Get Support
Recently active
How can I generate a report for bulk number of mac devices with its physical location? Any ready made criteria is there, if yes then please mentioned or else please let me know if it is possible through a config profile or else?
The JAMF machine certificate was expired, How to renew it? I tried to push a new cert to this machine on JAMF console, but no option found.
We had our studnets hand in their iPads over the summer and know we have 1000s of IPads marked inactive in JAMF School. They can still be used, but MDM functions are not working. We cannot get them to switch back to Active unless we wipe and re-install. There has got to be a quicker and easier way to get them back to active? Anyone else having this issue?
Hello Jamfnation! I just got back to work from JNUC 2018 and I'm very excited to put into use all the new things I learned. I manage a small fleet of 25 MacBooks, this is expected to double next year. We're using DEP to enroll our machines but would like to stop binding to AD and start using NoMad for AD authentication and local account management. Now there are a few tutorials and different ways to do this. Would anyone recommend a specific "simple" way of doing this, or point me in the right direction to get started. Thanks in advance!
We have our prestage enrollment set to create a hidden local admin account. The settings we have selected are: Create a local admin account before setup assistant, Hide managed admin account in Users & Groups, and Skip Account Creation. Initially, this seems to work 100% fine. I can log in through the local admin without issues. BUT, as soon as another user uses the computer and it creates their account, I suddenly lose access to the local admin. Let me walk you through this so it makes more sense.- The computer goes through prestage enrollment and creates the admin account.- When we reach the login screen it is populated with our Single-Sign On window asking for our company email login. We instead click local login and log in with the local admin. This works.- We log out of the local admin and return to the SSO login window. The new computer user will log in with their company credentials and it will create and account for them on the computer. They log out of the account.- T
Hello Jamf Nation! We recently released Jamf Protect 5.0.1. This release includes same-day support for macOS Sonoma 14 based on testing with the latest Apple beta releases. To ensure compatibility with macOS 14, all Jamf Protect customers need to update their target computers to the latest version of the Jamf Protect agent before updating their operating system to macOS 14. If you do not have AutoUpdate enabled for Jamf Protect, or if you are a Jamf Protect Offline Mode customer, you will need to manually update the agent to the latest version and deploy the agent manually to the computers in your organization. After successfully updating your computers to macOS 14, initiate a reboot for the computers in your organization. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Thank you!The Jamf Protect team
Hello All,I just wanted to know, if we can use touch command in Extension Attribute if needed, I know better it to avoid as we are collecting information from computer but technically is it ok to use touch command in my EA's body?
Hi all,We are currently in the process of deploying macs and we have a couple of applications we need to run on every startup, how does everyone go about achieving this in their environments? The applications we need to start automatically is Microsoft Teams (I'm aware of the tick box within the app to run on start but would rather automate this) and the other is Xink for email signatures? Looking for some advice and examples to guide us if possible.TIA.
1. How do users function? Are the Users in the Users menu on the left hand side of the screen only users created in the Users and Groups menu in Setup, or can these users be created elsewhere or imported from Azure? We are connected to Azure and I can see all of my Groups and Users when I try to create a new "User" in the same menu and assign rights to it, but is there no general user that is searchable for scoping purposes or does everyone need to have some sort of access/non-access to Jamf Pro? Ideally, I'd like to be able to link directly to all of my users in Azure for singular scoping if needed but I don't think this is possible and my current users menu from the left side of the screen is empty. I don't know where it populates from.2. How can I use Jamf to collect username, full name, and other asset information like location or department, or do I have to do this all by hand?
Yo.. We have many Mac's whose hostname doesn't match their computer name. Is there any easy script we could use that will 1...get the computer name and then 2...use scutil to set the hostname to match the computer name? Thanks!
Microsoft Defender has been added to the Mac Office 365 installer as of v.16.77.I do not want this being installed and sticking with an older installer for now. Has anyone successfully excluded it as part of the Office installation process? The “push out the 'InstallDefender' managed preference” did not give much info to go on.Thank you.
I'm new to managing my company's Jamf Pro environment - I added a device into our apple bm and then assigned the MDM profile to our Jamf. It has not shown up after 30 minutes. So I went digging through our Jamf to see if something had expired and I found that our activation code has expired since earlier this month. I do feel this is a pretty silly/simple question to be asking here but with an expired activation code, I assume that is preventing us from adding new devices into Jamf since our "license" is expired?I ask this because I am still able to make configuration profile changes to devices. I just want to make sure I'm not missing something simple within Jamf for not seeing the new device. Thanks for any input on the matter
Hello,Lately in our environment, our local management account on Mac has lost the ability to log in because it is no longer Filevault unlockable. When we set up our Macs, we enable FileVault via Jamfs config profile and policy using DEPNotify. Once DEPNotify is complete, we manually run this script to enroll the local management account to FileVault: #!/bin/bash admin_account="${4}" admin_password="${5}" status=$(sysadminctl -secureTokenStatus ${admin_account} 2>&1 | awk '{print $7}') filevault=$() if [[ "${status}" == "DISABLED" ]]; then if [[ $? = 0 ]]; then userName=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ { print $3 }') triesCount=0 while true; do ## Prompt for Password userPass=$(osascript << EOL tell application "System Events" to text returned of (display dialog "Please enter your Mac login password to complete configuration of FileVault 2. Contact your IT Support Team if
It's 8 minutes past the start time and I'm connected to the live stream of the JNUC 2023 keynote. All I'm seeing is some kind of ad about visiting 5 or more sponsors on a loop and there is no audio at all. Am I connected to the right stream? Even though I registered for this the day it was announced many months ago and I got confirmation, I was never sent a link to watch the Keynote so I had to dig through the Jamf website to find something that appears to be the right site on rainfocus.com?
I am trying to set up DEP on our JSS and when ever I get to the point where I have to upload the server token file, I get the error "Problem contacting Apple services" I've redownloaded the private key, deleted and recreated the Management server on Apple's side and tried again but always this error. Anyone got any idea why?
Currently JAMFPRO installed on Centos 7. I wonder what system should I migrate to.
Hello everyone,we use Jamf School with managed classes (manually created in MDM). The teachers' iPads work fine with Apple Classroom.Is there a way to require students to consent before their screen can be viewed?Our school management would like that.Currently, teachers can simply instantly mirror student iPad screens. The following is set in the Jamf settings:ON: Automatically configure Apple Classroom based on Classes and Users in Jam SchoolOFF: Allow Screen Observation Permission Modification And as payload in the profiles:OFF: Allow Classroom to perform View Screen without prompting for admin-created classesON: Allow Classroom to lock to an app and lock the device without promptingON: Automatically join Classroom classes without promptingON: Require teacher permission to leave teacher-created classes in Apple's Classroom appthank you for your help
Hi.We need to have Jamf Pro send it's logs etc to our SIEM (SumoLogic)We are currently on Jamf Pro Standard, and it seems like this isn't available for it. It does seem that having Jamf Protect can send events to a SIEM though (https://learn.jamf.com/bundle/jamf-protect-documentation/page/SIEM_Integrations.html). But would getting Jamf Protect also include sending events/logs from Jamf Pro too? Our other possible solution is upgrading from Jamf Pro Standard, to Jamf Pro Premium which would allow us to stream to the logs/events to an s3 bucket, where SumoLogic can ingest them from there (https://learn.jamf.com/bundle/jamf-security-documentation/page/Configuring_the_Threat_Events_Stream_to_Send_Events_to_AWS_S3.html) Just curious if anyone else (surely) has their logs/events streamed into a SIEM, and which product they used to do it with (e.g Jamf Premium Pro or Jamf Protect) Thanks
Hello, fellow admins, we are running JAMF Pro 10.48.2 on-premises, and I've noticed strange behavior with software title versions in Patch Management:There is a list of items in Patch Management which stopped updating their versions (not a Legacy definition) - usually we were able to fix it by deleting the title from Patch Management and re-adding it again.However, when we were trying to delete-add few titles recently, it was still keeping the same old version, despite the fact there is newer version available for a while already.Moreover, if I search for those titles in JAMF repository in Patch Management - it displays correct version, but switching to old one immediately after adding the title.Have anyone seen this issue before? Any ideas?Thanks
Hi team,Is there any way to suppress the notification asking permission for Falcon to filter network content (screenshot below).Our fleet is on either Catalina or Big Sur. I have created the relevant Configuration Profiles as per the deployment guide supplied by CrowdStrike. Functionally everything works as expected. I am wondering if it is possible to have that message automatically approve or if this is just part of macOS?Thanks!
Has anyone successfully deployed Crowdstrike Falcon on Big Sur silently? Perhaps this is not possible?I'm using the Falcon Profile.mobileconfig provided by Crowdstrike and pushing that out first, but it doesn't seem to suppress any of the pop ups or notifications. Also, the MDM profile doesn't seem to allow full disk access, which is necessary for Falcon to auto update itself.
I would be awesome if I could apply configuration profiles at the user level and then exclude myself and local admin accounts...I vaguely remember that this was not something that worked. Anyone have any successes with this? And would they share how they succeeded?
My DEPnotify policy is set to trigger on "Enrollment Complete". It seems as though the trigger only works half the time. I just tried enrolling 3 machines and the policy never ran. I ended up having to run the "DEPnotify (do not delete)" policy manually from Self Service. Any tips? I already tried disabling "Network State Change" Attached is a screenshot of one of the machines.
Afternoon AllHope everyone is having a good Friday.So we had our power profile set by config profile for our lab devices to be always on for updates, patching etc. I though I had set a screen saver.Seem not, some imacs are starting get image burn in from no movement on the screen. I have now added the settings to my login screen config profile.Its works great if a user is logged in and they step away from the machine. However if the machine is at the login screen. It doesn't seem to kick in.I assume it should as the machine is ideal but nothing happens.As anyone else had this issue?
Dear Jamf Community,I've created a custom desktop wallpaper and have there components: 1.) Desktoppr2.) A LaunchAgent plist3.) A shell script that the launch agent callsOwner and permissions are correctly set: root:wheel 644 for launch agent and script. Locations:Launch Agent is is: "/Library/LaunchAgents" Script in is in "/Library/Scripts"Desktoppr is installed in default locationLocation of wallpaper: "Library/Desktop Pictures/" Here is the plist and the script:PLIST<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Label</key> <string>com.BoltonCSD.set-wallpaper</string> <key>ProgramArguments</key> <array> <string>/Library/Scripts/set_wallpaper.sh</string> </array> <key>RunAtLoad</key> <true/> <key
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!