Get Support
Recently active
Just checking to see if anybody has tried the new Software Update. I tested it on my Monterey Mac and set it to do 3 deferrals and update to the 12.6.8. I had my device locked at the time and it just restarted and updated automatically after 15min.
IT Specialist, 25 years - I have taken a keen interest in the Apple side of this since I’ve taken this role. We have a fleet of iOS devices we manage through jamf pro - anyway I am looking for a career in MAC/jamf/iOS management/administration. Is their any path recommendations, I’ll be taking jamf 100 this year and later jamf 200.
We're currently progressing on a fresh implementation of JAMF Connect. Our configuration's validation for obtaining tokens from our IDP through the JAMF Connect Configurator is confirmed. We've initiated the deployment of JAMF Connect via Automated Device Enrollment, in conjunction with the configuration profiles for the app. We seemingly have achieved successful authentication into our IDP through JAMF Connect. However, upon reaching the "Re-Enter your Organization password to synchronize with your new local account" screen, and re-entering the password:Upon licking on 'create account', we're faced with an error message that isn't particularly informative:Has anyone seen this before or know how to troubleshoot this moving forward?
I have a few questions: 1. With Jamf connect, can you still have local admin accounts? 2. Is there a way to force network connections during pre-stage enrollemnt (where users cannot bypass)?
Up front, this is a hypothetical:If there was an Apple TV in single app mode that cannot, for whatever reason, communicate with Jamf, what options exist for wiping or resetting said device?These are 3rd gen 4Ks, and since there's no longer a USB port on them you can't wipe it by hooking it up to a Mac anymore.How do you guys handle scenarios like this? We're working on a project to deploy almost 100 of these across a fairly wide geographical area and this is a question that's come up that I don't really have a good answer to. Thanks!
Apple released OS 13.5 today. We have noticed that the Connect Identity Authentication window disappears after the OS update. We are authenticating through Google. Has anyone else experienced this? Do you have a fix?
I am a new user to MUT, and Im trying to update an Extension Attribute as a test. I'm in our sandbox environment. When I run MUT, nothing updates.I've pulled the logs, and every device I'm trying to update says, "PUT failed. 401." I've figured out through my own research that 401 = unauthorized. I've double-checked I have full admin rights with the account I'm using. I'm now wondering if it's how I'm connecting to the server.Has anyone else seen this issue? How can I resolve this?
Hello,I've been changing our live JAMF system over from using a self-signed certificate to a proper public certificate. I finally got it all working Thursday afternoon. (Definition of "working": I was able to get a new Apple push certificate using it; communication between my JAMF server and Apple School Manager is working; I was able to reinstall a client and it picked up NDM and carried on happily.)On Friday, I was off, which means that nobody was doing anything with the JAMF system or that client.Today, I found that that client can't communicate with the JAMF server. And it lost the ability to communicate between 10:09 and 10:28 *Friday* morning. When I wasn't even there.Log entries go from this:Fri Jul 21 09:50:34 LISA-065 jamf[38385]: Checking for policies triggered by "recurring check-in"...Fri Jul 21 09:50:38 LISA-065 jamf[38385]: Checking for patches...Fri Jul 21 09:50:38 LISA-065 jamf[38385]: No patch policies were found.Fri Jul 21 10:08:57 LISA-065 jamf[39031]: Checking for p
So what is the best solution? The current word-of-mouth and tech releases appeal to the importance of Managed Apple ID. Even in Jamf's recent Blog, "Jamf After Dark: WWDC recap," @Haddayr Copley-Woods, and @AWebb speak of getting on the Manage Apple ID bandwagon. However, you cannot save stored credentials without LDAP Authentication. Jumping through SSO is difficult, from my experience, too, without stored credentials.Secondly, there's another instance of LDAP under Synchronization. One or the other? Both?Will moving from my Organization > Settings > using Apple School Manager's sync settings and Microsoft Azure Authentication to Microsoft AD (On-prem) LDAP break something?Should I also link LDAP within the Synchronization settings? Benefits? Pitfalls? Another sticking point, which may be these will fix, is I cannot filter Users based on the ASM role. All imported users are labeled as "Staff." Not sure if this is a bug or limitation of Azure Authent
I know there was a PI issue for not being able to scope policies to Azure AD groups at check-in. If you signed into Self Service and had the policy set for Self Service it would work, but setting the policy to check-in with scope to All Computers and a limitation of the Azure AD group didn't work. Has anyone heard if this is fixed Jamf didn't give me a PI issue for this?
I just ran in a changed behaviour with the defaults command.I have a script that adds a folder to the list of background pictures. It worked fine until macOS 13.2 I think. Never checked after that. Just saw the new behaviour while looking for ways to have a different lockscreen picture than the desktop picture. (Spoiler: It's not possible.) Normally the script simply runs this command in the user context: defaults write com.apple.systempreferences DSKDesktopPrefPane -dict "UserFolderPaths" "( 'path_to_my_wallpapers' )" This updated the plist file below and the user saw the folder with additional company wallpapers. ~/Library/Preferences/com.apple.systempreferences.plist Now the command writes to the sandbox container. And whats more worse, the user does not see the folder in System Preferences ~/Library/Containers/com.apple.systempreferences/Data/Library/Preferences/com.apple.systempreferences.plist So, currently I don't see a w
"Enrolling with management server failed" Unexpected error(MDMResponseStatus:401)
Can someone assist with making this EA display correctly? I want an EA to basically display how many days it has been since the last password change What I currently have is this: #!/bin/bash # Logged in user LoggedInUser=`ls -l /dev/console | awk '{ print $3 }'` # Current password change policy PasswdPolicy=0 # Last password set date LastPasswordSet=`dscl . read /Users/$LoggedInUser | grep --context=3 passwordLastSetTime` # Calculations LastPasswordCalc1=`expr $LastPasswordSet / 10000000 - 1644473600` LastPasswordCalc2=`expr $LastPasswordCalc1 - 10000000000` TimeStampToday=`date +%s` TimeSinceChange=`expr $TimeStampToday - $LastPasswordCalc2` DaysSinceChange=`expr $TimeSinceChange / 86400` DaysRemaining=`expr $PasswdPolicy - $DaysSinceChange` echo "<result>$DaysRemaining</result>" Can't get this to work correctly.
The CAPTCHA system that was recently added to Jamf Nation is extremely frustrating. Between the ambiguous images (e.g. the entire rider must be selected for a "motorcycle" instead of just the machine) and that _every_ post seems to require a CAPTCHA response no matter how short of a time since the last verification it really makes Jamf Nation a poster hostile site. If that was the goal if implementing the system then congratulations. If it wasn't then please implement a more user friendly system.Update: Ironically the CATCHA system did seem to remember my previous verification when I went to submit this post. Actually I take that back, by editing the post to add this update it invalidated my cached CAPTCHA verification.
Does anyone know if JC 2.25 | Okta OIDC support Authentication Passthrough? I have been struggling with getting this to work with Okta OIDC. A few have mentioned via Mac Admins channel that this is a feature request but Jamf support, via support ticket, has mentioned that it does work with Auth Passthrough and Okta OIDC. Scratching me head....
I've been seeing some extremely odd behaviors with the 13.5 installer involving internet connectivity during the installation. I use Download Full Installer to grab the whole shebang as a single installer so I'm not working with deltas or snub installers. I've done this for the past couple years without any problems. Reports are kinda scattered, but it appears that when the installer is running before the initial restart, it is trying to download additional bits from Apple. I only discovered this when a user was getting this error I triple checked that the installer that was pushed to his Mac worked on a couple of my test Macs. The installer was not broken. After deleting and reinstalling the installer on his Mac 3 times with the same result, I asked him to disable Wifi and unplug from ethernet.. same problem, The I had him reconnect to the network and then disable ZScaler. The installer worked instantly!Another sign was that a user's Mac was on our guest network but he forgot to
Hello everyone,We're running across a very mysterious issue with macOS systems running Monterey. Once in awhile, the Mac will get into a condition where com.apple.softwareupdated either gets corrupted, broken, or gets unregistered completely. These are all Macs connected to our Jamf Pro container. When the service goes into a problem state, the Software Update GUI spins indefinitely and when we try to run softwareupdate -l in Terminal, we receive an error stating:The connection to service named com.apple.softwareupdated was invalidated: failed at lookup with error 3 - No such process. When we try to run sudo launchctl kickstart -k system/com.apple.softwareupdated , we get error:Could not find service "com.apple.softwareupdated" in domain for system To verify the service is even installed on the Mac, we run sudo launchctl list | grep com.apple.softwareupdated and it doesn't return anything back. When we run this same command on a Mac where Software Update is still functio
Long story short. Everything was manually created and assigned statically or via smart and everything was good. Now all the devices have come back and mixed all together and they need to go back out. What is the best way to deploy from that scenario. I've been looking for days but finally decided to reach out since no one has a clue just an idea of what they want it to do. I was tossed this project with the knowledge of only assigning and simple usage of JAMF. Now I am in charge of recreating the beast and getting it up and running with new parameters. Any help is appreciated. We have around 1000 devices that are named based on site rooms and a few assigned to the user or teacher. We now have SFTP pulling data for grades tk-1st along with their teachers, in the hopes of enabling classroom. Apple school manager is being used but that's another beast in itself that I have to deal with.
We are currently looking to implement some preferences to Outlook.We have configurations to block users from adding personal emails but is there a way to report on how many users have personal emails added and how to remove them Thanks
Hey JAMF Nation Community!I was exploring with my team and wanted to see if there's a way to block users from adding a personal O365 account to their Outlook via a plist. I've checked around JAMF Nation and online and haven't seen anyone bring this up. Just wanted to see if anyone has implemented a solution in their own environments? Thanks!
Hello all, Requiring our org to update the password complexity and have a quick few questions. We have a configuration profile setup to update the password complexity to a higher number of digits needed. Currently our systems have static passwords. We are doing this in a two pronged approach1. Config profile will be updated from 12 characters to 16 characters2. Policy will be run on the determined group of people at a determined time. # Pulls the current logged in user currUser=$(ls -l /dev/console | awk '{print $3}') pwpolicy -u "$currUser" -setpolicy "newPasswordRequired=1" Since we are planning to roll out this update with groups of people at a time, can we push the config profile (step 1 above) to ALL users without it prompting them to update their password until we run the policy/remote command (step 2 above) to flag the account for a password reset? Or does the config profile have to be scoped to each group at a time (depending on when w
Hi :) Has anyone else found themselves looking for a smart group you know you created?Every now and again we will create a new smart group and it could be anywhere from a few hours to a couple of days and suddenly it is nowhere to be found! It happened again this morning; I created a smart device group and within an hour it was gone.Just me or goes the Jamf gremlin not like your smart groups either? 🙊 Thanks.
Does anyone successes to build the VM in Apple Silicon chip devices using VM Ware fusion 13.0,2, If so please guide me to create it successfully.
Hi everybody,Hope everyone is having a great Saturday.Quick question for all.. I have a remote user that keeps entering the correct password (according to her) on her Mac, but it doesn't work and would like to reset it at this point. However, the credentials for the admin account seem to not work either for some reason. Is there a way in Passcode Compliance in JAMF pro to reset the password on a Mac or disable it on her machine so she can enter the last PW? Thanks everyone.
Basically the title.Our Jamf Pro environment is setup with Jamf connect via Okta, and our users use their AD short name to login, so changing it to Azure AD would be too much of a change (unless we can change the login username).As such, we can't leverage as easily AzureAD group membership on the local device.Is it possible to use a policy + script to create a local group that contains the members of the Azure AD idp group?Thanks!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!