Get Support
Recently active
So, I could go to the devices and use this: If an app would like to connect to devices on your local network - Apple SupportBut surely there is a configuration policy that I could implement instead? Basically these are restricted kids games station running on iPads and having them connect to other iPads in the building creates a potential behavior problem, bullying, etc.Would rather when they play Minecraft on these devices, they just have their own local world and nothing else.
I'm looking for a way to get the checkin history of all machines in the Org - about 500 machines, specifically I'm looking to get the history of IP addresses from which the machines checked in in the last 30 daysthe JSS does preserve the history, but only the last checkin details. /var/log/jamf.log of machines preserve it but on a scale to automate pulling the file and consolidating on a daily basis sounds complicated and prone to error. any other thought on getting this/preserving the history?
I have seen this topic a few times on the forums but never a resolution. We have an issue where when we erase an iPad the apps the previous student had installed reinstall themselves. These apps are just "Make available in Self Service". We have very few that install automatically. We have tried various methods,, changing Year of Graduation in User and Location or Department temporarily... It doesn't always happen and the fixes don'y always resolve it.Wondering if anyone has resolved this yet.
My company currently blocks Microsoft Auto Update via Restricted Software tab in JAMF Pro. I've been tasked with finding a way to create an exception so that Defender gets updated on all of our macs while MS auto update is still in place. Has anyone had any experience with this in the past?
Hello Jamf community, We have multiple PreStage Enrollment (1 for each lab + 1 for employee laptops). Other than each one being used as a criteria to place devices into Smart Computer Groups, there is no reason for these to exist as they all have the same settings anyway. So I am attempting to simplify this by deleting all existing PSE and creating a new one (and checking the box for Automatically assign new devices). We'll then use PO number as criteria for Smart Computer Groups or just manually assign each device to a Static Computer Group. My question is: what effect will it have on existing enrolled devices? If any of the existing devices need to be re-provisioned (e.g. a Macbook being assigned from a leaving staff to new staff), do we have to do anything special? Thanks for any advice on the matter.
We are using a policy with a script to make the currently signed in user an admin. We have tried both normal commands for making a user an admin but only certain test devices actually make the user an admin. We are in the process of wiping our devices multiple times a day to test the Pre-stage enrollment and this seems to be one of the few hang ups. For reference, this is the script we are using that works on some devices but not all:`#!/bin/bashcurrentUser=$(who | awk '/console/{print $1}')sudo dscl . -append /Groups/admin GroupMembership $currentUserexit 0`Sometimes it will work and make the account admin but then when we restart the device it will go back to being standard. No amount of re-running this script or a similar one will get it to work after the initial try if its successful either. Is there any chance there is some sort of cache or file somewhere that maybe tells the Mac that a user belongs to the Standard section that needs to be erased or appended to get rid of the
Hello, I am setting up configurations profiles that now I want to start adding in some scoping to using based on user logged in. I see when I go to exclusions it shows the options for LDAP Users, LDAP Groups. However if I go to select specific scope targets (not exclusion) for tabs I don't see LDAP Users or LDAP groups. Is this by design or is there something I can do get that to work? Thank You
Is anyone else having issues with WebClips loading on iOS 16.6?I can get the WebClips to show on the iOS device but it will not load the site I have it set for. I put the same web clip on an iOS 16.1 and the link loads with no issues. Any help would be helpful.
I'm getting these characters n""n""n""n""n""n""n""n"" in notification emails. The email body is / n""n""n""n""n""n""n""n"" The following computers were removed from the group "All Managed Clients"Anybody know how I can resolve this issue? I'm not even sure what is suppose to be there. Anyone have an example of a properly formatted notification?Thanks
Hello everyoneNeed assistance with users idle time.When I run the following script on my workstation ( Apple M1 Backbook Pro ) I get what I need but when I run on a M2 Mac mini, it does not work.After moving the mouse or pressing a key, the counter just keep increasing. It looks like the IOHIDSystem is using the computer logged in time. I am wondering is there a new way to check for user idle time, command or in Jamf Pro itself.See the out below. #!/bin/zsh # Pause/Interval between checks checkInt=1 # Timer in sec timerLength=15 # Keep track of the idle timer lastIdle=0 # Get the current user current_user=$(who | awk '/console/{print $1}') # Get the computer name computer_name=$(hostname | sed 's/.local//') # Message to system.log log_message="User $current_user Test" # Function while true ; do ioresp=`ioreg -w 0 -c IOHIDSystem | sed -e '/HIDIdleTime/ !{ d' -e 't' -e '}' -e 's/.* = //g' -e 'q'` idleNow=`echo $(( ${ioresp} / 1000000000 ))` #
I’m wondering if there’s a way to enable lost mode on a group of iPads in JAMF School. Using the admin interface you have to click on each iPad one at a time and then enable lost mode. We have a number of iPads left over from last school year that need to be retired this year and I want to disable them with a message to return them to our Helpdesk staff. I figure the best way to do this would be to enable Lost Mode. Is there a bulk way to do this? Maybe with an API? I couldn't find anything about this with a casual search.Or is there any workflows that would make this more efficient?
Has anyone rolled out the new device compliance within Jamf? we have the old legacy conditional access for our Macs, but I'm wondering if we can incorporate the device compliance for the ipads first and THEN migrate the macs?
Hi,Am I the only one who thinks the latest Jamf Pro cloud UI changes are bad??The links were changed to a blue colour and the other colours look faded.Makes things look they were done by a rookie website designer.It is even worse using the iPad.I use it alot on the ipad while I am out in the field and it is almost unusable.I use it in portrait mode and I cannot see the left hand column of info UNLESS I collapse the menu.Someone needs to explain how this is an improvement!!!Please contact me for further details.
We sent a mass OS update command to install some rapid security response updates. We gave a deferment period of 7 days. This worked for the vast majority of our machines. There are a few however, that a month later are still showing the prompt widow daily. The window states 1 deferral left every day and when you click on it, no updates are available (they've already been applied).These machines are all on 13.5 and all are Apple silicon (likely a false flag). I sent a mass cancellation of commands and they are still persisting. Has anyone else had this happen?
Hello. Is there a way to enable the automatic backup in OneNote app for MacOS and set the interval using plist?
Hi all,We are trying to upload .csv files into Apple School Manager, and we keep getting this error:[OK] unzipped file: classes.csv.[OK] unzipped file: courses.csv.[OK] unzipped file: locations.csv.[OK] unzipped file: rosters.csv.[OK] unzipped file: staff.csv.[OK] unzipped file: students.csv.[ERROR] rosters.csv: CSV file is missing some headers, or the headers are not correctly formatted.Does anyone have an example of what a correct rosters.CSV file should look like so I can compare with mine? My headers are in all caps ... would this make a difference?Thanks for your help.
Hello,We've recently noticed that user-initiated computer enrollment is now using a Quick Add package when previously users who initiated enrollment would have to download a CA certificate and MDM profile. This has been causing issues as the Quick Add package has not installed any of our Profiles and while those computers appear in Jamf, we are not able to push any management commands. This has happened with DEP enrolled machines too.Our team hasn't made any changes to the enrollment as far as I know.Any assistance would be greatly appreciated. Thank you.
We have used Jamf now for about 6 years and think it has been stable and good (earlier on-prem, now Jamf Cloud). We currently have around 1,000 Mac computers and 3,000 mobile devices. We are in the middle of changing platforms, we are leaving Novell in favor of AD with Office 365.Those who are changing platforms, networks, etc. are thinking about whether they should have Mac, iOS devices, Android and PC under the same management tool. In this case it would be about Intune. Of course, this is not a good option for us in the Apple world, not something we would look forward to in any way. Jamf works well for us and we are satisfied.I would need some help with what is best to lift to convince my other colleagues to keep Jamf and not move everything to Intune. Which points/functions are important to highlight in order to convince the colleagues?In the long term, we had also intended to implement Jamf Connect or something similar to authenticate against Azure. How does it actually work? Can
Hello everyone,some of our users use a software called openLCA. As we had some issues with new versions in the past we distribute updates the way the last version stays. So in general they have two versions of this App on their systems.But my EA only finds (and reports) the wirst version. Can someone tell what is wrong with my code?Thanks. #!/bin/sh ########################################################################## # A script to collect the Bundle Version of openLCA. # ########################################################################## PATH_EXPR="/Applications/*/Contents/MacOS/eclipse" BUNDLE_ID="openLCA" KEY="CFBundleShortVersionString" RESULTS=() IFS=$'\\n' for BINARY in ${PATH_EXPR}; do PLIST="$(/usr/bin/dirname "${BINARY}")/../Info.plist" if [ "$(/usr/bin/defaults read "${PLIST}" CFBundleName 2>/dev/null)" == "${BUNDLE_ID}" ]; then RESULTS+=($(/usr/bin/defaults read "${PLIST}" "${KEY}" 2>/dev/null)) fi done unset IFS if [
https://support.google.com/chrome/a/answer/9301891I've tried the "CloudManagementEnrollmentToken" file placed in the directory through JAMF as described above with no luck. Reinstalled chrome, signed existing users out and back in, but nothing seems to trigger enrollment or show as enrolled within google admin's "managed browsers" The token itself is a simple text string and nothing more. Example value:"37185d02-e055-11e7-80c1-9a214cf093ae" Below is the limited instruction on setting up this feature of chrome/g-suite **Option 1: Use a policyPush the token to your browser as a policy named CloudManagementEnrollmentToken. Setting policies on Mac devices requires the Apple Profile Manager. Option 2: Use a text filePush the token in a text file called CloudManagementEnrollmentToken, under /Library/Google/Chrome/. This file must only contain the token and be encoded as a .txt file, but should not have the .txt filename extension.** Just curious if anyone has had success remotely pushi
Hi Team,I am trying to create a Jamf Pro Classic API Connection in OKTA Workflows. I created a service account in JAMF Pro granted Administrator, Standard user and Full privileges. When I try to test the connection. I am getting HTTP 401 Authorized Error. I am not finding settings to grant access to "Make sure that your Jamf Pro Classic API account has access to the /JSSResource/activation code endpoint"Appreciate any help or pointer!Thanks,Kalai
Hi. This is kind of a weird one. We want to create a configuration profile that forces VPN to always stayed toggled on, so that any internet activity is monitored. Obviously we would want this setting to be locked/grayed out. Is this possible to do for iPads/iPhones?Note: We already have a separate configuration profile in place that has the actual VPN connection configured. We just want to make sure that the general VPN setting within the mobile device is locked to ON at all times.Thanks.
Best way to setup auto-restart on a nightly or certain day basis. I want to do it without installing a package to force the restart
Very much a newbie here and not good at writing my own code (I'm very much a copy paste guy when it comes to creating plists etc) - I find that there is no easy way in the JAMF Pro UI to reboot machines in a static group - can anyone give me an easy guide for a policy or config profile that just performs a simple reboot on a machine that I can apply to a static group?
Hi All, I'm wondering if anyone else here force installs chrome apps and how you do it?Right now, I am trying to use the com.google.chrome.plist in /Library/Preferences.That method works great for all other chrome settings that I want (for example I have developer tools turned off, populated the blacklist for extensions, etc), and it's easy to deploy and update with jamf. BUT I cant get it to actually force install any extensions.chrome://policy lists everything right and even says the status for that policy is "OK"any ideas? or a better method? thanks!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!