Get Support
Recently active
Hi Jamf team, Our Automated Device Enrollment Instance server token expired. I followed this steps to renew ityoutu.be/HBV9VoRzajM however, every time I try to upload the key it gives me " the file received was not valid" error I can't see any difference between last year token name and this year except the date. I don't understand why it throws error.I would be appreciated if you could help me in this matterMany thanks
We use a script to rename our Macs along the lines of DA-%SERIALNUMBER%For the last year or so, around half of our estate (I expect those using our campus network) regularly renames itself along the line of DA-FVFHF4BGQ05F (6), the suffix number incrementally increases and we have some devices with hostnames that end (533) or greater. This obviously looks a total mess.I don't fully understand why this happens, nor how to prevent it - I presume it relates to the device wanting to avoid a duplicate name on the network, which in our case would only be itself, so it's confusing why it happens at all. WIndows isn't affected in the same way. I suspect the ultimate fix would be something at network level, but wonder if anyone knew the root cause, or had dealt with this via macOS config and/or Jamf?
When our users change their SSO password, JAMFs pops a message that the passwords are now out of sync and to enter your "local password" in order to sync. When that local is really their previous SSO password. This is confusing all our users since we rolled this out. Is this wording able to be changed? Thank you.
Is there any industry standard documentation on the XML format of app level configuration options or is that something I get from the third party vendor of the app in the form of a schema that their developers make available?
Hi there, When opening the Jamf Pro portal on the notification section (blizzard) I noticed I get the message: Device Count ExceededThere is an link: Purchase additional devices here but when browsing to the link from the Jamf Pro portal to this address: https://www.jamf.com/jamf-nation/my/renewal I get a 404 error: The URL requested does not exist.Contact support or your Jamf Buddy to report the broken link. Only from the Dashboard I can see the software licenses. But I don't think this is the issue I'm looking for. I'll attach some screenshots perhaps anyone knows how I can solve this issue. I don't think this will effect further enrolling devices but I just want to get this fixed and get the notification solved/gone. Hope to hear from you, Kind regards, / Bart
So I created a static group for the purpose of sending out targeted messages when needed. The idea being, if I have a need to send a message to a bunch of iPhones or iPads, I could put them in this group and send the message out. That's just background on why I created the group.After I was done with the group task, I pulled up the group membership to remove all the devices from the group, and I don't see any way to do that. I can "view" the group but there's no way to select all or a portion of them and remove them from the group. In other words, there's no check box next to the member devices or an "select all" option.I see how I can search for a member and then remove that member from the group but seriously that can't be the way it works right? I have to delete them individually by searching? Seems like it would make a lot more sense to be able to select the "view" option, see the list of members, and just uncheck the ones you want from the results a la cart so to speak.What am I m
We have several hundred field workers with iPhones and iPads. Our mobile apps are set to auto update when updates are available. When in the field, and away from WIFI, often times, the app updates will take a considerable amount of time to finish, during which the app is unavailable to use.Is it possible to have app updates only happen when connected to WIFI? That way, updates would never happen in the field and disrupt the use of certain apps. I would like to retain the ability to deploy and install new apps even when the people are away from WIFI. So if it is possible to only UPDATE apps over WIFI, would that prevent them from RECEIVING and installing new apps in the field?Thanks,Rob
Hi All,We need to disable all safari extensions through Jamf Pro except few. I have achieved for google chrome using plist but not for safari.If anyone has done this, please let me know.
Hello,I'm new to managing devices (iOS) in Jamf Pro. I'm looking for a set of best practices when it comes to setting up devices, including restrictions, settings etc. We have just a few iPhones in the company but I want to make sure they are properly secured and managed. Any advice is much appreciated! Thanks.
Guys,We are migrating to Intune from Jamf. And our end users are standard users and for the installation of MDM profile it's prompting for administrator credentials. So I tried making the standard users as an admin using shell script and as soon as they enrolled into Intune once again using another shell script to convert them to standard users. But that's not working when I tried it in my Mac as username should be add in sudoers file. Even unable to create an admin account too getting the below message. Kindly advice.
Hi Folks,I'm trying to find a way to update our extension attribute every 5 minutes, but only one specific, so i don't want to mess with the inventory collection.I figured my best bet is to create a script that does the same as it does now for the EA, but instead of just doing a <results> echo, writing it directly using the APII still need to redo my JAMF 400 since i found the whole API thing so confusing, but i think i have the idea down.would this be effective/would you do it differently?-credentials-grab serial number from system profiler-use serial to grab the computer ID using the API (so "https://***.jamfcloud.com/JSSResource/computers/serialnumber/$serial_number")-execute the script (in this case, it checks the IP for a specific interface)-writes the value using the API by using the previously fetched ID (i think this should go via the computer then, not clear if there's a better way?)as you might be able to tell, i kind of know what to do but still feel lost, tips/hi
TeamWe have planned to enroll Yubikey for our Mac population.We have pre-configured Keys: customized PIN + PUK.When the user lock his smartcard logging into his session, Mac os is not asikng him to insert his PUK code.This is done in windows using deployed "Yubikey Mini Driver". I see no such app for mac os.This a major roadblock for the project. Any idea heroes ?
Hi, I've created a 802.1x Ethernet configuration profile and deployed to a couple of test devices.I can get 802.1x to connect going into Network - Ethernet Connection - Details - 802.1x - select Configuration Profile for Network and clicking connect. It auths via TLS and connects but i would like this to happen automatically, we cannot expect our users to manually go in and connect everytime.Does anyone know how i get this to connect automatically? TIA.
Although it is common for Major OS upgrades to disable the Jamf Connect login window, I've noticed that when installing the Apple Studio Display software update, on reboot the Jamf Connect login window is missing. Is this a bug in its update logic for OS updates, where it still thinks one is happening and stays disabled? I've noticed that authchanger will not restore the screen, but if I let the machine sit long enough, it seems to recover. Again, making me suspicious this is something to do with it's OS update/temp disable logic.I'm seen this on OS 12 and 13, and currently Ventura 13.3.1 with Jamf Connect 2.23.Is there a log I should be looking at to see what Jamf Connect thinks is going on?
Would like to have advice.i know i can do "sudo jamf policy -event" to trigger policy in jamf pro. but if i want to manual trigger one 'confiugration file', how to do that?ThanksChris
Hello all,With some help from our community I've been using Dockutil for our elementary classes for a while (hint: I need help again). However, while I'm waiting and hoping for someone to enlighten me on how to apply dock changes using based on the Active Directory group membership of the logged in user, I figured I'd open up the conversation a bit and ask what methods you all are using and prefer to offer dock configurations to end users. My challenge is of course that as a PreK-12 school, we have very young users.An alternative solution I'm thinking of is offering Dock Configurations via Self-Service using Jamf's built in Dock Policy. Apple has made it increasingly difficult for admins to administer (while making things safer to be fair). I still miss the remote desktop solution that was once part of the suite of tools. Here's hoping ARD continues to live (and work).
Hello everyone. So I'm a bit confused about the subject. We're doing a refresh of staff computers this year. M1 MacBook Airs. Until recently they did not have the ability to use this feature due to hardware limitations. Many of them were looking forward to using this feature. A teacher and I were doing some testing on a machine I ordered just for that purpose. When she tried using a popup appeared saying something like "you can't use Universal Control because your account doesn't have 2FA configured.Of course our Managed ID's have 2FA so I did a bit of searching and came to find out that Managed ID users are unable to use UC. I did a quick search of JAMF Nation and found out there is a profile setting, under restricted, that allows you to enable UC. My question is does this just work with non-managed ID's?I'm really disappointed that Apple would do something like this. We purchase the same hardware as consumers do. Use the same software, have 2FA configured. Not only is UC not su
I'm aware that JAMF has the "Wipe Computer" MDM command, but for security reasons, this doesn't go far enough. After the MDM wipe is complete, the device is still usable since it just deletes all the data and does a reinstall of the OS. I'd like to know if there's a method to remotely wipe the entire drive of a machine like what you can do in Disk Utility. That way if a device is stolen I can render it completely nonfunctional.
Hi,We sent a lock command to a Mac (it was showing vulnerabilities in our antivirus system)It picked it up but the user put in the wrong 6 digit code multiple times and now shows the below times before she can even type in a pin.Apple Silicon Mac on Monterey 12.4.How do we get the Mac unlocked?Thanks.
Does anyone have recommendations for installing Jamf Infrastructure Manager? I am receiving the attached rollback error after initiating the installation and entering the verified parameters. I used the following as resources: https://hcsonline.com/support/white-papers/installing-jamf-infrastructure-manager-on-a-windows-server https://docs.jamf.com/infrastructure-manager/2.1.0/Installing_a_Jamf_Infrastructure_Manager_Instance.html The system settings are as follows: Windows Server 2016 x64 VM (patched, latest build).4 GB RAM80 GB HD w/ plenty of disk space availableJava 11 w/ path configured I currently have a ticket open with Jamf but so far the troubleshooting suggestions have been fairly basic steps that I had already taken like ensuring the FQDN is used for hostname and installing from an elevated command prompt session. The login credentials for the API user are also valid. The installation log is extremely verbose but I parsed every single line. There is a single 1603 error
Students often use a hotspot on campus to get around our firewall and filtering. I'm trying to find an effective way to reconnect them to our school ssid if it's detected. I created a smart group to detect if they're off campus based on their ip address (this works) and then set up a configuration profile with a network payload that connect to our school ssid and scoped it to the off campus smart group (this works intermittently). Has anyone come up with an effective solution for doing this?
Job Title - Citrix AdminLocation - Bloomington, ILType- Contract Job Description: Desired candidate will serve as L3 admin, who will help us support the remote enterprise DC from offshore.• Provide technical support, monitoring, maintenance and trouble-shooting as necessary to keep DC infrastructure up and running.• Manage Infrastructure from build to decommission• Build/patch/upgrade/install /migrate/decommission Servers / applications on need bases.• Handle alerts/incidents/work orders/change request/problem records/ticket analysis/RCA as a part of support team• Work in synergy with other su
Hi Jamf team,Currently macOS 14 Sonoma Beta version is released, and we are actively testing the compatibility on same. Please do share any challenges faced with this version and when is the actual version release expected ?Moreover, when will be CIS benchmark for Sonoma will be released ?Thanks,Siddhi Desai
Please find the job description below: Job: MAC Engineer Location: Richardson,TX or Frisco,TX or Bloomington,ILType: Long Term Contract Job Description: Responsibilities of Macintosh Workstation Steward:Review and Approve/Deny forms for supported workstation type. Examples include Workstation orders / Workstation enhancement requests, security access requests, and any new software that is in consideration of being brought in.Manage workstation types and workstation profile(s)Represent Macintosh customers regarding enterprise workstation decisionsKnowledge source – providing information about available productsFacilitate creation of workstation training / Job-aidsCommunicate client environment changes to business partnersParticipate with the Client Integration TeamProvide and maintain a test environment for areas to test products (ex: jamfcloud.com)Load and test workstations as needed – Physical workstations in GC LabWork any incidents or requests assigned to 3rd level wo
We are seeing a chronic issue where new and re-enrolling DEP devices, right after MDM enrollment screen, screen goes black or reboots, completely skipping account creation, etc. Boots to login window and blank username and password .This has been a HUGE issue as we drop ship laptops to users to set up their local accounts, then receive their software for their first day, or when they have had their previous computer replaced.One of two things happen in the JAMF device recpord1. Partial record showing DEP - serialnumber. Device is not managed2. Full device record with what looks like all the info, but device is not communicatingWe end up, in most situations, walk user through Recovery. Basically wiping and reinstalling macOS. Sometimes, the proceeding setup is successful, but have had times where it happens again.JAMF support has not been hugely helpful.The saw our activation could was expired, we updated but are still seeing the issue, even after the 10.48.1 update (JAMF Pro). We are h
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!