Get Support
Recently active
Hi All,I need to deploy MS Defender using Jamf pro to all managed macOS. I am following the instruction mentioned by Microsoft on Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro | Microsoft Learn. But I am not able to navigate to Settings > Endpoints > Onboarding. I don't see onboarding option. I do have Global Admin access in Azure. Do I need to get any other access to access the above mentioned path please? Thanks.
I'm trying to deploy some apps to a batch of macOS devices using Jamf Pro, but every time I initiate the deployment, I receive an error message with code 432. Has anyone else encountered this error before, specifically error code 432? Please give some guidance to solve my problem.
We recently upgraded our PaloAlto firewall and are having issues downloading files on Macs. Files start out fast and then suddenly decrease on the clock to "Days" instead of "Minutes". Our security team says that it has to do with TCP Window Scaling. They say that TCP Window Scaling, is off by default on a Windows system, but on by default on a Mac. Is there a way to disable TCP Window scaling on a Mac, via a terminal command that anyone knows of? Thank you all in advance!
We used to sync classes down to Jamf from Apple School Manager, but during the summer transitioned away from that and also transitioned from AD to Jamf Connect. About a 1/3 of our staff Macs still have the EDU profile on them which is preventing rosters from Apple School Manager from populating via the teacher's Managed Apple ID. On Jamf Pro, the user currently assigned to the Mac does not have any roster data associated with them nor are they in any classes. The EDU profile left behind on the machine shows as being assigned to the current local Mac account. The handful of Macs I checked do not appear to be running the command to remove the profile. Any ideas on how to resolve this?
So we know that JAMF recommends to enable HSTS on Jamf Pro on-prem instances. However, I find the article lacking in several aspects.If we start with what I'm most curious about - Why? For instance, these specific questions come to mind:* If HSTS isn't enabled, can the MDM connection be downgraded to HTTP when the device is already enrolled, and thus can the device be tricked into executing MDM commands on either a HTTP session or a HTTPS session with an invalid certificate? Is the user prompted in this case and can the user choose to continue?* Is the HSTS recommendation meant or administrative access only instead?* Is the HSTS recommendation there to prevent MITM attacks for initial enrollment only? Or a combination of that and administrative access? In essence, describe the risks if it isn't enabled in a JAMF pro specific scenario.* Are there any downsides or pitfalls when enabling HSTS? A far-fetched thing would be that it automatically also enables certificate pinning so that an u
I've got a device that shows not having checked in since 8/21 but the end user has been using it daily. She went to use her phone this morning and it said iPhone Unavailable, check back in 15 minutes. No love after 15. Remote commands are not getting to the device and she cannot use her pin to unlock it bc of said message. Hard shutdown and restart did not help. Any thoughts?DeclarativeManagementPending
Hello, we are looking at implementing SCEP Proxy with SecureW2, when you setup the external CA with the SCEP Proxy settings and upload the Change Signing and CA Certificates, does this affect the Jamf Pro built-in CA? We use the built-in Jamf Pro CA for enrollment and don't want to change that. Does this external CA cause you to have to re-enroll all your devices?
Hi Everyone, I have set the Mac up to accept Yubikey account creation. It queries AD then creates an account if it finds the user's certificates from the Yubikey. However, when signing in, it repeatedly prompts for a keychain password saying "macOS wants to use the "login" keychain." Any ideas on how to stop this from popping up, or why it does? I would also prefer it asks for a PIN over password if that prompt is required to get full use of the mac. Also, other items keep prompting for the Keychain instead of the pin as well. Such as Spotlight, Transparent Network Proxy for Apple system services, security, and ScopedBookmarkAgent. But once I cancel those enough times, they do not prompt me again. But the macOS does. Any and all help is appreciated. Thank you.
Hi Nation, I hope you are all well.I am trying to set up Intune Integration for Compliance, however every article I seem to find is around Conditional Access which is legacy, I can not find anything that details guidance for Device Compliance and the Intune config. Does anyone have a good link ? ThanksBob - Reno
We have some computers where the screen will default to "Extend Display" rather than "Duplicate" for the built in screen. This works for returning accounts but not new ones and in our university setting we wipe the accounts at the end of each day so each account that gets made is seen as a new one and defaults back to "Extend Display". Anyone found any scripts or settings in or outside of Jamf that can solve this issue?
Hi All. I'm trying to change this value from NO to YES.This is located here: /Users/username/Library/Containers/com.microsoft.Outlook/Data/Library/Preferences/com.microsoft.Outlook.plistIt essentially ensures that MS Teams is auto-defaulted to the preferred Meeting type when creating a new Calendar invite. I'm not sure what command/script I need to use for this.
While doing some filevault key refreshing via script, i got a few (less than 10%) of these errors, and i cant seem to find any info on error 45 for filevault. DOes anyone have any kinf of info about this?"fdesetup exited with return code: 45."
Can anyone shed some light on what I need to do when it comes to the 'Certificate Download' and 'Upload Additional Certificate' options? I've went thorough all the docs I can find and the most helpful line is this:"save the certificate in the appropriate location dictated by your web server vendor." That just doesn't help me much. I have our images on an apache2 web server and they working correctly using SSL. They are accessible inside our network and out. When I attempt to add our wildcard certificate as the 'Additional Certificate', I get a message that it has not been uploaded. You can see the process in the pics. Does anyone had more detailed information on what to do with the certificate I get from the Download button and what certificate to upload as an Additional Certificate? When I use the test button and use a valid url to a user image, I get this:
Is it possible to allow an app to add proxy configurations with a configuration profile, similar to something like full disk access?We're not currently using Forcepoint Neo as a proxy, but this prompt appears during the installation of Forcepoint DLP. If it's not allowed here, the installation will not complete until it's allowed through System Settings/Preferences. I've added configurations for this app to allow network monitoring, disk access, system events, etc., so I assume it's possible here and I'm overlooking it.
Just wondering if any has instructions on how to configure an iis server as a distribution point for user images.I have tried to follow the generic instructions but just cant get it to work. Prepare to enable user images I have a basis iis server built with images but cant get past that.
Hello , I need to create local admin accounts on large group of computers. Is there any solution how to grant access to FileVault for this admin account ? I will know id and password of this admin accounts , but for now access to FileVault have only end user account(standard one )Thanks for tips
Hello World! So from my research I am not sure this is a thing, but I am looking to spin up a test instance through Jamf Cloud for test and training purposes. I am not looking for a trial addition, and we are already using Jamf Pro. Let me know if this is something that's possible or if we are going to have to use our present environment, scope and enroll some devices for testing. Thanks so much!
Bear with me on this, but I am considering allowing 6 digit number passcode for macOS login. My threat assessment is similar to that of an iPhone, that has a 4 digit passcode protecting the device, which essentially has access to all the same company information the Mac is going to have. In both cases, the attack vector requires physical access to the device and then a considerable amount of number guessing, but not before locking the device out after 10 wrong guesses. Our devices will also have Password Sync installed, so users who wish to configure that certainly can, and then use their company password for login. Our Macs are all ABM -> MDM enrolled, purchased through official channels, we don't have Active Directory. We do use Okta for but as i mentioned and I have configured Password Sync with Okta and as mentioned users can configure Password Sync if they wish. Am i missing anything here, that should require Mac login passwords to be long and c
Has anyone successfully used the SecureW2 SCEP setup with Jamf on macOS AND iOS?I am having an issue with our iOS devices not connecting to the network. They get the profile payload that includes the cert, Wi-Fi profile, and SCEP settings (the same settings as on the macOS devices) and the iOS device starts to connect but never fully connects and just cycles through the connection process over and over. The macOS devices connect fine a few minutes after they get the cert.It gets the cert from SecureW2, so that part is working, but it just never actually connects to the network. I followed their, somewhat out-of-date, instructions found here:Deploy Client Certificates via SCEP to Jamf Managed Devices (securew2.com) Anyone else had issues with the setup for iOS devices?
I have multiple Adobe 2023 packages that are failing from Self-Service. I see the following in the log when reproducing the error:Mon Aug 28 09:29:58 MachineName jamf[2225]: Checking for policy ID 1424...Mon Aug 28 09:30:00 MachineName jamf[2225]: Executing Policy Acrobat Test Policy Faculty and StaffMon Aug 28 09:30:00 MachineName jamf[2278]: Mounted file serverMon Aug 28 09:30:00 MachineName jamf[2225]: Error Domain=com.jamf.management.daemon Code=14 "mounting a file share failed because of invalid command output" UserInfo {NSLocalizedDescription=mounting a file share failed because of invalid command output}Running the same policy on the same machine using the sudo jamf policy command will successfully install the software.Any suggestions? Thanks in advance!
I'm trying to push Sophos onto a machine through Jamf Self Service and when I click install it says done but the app doesn't install. I've packaged Sophos using Composer and use the same .pkg for a Sophos policy which is pushed out to all the devices and this pulls down and installs. Any idea what I could be missing?
I want to add 1000 device into a smart computer group in jamf but I don't know how to add device in smart group using API. Can you please help me to create a computer group using API in jamf pro.
Hello guys, I have a bunch of test macs which I use for testing so I'm constantly re-imaging them and enrolling them to Jamf. I want to know if there is a way that I can automate the removal of the Jamf record without having to in Jamf gui web interface and looking for the record for the mac and then deleting it.
Hi all,Is there any way to disable export option for some private keys and certificates in KeyChain?I tried to import the keys with -x option (Specify that private keys are non-extractable after being imported.) security import -x At the first right click to the key in KeyChain, it doesn't show the export option. However, at the second and later right click, it shows the option.
We are having a very strange excel and one drive problem. If you use the one drive icon and use the folder view files button, any excel file you click on opens in read only mode. If you open them in excel recent documents, they work fine.What we have done:We opened a Microsoft Case, and they examined the logs.Then they had us remove our security agents. Same problem.Then we removed management. And then it worked!On our second test machine machine, we left the agents in place, and removed management and it worked again. So we're all scratching our heads.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!