Get Support
Recently active
We have 2 users who need to use the terminal a lot for their day2day work. With Jamf installed (with firewall policy), opening a new terminal window takes a long time and this time increases. After a reboot it works ok for a while, but gets slower again. When we remove the MDM profile, it works as normal again. Anyone experience with that?
Hi all, been looking around the past few weeks on some information on getting Tableau and JAMF to play nice so I can make use of Tableau's nice visual reporting for our environment. Haven't really found anything substantial. I did find a JAMF Marketplace post (https://marketplace.jamf.com/details/jamf-tableau-integration/) but all the links seem broken, and it looks to be catered more towards On-Prem environments anyway. Wondering if anyone has had experience on using the two together? Thank you!
Hi, has anyone tried to set "export JAVA_HOME='/usr/libexec/java_home'" with a policy/script yet?Or write it into the profile? No success on my side until now :( The installation of the JDK 8u91 package is succeeding without issues.Maybe someone can help me :)
I've raised a ticket with JAMF on this, but some Jamf Nation...clarification... would be welcome. On a JAMF instance there is a configuration profile setup for FileVault escrow. The associated certificate in the configuration profile has expired. JAMF support say to delete the cert and it will auto generate a new one. Before this is actioned, does this sound correct?Surely the cert here is used to decrypt the PRK that exists in the jamf database. If you update the certificate will this not break it? What is the ongoing impact of deploying this config profile with the outdated cert? Ive seen something along these lines before and its ended up with a need to decrypt the Macs and redo FileVault.
Our Jamf server is no longer getting any inventory updates from our iPads and we can no longer push apps whch all started on 6/3/22. the Jamf Pro Server Logs shows this error - 2022-06-03 23:54:17,389 [ERROR] [lina-exec-8] [dmControllerProcessorImpl] - Could not create MDMResponseAction, returning 500Any idea what would cause this?
I want to push a policy or something out to our computers that when they start either Chrome or Firefox it will open two tabs by default. I found a plist command that will open our home page, but can't figure out where or how to have it open the 2nd tab. My plist is below... I got this to open our school home page via this plist. Is there a way to open two tabs when chrome is started? I tried below info but no luck, if anyone has accomplished this, please share what I might be missing or did wrong. <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict> <key>DefaultBrowserSettingEnabled</key> <false/> <key>HomepageIsNewTabPage</key> <false/> <key>HomepageLocation</key> <string>https://www.emknights.org</string><key>HomepageIsNewTabPage</key> <
Full disclosure - we're only just getting started with JAMF Pro, so apologies if I've missed something obvious.We want to manage a small fleet of iPads, configured to be in Shared Mode using guest account only (so no data is retained between sessions - important consideration for us).I want to add a webclip / URL to the key web application that these will be used for, and from what I read here (https://docs.jamf.com/10.24.1/jamf-pro/release-notes/Bug_Fixes_and_Enhancements.html) this should now be possible. However, I still get an error in the management console for the device stating "The payload type “com.apple.webClip.managed” is not permitted to be installed for the system in multi-user mode.". Wondering if I'm missing something obvious?Secondly, I have the device smart group supposed to be setting a wallpaper / lock screen on the device, but this doesn't appear to take. The group says the wallpaper command was 'Acknowledged', but it stays on the default. I DO have a setting a
Chrome is removing itself from the dock after receiving today's Chrome update via App Installers.
Hello I am new to scripting and i found this script online and i showed it to my boss he said "the script is good and it will work" he then asked me "how would that script look if it were to be in jamf extension" Here is the script i showed him i am assuming we are going to be using this script in jamf attributes extension but for it to be valid in jamf do i just need to add a results tag? how can this script be acceptable as a jamf extension?
I've been attempting to deploy the latest creative cloud software installs and encounter the following error when running the policy. Installing the PKG outside of Jamf works without issue.Checking for policies triggered by "Acrobat2023" for user "username"...Executing Policy Acrobat 2023Mounting Casper_File_ShareInstalling AcrobatPro2023_SDL_Install.pkg.zip...Installation failed. The installer reported: installer: Error - the package path specified was invalid: '/Library/Application Support/JAMF/Downloads/AcrobatPro2023_SDL_Install.pkg.unzip/AcrobatPro2023_SDL_Install.pkg'.Submitting log to https://mdm.domain.edu:8443/ Any suggestions?
I've seen a bunch of posts on how to set Adobe Acrobat as the default PDF handler on Mac OS, but it seems as new versions of the OS comes out many of these may have broken. We are currently running Monterey, is that any methods that work on this OS? Thanks in advance.
Does anyone have any guides within the past 3 years for getting the dev environment setup for jamf pro? Everything i find online is from 2016-18 and rather outdated. I want to test the LAPS but dont want to enable it in prod incase pulling the password doesnt work.
We have a Mac which installed the macOS 13.5.1 update in the afternoon at 14:48.This is confirmed by the user as the install.log (/var/log/install.log)In the afternoon at 14:36 a script was running which checks and reads the macOS version. The corresponding policy log says that he still had macOS 13.5 installed at this time (14:36).This is another confirmation that the user has made the macOS 13.5.1 update in the afternoon at 14:48.Now to the unclear:In the Jamf under "Hardware and Software history" it shows that he already installed the update in the morning at 09:54:From where did Jamf get this info?Has anyone else observed this?(We have not observed this phenomenon on any other device)
Hi, I have a few .apps that i need to deploy to users devices. I have created a script that copies the files from a temp location to users/applications however when the app is opened i get a warning saying the app is not trusted etc. My question is what is the easiest way to deploy the .apps and also prevent the warning message from appearing?TIA.
Details shows "Deferred enablement appears to be active for user"Disk Encryption is success.Kicked off 4 iMacs and they all show same Details.Any suggestions?
Hi All, Our Macs all reboot when a new MacOS patch comes out. We've had JAMF pro for over a year and I don't think this started till 10.14.1. Our users get a pop up saying 'Updates were installed and the system needs to reboot in 5 minutes'. Oddly enough my machine got the pop up and it didn't install the update. After talking with JAMF support when this happened on 10.14.2 we added restart options to NOT reboot if a user was logged in. That apparently did nothing. Any other suggestions?
How does one request a Safe Internet category change for a site?Example: ducksters.comCategories: Video Games, EducationI block video games, but this IS an educational website. Shouldn't the category just be education, or at least be prioritized as educational? Because I block video games this educational site got blocked. How can we manually change a sites category and/or request that a site be re-evaluated and the category possibly changed? As it is I created a custom allow rule for the site.
Hi All,We have got the requirement where we need to push same day update to all MS Office apps and macOS update. We have pushed MS office apps using a complete package with teams.Thanks
Hi All,I need to deploy MS Defender using Jamf pro to all managed macOS. I am following the instruction mentioned by Microsoft on Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro | Microsoft Learn. But I am not able to navigate to Settings > Endpoints > Onboarding. I don't see onboarding option. I do have Global Admin access in Azure. Do I need to get any other access to access the above mentioned path please? Thanks.
I'm trying to deploy some apps to a batch of macOS devices using Jamf Pro, but every time I initiate the deployment, I receive an error message with code 432. Has anyone else encountered this error before, specifically error code 432? Please give some guidance to solve my problem.
We recently upgraded our PaloAlto firewall and are having issues downloading files on Macs. Files start out fast and then suddenly decrease on the clock to "Days" instead of "Minutes". Our security team says that it has to do with TCP Window Scaling. They say that TCP Window Scaling, is off by default on a Windows system, but on by default on a Mac. Is there a way to disable TCP Window scaling on a Mac, via a terminal command that anyone knows of? Thank you all in advance!
We used to sync classes down to Jamf from Apple School Manager, but during the summer transitioned away from that and also transitioned from AD to Jamf Connect. About a 1/3 of our staff Macs still have the EDU profile on them which is preventing rosters from Apple School Manager from populating via the teacher's Managed Apple ID. On Jamf Pro, the user currently assigned to the Mac does not have any roster data associated with them nor are they in any classes. The EDU profile left behind on the machine shows as being assigned to the current local Mac account. The handful of Macs I checked do not appear to be running the command to remove the profile. Any ideas on how to resolve this?
So we know that JAMF recommends to enable HSTS on Jamf Pro on-prem instances. However, I find the article lacking in several aspects.If we start with what I'm most curious about - Why? For instance, these specific questions come to mind:* If HSTS isn't enabled, can the MDM connection be downgraded to HTTP when the device is already enrolled, and thus can the device be tricked into executing MDM commands on either a HTTP session or a HTTPS session with an invalid certificate? Is the user prompted in this case and can the user choose to continue?* Is the HSTS recommendation meant or administrative access only instead?* Is the HSTS recommendation there to prevent MITM attacks for initial enrollment only? Or a combination of that and administrative access? In essence, describe the risks if it isn't enabled in a JAMF pro specific scenario.* Are there any downsides or pitfalls when enabling HSTS? A far-fetched thing would be that it automatically also enables certificate pinning so that an u
I've got a device that shows not having checked in since 8/21 but the end user has been using it daily. She went to use her phone this morning and it said iPhone Unavailable, check back in 15 minutes. No love after 15. Remote commands are not getting to the device and she cannot use her pin to unlock it bc of said message. Hard shutdown and restart did not help. Any thoughts?DeclarativeManagementPending
Hello, we are looking at implementing SCEP Proxy with SecureW2, when you setup the external CA with the SCEP Proxy settings and upload the Change Signing and CA Certificates, does this affect the Jamf Pro built-in CA? We use the built-in Jamf Pro CA for enrollment and don't want to change that. Does this external CA cause you to have to re-enroll all your devices?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!