Get Support
Recently active
Hi All,We've managed to setup Okta LDAP as an LDAP server for Jamf PRO and it shows correct in tests.We've been wanted to setup an Extension Attribute for computers based on the LDAP group membership of the relevant user.But no matter what we do (we use the memberOf or uniqueMember attribute) it won't show up with any value.We also have JAMF Connect if that's relevant but I haven't been able to populate the UserGroups field in the state plist no matter what I do either. At the end of the day we are trying to limit policies based on LDAP groups - and while we manage to setup the rule, no Computer/User is assigned to the group. Any and all help would be greatly appreciated. Also let me know if you need any more info.
I wanted to reach out to this forum to see what you all are planning to do when Jamf Remote goes away. As a large K-12 enterprise, our campus tech's rely on Jamf Remote's ability to push commands to devices WAY more than they do the ability to screen share. Our users aren't administrators on our machines, and we don't use localadmin accounts, so SSH-ing into a machine is also not in the cards. We're going to be in quite the pickle.I'd like to know how others plan to address this, and if there is anything out there than can leverage JAMF remote's abilities that perhaps we don't know about.
Hello,I am a new Jamf admin and running into an issue hoping the community can lead me on the right direction.Objective: Accounts that have a security group SG-Developer will need to be admin and everyone one standard.Current Configuration.Prestage EnrollmentLocal account User- SkipJamf connectConfigured to authenticate with Google IDP with MFAScript is configured with the following. <key>CreateAdminUser</key> <true/><key>OIDCAdminAttribute</key> <string>SG-Developer</string>Issue:So, everything works except the admin part after a restart.The account will be created as admin but when restarted its set back to standard even though the user is part of that security group SG-developer. Any assistance would really appreciate it. Thanks, you!
There are a bunch of privileges settings under server actions in group privileges that I can not find any documentation on exactly what they do. Does any one know or can you point to me to where this is documented?The privileges are:Send Local Admin Password Command Send MDM Check In CommandSend Set Recovery Lock Command View License Serial Numbers View Local Admin Password View Local Admin Password Audit History View Recovery Lock Allow User to Enroll Send Application Attributes CommandSend Computer Unlock User Account Command
I'm new to jamf. We have a classroom with old imacs that are being replaced. I need to get them out of jamf before they go to recycling. Id also like to wipe them. What is the proper process for doing this? Any help would be appreciated.Thank you
Hi everyone. I hope you are all good. I have set up a Trial of Jamf CONNECT with Azure. It seems to work well. It does what I want however I signed in using a different Azure login and it created the user and logged in but it did not prompt for MFA even though my Azure policies require MFA for this account.In my Azure App registration I followed the Jamf documentation to assign admin and standard rights and this is working.Has anyone seen this before , I need any account that logs in to go through Azure MFA.Thanks Nation :)
Hey guys, I'm looking to have my department, maybe even building set automatically during imaging. I have 3 department groups; staff, admin, and student. We are using and AD right now, but until we re-organize it, I cannot rely on it to pull department info correctly. I was wondering if anyone knew how to script this out? I'm not sure if the API is needed. Thank You!
Hi All,looking for some guidance - Im trying to enable Admin By Request have Full Disk Access across my mac fleet.I have a PPPC that I have deployed and its says completed but on the mac (Ventura) When I check in in Security / Privacy -> Full Disk access , its not ticked .. I have seen on the other app - that although on FDA is enabled - the mac UI may not be updated. Here is the config that I have deployed as per ABR instructions..macOS Client: IT Admin Manual (adminbyrequest.com)Im wondering if there is a way i can locally in terminal to see if the FDA is enabled or not .. Any input be great! Thanks
Hi all, I'm working with some of my organizations compliance policies in Microsoft Azure, and I'm having some issues with a Microsoft-issued certificate/private key that gets issued when visiting a Microsoft resource, i.e. portal.office.com. Is there anyway to suppress this certificate so our end users aren't prompted every time they have to login to a specific resource? And to clarify, this is a unique, private key that is generated for each user. So far I've tried deploying a configuration profile with a Chrome plist that explicitly allows anything from the issuer: MS-Organization-Access, as well as changing the trust settings in the Keychain to trust/allow for all applications, but nothing has prevented the certificate prompt.
#!/bin/bash # Written by Justin Repasky 08/03/2023 # Runs Crowdstrike's diagnose command and outputs results to /Users/Shared/Diagnostics # Crowdstrike command includes macOS system diagnostics logs command_to_run="/Applications/Falcon.app/Contents/Resources/falconctl diagnose --silent" target_text="Falcon sensor diagnostics are complete. Please send this file to CrowdStrike Support" target_folder="/Users/Shared/Diagnostics" date_time=$(date +"%Y%m%d-%H-%M-%S") mkdir "$target_folder" 2>/dev/null $command_to_run | while IFS= read -r line; do echo "$line" if [[ $line =~ $target_text.*(/tmp/[^[:space:]]+) ]]; then path="${BASH_REMATCH[1]}" echo "Path found: $path" # Move zip file from tmp folder to /Users/Shared/Diagnostics mv $path "${target_folder}/falconctl_diagnose_${date_time}.zip" # Open /Users/Shared/Diagnostics so user can copy file to where we determine /usr/bin/open "$target_folder" fi done
So I have been going through all the documentation I can find and have tried and tried to get it so that users can just open the Unity.app without signing into the unity Hub.app. This is with an Educational Grant License.Anybody got this working and like to share how you did it? What is your strategy? I have come across syntax errors in the commands they give you as well as contradictory information. They say when you download the packages that there is a "handy install.sh" but instead it is a .ini What! Not good : ( I need this working on 120 Macs like two months ago!Nightmare...
I received this error message on 5 machines this morning. I'm assuming that our policy to recon tried to run but couldn't because the user terminated their connection in the middle of it.I just wanted to see if anybody else has seen this before.Thanks Executing Policy JAMF ReconRunning script JAMF Recon...Script exit code: 1Script result: Retrieving inventory preferences from https://Finding extension attributes...Locating applications...Locating accounts...Locating software updates...Locating package receipts...Locating plugins...Locating printers...Locating hard drive information...Searching path: /Library/Internet Plug-InsSearching path: /Users/[domain username]/ApplicationsSearching path: /Users/[Local Admin Username]/ApplicationsSearching path: /ApplicationsLocating hardware information (Mac OS X 10.14.5)...Gathering application usage information...Submitting data to https://**There was an error. Connection failure: "The operation couldn’t be completed. ( error 502.)"Error
Does anyone know if there's a way to restrict the visibility of Wi-Fi passwords on a system level in iOS and iPadOS 16? I looked around but haven't seen anything about this yet. I know they aren't visible to the user if the credentials are provided via configuation profile. My specific concern is that passwords may become visible to some users if the credentials had to be entered manually (by me) to rejoin the network on the fly. It's a pretty serious security concern, so I'm hoping there's a way to just turn this feature off completely on supervised devices.
So I created a policy for Arctic Wolf like i would for another piece of software. When I tried installing it, I got the error in the attached screenshot. Anyone else get this error?
Updated to 13.3.1 (a). Wanted to monitor via Smart Group but it doesn't look the fields populated after inventory check ins.How are you monitoring?The fields do populate for iOS.
Hello Jamf Nation! I work for an asset recovery company that regularly buys large lots of Apple equipment from schools, and as a result we are well versed in helping schools remove their devices from MDM and releasing them from ASM/ABM. Lately we've been encountering issues from more than one school (system) where Macs are fully erased, but are locked with EFI firmware passwords and the IT departments 100% insist that they don't know what the password is. We know that EFI passwords can be deployed and removed via MDM, so we sent them links to Jamf documentation for managing EFI passwords in hopes of refreshing their memory and they still insist they know nothing. We asked them to check with any employees or volunteers who may have helped deploy these Macs and still nothing. If this were one school system, we'd chalk it up to an unfortunate mistake, but we've received batches of Macs from different parts of the country with this exact same issue— No one in their technolog
Please can someone advise in plain English how to push profiles? Thanks in advance.
Automatic Device enrollment is no longer workingAfter an OS re-installation multiple devices are stuck on the "Remote Management" screen.Clicking on "Continue" shortly displays "Retrieving enrollment profile" but nothing is happening.Manual enrollment via JAMF-enrollment-website is working, requires a reinstallation of a "stuck" machine and unplugging the network cable at the right time.Any idea how we can troubleshoot and resolve this issue?Thanks Bjoern
I know that Jamf Pro has support for the Jamf Teacher app. It supports installing the app and allowing the classroom management functionality with Jamf Pro classrooms.Also, I'm familiar with Jamf School and it's integration with the Jamf Teacher API. So my question is specifically regarding the API, is there support for using the Jamf Teacher API with the Jamf Pro MDM? ThanksSteven
Hi,I currently have problems with the login to the Jamf Page (not my Jamf Pro instrance, the regular jamf.com website). When I try to log in I just get set back to the main page and nothing happened. Already tried the standard solutions. Deleted cookies, incognito mode, different browser, different account, different computer, nothing worked. Has someone similar issues? Is there a problem on Jamfs side?Unfortunately I cannot ask their support directly, because I cant log in. :DKind regards
Hi all!In our new environment that we are setting up with Jamf Connect we are unable to create MDM Capable Users. This takes the option away to deploy certificates, in this case a user certificate, in our Login Keychain.The known workarounds for making users created with Jamf Connect MDM Capable Users are not something we can use in our environment. Because of this I was looking for different solutions and I found out that you are able to perform actions on the Keychain with AppleScriptExample:tell application "Keychain Scripting" to tell keychain "login.keychain" ... end tellNow I'm wondering if it would be possible to move our User certificate from the System Keychain to the Login Keychain with AppleScript. Or maybe someone knows a different solution for getting our User certificate in the Login Keychain without user interaction?
Hello, I would like to update some devices from Jamf. I create a script but it doesnt work. Where is the problem?The script is,#!/bin/bashsudo softwareupdate -i macOS\\ Monterey\\ 12.6.3-21G419 -Rexit 0Thank you.
Hi all, I don’t suppose someone could share a snippet of their config with Jamf Connect shares including their custom menu item for shares and possibly a passworditem to update secure air printers?If I manually connect to the shares, all fine no issues with auto, it just won’t do it automatically. Also the Shares menu won’t appear in the app. Same with keychain items, I just can’t get it to work!! Thanks!
Hi,Our company recently onboarded Jamf. I'm looking at best practices, or what others in the community, has done with Patch Management.It seems we must manually search for and download or create .pkgs of applications > upload the package > select Patch Management Application > Definitions > Add > Create Patch Policy or edit existing patch policy. I currently have applications all from the Jamf internal source. But the list of applications are getting longer as I onboard more Mac users. Having to download/create pkgs every month seems quite cumbersome. What do you do? Thanks.
So I open the network prefs, select the wifi interface go to the little cog wheel at the bottom and select "Make Service Inactive". Can somebody please tell me how to do this via the Terminal, or at least a script that I can push out via jamf or something? Oh, it needs to work on Mojave and higher macOS...
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!