Get Support
Recently active
The previous System Admin used a script to rename our laptops in AD, JAMF, and the local machine, which worked until a month or so back. I found the script we currently use in this thread answered by "luke_reagor" However, now, only part of the script works to rename in JAMF and the local machines, but, makes no changes in AD.Microsoft and Apple have been releasing more and more updates related to security and encryption and my thought is that the new updates have broken that script somehow. Has anybody seen or heard about this issue? I did notice that if I manually unbind/rebind to AD the computer name gets updated, but, that won't work in a 500+ employee environment. Any input will be greatly appreciated and if there are new ways to rename bound computers to AD, input your $0.02 cents here.
We have a lending program with around 100 Macbooks. We use the "Lock Device" feature to lock down late or lost machines. A few weeks back we had to lock a few machines. They were returned, unlocked, and loaned out a few more times. Yesterday and today we had those same machines lock on their own with the same code used before. 3 of them so far. Has anyone experienced this? How can I stop that from happening? I've checked logs and saw no command to lock the device a second time coming from JAMF. Only 3 people have access to lock devices and none of them sent the second command.We have these set to "Prevent Users from enabling activation lock" in prestage.
Hello,I am new to Jamf Pro and scripting and would like to know if there is a way for me to auto-name the computer by Building-Department-AssetTag#, Example: NY-LAB-01 the Asset# has to start from 1 and up for each department, not sure how to accomplish this, thank you for all the help in advance.
Hi,I'm currently configuring Jamf Connect and having a bit of difficulty. I am using Azure AD as an IdP.What I'm currently experiencing:Turn on new Mac > Select Country > Connect to Network > Remote Management hits > Authenticate with Microsoft Azure > Remote Management loads profiles/policiesOnce Remote Management configuration is complete it brings me to the standard/normal Mac login screen.I enter local administrator credentials. This user was created during PreStage Enrollment > Account Settings before the Setup Assistant.Jamf Connect Sign In pop's up and Jamf Menu also loads. I can enter my UPN and password and sync the local account which does not align with my AAD account name because it's the local-admin account.If I run the AuthChanger script from terminal I can log out of the local-admin account and the Jamf Connect GUI will appear. sudo authchanger -reset -JamfConnect I will receive 1 of two errors:If no ethernet is plugged in I receive err
Google Chrome has created a great tool for a user to cover their tracks after their browser session has concluded. I need to figure out how to turn it off or at least make it difficult to access. The web filter we have is outdated and we're awaiting a new device to pilot, but we're trying to stay ahead of this in the meantime. Thanks for any info. DVG
I have setup EFI password for a static group. The Policy was applied. I have pushed another policy to remove the EFI password. The 2nd policy not triggering:- Exclusions is not over scoping target.- No machine set in pending, no logs, sudo jamf policy "nothing found''.- Policy clone, retire exclusion, change target group to one signe machine : same- push another policy: ok
I have several users who do not want this option. We are using the AD functionality in JSS to bind the machines to the domain which creates mobile accounts. I have unchecked the "Use UNC path from Active Directory to derive network home location" But "Force local home directory on startup disk" is greyed out and selected. I am not sure if this is what is mounting that when they first log in and getting a "directory.org cannot be mounted" error. Any ideas?
In the last two weeks, this is the second time that I have seen multiple posts that have the exact same headline, body, and questions. It looks like Jamf nation is now a part of the global environment by getting trolled by spammers just wanted to give everybody a heads up in case they haven't seen this either. @jamf11 I know its hard, but maybe you can be the leader of the pack and find some way to avoid this?
No one likes spammers, including the Jamf Nation Community team! Here are some methods for reporting spam. If you spot a forum post, question, or blog comment that appears to be spam, please flag it to the Jamf Nation team by clicking the Report Inappropriate Content, that you can find in the message Options menu. Did you receive a suspicious Private Message from another user? To report this issue to our team, click on the Report link at the bottom of the message, and we'll handle the abuse as soon as possible. Please include the username and content of the message you received. Let us know if you have any questions! Thanks for your help in keeping Jamf Nation spam-free!
A massive thank you to all our Tech Thoughts authors! Every week we get submissions on outstanding technical topics for our community members to read, and it does not go unnoticed that this is a huge effort on the authors' part. So @tom_koehler and I wanted to take a moment to reward our authors for their published posts with a gift card to a popular online store that offers anywhere from a trombone to a last-minute gift for your dog's birthday. Congratulations, @jflanakin, author of Certificates, SCEP, and 802.1x: What are they? What do they do? Let’s find out! (Part One) and @bweber26, author of Introduction to JPS API Wrapper: All-in-one package for using the Jamf Pro Server API! Thank you again to all our authors! And for those who did not win today or have yet to publish a post, do not worry; there will be more opportunities to win in the future. The first step is to submit your Tech Thoughts post!
By default, when an Office 2019 app is installed, Microsoft AutoUpdate will automatically launch. I don't want that to happen (we handle patching Office apps through a patch policy in Jamf), but I'm having little luck. As part of our Office 2019 deployment policy, I have a script that runs prior to the installation to populate a few settings in /Library/Preferences/com.microsoft.autoupdate2.plist. I'm setting things like HowToCheck to "Manual" and disabling the data collection policy prompt, but another option that I'm adding is IgnoreUIOpenAfterInstall. That's a relatively new option for MAU which, according to Microsoft's release notes, was added in the fall of 2020. That's supposed to do what I want, not launch MAU after Office is installed. Problem is, I can't find any documentation about that option anywhere, just that it was added. I'm trying to set it with a boolean value of TRUE, but it doesn't work -- MAU still launches. It's also not listed in any of the MAU preference refe
Hello, does anyone know the max number of devices you can send a remote command to? I used the action tab in one of my advance searches to Send Remote Commands to over a thousand devices but it never completes the task. It only spins.
So we have an iMac setup for our Autopkgr server. It was working fine for almost 2 years then stuff went down hill 3-4 months ago and I put it aside as I had other projects in the works. This week I did a clean install of MacOS Ventura 13.3.1. I then went through all the steps to install and configure Autopkgr as well as Autopkg. Everything looks right until I either try to create an override or search repos. Screenshots attached. Any help would be appreciated. Thank you
Customer Education is back again with our next Jamf Pro Release Notes video! Join us for an overview of some of the new features and enhancements that are available in Jamf Pro 10.46. We hope this resource continues to provide additional details to support your use of the features in this release. Thank you all for the continued feedback as we look to improve each video. Feel free to leave a comment and let us what you liked and how we can make it even better next time. We look forward to hearing from you! And don't forget to take the three-question quiz below to test your knowledge!
Hi all, i have a question about locked user accounts. Is it possible to deny complete access to a MacBook after the user has been locked in Microsoft Azure? We recently had a case where a user was locked out but still had access to his MacBook through his "local account".Is this possible or do we always have to click on Lock Computer in Jamf?
HI,Need to display a popup message for os update with steps to all devices. We have created a test policy and using interaction tab displayed the message with test devices. but unable to expand the notification and its very small too to miss. is they any script file to display the message notification in a frequent time intervals until the os got updated on that device.
One of my client is reporting high memory usage on his computer. memory usage gets higher ans higher as it's goes on. any suggestion of how to stop my client's from crashing. it's checking in every few seconds. I keep seeing this on the jamf log: No patch policies were found.Checking for policies triggered by "recurring check-in" for userChecking for patches...
An issue while ForeScout SecureConnector integration with Jamf ProAlmost the integration is completed but we have observed an issue that in most of the machines, it's not showing in the menu bar which supposes to be.is anyone integrated this before? please advise
We are managing iPads out in the field and it has become necessary to completely lock down use of apps using the "Only Allow Some Apps" setting and then providing a list of the specific list of apps that can be installed on the device This, however, leads to a problem using Web Clips....once the configuration profile with all the restrictions is distributed to the device, all of the web clips applied to the device disappear. If you remove the restrictions, the web clips reappear. Is there a way to make the web clips unrestricted, or work around the app restrictions so that they continue to appear?
Jamf Cloud - communicating with SCEP server via https, where do you obtain a 3rd party certificate, as per below diagram/ Also referenced in youtube snippet. REF: https://www.youtube.com/watch?v=jn0HTWKubFY
I have an (non admin) end user using VMware Fusion 13.0.2 on a MacBook Pro M1 13.3.1.I've used PPPC Utility to set up a Configuration Profile that has "Accessibility - Allow" for Fusion.The end user still gets an error when they start Fusion to allow Accessibility. They are getting the profile and other profiles are working. Any insights would be appreciated.
Seeking some with Jamf Connect Implementation,We have purchased Jamf Connect after a month or so of testing and even now there still appears to be issues. Initially the ability to change passwords within the Jamf Connect Application was working, and now all of sudden it has stopped with no change to the configuration received by a Jamf Engineer. The workaround implemented that we received, gave an expanded window from the Menu Bar when you selected change passwords. Now Reset Password remainsChange Password reflects "Actions"But the "Click here to change password." window remains.To make matters worse MFA is working sometimes and sometimes it is not. Any help anyone could suggest here would be great.
Since last week every iPad gets a flashing box (see below) of an update that's failed.No-one is able to exit out of the error despite hitting OK multiple times. As a result this renders every iPad unusable.Powering it off and on again solves it; however, anywhere between 10-60 minutes it's back again!
Purpose: While Jamf Pro can deploy multiple packages as part of a pre-stage enrollment, some MDMs are not capable of this. Alternatively, if a client computer is on a slow network connection or a user proceeds through Setup Assistant very quickly before Jamf Connect can be installed, a user may experience an unexpected result of getting a macOS login screen. By wrapping the Jamf Connect installer package in another installer package with assets and a postinstaller script, administrators can add custom branding images and scripts in a single package. Tools required: Jamf Composer or similar tool to create .pkg files. Procedure: Collect wallpaper images, branding logos, help files, scripts, and any additional assets needed for a zero touch deployment of Jamf Connect. Refer to https://www.jamf.com/blog/zero-touch-deployment-with-jamf-pro-and-jamf-connect/ for a larger discussion on this topic. Keep the assets to be included in the file as small as possible. For best user experience
Hi all, I am trying to find the plist that I can target to restrict Nessus Agent from being clickable in System Prefs. Any ideas?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!