Get Support
Recently active
How would I remove a user associated to a laptop? They just received a new laptop, and I'd like to remove them from the current laptop so It can be redeployed. Additionally, whenever I try to make changes to the laptop (like renaming it) I receive a prompt stating the user will be added to a group or other changes could be made to the user.
Our cloud asset was recently upgraded to 10.27There are new Patch Policies available and a handful of "Legacy" and "Deprecated" Software Titles. I'm seeing EA errors for the Patch Management of Microsoft AutoUpdate and for Mozilla Firefox. I'm no EA wizard, but I don't see anything obvious in the EA provided by the Patch Management. Anyone else seeing this?
When migrating from jamf on-prem to cloud, devices are first unenrolled from on-prem. Which means they loose every Configuration Profile for system extensions, PPPC, 802.1X etc. Users get the notification prompt to enroll into jamf cloud and if they click through that it does migrate them successfully. But is anyone aware of a process to make this smoother so users don't see dozens of other notifications/prompts while they're in the "limbo" state? I saw Rocketman Tech had a workflow using DEPNotify that made things a bit smoother. It did look like it was able to hide all of those notifications (at least during the demo https://youtu.be/ZTbv5ZvI3pI). But on current versions of macOS there isn't a way to stage profiles that remain after unenrollment as far as i know. So the only option i see to help with all the prompts would be to use AppleScript to close out the undesired notifications. I don't know how well that would work since that
Hi all,I’m having an issue trying to get a machine to register to my intune. This issue is only happening to one computer and all of the others are working fine which leads me to believe that the issue is within Intune. Please kindly share your thoughts on this issue on where to check in intune or Jamf. (See screenshot) Thanks.
Hi, I'm looking for a way to setup an Extension Attribute to let us know when a local user account is locked out of their MacBook. I'm not seeing or know of a way to track in JAMF. The devices are not bound to AD. Currently in JAMF when I check the local user account and click on managed for that account, I only see the option to unlock it, but it doesn't say if the account is locked or not.
Hi team,We have jamf integrated with Azure directly.We are trying to update jamf client from Intune on Macs, but although from Intune marks the application as updated, on the devices we find that the version installed on the previous one.Has anyone had this problem? Do you need more information?
Ex.A user brings their device (BYOD) -- They log into the MacBook that's under our JAMF control, and it automatically adjusts settings they may have set for things. Semi-new JAMF user here.
I just deployed jamf connect to a new fleet of imacs. They are using jamf connect with azure. I had a pervious policy that handled the "login window". This policy configed a welcome message, how the usernames are displayed, and it also configured a screen saver on the login window. This policy DOES not affect any jamf connect login imacs I have. How can i change the screen saver for the login screen on jamf connect?
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 10.48.2 fixes the following product issue: [PI112230] Jamf Pro startup is no longer suspended after upgrading to Jamf Pro 10.48.x on an on-premise Windows server with the MySQL database configured to force lowercase table names. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro.
Hi there,Hoping I can entreat the Hive Mind to help me nail down why I'm getting an error in the last part of this script. I'm putting together a self service policy that will run two scripts. One grabs the current computer name as a variable, deletes all the relevant networking plist files in /Library/Preferences/SystemConfiguration, and then renames the computer to its original name. That one is working great.The second script is where I am having trouble (I split them into two because for no discernible reason, the first part would throw weird errors when they were combined in one script but now it seems to work fine with them separate despite there being no differences in the command statements).This script creates a new network location, switches to it, and deletes the old one. But I'm having trouble with the last part. I'll include the script below, and the jamf policy log output from a test machine.#Created by John Geck, 7/21/2023 #Create a new network location and substitute t
For this MacBook Air (that is managed via Jamf Pro), when you change the background image, you can see it change in the menu bar but the rest of the desktop image is black. Almost like the black screen is layering over the image (but the desktop icons are still fully visible). When you go to Mission Control to see all the open tabs, then you can see the desktop image, but only then. I made sure the configuration profile in Jamf allows changing of the desktop image in the restrictions payload and we also tried deleting the .db file in ~/library/application support/dock and restarting but it just generated again. We are trying to avoid resetting NVRAM if possible, so if there are other suggestions, it is much appreciated! The device is also running on Ventura.Thanks!~Gabby
Hey, I am searching for a method how to use patch management with Cisco Anyconnect VPN. Since it is not available in the standard jamf catalogue. I know you can create your own patches with the Title editor.But therefore I would either need an external source or a json file with the settings since I never created this before.If someone maybe has some information or hints I would really appreciate that
We are experimenting with using Managed Apple IDs as the primary Apple ID for our end users for all the reasons. We hoped the user could then use their personal Apple ID with Messages, but the option to "Enable Messages in iCloud" is disabled in this configuration. So Messages can work with their personal Apple ID, but all the syncing goes away. Any work around here?
We deploy the Jamf Connect app via Pre-enrollment. Everything installs and works but the Jamf Connect app that runs in the tool bar does not get added to the login items\\Run in the background until a user manually launches the app, then it adds itself to the login items.I thought it would do that on it own, what steps should I take to enable that without user intervention.
Hello.In our environment we are moving away from binding devices to Onprem AD except for a few small use cases where it is still currently required for Onprem related services such as WIFI, Printing and a couple of Network drives that are slowly being phased out.One of the tasks I am trying to get working is to elevate the status from Standard to Admin of any AD based Security Group inhabiting Local Admin account created on a Mac.So my process is as follows;* User logs into Mac via Jamf Connect authenticating to Azure via their User account* User account is created locally as Standard (not dependent on onprem AD at all).* Device has an AD object, is already bound to AD during setup and device is connected to domain via ethernet, wifi or VPN having direct sight to the AD.* A script is run that unbinds and then rebinds the device but including the name of the security group that the elevated user account is also a member of that utilises the device hostname in the security group naming c
Hey looking for help on the below please. We are in the process of deploying jamf out to our users over the coming weeks.We are using a few jamf products including jamf webfiltering.We also you crowdstrike and use the ZTA to enable users to access Okta.I have been told by a jamf support agent that the 2 will not work together due to MacOS only allowing 1 network extension.Is this the case? Any help would be much appreciated.
I do have a question regarding patch management and a smb share. We are using Jamf on premise. and we do have a DP that is in the DMZ and is using a smb share and https.So if I configure a computer outside of the internal network all policies gets installed. But if for example a patch should be installed I often get in the logs an error. Trying to mount the smb share... tried for 3 times and always fails.Shouldn't that also work? I mean of course without a vpn connection he cannot mount the smb share but then he should be dl it from the https source. Or is the patch management still broken I have the latest 10.48.1 server version installed
We use school profiles for our students' iPads (BYOD) with a time filter. Works pretty well but every time the profile is deactivated, the iPads forget the previously saved wifi passwords so the students have to reenter their private networks' information every single day. Is there a way to avoid this?Thanks four your help :-)
I'm having issues with uploading to JAMF. Getting the error below. WARNING: com.github.autopkg.grahampugh-recipes.jamf.zoom.us-pkg-upload is missing trust info and FAIL_RECIPES_WITHOUT_TRUST_INFO is not set. Proceeding... Expecting value: line 2 column 1 (char 1)Failed.Any ideas on what could be causing this, and how to fix it? Thanks.
If I write a script using an if statement, and use "then exit 0", what would I enter after "else" to make the script continue running if the result of the if statement is a different value? I thought I knew how to do this but I can't think of it.
a couple of our clients recently had some Macs stolen. While we can lock them via Jamf MDM command I was management was curious about Activation Lock. We currently do not let users enable Activation Lock, but we got to thinking this might be another line of device provided we have the bypass key stored.So... Do you let uses enable activation lock on your Macs? If yes...why? If no...why?
Hi Jamfs,Using Inventory Pre-load for our AppleTV enrollment and it's working great. But hoping there is a way to re-name the AppleTV at enrollment time so when it enrolls in Carousel is has better descriptive name other than AppleTV. If I could name the device in the Preload it would resolve this issue for me. Issue is I don't see an option in the Pre-load template to name the device. Not being able to re-name the AppleTVs causes confusion not know who enrolled the devices.Thanks
- 2020 MBP 13" 4x Thunderbolt ports- Active Directory bound- Enterprise Connect for password sync- FileVault 2 configured (via mobileconfig profile)1. User was prompted to update AD password2. User set new password with Enterprise Connect, as instructed.3. FileVault unlock screen does not recognize new password, only the recovery key (escrowed in Jamf), and the user has immediately forgotten their old password, so I can't test if that would still have worked.4. Thinking this is some kind of AD/Keychain disconnect, I nuke the user's keychain.5. This doesn't resolve the issue, so I unbind & rebind to AD.6. This doesn't resolve the issue, so I create an exception and remove the FV mobileconfig profile, and manually turn off/decrypt FileVault, reboot, log in, remove the exception in Jamf Pro and re-enable FV. A new recovery key is escrowed.7. User's current password still doesn't unlock the volume on reboot. New recovery key works.8. I exchange the laptop to get the user up to speed, a
Hi Team, How to check JAMF on-premises DP usage?
Hello Jamf Nation! You will find details about Jamf Pro 10.48, including the Cloud Upgrade Schedule and Release Notes Video, as well as all future versions in the new Jamf Release Info space.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!