Get Support
Recently active
I know there's quite a few different ways people have tackled macOS Updates. In the past I've general leaned into the "encourage" users camp vs trying to brute force them. I've done a number of methods all to varying degrees. This week our CSOC identified CVE's that needed patching by getting everyone to macOS 11.6.3 or 12.2. Instead of guiding users to update, I'm actively trying to force them at certain actions (login/logout is my goal). That being said, I checked with Jamf about best practices and was pointed to this article -> https://docs.jamf.com/technical-papers/jamf-pro/deploying-macos-upgrades/9.96/Running_Software_Update_Using_a_Policy.html (we don't have any M1's so the article applies). I built my policy, applied it to some test boxes and, well, hit or miss. Specifically I'm running into this running software update locally: Last login: Thu Feb 3 11:22:11 on console Ed@TestBox ~ % softwareupdate -la Software Update Tool
My apologies if this post is redundant but I'm looking for a method of naming Macs as they are enrolled from a list. For example ORG-MAC-001, ORG-MAC-002, etc using the names sequentially and not allowing them to be used again. TIA
Hi Team,After enrolling to JAMF, the Apple Icon -> System Settings -> Apple Sigin. the page is empty and shows as data is not available. I tried re-enroll [remove JAMF and enroll back] & remove the user profile from /var/db/ConfigurationProfiles then again enrolling back. Finally, reset the Mac and then enroll the mac. but no improvement. Note: before enroll the mac its showing, but after enrolling to JAMF it's showing as not available. Only this mac having this issue. other all Macs showing correctly.could you guide me.
I am importing data from jamf into ServiceNow using the REST API (not using the graph connector because we are not licensed for it) and for some reason the Storage Section is not expanding so I can add those fields, other ones like userandlocation and hardware work and can be expanded, any ideas why this would be? You can see in my screenshot that the section is specified but the pill on the right the storage one is a string not an object...
Hello all,Question, Has anyone come across JAMF Pro blocking some system settings options such as User Groups, Network etc? If so, how do I remove it and still have MDM installed? Once I removed JAMFcompletely from the PROFILES option in System Settings, everything comes back normally. Here's a screenshot of the block. - Thanks.
I apologize as I am very new to the area of MDM. We are deploying iPads and iPhones to our employees, but while setting up the config profiles, I can't find a way to restrict which apple ID's are used. When checking the settings menu, I would like to remove or deactivate the ability to sign into icloud because these are for business use. Is there a way to make this happen or is there a way to force it to only accept managed AppleID's? Thank you in advance!
Just curious to know what are the most complex packages are there for macOS and we can easily build those package using by composer? I am looking for their name and why it is complex and which method I need to build it? Like SAP GUI is one of them what I can say any other please?
We started getting calls yesterday afternoon about Mac's that were restarting by themselves. If they had anything open, it would close the app and restart or it would just close that app and act like it was going to restart, but wouldn't. We have no policies running for updates. We did deploy Nudge a few weeks go and removed the json file that was stored on the devices, but we had a reboot today. Checked all the logs and nothing sticks out, just a lot checking for softwareupdates. Even Jamf said nothing stuck out, but provided them the sysdiagnose to check. The only thing that updated yesterday afternoon was Jamf Protect. We also noticed in the hardware and software history, that it's showing all the apps including built in apps as deleted and then added. We have a ticket open, just seeing if any of the veteran Jamf admins have seen anything like this.
Hi all,For a bit now our users have noticed that if they use chrome, they get prompted to sign into our various O365 logins over and over if they close their tab or window. This doesnt happen if they "sign into google" and turn on syncing. However anyone using a guest or unnamed profile in google loses their authentication once the window is closed. We are in the process of requiring MFA for all our staff however anyone with google is getting prompted over and over to sign in and get their phone pin, since each time they close their window it requires re logging in. This does not happen in Safari or Firefox, where once signed in, and you close a window, it remembers that you signed in. I started playing with plists for chrome to see if we could get this to work as it used to and figured it was something with cookies or related to guest browsing and I have yet to find the right plist to make this work. Anyone else seeing this?
Before updating Jamf showed that all iPads are in 16.4.1 version and need to update. After updating the shown version in still 16.4.1 and update is required. Update status is failed.If I look info from specific device I see that version has changed from iOS 16.4.1 20E252 to iOS 16.4.1 20E772520a but Devices -> Updates shows that all iPads require an update.
We have a configuration profile configured in Jamf Pro. Config is set to auto join users using PEAP and radius authentication with a saved generic AD username and password. When applied the associated ipads fail to auto join. If you then remove the config profile from the ipad, you are then able to connect manually adding the username and password (or any other AD user account) to the wifi SSID on the iPad. We are using Meraki access points for WIFI config.
Hello! I've recently started using the JAMF App Catalog of applications available and i've run into an issue i can't seem to put my finger on. I know on some Applications that don't have a application updater themselves, the icons will show as th exclamation point or the Self Service icon, but either way, my users are seeing the icons with the crossed out, buster, icon on top of the application. On the applications i've disabled the built in Configuration Profile, i've rebuilt the Application notification profile needed but that doesn't seem to help. What am i missing?
Hello! I've recently migrated a fleet of laptops into a new JAMF instance using JAMF Connect. Everything has gone smooth but i have two users with an issue i can't explain. When they log out for the first time and log back in, instead of being prompted to connect the user to a local account, it skips right past that part and creates a new user instead. I've only asked one of them to unenroll-renroll but that didn't seem to fix anything. I know i could move them over to the new account that is created but that might be painful. Any thing i'm missing or can check? Right now they are just having to log out and log back in Locally to get to their original account where all their local data is. any help would be appreciated, thanks!
I have been getting an error every time I run sudo jamf manage. Has anyone seen an error like this before? It seems to be the root of a lot of other issue in my environment. It started when I upgraded my on prem instance from 10.36 to 10.45Errors: - code=INVALID_STATE description=Internal Server Error id=0 field=null 2023-05-08 15:18:14,991 [DEBUG] [Thread-3 ] [lientCommunicationServlet] - Error processing communication content com.jamfsoftware.api.core.exceptions.ApiException: 500 INTERNAL_SERVER_ERROR "500 [code=INVALID_STATE description=Internal Server Error id=0 field=null]" at com.jamfsoftware.jamfmanagementframework.impl.computerinventorycollectionsettings.ComputerInventoryCollectionSettingsServiceImpl.lambda$collectWhenOnlyOneIsPresent$0(ComputerInventoryCollectionSettingsServiceImpl.java:49) ~[jamf-management-framework-impl-10.46.0-t1681398190.jar:?] at java.util.function.Function.lambda$andThen$1(Function.java:88) ~[?:?] at java.util.stream.ReferencePipeline.collect(Refer
Hi all,We're piloting Snipe-IT in our environment and we're trying to automate as much of the asset collection as possible. I found Jamf2Snipe a couple of days ago (https://github.com/ParadoxGuitarist/jamf2snipe/) and got it working, but as soon as I did my sync I realized that I'd made a few mistakes in my config file. I've fixed those, but now that I'm trying to resync...nothing is happening. If I run Jamf2Snipe in verbose mode, it says it's processing all the computers in my Jamf Pro tenancy but the computers aren't updating in Snipe-IT. Anyone able to shine some light on what's going on here? TIA!
Does anyone here have experience connecting iPads to the NYC Dept of Ed wifi networks (ncpsp) using a configuration profile. I've got the network and password setup correctly but am not able to make a connection via the configuration profile. I can only connect entering the password by hand. I think I must have one of the parameters set incorrectly. Long ago, I remember NYCDOE required special proxy settings but I don't know what that would be currently. Any clues are appreciated. Thanks.
Has anyone been able to this without using Configurator or touching each device?
We're installing Adobe Creative Cloud (formerly the Desktop Manager), and it needs to auto update before you can use it once it's out of date. But that auto update requires admin rights, which we don't give users for security reasons. We don't want to repackage this every time there's an update available. Working through the workflow, I noticed it first downloads the installer app to a temporary folder in /private/tmp/XXXXXXXX. If it used a local updater, I could launch it through a Self Service policy and we'd be fine. However since it's a random folder, I can't do that. Does anyone run the updater somehow without granting admin rights to users? I found this thread and tried the script, but still get prompted for admin rights:
Hi All,I can see in Menu Bar App Settings - Jamf Connect Documentation | Jamf it says that Microsoft DFS shares are not supported in Jamf Connect at the moment.Are there plans to implement Microsoft DFS support ? If so is there an estimated release date for the functionality ?Thanks !Sam
I know you can skip different setup assistant windows, but we still get an Analytics window that we'd like to hide.https://developer.apple.com/documentation/devicemanagement/setupassistantHas anyone come up with a way to hide the Analytics window?
Oops! I deleted a computer from Jamf Pro by mistake. The computer is still being used (I thought it was out of service). What do I do to get it back into Jamf and managed? I tried to manually enroll it but the MDM Profile that gets downloaded to the machine isn't fails to install ("New profile does not meet criteria to replace existing profile.")Help!Thanks! --Jeff
Hey all. I'm still fairly new to all this. I've been trying this for a couple of days now, and I cannot seem to get the proper permissions for AdminByRequest to work. Per this article, I need to allow SystemFilesAllAccess for ABR. I've been using PPPC Utility to created the profile, and I have tried a few different combinations of settings, but none of them have worked. I know it will not show in the Security settings on the Mac, but in profiles, my PPPC is there, and it still not working. I've uninstalled and reinstalled the app with the profile applied, still nothing.Has anyone had any experience like this, whether with ABR specifically, or another app, that could give me some pointers? This has all been on a singular test computer on Monterey, and I need to try to deploy this PPPC to about 80 or so machines, so the manual route is not really an option. Thanks,C
Hello dear Jamf community,I hope you can help me here. I'm very desperate and can't find any help.We have 17 iPads connected to Jamf-School at work.Some apps won't install or update. It says "Wait" all the time, but nothing happens even if you update the app via the Jamf administration etc.Does anyone know the solution to this?
I've getting reports of people that have upgraded from an older OS (anything from 10.14.x on up to 12.x) to Ventura, but it seems like a significant portion of them put in their credentials at the FV screen but never get a desktop. The progress bar seems to halt around 3/4 of the way through. The support technicians noticed it's a lot of the Intel Macs vs the M series, but I haven't been able to confirm it. Further, it seems like it may be related to a login script and home drive mapping in AD for their accounts. Typically we can clear that and have them reboot on the corporate network. The issue becomes when users are remote and can't get to an office building. The accounts have all been AD mobile accounts. Typically when I'm working on those devices I will convert them to local accounts and then use Kerberos Extensions to handle the AD relationship. Curious if others have run into this? I haven't been able to reproduce it on
Working with Internal Services and Jamf Safe Internet Earlier in the year, we released our education-focused security tool, Jamf Safe Internet, which focuses on keeping students and teachers safe online. As the adoption of Jamf Safe Internet increases, so do the use cases. A common use case that has become clear in the months since release is the ability to connect to internal services, such as file servers (for storing data), web servers (for platforms like Moodle) as well as a host of others. Due to the way that Jamf Safe Internet is designed to push all DNS requests to the DoH Gateway in our Security Cloud to evaluate domains against allow/block & security policies (fig1), education institutes aren’t able to access internal services without some advanced configuration. fig 1 - basic diagram of Jamf Safe Internet flow In order to better understand why we need to add the advanced configuration to our Jamf Safe Internet deployment, you will require a basic knowledge of
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!