Get Support
Recently active
I guess I am not the only one that is tired of adobe bad update options.I know adobe remote update manager exist - but that is only working for patches.What about new versions - what is the best practice to push them out - and even more, how do you remove the old version, that is not auto removed during update to a new version
We have a machine in JAMF randomly start to get this “different server URL” error. We have unenrolled and completely deleted it from JAMF. Re-enrolled, works briefly, then back to this error. Any thoughts?I have seen others state this is a JAMF "issue" and the only way to resolve is to erase the machine and restore from backup. This is a rough and time consuming solution, curious if there's anything else we can try.
This is our first JAMF Pro instance being hosted in the cloud by JAMF and we've been hitting roadblocks while getting it set up for the first time using our on-prem Microsoft AD LDAP server. The first block was a firewall issue where it wouldn't proceed past the "Enter Server Info" step using the LDAP Server Assistant. We've got that sorted and it proceeds to the next step of "Enter Credentials," but that is where we are currently stuck and support emails haven't provided much insight and it seems this step isn't a big enough trouble point to be online on forums. We're using SSL with a cert generated from Digicert(also attempted a self signed cert from the server, but can try again if better instructions are found). I've created an AD Service Account just for this connection and have confirmed it exists. I've also tried my personal AD account and it still states "Could not find user." What are we missing here and how can we determine the point of failure?
Hi EveryoneDoes anyone face this issue? My policy is working (app install) with Recurring check-in but not working when i am trying to install same app (no matter what I creat package in composer or download from 3rd party website) on endpoint. So, any help is appriciable.
The Jamf cloud team is working on an effort to improve the infrastructure of the Jamf Pro cloud environment. This is part of a continued effort to always provide you with the latest features that are available from our Amazon Web Service (AWS) environment, most notably to improve reliability and scalability to reduce environment downtime and better serve you as a Jamf customer. As an incremental step in this process, we are planning to migrate all Client Not-for-Resale (NFR) Jamf Pro cloud instances on Saturday, July 8, 2023 (starting at 12:01am) which will require a small outage of any NFR instances. Note: this will NOT affect any Production instances. Thank you, Jamf Cloud Team
Hello,I'm currently configuring all things Jamf for my company and am having some trouble with DisplayLink. Currently I have configuration profiles set up to allow standard users to permit screen recording on Teams, Splashtop, and Zoom. So, when users are prompted to allow screen recording, they don't need to be an admin to do this. I tried the same method on DisplayLink, but it remains greyed out. Is there an extra step like allowing a Kernel or PPPC for this to work? See the screenshot and if you need more information, please let me know!Edit: Resolved. The profile I uploaded was corrupted. New profile with the same configuration was used and it worked fine. Thanks in advance!
I've noticed there isn't an option to force the enablement of Location Services on a Mac. I've opened a ticket with Apple and they said this is by design for privacy. I can completely understand that on a personally owned Mac, but for a corporate owned asset, we should have full access to the device in case it's lost or stolen and we can tell the last place it was, which means enabling location and not letting someone turn it off. People don't have any expectations of privacy with work computers and things like email or what applications are installed, I don't understand why Apple is drawing a line in the sand with location. Am I crazy for thinking this should be an MDM option?
Today we are releasing Jamf Pro 10.47. Highlights of this release include: Enrollment SSO with Okta VerifyEnvironments using Okta as an identity provider can now configure an Enrollment single sign-on (SSO) workflow to augment the Account-Driven User Enrollment experience. App Installers Enhancement: Availability in Self ServiceWhen distributing software titles from the Jamf App Catalog to a smart group using App Installers, you can now make the app available in Self Service for end users to install when they are ready. After installation, the app is automatically updated when a new version is available in the Jamf App Catalog. Customizable Self Service Buttons for Mobile Device AppsYou can now use the Button Name Before Initiation and Button Name After Initiation fields in Jamf Pro to customize app action buttons in Self Service for iOS to better suit your users. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. T
Hi ev'ryone.We are using the import of placeholders regularly. We would like to use the API instead, because the import files are already generated by a selfwritten program, which could send the data direct to the API - instead of having the user switch to his browser and interact.Sadly, I was not able to find a solution which fully supports our needs as- it is only possible to update existing placeholders (POST for nonexisting serial responses "success: false, message: PlaceholderNotFound")- no support for updating the "locationId:"-value (POST seems to ignore this param)-no support for "AssetTag" (which is also missing in GET ADE Device-call) If anyone encounteded that case before - hints and suggestions are welcome. Thanks.Marco
Hi,I find the new design of Jamf Nation very confusing. Where has the support section gone. I need to log a support ticket and can't find where it is now done. I can't even find my old tickets. The last thing people with an issue need is not to be able to find out to report a problme. Anyone with help please? Updated: found the answer https://account.jamf.com/support
Hi all,I am new JAMF admin and need some insight about the issue that we are facing in our environment. On few of the newly procured MacBook which are already MDM enabled, we are receiving the below mentioned casperadmin login screen instead of standard remote management screen. The only workaround that I can apply is to remove the enrollment server from ABM and then add the server back. However, this does not work everytime.Has anyone seen this issue and would really appreciate any kind of help. Thanks
Hi all, I am deploying zimperium and they have integration only with Jamf Pro.Will it work also for my Jamf School devices? Or is it totally different? Thanks!
Hello,I'm fairly new to jamf pro / protect and just took over partial responsibility for a tenant. I noticed, that lots of devices do not have the most recent Protect version, even with "automatic updates" enabled. (Most of them on os 12+)They check-in daily and I can see them as "connected" in Jamf Protect. Do I have to push the updates manually or is there something else at fault I haven't thought of?Thanks,Georg
I use a script that configures and activates remote management. It uses the kickstart command to configure it and calls an API to activate it. But I have 2 problems.The first one is that it should activate the remote management with all privileges for the admin account, not for everyone. But sometimes, despite the fact that I see the admin account in the "only for specific users" box with the right setup, the radio button for "All users" is active. I was thinking that it may be due to the fact that I never logged in into the admin account but it's not true as it works most of the time.The second one is that sometimes, I get the error "Connection failed. severUnableToReadScreenMessage". I don't know how it may happen in Monterey, but it seems that a "tccutil reset All" breaks it on Ventura. I sometimes need to use that command to be sure that my pppc profiles are good and not because I allowed access to the app. Of course, I use that command in my test lab. What I need to do is to use t
Here are the direct Apple CDN download links for the Safari 16.5 update released today (2023-05-18) for macOS Monterey and Big Sur:Monterey: https://swcdn.apple.com/content/downloads/46/42/032-63972-A_STXDTZU8QO/q8fdl64hobp69ahribtrieag6r3086hvy6/Safari16.5MontereyAuto.pkgBig Sur: http://swcdn.apple.com/content/downloads/27/11/032-63973-A_V5EERCMLQS/8uk80mv3nd7zt40dw3k8ok1vrynvytj2s0/Safari16.5BigSurAuto.pkgThe Safari 16.5 update for macOS Ventura is part of the macOS Ventura 13.4 update.Note that I have not personally tested these installers as macOS Ventura is now the minimum support version of macOS for my org.
I've been using DockMaster for quite awhile and it's great up until a new OS comes out and Apple changes the name or location of an app which I realize isn't a unique issue to DockMaster however if I could set static apps with dockutil then I'd only have to modify the parts of the script that need changing whereas currently with DockMaster I have to reconfigure the entire dock on the web interface since it doesn't save your config, then generate a new pkg, upload it to JAMF, modify my policy etc.So the question is, can Dockutil set static apps? Currently I set our self service and school / state assessment apps as static on the dock so I can guarantee every student has the app on the dock in the same place when its time for testing, everything else can be changed by the user.Here is a sample of the plist generated by DockMaster that places those static apps.<key>static-apps</key> <array> <dict> <key>tile-data</key> <dict> <key&g
we have tested Jamf Connect with Okta for password sync in Mac with network password. its goes well except password expires count. its not refresh immediately after changed password. it took some time(nearly 45 minutes) or we need to logout from Mac then login back (if in company network) or reconnect VPN (if outside of company network). any command to for update count after password change. we are using Kerberos here.
Vacancy Open & closing dates : 06/26/2023 to 07/10/2023SummaryThis position is in the National Marine Fisheries Service (NMFS), Northwest Fisheries Science Center (NWFSC), Operations, Management, and Information Division (OMI), with one vacancy in Seattle, WA.This position is also announced under vacancy number NMFS NWFSC-23-12007036-DE, which is open to all US Citizens or Nationals. You must apply to both announcements if you want to be considered for both.DutiesAs an IT Specialist (Sys Admin), you will perform the following duties:Responsible for managing and supporting enterprise Apple computers. This will involve leading the NOAA Fisheries Mac Desktop Working Group and providing guidance to other Mac system administrators within the organization.Documenting and communicating processes to other IT professionals, developing Apple security baseline policies, and administering Centrify Privileged Access Management and JAMF Pro Apple Device Management servers.Automati
Hi y'all,We are facing a mayor issue when registrating our devices to Intune for compliancy.In the Self Service portal we initate the registration process,Company Portal show, we log in and Company Portal states: You're all set! Then JamfAAD opens with the message: To Complete the registration process, do the following. Safari starts up and shows the following question: "JamfAAD" want to use "microsoftonline.com" to sign in. When we sign in, the screen keeps loading and after a while Safari shows a error: This connection is not private. From there on, there nothing we could do and the process seems to break. When we close the browser and start the whole process again, everything works fine. Why does this not work directly? Please hulp us.Leo
We are having an issue with all new enrolled IOS devices. The device is being enrolled correctly, but when we attempt to open self service we get this error. I have verified that we have enough licenses from the VPP. Self service is running properly on our computers just not on IOS devices.
Hello, I'm hoping someone else can guide me towards a better workflow for wireless radius certificates and JAMF. Our current process is that once a year, we renew our radius certificate (publicly signed) and add it to a certificate payload configuration profile a week before the old one expires. We email all our employees and students to let them know that at some point, their phones and some Macs will prompt with a popup to trust the new certificate.But, with it being a near certainty that Google will soon require 90 day max certificates, followed by probably 10 day certificates, we'll need to find a way to full automate the process so that wireless continues to work. We should be able to ACME to renew the radius certificate itself, and then presumably use the JAMF API to move the certificate to JAMF and configure anything that needs it.Does anyone already have this running in a non-painful way? If so, will your process work for 90 day certs, and are you willing to share it? Or, does
Hello! I'm moving a client from a macOS file repo to Synology NAS. I'm having trouble mounting the repo with Jamf Admin. Manually mounting in Finder or on Windows works no problem with these credentials. Is anyone doing this in 10.47.0? I saw a couple of threads where people were trying to put / in front of the username like a Windows SMB login but had no luck there.
Hi,I have been asked to report the initial OS installation date and user profile creation dates for Macbooks. I couldn't find a way to do this with Jamf Pro. Is there a way to get this with a script to be run through Jamf Pro or Jamf Pro?
We have SSO enabled which works great. However, I need to create a local account that will use the ?failover url. This is an account for an intern so I can't make it an admin account. I created a custom account with the desired privileges but every time we try to use the ?failover url, we get a access denied. Our backup admin account for the ?failover url works as expected. What am I missing?
Hello All,Need your help, i have Apple script which will update the macOS for both Intel and M1 and restart if it's M1 it will prompt for the user password to install macOS. now it's working fine when i run from Apple script editor.But i need to convert the Apple script to run as bash script so that we can push from JAMF.=========================================================================================# Launch software Update preference panedo shell script "open x-apple.systempreferences:com.apple.Software-Update-Settings.extension"tell application "System Events"repeat 60 timesif exists (window 1 of process "System Settings") thendelay 3exit repeatelsedelay 1end ifend repeatif not (exists (window 1 of process "System Settings")) thenreturnend ifend tell# Click "Update Now" or "Restart Now" if presenttell application "System Events"tell process "System Settings"repeat 60 timesif exists (button 1 of group 2 of scroll area 1 of group 1 of group 1 of group 2 of splitter group 1 of
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!