Get Support
Recently active
I'm working on moving users away from using the App Store to install apps and instead using Self Service. To make this transition easier, I want users to be able to open and browse the App Store, but not install anything. That way, if the user needs an app, it's simply a matter of the user getting a screenshot of what they need and submitting a ticket with the request, and I will then add it as a Self Service app.The most straightforward way of doing this seems to be to just prevent users from logging on to the App Store, but I'm not sure how to do this. We are not currently using managed Apple IDs.A similar question to this has been asked several times, but it looks like no one has presented the solution I am looking for:https://community.jamf.com/t5/jamf-pro/disabling-app-store-access/td-p/46605https://community.jamf.com/t5/jamf-pro/config-profile-restrict-app-store-and-restrict-app-store-to-mdm/td-p/180089https://community.jamf.com/t5/jamf-pro/restrict-app-store-apps/td-p/219061http
I'm attempting to deploy Canon's Uniflow follow me printing service. Adding the print driver is easy enough and I can map the printer and add it via jamf admin. The issue I'm having is that the "URL" of the printer (LPD/LPR) is unique for each user as it includes their username. The URL is like this: lpd://<username>@xxxxxxxxxx/PrintAnywhere where I'd like <username> , to be their actual username. We are currently not bound to any directory service and have not deployed Connect yet (Azure AD). The local user account usernames are the same as their AD username. My question is this, what is the cleanest way to inject or replace the LDP address with their custom url that includes their username? Canon has been no help and I'll be honest in the fact that I'm not a scripting whiz.
I receive from Canon a SmartClientMac.iso package to deploy the UniFlow client and printer include settings.The SmartClientMac.iso is not supported in Jamf and its not possible to deploy.Inside the iso there is a dmg and a plist /jpg and ds store file.I already tried to convert the iso to dmg with the disk utility and after this deploy but it doesnt work.Is there a way to deploy the UniFlow client include the settings?
Hello mates, New to JAMFPro, just was wondering, I'm getting a "Your Mac is running the latest software update allowed by your administrator - macOS Mojave 10.14.4" message in Software Update, But I can't see any policies or config profiles that would prevent that. How can I push the option at least to upgrade to 10.14.5 through Software Update? Thanks in advance mates!
Hello - last post on this topic I could find was from 2015. Any way (Mojave and Higher) to disallow the "Reopen Windows When Logging Back In" across all Macs in a fleet? I know the way this is controlled behind the scenes has changed over the years. Thanks all!
I am new to Jamf Pro API and I am diving into more and more automations. Can someone help me with how i would go about to updating multiple computer assignments for a static group by using computer names. If you have a working script, please assist. maybe via csv file?
Is there a way to send a pop up message to all Staff computers to notify them that there is an email problem?
Hi, I am trying to add Microsoft Offic 365 packages (Word, Excel, powerpoint etc..) to Dock but I got only ? mark. Obviously path is not correct.I have tried the below paths, none worked. Any help apreciated, please./Applications/Microsoft Wod.app/System/Applications/Microsoft Word.appfile:///Applications/Microsoft Word.appfile:///Applications/Microsoft%20Word.app/Applications/Microsoft%20Word.app Thanks
Is there a way to see the progress of a Mac App Store installation from Self Service?These installs always seem to take a long time without any feedback within Self Service. Right now I have a Mac that I am helping the local school contact troubleshoot. Currently they are trying to install iMovie and Garageband (I always tell them to do one at a time, but oh well), and both are just showing the spinning circle in Self Service. Even after a reboot.They have been sitting at this for over an hour. I was hoping that there was something I could check in Terminal to see the status of these installs. Anything possible?Tim
Our security team wanted to know what these two local accounts that are added to every macbook when its enrolled into jamf. Does anyone know what each of them are used for and what access they have?Is it related to Jamf MDM or Jamf Connect?jamf-management /private/var/jamf-managemen svc-securityscans-mac-jamf /Users/svc-securityscans-mac-jamf
Hi,I have a few programs i want to install on our new iMacs, Logic.pkg, Papercut.dmg, Sibelius.pkg & netsupport.dmgI have searched and tried several scripts but nothing seems to work, JamF says the iMac has recieved the script but nothing happens.the packages are currently stored on a munki repository accessible by URL, if its easier i can copy them to a network share?i need it so they automatically download and install on the iMacs using Bash or Apple Script, i can see a lot of you are good at doing this type of scripting and i thank you for your help.PaperCut website:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>Label</key><string>com.papercut.client.agent</string><key>ProgramArguments</key><array><string>/Applications/PCClient.app/Contents/MacOS/JavaAppLauncher</string></arra
Hello Everyone!I've been working with Jamf Pro for a while now and have successfully deployed it for our laptop for business needs. However, I've encountered a challenge that I'd like to discuss with the experienced members of this community. Your insights would be greatly appreciated.Multi-Site Management: I'm currently managing multiple sites with varying laptop for business requirements. How can I optimize my Jamf Pro setup to efficiently manage these diverse environments? Any best practices or tips you can share?Custom Scripts: I'm keen to explore advanced scripting options within Jamf Pro for our laptop for business use case. What are some advanced scripting techniques or creative ways you've used custom scripts to automate tasks or enhance device management?Security Policies: How do you handle complex security policies within Jamf Pro for laptop for business scenarios? Are there any strategies or features you've found particularly effective for maintaining a high level of securit
The remote command Update OS Versions on supervised devices is no longer available to run on the Devices tab. The 'Next' button is greyed out. There is a box saying You can now use Software Updates to manage OS updates but I do not want to do that, I want to run the OS update remote command. How do we get this option back? Thanks!
Recently acquired some new software called Rave Mobile Safety. I have a .pkg that I've made through composer. It installs the software but it doesn't include the activation key. When a user launches the software it asks them for the activation key. Am I missing it somewhere during the process in composer or is it possible to create a script to add the key after in gets installed?
Hello, We use Azure AD and SSO with our Jamf cloud instance.When we log in to the Jamf self service with an Azure AD account, if we don't click "disconnect", each time we log in to the self service, it automatically logs in with the previously used Azure AD account.This poses a problem for us because our technicians can log in with their Azure AD admin accounts on the users' Jamf self-service in order to access administrative content but do not always log out properly.Therefore, users can subsequently open the self service and by clicking on "login" be automatically logged in with the technician's admin account.Is there a way to avoid this please?Thank you for your help
We've encountered an issue related to expired Wi-Fi certificates interfering with Kerberos and SmartCard logins, despite not utilizing SmartCards in our setup. Oddly, Kerberos perceives our expired Wi-Fi certificates as identities for SmartCard logins. Yet, when the certificates aren't expired, this issue doesn't manifest.Recently, SmartCard login has been inadvertently activated on some user machines. As a result, these users cannot log out of Kerberos SmartCard. We found a temporary workaround: deleting the expired Wi-Fi certificate and rebooting allows Kerberos to permit the user to log out. Interestingly, in the absence of any expired certificates, the Kerberos SmartCard cannot recognize any identities, preventing it from being set up on a user's Mac.I'm trying to create a policy script to delete any expired system keychain certificates, but I've hit some roadblocks. Would anyone have relevant scripts or recommendations I could leverage?Thanks in advance.
Before the last update we were deploying FileVault activation during enrollment via pre-stage. It was working fine until we upgraded to Jamf Pro 10.50.We encountered a issue: If you deploy a FileVault configuration profile in pre-stage, without enabling the new feature "Force Enable in Setup Assistant", the enrollment crashes with "Waiting for the management server..."
Hi All, I have created a local admin account in prestage and also a local admin account policy but whenever I login to it on the device it never works!Any advice or a better process to achieve this?
I have several users who are not receiving newest Xcode update via Mac Apps. In self-service, it shows 14.3.1 but no install button, but an open button. When the user opens Xcode, it's 14.1 and have tried to force updates to no avail. I am trying the unscope and re-scape method now, but its there any reason that the Mac App Store would do this?
Hi, I'm trying to get a network volume mounted automatically at login. The volumes are on an AFP server. In Jamf Pro I am using Configuration Profiles > Login Items > Network Mounts and entering the following: afp://myserver.mycompany.com/MyVolume On client computers I can see in Utilities > System Information > Software Profiles that the loginitems.managed item is being pushed correctly to the client, with the correct afp path as above. However, no volume is mounted at login. In System Preferences > Users & Groups > CurrentUser > Login Items a volume is shown, but there is no path - only "/". I can see discussion that others have problems with this payload. Is it expected to work at all with 10.14 and 10.15? Thanks, ft.
Hello Jamf Nation! We recently released Jamf Protect 5.0.0. This release includes the following changes and improvements: The Computers Overview dashboard and the macOS Version column on the Computers page now displays the Rapid Security Responses (RSR) version. The RSR version of macOS continues to be reported in the Computer Details, under OS and in Alerts. The Apple Provided Software is Current insight also continues to support RSR versions. The new query listBaselineRules has been added to the Jamf Protect public API. The query lists information for insights including their Center for Internet Security (CIS) benchmark ID. Previously, the Time Machine Volumes Are Encrypted insight reported noncompliant when a user did not have Time Machine enabled. Now the insight verifies that Time Machine is enabled prior to reporting compliance based on whether encryption is enabled or not. Product Documentation For additional information on what's included in this release, review the
Reports have been coming in about macs on the corporate network getting "poor network stability" messages periodically and my networking team has confirmed that systems are jumping from 5ghz network to the 2.4ghz network, or having a hard time moving from AP to AP based on proximity. After doing some digging I have noticed some articles with similar issues referring to AWDL (Apple Wireless Direct Link). https://www.meter.com/mac-osx-awdl-psa Mainly to disable this feature on systems to avoid future issues. This article mentions that the issue should have been resolved in the recent updates to macOS, but systems with the latest OS are still reporting issues. Have others seen similar issues and implemented this practice of disabling the AWDL?
I'm using the not-very-well-documented computercommands API to trigger device locks during termination events. I got it working on a test device last week, but it has not sent out the command to two separate devices in PROD just today even though when I run the script in verbose it returns a 200 from JSS.Does anyone else use this API or seen something similar?Here is my code:$uri = "https://mycoolcompany.jamfcloud.com/JSSResource/computercommands/command/DeviceLock/passcode/246810/id/$jamf_id";$ch = curl_init($uri);$curlOptions = array( CURLOPT_HTTPHEADER => array( 'Content-Type: application/json', 'Accept: application/json' ), CURLOPT_HTTPAUTH => CURLAUTH_BASIC, CURLOPT_USERPWD => "$jssUser:$jssPass", CURLOPT_RETURNTRANSFER => true, CURLOPT_VERBOSE => true, // Enable verbose output);curl_setopt_array($ch, $curlOptions);$result = curl_exec($
how to get the deviceId id from jamf API i want to bring the compliance details
Hi, A Macbook user just raised an issue with me regarding they can't plug in a USB drive to ttransfer files. I do know we have a restriction profile that stops iCloud, imessage. I don't know we had a restriction on USB connectivity. If it a setting in JSS, where would I find this (and disable it)? We're using JSS 9.81.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!