Get Support
Recently active
installs of office products taking over an hour.this happens in office locations and at home, wired via LAN and over WiFi.Our office apps are packaged as individual pkgs, the installs do complete, but are taking excessive amounts of time all of a sudden. previously these would complete in a matter of minutes.Jamf Pro instance is 10.47.I can not see an obvious reason for this, anyone have any input or had the same issue?I have placed some examples below but not sure why suddenly these are taking so long to complete? Microsoft Word17 minutes ago1h 26m 18sCompleted Microsoft Outlook36 minutes ago1h 07m 49sCompleted (2 attempts) Microsoft OneDriveToday at 11:15 AM1h 00m 07sCompleted Microsoft ExcelToday at 10:15 AM23m 40sCompleted Jamf daily reconToday at 9:51 AM17sCompleted Enable Jamf Connect12/07/2023 at 5:21 PM1sCompleted
I have a simple dock addition policy, it completed successfully but does not show the self service app on the dock afterward. the after policy user interaction pops up as well I tried killall Dock as well and nothing changed I added the Dock item via Jamf Admin and then pointed to it for the Dock Items attribute of the policy
Hi all, I'm jumping into editting plist files with scripts and I'm seeing something I don't know how to handle and I'm hoping someone has seen this kind of thing before and can point me in the right direction. What I am tryingto do is to read a plist, edit a value, then put the result back in. I'm using 'defaults read | grep' to pull the value I want, but what is returned looks like:SyncTargets = {length = 118, bytes = 0x1a2b3c4d 11aa22bbcc ... 12345678}Is there a way to read this value into a string? I'm expecting the string to be base64 encoded when it reads the plist because this is how it appears in the plist file when I inspect it manually. I have never seen this before and I can't find the magic phrase to put into Google to find what I'm looking at and what I can do with it. I have the decoding, modifying, encoding and writing back into the plist all working, it's just this weird read result that I don't know what to do with. Help me Jamf Community, you'
If you havent up voted for this, heres a link to help you out....we have GOT to get Jamf to make some movement on this. My security team is SCREAMING at me on a weekly basis. Please upvote this! https://ideas.jamf.com/ideas/JN-I-16171
I am currently trying to test the new features of JC with the 2.25 release and Okta OIDC. We have successfully been using the "old way" with JC and "Okta Classic" via Authentication API. In Jamf Connect Configuration app under "Identity Provider" I have selected Okta (OIDC) and filled out the appropriate fields:OIDC client ID:ROPG client ID:Tenant: Can I just put the Tenant ID here or does it need to be a URL/TenantID? I have tried both ways and still getting an error I am getting a connection error when testing the new OIDC connection prob because I have not properly configured something correctly. I have not filled out anything in the "Advanced OIDC" section of the Configuration app. I have Jamf Connect configured in our Okta environment via OIDC configurations and as mentioned above we have been using it successfully via the Okta API Authentication previously.
I recall many years ago having students complete an online safety quiz before they could proceed onto the managed macbook. It appeared right before or after the login. Pretty cool! I was interested to see if that is still available and if so… can it be applied to a managed ipad? Profile/Script possibly. My JAMF person who helped me set up our devices like 10-12 years ago helped me with this. Kirk
Is there a way to re-name automount shares to use a set name for each in the array instead of the root folder name? We have some file shares with "Share" or other generic nonsense name that the share gets mounted to the desktop with.
Hello Jamf NationMy boss lost their Mac book Pro and is asking if our MDM Jamf Pro 10.47 can find itThe pre-stage enrolment does require location services be enabled but I do not see anywhere to look for the laptop from Jamf ProIs this a function of Jamf Pro or can this only be done iCloud > Find My app?I don’t believe they set up iCloud
I modified the JAVA_OPTS to attempt to fix an issue we're having with our DEP token per https://macmule.com/2019/10/01/more-dep-sync-errors/#The_Solution. After doing so and restarting Tomcat it was freezing on "Analyzing web application". I restarted the VM and upon coming back up I was getting the same thing. I reverted the file back to its original settings, removing the text I added, but now I'm still getting stuck on "Analyzing web application." Does anyone have any advice?
Hi,We are trying to configure it so that computers enrolled in our company Jamf have their screens locked after 5 mins of idling. As far as I know, the way to do this is by starting a screen saver after 5 mins of idling and then forcing a passcode to unlock the computer.Is there no way to lock the screens without starting a screen saver?Thanks
I am using Composer 10.38.3 to make an installer of Karabiner - Elements, but I keep getting prompted for "System software from application 'Karabiner-VirtualHIDDevice-Manager' was blocked from loading". I am using the snapshot method to capture the installation which I am allowing said software to install. Also I have modified the owner/group to root/admin and applied to all sub folders and files. However, whenever I run the Self Service install, I still get prompted for the "Allow". The software does require Security & Privacy Input Monitoring which I have created a configuration profile for. I still think this is a permissions issue.
I'm trying to get Firefox working on our network. We have an explicit proxy via a PAC file that I'm trying to configure. Once I figured out the "ImportEnterpriseRoots" key in my config profile, I am able to login to Azure AD SSO (I had been getting unknown cert signer before). It also looks like websites that are explicitly marked as direct in our PAC file work fine (our Jamf cloud instance for example). The issue is every other website. When I try to go to github.com for example, I get:"The proxy server is refusing connections"I do get prompted for creds to our proxy servers, so I know it's connecting, plus the fact that direct websites work fine as well as the untrusted cert error that got fixed but it's just the non-direct websites that aren't fail to load. We have no problems with the PAC settings in Safari or Chrome.
Our organization's Apple Push Certificate is expiring soon. I was able to renew the cert but when I try to upload the new one it says that the Identifier is different than the old cert. Will this break the push cert that has ben pushed out previously on all our deployed machines? I believe the identifier is different because I was not the one who created the current push cert. Will using my Apple ID break the current push cert? Thanks!
We are looking at getting a design/concept for an in-room patient experience in our healthcare system. Does anybody have any vendors that we could take a look at?
Hello Jamf Nation! You will find details about Jamf Connect 2.25.0 as well as all future versions in the new Jamf Release Info space.
Hello, I am attempting to upload two different .pkg files into Jamf School for distribution to the macOS devices in my environment. While uploading the packages i am receiving the following error "Error: This is not a product archive, parsing component packages is not yet supported" I have tried different version of the file and I also used pkgbuild to build a .pkg from a .dmg mount. Any help is greatly appreciated!!
Hello,My place of business recently purchased Jamf Pro and we are going to be moving about 200 macs from Intune over to Jamf.I'm not sure where to start. I don't seem to be able to find any articles or documentation about the process. Is this as simple as deleting all of the devices from Intune and then using Apple School Manager to change their MDM to Jamf Pro, or is there something more involved? I would greatly appreciate any help.
We have a few hundred MacBook Airs that we're going to be deploy in the next couple weeks. On our test ones, during setup, after the MacBooks get all the settings, profiles, etc. from Jamf, the MacBooks restart without warning and never finish setup properly. I don't see anything that should be causing the restart, but I could be missing something obvious. Here's what I see in the logs Jamf-wise:Thu Jan 26 09:55:50 MacBook Air jamf[999]: The SSL Certificate for https://xxxxxx.jamfcloud.com/ must be trusted for the jamf binary to connect to it.Enrolling computer...Thu Jan 26 09:55:56 MacBook Air jamf[1012]: Skipping trustJSS command...Thu Jan 26 09:55:56 MacBook Air jamf[1012]: JMFCommons.JamfKeychain.JamfKeychainSecurityError.failedToReadJmfKeychainPasswordThu Jan 26 09:55:56 MacBook Air jamf[1012]: JMFCommons.JamfKeychain.JamfKeychainSecurityError.failedToReadJmfKeychainPasswordThu Jan 26 09:55:58 MacBook Air jamf[1012]: Creating user xxxxxx...Thu Jan 26 09:56:39 MacBook Air jamf
I've setup our JIM and LDAP Proxy on an AD box with an external IP address and an externally resolving DNS but Jamf keeps saying it's unable to connect to the LDAP server when using the Test button. This JIM has one IP but dual DNS since our AD does not resolve externally. I use our InfoBlox DNS which can resolve externally to provide an externally resolvable DNS. The DNS are something like jimmy.ad.company.com and jimmy.company.com respectively. When I do a reverse lookup of the IP from the JIM itself it provides the externally resolvable DNS of jimmy.company.com This DNS name is what shows up on the Jamf side and it checks in about every minute. Below is the log from Jamf Pro (we have a cloud instance). Any ideas? Thanks. 2019-09-06 19:16:42,851 [ERROR] [ina-exec-17] [LdapDirContextFactory ] - javax.naming.CommunicationException: jim.rice.edu:8389 [Root exception is javax.net.ssl.SSLException: Unexpected error: java.security.InvalidAlgorithmParameterException: the trustAnch
We are experiencing an issue where a laptop going through enrollment shuts down during enrollment leaving the device not fully enrolled and the admin account in a corrupt state. At first we thought it was just M2 laptops but as we start resets with older devices the same thing is happening. We are wiping the laptops using Configurator and have created a fresh Prestage but it still happens. Usually restoring a 2nd time with Configurator allows enrollment to complete but now I'm seeing a few devices consistently fail in this way. Have an open ticket.
We recently had two different departments ask for a few ipads which will be shared among several users. Some of the apps they are requesting to have on the iPads is Microsoft Office Products such as Word or PowerPoint. I know Shared iPads is a thing, but unfortunately the person who would need to set up all these managed accounts for SSO ability would not be able to work on that for months. So right now our only option is to have the iPads being shared without separate logins. However it seems in order to be able to use Microsoft Apps, it seems they would need to log in with a license on each device. It is my understanding that our licenses are O365, and thus are tied to individual user accounts. Is there a way to have one generalized license (like how Volume Licenses used to be done) to use with these apps? What is the easiest way to go about this? I'm happy to answer any questions I can to help point us in the right direction.
I'm posting this in case others encountered this issue with bootstrap tokens on macOS 10.15. Particularly, we were running Jamf Pro 10.23.0 but were still seeing our devices show that tokens were not supported on the server. Checking the status:sudo profiles status -type bootstraptoken Results:profiles: Bootstrap Token supported on server: NO Our devices met all the requirements, namely:1. Registered in Apple Business / School Manager2. Enrolled via pre-stage enrollment.3. Running macOS 10.15.4 or later.4. Enrolled after Jamf was upgraded to 10.18.0 The issue was that an undocumented requirement (possibly a bug) is that the pre-stage enrollment must have the following option checked: Prevent user from enabling Activation Lock Once changed, we were able to fix existing devices by issuing the Remove MDM Profile command, then on the device enrolling again with the following command: sudo profiles renew -type enrollment Once the device re-enrolled the results showed as expected th
Hi All,I hope you're doing well. I have a question regarding the installation of Camtasia 2021 on more than 200 Macs in our organization. The audio system requirement for Camtasia indicates that we need to reduce security under Startup security utilities and allow user management of kernel extensions from identified developers.I am interested in automating this process by deploying a configuration profile. If any of you have experience with this requirement and have successfully deployed a configuration profile to allow the audio extension, I would greatly appreciate your guidance and insights.I have found that if the "reduce security" option is already enabled on all Macs, I can create a configuration profile and deploy it to allow the audio extension. If anyone has gone through this process or has any suggestions or best practices to share, please let me know. https://support.techsmith.com/hc/en-us/articles/360055945312-M1-M2-Chip-and-the-Camtasia-System-Audio-Capture-Componenth
I have a department who has been letting their patients facetime their family on devices that were previously unrestricted. With our migration, we don't want anyone signing into the devices with personal accounts but the department created iCloud accounts just for the patients to facetime. Is it possible to restrict signing into iCloud on the device but still use iCloud logins for facetime?
Hi everyone! I'm Kate - a member of the research and insights team at Jamf! We have a new survey opportunity available focused around security. The survey should take five-ten minutes to complete. Thanks!https://www.research.net/r/LV3JMW9
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!