Get Support
Recently active
Hello,This might be something I am looking through, but is there a way to pull a full application inventory from all my Macs into one location, either in Jamf Pro or a CSV? Trying to do some application cleanup/updating and not looking forward to going Mac to Mac looking at their application field in Inventory.Thank you!
Does anyone know a way to exclude Jamf Connect from MFA in Azure Conditional Access? I have created a web redirect URI to make Azure see the app registration in conditional access but when I add this as an exclusion users are still asked for MFA. Thanks!
Hi everyone, I just reinstalled Mac OS on my MacBook Air, when I tried to enroll my MBA to JSS, it tells me MDM Capability: No I've checked my certificates, none of them expired. and just did a push diagnostic and it pass too Any idea?
Hi all, I'm trying to make our cofiguration profile work for our macbooks. I'm noticing for new Macbooks to be enrolled, I get MDM Capability = No. Verify MDM Enrollment = Enrolled. With MDM Capability = No, it mean none of the Configuration Profile would be pushed to them. I've read on past JAMF Nation discussionshttps://jamfnation.jamfsoftware.com/discussion.html?id=19266https://jamfnation.jamfsoftware.com/discussion.html?id=11948 that this push MDM actually is dependent on Apple, and running sudo jamf mdm may trigger it to work. But when I do run /usr/local/bin/jamf removeMdmProfile/usr/local/bin/jamf manage/usr/local/bin/jamf mdm all I get is Verify MDM Enrollment = Enrolled. Any other ideas on how to activate this MDM? Right now half our Macbooks have MDM, but the other half have this turned off. I'm puzzled as to what is required.
Hello Everyone, I have seen multiple discussions on this topic, but I was unable to glean anything that would solve our situation. We are using DEP and our Macs are coming into the JSS just fine. We can even use the erase install command to remotely wipe and get our Macs back to an out of box state. Somewhere along the way though, we are seeing Macs losing their MDM capability. We have tried just about everything. Granted, if I do something manual in front of the Mac stuff to restore MDM, we might be able to get things going. Something like removing the framework or taking the Mac out of the JSS. I am trying to find a way to do this remotely or the next time one of these systems checks in. MOST of the profiles seem to be loading and working. We have tried to remove the keychain pieces and running quick add again. Still no go. We have tried running sudo jamf manage, this didn't fix it. We tried to renew our MDM, still no good. I do have a support ticket open and they have
Aloha All,We are a K-12 located in Hawaii. At this time, we are prepping for Summer School, which begins next week. We have been able to set up iPad Air 4 as shared devices for the past year. Our requirements have grown beyond our inventory and are trying to set up iPad Air 3 to accommodate the excess.Following the same steps that we've done in the past, we are able to get to the Sign In screen which takes us to our SSO landing page. After entering the account password, it kicks back to the Sign In screen with a pop-up message "Sign In on a Managed Device. This account can only be used on a device managed by your organization." The most confusing part is that we are able to log in on an Air 4 with that same account. We have unsuccessfully tried to set up iPad Air 3 and iPad Pro 12.9 Gen3 thus far. New Air 4 set ups go through just fine. Any help or thoughts would be appreciated. Thank you!
Hi, very new at supporting Jamf and we have a small issue (more an inconvienience for our users) Two issues really:On login our users, when signing in using their azure creds and authenticator app are then prompted for their AzureV2 password rather than just letting them continue the sign in. Is this behaviour expected or are we looking at how our access rules are configured in Azure? Interested if anyone else has seen this behaviour before?
Does anyone know of a setting or script to run to make chrome the default browser on ipads? We have an in house app that launches into safari by default. Unfortunately, it gives a lot of issues because safari doesn't support certain features. Everything we do is in Chrome. We have 14,000 devices so doing it manually would be a pain. Any help would be greatly appreciated. Thank you!
I've got a policy I'm testing that will run on checkin on a subset of devices. The policy runs the softwareupdate command to obtain the 13.4 installer from Apple's servers and then update inventory once finished. The reason for the inventory update is so the Mac will be put into a smart group containing the Macs that have the 13.4 installer in /Applications. This smart group is excluded from the policy scope.I'm finding that because the softwareupdate command takes some time to download the full OS installer, the Macs aren't updating their inventory afterwards, meaning they're not put into the smart group and next time they check in, they run the command try to obtain the 13.4 installer again. Has anyone encountered this before? Or have a better way to achieve this? The end goal is to have the installer in Applications so staff can update their OS when convenient to them, rather than forcing updates on them in the middle of a school day.
So I am working to get Jamf Parent up and running and integrated with Jamf School, and i seemingly have done everything correctly. However, whenever a parent tries to scan the QR code to add their child's device to their Jamf Parent app, the message,"Your child's device cannot be found. Try again later or contact you child's school. Your child's school removed this device from the list of devices you can manage with Jamf Parent."How might I resolve this? I can't seem to find where I would add the device to a list that would allow the device to be managed by Jamf Parent.
I have 802.1X Wifi profiles with trusted Cert setup.It works very well until user changes user account password.Is there a way to change both mobile account and the Wifi login keychain password simultaneously so that users do not need to enter the new password to re-authenticate Wifi?Please advise.Hello,
Hello communityWe want to start to enroll iPads to our employees. But we cant, because some bug (already reported at forti) exists and its not possible to configure it like it should. Because I am dependent on our external security provider (which has the connection to forti) I am looking myself for some solution.So has maybe someone here in the community forti running successfully on iOS or iPadOS.We are using the forti clients and the Forti EMS server on premise. Forti version on 7.2.Thank you in advance for any good ideaBR J
I have a pre-enroll that that I’m in need of a second local acct created before first boot. I’ve created a policy that will create the user and scoped it to the machine group. I set the trigger for enrollment completion. I know the policy works because if I run it in Self Service it creates the user. My scope works for other policies so I know the group works. I have created another policy that fixes the secure token issue with the initial admin user. Is it only possible to run one policy install with the completion trigger? If not, any suggestions to make this work?
Hello Jamf Nation! Jamf Protect Insights have been updated to adhere to the current CIS Benchmark guidance for macOS Ventura 13. As a result, the Insight names and categories in Jamf Protect have been updated. For additional information, see Insights via the Jamf Learning Hub. Thank you!The Jamf Protect team
I am working on deploying CrowdStrike initially to a test group of Macs for later deployment companywide. The one thing we are having problems with is the "Managed Login Items Added" alerts that users are seeing when CrowdStrike gets deployed to their Mac. The profile I created for CrowdStrike configures the Content Filter settings, Notifications, PPPC, and System Extensions along with Managed Login Items. On my own test Mac, I have only seen this alert pop up once. I have uninstalled CrowdStrike and either allowed it to reinstall at check-in, and I have ran the command to run the policy in Terminal. Most of the time, I don't see the alert. I'm wondering what I may have done wrong. This security feature in macOS debuted with macOS Ventura. I did not have to deal with this until now since I was working in other areas of Jamf Pro for the last several months. Allowing login items is still new to me. I would appreciate some help on this. I checked the other apps we are deploying that inclu
Has anyone found a way to display, via smart groups, macs that have been sent from ABM and haven't been assigned yet? These are machines that aren't even unmanaged.
Hi all,I am trying to deploy Cynet on several macOS machines with pkg and then grant full disk access on each machine remotely using Jamf pro.Can you please help me on how to do it? Thanks! Ben.
Still trying to wrap my head around how this works. I have an enrollment process in place where I can send a user new in the box mac and it pretty much sets up itself, we have to have FileVault encryption and we are using Azure with MFA. After everything is completed if the user reboots they are presented with the FileVault login, then it brings up the Jamf Connect login to Azure which will prompt for MFA. Is that the expected behavior?
First of all, I'd like to say that I'm really excited about all the new management features that are coming for iOS, iPadOS and macOS! Finally Apple seems to have implemented ways to reliably and efficiently handle a lot if challenges enterprise organizations have when using Apple devices in their corporate infrastructure! Personally, without these new features, Apple hasn't been ready for the enterprise IMO.Now, with these awesome new features, we as admins can finally fulfill the requirements that most organizations have!My personal most-wanted list in falling order is:1. Reliable, automated automatic OS updates with working deadlines for upgrades2. Per-app VPN (or similar) access to internal resources that aren't connected to the Internet directly without the need of a third-party VPN or require a tunnel to be connected/negotiated3. Device compliance, granular access to settings and configurations etc (combo of managed configurations, device attestation, granular access controls and
Ever since the Jamf Pro 10.46.1 update was applied, any and all Macs that are re-enrolled without deleting the computer records first are not getting their policy logs and Extensions Attribute values cleared. This is causing major problems.I verified the settings and as you can see they are set to clear.
Hi All,We currently are using McAfee Endpoint Protection and we would like to at least have it update automatically.Able to know if there is a script that we can use to do just that?Sorry as I am literally new in scripting.
I've had printers pausing all the time on macs and a simple resume gets it back up and running but I've just started seeing printers pausing and once resumed they pause again instantly and say "connection refused". Reinstalling the printer doesn't work, reinstalling the drivers doesn't work, removing the printer keychain password doesn't work, resetting all the cups config and plist files doesn't work. The only fix has been wiping the macbook and rebuilding it. All users are added to print admins so have rights to un-pause a printer and add/remove them, etc. I've tried various scripts to force queues to continually un-pause and to restart services but nothing seems to fix it. Has anyone ever come across this as I can't find anything online anywhere and I'm getting to my wits end now?!?!?!
Hello,I wan to use PingID on my mobile to login to my macOS ( MFA ).The pingID config file is missing for guides “ Downloading PingID properties file with restricted permissions.“ !!!https://docs.pingidentity.com/r/en-us/pingid/installing-the-pingid-integration-for-mac-login?section=qvf1578315912961Any idea? Cannot reach to PingID support phone/email !!
Hello all.After deployment, and, just after entering a session, i'm stuck on this windows. Any session is impacted.Only way to pass this window is to hard extinct, reboot and re-enter the same session ?Help needed please.
I thought you used to be able to share extension attributes but I do not remember now. I got the basis of this from an older EA located here [McAfee Check EPO Agent Version]https://www.jamf.com/jamf-nation/third-party-products/files/525/mcafee-check-epo-agent-version) #!/bin/sh #Reports the version of the McAfee EPO Agent installed on the client computer. #Data Type in JSS for this script should be set to: string Version=`cat /etc/cma.d/EPOAGENT3700MACX/config.xml | grep "<Version>.*</Version>" |sed -e "s/<Version>(.*)</Version>/1/"|tr "|" " "` echo "<result>$Version</result>" fi
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!