Get Support
Recently active
Hi all,Is there a way to hide apps from the homescreen in iOS without removing them entirely from the phone? I know how to do it manually on my phone, but I'm not sure I've found anything that works within Jamf. We have a content filter application that needs to be installed to function, but the app itself only contains text and so it seems to confuse our users if it's visible on the home screen. Thanks in advance for any suggestions!
Hello !I try to upgrade mac computers to the latest version of Ventura, 13.5.2. I have Big Sur and Monterey OS and downloaded the installer through the mac App Store but when I want to install from it, it says that macOS Ventura cannot be installed on this computer. I was thinking about the updates deferral, but some computers haven't that profile installed. And when I use the software update, it doesn't install the latest version of the OS.On one computer, I installed Big Sur => Ventura 13.4.1 from the software update and once it was done, it only proposes 13.5.1. When I tried to install the 13.5.2 installer from Jamf => App Store, it still said that Ventura cannot be installed on that computer. I don't know how to proceed to be able to install the latest version of macOS. Is there a way to check if a deferral is configured ?Any help is welcome !
There is another thread with this that starts with discussing the managed preference involved. Wanted to start a new thread with the user-facing error message as the subject. So far I have been running into this on pre-WWDC 2023 Apple Silicon MacBooks running macOS Ventura 13.4(22F66) and 13.4.1(22F82), while older releases seem to be able to leap into 22F82 and then begin enjoying the broken updates. This error is showing up now on systems attempting to install the rapid security response (c) too, so even more reason to bump the thread up. Our solution was to remove the Defer Updates from our restrictions payload entirely. The image below shows the only thing I changed to get it working. That instantly allowed people to install updates. Hope this helps and that Apple fixes it. Also worth it to see what we had set before that is causing problems.
Hi there, We're running a test scenario of a device configured with FDE and passthrough. There's a glaring issue that we can see and that is the the reliance on the Jamf Connect Menu being the only means checking for password mismatches between our IDP and the local account.The concern is that once credential mismatch is detected a sign in window appears which can simply be ignored indefinitely. With no way to directly enforce IDP and local account password syncs without disabling passthrough which will cause the double login issue on boot and restarts.Could anyone confirm if this information is correct or if there's information we're missing?
Requirement: need to get check in / current ip of all the machines for about 1k machines in the network on regular intervals.Since the Jamf server does not keep record of check in IPs, planning on scheduling a script to run every 15 minutes on all machines ( a simple command to echo `date +%T`,`curl ifconfig.me` ) to a log fine, the resulting log file needs to be pulled out to harvest/consolidate and create an inventory of all machines records probably in a database table. the challenge I'm trying to solve is the retrieval of the log file from all the machines to a central locationHow secure is to use a script that uses creds in it though encrypted when applied via policy against all machines? and if we upload to the attachment section of machines in jamf, how easy it is to pull this to a central location for all the machines.. I'm assuming via an API if that is supported.https://github.com/kc9wwh/logCollection/wiki/Using-Encrypted-StringsAlso is there a good practice to copy the
Hello All,In my organization Xcode is getting deployed through VPP Self-Service policy, now few developer raised a concern that Xcode IDE should not patched to next version, auto updates should be disabled as it is impacting their testing job.Now my question is what should be the best way to stop auto update for that team but others team it will be patched automatically?If I exclude their machines from VPP deployment policy then it will stop auto update or Xcode will be removed entirely from mac?
Since 10.50 (Cloud)When I click on a smart group on the dashboard (the value) I'm redirected to the page.. there is some blue-whirling.. and a blank page.. no results are displayed. Not every time, but more often than not.I now need to click on the smart group name, then results. Chromium browsers (no I can't use a different browser) Anyone else? Was all working fine in 10.49
How can I generate a report for bulk number of mac devices with its physical location? Any ready made criteria is there, if yes then please mentioned or else please let me know if it is possible through a config profile or else?
The JAMF machine certificate was expired, How to renew it? I tried to push a new cert to this machine on JAMF console, but no option found.
We had our studnets hand in their iPads over the summer and know we have 1000s of IPads marked inactive in JAMF School. They can still be used, but MDM functions are not working. We cannot get them to switch back to Active unless we wipe and re-install. There has got to be a quicker and easier way to get them back to active? Anyone else having this issue?
Hello Jamfnation! I just got back to work from JNUC 2018 and I'm very excited to put into use all the new things I learned. I manage a small fleet of 25 MacBooks, this is expected to double next year. We're using DEP to enroll our machines but would like to stop binding to AD and start using NoMad for AD authentication and local account management. Now there are a few tutorials and different ways to do this. Would anyone recommend a specific "simple" way of doing this, or point me in the right direction to get started. Thanks in advance!
We have our prestage enrollment set to create a hidden local admin account. The settings we have selected are: Create a local admin account before setup assistant, Hide managed admin account in Users & Groups, and Skip Account Creation. Initially, this seems to work 100% fine. I can log in through the local admin without issues. BUT, as soon as another user uses the computer and it creates their account, I suddenly lose access to the local admin. Let me walk you through this so it makes more sense.- The computer goes through prestage enrollment and creates the admin account.- When we reach the login screen it is populated with our Single-Sign On window asking for our company email login. We instead click local login and log in with the local admin. This works.- We log out of the local admin and return to the SSO login window. The new computer user will log in with their company credentials and it will create and account for them on the computer. They log out of the account.- T
Hello Jamf Nation! We recently released Jamf Protect 5.0.1. This release includes same-day support for macOS Sonoma 14 based on testing with the latest Apple beta releases. To ensure compatibility with macOS 14, all Jamf Protect customers need to update their target computers to the latest version of the Jamf Protect agent before updating their operating system to macOS 14. If you do not have AutoUpdate enabled for Jamf Protect, or if you are a Jamf Protect Offline Mode customer, you will need to manually update the agent to the latest version and deploy the agent manually to the computers in your organization. After successfully updating your computers to macOS 14, initiate a reboot for the computers in your organization. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Thank you!The Jamf Protect team
Hello All,I just wanted to know, if we can use touch command in Extension Attribute if needed, I know better it to avoid as we are collecting information from computer but technically is it ok to use touch command in my EA's body?
Hi all,We are currently in the process of deploying macs and we have a couple of applications we need to run on every startup, how does everyone go about achieving this in their environments? The applications we need to start automatically is Microsoft Teams (I'm aware of the tick box within the app to run on start but would rather automate this) and the other is Xink for email signatures? Looking for some advice and examples to guide us if possible.TIA.
1. How do users function? Are the Users in the Users menu on the left hand side of the screen only users created in the Users and Groups menu in Setup, or can these users be created elsewhere or imported from Azure? We are connected to Azure and I can see all of my Groups and Users when I try to create a new "User" in the same menu and assign rights to it, but is there no general user that is searchable for scoping purposes or does everyone need to have some sort of access/non-access to Jamf Pro? Ideally, I'd like to be able to link directly to all of my users in Azure for singular scoping if needed but I don't think this is possible and my current users menu from the left side of the screen is empty. I don't know where it populates from.2. How can I use Jamf to collect username, full name, and other asset information like location or department, or do I have to do this all by hand?
Yo.. We have many Mac's whose hostname doesn't match their computer name. Is there any easy script we could use that will 1...get the computer name and then 2...use scutil to set the hostname to match the computer name? Thanks!
Microsoft Defender has been added to the Mac Office 365 installer as of v.16.77.I do not want this being installed and sticking with an older installer for now. Has anyone successfully excluded it as part of the Office installation process? The “push out the 'InstallDefender' managed preference” did not give much info to go on.Thank you.
I'm new to managing my company's Jamf Pro environment - I added a device into our apple bm and then assigned the MDM profile to our Jamf. It has not shown up after 30 minutes. So I went digging through our Jamf to see if something had expired and I found that our activation code has expired since earlier this month. I do feel this is a pretty silly/simple question to be asking here but with an expired activation code, I assume that is preventing us from adding new devices into Jamf since our "license" is expired?I ask this because I am still able to make configuration profile changes to devices. I just want to make sure I'm not missing something simple within Jamf for not seeing the new device. Thanks for any input on the matter
Hello,Lately in our environment, our local management account on Mac has lost the ability to log in because it is no longer Filevault unlockable. When we set up our Macs, we enable FileVault via Jamfs config profile and policy using DEPNotify. Once DEPNotify is complete, we manually run this script to enroll the local management account to FileVault: #!/bin/bash admin_account="${4}" admin_password="${5}" status=$(sysadminctl -secureTokenStatus ${admin_account} 2>&1 | awk '{print $7}') filevault=$() if [[ "${status}" == "DISABLED" ]]; then if [[ $? = 0 ]]; then userName=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }') triesCount=0 while true; do ## Prompt for Password userPass=$(osascript << EOL tell application "System Events" to text returned of (display dialog "Please enter your Mac login password to complete configuration of FileVault 2. Contact your IT Support Team if
It's 8 minutes past the start time and I'm connected to the live stream of the JNUC 2023 keynote. All I'm seeing is some kind of ad about visiting 5 or more sponsors on a loop and there is no audio at all. Am I connected to the right stream? Even though I registered for this the day it was announced many months ago and I got confirmation, I was never sent a link to watch the Keynote so I had to dig through the Jamf website to find something that appears to be the right site on rainfocus.com?
I am trying to set up DEP on our JSS and when ever I get to the point where I have to upload the server token file, I get the error "Problem contacting Apple services" I've redownloaded the private key, deleted and recreated the Management server on Apple's side and tried again but always this error. Anyone got any idea why?
Currently JAMFPRO installed on Centos 7. I wonder what system should I migrate to.
Hello everyone,we use Jamf School with managed classes (manually created in MDM). The teachers' iPads work fine with Apple Classroom.Is there a way to require students to consent before their screen can be viewed?Our school management would like that.Currently, teachers can simply instantly mirror student iPad screens. The following is set in the Jamf settings:ON: Automatically configure Apple Classroom based on Classes and Users in Jam SchoolOFF: Allow Screen Observation Permission Modification And as payload in the profiles:OFF: Allow Classroom to perform View Screen without prompting for admin-created classesON: Allow Classroom to lock to an app and lock the device without promptingON: Automatically join Classroom classes without promptingON: Require teacher permission to leave teacher-created classes in Apple's Classroom appthank you for your help
Hi.We need to have Jamf Pro send it's logs etc to our SIEM (SumoLogic)We are currently on Jamf Pro Standard, and it seems like this isn't available for it. It does seem that having Jamf Protect can send events to a SIEM though (https://learn.jamf.com/bundle/jamf-protect-documentation/page/SIEM_Integrations.html). But would getting Jamf Protect also include sending events/logs from Jamf Pro too? Our other possible solution is upgrading from Jamf Pro Standard, to Jamf Pro Premium which would allow us to stream to the logs/events to an s3 bucket, where SumoLogic can ingest them from there (https://learn.jamf.com/bundle/jamf-security-documentation/page/Configuring_the_Threat_Events_Stream_to_Send_Events_to_AWS_S3.html) Just curious if anyone else (surely) has their logs/events streamed into a SIEM, and which product they used to do it with (e.g Jamf Premium Pro or Jamf Protect) Thanks
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!