Get Support
Recently active
Hi Everyone, I have set the Mac up to accept Yubikey account creation. It queries AD then creates an account if it finds the user's certificates from the Yubikey. However, when signing in, it repeatedly prompts for a keychain password saying "macOS wants to use the "login" keychain." Any ideas on how to stop this from popping up, or why it does? I would also prefer it asks for a PIN over password if that prompt is required to get full use of the mac. Also, other items keep prompting for the Keychain instead of the pin as well. Such as Spotlight, Transparent Network Proxy for Apple system services, security, and ScopedBookmarkAgent. But once I cancel those enough times, they do not prompt me again. But the macOS does. Any and all help is appreciated. Thank you.
Hi Nation, I hope you are all well.I am trying to set up Intune Integration for Compliance, however every article I seem to find is around Conditional Access which is legacy, I can not find anything that details guidance for Device Compliance and the Intune config. Does anyone have a good link ? ThanksBob - Reno
We have some computers where the screen will default to "Extend Display" rather than "Duplicate" for the built in screen. This works for returning accounts but not new ones and in our university setting we wipe the accounts at the end of each day so each account that gets made is seen as a new one and defaults back to "Extend Display". Anyone found any scripts or settings in or outside of Jamf that can solve this issue?
Hi All. I'm trying to change this value from NO to YES.This is located here: /Users/username/Library/Containers/com.microsoft.Outlook/Data/Library/Preferences/com.microsoft.Outlook.plistIt essentially ensures that MS Teams is auto-defaulted to the preferred Meeting type when creating a new Calendar invite. I'm not sure what command/script I need to use for this.
While doing some filevault key refreshing via script, i got a few (less than 10%) of these errors, and i cant seem to find any info on error 45 for filevault. DOes anyone have any kinf of info about this?"fdesetup exited with return code: 45."
Can anyone shed some light on what I need to do when it comes to the 'Certificate Download' and 'Upload Additional Certificate' options? I've went thorough all the docs I can find and the most helpful line is this:"save the certificate in the appropriate location dictated by your web server vendor." That just doesn't help me much. I have our images on an apache2 web server and they working correctly using SSL. They are accessible inside our network and out. When I attempt to add our wildcard certificate as the 'Additional Certificate', I get a message that it has not been uploaded. You can see the process in the pics. Does anyone had more detailed information on what to do with the certificate I get from the Download button and what certificate to upload as an Additional Certificate? When I use the test button and use a valid url to a user image, I get this:
Is it possible to allow an app to add proxy configurations with a configuration profile, similar to something like full disk access?We're not currently using Forcepoint Neo as a proxy, but this prompt appears during the installation of Forcepoint DLP. If it's not allowed here, the installation will not complete until it's allowed through System Settings/Preferences. I've added configurations for this app to allow network monitoring, disk access, system events, etc., so I assume it's possible here and I'm overlooking it.
Just wondering if any has instructions on how to configure an iis server as a distribution point for user images.I have tried to follow the generic instructions but just cant get it to work. Prepare to enable user images I have a basis iis server built with images but cant get past that.
Hello , I need to create local admin accounts on large group of computers. Is there any solution how to grant access to FileVault for this admin account ? I will know id and password of this admin accounts , but for now access to FileVault have only end user account(standard one )Thanks for tips
Hello World! So from my research I am not sure this is a thing, but I am looking to spin up a test instance through Jamf Cloud for test and training purposes. I am not looking for a trial addition, and we are already using Jamf Pro. Let me know if this is something that's possible or if we are going to have to use our present environment, scope and enroll some devices for testing. Thanks so much!
Bear with me on this, but I am considering allowing 6 digit number passcode for macOS login. My threat assessment is similar to that of an iPhone, that has a 4 digit passcode protecting the device, which essentially has access to all the same company information the Mac is going to have. In both cases, the attack vector requires physical access to the device and then a considerable amount of number guessing, but not before locking the device out after 10 wrong guesses. Our devices will also have Password Sync installed, so users who wish to configure that certainly can, and then use their company password for login. Our Macs are all ABM -> MDM enrolled, purchased through official channels, we don't have Active Directory. We do use Okta for but as i mentioned and I have configured Password Sync with Okta and as mentioned users can configure Password Sync if they wish. Am i missing anything here, that should require Mac login passwords to be long and c
Has anyone successfully used the SecureW2 SCEP setup with Jamf on macOS AND iOS?I am having an issue with our iOS devices not connecting to the network. They get the profile payload that includes the cert, Wi-Fi profile, and SCEP settings (the same settings as on the macOS devices) and the iOS device starts to connect but never fully connects and just cycles through the connection process over and over. The macOS devices connect fine a few minutes after they get the cert.It gets the cert from SecureW2, so that part is working, but it just never actually connects to the network. I followed their, somewhat out-of-date, instructions found here:Deploy Client Certificates via SCEP to Jamf Managed Devices (securew2.com) Anyone else had issues with the setup for iOS devices?
I have multiple Adobe 2023 packages that are failing from Self-Service. I see the following in the log when reproducing the error:Mon Aug 28 09:29:58 MachineName jamf[2225]: Checking for policy ID 1424...Mon Aug 28 09:30:00 MachineName jamf[2225]: Executing Policy Acrobat Test Policy Faculty and StaffMon Aug 28 09:30:00 MachineName jamf[2278]: Mounted file serverMon Aug 28 09:30:00 MachineName jamf[2225]: Error Domain=com.jamf.management.daemon Code=14 "mounting a file share failed because of invalid command output" UserInfo {NSLocalizedDescription=mounting a file share failed because of invalid command output}Running the same policy on the same machine using the sudo jamf policy command will successfully install the software.Any suggestions? Thanks in advance!
I'm trying to push Sophos onto a machine through Jamf Self Service and when I click install it says done but the app doesn't install. I've packaged Sophos using Composer and use the same .pkg for a Sophos policy which is pushed out to all the devices and this pulls down and installs. Any idea what I could be missing?
I want to add 1000 device into a smart computer group in jamf but I don't know how to add device in smart group using API. Can you please help me to create a computer group using API in jamf pro.
Hello guys, I have a bunch of test macs which I use for testing so I'm constantly re-imaging them and enrolling them to Jamf. I want to know if there is a way that I can automate the removal of the Jamf record without having to in Jamf gui web interface and looking for the record for the mac and then deleting it.
Hi all,Is there any way to disable export option for some private keys and certificates in KeyChain?I tried to import the keys with -x option (Specify that private keys are non-extractable after being imported.) security import -x At the first right click to the key in KeyChain, it doesn't show the export option. However, at the second and later right click, it shows the option.
We are having a very strange excel and one drive problem. If you use the one drive icon and use the folder view files button, any excel file you click on opens in read only mode. If you open them in excel recent documents, they work fine.What we have done:We opened a Microsoft Case, and they examined the logs.Then they had us remove our security agents. Same problem.Then we removed management. And then it worked!On our second test machine machine, we left the agents in place, and removed management and it worked again. So we're all scratching our heads.
So, I could go to the devices and use this: If an app would like to connect to devices on your local network - Apple SupportBut surely there is a configuration policy that I could implement instead? Basically these are restricted kids games station running on iPads and having them connect to other iPads in the building creates a potential behavior problem, bullying, etc.Would rather when they play Minecraft on these devices, they just have their own local world and nothing else.
I'm looking for a way to get the checkin history of all machines in the Org - about 500 machines, specifically I'm looking to get the history of IP addresses from which the machines checked in in the last 30 daysthe JSS does preserve the history, but only the last checkin details. /var/log/jamf.log of machines preserve it but on a scale to automate pulling the file and consolidating on a daily basis sounds complicated and prone to error. any other thought on getting this/preserving the history?
I have seen this topic a few times on the forums but never a resolution. We have an issue where when we erase an iPad the apps the previous student had installed reinstall themselves. These apps are just "Make available in Self Service". We have very few that install automatically. We have tried various methods,, changing Year of Graduation in User and Location or Department temporarily... It doesn't always happen and the fixes don'y always resolve it.Wondering if anyone has resolved this yet.
My company currently blocks Microsoft Auto Update via Restricted Software tab in JAMF Pro. I've been tasked with finding a way to create an exception so that Defender gets updated on all of our macs while MS auto update is still in place. Has anyone had any experience with this in the past?
Hello Jamf community, We have multiple PreStage Enrollment (1 for each lab + 1 for employee laptops). Other than each one being used as a criteria to place devices into Smart Computer Groups, there is no reason for these to exist as they all have the same settings anyway. So I am attempting to simplify this by deleting all existing PSE and creating a new one (and checking the box for Automatically assign new devices). We'll then use PO number as criteria for Smart Computer Groups or just manually assign each device to a Static Computer Group. My question is: what effect will it have on existing enrolled devices? If any of the existing devices need to be re-provisioned (e.g. a Macbook being assigned from a leaving staff to new staff), do we have to do anything special? Thanks for any advice on the matter.
We are using a policy with a script to make the currently signed in user an admin. We have tried both normal commands for making a user an admin but only certain test devices actually make the user an admin. We are in the process of wiping our devices multiple times a day to test the Pre-stage enrollment and this seems to be one of the few hang ups. For reference, this is the script we are using that works on some devices but not all:`#!/bin/bashcurrentUser=$(who | awk '/console/{print $1}')sudo dscl . -append /Groups/admin GroupMembership $currentUserexit 0`Sometimes it will work and make the account admin but then when we restart the device it will go back to being standard. No amount of re-running this script or a similar one will get it to work after the initial try if its successful either. Is there any chance there is some sort of cache or file somewhere that maybe tells the Mac that a user belongs to the Standard section that needs to be erased or appended to get rid of the
Hello, I am setting up configurations profiles that now I want to start adding in some scoping to using based on user logged in. I see when I go to exclusions it shows the options for LDAP Users, LDAP Groups. However if I go to select specific scope targets (not exclusion) for tabs I don't see LDAP Users or LDAP groups. Is this by design or is there something I can do get that to work? Thank You
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!