Get Support
Recently active
Hello Jamf Nation!We recently released Jamf Protect 4.2.0.This release includes two resolved issues:Occasionally, computers with a large queue experienced high CPU usage if disconnected from the Jamf server. This has been resolved and in the event of a disconnect, queue uploads will pause until reconnected to the server.Previously, the ProcessDisguisedAsApple analytic was being erroneously triggered due to an issue interpreting the process signing information. This has been resolved and the alert should no longer be communicating a false positive for this analytic.Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.Thank you!The Jamf Protect team 0 Kudos Share
It's been a while since I posted anything, so, for (future) me & for you I am posting this script that dynamically updates Static Group membership. You might be saying to yourself, "Dynamically updating a Static Group is impossibly dumb, because, that's what Smart Groups are for...", but, here is my dilemma: I need to assess an endpoint state for which there are no good client-side attributes to collect. In this particular case (if you must know, Microsoft modern vs. basic authentication) there is no definitive data on the endpoint that accurately reflects the sheer number of highly-variable user login behaviors in my environment. It's not that it's too hard, it just can't be accurately done (&, yes, I've talked to Microsoft... https://techcommunity.microsoft.com/t5/exchange-team-blog/notes-from-the-field-does-outlook-for-mac-insist-on-using-basic/ba-p/3629510). The user login data I need (i.e., email addresses that are using basic auth) is available, however, in the Exchange l
I found this thread for an Intune EA, but am getting conflicting information. I check if a user is enrolled in Jamf by navigating to their computer, clicking the History tab, then navigating to macOS Intune Integration Logs. The extension attribute will return "None" despite the user being enrolled with Intune (see screenshots attached). I have tried to find documentation on creating a smart group based upon the Intune Integration reporting Jamf already has, but have not been able to find any. I also quickly glanced through the Jamf Pro API reference and documentation to see if this could be accomplished via the API but was unsuccessful. Any help would be appreciated! Thank you for your time!
I'm looking to set up a sandbox instance of Jamf Cloud. Does anyone know how many certificates the APNS portal supports? I'm a little nervous in selecting "Create new certificate" when I have a production instance and certificate deployed. I'm "assuming" that the "Create new certificate" wouldn't impact my current & valid production certificate, but rather be safe than sorry and ask the group. Any impacts to currently deployed certificates when creating a new one in the APNS portal?
Hello,Could you please advise me on the following?I have Jamf Connect deployed via Jamf Pro (with Azure AD) anf FileVault enabled via a Configuration Profile.At the booting and restarting, macOS login window first appears to ask for Password and then presents the Jamf Connect Window where I supply the Azure Credentials.At the logout, it presents the Jamf Connect window.is it the way it should appear? Since FV enabled, it requires to be unlocked first and then JC login window appears there.if there is no FV, it straightaway presents the Jamf Connect Login Window.(User Migration has been chosen with Jamf Connect Configuration.) Thank you,Arun
Hello All,I just wanted to know if I can bypass the SSO authentication putting "?failover" after my JAMF console URL then what is the point to use SSO, or it is known to administrator only not for others? Or it can be stopped also to bypass in this way?
JAMF Nation, it is my honor to announce that JAMF Software is seriously, no-joking, really, truly working on a swag store for your shopping pleasure. Per this feature request, the hoodie is in demand... So, what else do you want to see in the store?
I am trying to get the SCEP profile information from the command line on my mac.I can see the SCEP server URL and the SCEP certificate name in the settings profile page but I can't find it with the profiles command or the system_profiler commandDoes someone know how to reach this information from the command line?Thanks
We use Jamf Connect to sync users Google account password and set it to their Mac account password. One of the users have changed their google password, Jamf connect has realised that the passwords don't match, but wont let him sync the accounts. He gets a notification from JC that the password needs syncing, but when we try the Username and Password fields are greyed out and we can't confirm the accounts. Has anyone come across this issue or have any troubleshooting steps I can try and take?
Hello, I've been unable to find answers to these questions in regard to managing Mac App Store Apps via Jamf Pro (looked in admin guide and YT channel with no luck) Question 1: I've deployed an app to a user via Mac App Store Apps and the user has subsequently put the app in the bin on their device. How do I remotely reinstall the app in this scenario? In the Jamf Pro web app I can see that the number of "in use" licenses for that application is "2" when I would expect it to now be "1" since one of two users manually uninstalled the app. Question 2: How do I remotely uninstall a Mac App Store App from a user device? We installed an application then in "Scope > Targets" removed the user however the application has not been uninstalled from their device.
Hi everyone,today I came across an error where the user can't login in the SelfService anymore. The authentication in the MacOS SelfService does work.It is strange to see that the logs mentioned further down are basically saying that the login successfully failed.We tested the LDAP connection without any error. JAMF Pro Version: 10.43.1-t1674743888SelfService Version: 11.1.0 JSSAccess.log:username=xxxxxx, status=Successful Login, ipAddress=xxx.xxx.xxx.xxx, entryPoint=Casper Suite Application JAMFSoftwareServer.log:[ERROR] [Thread-2 ] [lientCommunicationServlet] - Error processing communication content - com.jamfsoftware.jss.exceptions.authentication.AuthenticationException: An authentication error has occurred. I hope someone can help. Kind regards.
We collect ipads at the end of the year. They previously had a user assigned. Is there a way that we can reset that device (in mass, or having the student manually do it), and then when it turns back on in the fall, it does NOT ask for username and password to refresh and install profiles again? I mean- it allready knows who the user is going to be, so how do I get it to just ask for which wifi network and country, and then have it auto load profiles without needing a new username and password? And- with that- can you preload/preassign usernames to NEW devices that havent been assigned before and are only in the prestage area thus far?
Hey y'all,I can anyone add printers via the Jamf Admin-app on 10.42. I can click the menu-button, but no dialog shows up. If I rapidly click it several times I can see a dialog for a split second, but it disappears almost immediately.I see this on all my machines here, MDM enrolled, not enrolled, profile manager enrolled, virtual machine, everywhere.I'm running Monterey 12.6.1 and 12.6, but it happens also on Ventura.Does anyone else see this and/or have a workaround for me?BestMorgan
I have some iOS Devices which has installed the self service app but the server from the self service is unreachable. Jamf Pro Version 10.45.0-t1678116779. iPad Air: iOS 12.4.7iPhone SE Gen3: 16.4.1InstallType is Manually install over a group. The Cloud Distribution point test is successfully.A reinstallation or completely new install of an Device aren't working.Thanks for the help
Hey I have a question regarding the CA Certificate while self enrollment.During the process of self enrolment the user will download 2 mobileconfigs (ca certificate and mdm profile) I just saw that some users seems to only have installed the mdm profile and were missing to install the 1st ca certificate profile.2 questions- What happens to the users that are missing the Ca certificate profile?- Can I push this profile to the missing ones somehow? thanks
Our asset management dept is asking how to get reports of software installed on machines. I can output an applications list, but it's WAY too detailed, meaning minor versions are all listed separately per device which makes it way too complicated to sort through. They want something like BigFix provides, though they weren't able to provide an example. Anybody have any thoughts on how to export a list like that?
Hello,We are planning on issuing our users MacBooks. We wanted to use goguardian since we already use it for user ipads. I see that for ipads we have a configuration profile with the goguardian certificate that gets pushed. Would it be the same process for issuing the goguardian certificate to Macbooks via a configuration profile or policy? Thanks,
I have a number of Mac Apps (Office suite and Google Chrome are among them) configured to install when a new Mac is enrolled in our Jamf Pro system. The install of these apps seems to be pretty inconsistent and I'm not sure where they get hung up.Some times, a handful of the apps will install just fine, while others don't appear within a few hours of enrollment. Other times, nothing will install. I've looked at deployment status and they are often sitting in "In Progress" seemingly indefinitely. I've reset my test MacBook several times through the course of the day with no change. I've pushed our policies as well. This issue is not every time, as very occasionally all apps will install within an hour or two and a couple restarts, but happens more often than not.
Recently had a customer report a lost iPad so I did a search for the device to put it in lost mode. When trying to click into the device details, Jamf just spins endlessly. I was then able to click into several other devices with no issue. Restarted the browser, cleared the cache, restarted the computer etc- no change. This has happened before and is extremely frustrating.
Any idea why there is not a Jamf Pro Binary definition for patch management ?
Hey all, Hoping you all can shed some light. Essentially, I'm trying to create an extension attribute to simply pull the agent version and build info.https://community.jamf.com/t5/jamf-pro/extension-attribute-tenable-network-security-nessus/td-p/109007 So I'm following the above article related to its extension attribute setup. Deployment is going well but getting Jamf to acknowledge via the setup of an extension attribute is rough for me. Namely in the Nessus Agent Version and Build info: I'm going awry somewhere so any help would be appreciated if possible.
Am I the only one? I have the problem that the configuration profile, which is automatically installed on an iOS device, is reinstalled after a certain time.I can sometimes (not always) reproduce the issue by changing the device name and waiting, or by clicking Update inventory in Jamf Pro.After that, configuration profiles are reinstalled although they are already installed on the iOS device.The user has to re-enter his Exchange password or CardDAV requires a password after the configuration is reinstalled.Configuration profiles that will be available in Self Service are not affected.We also manage Macs in Jamf, we don't have any problems with that.I've been in contact with Jamf Support for months, but I wanted to ask the Jamf Nation community if anyone had the same or similar problems and could possibly give me a tip.Since February 2023 we have been using Jamf Pro Cloud (migrated from OnPrem).Device Compliance for macOS and iOSCloud Identity Providers: AzureSingle Sign On: AzureThank
Pretty much the title. I'm doing some testing for Jamf Connect deployment and for an account that has an admin role assigned in Azure (which is what I'm using for the identity provider) it will prompt me to make a new local account and sync it with Azure or it will ask me to sync a current local account. But for some users I'm not getting the option to make a new local account. I have the option to "hide the create new user option" unchecked so I don't think that is the issue. This would only be an issue for new users. I assume I can just make the non admin local account beforehand and let them sync, but if I can avoid doing that let me know.
I am trying to figure out how to deploy a script to our users that deregisters the O365 suite. On the Microsoft site I have found the following Terminal command:defaults write com.microsoft.Word ResetOneAuthCreds -bool YESThis works like a charm when I run it locally, but when I try to run it through Jamf (selfService) it gives no result. I think this might be because the script through Jamf does not run as the logged in user.This is what I have sofar:#!/bin/bash#Remove all Microsoft usersdefaults write com.microsoft.Word ResetOneAuthCreds -bool YEShoping there is someone that can point me in the right direction here.
am trying to deploy in the laptops with M1 chip, but its getting failed at the end while installing with an Error: Push workflow for macOS update/upgrade via MDM timed out after 300 seconds, trying again in 3600 seconds Does anyone found a solution
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!