Get Support
Recently active
I am unable to revoke the Apps from VPP locations on Jamf Pro. These Apps have been removed from App Store. On Jamf Pro, Settings > Global > Volume purchasing, they appear:-NAME: No NameContent Type: UnknownTOTAL: 20IN USE: 0REPORTED: 20I did try "Revoke All Apps" for several times in vain :-(On ABM, these Apps can't be seen under "Apps and Books," and I can't transfer the App licenses from the locations.
Hello,Can anyone help me with the command line to remove/uncheck the "Automatically join this network" on a known network?In Monterey's it says "Automatically join this network" and in Ventura its "Auto-Join"We have two SSIDs and I want to make sure only the corporate is set to auto-join but not the other one. I appreciate your help. ThanksJoy
Hi all,I am trying to deploy a desktop background image to all our machines, currently I know how to push an image to our machines and how to set and lock the image as the background using a configuration profile, but the issue I'm having with this is it doesn't scale the image on our devices. I would also like to burn the users device name with our IT helpdesk information onto the background if possible.I have discovered a tool called desktoppr can do this but I can't quite find instructions for how I can install this to our jamf instance and set it up.Would anyone be able to let me know the steps I need to take to install this or another tool which can do this, and a script to set the background, scale the image and burn the device information with some info text that would be great?Any help would be much appreciated.Thanks!
Long Story will try to keep it brief. 1,900 iPads enrolled into Jamf were set up as single use Devices for training. Restricted to Safari and a couple of apps. No Apple ID, no need to connect to Azure Entra.Project gets put on hold, everyone forgets about iPads. Two years later project no longer on hold. Pull them out and all sorts of fun including expired MDM profile and Certs. We have figured out most of the issues in reenrolling or DFUing the iPads.Except this one: After iPads went into storage we started enrolling Macs. Have pre-stage enrollment setup with Jamf Connect and Entra and SSO. Everything going great.. until.. iPad Project no longer on hold. When we go to DFU and re-enroll the iPad we are prompted for SSO. We do not want this. The hope is I can create an enrollment for the iPads that does not require SSO authentication. Ideas?
Recently got Jamf Connect onboarded and half our machines are on it and it's been great. We are using Okta and have had no issues except for dns. I cannot get the machines to register to dns. Suffix list works and the machines are able to use shortnames etc. while on vpn (global protect). yet the machines unable to register. I don't really see any errors, it's just like it's not trying. Best I can tell it may be a kerberos realm issue? If I have to bind the mac anyway then i'm going to regret buying Connect pretty fast. The whole point was to get away from binding. Does anyone have a guide for something like this?
We use Safe Internet on iPads in Jamf School. When students open the app we have been getting messages that state we have a vulnerable OS since we are not on the absolute current OS version. We defer updates for 30 days so most of our iPads are on 16.6 or 16.4 and not 16.6.1Is there a way to suppress this message on an iPad?
A lot of our macOS devices are seeing "Self Service cannot connect to the server." since updating Jamf Pro to v10.0.0. Anyone else seeing this? How do we fix it?
Anyone pros with maintaining self-hosted clustered Ubuntu Jamf-Pro instance? After upgrading all of our Jamf-Pro hardware and updating to 10.48.2, our iPads only report the IP address of our load balancer to the JAMF pro GUI. We are running an HA Proxy load Balancer in front of all of our JAMF child nodes that is also used to terminate the SSL connection. We didn't really make any changes to our HA proxy configuration, but now the iPads that are on our internal network only display the IP adress. If an iPad checks in outside of the network it does get that public of wherever it is, but not on our internal network. I messed with adding the "forwardfor" line in the HAproxy config and it doesn't seem to make a difference. Has anyone had this issue?
Hi all,Is there a solution to mark several iPads via Jamf and trigger a LostMode?e.g. 20 or more 50 iPads are stolen from a school and you want to activate the Lostmode with the appropriate message.How could we trigger this as quickly as possible and without much time expenditure with a message?Without having to set the LostMode on the iPad individually?Nice RegardsPeter
Afternoon All!Work for a school and we are moving away from paper based finals. But a general student laptop is wide open to all sorts of stuff. How do we lock it down? iOS has Kiosk mode options but MacOS doesn't have anything (that I've found) as straight forward. I've cobbled together a couple of config profiles that get the job mostly done but it also throws permission errors. Looking for advice on:1. what other schools have used, in relation to laptops, Jamf Pro and testing in a Kiosk-esque setup.2. how I can tinker the config profile to not throw so many errors. Let's start at the beginning. 2 config profiles (Dock & Kiosk Mode). Dock limits the dock to only Text Edit, Self Service & System Pref. Fairly strait forward and works like a champ. Kiosk Mode does a bunch of stuff:Restrictions are set as follows:-Disables everything in Sys Pref except - Network and Parental Controls- Restricts app to only TextEdit- Widgets are turned off- Media al
Hi,Let's first start with the question, then some introductions and considerations...Is the sign-in performed every 15 minutes supposed to be an interactive or non-interactive sign-in? We are using Jamf Connect several years now and some time ago we were able to resolve the failed login messages by excluding it from our MFA policy.We still struggle with the Risky Sign-ins as you cannot exclude or filter apps from the auto-remediation policies.Every now and then the regular pwd checks of Jamf Connect causes someone to be marked as Risky, because JC only is interested in the username and password and ignores any MFA challenge to auto remediate the risky sign-in.As far is we understood ROPG sign-in are supposed to be non-interactive, non-interactive sign-in are not checked for conditional access. Jamf Connect performs a ROPG authentication every 15 minutes to check password in AzureAD.When reviewing the logs in AzureAD, we see the 15 minute checks as interactive sign-ins. I recreated
In the latest versions of Jamf Pro I am seeing several new Connection Types available in the VPN option of macOS Configuration Profiles (and mobile too).I am interested in using the Connection Type of /Cisco AnyConnect. I can't find any documentation on what should go in the fields or how it relates to the Cisco AnyConnect Secure Mobility Client (if it does at all). Is anyone using this or knows of any documentation? For the record the "new" types areCisco Legacy AnyConnectCisco AnyConnectJuniper SSLF5 SSLSonicWaALL Mobile ConnectAruba VIACheck Point Mobile VPNCustom SSL
Hi allUntil now it is not possible to change a created LostMode text afterwards without deactivating the LostMode and reactivating it with the new/corrected text.Why is it not possible to change the LostMode text afterwards?How do you proceed?Nice RegardsPeter
Hello together,Is it generally possible to assign the same app from two different ABM in same JAMF environment?Maybe is a stupid question but would like to know if it is possible.I have booked the app from two different ABM and assigned to the same JAMF but can only see booked app from one ABM!Thanks already for your help 🙂
We currently roster Apple Classroom through Apple School Manager using staff and student Managed Apple IDs. While everything worked as expected last school year, we've run into an issue this school year. We decided not to wipe/re-enroll our devices over the summer so we simply left them as they were from the last school year, including leaving the students signed in to their Apple IDs. At the start of this year, around 2/3 of the students received their new classes from Apple School Manager as expected, but the other 1/3 did not, they still show their old 2022-2023 classes on device. Everyone has the correct and current classes in ASM. In troubleshooting, we've updated the impacted devices, wiped all settings, and tested the Apple ID to see if it's actually functioning. The update/settings wipe had no impact and the Apple ID was indeed working correctly as we could create files in the Files app and have them correctly sync up to iCloud. From there, we simply signed out of the Appl
So I’ve setup my test mac m1 Ventura, followed the integration documentation for setting up the jamf connect and deploying using Jamf Pro cloud, not done the menu bit yet as the documentation seems a little confusing. I get a Microsoft login page at the Mac boot screen in place of the standard mac login. I’m able to auth to entra fine but I’m the immediately presented with a secondary user name and password dialogue, followed by a password verify dialogue and finally I’m in. I’m hoping I’ve done something wrong and this is more streamlined in a correct setup???
Hello There,I am wondering if anyone having same issue that I am facing regarding Nudge. Somehow when I am launching it the Nudge window doesn't show Deferral dropdown box as it is suppose to, So user can't defer the app any shap or form and it stays on window until user updates their compurter. All settiing for deferral are in JSON file. Deferral dropdown doesn't show on buttom right as it is suppose to. Any help appreciated. { "optionalFeatures": { "acceptableApplicationBundleIDs": [], "acceptableAssertionUsage": false, "acceptableCameraUsage": false, "acceptableScreenSharingUsage": false, "aggressiveUserExperience": true, "aggressiveUserFullScreenExperience": true, "asynchronousSoftwareUpdate": true, "attemptToBlockApplicationLaunches": false, "attemptToFetchMajorUpgrade": true, "blockedApplicationBundleIDs": [], &nb
Hello,I want to use PreStage to enroll my macs that I already purchased.So I use Apple Configurator 2, they are registered in ABM but they don't appear in Jamf.Then I saw on ABM they are enroll with the Apple Configurator MDM server. I change the server to Jamf pro. I set by default that all macs added to ABM have to automatically use Jamf pro MDM server. But same issue, they use : Apple Configurator MDM server.My question is : is it possible to successfully enroll a mac with Apple configurator with Jamf pro?
iPads won't reinstall apps and apply profiles after erase. I can remotely eg restart the devices and the last check-in time shows that the iPads are communicating with Jamf. All iPads are Supervised. 9th Gen iPads have still iOS 15.5.I got apps installed when I modified the app list for the device group where the iPads are.
Guys,I'm using promote script to make standard users as an administrator. And my requirement is, not to demote the user who are all already an administrator.I've logic here correct me If I'm wrong. When I execute the promote script, I will be storing the log saying 'You are already administrator' if the script executed on the administrator user profile. Taking the log as an input and making the condition that if the log has this message then no action required on demote script. And anyone help me with the script how to read the string in the file and make that has a condition. Thanks for understanding.
With Apple's changes to who qualifies for the Developer beta (as well as how it is installed), does anyone have advice on how to block users from installing it? In the past we always created a Restricted Software policy that restricted and then killed the process named "Install macOS <this year's name> Beta.app", but it looks like Apple is no longer deploying these in that way anymore. Granted, I could be wrong on that haha.We've created a similar policy for Sonoma, as well as an additional policy that blocks "macOSDeveloperBetaAccessUtility*" -- since it looks like that is the new deployment method. Have any of you come across a better solution?
I have been testing the Jamf compliance editor, and the scripts for the extension attributes are reporting 0 when the files the script is reading has a few failures and 2 exemptions. I am not seeing anything out of place in the script, any help? Here is the script for the Failure Count Attribute: #!/bin/bash# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # ### Copyright (c) 2022 Jamf. All rights reserved.## Redistribution and use in source and binary forms, with or without# modification, are permitted provided that the following conditions are met:# * Redistributions of source code must retain the above copyright# notice, this list of conditions and the following disclaimer.# * Redistributions in binary form must reproduce the above copyright# notice, this list of conditions and the following disclaimer in the# documentation and/or other materials provided with the distribution.# * Neither the name of the Jamf nor the names of its cont
I am trying to install and license Avid Media Composer on lab machines using floating license.Used Jamf composer to install the pkg for Avid Link first and then Avid Media composer with postinstall scriptinstaller -pkg /“installer.pkg” -target / the app install fine.I tried to capture the license using another package.But getting error when opening Avid Linkanyone knows how to capture the license?
I have combed through all the threads here before posting, I am trying to figure out why this is happening to all unencrypted Macs on this server. The user gets a pop-up to enable FV, enter password, and then the following shows up in the logs: All the users have Secure Token, and they are enabled for FV2. Any help would be appreciated. Here is the setup we have:
Our Jamf environment requires that all Macs have FileVault enabled and we recently discovered that all of our Ventura systems can no longer unlock the drive with any administrator accounts. The only ones that can are standard accounts. We we're able to reproduce this issue on both an existing system that was upgraded to Ventura and a brand new MacBook Pro. To clarify:- FileVault is enabled on Mac OS Ventura.- Administrator accounts are unable to unlock the drive at startup/reboot.- Only Standard accounts are able to unlock the drive at startup/reboot.- We were able to reproduce the issue on both an older Silicon Mac and a brand new Silicon Mac out of the box. Any advice is greatly appreciated.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!