Get Support
Recently active
With Intune Integration (Legacy) setup - the consensus seems to be to enable JamfAAD to use WKWebView for the best performance. I've pushed that option via profile, and it works well through the first part of the Azure registration. The problem is, using WKWebView we never get to that Jamf Native macOS Connector window...so it seems to finish with no errors, but the computer never actually gets registered. Every time you try to access a resource targeted by conditional access, it takes you back to the message that this device needs to be set up for access. If I turn the WKWebView option off and set the default browser to Safari, it works (including the Jamf Native macOS Connector prompt). Hoping I'm missing something easy and obvious.
Hi everyone, Today I struggle a bit with the intune integration. Connection between jamf Pro and Intune was quite easy to do if you follow the documentation on jamf. Also this blog helps a lot:[https://ems.world/2018/01/17/jamf-pro-and-microsoft-ems-better-together-part-1/ ](link URL) The issue I’m having is with enrolling the user into intune.User hits Self Service to load the company portal, user logs in with their AD account and then the Jamf Native macOS Connector keeps asking for approval by an admin. Why?!? Message is in dutch, sorry about that: Hope there is somebody who can point me into the right direction. Thx.
I started using the new API. For now I'm using basic authentication (with my personal acount) with /v1/auth/token to get a Bearer token. Works like a charm.However, I really want a seperate account, because the scripts run on a seperate VM.However, I just can seem to find an account manager for Jamf Pro. So my questions are:Where do I find the account manager to manage the users which can login to our Jamf Pro instance (xxx.jamfcloud.com)Is the basic authentication + auth-token a good way to authenticate on a standalone VM?
Guys, We have installed 3rd party Root CA and Enterprise CA cert in keychain via Intune mdm and those are showing as non-trusted. Now I would like to know how to make those cert are trusted using shell script. Kindly help. Thanks.
Hello All, I was just curious to know why I am not able to convert the source for MS Office package, MS Edge etc.It is not creating any issue but I am just curious to know this? Vendor do they make something like restriction so that it cant be converted into source? If yes then how?
Sometimes, I notice app owner provides .app file instead of .pkg, what is the best way to deploy this .app file on macOS through Jamf?Should install the .app file on my test mac and drag and drop into my Jamf Composer and build as .pkg for deployment through Jamf?Or do we have other best way to do it? Like as any command line or something else?
Inventory PreLoad does not reflect the room number in search computer though it is uploaded and does show it in the Preload Inventory though. What am i missing here to ensure that the preload inventory does reflect in the device information
Hello All, I deployed the SUPERMAN, when I ran this policy on mac, multiple dealine options are not coming, I am getting only Restart and Defer option on display message. If I click in Restart it is telling that software updates/upgrade failed and this time mac can not be restarted. Please help me on this.
Hi all, it's really great to finally have the ability to have Azure as a Cloud Identity Provider in Jamf Pro. Now i have all my Mac and Azure User information in one place, i'm wondering how this be brought together? Specifically we're wanting to populate the 'User and Location' information for each Mac with the relevant information from Azure. Unfortunetly this doesn't seem to happen automatically. Has anyone found a way to do this yet?
Hi there team, I'm new to this community and first of all I would like to say "Thank you" for all the support and help you provide; Can you please help me to know if there's any solution on this? Once I send the wipe command over the JAMF PRO platform to the device, the device reboots and enter to the recovery process but there's always a connection error apple error 5101f, 2003f, 2100f or 3001f ? i though this was some kind of update issue as many of the users that use to have an old version i.e 13.3.1 face this situation but lately this has been presented while processing a wipe process on the 2018 device with Ventura 13.4.1 or 13.4, Any help will be highly appreciated :D
Hello, I inherited jamf Pro and am wondering how I get rid of this notification in the Self Service application:"You must accept your organization's invitation. You will not be able to install apps or books purchased in volume until you accept this invitation."We dont purchase any MacOS apps via Apple, so is it just a case of removing the details under Global > Volume Purchasing? Thanks
Hi every one,so since macOS Ventura we can set login items to not be disabled by the user with the "Managed Login Items"-preference.But is there a way I can prohibit some specified launch agents to be loaded at all?Kind regards, Matthias
Hello. I've been tasked with forcing a homepage to stick within Google Chrome. I've seen many discussions, and many paths to try to manage this task. Unfortunately for me, none of them have worked. Many of these paths have taken me to places I'm not familiar with, so there has been a lot of learning needed. This is what I've tried:Managed Preferences : (MCX?) - https://www.k12techsystems.com/2014/11/using-managed-preferences-mcx-to-block-or-uninstall-chrome-extensions/https://www.jamf.com/jamf-nation/discussions/12520/chrome-managed-preferences Changing Google Chrome Manifest - http://www.chromium.org/administrators/policy-templates Chrome Policy - http://www.chromium.org/administrators/policy-list-3 I'm actually not sure how this is implemented. Configuration Profiles - These don't seem to apply to Chrome. This page looked like it would be the most helpful, but nothing I tried worked. https://www.jamf.com/jamf-nation/discussions/9868/chrome-homepage The most promising thi
Hello Jamf people, we have recently migrated our on-premises 10.46.1 Jamf Pro to another server (Ubuntu 18 to Ubuntu 22), and everything seems to be working OK, however all clients reporting localhost IP address now - 127.0.0.1, while previously it was their actual IP address.It might be related to Apache proxy we've got running on that server as well - it was migrated to the new one with exactly the same configuration though.Is it possible it's something JAMF related or we should keep looking more into Apache config? Did someone else face this kind of issue before?Thank you!
Hey everyone this is a dumb question, I want to add the latest version of zoom which is 5.15.2 but when i go to patch management i see 5.14.7 how do i update it to show 5.15.2 so i can upload the PKG file
Howdy!We have Jamf Pro hosted in Jamf Cloud. I am not sure when this started, as this matter was brought to my attention by another team member. However, our Change Management logs are flooded with entries from our VPP Account supposedly editing our VPP object. Screenshot:I did some searches but I could not find a similar issue. The problem is that each of these entries, if I click on the Details button, show the exact same data. Seen here: This entry appears every minute. It is making auditing nearly impossible because it is flushing out previous entries that are actually team members making changes.How can we fix this?Thank you.
Does anyone know what flavor of regex is used by Jamf Pro? I've been using PCRE for my patterns, and haven't had any problems (that I know of,) but would like to get official confirmation just to be sure.
At Jamf, we value transparency and giving you greater control over your information. As such, we are writing to inform you that we’ve updated our Privacy Policy. We encourage you to carefully review our Privacy Policy, particularly if you reside in California, as it contains specific information about your California privacy rights and how Jamf collects, utilizes, and shares your personal data. Additionally, with the expansion of our product portfolio, we have revamped and enhanced the way we offer information regarding our products and services. You can find our list of sub-processors in our Trust Center or by clicking here. If you have any questions about these changes, contact privacy@jamf.com. For more information about our privacy program, please see the following: Data Processing Agreement for Customers Data Processing Agreement FAQs Information Security Schedule Privacy Policy All the best, Jamf privacy@jamf.com
In my environment, we use Jamf connect and user ID is the user account created as UID 501 by default, no other local account creates here, my question is how SUPER can install pending Apple updates on Apple Silicon mac devices with existing local user account? I dont want to create a service account or Jamf API account. How can I take the decision for script parameter to set in my policy, for what parameter what string I need to put there? All these are very confusing. Please help me on this.What does --reset-super parameter do? I did set under script parameter 6, every time I ran the super policy on my test mac it still saying n number of deferral remaining decreasing by 1, whereas I was expecting that it should reset and show me as N number is remaining which I did set in my config profile a deferral count.
Hi folks, Can someone help me with an EA that can collect information on if someone is logged into iMessage? Thank you,
Here's what you need to input into the "OAuth Sign In URL" and "OAuth Token Request URL" fields for the Exchange ActiveSync device payload for when you need to account for modern authentication: OAuth Sign In URL: https://login.microsoftonline.com/ENTER-THE-TENANT-ID/oauth2/v2.0/authorizeOAuth Token Request URL: https://login.microsoftonline.com/ENTER-THE-TENANT-ID/oauth2/v2.0/tokenTo find the Tenant ID: Go to Portal.azure.com > Azure Active Directory > Properties. The ID it shows there is your tenant ID. Enjoy.
Since we got the last Mac OS update Ventura, we have been having this failed command in Jamf Pro. Could someone help us :D
Hi, How do we create a smart group to identify devices with no Site assigned ?
Scenario: Large school with students using mainly macbooks, work is saved to OneDrive. Students are often breaking their OneDrive syncing by using illegal windows characters in file names (word docs ect) causing sync errors and are then requiring a manual fix by IT Staff renaming the files/resolving onedrive syncing. All devices are MDM enrolled, is it possible with Jamf Pro to disable the ability to use special/specific characters when naming files. I did see the following post: Solved: Any way to create a policy to prevent users from u... - Jamf Nation Community - 108934 that hinted it wasn't possible, but this is now several years old and things may have changed. Thanks a lot,JM
Is there an application out there that lets you connect to WiFi before logging in? We have Jamf Connect, but I'm looking for a standalone app to use until it's rolled out completely. We would like to mimic our Windows environment where you connect to WiFi then VPN and can login with AD creds so our techs don't need to reset a user's password when building a new device.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!