Get Support
Recently active
As our staff are returning to school, we have had a few laptops come back with no profiles installed. Oddly the devices are still checking in and reporting inventory. They have these failed commands At this point the only good option appears to be to set up a new device. Running the command sudo profiles renew -type enrollmentdoes reinstall some of the profiles - but then the user must accept - and that is different than the install from a prestage. Not really sure why this is happening or if there is a better solution.
Is anyone else seeing strange spacing with the columns in Jamf policies now? When I go to scope a computer to a policy, each column is not very wide, making the display for one computer be on multiple lines. Am I missing something that would allow for sorting this or extending the column size?This is what my machine looks like in that view... the MAC address takes up three lines... the username (only 8 characters max at our site) takes up two lines... the Serial Number takes up two lines... the OS Build takes up two lines. For folks with longer full names, it can take up to 8 lines (highest I've seen but possibly more).We did not have this same display in 10.47 and we skipped 10.48. I can adjust the column sizes here, but they reset to this as soon as I open the screen in another policy.
Hello All,I have two patch management sources, one for Apple Silicon/Universal applications and one for Intel applications. When I attempt to populate them both, I receive a popup that the software title cannot be configured because the extension attribute already exists, rename the existing extension attribute to continue. The JAMF Pro documentation says the same thing, to rename the extension attribute. I cannot determine how to do this. When I go to extension attributes, the patch management attributes provided by Jamf are not accessible to change. Is it possible modify these or am I going in the wrong direction? I appreciate any guidance.
Hi guys We have 30 ipads at our school managed using JAMF.one user wants to be able to use voice to text but the microphone on the keyboard is greyed out.i have enabled dictation on the ipad side and also in the configuration profile in JAMF but the microphone is still greyed out.Do i need to also enable Siri in the configuration profile?Any help would be much appreciated.
Doing some testing as we are making a policy to remove computer records from jamf if they have not checked in after 160 days.I noticed if I delete a computer record from Jamf and run sudo jamf recon from that computer I get:Device Signature Error - A valid device signature is required to perform the action.The computer still has its MDM profiles and Jamf binary installed. Is this expected behavior? I believe in the past that Jamf would just create new computer record?
My organization is new to Jamf. We are looking to see if Jamf has published documentation for when they will be ready to release updates for iOS 17/ iPadOS 17.Most importantly, are there any changes we need to be aware of so it doesn't break anything in our organization.Secondly, we need to know when Jamf will roll out the changes so we can be prepared. We are already asking our user base to postpone updating so we encounter as few issues as possible on day one.Thanks!
Hello, I create simple launch deamon file to start sh script and all works fine , but I have problems to block this script from disabling in login items. Try few config profiles but every time it didn't work for my script , but works for other apps like Microsoft apps.I see that all signed application have attribute "Embedded Item Identifiers:". My application wasn't sign , it is a problem? If application isn't signed I can block it ?
I've got a new M1 MBPro 13" running Big Sur 11.0.1. We use ESET Antivirus on our Macs, and I've built a config profile for Privacy and System Extensions. I'm using ESET 6.10, which is compatible with Big Sur, and the instructions provided by ESET for building the Config Profile in Big Sur, which contain the necessary Team Identifier, Code Requirements, etc.The profile is scoped only to ARM64 Macs. I can build the profile without issue. Once thats done, it should get deployed. Here is the weird part... Watching System Prefs/ Profile window on the MacBook, I can see the profile appear. It's verified and has all the expected settings and information.About 15 or 20 seconds later, it disappears.In Jamf, I'm also watching the logs for the Config profile, clicking refresh every so often. While I'm viewing the profile on the MacBook, the deployment status shows pending.After the profile disappears from the MacBook the status updates to "Failed�
Hello,I've recently provided a remote employee with a Macbook. There's an admin account only I know the password to, and a secondary account the employee uses. The Macbook has been set up with my Jamf Now account.It turns out we forgot to enable Screen Recording for Microsoft Teams, which is located under System Preferences -> Security and Privacy -> Screen Recording, and the remote employee is not able to change this setting themselves without the admin password.If I can not do this, is it possible for me to change the admin profile password temporarily for my employee to log in to it, change the preference, log out, and then remotely change the admin profile password again?What are my options? I do not want to provide the admin password to the employee.
Does anyone have a script to delete saved passwords in the Chrome browser to deploy through a Jamf Pro config profile or policy?
Hi, I am trying to enroll our AppleTVs to JAMF School.All our MacBooks and iPads will have a Google login page like attached image. Can anyone share the procedures to enroll AppleTV into JAMF School? I have a DEP which skip everything except terms and conditions. Created a smart group which detects tvOS which pushes a Wifi Profile.Thank you
I'm in the process of deploying several software applications to a lab with new mac minis. The policy with the application file .dmg is failing. Do I need to check the FUT or FEU options? I just started using jamf this summer so I apologize ...Thank you
Hi,We have deployed 802.1x successfully using EAP-TLS (device Certificate) without any issues. We've tried to replicate the same configuration on ethernet and have been unable to get the device to automatically authenticate using 802.1x. We've set the interface to "first ethernet" and "any ethernet" however this doesn't seem to make a difference. The only way we can get the device to connect is to go into the ethernet connection, select 802.1x and then click the connect button. We then need to select the device certificate and enter admin credentials to allow eapolclient access to system keychain. Does anybody know how we can do this automatically in Jamf Pro? TIA.
Is it possible to disable iMessage or FaceTime on an iOS or iPadOS device? My company is heavily regulated and since iMessage cannot be audited, we need to have this functionality disabled. In turn, is possible, we would like to disable the option to log into iCloud completely if possible. From what I've read and seen online, it is absolutely possible on MacOS but the mobile versions not so much... Ideally if we can retain SMS and just disable the iMessage that would be for best.
Hello everyone, Just a little background: I work in an AD environment that utilizes Xerox MFDs among several others types of printers. I've had success capturing the device with Casper Admin and deploying the printer either through Self Service or some other trigger. The question I have is that our Xerox MFDs by default print in color and historically we've had to go into localhost to set this default option to black and white. Has anyone had experience adding a script to the process so as to set the default option? Thanks!
One of our users have not use her MacBook in little over three months, and the computer has there for been marked as inactive in Jamf.The user has forgotten the password she gave the local administrator account that she created when she first set the machine up, and not the computer is stuck at the login screen, with no network access.I have tried booting into recovery and connecting it to our network, but it is still marked as inactive in Jamf.Is there any way I can get the computer to talk to Jamf again?And is there any way we can recover the users account and data?
Im not sure if this has been covered or not, but this is a handy little thing that I found a few weeks back. If you have a user who isnt very technologically savvy, you can open up the self service Web Clip on your computers browser and deploy apps to the mobile device for the user. The url schema is https://yourjamf.server.com:8443/mdss/?udid=UDIDofDevice The UDID of the device can be found on the hardware tab. Just copy and paste it into the url and you'll see the self service webclip interface for that device. Hit install and it'll send the push notification from Jamf to the device to install any apps or profiles that are in Self Service. Again, not sure if this was something that has been covered but a quick search didnt show anything. I find it really handy with our older users or users who dont really have the time to be troubleshooting issues.
Loom is only showing up to version 0.168.1 in the Patch Management definitions, however Loom on the machine that I use to create packages has updated to 0.169.3. Since 0.169.3 isn't an option in Patch Management I'm unable to associate a new package to update the rest of the machines. Can someone update the definitions that are available for Loom? Thanks In Advance
1
It's been a while so here is something that you may never need, or, you have something clever that you already use for this & I am too dumb to know about it, or, maybe, someone will find it useful.2 things actually:1) I have arrived I what I feel is the bare minimum "boilerplate" code for a shell script intended to do something with a Jamf API token so, that's 1st. It's as short as I can make it, it has error checking, it does not store a password in the script (it's interactive) & it has a function that can be called at any point to ensure the key is valid or invalid. Feel free to copy, it's been working well for me. 2) Remember that time you wanted to input new Network Segments & your fancy network guy gave you a single column of CIDR ranges? This converts them to integer ranges with bitwise arithmetic. #!/bin/bash # data datafile='/Users/Shared/building.subnet.data.csv' # jamf API jamfurl='https://some.company.com:8443' jamfapi="$jamfurl/api/v1" jamfchk="$
We are using Jamf Pro and are setup as shared devices using Setup and Reset. and microsoft authenticator.What is involved in switching over to user assigned still using reset for a device format and logging into a device with Azure creds?Is Jamf connect required for this?I am trying to achieve a shared device that users make their own for their shift and reset and wipe at the end, during their shift they can use outlook/teams/word/onedrive etc with app protection policies and conditional access.
Good eveningI have recently become the new ICT manager at our school. I replaced the push certificate with one with my Apple ID. And pushed a new profile on all iPads with Apple configurator. In Jamf, the iPads are paired with the students again. So far it went well. Now I can no longer manage almost all iPads in Jamf. What am I doing wrong?Greetings from ArubaJohan
I currently have about 40 iphone devices managed by JamfPRO and the users are complaining because they connect them to their windows PC, are asked if they trust the computer and still can not get into the internal storage. I have tried installing iTunes on the PC's to retrieve by that just gives the "This device is managed by another computer" error. Any advice on how to easily access the photos folder without having to upload to the cloud or email to themselves?
Does anyone know how to pull the version of the actual Adobe RemoteUpdateManager? the binary is installed under \\usr\\local\\bin apparently Adobe released a new version in July 2023 ... and the version shows as 3.1.0.3 I notice that our Creative Cloud Desktop installations are updating but the installed version of RUM doesn't seem to be updating ( currently at 2.6.0.9 ) the actual executable file is a Mach-0 universal executable. using the otool -P command, I can see that there is a plist embedded in that file but I do not know how to access if from a command to pull that info and return it from an extension attribute. For the Adobe gurus out there, would replacing the older RUM with the newer one be a recommended activity, or do I NEED to build\\Deploy an entirely new Creative Cloud Desktop application installer package ?? Thanks in advance for any assitance
For any who wants to keep Kelvin/Hue apps update to date, Creative force didn't seem to have a way of updating that the app without admin rights and the app updates a few times a month. So instead of always going updating the latest package into Jamf, here is a script to download/update the latest version. Can have it run once a week to check the versions or run when needed. For the "Hue" app just replace and "Kelvins" with it. #!/bin/bash# Download latest yaml file for latest version numbercurl -o /tmp/kelvinversion.yml https://download.creativeforce.io/released-files.3x/prod/hue/mac/latest-mac.yml# Now check yaml file version# Path to yaml fileyaml_file="/tmp/kelvinversion.yml"# Get yaml versionversion_yaml=$(awk '/^version:/ {print $2}' "$yaml_file")# If the output of the command is empty, then the version key is not present in the YAML fileif [ -z "$version_yaml" ]; thenecho "Version information not found in the YAML file"else# If the output of the command is not empty, print
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!