Get Support
Recently active
Hey guys, i'm completely new to Jamf and still trying to find my feet there, I have configured PreStage enrollment and it works fine but I want to enable SecreToken on the management account. During the setup assistant user creates an "admin" local user account for themselves and login so they get SecureToken enabled on their account so how can I enable it on the management account that got created using PreStage enrollment process ? I tried this sysadminctl interactive -secureTokenOn "management account" -password "password"but it returns this error in the screenshot
I am not able to change the text for sunHeader, instead of local IT team I want to put our own internal IT support team name, but no effect. Also it is not picking up the company logo but picking up the default Apple logo yet the logo has been deployed on the mentioned path and text has been modified in my config profile, any idea why it is happening and what is the resolution?
Hi Everyone, I was wondering if you can assist me on this matter. I'm trying to setup Nudge and I'm going with option 2 on the GItHub site. My question is, how do I add a Smart Group into a Scope? The only options I have are All Computers or Specific Computers? I was trying to attach a photo to this post as an example but community.jamf.com website is not letting me upload a screenshot. I hope this made sense. Thanks,Rony
Hi everyone!Recently we faced with a problem - one of the user after enrolment in the Disk Encryption tab don't see Recovery Key, it says Disk Encryption Recovery Key Status: Not PresentRest of the user normally encrypting and receive recovery keys for restore.now we have problem - user laptop asked for reboot after some actions and macbook asked for the key. but in the profile its empty, but status is encrypted. Pls kindly assist! How its possible with jamf to decrypt this mac and hard drive?? is there any way? Thank you in advance! Best regards!
So I am testing re issuing filevault keys. We have a few macs encrypted but no key. I have found that I did need a new configuration profile for High Sierra and after setting that up I am able to start encryption and get the key escrowed toy the server. But if I try to re issue this key I keep failing after regenerating the new key. I get this errorSuccessfully prompted for Mac password.<br/>Issuing new recovery key...<br/>[WARNING] FileVault key was generated, but escrow did not occur. Please verify that the redirection profile is installed and the Mac is connected to the internet.<br/> As the key gets there for a new install doesn't that mean the re direction profile is installed properly. Same setup works properly in Sierra. Any one got this working ?
Anybody else noticing that the macOS 13.2.1 update is causing machines to boot to system recovery? I had 1 user report that it booted to recovery, but they were able to reboot it again and it was fine. Another user had to enter the recovery key. I think they were both m1 Macs, and used Nudge (current version) to initiate the update process.
I push Microsoft Authenticator to all my iPhones as a managed VPP app.I want to set a configuration to disable App Lock in Microsoft Authenticator. How do I obtain the PLIST necessary to do this? Jamf says "For help generating the PLIST file tor preferences, use AppConfig Generator".I managed to find the "AppConfig Generator", but it requires a "specfile" file... I'm stomped, no idea where to get this from. I googled, can't find anything remotely useful.Does anyone have any suggestions please?
Hi!Does a device have to be logged in, in order for jamf to check in and to run policies? I am trying to schedule a wake up and have the device check for policies and run them over the weekend.Thanks!
Hello!We've noticed that some users' screen savers are turning on while they're in a Google Meet. This only seems to happen when the user has their camera turned off during the meeting. It's occurring on Chrome, Safari, Mozilla, and the PWA app.Has anyone else encountered this issue before, and if so, how did you resolve it?
I'm using JAMF helper to display a message on the users and I have set two buttons named "Yes" and "No" (it doing nothing as of now), i'm asking if there is a way to record what button user clicked and report it to jamf pro? or record it on the users laptop and get it later.
We’re migrating Macs from our old JSS to a new JSS. The Macs in the old JSS are encrypted via FileVault 2. There are preexisting Macs in the new JSS that are also encrypted. Since the FileVault 2 policy in the new environment is set for all computers and users with an ongoing frequency, what is the best way to generate new keys for the migrating Macs (keys are redirected to the JSS via top-level policy)? I do see policy for ‘Disk Encryption - Issue New Recovery Key’, but doubt that this policy should also run alongside the FileVault 2 policy. I think a Smart Computer Group might help, but its criteria is allusive. Does anyone have any advice? It’s appreciated!
Hi everyone, We have 2 JAMF Pro environments that are mirrors of each other – DEV and PROD.Our endpoints or DEP enrolled and FV keys are stored per environment. Without wiping and re-DEPing can anyone advise on an automated workflow to move devices?Some insight in re-escrowing the FV keys without decrypting and encrypting would be a win.*We are enabling FV using config profiles. If anyone can provide some insight, that would be much appreciated.
Hey guys, just checking to see how the new update is settling in before I make the jump. We have our JSS on a Windows 2016 server. Would move from 9.98 to 9.101. Thanks!
So I have machine that I am migrating from Workspace One to Jamf Pro. Is there a way to leave FileVault enabled after unenrolling from Workspace One - and then having Jamf Pro issue a new recovery key? Hoping to do this with zero touch.I am researching how to turn off file vault via Workspace One at the same time.
Hi Community,I have a issue with unknown filevault recovery key in Jamf. The script does not run or is blocked somewhere.The smart computer group is :Computername like "***" (and) filevault2 individual key validation (is) unknown. Has anybody successfully made a script to get the filevault recovery key that works? Thanks, Arno
Every once in a while, we will see a system fall into a boot loop. Not a problem. But something else is up when you start to see it every few days. Every time it is a com.jamf.reboot.xxxxxx.plist or something like that. It is not rocket science to fix it when every system is on Prem, but what to do when they are off-site far far away. We have them start their systems in Safe mode. While they do that, we add them to our boot loop policy and have them run the script from Self-service. You can have it run in the background as well. The script is simple. it looks for any plist that has the word reboot in the file name and removes it. After that we restart the system and hope that it worked. so, far 99.99% of the time it works. Here is the shell script: #!/bin/bashfor path in /Library/LaunchDaemons /Library/LaunchAgents; dofor file in $(ls -1 $path | grep -i reboot); dosudo rm -rf $path/$filedonedone
Is there a terminal command to do this? I made one change to my 10.7 config profile in the JSS and resent it out to all machines but the few I've checked don't have the new preference enabled. I have tried rebooting and logging in/out a few times on the machines in question. Best
Hi all, Apparently* after upgrading to 13.4 my users are receiving the following error when trying to print. The users are all running with active directory "mobile accounts" and previously had no problems printing. If an admin account is used to print on the machine, the "mobile account" users no get the message and are able to print just fine.If a script is used to print as an admin account then the users are are able to print but still receive the message. Has anyone else seen this on Ventura 13.4 ?(I am aware there have been issues on older versions, and I would prefer not to make users print administrators) * no one has mentioned it previously so I believe this to have been introduced between 13.3.1(a) and 13.4
When I push the Configuration Profile with Jamf I get all (?) marks. But when I install the Configuration Profile local it works.
is it buggy? many issues? does it mess with your production network?
Hey Everyone,I'm looking at setting up DEPNotify again but I'm wondering if this is the best way to go with Apple's changes they've made and DEPNotify hasn't been updated in a while. What I do like about DEPNotify is that you can pop it before logging in. Looking through the MacAdmins Slack I see reports of the window getting cut off and there isn't really a way to resize it per the channel. This isn't really a deal breaker but appearances, right? There are suggestions for Dan Snelsons swiftDialog - swiftDialog. I saw his post on here a month or so back and it looked like a good alternative too.I know of IBM Notifier, DEPNotify and swiftDialog. My goal with either of these assistants right now really is to just capture some input from the tech to set the Device Name and preferably Asset Tag so the machine can get the right policies based on the naming convention of the device. Connecting it to my Jamf Pro instance via API is not necessary right now hence Asset tag is preferable. I
Hello everyone,We're about to convert our eDirectory to AD and will at the same time (finally) level up to Office 365. Today we only have local accounts on the computers but wish to have a more network based login or sync. I know that Jamf Connect is available but I don't know if it fulfills our wishes.Is there a solution so that you can log in to the computer with an Office 365 account? If so I would be very happy for more information, guides and/or links. :)Thanks.
Hello Jamf Nation, We are working on a project to require all of our users to update their passwords lengths from 8 digits to 12 digits. I already have a configuration profile setup for the minimum passcode length (see below).Additionally, I have a script setup in a policy to grab the user ID and set the device to require a change of password (see below)# Pulls the current logged in user currUser=$(ls -l /dev/console | awk '{print $3}') pwpolicy -u "$currUser" -setpolicy "newPasswordRequired=1" My question is, is there a way to add to my script to check the length of the current user password and if it meets the password requirements, to skip and not require a password change?
Hello jamf nation members,I'm facing a challenge and I'm hoping someone here can help me. I want to add a user to an MS Teams channel using a static Jamf computer group and Power Automate.Specifically, I want to set up a workflow that automatically adds a user to a specific MS Teams channel when their computer is added to a static group in Jamf. The idea is to grant the user access to the corresponding channel automatically once their computer meets certain criteria.I'm unsure about how to configure the flow in Power Automate to add the user to the Teams channel. Has anyone here solved similar tasks or has knowledge about connecting Jamf, Power Automate, and MS Teams? I would greatly appreciate your help, suggestions, or advice.Thank you in advance!Best regards,Paul
Hi All,looking for some guidance,I have approx 200 systems that where removed from JAMF via script but still have a old MDM profile. I need to get these back into a working state with a valid mdm profile. Is the best way to fix = Wipe / Re-image -> DEP enrolment or is there another way to fix it ? via script or local steps?ThanksRob
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!