Get Support
Recently active
Is there a way in a single policy to allow install on reboot or enrollment at all times but restrict install on recurring check in to a maintenance window?
Does anyone know of a way to make the Autolock time longer than default on a shared iPad deployment? Students are complaining that it locks the device too quickly when they are referencing it as a textbook.
Hey everyone, I have a question about Jamf Pro hosted on site. Currently, we host Jamf Pro on a Windows Hyper-V instance with the public IP address directly on the network adapter of the virtual server. Our Internet Service Provider has informed us that we will no longer be able to have a public IP address on the physical adapter on our equipment without major changes to our network. If we did not want to make these major modifications, we’d need to set a private IP address internally/on the adapter and use a translated address for outside access to Jamf Pro and Web services. I am curious how if we went to this Private IP how it would affect our Jamf installation. I know that I can set a custom Forward Lookup Zone in our Windows server DNS servers to make the domain work internally, but will this have any drawbacks if our Jamf Pro URL is resolving to different IP addresses internally versus externally? Is the Jamf Binary, Apple MDM, and/or macOS DNS smart enough to re-resolve the
During JNUC2020 I opened my BIG MOUTH (I do that some times) and mentioned that I manage my Network Printers with Jamf Self Service. It seems that many people want to know my secret sauce for making this happen. So I promised a write up. Time to make good on that promise! Without further ado, here's the write up... Managing Network Printers with Jamf Computer Policies and Self Service Policies You're going to need a few tools to make this happen... A network printer Printer drivers for said Network Printer A computer (Preferably a Mac running OSX/macOS) A text editor (I prefer Sublime but you can use whatever makes you feel warm and fuzzy inside) A copy of ppdOptionsDiff.command (this script is mana from Heaven I tell you!) A working Jamf Pro environment that you have more than read-only access to (DUH!) SECTION 01 - Be The Hunter / Gatherer That Your Dog Thinks Your Are PART 01 - Gather Your Tools, You Tool01 - Create a folder called "Printer Stuff" (you can call it whatever
Hi, I have written a script to install CS falcon on Mac via JAMF, but script successfully install the CS falcon on Mac system but "Falcon” Would Like to Filter Network Content" in network extension and "The System Extension Blocked message" in Security & Privacy, which need to "Allow" manually. Need help to correct the script for automatically run the process without user interaction, following script. #!/bin/bash # Set the installation parametersCLIENT_ID="YOUR_CLIENT_ID"CLIENT_SECRET="YOUR_CLIENT_SECRET"INSTALL_TOKEN="YOUR_INSTALL_TOKEN" # Define the installation directoryINSTALL_DIR="/Applications/Falcon.app" # Define the Crowdstrike bundle identifierBUNDLE_IDENTIFIER="com.crowdstrike.falcon.Agent" # Define the Crowdstrike team identifierTEAM_IDENTIFIER="X9E956P446" # Copy the Falcon Sensor packagecp /private/tmp/ # Install the Falcon Sensor packageecho "Installing Falcon Sensor..."sudo installer -pkg "/private/t
Hello,This might be something I am looking through, but is there a way to pull a full application inventory from all my Macs into one location, either in Jamf Pro or a CSV? Trying to do some application cleanup/updating and not looking forward to going Mac to Mac looking at their application field in Inventory.Thank you!
Does anyone know a way to exclude Jamf Connect from MFA in Azure Conditional Access? I have created a web redirect URI to make Azure see the app registration in conditional access but when I add this as an exclusion users are still asked for MFA. Thanks!
Hi everyone, I just reinstalled Mac OS on my MacBook Air, when I tried to enroll my MBA to JSS, it tells me MDM Capability: No I've checked my certificates, none of them expired. and just did a push diagnostic and it pass too Any idea?
Hi all, I'm trying to make our cofiguration profile work for our macbooks. I'm noticing for new Macbooks to be enrolled, I get MDM Capability = No. Verify MDM Enrollment = Enrolled. With MDM Capability = No, it mean none of the Configuration Profile would be pushed to them. I've read on past JAMF Nation discussionshttps://jamfnation.jamfsoftware.com/discussion.html?id=19266https://jamfnation.jamfsoftware.com/discussion.html?id=11948 that this push MDM actually is dependent on Apple, and running sudo jamf mdm may trigger it to work. But when I do run /usr/local/bin/jamf removeMdmProfile/usr/local/bin/jamf manage/usr/local/bin/jamf mdm all I get is Verify MDM Enrollment = Enrolled. Any other ideas on how to activate this MDM? Right now half our Macbooks have MDM, but the other half have this turned off. I'm puzzled as to what is required.
Hello Everyone, I have seen multiple discussions on this topic, but I was unable to glean anything that would solve our situation. We are using DEP and our Macs are coming into the JSS just fine. We can even use the erase install command to remotely wipe and get our Macs back to an out of box state. Somewhere along the way though, we are seeing Macs losing their MDM capability. We have tried just about everything. Granted, if I do something manual in front of the Mac stuff to restore MDM, we might be able to get things going. Something like removing the framework or taking the Mac out of the JSS. I am trying to find a way to do this remotely or the next time one of these systems checks in. MOST of the profiles seem to be loading and working. We have tried to remove the keychain pieces and running quick add again. Still no go. We have tried running sudo jamf manage, this didn't fix it. We tried to renew our MDM, still no good. I do have a support ticket open and they have
Aloha All,We are a K-12 located in Hawaii. At this time, we are prepping for Summer School, which begins next week. We have been able to set up iPad Air 4 as shared devices for the past year. Our requirements have grown beyond our inventory and are trying to set up iPad Air 3 to accommodate the excess.Following the same steps that we've done in the past, we are able to get to the Sign In screen which takes us to our SSO landing page. After entering the account password, it kicks back to the Sign In screen with a pop-up message "Sign In on a Managed Device. This account can only be used on a device managed by your organization." The most confusing part is that we are able to log in on an Air 4 with that same account. We have unsuccessfully tried to set up iPad Air 3 and iPad Pro 12.9 Gen3 thus far. New Air 4 set ups go through just fine. Any help or thoughts would be appreciated. Thank you!
Hi, very new at supporting Jamf and we have a small issue (more an inconvienience for our users) Two issues really:On login our users, when signing in using their azure creds and authenticator app are then prompted for their AzureV2 password rather than just letting them continue the sign in. Is this behaviour expected or are we looking at how our access rules are configured in Azure? Interested if anyone else has seen this behaviour before?
Does anyone know of a setting or script to run to make chrome the default browser on ipads? We have an in house app that launches into safari by default. Unfortunately, it gives a lot of issues because safari doesn't support certain features. Everything we do is in Chrome. We have 14,000 devices so doing it manually would be a pain. Any help would be greatly appreciated. Thank you!
I've got a policy I'm testing that will run on checkin on a subset of devices. The policy runs the softwareupdate command to obtain the 13.4 installer from Apple's servers and then update inventory once finished. The reason for the inventory update is so the Mac will be put into a smart group containing the Macs that have the 13.4 installer in /Applications. This smart group is excluded from the policy scope.I'm finding that because the softwareupdate command takes some time to download the full OS installer, the Macs aren't updating their inventory afterwards, meaning they're not put into the smart group and next time they check in, they run the command try to obtain the 13.4 installer again. Has anyone encountered this before? Or have a better way to achieve this? The end goal is to have the installer in Applications so staff can update their OS when convenient to them, rather than forcing updates on them in the middle of a school day.
So I am working to get Jamf Parent up and running and integrated with Jamf School, and i seemingly have done everything correctly. However, whenever a parent tries to scan the QR code to add their child's device to their Jamf Parent app, the message,"Your child's device cannot be found. Try again later or contact you child's school. Your child's school removed this device from the list of devices you can manage with Jamf Parent."How might I resolve this? I can't seem to find where I would add the device to a list that would allow the device to be managed by Jamf Parent.
I have 802.1X Wifi profiles with trusted Cert setup.It works very well until user changes user account password.Is there a way to change both mobile account and the Wifi login keychain password simultaneously so that users do not need to enter the new password to re-authenticate Wifi?Please advise.Hello,
Hello communityWe want to start to enroll iPads to our employees. But we cant, because some bug (already reported at forti) exists and its not possible to configure it like it should. Because I am dependent on our external security provider (which has the connection to forti) I am looking myself for some solution.So has maybe someone here in the community forti running successfully on iOS or iPadOS.We are using the forti clients and the Forti EMS server on premise. Forti version on 7.2.Thank you in advance for any good ideaBR J
I have a pre-enroll that that I’m in need of a second local acct created before first boot. I’ve created a policy that will create the user and scoped it to the machine group. I set the trigger for enrollment completion. I know the policy works because if I run it in Self Service it creates the user. My scope works for other policies so I know the group works. I have created another policy that fixes the secure token issue with the initial admin user. Is it only possible to run one policy install with the completion trigger? If not, any suggestions to make this work?
Hello Jamf Nation! Jamf Protect Insights have been updated to adhere to the current CIS Benchmark guidance for macOS Ventura 13. As a result, the Insight names and categories in Jamf Protect have been updated. For additional information, see Insights via the Jamf Learning Hub. Thank you!The Jamf Protect team
I am working on deploying CrowdStrike initially to a test group of Macs for later deployment companywide. The one thing we are having problems with is the "Managed Login Items Added" alerts that users are seeing when CrowdStrike gets deployed to their Mac. The profile I created for CrowdStrike configures the Content Filter settings, Notifications, PPPC, and System Extensions along with Managed Login Items. On my own test Mac, I have only seen this alert pop up once. I have uninstalled CrowdStrike and either allowed it to reinstall at check-in, and I have ran the command to run the policy in Terminal. Most of the time, I don't see the alert. I'm wondering what I may have done wrong. This security feature in macOS debuted with macOS Ventura. I did not have to deal with this until now since I was working in other areas of Jamf Pro for the last several months. Allowing login items is still new to me. I would appreciate some help on this. I checked the other apps we are deploying that inclu
Has anyone found a way to display, via smart groups, macs that have been sent from ABM and haven't been assigned yet? These are machines that aren't even unmanaged.
Hi all,I am trying to deploy Cynet on several macOS machines with pkg and then grant full disk access on each machine remotely using Jamf pro.Can you please help me on how to do it? Thanks! Ben.
Still trying to wrap my head around how this works. I have an enrollment process in place where I can send a user new in the box mac and it pretty much sets up itself, we have to have FileVault encryption and we are using Azure with MFA. After everything is completed if the user reboots they are presented with the FileVault login, then it brings up the Jamf Connect login to Azure which will prompt for MFA. Is that the expected behavior?
First of all, I'd like to say that I'm really excited about all the new management features that are coming for iOS, iPadOS and macOS! Finally Apple seems to have implemented ways to reliably and efficiently handle a lot if challenges enterprise organizations have when using Apple devices in their corporate infrastructure! Personally, without these new features, Apple hasn't been ready for the enterprise IMO.Now, with these awesome new features, we as admins can finally fulfill the requirements that most organizations have!My personal most-wanted list in falling order is:1. Reliable, automated automatic OS updates with working deadlines for upgrades2. Per-app VPN (or similar) access to internal resources that aren't connected to the Internet directly without the need of a third-party VPN or require a tunnel to be connected/negotiated3. Device compliance, granular access to settings and configurations etc (combo of managed configurations, device attestation, granular access controls and
Ever since the Jamf Pro 10.46.1 update was applied, any and all Macs that are re-enrolled without deleting the computer records first are not getting their policy logs and Extensions Attribute values cleared. This is causing major problems.I verified the settings and as you can see they are set to clear.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!