Get Support
Recently active
When I upload connect login config profiles from the configurator app the profiles are blank.They still see to work but I was wondering if there is any advantage to uploading plist in application settings.
Hello,Is there download URL for Safari 17 for Ventura? Thanks!
Does anyone know how to disable the macOS Sonoma Large Clock via Jamf Configuration Profile or Script?
Today we released Jamf Connect 2.28.0. This release includes the following changes and improvements: The Secondary Access Group (OIDCSecondaryAccess) setting for the Jamf Connect login window is now available in the Jamf Connect Configuration app. The user experience for computer logins with a Jamf Connect one-time password is improved. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Thank you!The Jamf Connect team Updated 04 October 2023: This post was revised to remove the reference to the login window redirecting users to the Local Login screen when computers are not connected to the internet.
During our deployment we utilize jamf connect for account creation and for password sync thereafter. We don't use connect for login AFTER deployment (we have a policy in DEPnotify that resets authchanger). All is well and good until a macOS update comes along and machines revert authchanger to jamf connect. We have contacted jamf and were told it's a product issue. Now, to fix the issue so it doesn't keep happening. The idea is to place a dummy file on machines DURING enrollment with an extension attribute to verify the file's existence (report a value of true or false) and pull the configuration profile for jamf connect login (excluding a smart group with membership based on extension attribute data). The file/policy is done. The extension attribute is done and reporting correctly. The issue is I can't figure out how to scope a smart group based on the given data. Has anyone done this? Is it possible? Is there a better way to do it?
Hi,I'm using Jamf School and ran into the following problem:Upon installing macOs (Macbook Pro M1), I am receiving an error:Enrolling with management server failedUnexpected errorMDMResponseStatus: 401I have tried to move device to trash or unmanage it, but nothing works. If I wipe macbook and try again - problem happens again.This is how the macbook shows in Jamf School: Anyone can help?
Has anyone figured out how to configure the Camera and Microphone options programmatically? The configuration for "When visiting other websites" under "Camera" and "Microphone" do not appear to be stored in ~ com.apple.Safari. I'm guessing they have been tucked in some sqllite3 db somewhere. I disabled SIP so I could run opensnoop ,hoping to witness the file modification while changing the preferences but came up with nothing. Has anyone come up with a way to set "When visiting other websites" other than manually?
Just curious if anybody has ran in to this before. We switched our office update pkg to include Teams and we didn't remove the autoupdate portion. Now that we switched to it, we're getting quite a bunch of users where teams doesn't open or when they open it, there is a message at the top(screen shot below). For some of the devices, it's auto-updating to the latest version. I'm doing some testing on my mac that removes all the office/teams files and plists. For some reason, my device is still trying to update Teams. I'm testing with the screenshot below. It looks like it's removing all the files, but not sure why it keeps trying to run the update.
Hi Team We are getting this Error for all the users after upgrading the Jamf connect.
Hello, I use the Erase-Install to update/upgrade our Macbooks. But i have a problem. Task is works, macbooks download and install the package then reboot the device. But after reboot erase-install task start again then it dowload the same package again. And when i check the logs from jamf pro, it is "Pending" stiuation. Can you tell me what is wrong?Thank you.
HiWe have a customer with managed Apple MacBook Pro 16" (M2 Pro, 32GB, 512GB).As a backup solution they use the Synology Active Backup for Business solution with the Mac agent.I face problems with the creation of the hidden user, which is need for backup tasks, etc.URL: https://kb.synology.com/en-me/DSM/tutorial/Backup_failed_because_of_hidden_user_issuesThe creation of this hidden user fails, when the password of a filevault enabled user is needed. Steps I tried already are:- Changing the user password to a simple one (No special characters only letters and numbers)- Used administrator account with filevault transfered token.- Tried the root account with filevault transfered token. I didn't disable Filevault, as this would be my last option. Did somebody faced this problem or a similar one? Does someone has a suggestion? Thank youKind regardsDaniel
OK hopefully somebody can help or explain. Let's say we have the following setupA Jamf Server on premise with 2 Distribution Points also on premise only.Distribution Points setup:Public DP = FailoverUS DP = PrincipalNetwork Segment192.168.1.1 - 192.168.255.255 = use Public DP10.0.0.0 - 10.255.255.255 = use US DPok so now we have devices that work outside the LAN at home office. In Jamf I can see for example last reported ip 192.168.1.10. Meaning since he in the range of Public DP the computer should use the public DP. But if I start to install an app from self service I can see in the log file that the device tries to mount the US DP first then fails and then switches over to the failover DP which is the Public DP.My question now why is the device not taking the Public DP as the 1st try since the device is in the range of ip addresses from that network segment Public DP.Can somebody explain this behaviour to me or what am I doing wrong?
HI , I've been trying to get new recovery key and store them in JSS with no luck .I set it as it says on manuals :it get it fails but no errors and no key : anyone made it work? there is a bug I'm not aware of ? Regards ,Meir
Hi. New to jamf, so forgive me if it’s a stupid question.We already have an mdm set up up in ABM with Jamf pro for our company iPhones. We are now moving our Macbooks into jamf pro also. Would it make sense to create a separate mdm sever for the MacBooks. Or should I just use the current jamf pro mdm server, and add the MacBooks onto that on ABM. Thanks.
I package the erase install .pkg running the latest version of swift dialog and input the command /Library/Management/erase-install/erase-install.sh --os 14 --update --reinstall --confirm to update a test machine in Jamf Pro, it is scoped to self service and when I do run it nothing happens, logs show that the password is incorrect and a parse error, I never got a dialog box to enter a password for it to be wrong and also the parse error, does anyone have any insights?
I've got a strange one. I had played around with trials of Jamf Protect and Jamf Connect back in March of this year but ultimately removed them. I must have done so incorrectly (likely deleted the Profiles from the Jamf tenant rather than un-scoping my machines and THEN deleting the profiles). Regardless, I have clicked the "Remove MDM Profile" button under Management and everything leaves the Mac. Then I ran sudo Jamf removeFramework to start with a clean slate. When I run sudo profiles renew -type enrollment, these phantom profiles somehow come back. (This is a DEP machine, my personal 2020 M1 MBP). They are NOT anywhere in the Jamf tenant, I have no clue where they are coming from. BTW these same phantom profiles are not in the list of scoped Profiles in the Management tab. FWIW, I did a test on an older 2017 Intel (non-DEP laptop I use for testing. I wiped it and user-approved Jamf. Same result...these non-existent Profiles reinstalled themselves. They are not user or admin removab
Hi there,We're currently getting an influx of users who need to "update" simple apps like Keybase but those updates require admin permissions. To work around that requirement I add an update script to the Self Service portal which gets the job done but is there any way to maybe create a PPPC policy that will permit the user to update a version of software, I'm not sure what type of access is needed i.e full disk access or system file access that is being prompted in the admin credentials since it's non-descript.I know there are also other solutions like Admin By Request that allows on-demand access to user elevation.
Does anyone have an idea or experience with this issue?When you try to log in to the JAMF PRO it's stuck on the login page not giving any error URL being accessed -: https://Mycompany:8443/ Username/password - my company credentials (SSO)JAMF Pro runs on a server 2019Tried to access the JAMF Pro using the above link Enter my username and password no response from the page.Tried with the wrong username and password to check still no response/error from the page.Restarted the Apache and the Windows server still had the same issue.Could someone help?Thanks in advance
In my Restrictions profile for our pre-k kids I would like to hide this as it will most certainly be a distraction. However when I go to Apps/App Usage/Some apps not allowed and start typing Freeform it does not come up I the list of apps/Bundle ID's. Thanks,Robert
Is there a way to clear Safari's cache on our managed iPads using Jamf school?
I am testing out using iMazing Profile Editor and the app works great, and I can save the new profile and upload into Jamf and scope to my test machine and it applies and makes the changes needed which is great. The instructions I'm following say to sign the profile and when I choose to sign the profile within iMazing I have 2 options, the first one says DEP-my serial number and the other option is a long string of letters/numbers, so I'm not sure which to choose and I'm not even sure if this is needed since it worked the first time without signing, so I guess my question is do I need to sign the profile since it already worked without being signed, or will I see issues down the road if I don't sign it and if so, how do I know which cert to use to sign the profile? When I look at the certs in Keychain DEP-my serial number shows Jamf SCEP Intermediate CA as "issued by" and for the other cert with long letters and numbers within Keychain the "issued by" shows JSS Built-in Certificate Aut
We have been having this issue for months and have opened multiple support tickets. Just wanted to see if anyone from the community has resolved this issue.Things we have tried:- upgrading to version 2.27.0- re-pushing the License configuration profile- adding the updated launchagent to our PreStageIt seems this issue is caused by an invalid license, according to the Jamf Documentation: https://learn.jamf.com/bundle/jamf-connect-documentation-current/page/Installation_and_Licensing.html"If a license expires or if Jamf Connect detects that an invalid license key has been applied to the configuration, the following functionality will cease: The Sign In window, accessed from the menu bar app under Connect..., will no longer function. Username and Password fields will be grayed out and users will not be able to click the Sign In button."And for the deployment method for the License, there is one of two ways to deploy it. The one we use is Copy and paste encoded license string int
Hello,I am currently cleaning up our printers on our Macs. I have created a script to remove printers using lpadmin -x command. I created a script for six printers and noticed two of them do not get deleted. I am using the CUPs name in the script to delete unwanted printers. I believe these two printers that are not getting removed are very old and the CUPs name is not accurate so its just skipping the step to delete the printer. These two printers are no longer in Jamf and all our employees are remote so trying to get the actual CUPs name is a bit difficult. Is there a script I can run to either delete the printers based on the Device URI ie: lpd://10.1.1.1 or another way where I can run a script to collect the CUPs name of the printers that won't delete using my current script? If I can somehow get the actual CUPs name of the printers then I can revise my current script to delete those two printers that are still hanging around.
Hello all, I'm trying to create a policy to remove printers with a script. The script I found on here that I'm trying to use is: #!/bin/sh # remove all printers rm -rf /etc/cups/printers.conf # restart cups killall cupsd exit 0 When I put it in a policy in Self Service and run it I get the following back in the log: Executing Policy Remove Printers Script... [STEP 1 of 2] Mounting casdjamf.chambersburg.k12.pa.us to /Volumes/CasperShare... [STEP 2 of 3] Mounting casdmac to /Volumes/CasperShare 1... Error: Could not mount distribution point "casdmac". [STEP 3 of 3] Running script removeprinters.sh... Script exit code: 126 Script result: sh: /Library/Application Support/JAMF/tmp/removeprinters.sh: /bin/sh #: bad interpreter: No such file or directory I tried running the script using the sh command in terminal I don't get any error messages, but I still have my printers as well. I tried doing some research here and through Google but I'm still kind of
Does anyone else here use ConnectWise Automate (ie - not the standalone Screenconnect product)? I'm having trouble doing a clean and silent install for both the Remote Agent and the ConnectWiseControl piece. Looking for advice on how to roll forward with a silent installation of both of these pieces of ConnectWise Automate (CWA), so that they appear and work with our console correctly. What I currently have and what I'm currently seeing:When logged into the CWA Console, I am able to download the MacOS Agent installer that is setup to put the device into our instance of CWA. I have the following related PPPC Config Policies (Created used the latest PPPC Utility) in place:PPPC for bash:identifier: /bin/bashidentifier type: Pathcode requirement: identifier "com.apple.bash" and anchor appleAccessibility- ALLOWAppleEvents- ALLOWcom.apple.systemeventsBundleID / identifier "com.apple.systemevents" and anchor apple PPPC for LTechAgent:identifier: /usr/local/ltechagent/ltechagentidentifi
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!