Get Support
Recently active
iPads won't reinstall apps and apply profiles after erase. I can remotely eg restart the devices and the last check-in time shows that the iPads are communicating with Jamf. All iPads are Supervised. 9th Gen iPads have still iOS 15.5.I got apps installed when I modified the app list for the device group where the iPads are.
Guys,I'm using promote script to make standard users as an administrator. And my requirement is, not to demote the user who are all already an administrator.I've logic here correct me If I'm wrong. When I execute the promote script, I will be storing the log saying 'You are already administrator' if the script executed on the administrator user profile. Taking the log as an input and making the condition that if the log has this message then no action required on demote script. And anyone help me with the script how to read the string in the file and make that has a condition. Thanks for understanding.
With Apple's changes to who qualifies for the Developer beta (as well as how it is installed), does anyone have advice on how to block users from installing it? In the past we always created a Restricted Software policy that restricted and then killed the process named "Install macOS <this year's name> Beta.app", but it looks like Apple is no longer deploying these in that way anymore. Granted, I could be wrong on that haha.We've created a similar policy for Sonoma, as well as an additional policy that blocks "macOSDeveloperBetaAccessUtility*" -- since it looks like that is the new deployment method. Have any of you come across a better solution?
I have been testing the Jamf compliance editor, and the scripts for the extension attributes are reporting 0 when the files the script is reading has a few failures and 2 exemptions. I am not seeing anything out of place in the script, any help? Here is the script for the Failure Count Attribute: #!/bin/bash# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # ### Copyright (c) 2022 Jamf. All rights reserved.## Redistribution and use in source and binary forms, with or without# modification, are permitted provided that the following conditions are met:# * Redistributions of source code must retain the above copyright# notice, this list of conditions and the following disclaimer.# * Redistributions in binary form must reproduce the above copyright# notice, this list of conditions and the following disclaimer in the# documentation and/or other materials provided with the distribution.# * Neither the name of the Jamf nor the names of its cont
I am trying to install and license Avid Media Composer on lab machines using floating license.Used Jamf composer to install the pkg for Avid Link first and then Avid Media composer with postinstall scriptinstaller -pkg /“installer.pkg” -target / the app install fine.I tried to capture the license using another package.But getting error when opening Avid Linkanyone knows how to capture the license?
I have combed through all the threads here before posting, I am trying to figure out why this is happening to all unencrypted Macs on this server. The user gets a pop-up to enable FV, enter password, and then the following shows up in the logs: All the users have Secure Token, and they are enabled for FV2. Any help would be appreciated. Here is the setup we have:
Our Jamf environment requires that all Macs have FileVault enabled and we recently discovered that all of our Ventura systems can no longer unlock the drive with any administrator accounts. The only ones that can are standard accounts. We we're able to reproduce this issue on both an existing system that was upgraded to Ventura and a brand new MacBook Pro. To clarify:- FileVault is enabled on Mac OS Ventura.- Administrator accounts are unable to unlock the drive at startup/reboot.- Only Standard accounts are able to unlock the drive at startup/reboot.- We were able to reproduce the issue on both an older Silicon Mac and a brand new Silicon Mac out of the box. Any advice is greatly appreciated.
We've successfully deployed the reissue FileVault key script in our environment to send FV recovery keys to Jamf Pro to 99% of the Macs in our fleet. However, we have one Mac whose user is unable to send the key to Jamf Pro due to the following error: Error: User could not be authenticated. Error: Unable to unlock or authenticate to FileVault.To be sure, the user is using his Mac password to unlock System Settings, unlock FileVault at login, etc. But it's unable to generate a new FV key. Any suggestions on how to troubleshoot this sort of thing? I would prefer to avoid having to wipe/reinstall the OS unless it's the only option.
Testing out an Exchange ActiveSync profile in Jamf Pro. I've filled out all the fields in the profile and the profile pushes to the test device just fine. When opening the contacts app on the device, it prompts for the "com.apple.eas.account" password. Nowhere in the profile is there a field for that password. This is the Exchange ActiveSync user account which of course the end users wouldn't have the password for.
We went through a migration process to Jamf Cloud, and have had success with macOS as the process end users follow is quick, painless, and non-destructive. We haven't had any real success encouraging manage device users to migrate as the only successful process they can follow involves resetting the device, and erasing all content and settings - as we use apps like Microsoft Authenticator, the disruption to users is fairly significant. I want to understand if anyone else has been in the position and what strategies they've used to encourage users to reset? There isn't an equivalent to jamf helper for iOS/ipadOS, we used that on macOS to send pop-up messages to encourage stragglers.
Hello all! I'm new to JAMF. We have installed Mac Mini machines to be content caches for our iPads in the school system. They are set to configure themselves when they are plugged into the network and powered up. The default name is mac mini. I go and manually rename each one after it comes up. But for some reason, a couple of days later, the name has reverted to mac mini. I look in the history in JAMF and it only shows when it was created and each time I have renamed it. Any logs I can look at other than the history for the machine? Any ideas?
Hi, I've just created an Jamf account. Now i want to get the jamf 100 Certificate, but my invoice needs to be sent to my company. Can i know how can i update my company informations?
I have Apple Business Manager already successfully federated to Azure AD and ABM creating the matching (managed) Apple IDs in ABM and logins working.The next goal is to provide these to our Mac and iPhone users for utilising FaceTime.There is no problem doing so manually on devices but I have not been able to find any Jamf advice on how to automate this for users. Ideally this would be possible for existing devices and not just freshly DEP/Automated Enrolment devices. So is it possible to push out the Apple ID for a user for use with FaceTime to their device like it is possible to push out e.g. an email account to the email client on that device?
It would be great if Apple/JAMF would support via DEP/MDM Airtags that can be permanently attached to iMacs and MacMinis to discourage units being “lost”. Corbin
With the release of macOS Sonoma Beta I want to look at getting this on a test machine but the directions to find the beta option under Software Updates is not being seen. Would this be due to JAMF management? The device is logged in with an Apple ID that has access to the Apple Developer Program. I have nothing set in JAMF that I'm seeing that's restricting the beta.
We use Jamf Pro Cloud to manage our Mac fleet but would like to hybrid join our Macs to Intune as a method to control who can use Office 365. I see that Conditional access is being Deprecated. Can I accomplish this with just using Device Compliance? I keep getting Notifications in endpoint stating that an Intune update is coming concerning Intune device compliance. I’m new to Azure / Intune so I apologize for my ignorance on that side.
Two questions:1. Interested in testing a Shared iPad configuration on an new iPad. But how do I undo it once testing done - convert back to standard ipad. 2. How to I convert an existing ipad to a shared ipad, it has already been enrolled in Jamf at a normal configuration. All the documentaiton refer to new imports from ASM, not converting an existing iPad..
We have an application installed on all of our Macs called Egnyte Connect which we want to remove. This application was deployed using a pkg via JAMF. Egnyte have given us a command to run their uninstaller.sudo /Applications/Egnyte\\ Connect.app/Contents/Resources/Egnyte\\ Connect\\ Uninstaller.app/Contents/MacOS/Egnyte\\ Connect\\ Uninstaller How can I use this command in JAMF? I tried using it in a script but that didn't work.#!/bin/bashsudo /Applications/Egnyte\\ Connect.app/Contents/Resources/Egnyte\\ Connect\\ Uninstaller.app/Contents/MacOS/Egnyte\\ Connect\\ UninstallerWhat's the best way to approach this?Thanks
Today we released Jamf Connect 2.27.0. This release includes the following changes and improvements: UI Changes to Jamf Connect and Microsoft Azure Active Directory (AD) All mentions of Microsoft Azure AD will be changed to Microsoft Entra ID. Key-values in the configuration profile XML file will remain unchanged to prevent any configuration issues. Jamf Connect documentation will be updated to ensure all UI elements match where applicable. For more information, see Microsoft's New name for Azure Active Directory documentation. Other Changes and Improvements The Jamf Connect menu bar app can now display the current user's name in addition to indicating whether they are a standard user or administrator. The OIDCSecondaryAccess key has been added to the Jamf Connect login window. This key specifies user roles or groups that contain users who are allowed to create additional users on computers after the first account is created. You can specify one role or group and more r
"Just wakin' up in the mornin', gotta thank GodI don't know but today seems kinda odd".........So has anyone run into these issues:1. Yesterday [20230907] we were enrolling devices without any issues. It was all good!2. In the late afternoon, things went bonkers!3. Once the device got pass JC, the device booted to the desktop and just stood there. In JPS it showed up as an unmanaged device. It never proceeded to run enrollmentcomplete. What's worst we couldn't even do a EACAS. We had to N&P™ the long way.4. So we tried another device, same issue and same results.5. Then we thought we'd be smarter than the average bear and DFU a mac(hine) to macOS 13.5.2. In hopes that we would identify an issue. Sadly, same results.Now for hoy dia, we are having more stranger issues:1. Regardless of macOS 13.5, 13.5.1 or 13.5.2, JC allows the us to sign in. However now it by-passed FileVault prompt.2. It created the account and proceeded to the Desktop. It went straight to jail and did not pass Go
Sorry if this has been hinted at before, its a weird one... we have been using a corporatised script takes from the bones of the "Make me an Admin" script and have been using it in one way or another for 6 years..for those who dont know it, it adds a standard or mobile user into the 'admin' (id:80) defualt group for a certan period of time before a launchdameon cuts it off:-/usr/sbin/dseditgroup -o edit -a $user -t user adminso Monterey and below that has always allowed a user to enter a password to install a package or unlock a padlock, as well as sudo and su themselves on a terminal to use admin commands there... except I cant get this to work on 13.5.2, i can install a pkg graphicly, but I cant use sudo or sudo -s to get a root terminal to run it on the command line via /sbin/installerinstaller works when i have used the jamf management account to sudo -s with its complex password... so dont know why users dropped into the admin group cannot do that? if no i will raise a
Does anyone have any good recommendations for free or inexpensive training content for Jamf Connect? I feel mostly confident about rudimentary functions in Jamf and am planning on taking the Jamf 200 course sometime this summer, but I am less confident about Jamf Connect. My organization just started using it and would like to dive in to learn more about implementing it successfully and succinctly.
I want to deploy bomgar macos with intune but I get the error that the original .dmg file that was downloaded could not be located.
We manage 5 devices for our small business via Jamf Now. All of the devices are supervised and have no issues. We went into our Blueprint > Security and enabled the Jamf Protect function. I can see Jamf Connect is running in settings of all of the targets devices. My question is there a dashboard via Jamf Protect for me to view the state of these devices or am I stuck subscribing to Jamf Protect in order to get a dashboard view of all the devices and their security status? Thank you
We are restricting access to several websites through a managed profile that has unwanted URLs in the Blocklist (formerly Blacklist). We now want to add several dozen more URLs to the Blocklist, however it seems the URLs have to be entered one by one? Surely there is another faster way to import a bunch of URLs into the Blocklist at once.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!