Get Support
Recently active
Hi All,We currently are using McAfee Endpoint Protection and we would like to at least have it update automatically.Able to know if there is a script that we can use to do just that?Sorry as I am literally new in scripting.
I've had printers pausing all the time on macs and a simple resume gets it back up and running but I've just started seeing printers pausing and once resumed they pause again instantly and say "connection refused". Reinstalling the printer doesn't work, reinstalling the drivers doesn't work, removing the printer keychain password doesn't work, resetting all the cups config and plist files doesn't work. The only fix has been wiping the macbook and rebuilding it. All users are added to print admins so have rights to un-pause a printer and add/remove them, etc. I've tried various scripts to force queues to continually un-pause and to restart services but nothing seems to fix it. Has anyone ever come across this as I can't find anything online anywhere and I'm getting to my wits end now?!?!?!
Hello,I wan to use PingID on my mobile to login to my macOS ( MFA ).The pingID config file is missing for guides “ Downloading PingID properties file with restricted permissions.“ !!!https://docs.pingidentity.com/r/en-us/pingid/installing-the-pingid-integration-for-mac-login?section=qvf1578315912961Any idea? Cannot reach to PingID support phone/email !!
Hello all.After deployment, and, just after entering a session, i'm stuck on this windows. Any session is impacted.Only way to pass this window is to hard extinct, reboot and re-enter the same session ?Help needed please.
I thought you used to be able to share extension attributes but I do not remember now. I got the basis of this from an older EA located here [McAfee Check EPO Agent Version]https://www.jamf.com/jamf-nation/third-party-products/files/525/mcafee-check-epo-agent-version) #!/bin/sh #Reports the version of the McAfee EPO Agent installed on the client computer. #Data Type in JSS for this script should be set to: string Version=`cat /etc/cma.d/EPOAGENT3700MACX/config.xml | grep "<Version>.*</Version>" |sed -e "s/<Version>(.*)</Version>/1/"|tr "|" " "` echo "<result>$Version</result>" fi
Hello All, Please let me know what is the best way to upgrade Ventura (in place upgrade). If the create two policies one is to download the OS installer under /applications folder by softwareupdate command and second policy to upgrade it by startosinstall command with a display messgae to end user screen would be great? Or better solution we have through Jamf?
Hello everyone,We have standard Intel/M1 accounts (non-admin) (OS: 10.14.6 to 12.6.1).Could you advise how best I can grant them admin access to make the upgrade ?Thank you.
Under Configuration Profiles, we have the option to either enforce or ignore a complex passcode, 'Passcode cannot contain repeating, ascending, and descending character sequences.'My question is, are we able to edit exactly what this complexity means? For example, up to 2 repeating/ascending/descending character sequences? We are trying to mimic the password complexity of Okta.
I have put in a ticket and contacted our CSM. Anyone else has been down or not been able to send policies, update policies, or update packages? The error was:An exception has caused clustering to fail on the server "xx.xx.xx.xx". Information on this node will be out of date. Error: could not extract ResultSet; nested exception is org.hibernate.exception.JDBCConnectionException: could not extract ResultSetPlease, we are waiting two full business days without JAMF support or our CSM taking action. I have called and written but they are not getting on a call with me to resolve this obvious AWS issue. They are not explaining why we got a cluster error.This is the third major issue in three months that there has downed our JAMF, and they have not been able to fix them. Is anyone else having these mission-critical issues? Is anyone else not getting a response from JAMF for 24 hours when their entire site is not working? Any insight on this or similar J
I have a policy that currently runs once a day that nags the end user to reboot. Many of the users within the fleet have uptime greater than 30 days. It prompts them on-screen to reboot - and if they dismiss it runs once the next day. Sadly this doesn't seem to be enough of a nag. Is there a way to execute a policy two or three times a day? # Script to make the user aware that a restart has not occurred in over 7 days # Use JamfHelper tool to show alert message jHelper="/Library/Application Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper" # Set maximum days to 30 before warning about restart maxDays="30" # Check to see if the machine has restarted in the last day # See if "days" exists in the uptime upTime=`uptime | grep "days"` if [ -z "$upTime" ]; then echo "Not yet one day" exit 1; else echo "More than one day" fi # Get current uptime upTimeDays=`uptime | awk '{pr
Hello There, I want a policy on JAMF that all Mac users' laptops will auto-restart after 25 days.If anybody has it please do post.Thanks
Got our first few Silicon macs on site, deploying Adobe Creative Cloud Desktop App is giving me fits. I’ll include the jamf policy log below if anyone has seen anything similar? Also tried installing the pkg manually on the computer, fails with the same error. Issue is a bit time sensitive as we are expecting an additional 400 of these in an upcoming delivery. Pkg was downloaded direct from Adobe Admin console and platform set as “silicon” when creating the pkg for download.“Installation failed. The installer reported: installer: Package name is AdobeCCDA_Siliconv5.4.5.550installer: Installing at base path /installer: The install failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurred while running scripts from the package “AdobeCCDA_Siliconv5.4.5.550_Install.pkg”.)” Also notice that when I check the signature for a valid date I get a "no signature" response. Not sure if that is rel
Just noticed in my dashboard that my patch management status indicator for Zoom has disappeared. Looking at the patch management item, it's still checked to appear in the dashboard... but looking at the list of patch management items, the publisher is flagged as a (Deprecated Definition).I manually added a new patch management item for the latest version of Zoom 5.14.10 released on 2023/06/05 and can start getting my fleet updated. It would have been nice to get some kind of notification from Jamf Pro that this was changing?
I am wanting to create a smart group that will show me all the Macs that are capable of running Big Sur, not actually on Big Sur, but could upgrade to it. Is there a way to create a smart group that I can filter out the most recent version of macOS the device is capable of running? Thank you
Hi All, Looking for a way to sign our users out of the AppStore and iCloud as we plan on restricting those going forward. Found a few discussions like This Post but it doesn't seem to be working on El Capitan. We've noticed the ~/Library/Preferences/com.apple.storeagent.plist file doesnt seem to exist anymore as well. Has anyone had any success doing this?
Hi. I will start by saying that I have limited experience with Jamf Pro and Jamf Connect but can find my way around most of the time. Here is what we have happening: when our Mac footprint was only a few Macs, they got bound to AD and were never in ABM. This seemed to work ok, but as our Mac presence increased and we learned of issues that binding Macs could lead to, we decided to go the route of ABM enrollment, then leverage intune and Jamf Connect, keeping the Macs unbound. Since doing this, any config profiles pushed from Jamf Pro seem to work well. We ran into any issue where we had to update wireless certs and push them out through a config profile and all of the Macs that were enrolled and using jamf connect/intune got the profile and updated cert no problem. However, the Macs that were bound to AD "got" the profile and certs, but those machines cannot connect to the wireless network now. My question is (and thanks for your patience) - is it possible to "unbind" the Mac from AD a
Found this nice little limitation a little while ago. So basically, "patch reporting" can't be used to do anything actionable, like, say, patch something. The use case was checking for machines not on the latest version of Chrome, and if found, running a script like this: #!/bin/bash #Command will trigger Google's native updater process in the background cd /Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bundle/Contents/Resources/ ./CheckForUpdatesNow.command exit 0 And then update inventory to have it drop out of the computer group.
Hi,I'm looking for a bit of specific information around how device info travels between Jamf, Intune and Azure.We have a client using compliance via InTune on Macs, they're questioning why the three locations are showing different levels of info and therefore different compliancies. My understanding is that the flow of information goes:A change in device info during a Jamf Inventory triggers a sync to InTuneWhilst this info is then stored in InTune, it's not used for Compliance. InTune collects it's own data via Company Portal for that (OS, Encryption, etc)Then 'eventually' Azure receives the info - from a mystery source. Am I mistaken? I can't find this in any Jamf/MS documentation, so if anyone is able to shed any light on it, I'd be grateful. Thanks
I recently setup JC/Okta and have been testing this setup in a Jamf sandbox environment. When test users login to their Macs we are seeing the Okta login screen, which we can use for successful authentication, but its not allowing us to use any type of two factor authentication for Okta. We typically use Okta Verify app for two factor and I have configured Jamf Connect in Okta via Admin>Authentication Policies>"Any Two Factors".Am I missing something here?
Hello all, recently email alerts stopped arriving from Jamf, so we created a user for tests to see if it will get notifications.In that user, I subscribed to almost all the emails that are possible, but still only 2 users are being used in the notification email.I've tested the email address with the SMTP test from Jamf, it works. We got the test. But when I re-enroll a device, for example, I see the emails in the SMTP defined account. But those are only addressed to 2 other users.What could be the cause of this?
How to Create an Extension Attribute to output the latest macOS that can be installed on that system?I created a script that will run through all model identifiers in the script list but it's having a lot of issues, is there an easier way to do this in JAMF?I've been trying this with dubugs but stil can't figure it out.My model identifier: Mac14,9But when I run the script I get:Model Identifier: Mac14,9Checking Model: 5Checking Model: 9Array Entry for Model Identifier: System Not Found #!/bin/bash # Read the Mac's model identifier system_profile=$(system_profiler SPHardwareDataType) model_identifier=$(echo "$system_profile" | awk -F': ' '/Model Identifier/ {print $2}' | tr -d ' ') # Define the list of model identifiers and associated operating systems model_os_list=( ["Mac14,5"]="macOS Ventura" ["Mac14,9"]="macOS Ventura" # Add other model identifiers and operating systems here ) # Debug: Display the value of the model identifier echo "Model Identif
Hello. We currently have devices bound to Active Directory and are testing (in dev) a migration to Azure. We currently have extension attributes for some items, such as software licensing. When software licenses are purchased, the license holder's AD user object is given group membership in the Active Directory group of license holders for that app. Access to that app in Self Service is made available to those license holders based on an extension attribute that accesses AD, looks for the AD attribute for that software license group membership, and populates a smart group based on the logged-in user's membership in that group. I've been looking online for documentation for a similar way creating an extension attribute for accessing Azure and determining if the logged in user is a member of an Azure group, but I am not finding much info, or I'm not looking in the right places. Thanks for any help you can give me with this.
Hi,We had a health check last week today my VP of IT and on my test machine we have where if WIFI is not available, it makes us put the password in twice because it can't find our Azure (I am guessing), then forced to do local login.. Is there a way to work around that on some sort of cached creds or at least just have it login 1 time?
Has anyone wrote a script for Macs that can help detect all known 3rd party anti-virus software that are still running as a service?
My company needs to change some camera settings such as camera>formats - most compatible and camera>transfer to Mac or PC - automatic for all of our devices and Im hoping jamf has way to do this but I’m not seeing it under the configuration profile options. Anyone have any experience changing settings such as this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!