Get Support
Recently active
I have created and configured a lot of Jamf Pro servers over the years. While creating a new one today to use for testing, I ran into an issue I have never seen before. While following the steps for installing Jamf Pro on Ubuntu I am not prompted to create a root user password during the MySQL install process. I'm also not prompted to use legacy authentication. The Jamf article I am using is here:https://learn.jamf.com/bundle/technical-articles/page/Installing_Java_and_MySQL_on_Ubuntu_for_Jamf_Pro_10-14-0_or_Later.html#concept-5140What, if anything, could I be doing wrong? MySQL installs. I'm just not being prompted. Even though I have followed this process many times I always pull up the instructions published by Jamf to ensure that I complete all steps and catch any new or modified steps. Fortunately I have a snapshot of my server so I can revert back to the base install of Ubuntu quickly.
I just configured Teamviewer Remote integration after watching this videohttps://www.jamf.com/resources/videos/jamf-pro-and-teamviewer-supporting-users-wherever-they-are/and the documentationhttps://docs.jamf.com/10.32.0/jamf-pro/administrator-guide/TeamViewer_Integration.html All went well but there is an issue if I click in Jamf on the manage computer and and Management I dont see the option for Remote Management in the list!!Is it buggy or what could be missing that it is not working?
I feel like I'm playing whack-a-mole with these but our students with macbook airs are finding ways to get around everything I have in place and still managing to install VPNs Students have a standard accountI have a profile in place to prevent adding chrome extensionsI have the App Store set to updates onlyStudent devices have Securly at home filtering set up The latest VPN they have is StarVPN it doesn't show up as running, the only way to see it (so far that i've noticed) is it adds a network service, which they shouldn't even be able to do without admin permissions. any suggestions on preventing this further? We are being forced to hold off on device collection until the last day of school and are worried that VPNs will prevent us from locking computers that aren't returned.
Hello,I hope someone have a suggestion how to sovle this in Jamf ProI want to have two Search Invetory Groups1. One that list all Macbooks we have that are managed but never wiped with remote command.2. All Macbook we have still in Jamf, but they have been wiped with Wipe Computer command = not in use anymore.The reason for this is that we must keep all computers in Jamf that we have taken out of use, but still remain as proof that we have done a remote wipe on them.
Can anyone tell me the location of the Self Service company branded icon.This is not the Jamf icon found in Applications/Self Service.app/Resources/AppIcon.icns I am after the branded icon that you upload into the Branding section of Self Service in Jamf Pro. The reason I ask is I wanted to add this to messages we send out using Jamf Helper and -icon "full path to icon location" I would have thought this would be locally on the machine somewhere, but I have had no luck looking for it on the machine, or within Jamf Nation posts. Many thanks
If I have Jamf cloud and I have integrated my Jamf cloud with Azure AD for device compliance and also registering the mac in AAD then should still need AD-CS connector to get the certificate? If yes then why? and this AD-CS connector should run on DMZ?How can I know if AD-CS connector is integrated properly in my Jamf? Is it from Settings/PKI Certificate/Certificate authority?
We have been using EAP-TLS wi-fi with our iOS and macOS devices for some time. I use a Jamf pro configuration profile with 3 parts:1) install the wi-fi profile2) install the root and intermediate certificate for our internal AD CA3) use SCEP to request a machine certificateBut I'm looking to expand this so the wi-fi user also gets a user certificate. I can utilize more Wi-Fi roles and place users into different VLANs and ACLs, etc.So my question is anyone installing AD CS user certificates on your macOS and iOS devices? Are you doing it in an automated way using SCEP? Or are the users going to a web site and enrolling themselves?If you can help, please provide as much detail as possible.
Hi guys,i am willing to create a schedule task in order to restart my managed ipads every week.is it possible?
Curious about any district using MacBooks (Pro, Air or otherwise), and if you are using any app or service for more parental controls? I have parents wanting more control of website blocking, time limits, and general view of what their child is doing on said machine. Jamf Parent would be great for this if it worked with Macs and not just iPads. Gabe ShackneyPrinceton Public Schools
I'm trying to authenticate against the JSS API URL with a valid login credentials and it seems to constantly fail, e.g. ../JSSResource/accounts with error 401, not authorized. The user has full admin privileges, but continue to fail on the basic auth. I've even tried cURL to see if the behavior is different: $ curl -kvu "jss:****************" -H "Content-type: text/xml" https://jss.*********/JSSResource/accounts * Trying *.*.*.*... * TCP_NODELAY set * Connected to jss.**** (*.*.*.*) port 443 (#0) * ALPN, offering h2 * ALPN, offering http/1.1 * Cipher selection: ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH * successfully set certificate verify locations: * CAfile: /etc/ssl/cert.pem CApath: none * TLSv1.2 (OUT), TLS handshake, Client hello (1): * TLSv1.2 (IN), TLS handshake, Server hello (2): * TLSv1.2 (IN), TLS handshake, Certificate (11): * TLSv1.2 (IN), TLS handshake, Server key exchange (12): * TLSv1.2 (IN), TLS handshake, Server finished (14): * TLSv1.2 (OUT),
Having a little trouble finding the correct operations to pull the Warranty info from the API. Im not even sure if it is possible. The reason to do this is to have a popup on a computer, which is coming up to warranty end, to inform the end user to prepare their machine for replacement. If there is a better way to do this please let me know.
Hello,Has anyone been able to configure the Payload needed for Crowstrike to run with Ventura? (Screenshot attached it all Crowstrike's support continues to give me)I have configured the system extensions as well as the content filter, but can't seem to figure this one out as they don't give much information. I've attempted to use PPPC-Utility as well as Apple Configurator, but they don't seem to work. As we have to go in and manually approve access. This is not ideal as it's our antivirus software and we'd like to have it up and running as soon as the device is enrolled. I am also confused about how to enter the XML script into Jamf, that they provide to allow full disk access to Crowstrike. (Code below) Any assistance is much appreciated. Thank you!<dict> <key>SystemPolicyAllFiles</key> <array> <dict> <key>Allowed</key> <true/> <key>CodeRequirement</key> <string>identifier "com.crowdstrik
So i just update my mac to ventura, and the things is that i changed my AD password 1 day before. Now after updating to ventura, i can only login to my mac using my old password.is there a way to force nomad to check ad and sync the latest password?
Hello, we are attempting to deploy the Zscaler connector using a zero-touch deployment method. However, after completing SSO, users are prompted with a message in Safari asking if they want to allow the page to open "Zscaler". Is there any way to bypass this and pre-allow/permit access?
Hello all,In our institution, all staff users have managed computers using standard accounts. Computers have filevault enabled and PRK's are escrowed into JAMFcloud under the disk encryption pane.I've seen it happen a couple of times - occasionally we have users that go to boot their device up and log in, but after entering their password, they are fed into device recovery with a request for a password. Entering their password can't unlock the disk/proceed and only a PRK can allow you to go further.With the PRK entered, users can attempt to change their password, but it doesn't make a difference. On restarting device, they still can't log into the computer and are again fed back into device recovery.The quickest routine is to flatten the device and re-install macOS as troubleshooting with staff present often leads nowhere. As we're not using 'Erase all contents and settings', reinstallation takes over an hour, and then have to re-enroll and resetup the computer.Has anyone seen occasion
Do I understand correctly that there seems to be no method currently for Jamf School to deploy apps to iOS devices for "On-Demand Installation"? This is not spelled out in any of the Jamf School marketing materials or documentation. And because Jamf School blends its UI for both OSes, it seems to allow me to select "On-Demand Installation," when scoping apps to iOS devices or groups. But Self Service for iOS appears to only support Jamf PRO, and is only documented in the Jamf PRO manual, not the Jamf School manual. I am frustrated, not so much by the absence of this feature, but by the absence of any communication from Jamf or elsewhere on this subject. I have searched and searched. Can someone please spell this out? Is On-Demand install of apps on iOS supported in Jamf School or not?
Hi All, I completed my Jamf 200 on July 2020, I didn't take a copy of it. Now I am unable to find it. Can anyone help me where to find it.
Afternoon!We run our inventory through FileMaker, and want to use the API in Jamf School to do some basic GETs.Having a hard time figuring out how to make it work.Know my Network ID. Have the API Token built in Jamf School. Turned those into the UN:PW respectively and then turned those into Base64.In FileMaker I am "Inserting from URL".Set the URL to https://{ourDomain}.jamfcloud.com/api/devicesSet cURL options to "Authorization: Basic Base64Output"Keep getting same output in FileMaker: Did this for Jamf Pro (using a hand built user and not an API token), and worked like a champ.What am I missing? Thanks- Kevin
As I have been deploying an update script (erase-install) for users to upgrade to Ventura, I have begun to notice that some users are not Volume Owners and therefore unable to perform the upgrade themselves.Some background:This does not occur on all machines, approximately 5% of them.All of the machines in question were initially set up with a local admin user, then added to Jamf via the user-initiated enrollment process.The machines are all AD bindedThe non-volume owner users in question are mobile accounts that are created after all of the above takes place.One interesting thing I noticed all of the affected machines have in common is that they all list the non-volume owners as not having FileVault 2 enabled. However, the local admin account as well as every other account on every Jamf enrolled machine in our inventory, lists FileVault 2 as being enabled - even though FileVault is not turned on an any of those machines. I'm not sure if FileVault Enabled: Yes (Admin Center) = Fi
We are migrating our organization devices for users to sign into their macs with SSO.We use Jamf Cloud and therefore do not have access to the Apache Tomcat settings.We have a few users receiving this issue: Any help would be much appreciated.Thank you!
Seriously why is this still simply showing "failed" without any details/log/data???Suddenly one of the most important config profiles started failing on every mac for no reason and I can't figure out why as nothing was changed.
Hello everyone,What I need to do is, as I said, only allow users to change wallpaper (lock & home screen) but only giving them a few choices (branding purposes). Is there a way of doing this either with policies or configuration profiles?If possible, I'd like to leave out the default Apple wallpapers.Thanks!
Hello Jamf Nation, Have a question about the printtool in macOS. Currently all our users are standard, non-admin accounts. As such, whenever printtool tries to modify printer settings, users are prompted for an administrator username/password and are unable to authenticate. Was wondering if anyone has any methods to get the printtool notifications suppressed or potentially just add all users to have the functionality to be able to authenticate through the prompt?
Hi!we are facing an issue with ARD that started some months ago, in details:- No issue with ARD MDM command to enable it- Admin login authentication go through- Observe and Control doesn't work, it loads a while and the following error appears: " Make sure the remote computer is available and the firewall is not blocking screen sharing"- In ARD app on "current application" I can see that it shows the APP in use- TCP/UDP ports are all opened. From networks logs we can see that target device is not responding- ARD app release is the latest one 3.9.6- ARD agent is 3.9.8 - Tested on Ventura 13.2.1 / 13.3 / 13.3.1 Does anyone facing the same issue? Any workaround? Thanks! Daniele
We are an MSP that specializes in macOS and iOS, with macOS devices making up about 50% of total computers we support. Many are in Jamf Pro (separate cloud instances), and of those, the majority are ADE (vs. manually enrolled). All computers have an RMM agent installed, and we are looking to move to a different RMM platform. It would be helpful to know which computers have Jamf via ADE and which do not so we can anticipate which users will have permissions issues due to lack of profile-based PPPC control. Does anyone know of an option within the Profiles command that can identify the presence of the non-removable Jamf "MDM Profile" on a Mac? When I run the "sudo profiles -P" command, I can see all installed profiles. Some have human readable names, while others are just named with GUIDs. Nothing jumps out as the profile I need to verify. If one of the GUID entries is indeed the "MDM Profile" profile, then I'm going to assume the GUID is unique to each Jamf instance.I'm trying to a
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!