Get Support
Recently active
Has anyone got FV2 Key Rotation working through policy for 10.13? I understand that the management account needs to be enabled for FV2 for this to work but that policy also fails for me..
I am looking for proper workflows to enable FileVault with Big Sur. Are there any new changes in 10.26 regarding FileVault configuration (current process seems very archaic) I currently use the FileVault process form the Jamf Admin's Guide and that works with 10.15 and so far with macOS 11 Another concern is escrowing filevault keys that may not have been escrowed in jamf, the Jamf FileVault escrow script works in 10.15 but not in any tests with macOS 11, is there an update to this?
Hello @elliotjordan and others! Elliot I have been using your Filevault reissue script with success, however I have one machine in particular that keeps erroring out:Running script reissue_filevault_recovery_key.sh...Script exit code: 11Script result: Alerting user washburb about incoming password prompt...Prompting washburb for their Mac password...Successfully prompted for Mac password.Issuing new recovery key...[WARNING] fdesetup exited with return code: 11.Adding personal recovery key.Error running script: return code was 11.I am a little fuzzy on what "authentication" the error is referring to as it seems like they are putting their password in correctly. There is a profile set up on their machine to redirect keys to the JSS. Any insight on where to look in this case? Strangely, I also see that there is a key in the JSS for this user, but I am thinking that it is no longer valid at this point. Any insight would be much apprecitated.
Hi, Can someone provide a plist that can be used as a baseline for UBlocker Origin extension whitelisting? It has been a huge struggle to put one together. essentially, we are trying to push only whitelisting of URLs for the extension in chrome.
Hi All We have had reports of a massive file and wondering if anyone else has seen this or is there a known defect? We are on version 9.82 In one case the file was /Library/Application Support/JAMF/81489.tmp and its size was 295.93 GB On 3 occasions the users have had pop ups their computer is running out of space, and so its not good Unfortunately i do not have access to the computer see what the contents of the file is or if it still exists. In policy history for the computer nothing is standing at all.
Hey guys, i'm completely new to Jamf and still trying to find my feet there, I have configured PreStage enrollment and it works fine but I want to enable SecreToken on the management account. During the setup assistant user creates an "admin" local user account for themselves and login so they get SecureToken enabled on their account so how can I enable it on the management account that got created using PreStage enrollment process ? I tried this sysadminctl interactive -secureTokenOn "management account" -password "password"but it returns this error in the screenshot
I am not able to change the text for sunHeader, instead of local IT team I want to put our own internal IT support team name, but no effect. Also it is not picking up the company logo but picking up the default Apple logo yet the logo has been deployed on the mentioned path and text has been modified in my config profile, any idea why it is happening and what is the resolution?
Hi Everyone, I was wondering if you can assist me on this matter. I'm trying to setup Nudge and I'm going with option 2 on the GItHub site. My question is, how do I add a Smart Group into a Scope? The only options I have are All Computers or Specific Computers? I was trying to attach a photo to this post as an example but community.jamf.com website is not letting me upload a screenshot. I hope this made sense. Thanks,Rony
Hi everyone!Recently we faced with a problem - one of the user after enrolment in the Disk Encryption tab don't see Recovery Key, it says Disk Encryption Recovery Key Status: Not PresentRest of the user normally encrypting and receive recovery keys for restore.now we have problem - user laptop asked for reboot after some actions and macbook asked for the key. but in the profile its empty, but status is encrypted. Pls kindly assist! How its possible with jamf to decrypt this mac and hard drive?? is there any way? Thank you in advance! Best regards!
So I am testing re issuing filevault keys. We have a few macs encrypted but no key. I have found that I did need a new configuration profile for High Sierra and after setting that up I am able to start encryption and get the key escrowed toy the server. But if I try to re issue this key I keep failing after regenerating the new key. I get this errorSuccessfully prompted for Mac password.<br/>Issuing new recovery key...<br/>[WARNING] FileVault key was generated, but escrow did not occur. Please verify that the redirection profile is installed and the Mac is connected to the internet.<br/> As the key gets there for a new install doesn't that mean the re direction profile is installed properly. Same setup works properly in Sierra. Any one got this working ?
Anybody else noticing that the macOS 13.2.1 update is causing machines to boot to system recovery? I had 1 user report that it booted to recovery, but they were able to reboot it again and it was fine. Another user had to enter the recovery key. I think they were both m1 Macs, and used Nudge (current version) to initiate the update process.
I push Microsoft Authenticator to all my iPhones as a managed VPP app.I want to set a configuration to disable App Lock in Microsoft Authenticator. How do I obtain the PLIST necessary to do this? Jamf says "For help generating the PLIST file tor preferences, use AppConfig Generator".I managed to find the "AppConfig Generator", but it requires a "specfile" file... I'm stomped, no idea where to get this from. I googled, can't find anything remotely useful.Does anyone have any suggestions please?
Hi!Does a device have to be logged in, in order for jamf to check in and to run policies? I am trying to schedule a wake up and have the device check for policies and run them over the weekend.Thanks!
Hello!We've noticed that some users' screen savers are turning on while they're in a Google Meet. This only seems to happen when the user has their camera turned off during the meeting. It's occurring on Chrome, Safari, Mozilla, and the PWA app.Has anyone else encountered this issue before, and if so, how did you resolve it?
I'm using JAMF helper to display a message on the users and I have set two buttons named "Yes" and "No" (it doing nothing as of now), i'm asking if there is a way to record what button user clicked and report it to jamf pro? or record it on the users laptop and get it later.
We’re migrating Macs from our old JSS to a new JSS. The Macs in the old JSS are encrypted via FileVault 2. There are preexisting Macs in the new JSS that are also encrypted. Since the FileVault 2 policy in the new environment is set for all computers and users with an ongoing frequency, what is the best way to generate new keys for the migrating Macs (keys are redirected to the JSS via top-level policy)? I do see policy for ‘Disk Encryption - Issue New Recovery Key’, but doubt that this policy should also run alongside the FileVault 2 policy. I think a Smart Computer Group might help, but its criteria is allusive. Does anyone have any advice? It’s appreciated!
Hi everyone, We have 2 JAMF Pro environments that are mirrors of each other – DEV and PROD.Our endpoints or DEP enrolled and FV keys are stored per environment. Without wiping and re-DEPing can anyone advise on an automated workflow to move devices?Some insight in re-escrowing the FV keys without decrypting and encrypting would be a win.*We are enabling FV using config profiles. If anyone can provide some insight, that would be much appreciated.
Hey guys, just checking to see how the new update is settling in before I make the jump. We have our JSS on a Windows 2016 server. Would move from 9.98 to 9.101. Thanks!
So I have machine that I am migrating from Workspace One to Jamf Pro. Is there a way to leave FileVault enabled after unenrolling from Workspace One - and then having Jamf Pro issue a new recovery key? Hoping to do this with zero touch.I am researching how to turn off file vault via Workspace One at the same time.
Hi Community,I have a issue with unknown filevault recovery key in Jamf. The script does not run or is blocked somewhere.The smart computer group is :Computername like "***" (and) filevault2 individual key validation (is) unknown. Has anybody successfully made a script to get the filevault recovery key that works? Thanks, Arno
Every once in a while, we will see a system fall into a boot loop. Not a problem. But something else is up when you start to see it every few days. Every time it is a com.jamf.reboot.xxxxxx.plist or something like that. It is not rocket science to fix it when every system is on Prem, but what to do when they are off-site far far away. We have them start their systems in Safe mode. While they do that, we add them to our boot loop policy and have them run the script from Self-service. You can have it run in the background as well. The script is simple. it looks for any plist that has the word reboot in the file name and removes it. After that we restart the system and hope that it worked. so, far 99.99% of the time it works. Here is the shell script: #!/bin/bashfor path in /Library/LaunchDaemons /Library/LaunchAgents; dofor file in $(ls -1 $path | grep -i reboot); dosudo rm -rf $path/$filedonedone
Is there a terminal command to do this? I made one change to my 10.7 config profile in the JSS and resent it out to all machines but the few I've checked don't have the new preference enabled. I have tried rebooting and logging in/out a few times on the machines in question. Best
Hi all, Apparently* after upgrading to 13.4 my users are receiving the following error when trying to print. The users are all running with active directory "mobile accounts" and previously had no problems printing. If an admin account is used to print on the machine, the "mobile account" users no get the message and are able to print just fine.If a script is used to print as an admin account then the users are are able to print but still receive the message. Has anyone else seen this on Ventura 13.4 ?(I am aware there have been issues on older versions, and I would prefer not to make users print administrators) * no one has mentioned it previously so I believe this to have been introduced between 13.3.1(a) and 13.4
When I push the Configuration Profile with Jamf I get all (?) marks. But when I install the Configuration Profile local it works.
is it buggy? many issues? does it mess with your production network?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!