Get Support
Recently active
Hello, I was looking for where to open a ticket for this issue but did not find where to do that.Maybe some of you will have an idea about what I am doing wrong. We have Jamf Pro cloud version and I have never deployed a pkg and made it run on a user’s machine. The user is one of my bosses and he gave me a link to a DuoDeviceHealth pkg which I was able to download from Duo. I then set a cloud distribution point and uploaded the pkg. In Computer Management – Scripts I pasted the script he supplied.sudo mkdir -p "/Library/Application Support/Duo/Duo Device Health"sudo touch "/Library/Application Support/Duo/Duo Device Health/NoAutoLaunchAfterInstall"sudo /usr/sbin/installer -pkg /path/to/installer/DuoDeviceHealth-3.0.0.0.pkg -target / (This path location is where the PKG file was downloaded on my laptop)sudo rm "/Library/Application Support/Duo/Duo Device Health/NoAutoLaunchAfterInstall"I made a policy named DuoDeviceHealth and enabled it and the trigger is Recurring Check inIn Packages
I'm trying to create an EA to show when the device is added to domain, so then I can make a smart group based off of that. The script I'm trying to use is:#!/bin/bashdomainName=`echo show com.apple.opendirectoryd.ActiveDirectory |scutil | grep DomainNameFlat | awk '{print $3}'`echo "$domainName " When I run that in terminal, it gives me the result that I expect, but when I use that script as an EA, none of my devices are reporting in that field yet.
HowdyI work at a university and I’m trying to find a way to sign into a single user profile using credentials from AD. I can bind the computer fine and confirmed it works well. However, it creates a new profile for each user that signs in. Has anyone set up a method of being able to sign into a single profile with any credential seen in AD, or even better a selective list of users?
Hoping someone can help as this is getting really frustrating. I recently started in a district that is transitioning from Jamf Pro (Cloud) to Jamf School. I've been trying to build our mac app inventory for almost a month and it has been nothing but headaches. Any package I try to upload either from the distributor or taken from our Jamf Pro instance errors out with an XML parsing error. I reached out to Jamf who helped with one package, but then when it was happening on all others I was told yeah a lot of packages will have issues without those workarounds. I've tried also installing the app and then putting it into composer, to which it uploads but then won't install properly on clients. Uploading packages to me seems like should not be something that always requires workarounds so I'm seeing if anyone else has an easy solution that worked for them. Packages I've tried and all fail are, Microsoft Suite, or each product broken down
Trying to install Microsoft Apps with jamf school and receiving an error " License not found". Has anybody experienced this and knows how to resolve it?
This is a weirdly specific situation and I'm just trying to figure out if there's a way to do what I want via a more targeted shell script versus a master override. Also, sorry in advance...you'll probably hear from me a lot about weirdly specific situations because they seem to gravitate to me. Anyway...I work at a school using various types of audio and video software and their related plug-ins. We have a class in a lab of about 14 computers (so, at least not a lot of machines...) using Reaper and Max among others. With these two apps, they happen to be using a bundle of third-party plug-ins that all appear individually within the folder and thus, kick off Gatekeeper for every single file in that folder- right when Reaper or Max tries to scan them upon first launch. So basically, about 12 popups occur giving you the third-party app warning about Gatekeeper, which in a few occasions has also crashed or required me to force-quit Reaper (which is part of the problem). So that'
Hi All,We didn't have this issue deploying to Big Sur or earlier.Since installing Monterey and testing policys against it were are hit with "Jamf wants access to control finder" and "Terminal wants access to control finder". The existing PPPC seem to not work but are deployed. Nothing shows up in automation.We have 2 other issues as well and thats with Symantec Antivirus and Wacom, both of which worked prior.Can anyone point me in the right direction.Thanks
Greetings, Hoping that someone has seen this issue out there. I am having a weird issue with Jamf Connect where I cannot sync password unless I toggle Wifi On/Off. This happens very consistently and about 10 of us in a test lab are experiencing same exact behavior. has anyone seen this?
Hello,I wanted to share my experience with the "Mac apps" feature within our organization, which has proven to be quite efficient in deploying applications like Zoom and Slack. The functionality is impressive; however, I've noticed that many of these apps release updates every three days. As a result, our employees are becoming somewhat overwhelmed with the frequency of these updates.I'm reaching out for guidance on how best to manage this situation. I'm interested in controlling the deployment of app versions to mitigate the constant update notifications. Ideally, I'd like to transition to a bi-weekly update schedule to reduce the impact on our employees.Your assistance in addressing this matter would be greatly appreciated. I acknowledge that the "Mac apps" feature offers distinct advantages over the alternative of manually uploading PKG files and creating individual policies for each app. This method ensures compatibility with both Intel and Apple processors.Thank you for your suppo
Has anyone made this migration yet? we are looking to get some feedback and maybe how your migration went. any help would be appreciated.
Hi folks,we have to change the resolution for a lot (100+) AppleTVs in our schools. This is caused by issues with the projectors which do not work properly with the 4K signal.Is there a way to get this done without touching every device?
Hi All,Have anyone tried to install ChatGPT on MDM manage devices(I'm using JAMF pro )?When I tap on the installed app I get an error as below with two options VIew in store or OKUnable to Install "ChatGPT"you must purchase this app to install it. View in App Store OKI have pushed the app to selected devices it is available in the Self-service and shows as "Reinstall"This is urgent have to configure this before WednesdayHelp will be much appreciate Thanks
A Read-only Friday post by William Smith If the thought of standing up in front of an audience makes your skin crawl, trust me when I say every new presenter gets that feeling. Conference season for Mac Admins starts this year in late March and lasts through October. Locales range from Australia to Great Britain to Sweden to Canada to the United States. And despite the tragic wartime circumstances in Ukraine, the MacAdminsUA free online conference carried on for its second year in 2022. The fact this conference exists shows our Apple Admins community may be small and spread across the globe, but it’s tightly knit. A conference is where community comes together Yuri Vlasyuk, the organizer of MacAdminsUA, brought his story to the January 9 Mac Admins Podcast where he said (paraphrased): “In these conditions, I have a strong belief any community needs to talk more and maybe closer about topics they are working on, because there’s a lot of stress, a lot of depression, and community needs t
I am seeing an issue with Password expiration on macOS. Some of the details are the following:-DEP Enrolled M1 MacBook running Monterey with FV2 and PRK hidden from user while escrowed in Jamf. This is done with Security & Privacy payloads and some policy glue, but end result is FV2 on and users can cold-start the mac with l/p for local account.-First setup user is break glass account with unique random password per system stored in enterprise password manager.-End user gets two local accounts, one with admin and one standard. Usual login is to standard, while admin is more for satisfying prompts and occasional logins to install/update software tools. This has worked okay for a long time, but one thing is we don't expire the local account passwords. I started testing out the Passcode payload in a configuration profile to see what it is like. The first thing was lock/unlock, as it is our most likely scenario. This worked reasonably well and a new password set. There is no promp
After starting with my company in June, I went through our Jamf Pro server to look things over. I noticed several Macs that have either failed MDM commands such as profiles that attempted to install, or a long list of pending commands. They are still checking in with Jamf Pro. I need to create a list of these systems but I haven't figured out how to do that. I don't know what criteria to use to track them all down. Has anyone ever had to do this? If so, what was your solution?
I'm in the process of enrolling new mac minis and imacs for 3 different labs. The imac enrolled and the policies that create the local user account ran correctly. The mini's seem to be having a problem. The policy log shows that the policy completed. There are icons for the users on the screen. When I enter the password I just get the spinning wheel. When I look at the computer in jamf, it shows 0 local user accounts.
We are tearing our hair out with this problem. Some of our Macs (random, not always the same) are not checking in with the JSS on the 15 minute Check-in Frequency set under Computer Management. This means that when a policy is available it takes sometimes hours and even days for the policy to apply to all the Macs (currently around 40 as we're still in early stages of rollout). Our network admins say that all the ports are open to APNS. What are some of the reasons why some Macs might not be checking in? We have verified that they are turned on, plugged in (wired not wireless) and not sleeping.
I am working on new groups of Macs, and in order to get Apple Remote Desktop to work, I have to select the Smart group and the View the members, then I hit the Action Button, in there I send a remote command and tell them all to allow ARD access. However when I hit the Action button all I get is a twirling blue icon, and nothing happens.Makes no difference if I switch to a different browser, or a different computer on a different network. Any Suggestions as to what is broken? or something I can fix?
Hi, I am trying to update 60 MacBook Air. I pushed JAMF School to update 13.5 from 13.3 skipping 13.4.1 etc.It keeps failing. I tried updating to 13.4.1 and it stops at 10/15%.I tried restarting and redo but still failed. Any advise pls.🙏
On our student iPads we are having messages pop-up in IOS Safari saying "You cannot browse this page at 'fill in the blank' because it is restricted." So far they have been blocked by a Google form and a link inside Google doc to a BuzzFeed article. Works fine on another devices that students use. I have a "fake student" account and iPad for testing that shows the same behavior. I removed the config profile on my testing iPad with all the restrictions.No difference. I switched to a wifi hotspot with no filtering to see if there might have a filter in between, no difference. So, what or who is causing the restriction? Any thoughts?
Local Admin Password Solution (LAPS) addresses security vulnerabilities of common admin workflows by supporting a unique and randomized local account password per device, that rotates after viewing, and that is accessible to a subset of authorized users. This security feature ensures an organization can maintain control over end user privacy and sensitive data. LAPS is an automated approach that allows IT administrators to maintain security, comply with regulations, improve efficiency, and maintain accountability by knowing who accessed the password and when. With Jamf Pro 10.46.0, Jamf introduced LAPS support as an API-first solution for better securing shared IT admin accounts on computers. This implementation was specific to the admin account created during Automated Device Enrollment using a PreStage enrollment. Jamf Pro 10.49.0, as part of User-Initiated Enrollment settings, Jamf expands LAPS support specifically for the Jamf Management Account specified. This soluti
Hi Team,Hope everyone had a great weekend.Question: I just purchased a new M2 Mac for my organization and I was able to enroll it into JAMF pro and all of the policies came down as it should. My issue is, I'm getting this error (See screenshot below) when trying to connect it to VPN.We had this issue in the past where we needed to remove the old computer name of an older machine in intune in order to get it processed as well as create a second local admin profile to connect it.So far, this is the only Mac with this issue and it happens to be an M2 machine.I was wondering if anyone has seen this or resolved it?Just to add, when we click "copy to clipboard", it takes me to the JAMF console and nothing happens. Thanks.
I'm trying to apply the same wallpaper image to multiple monitorsI set up the CP / Restriction / Functionality / Lock desktop picture to /Users/Shared/Wallpaper/Wallpaper.jpg It sets the wallpaper on the primary monitor but does not set on the secondary one.I've tried with a script also to test #!/bin/zsh wallpaper_path=/Users/Share/Wallpaper/Wallpaper.jpg osascript -e "tell application \\"Finder\\" to set desktop picture to POSIX file \\"$wallpaper_path\\"" Am I missing something or is this an Apple "feature"?
Here is what I'm trying to do. When we do 3rd party patching, we have to do them in phases, alpha, beta and uat. We currently have 10 applications that we update monthly. For each application smart group, we have to add the group manually to each one. For example, this is what it would look like. On day one we add Alpha group and the next we add Beta group. I've messing with different scripts, but keep getting 404 error. It would be nice to run a script that would add the groups instead of going in to each one. Not sure if this even possible.Here is what our update groups look like.This is one of the scripts I was trying.#!/bin/sh# API login infoapiuser="xxx"apipass="xxx"jamfProURL="xxx"# Smart group IDSmartGroupID="120"SmartGroupAPIURL="JSSResource/computergroups/id/${SmartGroupID}"# XML header stuffxmlHeader="<?xml version=\\"1.0\\" encoding=\\"UTF-8\\" standalone=\\"no\\"?>"# Get the current smart group criteriacurrentCriteria=$(curl -sSkiu ${apiuser}:${apipass} "${jamfProURL}
Happy Friday All, So, I am testing a Smart Card configuration profile to Enforce Smart Card use; more specifically, I am currently testing the Use Case scenario of, what happens if someone loses their Smart Card. So I attempt to remove the profile so that they could use their username and password to log in however, the removal of the profile is not occurring, it is stuck in pending. Any tips or tricks that could help me solve this? Our environment consists of:On-Prem Jamf ServerRequired VPN / Hardwired connection to the network to communicate with Jamf ServerForced FileVault EncryptionFrom my test computer, which is locked out, I am hardwired and can ping the Jamf Server from recovery mode. I am wondering if because FileVault is enabled it cannot remove the profile because the disk is in an encrypted state. Not sure though. Any advice is appreciated. Thanks
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!