Get Support
Recently active
I've setup our JIM and LDAP Proxy on an AD box with an external IP address and an externally resolving DNS but Jamf keeps saying it's unable to connect to the LDAP server when using the Test button. This JIM has one IP but dual DNS since our AD does not resolve externally. I use our InfoBlox DNS which can resolve externally to provide an externally resolvable DNS. The DNS are something like jimmy.ad.company.com and jimmy.company.com respectively. When I do a reverse lookup of the IP from the JIM itself it provides the externally resolvable DNS of jimmy.company.com This DNS name is what shows up on the Jamf side and it checks in about every minute. Below is the log from Jamf Pro (we have a cloud instance). Any ideas? Thanks. 2019-09-06 19:16:42,851 [ERROR] [ina-exec-17] [LdapDirContextFactory ] - javax.naming.CommunicationException: jim.rice.edu:8389 [Root exception is javax.net.ssl.SSLException: Unexpected error: java.security.InvalidAlgorithmParameterException: the trustAnch
We are experiencing an issue where a laptop going through enrollment shuts down during enrollment leaving the device not fully enrolled and the admin account in a corrupt state. At first we thought it was just M2 laptops but as we start resets with older devices the same thing is happening. We are wiping the laptops using Configurator and have created a fresh Prestage but it still happens. Usually restoring a 2nd time with Configurator allows enrollment to complete but now I'm seeing a few devices consistently fail in this way. Have an open ticket.
We recently had two different departments ask for a few ipads which will be shared among several users. Some of the apps they are requesting to have on the iPads is Microsoft Office Products such as Word or PowerPoint. I know Shared iPads is a thing, but unfortunately the person who would need to set up all these managed accounts for SSO ability would not be able to work on that for months. So right now our only option is to have the iPads being shared without separate logins. However it seems in order to be able to use Microsoft Apps, it seems they would need to log in with a license on each device. It is my understanding that our licenses are O365, and thus are tied to individual user accounts. Is there a way to have one generalized license (like how Volume Licenses used to be done) to use with these apps? What is the easiest way to go about this? I'm happy to answer any questions I can to help point us in the right direction.
I'm posting this in case others encountered this issue with bootstrap tokens on macOS 10.15. Particularly, we were running Jamf Pro 10.23.0 but were still seeing our devices show that tokens were not supported on the server. Checking the status:sudo profiles status -type bootstraptoken Results:profiles: Bootstrap Token supported on server: NO Our devices met all the requirements, namely:1. Registered in Apple Business / School Manager2. Enrolled via pre-stage enrollment.3. Running macOS 10.15.4 or later.4. Enrolled after Jamf was upgraded to 10.18.0 The issue was that an undocumented requirement (possibly a bug) is that the pre-stage enrollment must have the following option checked: Prevent user from enabling Activation Lock Once changed, we were able to fix existing devices by issuing the Remove MDM Profile command, then on the device enrolling again with the following command: sudo profiles renew -type enrollment Once the device re-enrolled the results showed as expected th
Hi All,I hope you're doing well. I have a question regarding the installation of Camtasia 2021 on more than 200 Macs in our organization. The audio system requirement for Camtasia indicates that we need to reduce security under Startup security utilities and allow user management of kernel extensions from identified developers.I am interested in automating this process by deploying a configuration profile. If any of you have experience with this requirement and have successfully deployed a configuration profile to allow the audio extension, I would greatly appreciate your guidance and insights.I have found that if the "reduce security" option is already enabled on all Macs, I can create a configuration profile and deploy it to allow the audio extension. If anyone has gone through this process or has any suggestions or best practices to share, please let me know. https://support.techsmith.com/hc/en-us/articles/360055945312-M1-M2-Chip-and-the-Camtasia-System-Audio-Capture-Componenth
I have a department who has been letting their patients facetime their family on devices that were previously unrestricted. With our migration, we don't want anyone signing into the devices with personal accounts but the department created iCloud accounts just for the patients to facetime. Is it possible to restrict signing into iCloud on the device but still use iCloud logins for facetime?
Hi everyone! I'm Kate - a member of the research and insights team at Jamf! We have a new survey opportunity available focused around security. The survey should take five-ten minutes to complete. Thanks!https://www.research.net/r/LV3JMW9
Hi all. I can easily create a smart group to determine which Macs are running 13.4.1, but what about 13.4.1 (c)? Is there a way to tell which Macs have that update installed? Thanks
Hello All,I am new to Jamf and have set it up for our entire company. After going through the Jamf Pro enrollment we believed everything was all set. Now we are noticing that users are unable to change their Azure Passwords through Jamf Connect. Is there any guidance of what may be causing this? Thank you in advance.
No text available
Hi, Couldn't find the answer I was looking for but I'm wondering if its possible to creating a configuration profile to clear pending commands and send a inventory update as we are having issue with our iPad's not checking in, iv created a smart group so it will show them but want to clear commands and send a inventory update without me doing it by hand, is there a option in Automated Management that can do that? Thanks much!
Hello !I have some questions regarding PPPC for apps permissions.First of all, I would like to know how I can find what an app needs for permissions. Access to accessibility, full disk access or user's folders, etc... Most of the time, I have a window asking an app to have access to accessibility for example but for controlling Finder, System Events, System UI Server, I don't know if I have to grant it or not. I ask that because I made a PPPC for apps like Teams but one user had the problem that she couldn't share her screen with others. She needed admin rights but she's a standard user. I didn't think about this and had to change my profile. I would like to avoid that because it was a serious problem for her when it happened.In fact, I would like to fine tune my PPPCs so they are more strict but with enough permissions. I also fear that an app needs more permissions but the user can't grant them as it needs admin rights. Screen recording, for example, or granting access to deskto
Hello,We use Jamf Pro but also have two on-site Distribution Points.These DPs can only be synced with Jamf Pro via 'Jamf Admin' from a machine on a particular subnet within our organisation.Anyone aware of another method of remotely syncing Jamf DPs with the Cloud? I have a Mac-Mini that pretty much just has one job, which is to sync the DPs, and it seems like a waste of a resource.Ta!Steve.
Hi, Is it possible to put in variables within these fields such as the serial number of a device easily? This would be very handy to be able to see on the lock screen. Thanks. :)
Good morning. We recently hit a APN snafu that resulted in a new APN and policy having to be pushed out. We are trying to find a script run as an extension attribute that can return either a "good" or "bad" result depending on what APN variable is stated. From there, we would make a smart group to see those endpoints in real time. Using Jamf Pro and managing MacOS machines. Thanks.
I'm trying to put together an Extension Attribute that will alert me to whether zscaler is logged in or not.This is what I've come up with. It works when run locally, and I thought it was working when run through Jamf but I'm noticing that machines are now reporting back as "No" when I have checked and zscaler is correctly logged in. Just wondering if anyone else has an EA that they use or could tell me what's happening.Thanks#!/bin/bash currentUser=`ls -l /dev/console | awk '{print $3}'` if (security find-generic-password -l 'com.zscaler.tray'); then echo "<result>Yes</result>" else echo "<result>No</result>" fi exit 0
Hello friends,I need to uninstall Carbon Black on all company devices. The app bundle includes a shell script to uninstall it, so I thought I could run a command with the Files & Processes payload of a policy. It looks like this:sh /Applications/VMware\\ Carbon\\ Black\\ EDR.app/Contents/Resources/sensoruninst.shIt works, but the user gets prompted to approve deleting the system extensions. I tried copying the sensoruninst.sh and pasting it into a script in Jamf, then adding the script to a policy. That does not work, returning this message:VMware Carbon Black EDR Uninstaller Copyright 2016-2021 VMware, Inc. All rights reserved Uninstalls the VMware Carbon Black EDR sensor. Must be run as root. Options: -d [ d ] Keep local sensor data. Maybe what I want to do is not possible but I thought I'd check here. Do any of you know if it's possible to uninstall this thing without user intervention? Any insight and suggestions are welcome. Thank you
Hello I need a help to deploy Nexthink collector app on mac through Jamf.I have .dmg for Nexthink which is having 4 different component, if I copy the .dmg file under /tmp and drag into composer and click on convert into source then shows me 4 components in a separate window, but composer never shows the actual path like /tmp/Nexthink.dmg, still I closed the window and built it as .pkg , but if I run manually on my mac it says incompatiable on this device. Any easy way to deploy Nexthink on mac through Jamf using by .dmg file?
Is there a way to check that OneDrive is online on the command line? One of my coworkers mentioned that he'd changed his password but OneDrive didn't prompt for the new password but did go Offline on the menubar icon. His worry was that people may not notice and continue to put stuff in locally without authenticating.
I am struggling with this pop up while using Outset to mount an SMB share on every login under login-every.Initial observation says this could be happening because of these lines in our script-############## Mount the network homewritelog "Mounting $adHome"mount_script=`/usr/bin/osascript > /dev/null << EOTtell application "Finder" activatemount volume "path to share"end tellEOT`Any idea if anyone here is seeing this issue?
We're in the early stages of setting up our Team Dynamix instance here at our university and I'm running into a snag on how to import JAMF inventory into TDX. Is there anyone out there who is using Team Dynamix in their work environment who has it integrated with their JAMF inventory? They provided an XML based asset importer but it will only connect to a Microsoft SQL or ODBC database. We're cloud hosted with JAMF so I trying to see what other options we have. Should we create a mirrored database of our JAMF inventory by means of API?
Hello, Has anyone already configured/Setup iOS device compliance integration (JAMF->Intune)? Everytime that we register the device via self service it won't ask us to enter the credentials instead we are getting "You are now Registered with Microsoft" prompt but when we checked back Intune we still don't see the device. Not sure if we missed something or doing it incorrectly. Steps taken: Device Compliance is ConnectediOS Device is enrolled in JAMF and supervised Self Service, Company Portal and Authenticator are installed on device (Latest Version)'Register with Microsoft' located in Self Service Configured JAMF Device Compliance in Partner compliance ManagementAppreciate the help!
I'm trying to deploy Maple 2021 to MacOS Big Sur. The software actually installs fine if I watch the application folder in Finder. However, as far as self-service is concerned, it just keeps spinning in process indefinately.My policy caches my pkg to a temp folder. I then run the post install script:#!/bin/shcd /users/shared/Temp/Maple2021.1MacInstaller.app/Contents/Macos./installbuilder.sh --unattendedmodeui minimal --mode unattended --licenseType network --serverName REDACTED --portNumber 27003 --enableUpdates 0 --checkForUpdatesNow 0 After this, another script to remove the installer runs:#!/bin/shrm -rf /users/shared/Temp Any suggestions? I'm a MacOS and Jamf novice, so I'm assuming I'm doing something incorrectly
Sorry if this is a really silly question, but...On https://www.jamf.com/blog/jamf-supports-rapid-security-response/ it states: Organizations can use Jamf Pro to send push notifications via Self Service to encourage users to apply the Apple Rapid Security Response, and with the combination of settings to permit users to apply Rapid Security Response updates and lightning-fast reporting on current update status, Jamf admins are empowered to protect their fleets from emerging threats as soon as Apple identifies them. Does anyone have an example or guide on how one might do that?
Hello everybody, i hope you guys can help me with my problem. Please excuse my bad english^^We are using Apple Mac Mini M1 (2020) as personal computers for our schools. We got this school lab with about 30 MACs that students can use for almost everything, like IT study, researching. Those MACs are managed with Jamf School. We build a device group and a profile that forbids stuff like changing wallpapers ( The students like to change those to ntfw content). Sometime we like to update those config profiles and push those onto the MACs. Now i got this Problem that those MACs are losing the connect to jamf school. I can reset those MACs. Then they work fine for about 2-4 hours. After that they are losing the connect. That is pretty frustrating because those conf profile updates cant be pushed. While they have no connect to jamf, they still got internet connection. I can use the internet without problem (like google stuff). We tried using mobile Data on those MACs (creating a hots
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!