Get Support
Recently active
We've successfully deployed the reissue FileVault key script in our environment to send FV recovery keys to Jamf Pro to 99% of the Macs in our fleet. However, we have one Mac whose user is unable to send the key to Jamf Pro due to the following error: Error: User could not be authenticated. Error: Unable to unlock or authenticate to FileVault.To be sure, the user is using his Mac password to unlock System Settings, unlock FileVault at login, etc. But it's unable to generate a new FV key. Any suggestions on how to troubleshoot this sort of thing? I would prefer to avoid having to wipe/reinstall the OS unless it's the only option.
Testing out an Exchange ActiveSync profile in Jamf Pro. I've filled out all the fields in the profile and the profile pushes to the test device just fine. When opening the contacts app on the device, it prompts for the "com.apple.eas.account" password. Nowhere in the profile is there a field for that password. This is the Exchange ActiveSync user account which of course the end users wouldn't have the password for.
We went through a migration process to Jamf Cloud, and have had success with macOS as the process end users follow is quick, painless, and non-destructive. We haven't had any real success encouraging manage device users to migrate as the only successful process they can follow involves resetting the device, and erasing all content and settings - as we use apps like Microsoft Authenticator, the disruption to users is fairly significant. I want to understand if anyone else has been in the position and what strategies they've used to encourage users to reset? There isn't an equivalent to jamf helper for iOS/ipadOS, we used that on macOS to send pop-up messages to encourage stragglers.
Hello all! I'm new to JAMF. We have installed Mac Mini machines to be content caches for our iPads in the school system. They are set to configure themselves when they are plugged into the network and powered up. The default name is mac mini. I go and manually rename each one after it comes up. But for some reason, a couple of days later, the name has reverted to mac mini. I look in the history in JAMF and it only shows when it was created and each time I have renamed it. Any logs I can look at other than the history for the machine? Any ideas?
Hi, I've just created an Jamf account. Now i want to get the jamf 100 Certificate, but my invoice needs to be sent to my company. Can i know how can i update my company informations?
I have Apple Business Manager already successfully federated to Azure AD and ABM creating the matching (managed) Apple IDs in ABM and logins working.The next goal is to provide these to our Mac and iPhone users for utilising FaceTime.There is no problem doing so manually on devices but I have not been able to find any Jamf advice on how to automate this for users. Ideally this would be possible for existing devices and not just freshly DEP/Automated Enrolment devices. So is it possible to push out the Apple ID for a user for use with FaceTime to their device like it is possible to push out e.g. an email account to the email client on that device?
It would be great if Apple/JAMF would support via DEP/MDM Airtags that can be permanently attached to iMacs and MacMinis to discourage units being “lost”. Corbin
With the release of macOS Sonoma Beta I want to look at getting this on a test machine but the directions to find the beta option under Software Updates is not being seen. Would this be due to JAMF management? The device is logged in with an Apple ID that has access to the Apple Developer Program. I have nothing set in JAMF that I'm seeing that's restricting the beta.
We use Jamf Pro Cloud to manage our Mac fleet but would like to hybrid join our Macs to Intune as a method to control who can use Office 365. I see that Conditional access is being Deprecated. Can I accomplish this with just using Device Compliance? I keep getting Notifications in endpoint stating that an Intune update is coming concerning Intune device compliance. I’m new to Azure / Intune so I apologize for my ignorance on that side.
Two questions:1. Interested in testing a Shared iPad configuration on an new iPad. But how do I undo it once testing done - convert back to standard ipad. 2. How to I convert an existing ipad to a shared ipad, it has already been enrolled in Jamf at a normal configuration. All the documentaiton refer to new imports from ASM, not converting an existing iPad..
We have an application installed on all of our Macs called Egnyte Connect which we want to remove. This application was deployed using a pkg via JAMF. Egnyte have given us a command to run their uninstaller.sudo /Applications/Egnyte\\ Connect.app/Contents/Resources/Egnyte\\ Connect\\ Uninstaller.app/Contents/MacOS/Egnyte\\ Connect\\ Uninstaller How can I use this command in JAMF? I tried using it in a script but that didn't work.#!/bin/bashsudo /Applications/Egnyte\\ Connect.app/Contents/Resources/Egnyte\\ Connect\\ Uninstaller.app/Contents/MacOS/Egnyte\\ Connect\\ UninstallerWhat's the best way to approach this?Thanks
Today we released Jamf Connect 2.27.0. This release includes the following changes and improvements: UI Changes to Jamf Connect and Microsoft Azure Active Directory (AD) All mentions of Microsoft Azure AD will be changed to Microsoft Entra ID. Key-values in the configuration profile XML file will remain unchanged to prevent any configuration issues. Jamf Connect documentation will be updated to ensure all UI elements match where applicable. For more information, see Microsoft's New name for Azure Active Directory documentation. Other Changes and Improvements The Jamf Connect menu bar app can now display the current user's name in addition to indicating whether they are a standard user or administrator. The OIDCSecondaryAccess key has been added to the Jamf Connect login window. This key specifies user roles or groups that contain users who are allowed to create additional users on computers after the first account is created. You can specify one role or group and more r
"Just wakin' up in the mornin', gotta thank GodI don't know but today seems kinda odd".........So has anyone run into these issues:1. Yesterday [20230907] we were enrolling devices without any issues. It was all good!2. In the late afternoon, things went bonkers!3. Once the device got pass JC, the device booted to the desktop and just stood there. In JPS it showed up as an unmanaged device. It never proceeded to run enrollmentcomplete. What's worst we couldn't even do a EACAS. We had to N&P™ the long way.4. So we tried another device, same issue and same results.5. Then we thought we'd be smarter than the average bear and DFU a mac(hine) to macOS 13.5.2. In hopes that we would identify an issue. Sadly, same results.Now for hoy dia, we are having more stranger issues:1. Regardless of macOS 13.5, 13.5.1 or 13.5.2, JC allows the us to sign in. However now it by-passed FileVault prompt.2. It created the account and proceeded to the Desktop. It went straight to jail and did not pass Go
Sorry if this has been hinted at before, its a weird one... we have been using a corporatised script takes from the bones of the "Make me an Admin" script and have been using it in one way or another for 6 years..for those who dont know it, it adds a standard or mobile user into the 'admin' (id:80) defualt group for a certan period of time before a launchdameon cuts it off:-/usr/sbin/dseditgroup -o edit -a $user -t user adminso Monterey and below that has always allowed a user to enter a password to install a package or unlock a padlock, as well as sudo and su themselves on a terminal to use admin commands there... except I cant get this to work on 13.5.2, i can install a pkg graphicly, but I cant use sudo or sudo -s to get a root terminal to run it on the command line via /sbin/installerinstaller works when i have used the jamf management account to sudo -s with its complex password... so dont know why users dropped into the admin group cannot do that? if no i will raise a
Does anyone have any good recommendations for free or inexpensive training content for Jamf Connect? I feel mostly confident about rudimentary functions in Jamf and am planning on taking the Jamf 200 course sometime this summer, but I am less confident about Jamf Connect. My organization just started using it and would like to dive in to learn more about implementing it successfully and succinctly.
I want to deploy bomgar macos with intune but I get the error that the original .dmg file that was downloaded could not be located.
We manage 5 devices for our small business via Jamf Now. All of the devices are supervised and have no issues. We went into our Blueprint > Security and enabled the Jamf Protect function. I can see Jamf Connect is running in settings of all of the targets devices. My question is there a dashboard via Jamf Protect for me to view the state of these devices or am I stuck subscribing to Jamf Protect in order to get a dashboard view of all the devices and their security status? Thank you
We are restricting access to several websites through a managed profile that has unwanted URLs in the Blocklist (formerly Blacklist). We now want to add several dozen more URLs to the Blocklist, however it seems the URLs have to be entered one by one? Surely there is another faster way to import a bunch of URLs into the Blocklist at once.
Hello, Currently our staff have admin privileges on our Mac OS X Machines. We would like to take this away and make them a standard user. The only thing preventing us from doing so is adding Wifi Networks either at work or home. Does anyone know a way we can give permission to add wifi networks to a standard user without admin privileges? Any help is much appreciated. We are typically a OS X 10.10.X or 10.11.X environment. Thanks in advance
We are a school new to Vivi and Jamf. I have seen the usefulness of the "App Configuration" area in Jamf for inputting settings for specific apps (Self Service and VMware Horizon Client for us) and I was just wondering if anyone knew whether the Vivi app supported configuration at least for setting the Organisation?Thanks,-Adam.
An internet connection is required to verify trust of the developer This app will not be available until verified. I have been getting this error message on some of our iPads. I believe the error message is incorrect, there is an internet connection at all times via WIFI or cellular.Unfortunately, the app developed for us does not start. I have already rebooted, uninstalled app, reinstalled - no improvement.At first, it only occurred on one device after a manual update of the self-developed app. Then on 3 others. The developer and app certificates are in order and valid until next year.I have no idea how to get around the message. For one device, reinstalling the app helped. Unfortunately not with the other devices.Google search is not helpful either.Do any of you have an idea how I can solve this problem?
Has anyone ever ran into an issue where Self Service, profiles and other apps are not deploying after enrolling.Here is our issue: Our laptops are enrolled in our ABM and pointed to out Jamf instance. We get through the setup assistant and once we get to the desktop Self Service or any other apps do not deploy. There are times we get all the profiles but there are times we dont. Also in jamf when we search for the mac it comes under serial number and not the computer name and does not see that there are any local accounts. Almost as if there is no communication. I opened up multiple tickets fro Jamf support but they have not been any help. I did try to set up a laptop at my home network and it did work so maybe its a firewall issue in our offices? We did just move to a new floor on our building Any ideas or tips to get this working
Hello! I have a fleet of Macs that are school-owned, and since they're managed and stored here in the school I have the AppleID System Pref blocked by creating a restriction in the configuration profiles. If a student clicks the "Apple ID" button in System Prefs (settings) they get a screen that says, "Blocked by administrator" or something to that effect.It's been working great!Until a student inadvertently found their way around it.Said student, in Safari, went to iCloud.com and logged in with their personal AppleID. Safari detected that they were indeed logging in with a valid ID and a popup appeared saying "Would you like to use this AppleID on your Mac?" Of course the student hit okay, then was presented with a Username and Password dialogue box with which they typed a correct password, and voila! Now the student "owns" the computer. Thankfully, the student is cool and came to me to tell me what happened. But in order for me to remove the AppleID from the compute
A couple of my users have experienced apps such as Chrome and FireFox deleting themselves after the migration from our previous MDM to Jamf.- We are using the migration tools from Jamf that were given to us after our migration meeting.- The only policies we have are for basic applications such as m365, OpenVPN, and Adobe.- Users retain their admin rights if they had them.- Chrome and Firefox are in our Self Service portal. I would like to find a solution to why this is happening. I keep going over our policies, our configuration profiles, and our prestage but I can't find a solution. We have zero uninstall policies and the only configurations that work on our computers are the initial Jamf Connect configurations and Windows Defender settings.When Jamf first enrolls or migrates, does it uninstall anything not in the provisioning script? Does it uninstall apps that are available in Self Service?
Has anyone found a way to bypass a password prompt when removing applications, system extensions or network filters on a machine via jamf policy. We are trying to silently remove something from users machines but we get a pop up for password prompt when doing so
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!