Get Support
Recently active
I'm trying to create a webclip that will be able to include the serial number. IEhttp://www.someurl.com/?=[Serial Number]
I'd really love to use my newly learned API knowledge in scripts that would be immensely helpful. The main use would be for a policy to run a script that collects all kinds of various system information and saves that info in various text files and then those zip files are zipped up into a single .zip file. I got that part figured out. The part that's tripping me up is how to use the fileuploads in script form. If I run the following command manually in terminal, it works fine. curl -sku USERNAME:PASSWORD https://jss.company.com/JSSResource/fileuploads/computers/id/100 -X POST -F name=@/PATH/TO/FILE The problem is that in order to run this in a script, I have to input the username and password - a huge no-no. I figure there's gotta be a way to encrypt the password for the script. I've found lots of articles that explain how to run commands on my local admin Mac to create the encrypted PW. The problem is once I have that info, then what
During setup of a new mobile IOS device, I am prompted for the region or country. The answer is always the same- United States for us. Is there any way to set a default country or region instead of scrolling through 10 pages of options? I've looked through the pre stage enrollment settings and didn't see anything. Thanks in advance,Robert
Hello All,How can I find the URL to download a package from URL using by curl command, I opened the URL to download Google Chrome installer for mac and then stop it download through GUI and copied the URL and opened the terminal and putted the command curl -o URL of GC source, it is giving me error saying zsh: parse error near &Any idea how to find the correct URL for curl?
Welcome to the new centralized Jamf Release Info space. This will be your one-stop shop for news about Jamf Pro and Jamf Connect releases. We encourage you to continue visiting the Jamf Nation Community Product forums to connect with fellow community members. In Release Info, you will find: Release announcements Jamf Pro cloud upgrade schedule Jamf Pro Release Notes video Jamf Pro knowledge quiz We recommend you post in the comment section on a Release Announcement to communicate about the update and any questions, comments, or celebrations you may have.
I'm testing out the Remote Wipe command for a computer ahead of needing to wipe a handful of remote devices in the near future.I've triggered the command on a test device I have at hand; I enabled 'Remove Activation Lock' as the device is actviation lock enabled, and I set a wipe passcode of 123456. The test Macbook almost instantly shut down and device logs in Jamf show that the command was successfully deployed. However the device is now stuck in a loop of prompting me to enter a user account password in order to unlock the hard drive (filevault is enabled). When i enter the user password the device shuts down, boots back up after a moment, then I'm re-prompted to enter a user password. I've gone through this loop a dozen times now.When I enter an incorrect password, or the wipe passcode, the pop-up doesn't accept the password. I can still boot the device into recovery mode and wipe the device via Disk Utility, but this is not the ideal solution for my situation.This
As we all know Jamf introduced us new LAPS solution. I have created EA to read local admin password. In order using actively LAPS auto deploy must be enabled. You can read this jamf article for how to enable Jamf LAPS -> https://community.jamf.com/t5/tech-thoughts/how-to-securely-manage-local-admin-passwords-with-jamf-pro-and/ba-p/289969. #!/bin/bash # Reading JAMF Laps password # Author: A. Collins username="api username" password="password" url="your jamf url" localadmin="local admin account that deployed in prestage" serialnn=$(ioreg -rd1 -c IOPlatformExpertDevice | awk -F'"' '/IOPlatformSerialNumber/{print $4}') #Variable declarations bearerToken="" tokenExpirationEpoch="0" getBearerToken() { response=$(curl -s -u "$username":"$password" "$url"/api/v1/auth/token -X POST) bearerToken=$(echo "$response" | plutil -extract token raw -) tokenExpiration=$(echo "$response" | plutil -extract expires raw - | awk -F . '{print $1}') tokenExpirationEpoch=$(date -j
Hello,We have some students that we want to be blocked in a given app. We would also like to have some way to disable the single app mode from the device itself to allow Technician/Teachers/Specialist/Parent to perform basic task on the device (web search / apps backup / etc..).I know guided access can allow a passcode to disable the restriction but this is not configurable in jamf. Access to jamf to disable single app mode for the iPads is not an options.
Is there a way to disable users from changing the computer name. We have students that are constantly changing the computer names.
Hi Everyone, My default browser right now is Chrome. but I don't have a problem with that. However, the following screen appears in some of the users I have installed Company Portal. When it approves this, it redirects to a page and asks the user to login to Microsoft. This happens randomly and is very disturbing for us. Does anyone know why this is happening and how to fix it?
Hello Jamf Nation... Question regarding BYOD options in JAMF Pro: We are a financial services company with a strong focus internally on security for our customers. We are working on beefing up our cell phone policy. Here's what we're looking at:-Allowing BYOD devices - we need to be able to limit screenshots from apps containing sensitive corporate information. Android devices are able to do this by creating a separate work profile. -Denying BYOD and distributing corporate-owned cell phones - This will be the easier option for the company, but not so much for end-users. We could just lock down screenshots on this period. I am trying to find a way to implement screenshots on just the corporate apps. JAMF support told me it's possible, but I'm not sure they were correct. They said something about using the screenshot blocking with app restrictions, but it looks to me like those two settings are mutually exclusive,
Hello, I went and looked through all similar threads but didn't find any experiencing my issue. I tested the 'Wipe" feature on my Macbook before performing the command on a user who locked himself out of his Mac and forgot his password and had some questions about the process. When you hit Wipe, it prompts to enter a remote wipe passcode, and there is a box above that says "Clear Activation Lock". I left that box unchecked and just entered 123456 for the PIN. But when I sent the command it just nuked my machine and reset/reformatted my Mac, it didnt ask for a PIN code or display any message. Is this PIN not needed when you do not check the Clear Activation Lock box? And also, should I be checking the Clear Activation Lock? And my last question is after the factory reset, the device now shows 'unmanaged' in Jamf Pro but on Jamf Pro's website it claims that the Wipe will not unenroll the device. So theoretically if I had done this on a
Hello, we are testing Jamf Connect, and one issue we run into is after you change your AAD password, a Jamf notification will show in the MacOS notifications stating your passwords are not in sync. However, a lot of us use Focus Mode and do not see the popup, and user's will often ignore their notifications because you get so many of them throughout the day. How can we force that Jamf password sync notification to automatically open after Jamf detects passwords are out of sync, instead of being a passive, ignored notification? Thanks!
Hi,since iOS 16.2 Apple changed the Airdrop option from "Everyone" to "Everyone for 10 Minutes".We use Jamf Pro in a huge educational enviroment with the Classrom-App. The problem is that teachers can´t send documents to students after the 10 minutes have elapsed. So every student has to change the setting again after the time period which is not practicable.Any hints to fix that problem or any workarounds?thx,Markus
Hi allHoping someone can assist with this. We are running PaperCut MF and have the print client on our Macs. When a user sends a job to print they get the pop up confirmation with the correct pricing information and the job comes out of the printer, but in the job log of the printer in PaperCut, we see the user that printed the job was service-jamf-scripts and not the actual user that sent the job.Has anyone else seen this or point me in the right direction to start investigating? Thanks, John
Hi All,Has anybody have reports of 13.4.1 upgrade fail when trying to upgrade via software upgrade?We have reports from users when it tries to begin the download and fails ...I have seen Apple Dev bug - Can't upgrade to Ventura 13.4.1 | Apple Developer Forums .. Rk
I use Apple Configurator and Imazing Profile Editor to create configuration profiles.If a configuration profile was pushed out with "Prevent users from removing this profile" as true, can JAMF still remove this profile? Isn't this just so users can't remove it locally on the workstation but the MDM server still can ?Also If pushing out the same configuration profile with same Payload ID to a workstation that already has it, won't the profile just be overwritten with the newer one? Or do I need to remove it first and then push it out again if I make changes.I know I can just push out another restrictive profile but I like to keep the profiles to a minimum.Just curious on what exactly would happen. Appreciate any feedback.
Hello All,How preference domain in my config profile understand where the corrosponding plist is kept? I can keep under /Library/Preferences, or /library/Manage Preference etcBut question is how Jamf is able to understand where is the plist kept to write on it?
I am trying create a policy to uninstall Citrix Receiver on my macs. Unable to add uninstall.app into jamf admin due to error message "not being support in Jamf Admin". I little experience creating scripts. Trying to create script but unable get script to run. Wondering if anyone has script for uninstall citrix receiver
Hi All,Looking for some input .. I have been asked by leadership to add the CA enrolment to my DEP enrolment .. How anyone managed to do this successfully and how?Im currently using DEP Notify to install apps and setting but looking at it I either need to trigger the CA enrolment either before or after enrolment ... Please advise..
Hello All,Need an explanation, I did set home page and startup page by config profile, I noticed that after mac boot up it takes time to connect internet, any resolution to make it perfect ?
Hi Jamf folks, is anyone doing change control across their jamf policies? We are looking to ensure that there's no unauthorized changes to our critical policies, and that they could be audited periodically.If anyone is doing this and could point me in the right direction I'd greatly appreciate it!
Hoping someone can help me out with this - I need to drop a file in ~/Downloads when deploying software during our automated enrollment. We use Slack for internal messaging, and there is a preconfigured Slack token that will populate our Workspace URL - in order for Slack to read this file, it has to be in the ~/Downloads folder. I've set up a config profile, and given Slack access to the folder, and created one as well for com.jamf.management.Jamf to have access to the folder. It doesnt look like I have the profile for Jamf set up correctly - I can watch the Console logs and see that the package is being deployed, however, its never written to the folder. If I manually place the file there, then open Slack, it reads the token and launches the app appropriately. Any ideas on where I went wrong?
So we have been running the same JAMF instance for 9 years and 51 weeks, and it turns out that the JAMF CA itself has to be renewed after 10 years, so I've got a week to sort out the problem I'm about to describe.My problem is, we are still using a self-signed certificate, so JAMF support has told me that if I renew the CA, all my clients will no longer trust it and will have to be reenrolled. But I already know, from experimenting on my test instance over the winter, that switching over to a publicly-signed certificate *also* drops all my clients.As far as I can tell, there is no way to migrate from a self-signed certificate to a publicly-signed certificate without dropping all your clients. I have googled and I cannot find any documentation anywhere discussing any such process. My JAMF support case seems to be languishing with people scratching their heads.Can anyone point me to steps for migrating to a public certificate without dropping all my clients?(Live JAMF instance is still 1
Have you encountered any challenges in achieving CIS level one compliance for Ventura on your MacBook devices, even after pushing all configuration profiles using the JAMF Compliance Editor for Mac Ventura OS and scoping all your MAC machines to these profiles? Specifically, some of the non-compliant points include* Install.Log Retained For 365 Or More Days* Reasonable Security Audit Log Retention* Sudo Timeout Reduced* Filename Extensions Turned On* Apple Provided Software Is Current * Wake For Network Access And Power Nap Disabledis there any way we can cover the above setting via script?Thanks
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!