Get Support
Recently active
Hi,When I issued a sudo pmset repeat wakeorpoweron MTWRFSU 08:00:00when I check it will show the correct.Repeating power events: wakepoweron at 8:00AM weekdays onlyWhen I issue command sudo pmset repeat shutdown MTWRFSU 18:00:00 it shows only but missing the wakepoweron. Am I missing anything?Repeating power events: wakepoweron at 8:00AM weekdays only
HI, I had a question regarding removing our current JAMF mdm profile and replacing it with a new one from new company taking us over. I'm trying to do this with as little user input as possible. I've tried creating a policy to drop off the new mdm profile then running the "remove framework" command to remove the current profile. I also had a script in the policy to run afterwards to install the new mdm profile. So far the only thing working with this process is the delivery of new package(mdm profile) and removal of current one. New profile isn't getting installed. Anyone try something like this before successfully?
<Disclaimer> New to Jamf here. I am finding after I enroll the devices into my inventory that I need to go into the profile that it is assigned in the scope tab, I have to click the save button for it to install. Save thing with pushing Apps to devices. I have the Apps in the device group but until I go into the App and save it, it just says pending.. Any ideas?
Hi,This is more of a preventive post and a sort of a horror story on how Jamf Connect was accidentally pushed in our environment while it is still in testing phases with nobody from STAFF even expecting it... With new Jamf Pro JSS server - Jamf Connect can be updated/DEPLOYED directly from JSS global settings area, which we have learned the hard way. In my initial opinion this was only a maintenance/update feature, not an actual push to every mac and while afterwards I saw "for an initial deployment" in little grey letters - it should be in BIG RED LETTERS! If anybody runs into a similar problem:1) Immediately switch Jamf Connect Version/Update Type to "None"2) Create a smart group which will check for Application Title: "Jamf Connect.app"3) Flush/Trigger Inventory Update policy on JSS to register all the macs which already received Jamf Connect ASAP4) Create a policy with every available trigger so it gets to every mac ASAP scoped to the Jamf Connect app present smart group
Does anyone have an example of pushing device specific configuration to a machine?Scenario: I'd like to populate a file on every laptop device that contains the content of certain extension attributes that are centrally defined and keep that regularly up to date when I make changes in the admin portal.Is there any means to do this? Everything I am seeing all seems to be geared around "shared" or "common" policies that are associated to machines/groups. I'm not looking to create 100 different policies each associated to one machine. I'm looking to populate based on actual attributes set on the device itself in the portal. Another way of looking at this - is it possible to have a policy that has "templated content" in it where the template values come from EA's set on the device?
There was an issue with 10.48.1 so there was no Windows installer.Curious if anyone updated to 10.48.2 yet.Jamf Pro 10.48.2 Now Available
What's the official statement from JAMF about Software Updates? With 12.2, our Mac mini M1s are refusing to update when performed by:-+ command line softwareupdate with or without sudo+ not working with running the full installer with sudo and piping password to stdin (not cool Apple)+ using JAMF to send Remote Commands to updates fails. When I checked the logs, it says:-SoftwareUpdate: request for status for unknown product MSU_UPDATE_21D62_patch_12.2.1SUOSUServiceDaemon: Connection invalidated!Removing client SUUpdateServiceClient pid=32208, uid=0, installAuth=NO rights=(), transactions=0 (/usr/libexec/mdmclient)The only successful way to install is to sit at the machine and open System Preferences > Software Updates and put in an admin password when requested.
Just checking to see if anybody has tried the new Software Update. I tested it on my Monterey Mac and set it to do 3 deferrals and update to the 12.6.8. I had my device locked at the time and it just restarted and updated automatically after 15min.
IT Specialist, 25 years - I have taken a keen interest in the Apple side of this since I’ve taken this role. We have a fleet of iOS devices we manage through jamf pro - anyway I am looking for a career in MAC/jamf/iOS management/administration. Is their any path recommendations, I’ll be taking jamf 100 this year and later jamf 200.
We're currently progressing on a fresh implementation of JAMF Connect. Our configuration's validation for obtaining tokens from our IDP through the JAMF Connect Configurator is confirmed. We've initiated the deployment of JAMF Connect via Automated Device Enrollment, in conjunction with the configuration profiles for the app. We seemingly have achieved successful authentication into our IDP through JAMF Connect. However, upon reaching the "Re-Enter your Organization password to synchronize with your new local account" screen, and re-entering the password:Upon licking on 'create account', we're faced with an error message that isn't particularly informative:Has anyone seen this before or know how to troubleshoot this moving forward?
I have a few questions: 1. With Jamf connect, can you still have local admin accounts? 2. Is there a way to force network connections during pre-stage enrollemnt (where users cannot bypass)?
Up front, this is a hypothetical:If there was an Apple TV in single app mode that cannot, for whatever reason, communicate with Jamf, what options exist for wiping or resetting said device?These are 3rd gen 4Ks, and since there's no longer a USB port on them you can't wipe it by hooking it up to a Mac anymore.How do you guys handle scenarios like this? We're working on a project to deploy almost 100 of these across a fairly wide geographical area and this is a question that's come up that I don't really have a good answer to. Thanks!
Apple released OS 13.5 today. We have noticed that the Connect Identity Authentication window disappears after the OS update. We are authenticating through Google. Has anyone else experienced this? Do you have a fix?
I am a new user to MUT, and Im trying to update an Extension Attribute as a test. I'm in our sandbox environment. When I run MUT, nothing updates.I've pulled the logs, and every device I'm trying to update says, "PUT failed. 401." I've figured out through my own research that 401 = unauthorized. I've double-checked I have full admin rights with the account I'm using. I'm now wondering if it's how I'm connecting to the server.Has anyone else seen this issue? How can I resolve this?
Hello,I've been changing our live JAMF system over from using a self-signed certificate to a proper public certificate. I finally got it all working Thursday afternoon. (Definition of "working": I was able to get a new Apple push certificate using it; communication between my JAMF server and Apple School Manager is working; I was able to reinstall a client and it picked up NDM and carried on happily.)On Friday, I was off, which means that nobody was doing anything with the JAMF system or that client.Today, I found that that client can't communicate with the JAMF server. And it lost the ability to communicate between 10:09 and 10:28 *Friday* morning. When I wasn't even there.Log entries go from this:Fri Jul 21 09:50:34 LISA-065 jamf[38385]: Checking for policies triggered by "recurring check-in"...Fri Jul 21 09:50:38 LISA-065 jamf[38385]: Checking for patches...Fri Jul 21 09:50:38 LISA-065 jamf[38385]: No patch policies were found.Fri Jul 21 10:08:57 LISA-065 jamf[39031]: Checking for p
So what is the best solution? The current word-of-mouth and tech releases appeal to the importance of Managed Apple ID. Even in Jamf's recent Blog, "Jamf After Dark: WWDC recap," @Haddayr Copley-Woods, and @AWebb speak of getting on the Manage Apple ID bandwagon. However, you cannot save stored credentials without LDAP Authentication. Jumping through SSO is difficult, from my experience, too, without stored credentials.Secondly, there's another instance of LDAP under Synchronization. One or the other? Both?Will moving from my Organization > Settings > using Apple School Manager's sync settings and Microsoft Azure Authentication to Microsoft AD (On-prem) LDAP break something?Should I also link LDAP within the Synchronization settings? Benefits? Pitfalls? Another sticking point, which may be these will fix, is I cannot filter Users based on the ASM role. All imported users are labeled as "Staff." Not sure if this is a bug or limitation of Azure Authent
I know there was a PI issue for not being able to scope policies to Azure AD groups at check-in. If you signed into Self Service and had the policy set for Self Service it would work, but setting the policy to check-in with scope to All Computers and a limitation of the Azure AD group didn't work. Has anyone heard if this is fixed Jamf didn't give me a PI issue for this?
I just ran in a changed behaviour with the defaults command.I have a script that adds a folder to the list of background pictures. It worked fine until macOS 13.2 I think. Never checked after that. Just saw the new behaviour while looking for ways to have a different lockscreen picture than the desktop picture. (Spoiler: It's not possible.) Normally the script simply runs this command in the user context: defaults write com.apple.systempreferences DSKDesktopPrefPane -dict "UserFolderPaths" "( 'path_to_my_wallpapers' )" This updated the plist file below and the user saw the folder with additional company wallpapers. ~/Library/Preferences/com.apple.systempreferences.plist Now the command writes to the sandbox container. And whats more worse, the user does not see the folder in System Preferences ~/Library/Containers/com.apple.systempreferences/Data/Library/Preferences/com.apple.systempreferences.plist So, currently I don't see a w
"Enrolling with management server failed" Unexpected error(MDMResponseStatus:401)
Can someone assist with making this EA display correctly? I want an EA to basically display how many days it has been since the last password change What I currently have is this: #!/bin/bash # Logged in user LoggedInUser=`ls -l /dev/console | awk '{ print $3 }'` # Current password change policy PasswdPolicy=0 # Last password set date LastPasswordSet=`dscl . read /Users/$LoggedInUser | grep --context=3 passwordLastSetTime` # Calculations LastPasswordCalc1=`expr $LastPasswordSet / 10000000 - 1644473600` LastPasswordCalc2=`expr $LastPasswordCalc1 - 10000000000` TimeStampToday=`date +%s` TimeSinceChange=`expr $TimeStampToday - $LastPasswordCalc2` DaysSinceChange=`expr $TimeSinceChange / 86400` DaysRemaining=`expr $PasswdPolicy - $DaysSinceChange` echo "<result>$DaysRemaining</result>" Can't get this to work correctly.
The CAPTCHA system that was recently added to Jamf Nation is extremely frustrating. Between the ambiguous images (e.g. the entire rider must be selected for a "motorcycle" instead of just the machine) and that _every_ post seems to require a CAPTCHA response no matter how short of a time since the last verification it really makes Jamf Nation a poster hostile site. If that was the goal if implementing the system then congratulations. If it wasn't then please implement a more user friendly system.Update: Ironically the CATCHA system did seem to remember my previous verification when I went to submit this post. Actually I take that back, by editing the post to add this update it invalidated my cached CAPTCHA verification.
Does anyone know if JC 2.25 | Okta OIDC support Authentication Passthrough? I have been struggling with getting this to work with Okta OIDC. A few have mentioned via Mac Admins channel that this is a feature request but Jamf support, via support ticket, has mentioned that it does work with Auth Passthrough and Okta OIDC. Scratching me head....
I've been seeing some extremely odd behaviors with the 13.5 installer involving internet connectivity during the installation. I use Download Full Installer to grab the whole shebang as a single installer so I'm not working with deltas or snub installers. I've done this for the past couple years without any problems. Reports are kinda scattered, but it appears that when the installer is running before the initial restart, it is trying to download additional bits from Apple. I only discovered this when a user was getting this error I triple checked that the installer that was pushed to his Mac worked on a couple of my test Macs. The installer was not broken. After deleting and reinstalling the installer on his Mac 3 times with the same result, I asked him to disable Wifi and unplug from ethernet.. same problem, The I had him reconnect to the network and then disable ZScaler. The installer worked instantly!Another sign was that a user's Mac was on our guest network but he forgot to
Hello everyone,We're running across a very mysterious issue with macOS systems running Monterey. Once in awhile, the Mac will get into a condition where com.apple.softwareupdated either gets corrupted, broken, or gets unregistered completely. These are all Macs connected to our Jamf Pro container. When the service goes into a problem state, the Software Update GUI spins indefinitely and when we try to run softwareupdate -l in Terminal, we receive an error stating:The connection to service named com.apple.softwareupdated was invalidated: failed at lookup with error 3 - No such process. When we try to run sudo launchctl kickstart -k system/com.apple.softwareupdated , we get error:Could not find service "com.apple.softwareupdated" in domain for system To verify the service is even installed on the Mac, we run sudo launchctl list | grep com.apple.softwareupdated and it doesn't return anything back. When we run this same command on a Mac where Software Update is still functio
Long story short. Everything was manually created and assigned statically or via smart and everything was good. Now all the devices have come back and mixed all together and they need to go back out. What is the best way to deploy from that scenario. I've been looking for days but finally decided to reach out since no one has a clue just an idea of what they want it to do. I was tossed this project with the knowledge of only assigning and simple usage of JAMF. Now I am in charge of recreating the beast and getting it up and running with new parameters. Any help is appreciated. We have around 1000 devices that are named based on site rooms and a few assigned to the user or teacher. We now have SFTP pulling data for grades tk-1st along with their teachers, in the hopes of enabling classroom. Apple school manager is being used but that's another beast in itself that I have to deal with.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!