Get Support
Recently active
Hello, I've got a third-party vendor that builds a private internal app for us. They're switching their developer tools and asked if JAMF is able to push progressive web apps. I don't know how to answer that as I'm not sure what that means. Does anyone have an answer to this question or do you need more info?
Hi All,I was wondering how my fellow admins handle this dangerous allowance if someone is a full admin. Some context is that you create a package and we scope by username however there is the option to change the default to "All mobile devices" instead of the default "Specific Mobile" devices. How are you guys handling this change control on this? I have heard of people using "Sites" to make sure that apps live in sites but this still doesn't prevent someone from 'mistakenly" scoping to all mobile devices.
Hello All I am trying to setup BYOD for mobile devices, we only need to push a password requirement to these phones. i have user enrollment enabled but I have a question regarding managed apple id's. Will the users need to have a managed apple id in order to enroll their personal phones? Preferably wed like it to not be required as we dont think every user has a managed apple id Also how can i capture which user is tied to the phone once they are enrolled. I am following this guide here https://docs.jamf.com/technical-papers/jamf-pro/byod/10.17.0/User_Enrollment_Experience_for_Personally_Owned_Mobile_Devices.html Thank you for your help
I've recently create a 2 configuration profiles (user level & computer level) to lock down certain features per our security & compliance needs. I scoped the profiles to a device group which contains devices running 10.8 and 10.9. Yesterday i received a list containing devices to be excluded from the user level profile (preference pane restrictions) so made the changes clicked distribute to all. Which brings me to my issue... The restrictions are still being applied I see this in my JSS under the Management tab... Remove Configuration Profile CMC User Policies Profile with identifier '750C5D23-D748-48AA-B0EA-D0CB9E8427CB' not found. <MDMClientError:89> On 1 of the devices I ran... profiles -P which returned this... _computerlevel [1] attribute: profileIdentifier: _computerlevel [2] attribute: profileIdentifier: _computerlevel [3] attribute: profileIdentifier: _computerlevel [4] attribute: profileIdentifier: shanpo [5] attribute: profileIdentifier: 7
Hi folks,Does anyone know a way to enforce the screensaver after 20 minutes of inactivity and require password to unlock in Ventura?I've been trying through a script but it doesn't seem to work, and end-users are still able to change the settings through System Settings.Thank you!
Hi all, Many of our users have less than 12 gb of free space remaining on HDD. Thus, no OS upgrade is possible and SSD performance is impacted.Is there a way to display a popup to concerned users to make a data cleanup ?Thanks
Hello,I am new to JAMF and still learning how to use the application. I was trying to set up a Macbook M1 for a user in our organization and now I'm unable to find the local account password for the Macbook. The steps are listed below:1. I completed the standard setup process for my MacBook, which required me to create a local admin account.2. After that, I connected the MacBook to my organization's network.3. Then, I enrolled the MacBook in Jamf using the Jamfcloud enroll feature.4. However, since Jamf is now managing the local admin password, I am unable to locate it on the Jamf platform. Can someone kindly advise me on how to retrieve the password for the local account of my MacBook on Jamf?
I am unable to revoke the Apps from VPP locations on Jamf Pro. These Apps have been removed from App Store. On Jamf Pro, Settings > Global > Volume purchasing, they appear:-NAME: No NameContent Type: UnknownTOTAL: 20IN USE: 0REPORTED: 20I did try "Revoke All Apps" for several times in vain :-(On ABM, these Apps can't be seen under "Apps and Books," and I can't transfer the App licenses from the locations.
Hello,Can anyone help me with the command line to remove/uncheck the "Automatically join this network" on a known network?In Monterey's it says "Automatically join this network" and in Ventura its "Auto-Join"We have two SSIDs and I want to make sure only the corporate is set to auto-join but not the other one. I appreciate your help. ThanksJoy
Hi all,I am trying to deploy a desktop background image to all our machines, currently I know how to push an image to our machines and how to set and lock the image as the background using a configuration profile, but the issue I'm having with this is it doesn't scale the image on our devices. I would also like to burn the users device name with our IT helpdesk information onto the background if possible.I have discovered a tool called desktoppr can do this but I can't quite find instructions for how I can install this to our jamf instance and set it up.Would anyone be able to let me know the steps I need to take to install this or another tool which can do this, and a script to set the background, scale the image and burn the device information with some info text that would be great?Any help would be much appreciated.Thanks!
Long Story will try to keep it brief. 1,900 iPads enrolled into Jamf were set up as single use Devices for training. Restricted to Safari and a couple of apps. No Apple ID, no need to connect to Azure Entra.Project gets put on hold, everyone forgets about iPads. Two years later project no longer on hold. Pull them out and all sorts of fun including expired MDM profile and Certs. We have figured out most of the issues in reenrolling or DFUing the iPads.Except this one: After iPads went into storage we started enrolling Macs. Have pre-stage enrollment setup with Jamf Connect and Entra and SSO. Everything going great.. until.. iPad Project no longer on hold. When we go to DFU and re-enroll the iPad we are prompted for SSO. We do not want this. The hope is I can create an enrollment for the iPads that does not require SSO authentication. Ideas?
Recently got Jamf Connect onboarded and half our machines are on it and it's been great. We are using Okta and have had no issues except for dns. I cannot get the machines to register to dns. Suffix list works and the machines are able to use shortnames etc. while on vpn (global protect). yet the machines unable to register. I don't really see any errors, it's just like it's not trying. Best I can tell it may be a kerberos realm issue? If I have to bind the mac anyway then i'm going to regret buying Connect pretty fast. The whole point was to get away from binding. Does anyone have a guide for something like this?
We use Safe Internet on iPads in Jamf School. When students open the app we have been getting messages that state we have a vulnerable OS since we are not on the absolute current OS version. We defer updates for 30 days so most of our iPads are on 16.6 or 16.4 and not 16.6.1Is there a way to suppress this message on an iPad?
A lot of our macOS devices are seeing "Self Service cannot connect to the server." since updating Jamf Pro to v10.0.0. Anyone else seeing this? How do we fix it?
Anyone pros with maintaining self-hosted clustered Ubuntu Jamf-Pro instance? After upgrading all of our Jamf-Pro hardware and updating to 10.48.2, our iPads only report the IP address of our load balancer to the JAMF pro GUI. We are running an HA Proxy load Balancer in front of all of our JAMF child nodes that is also used to terminate the SSL connection. We didn't really make any changes to our HA proxy configuration, but now the iPads that are on our internal network only display the IP adress. If an iPad checks in outside of the network it does get that public of wherever it is, but not on our internal network. I messed with adding the "forwardfor" line in the HAproxy config and it doesn't seem to make a difference. Has anyone had this issue?
Hi all,Is there a solution to mark several iPads via Jamf and trigger a LostMode?e.g. 20 or more 50 iPads are stolen from a school and you want to activate the Lostmode with the appropriate message.How could we trigger this as quickly as possible and without much time expenditure with a message?Without having to set the LostMode on the iPad individually?Nice RegardsPeter
Afternoon All!Work for a school and we are moving away from paper based finals. But a general student laptop is wide open to all sorts of stuff. How do we lock it down? iOS has Kiosk mode options but MacOS doesn't have anything (that I've found) as straight forward. I've cobbled together a couple of config profiles that get the job mostly done but it also throws permission errors. Looking for advice on:1. what other schools have used, in relation to laptops, Jamf Pro and testing in a Kiosk-esque setup.2. how I can tinker the config profile to not throw so many errors. Let's start at the beginning. 2 config profiles (Dock & Kiosk Mode). Dock limits the dock to only Text Edit, Self Service & System Pref. Fairly strait forward and works like a champ. Kiosk Mode does a bunch of stuff:Restrictions are set as follows:-Disables everything in Sys Pref except - Network and Parental Controls- Restricts app to only TextEdit- Widgets are turned off- Media al
Hi,Let's first start with the question, then some introductions and considerations...Is the sign-in performed every 15 minutes supposed to be an interactive or non-interactive sign-in? We are using Jamf Connect several years now and some time ago we were able to resolve the failed login messages by excluding it from our MFA policy.We still struggle with the Risky Sign-ins as you cannot exclude or filter apps from the auto-remediation policies.Every now and then the regular pwd checks of Jamf Connect causes someone to be marked as Risky, because JC only is interested in the username and password and ignores any MFA challenge to auto remediate the risky sign-in.As far is we understood ROPG sign-in are supposed to be non-interactive, non-interactive sign-in are not checked for conditional access. Jamf Connect performs a ROPG authentication every 15 minutes to check password in AzureAD.When reviewing the logs in AzureAD, we see the 15 minute checks as interactive sign-ins. I recreated
In the latest versions of Jamf Pro I am seeing several new Connection Types available in the VPN option of macOS Configuration Profiles (and mobile too).I am interested in using the Connection Type of /Cisco AnyConnect. I can't find any documentation on what should go in the fields or how it relates to the Cisco AnyConnect Secure Mobility Client (if it does at all). Is anyone using this or knows of any documentation? For the record the "new" types areCisco Legacy AnyConnectCisco AnyConnectJuniper SSLF5 SSLSonicWaALL Mobile ConnectAruba VIACheck Point Mobile VPNCustom SSL
Hi allUntil now it is not possible to change a created LostMode text afterwards without deactivating the LostMode and reactivating it with the new/corrected text.Why is it not possible to change the LostMode text afterwards?How do you proceed?Nice RegardsPeter
Hello together,Is it generally possible to assign the same app from two different ABM in same JAMF environment?Maybe is a stupid question but would like to know if it is possible.I have booked the app from two different ABM and assigned to the same JAMF but can only see booked app from one ABM!Thanks already for your help 🙂
We currently roster Apple Classroom through Apple School Manager using staff and student Managed Apple IDs. While everything worked as expected last school year, we've run into an issue this school year. We decided not to wipe/re-enroll our devices over the summer so we simply left them as they were from the last school year, including leaving the students signed in to their Apple IDs. At the start of this year, around 2/3 of the students received their new classes from Apple School Manager as expected, but the other 1/3 did not, they still show their old 2022-2023 classes on device. Everyone has the correct and current classes in ASM. In troubleshooting, we've updated the impacted devices, wiped all settings, and tested the Apple ID to see if it's actually functioning. The update/settings wipe had no impact and the Apple ID was indeed working correctly as we could create files in the Files app and have them correctly sync up to iCloud. From there, we simply signed out of the Appl
So I’ve setup my test mac m1 Ventura, followed the integration documentation for setting up the jamf connect and deploying using Jamf Pro cloud, not done the menu bit yet as the documentation seems a little confusing. I get a Microsoft login page at the Mac boot screen in place of the standard mac login. I’m able to auth to entra fine but I’m the immediately presented with a secondary user name and password dialogue, followed by a password verify dialogue and finally I’m in. I’m hoping I’ve done something wrong and this is more streamlined in a correct setup???
Hello There,I am wondering if anyone having same issue that I am facing regarding Nudge. Somehow when I am launching it the Nudge window doesn't show Deferral dropdown box as it is suppose to, So user can't defer the app any shap or form and it stays on window until user updates their compurter. All settiing for deferral are in JSON file. Deferral dropdown doesn't show on buttom right as it is suppose to. Any help appreciated. { "optionalFeatures": { "acceptableApplicationBundleIDs": [], "acceptableAssertionUsage": false, "acceptableCameraUsage": false, "acceptableScreenSharingUsage": false, "aggressiveUserExperience": true, "aggressiveUserFullScreenExperience": true, "asynchronousSoftwareUpdate": true, "attemptToBlockApplicationLaunches": false, "attemptToFetchMajorUpgrade": true, "blockedApplicationBundleIDs": [], &nb
Hello,I want to use PreStage to enroll my macs that I already purchased.So I use Apple Configurator 2, they are registered in ABM but they don't appear in Jamf.Then I saw on ABM they are enroll with the Apple Configurator MDM server. I change the server to Jamf pro. I set by default that all macs added to ABM have to automatically use Jamf pro MDM server. But same issue, they use : Apple Configurator MDM server.My question is : is it possible to successfully enroll a mac with Apple configurator with Jamf pro?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!