Get Support
Recently active
Hi all,I'm getting an error message when I try to register a device to Intune through Company Portal.It says: Couldn't add your device.You can retry or send a report to your IT admin.If I click "close" I see a generic error message saying:Registration with Intune failed.Run the item again, ensuring your computer is connected to the internet. If you still cannot connect, contact your IT department.Details: An internal error occurred in Company Portal.It's the first time I see it - does anyone have any idea what the cause could be?Thank you!
We're using cloud and just receiving this generic "Cannot toggle feature. Try again." message when pressing "Use the new experience" button in the new software updates experience page:Anyone else having the same issue or am I missing something?
I’ve run into this odd issue with a new laptop that I am trying to enroll into our JSS. It will not install any profiles at enrollment. I get this error: Error installing the computer level mdm profile: profiles install for file:'/Library/Application Support/JAMF/tmp/mdm.mobileconfig' and user:'root' returned 500 (The operation couldn’t be completed. (MDMResponseStatus error 500.)) Problem installing MDM profile.Problem detecting MDM profile after installation. I renewed our SSL cert last week and I am able to install profiles on other Macs except for this one. Any advice would be appreciated.
Hi Jamf Community,We have a MacBook Pro that is enrolled to Jamf Pro, but has stopped submitting inventory updates and we are tying to work out the cause of the issue.Having looked at the jamf.log file, we noticed a JSS 404 error around the time the device last submitted an inventory update. " There was an error. Could not connect to the JSS. Status - 404"Does anyone know what this error code means? Or has anyone else had a similar experience with this error code? Thanks
Hello frirends, We are starting to asses if Nudge can be used in our environment to force macos upgrades. i have done the reading and watched videos, but i still can't make the difference between the post install script and the configuration profile that we need to push. They both have userinterface and "button design" options and almost the same attributes.Thanks,
How can I generate a report to know how many mac was reenrolled and how many are freshly enrolled? Any ready made criteria is there? I cant find in jamf, if it is there then please mention the name.
Anyone experienced problems with authenticating 802.1x with Cisco ISE ver 2.3 patch 4.Log in ISE shows that the EAP-TLS handshake fails with the Mac.I have in Mac the ISE server certificates trusted as well as root of ISE certificatesin ISE I have the root of Machine certificate that issues the certificates to Mac clientsWeird thing is that 802.1x authentication works in the old Cisco ISE environment ver. 2.1 patch 5. Configuration profiles on Mac and Authentication/authorisation policies in ISE are all identical.
Hi, Bitdefender has activated a new web content control module in the Endpoint Security app, which now results in the end user having to approve a system extension. I have tried to add the below approved system extensions in a config profile, but they still show up. What else can I do?
I fully intend to contact support tomorrow because I cannot find any documentation that relates to Jamf Now specifically for this issue or really anything online but I figured I'd post here and see if you guys might have any insight.My company is going from unmanaged devices to using the Jamf Now Fundamentals package which includes Jamf Connect. I set up some managed Apple IDs and federated authentication using Azure but whenever I do a fresh install on a computer after entering the Apple ID / Microsoft login I'm then prompted to create a password for the device itself. This password does not sync to the managed Apple ID / microsoft, and furthermore it seems that the user that is created is always an admin and I am unable to change this.This essentially makes the management useless as not only does the user have admin privileges, but if they were to forget this password I wouldn't be able to change it. Furthermore, it seems like they could simply sign out of their managed Apple ID and
The other day I couldn't RDP into an iMac, I could issue remote commands, I could ssh in and do things, BUT no RDP through ARD or even VNC...turns out that if "Sharing" is disabled under restrictions that that breaks RDP. I guess it kind of makes sense but I always thought of restrictions in the sense of restricting user access to settings, not disabling features. Just in case anyone else runs into a similar thing...Best,Phil
Hey how can I block the upgrade to Mac OS Sonoma?I know I can do it either with restrict software or a configuration profile but which way to go? And I really ONLY want to block the upgrade to Sonoma. We also have some users for instance that have Big Sur installed and if I block major Mac OS upgrades that would mean that they are also no able to upgrade from Big Sur to Ventura for instance.So what would be the best way to accomplish that?
Has anyone put JSS on azure and used azure lb ? Can you tell me the correct setupI'm doing a migration recently to migrate a local server room deployment of Jamf Pro to an Azure environment.In a standalone scenario (with only one JSS service turned on), whether I turn off the master or the child JSS. it runs fine.But when I turn on two jss : master and child it has issues.When I access it from the public network, after login and entering account/password is complete the page fails to load out any resources.The current access link is: public network traffic via domain name (https) to - F5 intranet (F5 redirects all traffic to azure's lb) - Lb (load balancing) - my two JSS apps
Hi everyone, I am trying to deploy DLP profile for Microsoft purview.I follow this link to deploy profile with jamf:https://learn.microsoft.com/en-us/purview/device-onboarding-offboarding-macos-jamfpro-mdeI can see both profile on mac os (see image) but by default its OFF. I have to enable it manually (Asking for admin password).Is there anyway I can enable it with a script i can deploy from JAMF pro ?Thanks
Has anyone put JSS on azure and used azure lb ? Can you tell me the correct setupI'm doing a migration recently to migrate a local server room deployment of Jamf Pro to an Azure environment.In a standalone scenario (with only one JSS service turned on), whether I turn off the master or the child JSS. it runs fine.But when I turn on two jss : master and child it has issues.When I access it from the public network, after login and entering account/password is complete the page fails to load out any resources.The current access link is: public network traffic via domain name (https) to - F5 intranet (F5 redirects all traffic to azure's lb) - Lb (load balancing) - my two JSS apps
We are looking to upgrade from 10.47 to 10.50. We've held off going beyond 10.47 while we worked on devices this summer due to the changes implemented with LAPS. Currently we have a management account configured in the "User-initialted enrollment" settings. From what I understand, the password specified here will no longer be an option to be set on all computers for this account, and it will now rotate on each device with a randomly generated password and be stored in the device record in Jamf. That is fine as we do not typically ever need to use that account unless something went wrong during enrollment, which typically we just wipe and start again anyways. My first question with that change: We have 4-5 computers that the "Allow Jamf Pro to perform management tasks" box unchecked on the Inventory>General page as essentially we do not want Jamf to do anything with them and when we do, we recheck the box and type in our management account password, then
Hi everyone,I'm currently working on a custom desktop wallpaper and have learned a lot from reading older posts on here for it. My next question, or a second part of this project would involve using the same wallpaper as a login background. We currently AD bind our macs, if that's relevant.I have made the wallpaper 4480x2250 (same as Apple wallpapers). DPI 300. Any thoughts? Also, the simpler the better and to avoid me asking dumb follow-up questions, please provide explicit steps to accomplishing the solution :-)Thanks!Phil
I am restricting the apps my students use on their byod iPads during school hours using the positive list in the profile. As soon as the school hours are over, all the „private“ apps (games, social media, etc.) show up again, but in a completely messed up order. All the folders and widgets the students had set up during their time at home are gone. Does anybody know a workaround?
am i just now seeing this for the first time? or has it been here for a while? Has anyone used it? what switches does it make?
So I’ve setup my test mac m1 Ventura, followed the integration documentation for setting up the jamf connect and deploying using Jamf Pro cloud, not done the menu bit yet as the documentation seems a little confusing. I get a Microsoft login page at the Mac boot screen in place of the standard mac login. I’m able to auth to entra fine but I’m the immediately presented with a secondary user name and password dialogue, followed by a password verify dialogue and finally I’m in. I’m hoping I’ve done something wrong and this is more streamlined in a correct setup???
Hi community,Here looking for feedback on this beta feature from jamf pro specifically on things that have not worked out for you upgrading macOS to Ventura 13.5.2- I did a test on my mac but restart is not forced - anyway a restart can be forced? - I received the Software Update notification come in successfully on my machine and I diverted it but did not received another notification even though I set for this to occur 3 timesYour input is appreciated.
I am trying to use Google LDAP to authenticate users logging into a mac lab, but I have had nothing but issues. The Google LDAP search is successful finding the user account, but fails with a LDAP search with (&(|(objectClass=automount))(|(automountKey=xxxxx))) failed with NO_SUCH_OBJECT. The log in process just spins and spins. No local profile is created. I have removed all configuration profiles for the Mac and it is connected via Ethernet. I've followed these instructions and when I test using ldapsearch, it completes successfully. This is the first lab of macs I have used JAMF for, so I am most likely missing a step somewhere. We have Google LDAP setup successfully for logging into the lab software on the MiniMacs. Any suggestions for troubleshooting or even which logs I should look at would be greatly appreciated. I am very close to giving up and using Active Directory.Thank you!
Hello, I am trying to run my Office 365 download through Jamf Pro and I am getting the following errors: [STEP 1 of 4]Executing Policy Installing Microsoft Office[STEP 2 of 4]Running script install_pkg.sh...Script exit code: 4Script result:https://go.microsoft.com/fwlink/?linkid=XXXXXXX Download URL: https://go.microsoft.com/fwlink/?linkid=XXXXXXX Downloading the installation files... hdiutil: attach failed - image not recognized Failed to mount the downloaded dmg; exiting. Cleaning up installation files...Error running script: return code was 4.[STEP 3 of 4][STEP 4 of 4]
I have some questions about FileVault.Let’s say you have a new Mac computer that is installed with Jamf DEP. During the process a local admin account is created. And the computer will be bind to Active Directory. Then the device is given to the user who logs in onsite with their Active Directory credentials which creates a mobile account. Now he can login with his mobile account of course also from offsite.The Filevault configuration profile is installed and when the user logs out FileVault will be enabled. So far so good. But let’s say somebody else from AD wants to log into the computer now with their AD credentials. This would not work right? Because the “new” user cannot even unlock Filevault before the boot processWhat about the mobile accounts and unlocking FileVault. Will it work? Or do mobile accounts need to be on VPN or Onsite to reach ldap ??
Hello All,I have followed this guide exactly and am going crazy. https://docs.arcticwolf.com/agent/installing_mac.htmlThe error I am seeing seems to be related to the "Execute Command" section or perhaps the .sh script itself This is what the details from the log shows:Result of command:/private/tmp/AGENT/install_AWNAGENT.sh: line 1: {rtf1ansiansicpg1252cocoartf2709: command not found /private/tmp/AGENT/install_AWNAGENT.sh: line 2: syntax error near unexpected token `}' /private/tmp/AGENT/install_AWNAGENT.sh: line 2: `\\cocoatextscaling0\\cocoaplatform0{\\fonttbl\\f0\\fnil\\fcharset0 Monaco;}'I've tried my best to confirm that the .sh is created properly, the file shows SHELL on the Icon and its definitely a plain text documentAny insight would be extremely helpful. Also one thing to note is when I copy pasted the command from the .sh file and ran it in terminal it prompted for my password and then installedThanks
We've followed all the instructions for setting up InTune integration with our Jamf Server on both sides. When I run the self service policy to get a Mac registered in InTune, it goes through all the steps until it gets to the JamfAAD.app where it basically stops. I've let it sit with the spinning gear for an hour with no progress at all. Here's the screenshot:When I click on More Details, here's what it says: Has anyone else encountered this? What app is it trying to get? Could this window be any more vague?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!