Get Support
Recently active
I need to make a script that will clear all safari data, I found some commands that mostly work but I can't get rid of one thing saved microsoft account during SSO login, the only way that works is to delete safari history via GUI, but i need to do it using CLI.Commands I've tried so farosascript -e 'quit app "Safari"'rm -Rf /Users/$3/Library/Cookies/*;rm -Rf /Users/$3/Library/Cache/*;rm -Rf /Users/$3/Library/Safari/*;rm -Rf /Users/$3/Library/Caches/Apple\\ -\\ Safari\\ -\\ Safari\\ Extensions\\ Galleryrm -Rf /Users/$3/Library/Caches/Metadata/Safarirm -Rf /Users/$3/Library/Caches/com.apple.Safarirm -Rf /Users/$3/Library/Caches/com.apple.WebKit.PluginProcessrm -Rf /Users/$3/Library/Cookies/Cookies.binarycookiesrm -Rf /Users/$3/Library/Preferences/Apple\\ -\\ Safari\\ -\\ Safari\\ Extensions\\ Galleryrm -Rf /Users/$3/Library/Preferences/com.apple.Safari.LSSharedFileList.plistrm -Rf /Users/$3/Library/Preferences/com.apple.Safari.RSS.plistrm -Rf /Users/$3/Library/Preferences/com.apple.Safa
Wondering how and what communications admin have send out to users before enabling Apple managed ID?In our company we without doubt have some users who have created an @company.com apple ID, but find it really hard to send out info without it get´s to technical.So wondering if any has some input what they have done (both good and bad things) on sending out communication to usersSo as I understand when enabling managed Apple Id´s, if users do nothing, they and up with a account that will be lost
How do you guys rotate your FV 2 recovery keys?! any ideas?
プッシュ証明書の更新はVPP、DEPと同じで毎年行う必要があります。更新方法はその他の証明書と同様に簡単ですが、 以下の注意点を留意しないと登録済みのコンピュータ / デバイスとの通信が止まってしまう可能性があります。・同じアップルIDを使用する必要有り。・同じApple Device Managementを使用する必要有り。 「なぜ同じプッシュ証明書を使って更新しなければならないのか」を昔懐かしい関所を例に説明してみたいと思います。 ジャムフはアップルのAPNsを使ってジャムフ・プロに登録されたコンピュータ と通信を行いますが、APNsを介して通信を行うにはプッシュ証明書が必要になります。 詳細は割愛しますが、コンピュータはプッシュ証明書を「関所の通行手形」としてジャムフ・プロと通信を行います。通行手形は関所を管理する政権が変更しない限り同じですので、同じ通行手形を使用して、いつでも関所を安全に通過できる事になります。 プッシュ証明書の発行はhttps://identity.apple.com/pushcertで行われます。プッシュ証明書の発行にはアップルID(関所を管理する政権)とMobile Device Management(関所)が必要となります。例:全てのMobile Device Managementが1つのAppleID(政権)で管理されています。そして各Mobile Device Managementが特定のプッシュ証明書(通行手形)を管理する関所となります。 もし通行手形が変更された場合どうなるでしょうか。関所はコンピュータが所持する通行手形を確認、関所が発行した手形と異なるので関所の通行を拒否します。 通行手形が変更される理由は2通りあります。1)異なるアップルIDからプッシュ証明書を更新した場合。別の政権が発行する手形なので、当然手形が異なる事になります。 2)同じ政権しかし異なる関所からプッシュ証明書を更新した場合。同じ政権が発行する手形ではありますが、別の関所用なので手形が異なる事になります。 上記の理由から、最初に手形を発行した同じ政権が管理する、同じ関所から発行された、通行手形を使用しないといけません。つまり、最初にプッシュ証明書を発行した時と同じアップルID、同じMobile Device Managementから発
Hello.We developped an iOS app in XCode. So far, no problem. We've been testing the app on 3 iPads, distributed automatically through a Jamf Pro profile. When updating the .ipa file in Jamf, we see the update going to all 3 iPads. Seeing everything is in order, we unboxed 15 new iPads, all from the same manufactured batch, same models, running the same version of iOS, deployed the exact same way as the test iPads but for some reason, the app being pushed to these devices have that little cloud icon, and when trying to launch them, we get the unable to verify integrity message. We wiped clean 2 of the original test iPads, ran throught the same process and for a reason beyond my comprehension, the app deploys perfectly.We are running out of ideas. I went through many posts here and nothing seems to do it. Any thoughts?
The current Jamf-managed Firefox ESR patch management definition is missing Firefox ESR 115.0 and 115.0.1. These were released nearly a week ago. I put in a support request but the ESR patch management definition has still not been updated. I was trying to avoid creating my own definition just to push these versions but it may be necessary at this point. Should I go ahead with creating my own or is there a reason these are delayed?
Hello all i wanted to know if there is a script or a way on the mac terminal i can use that will show me all users in the company app version number they are currently on? is that something that can be done? example Zoom - current version they are on
What's the best method for Mac computer authentication for 802.1x wired connections? Is the Jamf ADCS connector needed for proper implementation? Can user authentication via PEAP not be used instead of certificates?
Since the most recent versions of Xcode are often a bit "buggy", the faculty that teach in our Computer Science labs prefer to run a slightly older version of Xcode. This adds some challenges to deploying Xcode as the APP store route using VPP can only install the most recent version of an app.In case anyone else has the same need, here is the method that I've come up with. This is working for me using Xcode 13.2.1 on MacOS 12.3 Monterey and Jamf Pro version 10.37.2.I hope this helps others navigate this challenge ... 1) Setup a "test" mac with similar hardware and the same MacOS that is DEP enrolled in Jamf just like your target macs. (You probably already have this as it's incredibly useful for so many things!)2) Get a Apple Developer's account (I believe a free account will work)3) Download the version of Xcode you want. (Only certain versions of Xcode will work on certain MacOSs so get the right version!)4) Xcode is delivered in an Apple specific package format whi
Customer Education is back again with our next Jamf Pro Release Notes video! Join us for an overview of some of the new features and enhancements that are available in Jamf Pro 10.48. We hope this resource continues to provide additional details to support your use of the features in this release. You can even take the quiz below to gauge your understanding of the update! Thank you all for the continued feedback as we look to improve each video. Feel free to leave a comment and let us know what you liked and how we can make it even better next time. And do not forget to test your knowledge with the quiz!
Hi, I created a smart group to get the list of devices inactive > 180 days, but then there lot of devices ready for deployment and after exclusion we identified 150 devices whose license we can safely removeBut the issue is to how to create a smart group or static group by importing the data from excel ?
Hello, I'm trying to install JAMF Pro (10.47) in multi-contexte JSS environment under Linux (Debian) on premise, by following scrupulously this documentation, https://learn.jamf.com/fr-FR/bundle/jamf-pro-install-guide-linux-current/page/Multi-Context_Jamf_Pro_Environments.html#concept-7325 , without success for the moment. For a unique context it's ok, but as soon as I put a second context, the file "context".war in the good directory (/opt/tomcat/webapps for me), java cpu process begin to increase very strongly (until 500%) during several minutes and after tomcat "crashes" I have checked the log file but I have seen "nothing special"( but I'm not a tomcat expert)There are some few "severe" messages likeSEVERE [localhost-startStop-1] se.jiderhamn.classloader.leak.prevention.JULLogger.error org.apache.commons.logging.LogFactory.release(java.lang.ClassLoader)SEVERE [Catalina-startStop-1] org.apache.catalina.startup.HostConfig.deployWARs Er
Send the Wipe command from Jamf Pro to a Managed MacBook Pro running Catalina yesterday. The MacBook immediately booted to the lock symbol but the 6-digit code did and still does not work. The Management history on the MacBook's Inventory shows the 6-digit code that was sent to be correct, but the lock screen does not accept it. The MacBook is now in a horrible halfway house of not yet wiped but unable to proceed further. Boot to Recovery mode does not work, but takes me to the lock screen. Jamf History shows the command has been successfully sent so I cannot cancel it. Has anyone else experienced this before?
Hi, we're currently running our mac's with automatic install scripts via jamf.Our users don't have admin privilegues. When they update Slack (which is simply a new installation of the most recent client), it always shows the dialogue mentioned in the subject or attached screenshot on every app start, until someone types in admin creds.If you click on cancel, the app still starts. But the pop-up on every start is still anoying. I do get an output from terminal saying: May 10 11:58:30 Slack[21065]: DEPRECATED USE in libdispatch client: dispatch source activated with no event handler set; set a breakpoint on _dispatch_bug_deprecated to debug May 10 11:58:30 SecurityAgent[21094]: objc[21094]: Class TKTokenRefImpl is implemented in both /System/Library/Frameworks/Security.framework/Versions/A/Security (0x7fff9712afa8) and /System/Library/Frameworks/Security.framework/Versions/A/MachServices/SecurityAgent.bundle/Contents/MacOS/SecurityAgent (0x10522fce8). One of the two will be used. Whi
My organization sometimes has users open up tickets whenever I a new minimum OS version in our Nudge configuration profile due to the software update window never loading its contents, thus not allowing users to update and badgering them with Nudge notifications. I've created a kickstart policy that runs sudo launchctl kickstart -k system/com.apple.softwareupdated; softwareupdate -l This has fixed the issue of software update not loading its contents, but I was wondering if it was possible to trigger this policy whenever I make changes to the Nudge configuration profile. This way the kickstart command would run after changes are saved in the configuration profile.
Hello we have slack policy in JAMF we just started to use the universal version of slack to all users since they both with m1 and intel some users are reporting that the slack app is unable to open or it crashes i am having issues figuring out a fix for this does anyone have an idea?
We currently have the JIM server working in our DMZ and are possibly looking into ADCS. Could the ADCS be installed on the same JIM server in the DMZ?
Looking for a solution (can include 3rd party solutions) where we can pull macOS student lab usage over various periods of time from Jamf Pro (Cloud Hosted).Jamf Pro web is limited to looking at log in history of each machine individually which makes data mining very labor intensive. Also looked in to Jamf / PowerBI and didn't see the data field (unless I over looked it).Reached out to Jamf support, and they only knew of the web ui / individual machine method.
Hi All, So we've seen this issue for years, and I've asked Jamf, and Apple's GSX support about it, and gotten non-answers, so I'm curious what others might be doing.If you look up a new purchase, still within the 1y warranty (or purchased with AppleCare and within the AC warranty), you'll get a PO Date and a Warranty Expiration Date from GSX. If you look up an old purchase, but purchased with AppleCare, you'll get the PO Date, and Warranty Expiration Date in the past. BUT. If you look up an old purchase that wasn't purchased with AppleCare, you'll get a PO Date, and a blank Warranty Expiration Date. I've asked Jamf and GSX Support "can we infer anything from this?" as in "Can we assume if the Warranty Expiration Date is blank, then the warranty expiration was one year from the PO Date?" and not gotten any answer. Is anyone already making this assumption and just filling in that info themselves?
Hello,We have a problem with a local account password that seems to no longer work for some unknown reason. During prestage enrollment, we create a local admin account (other than the management account). When created, a temporary password is assigned so that our support team can finish preparing the computer. Once our support team has finished intervening on the preparation of the computer, they execute a script via the self-service to change the password with a password that few people know. Below is the script we use to modify the password with openssl encryption. #!/bin/bash function DecryptString() { # Usage: ~$ DecryptString "Encrypted String" "Salt" "Passphrase" echo "${1}" | /usr/bin/openssl enc -md md5 -aes256 -d -a -A -S "${2}" -k "${3}" } LocalCurrentPassword=$(DecryptString "${5}" "${6}" "${7}") LocalNewPassword=$(DecryptString "${8}" "${9}" "${10}") sysadminctl -adminUser "$4" -adminPassword $LocalCurrentPassword -resetPasswordFor
Hey everyone, Is there a way to disable the Profiles pane in Ventura macOS? I don't want non-DEP Mac users to mess around with it and remove the MDM profile.Thoughts?
Does anyone know why some jamf profiles / policies, when a GET is run on the api will have their payload identifiers change?Example, running a check on a profile two times yields two different identifiers, though no changes have been made: <key>PayloadIdentifier</key><string>52776B4A-EC1C-478B-AC03-016F6D6589EE</string><key>PayloadIdentifier</key><string>F195DE3B-58AF-430C-B69D-A8E8C2606F80</string>
I am not a huge Firefox user, but, there are so many things that are great about it & about how it's made that I sometimes get sad it isn't as popular as it used to be especially given the fact that Google & Google Chrome (which are destroying the internet...) have no real competition. Here is a quick example...Firefox publishes a URL to get information about updates & releases which returns a simple JSON object: % curl -LsS https://product-details.mozilla.org/1.0/firefox_versions.json { "FIREFOX_AURORA": "", "FIREFOX_DEVEDITION": "101.0b9", "FIREFOX_ESR": "91.9.1esr", "FIREFOX_ESR_NEXT": "", "FIREFOX_NIGHTLY": "102.0a1", "FIREFOX_PINEBUILD": "", "LAST_MERGE_DATE": "2022-05-02", "LAST_RELEASE_DATE": "2022-05-03", "LAST_SOFTFREEZE_DATE": "2022-04-28", "LATEST_FIREFOX_DEVEL_VERSION": "101.0b9", "LATEST_FIREFOX_OLDER_VERSION": "3.6.28", "LATEST_FIREFOX_RELEASED_DEVEL_VERSION": "101.0b9", "LATEST_FIREFOX_VERSION": "
Hi All,I am struggling with WebClips. I had no issue getting Webclips to work for Self Service, but I am now trying to push them to our fleet of Shared iOS devices. I have built out a WebClip Profile with the URL. I also added com.apple.webapp (and com.apple.webapp.managed) to Only Some Apps Allowed within our App Restrictions policy. I then added the webclip to the Home Screen Layout and scoped all of this to a department. All my other apps are installing fine, but the Webclips don't appear at all. What could I be doing wrong here?Any help would be appreciated. ThanksDan
Hi all, Referring to this macOS installer script.macOSUpgrade/macOSUpgrade.sh at master · kc9wwh/macOSUpgrade · GitHub This script works fine for Intel Macbook upgrading to macOS Monterey 12.0.1. But it does not work with Apple Silicon Macbook 😞 When attempting, I get the following error:Error: failed to authorize for installation. Provide a password with --stdinpass or --passprompt.By using the agreetolicense option, you are agreeing that you have run this tool with the license only option and have read and agreed to the terms.If you do not agree, press CTRL-C and cancel this process immediately.Investigating further, I run the following in a M1 Mabook's terminal./Applications/Install\\ macOS\\ Monterey.app/Contents/Resources/startosinstall --agreetolicense --nointeraction --forcequitappsError: A method of password entry is required.Usage: startosinstall.....The error suggests I need to supply admin username and password via --user, an admin user t
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!