Get Support
Recently active
Hi allIs it possible to deactivate a profile on multiple iPads via Jamf? Maybe over the Group or mark all Devices in on of the group.Best regardsPeter
Hi There, Any help documentation on how to Deploy Windows Defender 365 via iMazing for JAMF NOW?
HiWe use Jamf Pro. I have lots of items displayed in the dashboard of my account. That seems to make the dashboard very slow. It usually takes more than five seconds to load and display everything. I would like to clear the dashboard and only add a few items to speed it up and make it easier to find relevant information.Is there a way to clear the dashboard without having to go through all the items one by one and uncheck the "Show in Jamf Pro Dashboard" checkbox?Thanks in advance!Manuel Brotz
Greetings, I am trying to support teachers using the classroom app on 2020 model MacBook airs with M1 chips running macOS 13.2 or macOS 13.2.0 Student computers are identical. Both groups are on the same wifi network. Both groups are not signed in with manage apple ids and join the classroom with a join code following the 1st pathway below. ####### There are three (3) ways to do Apple Classroom and they are all currently MUTUALLY EXCLUSIVE. 1. No Apple ID or personal Apple IDS - This is the scenario in which teachers can create the class and give students 4 digit code. No management in the scenario but very easy to implement and flexible for after school programs etc. There are also some MDM restrictions that can be set to make sure students can’t opt out in settings. 2. MDM managed - this means MDM must have all the roster data for all classes, teachers and students. MDM pushes what is called an EDU or Education Profile onto the device and it automa
I need to push updates to my macs and it seems like the Jamf Software Update tool (yes, I know it's unreliable) from the side bar seem to disappear.Can anyone here explain what might have happened?
Hi everyone,I use JAMF School to administrate the iPads from our school. Most of them don't belong to a specific user, but are borrowed by the students for only one lesson and then given back. That's why the devices "collect" lots of stuff like photos or documents.Is there a way to delete only this user saved data from the devices without losing apps, group affiliation etc. ? I have found "wipe device", which seems to do this (?), but it's not very feasible to do it manually for every single device.What I'd like to have is a command that deletes only the user stored data, preferably automatically like every monday or such - not only for one device, but for every device in a group. I don't want to have to re-enroll the devices or lose their profiles, device group etc. Thank you in advance!(Sorry for mistakes, I'm not a native speaker ;-) )
Hi,I have noticed that when an app is deployed through Self Service and an end-user installs an app, there is a spinning circular "loading" animation that is displayed while the app is downloading and installing. For small apps, this isn't an issue because the animation is replaced with a "done" status quite quickly.For larger apps, like iMovie, Visual Studio, or Premiere, this can be an issue, because the end-user may believe that the app is stuck as the circular loading animation keeps repeating over and over again. This may lead the end user to belive that the app is stuck and may cancel the process. If the animation can be changed to include a % or a loading bar, then the end-user will understand that the app isn't completely done getting installed and will know to be patient until the "done" status is displayed. Can you change the status to include a % or a loading bar when an app is getting installed from Self-Service?
Hi all. I have searched for this specific issue on here and got conflicting results, so I thought I'd post. Two things that we are trying to achieve: 1) Change the prestage enrollment local admin password - this one is pretty self explanatory and can easily be done, however will only take effect for newly enrolled computers. Which brings me to 2) Creating a policy that changes the local admin password. I thought I was successful in this and sort of was. Scoping the policy to a couple of test machines resulted in successful change to admin password when authenticating for things such as software installs and preference changes. The new password even works when changing users in terminal (su administrator). However, the password does not work for initial login to the machine. In fact, it breaks the old password as well, so we are left with a machine that the user "administrator" is unable to log in. I realize this was long winded, so thanks in advance.
Does anyone know the process on a Mac that is run when you use Kerberos authentication/configuration through JAMF.
Mac OS ventura:, Intel Mac mini, iMacs, and Mac Studios M1 - - so far I have 12 devices stuck in a boot loop. Had a few that started in June, and it's gradually increased. Some are at 13.3, some are at 13.5.Reset SMC, NVRAM, PRAM, first aid, can't get into safe mode. Held down option to ensure I was booting off the main disk - - Nothing is working. We've completely reset a few devices, seems to work for a few days then they go right back into a boot loop.Is it just my environment, or is this a thing from a recent update? If it is an update, is there a way to remove the offending files, or revert back without time machine? I can't even access terminal from the recovery assistant. No utilities option.
Below is our current configuration as we are trying to use our External CA to provide Computer and Mobile Device Enrollment. However when the certificate shows on the device, it shows as $COMPUTERNAME. I changed this to $DEVICENAME and get the same result. Additionally, when we remove the subject completely from the External CA configuration, it causes the enrollment to fail with the error "Your profile has expired".As shown we also have SCEP setup for our config profiles and the Subject config is working fine there. Any thoughts are greatly appreciated. This is on Ventura OS
We have a configuration profile that's deployed to our laptops that was modified not too long ago containing various payloads and is now being removed and replaced with individual profiles containing only one payload each. I removed everything from the scope of the original profile and deployed the newly created ones in its place. I have been monitoring the removal of the old profile via a smart group and noticed that everything still has it listed as being installed in inventory even though the removal command succeeded. I just took a look at one of the computers in question and decided to redeploy the original configuration profile to it and remove it to see it it would clear up. What I noticed was upon deployment, there were now 2 profiles with the same name, one with the latest settings it had and one with the old settings. I double checked in Jamf and there is in fact only 1 configuration profile with that name. I'm now stuck with 369 computers that have this orphaned pr
For Mac OS ventura it seems like the old PLIST to edit wifi settings is no longer a thing. I keep getting prompted to input an admin password when I want to remove wifi profiles as a standard user.
We have a group of students that travel to external school. We have a Smart User group that shows all these students. I have scooped this smart user group to a profile to create a wifi on their device to connect to the external school's WIFI.(turning off private MAC as well) I would like to send a list of the MAC addresses to the external school. I can't figure out how to easily get a list of the devices and the WIFI MAC of those devicesInfoJAMF Pro 10.49All devices are mobile devices iPads with latest iOS 16.5+Total devices 2500+Total users 3000+Users in Smart users group to be targeted 30Any ideas or information on how to tackle this would be appreciated.-TechTroy
We are having an issue with one drive and being able to open xlsx files from it directly. We made a Microsoft case and turns out, if you remove Jamf Management it works. We get the error: Excel cannot open the file ___.xlsx' because the file format or file extension is not valid. Verify that the file has not been corrupted... But if you copy it locally it works. Any ideas?
Hello,We are using Jamf Connect for account creation with Automatic Device Enrollment. Because of this, our user accounts are not managed users, per @rabbitt 's post https://community.jamf.com/t5/tech-thoughts/mdm-capable-mdm-enabled-or-mdm-managed-users-why-to-not-use-user/ba-p/276926 . We are trying to deploy user certificates but because they are not managed users, the certs go to the System Keychain. Exporting the cert and importing into Login Keychain is not an option for us. We know that we can re-enroll the devices to obtain MDM Enabled user accounts but it is inelegant. Are there other commonly used solutions out there of which we are unaware? How does your organization get around this problem? Thank you,Rafe Moody
According to the post below, (can be found at https://it-training.apple.com/tutorials/deployment/dm110 ) Setup Assistant should not let a user advance past the connection to a network screen. It should require a network connection to move on. This is not the case with our laptops. They are purchased through apple and enrolled in ABM. I verified serial numbers are in ABM. Any thought's on how to fix this? We have users not enrolling the latptop and they are never prompted to enroll the laptop later as the post says they should be. "Prior to macOS 13, users could use Setup Assistant without an internet connection, and accidentally — or intentionally — bypass enrollment in MDM. With macOS 13, users need an internet connection to complete Setup Assistant on organization-owned Mac computers with Apple silicon or an Apple T2 Security Chip. After a Mac with macOS 13 is set up and connected to a network for the first time, it’s acknowledged as owned by an organization (in
Has anyone been able to push LogMeIn zero touch using PPPC files?
As our staff are returning to school, we have had a few laptops come back with no profiles installed. Oddly the devices are still checking in and reporting inventory. They have these failed commands At this point the only good option appears to be to set up a new device. Running the command sudo profiles renew -type enrollmentdoes reinstall some of the profiles - but then the user must accept - and that is different than the install from a prestage. Not really sure why this is happening or if there is a better solution.
Is anyone else seeing strange spacing with the columns in Jamf policies now? When I go to scope a computer to a policy, each column is not very wide, making the display for one computer be on multiple lines. Am I missing something that would allow for sorting this or extending the column size?This is what my machine looks like in that view... the MAC address takes up three lines... the username (only 8 characters max at our site) takes up two lines... the Serial Number takes up two lines... the OS Build takes up two lines. For folks with longer full names, it can take up to 8 lines (highest I've seen but possibly more).We did not have this same display in 10.47 and we skipped 10.48. I can adjust the column sizes here, but they reset to this as soon as I open the screen in another policy.
Hello All,I have two patch management sources, one for Apple Silicon/Universal applications and one for Intel applications. When I attempt to populate them both, I receive a popup that the software title cannot be configured because the extension attribute already exists, rename the existing extension attribute to continue. The JAMF Pro documentation says the same thing, to rename the extension attribute. I cannot determine how to do this. When I go to extension attributes, the patch management attributes provided by Jamf are not accessible to change. Is it possible modify these or am I going in the wrong direction? I appreciate any guidance.
Hi guys We have 30 ipads at our school managed using JAMF.one user wants to be able to use voice to text but the microphone on the keyboard is greyed out.i have enabled dictation on the ipad side and also in the configuration profile in JAMF but the microphone is still greyed out.Do i need to also enable Siri in the configuration profile?Any help would be much appreciated.
Doing some testing as we are making a policy to remove computer records from jamf if they have not checked in after 160 days.I noticed if I delete a computer record from Jamf and run sudo jamf recon from that computer I get:Device Signature Error - A valid device signature is required to perform the action.The computer still has its MDM profiles and Jamf binary installed. Is this expected behavior? I believe in the past that Jamf would just create new computer record?
My organization is new to Jamf. We are looking to see if Jamf has published documentation for when they will be ready to release updates for iOS 17/ iPadOS 17.Most importantly, are there any changes we need to be aware of so it doesn't break anything in our organization.Secondly, we need to know when Jamf will roll out the changes so we can be prepared. We are already asking our user base to postpone updating so we encounter as few issues as possible on day one.Thanks!
Hello, I create simple launch deamon file to start sh script and all works fine , but I have problems to block this script from disabling in login items. Try few config profiles but every time it didn't work for my script , but works for other apps like Microsoft apps.I see that all signed application have attribute "Embedded Item Identifiers:". My application wasn't sign , it is a problem? If application isn't signed I can block it ?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!