Get Support
Recently active
Just for anyone else who happens to stumble across this in 2023 and is like, "What does this do?" The answer is NOTHING and DOES NOT WORK. Quote from a ticket earlier that address this very question. "Thank you for reaching out to Jamf Technical Support!To summarize, the feature “Computer administrators may refresh or disable management” is not working.Unfortunately, after some investigation, Jamf created a Ticket with Apple, but this appears this feature is not going to work. We tested on our end, and it is also not working.At this point, we will be marking this case as inactive. If there are any additional questions or concerns, let us know, and reference this case number to allow for us to continue working from where we left off."
Hi there, So when jamf notified us for APNS renewal, Instead of using the apple id assigned to renew the current certificate on the one on APNS. We have accidentally used a different apple ip and created a new certificate in APNS causing jamf to produce a new certificate on Jamf with a new topic. This has caused the managed laptops and phones enrolled on the previous certificate to lose the functionality to get any remote commands from jamf. The laptops still checking in and working fine, but the remote commands functonality has been lost. We have found the original apple id which was used to renew the certificate now. My question is if we renew mdm again on jamf with the certificate that was originally used in apns, will it make those devices receive the remote commands again or will it break the entire devices to be unmanaged? Hope this makes sense, any recommendation will be greatly appreciated.
how to customize Management Action window message
Hey everyone, I'm thinking to start integrating our Jamf Pro instance with Intune just for the sake of having confidtionl access, what do you think? any issues that I will encounter? tips?Thanks
I'm trying to find what is removing/hiding the default Mail app from our devices, this is not effecting all of our devices just ones in a set of Smart groups. The devices are enrolled to JAMF via an enrolment profile that is installed via Configurator 2, the devices have the Mail app up until the enrolment profile is installed and they get their configuration profile from JAMF. I've checked the configuration profile settings and can't find anything in restrictions about disabling, hiding or removing the app. The configuration profile is also set to Allow all apps under App restrictions. Any clues would be much appreciated. Thanks
Has any one tried setting up a Synology as a JAMF Pro File Share Distribution Point with http support?
Hi all,We are in the process of setting up 802.1x, using EAP-TLS wifi authentication.We deploy a configuration profile with SCEP/Network/Certificate payload at a computer-level, since we use Jamf Connect and recently found out that we cannot push configuration profiles at a user-level as we were initially planning (the solution of re-enrolling all devices is a no-go).Everything seems to be working, but our cyber security team challenged this configuration because Macs use that certificate to authenticate to the wifi regardless of the user logged in (for example a user could create a local account and authenticate to the wifi, which apparently it's not something they like).My question is: is there any way to manage which user accounts are allowed to use that certificate? Example: only specific users, or only domain accounts?Thank you!
Hello All, I was looking for a solution to uninstall Nexthink collector from mac device, if I run the uninstaller extracting from .dmg file which contains 4 .pkg it says uninstaller” can’t be opened because the identity of the developer cannot be confirmed. Should I run rm -rf /Library/Application\\ Support/Nexthink and rm -rf /Library/Application\\ Support/NexthinkVersions or do we have a better solution on this?
Hello,once again we have the problem, that at one school the wifi key was leaked.tbh we really don't know how, because the wifi is pushed via jamfschool profile.So it cannot be viewed with IOS 16.What other settings in jamf restrictions do you recommend to prevent that?thanks
I am trying to deploy Office 365 to my clients, all of whom have Office 365 accounts tied to their email. I would like to deploy through JAMF Pro using the VPP Mac App so the apps will update automatically. My problem is the $69.99 per year page before the sign in option. I don't want my clients scared of signing in. I want them to be prompted for sign in immediately, without the purchase prompting. Does anyone know of a way to script past this prompt? Below is the Screen that I'm hoping to avoid:
Does anyone know how to deploy SmartNotebook v.23?I downloaded SmartNotebook and uploaded the pkg to Jamf Pro and created policy and set for Self Service and it fails everytime.It looks like the SmartNotebook pkg has a packaged with a tool that checks the computer to see if it is compatible to be able to install.I have a feeling that this might be causing the pkg to not install. Does anyone know how to get past this feature?
Hey guys, Is there a way of wiping a iPhone with a script ? let me know if this is possible. Thanks
is there a way to remove the recovery lock password on Apple Silicon Macs without unenrolling/erasing them?
Hello,I'm currently working on a mass deployment of Jamf Connect Login for Azure. The primary goal is to demobilize accounts on a mass scale. However, I am keen on ensuring that this deployment process is as silent and non-disruptive to our users' workflow as possible.Here's what I have for my current .plist configuration for Jamf Connect Login:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>AllowNetworkSelection</key><true/><key>CreateNewUserHide</key><true/><key>CreateJamfConnectPassword</key><true/><key>LicenseFile</key><data>*license key value*</data> <key>OIDCAdminAttribute</key><string>roles</string><key>OIDCClientID</key><string>*client_id*</string><key>OIDCNewPassword</key><false/><key>
Hi everyone,does anyone have issue with jamf connect being grey out? currently on jamf 2.6
Hi people,I'm currently testing this MS plug-in for SSO for iPads I've had some success with it - when building a new iPad, I sign into the iCloud and, when entering the MAID, it loads MS Authenticator and makes that link. Then when I open MS Teams, I don't have to input any credentials, I just tap on the account and I'm signed in.It also works with safari, but with other 365 iOS apps (Word, Powerpoint, Excel, OneNote and OneDrive), I still have to input the email address. The account doesn't automatically appear like it does in teams.Does anyone have experience in SSO in Office 365 apps within Jamf School? Attached is our current SSO settings.Thanks
Hello there, we use Apps with exam modes. The Teachers would love to control the in App functionality via Jamf Teacher.Vote here if youre interested in this feature.https://ideas.jamf.com/ideas/JN-I-27324
Hello I'm trying to set an app configuration for Outlook on iOs using : <dict><key>com.microsoft.outlook.EmailProfile.AccountType</key><string>ModernAuth</string><key>com.microsoft.outlook.EmailProfile.EmailAccountName</key><string>Mail XXX</string><key>com.microsoft.outlook.EmailProfile.EmailAddress</key><string>$EMAIL</string><key>com.microsoft.outlook.EmailProfile.EmailUPN</key><string>$EMAIL</string><key>IntuneMAMAllowedAccountsOnly</key><string>Disabled</string><key>IntuneMAMUPN</key><string>$EMAIL</string></dict> So far it's working perfectly. But i want to enable/disable more settings.So i followed the information available on microsoft website :https://docs.microsoft.com/fr-fr/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/outlook-for-ios-and-android-configuration-with-microsoft-intu
Hello, I'd like to deploy a mobile conf to setup Safari for users.I checked iMAZING , PPPC and tools are not helping much.Any one knows how to create the needed plist /mobile conf settings with tools or script ?Thanks in advance,
I've been trying to find a way to package Logic and GarageBand with all of the loops installed and indexed for each user. The apps install fine, nothing weird/crazy to deal with. I download all of the loops and extra content with both programs and make a package from them after installed; I grab /Library/Application Support/GarageBand, /Library/Application Support/Logic, and /Library/Audio, another 46GB of data there. After that I use composer during the indexing and grab a bunch of database files there in the user directory. After making a configuration installing the apps, then the content, then the index I am able to log into users and not have GB or Logic run the index (which is actually what I was trying to do in the first place); however, when I open GarageBand it tells me that a bunch of extras are missing and I have to re-download them. I run through the 6-10GB download process (with composer open) and let it install but composer only shows a few files being touched.
Here's my scenarioHave a bunch of Mac laptops we lend to students for a class. They log in with a standard user local account and then authenticate to the WiFi using their network credentials. Is there any way to terminate the WiFi connection using Jamf once the student logs off, so the next student that logins can enter their WiFi credentials?
Hey all, anyone know of a way to prevent any and everyone from enrolling a macOS device through https://our.jamfserver.com/enroll without disabling ABM/DEP enrollments? I want to make DEP the only option for anyone to enroll into our jamf and would prefer that the web address just be invalid. But turning off user initiated enrollment breaks macOS ABM/DEP enrollments. Essentially I want to hide http://my.jamfserver.com/enroll completely or make it non-functional when accessed via a browser, while still allowing everyone in our domain to enroll a new macOS device via ABM/DEP.Any tips? EDIT 12.3.02021: This comment hopefully better explains what I'm looking for. Also updated post title.
Happy birthday, Jamf! On June 10th you turned 21! But it’s not just your birthday this month. It’s also Charlie Root’s 30th birthday today! If it weren’t for Charlie, probably none of us would be here right now. Who’s Charlie Root? Digital spelunking I consider myself an amateur digital spelunker and enjoy digging around the visible and hidden files of macOS to see what I can find. Apple has hidden some iconic Easter eggs in macOS over the years. Some are well-known. Easter eggs are those delightful undocumented software features that you might stumble upon accidentally or if you’re paying a little extra attention. They’ve come and gone over different versions of macOS, but Ventura still has a few to uncover. Look closely at the Maps icon and you’ll find the intersection of the 280 freeway and North Wolfe Road in Cupertino. In the upper right corner is Apple’s headquarters, the ring-shaped Apple Park. Navigate to System > Library > CoreServices. Right-click CoreT
Wanted to share this, finally able to deploy Finale 25.5.0.259 via jamf.This does not handle the licensing part however. This is still a bit rough around the edges, bit functional for me. Two packages & one script Package One Package that copies these files to the target computer, I used tmp MacDiskInstaller25.5.0259.dmg silentInstallerChoices.plist silenInstallerChoices.plist was downloaded from https://makemusic.zendesk.com/hc/en-us/articles/115007423647-Commands-to-silently-install-Finale-unattended-installer-#installMac Package Two Install Finale 25.5 on a machine, you don't have to launch or license it, Capture / Make a package of " userssharedGIFF_SAMPLE" Install script Modified from https://makemusic.zendesk.com/hc/en-us/articles/115007423647-Commands-to-silently-install-Finale-unattended-installer-#installMac #!/bin/bash hdiutil attach "/tmp/MacDiskInstaller_25.5.0.259.dmg" sleep 30 sudo installer -verbose -pkg /Volumes/Finale/Install Finale.pkg -target /
For whatever reason, there was a day when the macadmins slack was particularly goofy & there was a call for poems. I posted this Haiku: I have a problem.Use regular expression.I have two problems. I can't take credit for the joke above, only for formulating it as a haiku. The origin goes back into the lore of computing. Here's a good summary: https://arstechnica.com/information-technology/2014/05/what-is-meant-by-now-you-have-two-problems/ The regular expression syntax is an amazing human achievement. (Really!) The addition of regex values in Jamf Pro Smart Groups (which I have used a lot) probably made the idea of using them even more appealing. Eventually, most macadmins encounter a situation where they believe regex may be the answer to their problem. Often, it has something to do with date / time stamps, or, version strings. However, there are good ways of handling version string comparisons WITHOUT writing your own regex. You should take advantage of them. Don't introduce
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!