Get Support
Recently active
We are making the switch to a cloud DP - and chose Akamai. It took us a bit of effort to get it working, the info in the admin guide was a bit slim. I made some notes with the info that would have made it easier to get started. Hope it helps, if you are considering moving to Akamai. http://lisacherie.com/?p=227
Ever since our Jamfcloud instance was updated to 10.40.1 over the weekend I have seen this error in every Mac enrollment for a couple of our config profiles (Cisco AnyConnect and Crowdstrike Falcon): The same team ID may not appear in both AllowedTeamIdentifiers and AllowedSystemExtensions. We have made zero changes to the profiles in question, so I can only assume the reason we're seeing it now is because of a change in Jamf Pro that now reports this condition where before it would not. I looked it up and it appears that according to Apple's developer documentation, this is a true error. The question I have is how do we fix it? Which would be the better fix? Removing it from AllowedTeamIdentifiers or removing it from AllowedSystemExtensions?
Trying to get Defender deployed to our macs. Everything seems to work except for PPPC for Full Disk Access, so I can't get Defender to show its licensed.Followed the guide at MS and get the following error with Step 6 https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-jamfpro-policies?view=o365-worldwide#step-6-grant-full-disk-access-to-microsoft-defender-for-endpointIn the payload (UUID: 551B3172-1B04-4B74-85CA-87F7844CD9B6), the key 'CodeRequirement' has an invalid value.Bonus Question - Configuring background services - what is the proper preference domain to use?
Hello Jamf Nation!We're excited to announce the Jamf Pro 10.50.0 Beta.This version has many new enhancements to configuration profiles including Smart Card authentication for Platform SSO, new FileVault enhancements, and several new Restriction options. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once enrolled, you’ll see a link to the Jamf Nation Beta Forum. Note: There will be a short delay between enrollment and Beta Forum access; you will receive a notification in Jamf Nation to join. When you receive the invitation, click "Join this group Hub". Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program! 3
Hi,We are using Jamf Connect to allow users in our Azure AD instance to sign in with their network account to their mac devices.We also have other users residing in Google Workspace which we then invite as guests to our main Azure AD instance. Will these users be able to sign in to their devices using Jamf Connect (with microsoft prompt login), or do we have to set up a different configuration profile for Google Workspace login directly?Currently when I test this, I get the error that the microsoft account doesn't exist, however these accounts are used to sign in to apps registered in our Azure AD, so I thought it might be possible to do the same for Jamf Connect?
How can I get the list of apps installed with Brew? I could not pull this list with Jamf Pro via script. Because the brew list command should work in the corresponding profile. However, I guess Jamf Pro doesn't run it in the relevant profile. Is there a practical method? I used the following commands;brew list --caskbrew list
Hi Everyone, I have created a policy for erase-install with the following Files and Processes command: /Library/Management/erase-install.sh --force-curl --reinstall --update --current-user --overwrite --depnotifyThe policy ran successfully on my test machine but it did nothing. I checked the logs in Jamf Pro and it says "Result of command: /bin/sh:/Library/Management/erase-install.sh: No such file or directory" I can confirm the package is uploaded (erase-install 30.1.pkg). All the mac's in our fleet is Intel based. Also, I'm not sure if erase-install works with Intel Macs.I am quite new to Apple management and jamf pro, and I'm having trouble making sense of this error whatsoever. I appreciate your time and support. Thank you.
Hello, I was looking for where to open a ticket for this issue but did not find where to do that.Maybe some of you will have an idea about what I am doing wrong. We have Jamf Pro cloud version and I have never deployed a pkg and made it run on a user’s machine. The user is one of my bosses and he gave me a link to a DuoDeviceHealth pkg which I was able to download from Duo. I then set a cloud distribution point and uploaded the pkg. In Computer Management – Scripts I pasted the script he supplied.sudo mkdir -p "/Library/Application Support/Duo/Duo Device Health"sudo touch "/Library/Application Support/Duo/Duo Device Health/NoAutoLaunchAfterInstall"sudo /usr/sbin/installer -pkg /path/to/installer/DuoDeviceHealth-3.0.0.0.pkg -target / (This path location is where the PKG file was downloaded on my laptop)sudo rm "/Library/Application Support/Duo/Duo Device Health/NoAutoLaunchAfterInstall"I made a policy named DuoDeviceHealth and enabled it and the trigger is Recurring Check inIn Packages
I'm trying to create an EA to show when the device is added to domain, so then I can make a smart group based off of that. The script I'm trying to use is:#!/bin/bashdomainName=`echo show com.apple.opendirectoryd.ActiveDirectory |scutil | grep DomainNameFlat | awk '{print $3}'`echo "$domainName " When I run that in terminal, it gives me the result that I expect, but when I use that script as an EA, none of my devices are reporting in that field yet.
HowdyI work at a university and I’m trying to find a way to sign into a single user profile using credentials from AD. I can bind the computer fine and confirmed it works well. However, it creates a new profile for each user that signs in. Has anyone set up a method of being able to sign into a single profile with any credential seen in AD, or even better a selective list of users?
Hoping someone can help as this is getting really frustrating. I recently started in a district that is transitioning from Jamf Pro (Cloud) to Jamf School. I've been trying to build our mac app inventory for almost a month and it has been nothing but headaches. Any package I try to upload either from the distributor or taken from our Jamf Pro instance errors out with an XML parsing error. I reached out to Jamf who helped with one package, but then when it was happening on all others I was told yeah a lot of packages will have issues without those workarounds. I've tried also installing the app and then putting it into composer, to which it uploads but then won't install properly on clients. Uploading packages to me seems like should not be something that always requires workarounds so I'm seeing if anyone else has an easy solution that worked for them. Packages I've tried and all fail are, Microsoft Suite, or each product broken down
Trying to install Microsoft Apps with jamf school and receiving an error " License not found". Has anybody experienced this and knows how to resolve it?
This is a weirdly specific situation and I'm just trying to figure out if there's a way to do what I want via a more targeted shell script versus a master override. Also, sorry in advance...you'll probably hear from me a lot about weirdly specific situations because they seem to gravitate to me. Anyway...I work at a school using various types of audio and video software and their related plug-ins. We have a class in a lab of about 14 computers (so, at least not a lot of machines...) using Reaper and Max among others. With these two apps, they happen to be using a bundle of third-party plug-ins that all appear individually within the folder and thus, kick off Gatekeeper for every single file in that folder- right when Reaper or Max tries to scan them upon first launch. So basically, about 12 popups occur giving you the third-party app warning about Gatekeeper, which in a few occasions has also crashed or required me to force-quit Reaper (which is part of the problem). So that'
Hi All,We didn't have this issue deploying to Big Sur or earlier.Since installing Monterey and testing policys against it were are hit with "Jamf wants access to control finder" and "Terminal wants access to control finder". The existing PPPC seem to not work but are deployed. Nothing shows up in automation.We have 2 other issues as well and thats with Symantec Antivirus and Wacom, both of which worked prior.Can anyone point me in the right direction.Thanks
Greetings, Hoping that someone has seen this issue out there. I am having a weird issue with Jamf Connect where I cannot sync password unless I toggle Wifi On/Off. This happens very consistently and about 10 of us in a test lab are experiencing same exact behavior. has anyone seen this?
Hello,I wanted to share my experience with the "Mac apps" feature within our organization, which has proven to be quite efficient in deploying applications like Zoom and Slack. The functionality is impressive; however, I've noticed that many of these apps release updates every three days. As a result, our employees are becoming somewhat overwhelmed with the frequency of these updates.I'm reaching out for guidance on how best to manage this situation. I'm interested in controlling the deployment of app versions to mitigate the constant update notifications. Ideally, I'd like to transition to a bi-weekly update schedule to reduce the impact on our employees.Your assistance in addressing this matter would be greatly appreciated. I acknowledge that the "Mac apps" feature offers distinct advantages over the alternative of manually uploading PKG files and creating individual policies for each app. This method ensures compatibility with both Intel and Apple processors.Thank you for your suppo
Has anyone made this migration yet? we are looking to get some feedback and maybe how your migration went. any help would be appreciated.
Hi folks,we have to change the resolution for a lot (100+) AppleTVs in our schools. This is caused by issues with the projectors which do not work properly with the 4K signal.Is there a way to get this done without touching every device?
Hi All,Have anyone tried to install ChatGPT on MDM manage devices(I'm using JAMF pro )?When I tap on the installed app I get an error as below with two options VIew in store or OKUnable to Install "ChatGPT"you must purchase this app to install it. View in App Store OKI have pushed the app to selected devices it is available in the Self-service and shows as "Reinstall"This is urgent have to configure this before WednesdayHelp will be much appreciate Thanks
A Read-only Friday post by William Smith If the thought of standing up in front of an audience makes your skin crawl, trust me when I say every new presenter gets that feeling. Conference season for Mac Admins starts this year in late March and lasts through October. Locales range from Australia to Great Britain to Sweden to Canada to the United States. And despite the tragic wartime circumstances in Ukraine, the MacAdminsUA free online conference carried on for its second year in 2022. The fact this conference exists shows our Apple Admins community may be small and spread across the globe, but it’s tightly knit. A conference is where community comes together Yuri Vlasyuk, the organizer of MacAdminsUA, brought his story to the January 9 Mac Admins Podcast where he said (paraphrased): “In these conditions, I have a strong belief any community needs to talk more and maybe closer about topics they are working on, because there’s a lot of stress, a lot of depression, and community needs t
I am seeing an issue with Password expiration on macOS. Some of the details are the following:-DEP Enrolled M1 MacBook running Monterey with FV2 and PRK hidden from user while escrowed in Jamf. This is done with Security & Privacy payloads and some policy glue, but end result is FV2 on and users can cold-start the mac with l/p for local account.-First setup user is break glass account with unique random password per system stored in enterprise password manager.-End user gets two local accounts, one with admin and one standard. Usual login is to standard, while admin is more for satisfying prompts and occasional logins to install/update software tools. This has worked okay for a long time, but one thing is we don't expire the local account passwords. I started testing out the Passcode payload in a configuration profile to see what it is like. The first thing was lock/unlock, as it is our most likely scenario. This worked reasonably well and a new password set. There is no promp
After starting with my company in June, I went through our Jamf Pro server to look things over. I noticed several Macs that have either failed MDM commands such as profiles that attempted to install, or a long list of pending commands. They are still checking in with Jamf Pro. I need to create a list of these systems but I haven't figured out how to do that. I don't know what criteria to use to track them all down. Has anyone ever had to do this? If so, what was your solution?
I'm in the process of enrolling new mac minis and imacs for 3 different labs. The imac enrolled and the policies that create the local user account ran correctly. The mini's seem to be having a problem. The policy log shows that the policy completed. There are icons for the users on the screen. When I enter the password I just get the spinning wheel. When I look at the computer in jamf, it shows 0 local user accounts.
We are tearing our hair out with this problem. Some of our Macs (random, not always the same) are not checking in with the JSS on the 15 minute Check-in Frequency set under Computer Management. This means that when a policy is available it takes sometimes hours and even days for the policy to apply to all the Macs (currently around 40 as we're still in early stages of rollout). Our network admins say that all the ports are open to APNS. What are some of the reasons why some Macs might not be checking in? We have verified that they are turned on, plugged in (wired not wireless) and not sleeping.
I am working on new groups of Macs, and in order to get Apple Remote Desktop to work, I have to select the Smart group and the View the members, then I hit the Action Button, in there I send a remote command and tell them all to allow ARD access. However when I hit the Action button all I get is a twirling blue icon, and nothing happens.Makes no difference if I switch to a different browser, or a different computer on a different network. Any Suggestions as to what is broken? or something I can fix?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!