Get Support
Recently active
Anyone got a script for Dockutill on Monterey. Our old Python script doesn't work anymore. We are looking to keep the Self Service app permanently in the dock. This is the current script. #!/bin/shDOCKUTIL=/usr/local/bin/dockutilsleep 10$DOCKUTIL --add '/Applications/Self Service.app' --replacing 'Self Service' --no-restart /Users/$3killall cfprefsdkillall Dockexit 0
Is there any way to turn on YouTube strict or moderate filtering within Jamf Pro without using Jamf Safe internet. I simply want to enable the native YouTube app feature to enforce strict filtering.For example on the app - I want to enforce this setting on all iPads with the YouTube App.Open YouTube, select YouTube user, top right hand corner / select settings / general / restrict mode.
I have a Prestage set up that creates a local admin user.It works correctly in Monterey or before.Ventura it stopped working.My work around right now is to not add the machine to pre-enrollment until after I manually setup the local admin user then add the machine to Pre-Enrollment and run [profiles renew -type enrollment] from CMD.I would like to get my pre-enroll working again.Any suggestions?
Hi there,My company is using JAMF to have control over the Macbook I work. Recently, I did bough a Ipad which I did connected with the company managed icloud, only to use a few application I don't want to use in the work laptop(such as personal e-mail).I am trying to use Universal control for use the same keyboard(magic keyboard) and magic trackpad only by "trespassing the mac screen barrier". I did changed all UI controls in apple's guide to make it work, but it doesn't, I can use the ipad as a extension monitor but I would like to use the Unviersal control.I imagine it is due to any restriction in Airdrop(since I try to send file to macbook through airdrop but it doesn't appear in the other device, even the control saying I can receive files from enyone) , to avoid leak of files between devices, my question is: Is there any way the security team can configure the profiles to allow airdrop only for keyboard/trackpad but not allowing file transference?Thank you in advance!!
Hi, This may be a stupid question but I am new to Jamf and not much of a Mac user. I downloaded Jamf Composer from my Jamf Product page. Version 10.46.0.I get a .dmg file. I run the file on a test Mac and it pops up saying to drag Composer to your hard drive to start building packages. It didn't install anything. So I drag the .dmg file to my Applications folder and run it again. Same message. I plug in an external storage device same thing. USB drive, same thing.I was planning to use Composer to build a .pkg file for Figma as so Figma can be deployed using Jamf.Let me know if maybe I am dragging the Composer .dmg file to the wrong place or maybe it is a bug with Composer.Thanks.
I'm seeing a CodeSignSummary-xxxxxxxxx-xxxx-xxxx-xxxxxxxxx.md appearing in Applications on my computers. File content shows something about wdav-upgrade.zip, which has to do with Defender. Any idea why this file is getting generated?
I need someone help I noticed today that my CA Certificate on the certificate Details section is giving me the description but also gives me an error saying Not found in keychain
Curious if anyone has setup an automated removal of IOS devices that haven't reported after a period of time? We have enough devices that a few get destroyed, lost or stolen every month and I'd like to automate the removal after 6 months just to free up the JAMF licenses for re-use. Thanks!
Hi Jamf Community, Has anyone ever been asked to report on the number of systems that have Touch ID fingerprints setup? I've been attempting to write an EA as I have not found anything online. There are no Jamf Template EAs for TouchID, maybe this is a feature request. I know we can restrict the use (allow touch ID unlock, etc.) but we are unable to restrict our users ability to add a fingerprint into touch ID. If anyone has some suggestions on how to accomplish this, I would be grateful. Thanks,JR
For those unaware LAPS is based on an approach originally created for Windows environments whereby Windows devices are configured with local admin level accounts for which the password is randomised and stored in Active Directory per device record. (This relies on devices being enrolled in to AD.)This was and is a highly useful approach so that each device can have a unique admin password rather than all of them having identical passwords.As such this technique would equally benefit a Mac environment and a number of equivalent solutions have been developed over the years. Some even store the password in AD also but many store the password in Jamf hence this discussion here. Again many techniques have been previously discussed here before.However Apple being Apple 😦 this is more complex than it used to be or likely is for Windows.The big issue these days is the use of Secure Tokens for FileVault2 access.Firstly I will state that previously at a number of organisations over
Hello,We have a compiled AppleScript that users can click to access their account and bring up the password change window locally on their computer. It has worked great up to Monterey. But since Ventura it doesn't work at all! It opens System Preferences and Users and Groups but then it stops.Anyone who is sharp on AppleScript and has a solution or some good advice?
Has anyone been successfully able to update Splashtop Streamer via Jamf policy? I see that they have a guide for creating a package on their website (Splashtop), but I am unsure of what the "deployment code" is referring to.
Hey folks, I have a weird one. We use dockutil to manage Dock. Dockutil installation + sorting out the Dock is set as a policy after enrollment. Policy deploys fine, installs Dockutil, adds the required icons but doesn't remove any of them with error 'Remove failed for xxx in /User/Username/Library/Preferences/com.apple.dock.plist'. Although, same script is added to our SelfService and when its run from there, it works as a charm. #!/bin/bash echo "running dockutil" DOCKUTIL=/usr/local/bin/dockutil $DOCKUTIL --remove 'Safari' --allhomes $DOCKUTIL --remove 'Mail' --allhomes $DOCKUTIL --remove 'Contacts' --allhomes $DOCKUTIL --remove 'Calendar' --allhomes $DOCKUTIL --remove 'Photos' --allhomes $DOCKUTIL --remove 'Messages' --allhomes $DOCKUTIL --remove 'FaceTime' --allhomes $DOCKUTIL --remove 'iTunes' --allhomes $DOCKUTIL --remove 'iBooks' --allhomes $DOCKUTIL --remove 'Maps' --allhomes $DOCKUTIL --remove 'TV' --allhomes $DOCKUTIL --remove 'Music' --allhomes $
Our company is expanding our Jamf enrollments to company owned Macs in Japan. I know that for the users, the OS and Jamf products are multilingual and will display according to the system language. Obviously, anything I type into Self Service descriptions will be in English since that's the only language with which I am proficient. Today I was looking at the computer records of some Japanese Macs that recently enrolled and I saw most information was in English, but I saw the following under Software Updates:macOSセキュリティ対応 13.3.1 (a) 13.3.1 (a)macOSセキュリティ対応 13.3.1 (a) 13.3.1 (a)-13.3.113.3.1 (a)I don't speak or read Japanese, but from the context and version number I can tell this is for the Rapid Security Response 13.3.1(a) update. But it got me thinking... How would I run searches or Extensions Attributes on Macs in a foreign language. For Self Service descriptions, those of you in this situation, do you use a translator to put multilingual translations in the descriptions
Greetings,We are starting our setup for Jamf Connect and so far the login window is working, though on one M1 Mac Studio, it keeps asking for password verification each login. I read in another thread that is firmware issue?My main question is that we are having issues with the Connect App not loading. It seems to work sometimes but most times it loads we get the attached image. App with empty menu items.I can upload the plist from the config file if needed. But I'm at a loss for how to fix the issue.
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 10.46.1 fixes the following product issues: [PI111508] Resolved a broken access control issue within an authentication implementation (CVE-2023-31224). [PI111680] Jamf Pro users who use group-based access roles will no longer see an error when attempting to access the Volume Purchasing settings page. [PI111688] In clustered environments, Jamf Pro no longer stalls on the setup assistant if setup was initiated on a non-primary web app. [PI111726] A java.lang.OutOfMemoryError error no longer occurs when configuration profiles with a Certificate payload that is associated with an Active Directory Certificate Services (AD CS) integration are distributed to or removed from computers or mobile devices. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. Th
I work at a College to where we receive in anywhere between 400 - 2000 systems back after fall then spring semesters. We were using Mac Provisioner to Erase and reload all of our returns to Catalina (T2 chips requiring to first boot using Command, R to get to utilities and then running command line in terminal). Now with Big Sur this does not seem to work. Any other suggestions for mass loading this many returns as running thru Jamf requires logging into all systems then running downloads to Big Sur and running the erase and reinstall commands which I do have setup in Self Service.. just trying to avoid booting and logging in and downloading.
Wonder if anyone can help. Was asked to update our ipad estate to the latest IOS which appeared to go smoothly but on some devices the management tab will not open & will sit there loading until the page is closed. We are on the latest version of Jamf Pro. The database tables check says all is ok.
There has been a request to create a restriction on certain students' iPads to prevent them from disrupting the class. This looks, to me, like a student behavior issue and not a technology problem. Even so, I will like to see if this is possible. The teacher setup is as follows: Teachers connect their MacBooks to the projector via HDMI to teach the class. Here is the issue: students can start "Screen Mirroring" (to the teacher's MacBook) from their iPads triggering the "Join" code to overtake the class screen and interrupt the class. I will assume that if something can be done it will take a "Configuration Profile" scoped to the incurring student's iPads in order to block the Screen Mirroring from being available on the iPad. I have only found some restrictions for "Airplay incoming requests" and "AirDrop", but, none do the trick. Let me know your thoughts!
Hi Everyone, how do you get your users to Enrol in to InTune? I have all the correct apps set up, but it still requires the user to go into Self Service and click on "Register in InTune" and follow the steps, and today when the infosec team enabled conditional access, 300 users who all "claimed" to have enrolled were locked out of MS Office apps? Open to any suggestions
Hello everyone. So how we use Jamf Connect login is only on the first login for new hires. This is just to provision the account properly and do all of the magic.After that we run an onboarding script which contains authchanger -reset to kill the login window and just use the menu bar for password resets and whatnot. For us it just works better for our users when they have the native login. If they are out of internet and then looking for the local login button etc etc.The issue is that it seems after a major OS update for existing users the Jamf Connect Login window comes back as the login mechanism. I'm wondering if anyone has a good solution for this for existing users/upgrades?
Hi all,I'm looking for some feedback regarding Jamf Connect. We've recently purchased Connect and have it all setup and ready to go, it's connected to our IdP, which is Azure AD but gets passed through Okta for authentication. Everything is working perfectly: Connect menu bar app works wonderfully, as does the Connect Login window.When connected to the Internet, the Connect login window requires Okta MFA authentication. When not connected to the Internet, local login can be used. Which makes sense, we can't have users not being able to log into their machines if they aren't connected to the Internet. All working as designed wonderfully. However, mu question is this: If people can bypass MFA authentication and just login locally, what is the actual benefit of using the Connect Login window? I feel like I'm missing something simple.
Hello all,We are exploring solutions to allow some of our end users to have a local VM (on their daily Mac) that allows them almost full control. The key things we need are:User cannot copy and paste, or file transfer directly between the VM and their daily Mac.Network will be connected to a DMZ through a trunked port.The VM must be configured so that the user cannot modify the settings of the VM to allow defeating of the above protections of the daily Mac and the rest of our infrastructure.User will not be admin on the daily Mac, but will be on the VM, with less restrictions for testing and research purposes.The VM will likely be macOS in this case, as we have a proper infrastructure for Windows and Linux VMs on VMware, but that might change.In my quick experimentation, I have found that at least VMware Fusion does require admin privileges to modify the network configuration of the VM, but does not disallow modifying the sharing settings. VirtualBox and UTM do not appear to lock down
Hi, does anybody have a simple script to notify users to check for updates and then takes them to the default software update in sys pref? I don't want to use nudge or other software and I don't want to force the update at this point. Basically just a nagging reminder at a set interval. Thanks
Hello - I'm sending remote commands to 7000 iPads to update iPadOS on supervised devices>Latest version>Download, install and restart. None of the iPads were updated to 16.5(going on the 14th hour mark since commands were sent). Under Devices>History>Completed Commands, I see 'AvailableOSUpdates' on all the iPads. I am currently on JAMFPro version 10.45. There's no iPadOS defer in place. I've been pushing iPadOS updates throughout the year with no issues until now. Any suggestions? Thank you!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!