Get Support
Recently active
I created a script that will tell you what the latest available macOS is that you can install on your hardware but will not run as an extension attribute, it shows blank but if I run it manually it will show the macOS version.Does anyone know how I can fix the script to make it work for an extension attribute?Thanks in advance,#!/bin/bash # All models, model indentifiers, and macOS compatibility provided by Apple. # List will need to be updated when new model come out. # MacBook Pro - https://support.apple.com/en-us/HT201300 # MacBook Air - https://support.apple.com/en-us/HT201862 # iMac - https://support.apple.com/en-us/HT201634 # Mac Mini - https://support.apple.com/en-us/HT201894 # Mac Pro - https://support.apple.com/en-us/HT202888 # Mac Studio - https://support.apple.com/en-us/HT213073 # Read system profile and extract the model identifier system_profile=$(system_profiler SPHardwareDataType) model_identifier=$(echo "$system_profile" | awk -F': ' '/Model Identifier/ {print $2}'
Hello Jamf Nation, Following the exciting news last week at JNUC of Jamf Pro 11 coming soon, we know many of you have questions as to what this means for your existing Jamf certifications and what our plans are moving forward for training courses and certifications. To that end, we have put together the following questions and answers, which we hope address as many of these as possible. Look for another post once Jamf Pro 11 comes out with additional details then. -Jamf Training What happens to my existing Jamf Certified Tech, Admin, and/or Expert Certifications? Nothing! Per our Training Policies, your Jamf Pro 10 certifications are valid indefinitely for Jamf Pro 10. We will not be making any alterations to previously issued certifications and will continue to accept them as prerequisites for Jamf Pro 11 courses. For example, if you have achieved your Jamf Certified Tech certification on Jamf Pro 10, you will be able to use that as a prerequisite for the Jamf 300 or 370 Course
I have an issue of a new batch of devices that were ordered through our company's vendor like normal. The macs are prompted for "remote management" screen and then "username and password" with a tuxedo logo on the left of it. Usually it is supposed to prompt for Email on the Microsoft sign in page, but these arent. Any idea why?
We're trying to setup a few loaner devices at our schools in the event a kid forgets their iPad.I setup two iPad 9th gens for testing, setup the ADEP profile for a shared device, all users are setup in ASM.I logged in as a user and was prompted to create a passcode, great. Then I logged out and logged in with another user and it worked the same.The problem is now when you go to the other iPad to sign in it takes the shared iPad passcode, logs in for about 10-15 seconds, the automatically logs the user out stating "Login failed please try again"I've been messing with them for about a day and just can't find any reason for this to be happening. Has anyone else ever seen this issue?
After update from 13.6 (working) to v14 this option is not working anymore also when I put the clock back in de original position (right corner) this option isnt working (anymore) idea? thanks
Good morning, everyone! Does anyone have a new JAMF project planning template I could use? Rolling out a deployment from scratch at my new job and want to make sure I cover everything the higher ups might want to request. I have experience in JAMF Pro, but haven't ever planned a deployment. Thanks!
Hello everyone,Last year (Monterey) and the year before (Big Sure) we encountered problems now and then when enrolling Mac.Depending on what version om macOS that was installed the Macs crashed/shutdown with black screen in the end of the prestage installation. If macOS hade certain version they past through and everything was good. The others needed to be reinstalled and reenrolled, sometimes two or three times.This year I found out what was causing the problem. It was the prestage setup, the assistent options - what to show or not to show when starting upp the Mac after installation.The setup for last year and the year before looked as follows that:This setup did't work very well, not better with Ventura. I experimented with the setup a bit and finally got a good one for Monterey (not all older versions) and Ventura. It looks like this:Now it's soon time for Sonoma. So I've installed the latest beta on a machine (beta 6). The prestage goes through but when you click later or not
I’m looking to switch our organization from Jamf Now to Jamf Pro, we have about 200 devices (iPads). From my understanding we’ll need to erase every device and setup as new on Pro. Is this information correct, or are there other options? I’ll be the main point of contact in assisting transitioning devices over. These devices are in the field using AT&T cellular, as you can assume, the transition will take a while. Any help would greatly be appreciated.
Hi, We're looking to push out Wifi settings via Configuration Profiles to 10.7 and above machines. In testing and pilot this is working well. When we go live to the rest of the campus we'd like to be able to search/report on devices which do and don't have the profile installed. We've hunted high and low to find this, but don't seem to have any luck - is this possible? TIA Andy
Hello all! This is my first post on Jamf Nation - I'm a newcomer to Jamf and Apple in general, having taken over for my organization's previous Jamf admin.Some backstory:Currently, we install macOS updates by downloading the OS .app, packaging it in Composer as a .dmg, staging the update package on our endpoints via policy, and then using a second policy to initiate the installation with the following command: echo '<localAdminPassword>' | '/Applications/Install macOS Ventura.app/Contents/Resources/startosinstall' --agreetolicense --forcequitapps --nointeraction --user <localAdminUsername> --stdinpass This works great for initiating after-hours installs. However, my leadership has indicated they'd like an option for users to kick off updates from Self Service. While I can make this available in Self Service as-is, the problem is that this doesn't allow the user to control when the endpoint reboots; it doesn't even notify them a reboot is incoming.
From time to time I encounter policies that get stuck in pending and I don't know how to resolve the issue.Example, today a new system was setup for a user and enrollment complete fine. I have an enrollment trigger set for a provisioning package that installs all of our basic applications. This is the first time it didn't function - I can see the trigger is active and the logs show pending, but nothing happened after 20 minutes and a restart.In order to get the policy to run I had to scope it to self service to be run manually, which worked, but now the original enrollment provision is still sitting in pending with no failure or option to cancel.How do you resolve this? Both to get a pending to run and to cancel a no longer needed policy sitting in pending.
Hi everyone, Have a config profile that it seems to be corrupted, i can't update it or remove it from my Mac fleet .. contacted Jamf and it seems they still have issues with config profiles "PI112875" and so far nothing has been fixed .. The profile that is stuck has Security & Privacy payload, creating a new one with the same payload is failing to get installed since all the devices still have the old corrupted one.Thought to post it here and ask if anyone can help with any ideas .. TIA
Hello, I am attempting to disable 2 settings in outlook for mac Office 365 New look 16.77.1 the 2 settings are Disable "Encrypt-Only"Prevent users from applying the Encrypt-Only option to emails when using Microsoft 365 Message Encryption.Category Details Domaincom.microsoft.OutlookKeyDisableEncryptOnlyData TypeBooleanPossible valuesfalse (default)trueRequires Configuration ProfileNoAvailability16.40CommentsOnly applies to the new Outlook.Disable "Do Not Forward"Prevent users from applying the Do Not Forward option to emails when using Microsoft 365 Message Encryption.Category Details Domaincom.microsoft.OutlookKeyDisableDoNotForwardData TypeBooleanPossible valuesfalse (default)trueRequires Configuration ProfileNoAvailability16.40CommentsOnly applies to the new Outlook. I ransudo defaults write com.microsoft.Outlook DisableEncryptOnly -bool TRUE sudo defaults write com.microsoft.Outlook DisableDoNotForward -bool TRUE in termin
Using this json from https://github.com/macadmins/nudge/blob/main/Schema/jamf/com.github.macadmins.Nudge.json I am unable to get the mainHeader, subHeader and other elements customized with the text that I want. After I make a change in the configuration profile I see that the changes I made show up in /Library/Managed Preferences/com.github.macadmins.Nudge.plist but the Nudge app does not show these changes. What did work was changing the icon paths for light and dark modes. Does anyone have some tips on how to get this text to change? I have been quitting Nudge and relaunching it after each change I make. Nudge seems to be working well otherwise. Thanks!
Hello, I am trying to test the automated enrolment process via ABM to Jamf Pro, when trying to complete this process I receive the error MDMResponseStatus error 500. I have manually added a couple of devices to ABM, switch their MDM assignment to point at Jamf Pro, waited to see the device show under devices in Automated device enrolment then restarted. I then go to setup the device and receive our welcome screen, at the stage is says "Installing enrolment profile" we then receive the above error. This test has been done on a couple of different devices, on different networks, they do not seem to be going into the mobiles devices either as some have experienced. I have tried fully removing all records of the device from ABM & Jamf Pro then trying again but receive the same error. Am I missing something simple here, has anyone else come across this before and knows how to resolve it? It would be a great help, thanks for your time and much appreciat
I'm trying to complete a script run by a launchdaemon to delete a specific account if it is over X hours old. I started with Sean Rabbit's similar script here. But drifted away as I didn't need all that.I've tried "dscl -delete" and "sysadminctl -deleteUser" but they just convert the account to a standard user.I'm now trying to use "jamf deleteAccount" but it doesn't even seem to run (log created, but nothing in it).In all three cases the script works fine when run with sudo, and it's my understanding that /Library/LaunchDaemons/ are run as root? #!/bin/bash # Some Variables jamfBinary="/usr/local/bin/jamf" user="eucadmin" ageLimit=5 #in minutes ageLimit=$((ageLimit * 60)) currentTime=$(date +%s) #list users and if our target is on the machine check its admin and then if it's too old delete it users=$(/usr/bin/dscl . list /Users) if echo "$users" | /usr/bin/grep -wq "$user" && groups eucadmin | grep -qw admin;then userCreateTime=$(/usr/bin/dscl . -readpl
Hoping some of you folks who use Nudge for OS updates can help me out. I'm having trouble getting the Deferred Count to show anything but 0, even after multiple times closing the window by clicking the Later button. I think I have the config profile set up correctly, but I feel like something may not be right or has been left out.Here is my plist:<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>osVersionRequirements</key> <array> <dict> <key>requiredInstallationDate</key> <string>2023-01-06T12:00:00Z</string> <key>requiredMinimumOSVersion</key> <string>12.6.1</string> <key>targetedOSVersionsRule</key> <string/> </dict> </array> <key>userExperi
This is a test message to see if I can post hereas I recently joined Beta.
Hello All, I am looking for the URL to script to download the latest version MS Edge and to install on macOS when it will execute on mac device. I dont want to download and upload and add this latest .pkg every month in my Jamf policy. But after download I can see the URL is version dependent, do anyone has any suggestion how to get a fix URL so that same URL will download the latest version of MS Edge .pkg every month without changing the URL in my policy, I want to do it just I like MS Office package after taking the URL from https://macadmins.software Please help me for Edge browser.
Hi there, We are having some issues with the deployment of Jamf Connect. Seems a handful of people once Jamf Connect deploys to their machine and they get to the process of associating the local account with their IDP account, after the initial IDP login they're prompted to enter their local password and the passwords are not accepted even though we know for certain their password was entered correctly.About 80% of people migrate successfully while the remaining are having these issues only during the migration phase. Since we do a rollout without FileVault we have to wipe these machines to get the employee back working.Does anyone know what the cause of this issue is? We've checked keyboard inputs, the MacBooks themselves are all sourced from the same supplier with no variation between the region. It just seems very much like RNG at this point. We've tried external keyboards as well, since you cant view the password being entered a good assumption would be that even though the pa
We are trying to determine which computers are being shared in the company and to do so we need to know how many users there are per machine. Is there a way to report how many local user accounts per computer we have and list them? I tried some reports, scripts, etc but they only show me lastuser or duplicate computers with the same user. Thanks
Hello all,I am noticing that in iPadOS17 the method we used to set the Home Screen of a Shared iPad is no longer working.Previously we were able to do so by sending the wallpaper out via a smart group. For some reason in iPadOS 17, this method now only works with the Lock Screen. The Home Screen just turns black, and in Jamf Pro I see the message in Failed Commands: Settings - WallpaperThe wallpaper image could not be applied.Anyone else seeing this and/or have a solution?Thanks!
So im seeing a few posts that show some steps for blocking the pop up message in Venture about Background Items added, however I'm not seeming to have much success in blocking this notification. Im working on installing the smart client for Uniflow and am looking to block this notification from showing:Ive grabbed all the info from the process, and just am trying to make a config profile based on this. Anyone have this successfully blocked already who can chime in? UUID: 24282C71-85D9-4058-8CA6-534FF2F0024E Name: uniFLOW SmartClient Developer Name: NT-WARE Systemprogrammierungs-GmbH Team Identifier: 4M6FV5A8E6 Type: legacy agent (0x10008) Disposition: [enabled, allowed, visible, not notified] (3) Identifier: com.ntware.SmartClient URL: file:///Library/LaunchAgents/com.ntware.SmartClient.plist Executable Path: /Applications/uniFLOW SmartClient.app Generation: 0 Parent I
Anyone ever successfully configured ldap with FreeIPA? I can query users, and groups, but not if users are members of any groups.
Hello everyone, Our district has two seperate public SSIDs: CCS Devices (installed via profile) Concord BYOD (open public network) While all iPads are told to auto-connect to the CCS Devices SSID, this doesn't stop students from manually joining the guest network. When this happens, Apple Classroom is not able to see the students if the Teacher iPad is on CCS Device and the students are on BYOD. We have allowed the ports found in this support article:https://support.apple.com/guide/deployment-education/requirements-classes-synced-apple-school-edud491bf924/web Has anyone ran into this before? Any help would be appreciated! - - - UPDATE - - - We have moved away from open guest networks. This is no longer an issue for us!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!