Get Support
Recently active
So I’ve setup my test mac m1 Ventura, followed the integration documentation for setting up the jamf connect and deploying using Jamf Pro cloud, not done the menu bit yet as the documentation seems a little confusing. I get a Microsoft login page at the Mac boot screen in place of the standard mac login. I’m able to auth to entra fine but I’m the immediately presented with a secondary user name and password dialogue, followed by a password verify dialogue and finally I’m in. I’m hoping I’ve done something wrong and this is more streamlined in a correct setup???
Hi community,Here looking for feedback on this beta feature from jamf pro specifically on things that have not worked out for you upgrading macOS to Ventura 13.5.2- I did a test on my mac but restart is not forced - anyway a restart can be forced? - I received the Software Update notification come in successfully on my machine and I diverted it but did not received another notification even though I set for this to occur 3 timesYour input is appreciated.
I am trying to use Google LDAP to authenticate users logging into a mac lab, but I have had nothing but issues. The Google LDAP search is successful finding the user account, but fails with a LDAP search with (&(|(objectClass=automount))(|(automountKey=xxxxx))) failed with NO_SUCH_OBJECT. The log in process just spins and spins. No local profile is created. I have removed all configuration profiles for the Mac and it is connected via Ethernet. I've followed these instructions and when I test using ldapsearch, it completes successfully. This is the first lab of macs I have used JAMF for, so I am most likely missing a step somewhere. We have Google LDAP setup successfully for logging into the lab software on the MiniMacs. Any suggestions for troubleshooting or even which logs I should look at would be greatly appreciated. I am very close to giving up and using Active Directory.Thank you!
Hello, I am trying to run my Office 365 download through Jamf Pro and I am getting the following errors: [STEP 1 of 4]Executing Policy Installing Microsoft Office[STEP 2 of 4]Running script install_pkg.sh...Script exit code: 4Script result:https://go.microsoft.com/fwlink/?linkid=XXXXXXX Download URL: https://go.microsoft.com/fwlink/?linkid=XXXXXXX Downloading the installation files... hdiutil: attach failed - image not recognized Failed to mount the downloaded dmg; exiting. Cleaning up installation files...Error running script: return code was 4.[STEP 3 of 4][STEP 4 of 4]
I have some questions about FileVault.Let’s say you have a new Mac computer that is installed with Jamf DEP. During the process a local admin account is created. And the computer will be bind to Active Directory. Then the device is given to the user who logs in onsite with their Active Directory credentials which creates a mobile account. Now he can login with his mobile account of course also from offsite.The Filevault configuration profile is installed and when the user logs out FileVault will be enabled. So far so good. But let’s say somebody else from AD wants to log into the computer now with their AD credentials. This would not work right? Because the “new” user cannot even unlock Filevault before the boot processWhat about the mobile accounts and unlocking FileVault. Will it work? Or do mobile accounts need to be on VPN or Onsite to reach ldap ??
Hello All,I have followed this guide exactly and am going crazy. https://docs.arcticwolf.com/agent/installing_mac.htmlThe error I am seeing seems to be related to the "Execute Command" section or perhaps the .sh script itself This is what the details from the log shows:Result of command:/private/tmp/AGENT/install_AWNAGENT.sh: line 1: {rtf1ansiansicpg1252cocoartf2709: command not found /private/tmp/AGENT/install_AWNAGENT.sh: line 2: syntax error near unexpected token `}' /private/tmp/AGENT/install_AWNAGENT.sh: line 2: `\\cocoatextscaling0\\cocoaplatform0{\\fonttbl\\f0\\fnil\\fcharset0 Monaco;}'I've tried my best to confirm that the .sh is created properly, the file shows SHELL on the Icon and its definitely a plain text documentAny insight would be extremely helpful. Also one thing to note is when I copy pasted the command from the .sh file and ran it in terminal it prompted for my password and then installedThanks
We've followed all the instructions for setting up InTune integration with our Jamf Server on both sides. When I run the self service policy to get a Mac registered in InTune, it goes through all the steps until it gets to the JamfAAD.app where it basically stops. I've let it sit with the spinning gear for an hour with no progress at all. Here's the screenshot:When I click on More Details, here's what it says: Has anyone else encountered this? What app is it trying to get? Could this window be any more vague?
We have a PreStage set up for the techs to assign computers to (we have more than one PreStage)They need access to the PreStage for computer/Device assignment.Unfortunately they need to have update access to the PreStages in order to do this.And you know what happens when techs get update access that lets them change everything, they change everything.Is there any way to lock the PreStage down but still give techs ability to assign a computer/device to a PreStage?
Hello Nation!Trying to see what's the best way these days to script Zoom installs and automatic updates for it without bothering staff with updates. Thanks in advance!-FS
Just this week, we are noticing that many Macs, but not all of them, are not able to print via our Windows print server. Nothing has changed on our Mac side.We are printing via PaperCut, so using SMB on a printer installed via JAMF and no changes to the setup.Macs not joined to the domain and not using the AD Username as the machine or profile name in many cases, but likely in many others.I can add PaperCut LPD to the print server and print via LPD - but no authentication, so the job gets stuck with no way to get it to print from Papercut, unless the users profile on the Mac is named the same as their AD username.The issue looks very similar to this one:https://community.jamf.com/t5/jamf-pro/mac-printing-issue-after-microsoft-windows-print-server-update/m-p/246842However, we don't have the server updates referenced in the thread or PaperCut advisory.Affected systems are running Monterey, Big Sur, and Catalina.One Mac that was able to print, stopped printing immediately after upgrading
Hello,We signed up for a cloud RADIUS solution for our WiFi auth through portnox.com, and then set up the environment to use SCEP and push out these profiles to our MacBooks. Everything worked great and successfully pushed to most all of my devices (and the WiFi works great for them) however two of my devices keep throwing this very unhelpful error, and I can't for the life of me figure out what's causing it. It feels like the issue is at the device itself, however there is nothing special about either of these devices compared to the others (same profiles, same polices, etc. same OS version (Ventura). The error simply says "Unable to obtain certificate from SCEP server at "scep-eus.portnox.com". <InternalError:1>. These devices are connected to the same network environment as the others, so it's nothing related to the corporate firewall blocking access, and they have the same issues when they take their laptops home. 
Hello EveryoneWhen I select a group in Software Update payload, and select Download, Install and Restart install option with Latest version based on Device eligibility, the device does download and install however it will not restart the computer.The local IT team has to touch each computer to click the Sys Pref > General > Software Update > Restart. All computers are on at least 13.4.xCurrent Jamf Pro ver 10.50.0Anyone else having same issues or know the fix
We have about 200 employees with all 100% WFH. On paper, I think our patching numbers looks good relative to our user count each week, but my boss isn't buying it as optics are funneled all through Slack and each week, we have about 3 - 5 people complain an app broke during patch. My boss also gets hit up with anecdotal issues of someone complaining to him something broke during patching, and all of that is coming to me. We are using just policy based scripts with smart Groups, instead of leveraging Patch Management, Installer, and 3rd party tools. My question is what does a healthy patching environment look like in terms of statistics? Do you have complaints each week that an app broke? What percentage just fixed an app themselves without reporting or complaining? What are you using to patch our heavy hitters: Zoom, Chrome, and Slack?
Hello All i wanted to ask if this looks right, is this the correct way to restrict the Mac os senoma beta software?
We have recently implemented a new pre stage which includes jamf connect. Its been working great. However had some machines that don't seem to be enrolling correctly. As there is no jamf long in the console.I have wiped the machines and deleted them in jamf but this hasn't helped.Thanks
Any AppleScript people out there that can help me figure out why the "open location" part of the script is failing to open to the URL?This works:osascript -e "tell application \\"$browser\\" to activate"This does not work:osascript -e "tell application \\"$browser\\" to activate open location "https://www.yahoo.com"" loggedInUser=$(echo "show State:/Users/ConsoleUser" | scutil | awk '/Name :/ && ! /loginwindow/ {print $3}') # identify default browser defaultBrowser=$(plutil -p /Users/$loggedInUser/Library/Preferences/com.apple.LaunchServices/com.apple.launchservices.secure.plist | grep 'https' -b3 |awk 'NR==3 {split($4, arr, "\\""); print arr[2]}') if [ "$defaultBrowser" = "com.google.chrome" ]; then browser="Google Chrome" elif [ "$defaultBrowser" = "com.apple.safari" ]; then browser="Safari" elif [ "$defaultBrowser" = "org.mozilla.firefox" ]; then browser="Firefox" elif [ "$defaultBrowser" = "com.microsoft.edgemac" ]; then brows
Hello,Would it be possible to deploy the Company Portal without having the users to log in to the app?I have a Jamf Connect setup where you authenticate with your Microsoft Account and Jamf Connect to sync the password locally. Would it be possible to use Jamf Connect to automatically fill in the account for the Company Portal?
Hello,Our new Anti-Ransomware product needs a way to shut mac systems down.Something like ‘echo <password> | sudo –S shutdown –h now ‘ deployed via ssh would probably do the job; However we are using LAPS script by Phil Redfern (root password is also stored as an extension attribute).The question is how to get the LAPS password out of Jamf – the Anti-Ransomware product uses PowerShell?Any ideas?Thanks, Regards, JK
Hi,I'm very much a novice when it comes to launch daemons and the instruction on this page have me flummoxed https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-schedule-scan?view=o365-worldwideUnder the sub heading "Load your file" it has <your file name.plist> I cannot find any reference to this "Your file name.plist" Any assistance with this would be greatly appreciated. ThanksMatt
Hi all, we are just about to configure SYM and was wondering if anyone had the dimensions for the welcome banner, other images and icons etc so we can prepare these before we start the install. TIA
Greetings, Goal:I have been trying different GitHub workflows created to automate the process setting and locking a desktop background image on a macOS computer. Problem Statement:My core issue is after I use a workflow to install the image on the test computer. I cannot find a workflow to set that stored image file as a desktop background that works for me. Two examples: Example #1 Published this year for Intune. Not jamf pro but the workflows for scripts and configuration profiles should be MDM agnostic. Step one: Use a script to download the wallpaper. This works. Step two: use a .mobleconfig to set the wallpaper. This does not work for me and there are no readable logs so I am having difficulty debugging the problem with workflow. All I see on the test computer is the screen flash when the configuration profile is saved and after that, the desktop image stays the same. Example: 2Armin Briegels desktoppr workflow. Last updated 05/
There's this SSO plugin that offers platform-wide SSO on a Mac. It works great. https://learn.microsoft.com/en-us/azure/active-directory/develop/apple-sso-pluginBased on this blog from July, the extension should work for the login window starting with Ventura, but I can't find anything recent on how to actually make this work. https://techcommunity.microsoft.com/t5/endpoint-management-blog/microsoft-simplifies-endpoint-manager-enrollment-for-apple/ba-p/3570319 Anyone else tried this or seen any other information on how to deploy this feature?
Hi there,Does anyone know of an extension attribute or a way to reference devices' current set login mechanism. This is to run authchanger policies whenever jamf connect isn't the set login mechanism i.e after macOS upgrades and every other state we've not yet encountered but could potentially revert the login mechanism back to macOS default.
I had a smart group set up that I used for years, but I can no longer find it and I need to recreate it.I enroll iPads before students come in to pick them up. When they arrive, I show them how to do one of two things 1) sign into an existing personal Apple ID account or 2) set up a new Apple ID account using their school email address. I'm working with several kids at a time but I usually don't keep track of who shows up because I had a smart group set up that would keep track of who signed into their iPad. This is how I knew who still needed to pick up a device. Now that this smart group somehow disappeared, I've had to rely on a spreadsheet and basically take attendance with each group so I know who has been set up.I've been having difficulty recreating this smart group so I'd like some help. I have new students from different graduating classes receiving different model iPads, so none of those criteria types would narrow down. The iTunes Store Account criteria of 'Active' woul
I was searching around and looking for a possible way to start removing/limiting what users can install/do on there own. I run everything on JamF and I wanted to start cracking down on this as our windows machines are pretty locked down on what a local user can do. (Removes Local Admin.)(Replace USERNAME with the user's name that you’d like to remove from admin.)dseditgroup -o edit -d USERNAME -t user admin —----------------------------------------------------(One user per machine.)#!/bin/sh LoggedInUser=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }' ) dseditgroup -o edit -d $LoggedInUser -t user admin—----------------------------------------------------(Change Standard Member -D to Admin Account -A.)dseditgroup -o edit -a $LoggedInUser -t user admin I found and formatted/referenced these scripts and I was wondering if this is still what is used for 2019+ MBP's. Mainly the new M1/M2 devices before
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!