Get Support
Recently active
Hi everyone, we are currently working on enabling a Safari extension. However, we've encountered issues creating the Plist. Do you have any suggestions on enabling extensions for Safari? Are there any recommended Config Profiles?
As described in the subject.I'm looking at forcing installation of certain apps for certain Smart Mobile Device/Network Segments/.... groups whilst making them available for other groups in the Self Service Store. Do I best work with each network segment and assign apps through that or do it otherwise?The setup I have is currently used for 2 schools (segments) and others get added afterwards. Also how do I use 1 VPP account for multiple segments? Kind regards.
Hi, I've had one user machine and one test machine failing to reinstall after an erase and reinstall in Sonoma 14.0 and I fully expected coming in here and realizing everyone was having it, but apparently not. We're on Jamf Pro, using Jamf Connect to create user accounts and twice now, erased and reinstalled computers have become stuck on a black screen during first time setup. It may be relevant that I had only pushed Jamf Connect 2.20 and only now updated to 2.27. Has anyone else had this?
I am wanting to Configure Office 365 Outlook, PowerPoint, OneDrive, SharePoint etc. All to auto login to the Assigned Devices User Email. From O365 Instance. Can Someone help me please? The App Configurations I am finding are not doing anything.
Hi We have upgraded our on prem Jamf from 10.42.1 to 10.47.0 On testing policies all download as they should to devices but when using self service suddenly the machines cannot mount the smb distribution point. We have also enabled HSTS as per the upgrade docs and incrementally upgraded to 10.46.1 first before 10.46.0This was all working fine in 10.42.1 and now not working on 10.47.0Has anyone else had this issue?Nik
hello is there a script out there already or how can i create a script that can determine the Slack app architecture whether the user is using a - (intel, silicon, universal)? version of slack
Hi all,We've recently upgraded our test JAMF on-premises instance from 10.48 to 10.50 - which means management account password became randomised (it wasn't before).Previously, we were using same account as management one with the same password in PreStage enrolment settings (where it's created before Setup Assistant), then we were logging in with that account first to grant volume ownership and bootstrap token privileges, and all MDM commands for software updates worked perfectly (almost).Now, however, we had to switch to another account with another password for all pre-stages, as we obviously cannot keep same name as management one. We've also logged in with that account first to grant all privileges, checked bootstrap token successfully escrowed and tried mass action software update to find nothing is happening.Is it expected behaviour or are we missing something? Thanks!
Unfortunately, the user setting mentioned above does not work. This user's devices are placed in audit mode when restrictions are placed (e.g. Single-App-Mode).
Are there any gotchas to look out for when switching an app (e.g. Chrome or Office365) from a package install via Policies to using App Installers? We're thinking of doing it so that we can enjoy the ease of updating that App Installers provide.
Hello Everyone,I am looking for a product that controls external storage devices when plugged into a Mac. For example, when a user plugs in a flash drive, if the flash drive is encrypted, then allow read-write permissions, if it is unencrypted allow read-only. This product also needs to be hosted on-premises. Any recommendations are appreciated, thank you.
For reasons too long to mention here, I need to acquire the MAC address from a large quantity of new iPads to allow them on a very specific network.Apple School Manager only shows serial, not a MAC.The box/labpack only shows a serial, not a MAC.The “i” information button in the lower right corner of an out of the box iPad now only shows the serial (I believe older models used to show serial, MAC, and some other bit of identification).Reseller/Apple can only provide a list of serial numbers for all items with no corresponding MACs.So far the most simple way I have found is to either:-- Unbox iPad, connect to a temporary wifi network to achieve activation, jump through setup, then pull up MAC in settings.or-- Unbox iPad, connect to a Mac using Apple Configurator, copy and paste MAC.Simple does not always equal efficient and that is very true here!Does anyone have other suggestions for acquiring MAC addresses from a quantity of iPads?
Hello, I have some automated folder action workflows that I want push out to our lab environment. Problem is we have AD based user accounts and the work flow file only ties to individual accounts. Is there anyway for this to apply to anyone who logs in with their own account?
I'm new to Jamf. We have 1 computer that went through the prestage enrollement. I can see the MDM profiles on the device and it states that this mac is supervised and managed but in Jamf it shows as unmanaged, enrolled via automated enrollment =yes, it has not checked in since the device was wiped. Can someone point me in the right direction.
I've seen a lot of posts on this but none quite like I am experiencing. We have a laptop and a desktop prestage. Both create local admin account before setup assistant the laptop creates and admin during enrollment. The desktop skips it. However what we are seeing is the account that gets the SecureToken is a standard account thats pushed via policies. On desktops the prestage localadmin is the first account to login always but yet it doesnt get the securetoken.. The laptop an admin is created during the setup process and that seems to not get it either. This causes a problem when running OS updates or changing a forgotten pw from the localadmin account. Typically, I promote the standard account to admin, login and use a terminal command to give the localadmin a SecureToken.Is there a way to ensure that the Prestage LocalAdmin gets a securetoken everytime?
Hi, I've built a configuration profile with the above preference set on one of our Macs, then uploaded the launcservices plist from it into the profile payload (omitting anything unrelated to Adobe) and deployed that to another test Mac to confirm it works - but PDFs still open in Preview. I've checked and re-checked the plist, and it matches the Mac that does open them in Acrobat Reader DC where relevant. Is there a way to achieve this, besides using Duti (the current build of which I believe doesn't even work under Mojave)?
I am working through migrating computers using the tools provided by Jamf. I've been encountering this issue.When doing the actual enrollment everything appears completely normal and finishes as expected. The first sign something is wrong is that when logging out and going to log back in, our SSO page is not present. It's the normal Mac login page.Then when I check it in Jamf it says "unknown enrollment type" though everything else appears normal.How can I correct this?
Teachers (with managed Apple IDs) can go to the App Store and Share a request for an app for the students. BUT, I would like teachers to have the capability of requesting an app for themselves as well. Currently, I do NOT see that option available.
According to this article the device_aad_information is written to the Jamf database, how can I use this to create a smart group or at least show in Jamf if it is registered with Azure AD https://learn.jamf.com/bundle/technical-paper-microsoft-intune-current/page/Computer_Regisration_for_End_Users.html
hi All, Looking for some advise , We are stating to release macOS Ventura to the org and we have noticed that you can disable certain apps from the Login Items on Ventura - specifically a security agent that we have running...Is there a way to block this? or disable the user from doing it... ThanksRob
This is what I have now, just looking for guidance on making this work #!/bin/sh username=`ls -l /dev/console | cut -d " " -f 4` scutil --set ComputerName "$4""$username" scutil --set HostName "$4""$username".domain scutil --set LocalHostName "$4""$username" jamf recon If I execute this script from terminal following results: SCPreferencesSetLocalHostName() failed: Invalid argument I can run following lines, line by line fine all is good. scutil --set ComputerName whateverUsername scutil --set HostName whateverUsername.domain scutil --set LocalHostName whateverUsername Any suggestions?
Hello All, Just wanted to know if I can enable Jamf app catalog for Google Chrome patching as Google Chrome deployment policy is configured in such a way that after deployment it will enable the Google chrome auto update. Now I am worried if it can cause any issue to patch Google Chrome through Jamf app catalog. Need your suggestion, if it is possible to enable Jamf app catalog then can I do for other apps those are enabled with auto update?
Hello! We have Jamf Safe Internet at our school, and I am trying to locate some information on best practices as far as settings go. Where can I find this?
Not my organization, used a photo from Google.How can I stop the Jamf Connect login window from coming up every time someone uses a computer? We have a lot of shared users and they sign in with an SSO. We want to prevent people from accidentally syncing their account to existing local users, which are usually shared classrooms.Is there a way to do this?
So, i'm trying to use https://github.com/grahampugh/erase-install and I'm having a VERY hard time understanding the steps to make it work.I added the package to Jamf Cloud, and pushed it out to my test computers by policy.How doi I get the various switches into the install? I thought i could make separate polices that included scripts that talk to the installed package. Is this the correct usage?
I work in an education environment and some of the new features in Ventura have prevented our students from using the programs in the way they used to.For example, they have limited access to Garage Band and aren't able to make their own changes or add their own files. Is there some way to give "full access" to applications through Jamf?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!