,I wanted to try and avoid reinventing the wheel and thought best to ask here!What are peoples approach to testing the latest OS before releasing to their company?I know theres a short deployment limbo in that machines out of box dont immediately ship with the latest OS, so to my knowledge you cant test that immediate zero touch process, but what about existing machines that are upgraded in place and testing their suitablitilty for the general app estate you have?I know it will be somewhat bespoke to your company, but short of just upgrading, then opening as many apps and loading websites/tools as possible there was a more structured/automated way? Cheers!
Hello Jamf Admins,We've recently found new enrolments not getting Jamf Notifications profile automatically anymore - both DEP enrolled and user-initiated. Tested in Monterey and Ventura - all other profiles are coming OK (Privacy policy control, MDM itself and JAMF Login items for Ventura), however Jamf Notifications is missing.Nothing was changed in Security settings - it's still ticked to install it automatically. Nothing else was changed. Kind of confused now.Of course I can just manually create similar profile and scope it against all devices, but I would prefer JAMF to work as intended.Has anyone seen this issue? Thanks.
I need to script the uninstall of CrowdStrike on Macs. While deploying CrowdStrike this past week, I realized that we may need to push out a policy or make one available in Self Service to uninstall the software. The uninstall command to do this is: sudo /Applications/Falcon.app/Contents/Resources/falconctl uninstall --MANAGMENT TOKENThis command would work perfectly in a script. The issue we have ran into is that using this command sometimes fails. We have not yet gotten a solution from CrowdStrike. The other command that will uninstall the software is:sudo /Applications/Falcon.app/Contents/Resources/falconctl uninstall -tUpon entering that command, we are prompted to enter the management token. The prompt is:Falcon Management Token:I remember several years ago working with some scripts that would respond to password prompts and enter the password needed. Unfortunately, I didn't write those scripts and I don't have them on hand to modify. Does anyone know how to script this
Hello,i have troubles to reset the PW of a hidden Admin account we have on our local clients. I got the message that the password could not be reset because the old password is needed. In this case i delete the user and recreated it again, this now returns the same message."Local admin user exists. Resetting password... An error was encountered while attempting to change the password. /usr/bin/dscl exited Permission denied. Please enter user's old password:<dscl_cmd> DS Error: -14090 (eDSAuthFailed) passwd: DS error: eDSAuthFailed."Is it possible to do a "hard" delete of the user without knowing the password?
Hi Team, Operating system crashing post upgrade form Ventura to Sonoma, happening for multiple endpoints. is there any fix.
I was wanting to see if this is possible before I sign up for JAMF NOW for my home devices. Are you able to use JAMF NOW to turn off the Hotspot feature on a managed iPhone? So, for example, I have a person that I have restricted access to certain sites, but they have gotten around that by using their Hotspot on a phone that I am providing. If I put the phone on JAMF NOW, can I turn off their hotspot functionality? Thanks.
Just wondering if anyone has come up with an extension attribute for Intune integration. Looking to use a smart group to keep track of devices (or users) not yet enrolled in intune.
We are relatively new to the Jamf / MDM scene. I have a weird issue that I thought maybe someone could explain.I deployed a staff member into a Mac with Jamf Pro. We have his machine in a static group, and there is a configuration profile for a hidden wireless network that we push to our non-Windows devices that we scope for that group.This new staff person randomly was not getting that profile for the wireless network pushed all of a sudden. Other profiles we have set up for that group were still pushing, but not that one. It worked for a week or so, then yesterday it stopped.After inventory updates, etc it still wouldn't push. I was only able to fix it by specifically excluding that machine then "unexcluding" it. When I removed the exclusion for that machine, it immediately connected to that network again.Is this just a bug / quirk? A known issue? Something we are doing that isn't best practice? Just curious what those that have been using this longer could do to explain.Thanks!
I'm pretty new to Jamf, and I've never set up iPads for a school before. I'm wondering how I can set up Jamf to let students and staff use their Google credentials to log in to the iPads.My idea is to have students and staff log in using their Google info. And for the staff, I want to give them extra permissions to manage the iPads that students use in class, like locking the screen and sharing the screen with the Student iPads.Right now, I've already enrolled the iPads with Jamf and Apple School Manager. Any tips or advice on how to move forward would be greatly appreciated!
We're currently in the process of going away from using Umbrella with Anyconnect. We use the Choices Packager 1.0a1.scpt to create our pkg's. Everything works, but the only thing I notice is that throughout the day, the client does a reconnect. When I'm in the office I'll notice popups throughout the day saying it's reconnected. I'm plugged in to the LAN and not wifi.
Hey all!Wondering if there is currently a way to disable Sensitive Content Warning in Privacy & Security specifically. The setting is turned off by default but we're looking into not allowing users to toggle it completely. Is this possible?
Hi All,looking for some advise when it comes to patching MS Office and quickly - Currently I have a config profile deployed to the org to help manage this but it seems to be slow..Im also looking at "Installometer" and currently going through testing but ... Im just looking to see if there is anything else out there that can help me update MS office quickly and easily on the mac.. ThanksRob
Is anyone else seeing an increase in clearing teams cache to get it to open? it started a month or so ago, and has only gotten worse. clearing the cache takes a few seconds, and ive even added an app in self service for my users.
Today we are releasing Jamf Pro 10.48. Highlights of this release include: Conditional Access to Device Compliance MigrationA migration path from the legacy Microsoft Partner Device Management API (macOS Conditional Access) to the new Microsoft Partner Compliance Management API (macOS Device Compliance) is now available. Jamf Pro Dashboard RedesignThe Jamf Pro Dashboard is refreshed to improve the user experience and includes several accessibility improvements. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!