Get Support
Recently active
Can someone with more experience assist me in creating a package with Composer to install Velociraptor? Here is the information i was provided, the only thing i was given plus the client.config.yaml file. Due to restrictions with Mac OS, a binary with a custom configuration file bundled is unable tobe compiled. For this reason, the install requires specifying a config file when launching theagent.The service install directive can be used to install the agent on Mac client. The followingcommand installs binary & config to /usr/local/sbin.• <velociraptor_file> --config client.config.yaml service installNote: The “client.config.yaml” file will be provided by Stroz Friedberg and included in the uploadportal.The service can be uninstalled with the following command:• /usr/local/sbin/velociraptor service remove --config=/usr/local/sbin/velociraptor.config.yaml• Confirm with ps -eaf | grep velo and sudo launchctl list | grep velo I am assuming i need
Today we released Jamf Connect 2.23.0. This release includes the following changes and improvements: You can download all Jamf Connect logs from the past 30 minutes using the jamfconnect logs command in Terminal. For additional information about the command, use jamfconnect help logs. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. Thank you!The Jamf Connect team
Hi all, I'm back again with another question on how to implement some settings from the CIS Benchmark. We are stuck on requiring an administrator password to access system-wide preferences. I've been doing some research on the issue and I've been hitting a dead end. I found the extremely helpful blog of rtrouton (https://derflounder.wordpress.com/2014/02/16/managing-the-authorization-database-in-os-x-mavericks/), but this doesn't seem to be working in Sierra. Does anyone know a good way to script this change? Thanks!
How can one remove an Extension Attribute that was created from a "Patch Management Extension Attribute" template?I do not see how in the official Jamf Pro admin guide instructions.Admin Guide Link - Creating a Computer Extension Attribute from a Template Creating a Computer Extension Attribute from a TemplateJamf Pro has built-in templates for many commonly used extension attributes.Log in to Jamf Pro.In the top-right corner of the page, click Settings Click Computer Management.In the ”Computer Management–Management Framework” section, click Extension Attributes Click New From Template.Click the extension attribute template you want to use.(Optional) Make changes to the settings as needed.Click Save .
I’m the director of technology for my school. We are thinking about moving to Jamf School for our iPad MDM solution. We currently use VMware Workspace One. One of the features I love about our current MDM is that it has an app catalog on all the iPads Home Screen. When you go into it, it opens a webpage in safari that show all of the apps that are assigned to that specific iPad (or group). We’re able to quickly install or reinstall an app directly from the iPad.Does Jamf have a similar offering?
We control our iPads using JAmf, and I'm having an issue with the Diagnostic feature of i-Ready and MClass. MClass displays a white screen while trying to asses, and i-Ready displays a blue screen. I already whitelisted all the required websites.I did a system check using i-Ready and Mclass verification tools, and all seems ok. Any idea what the issue can be?
Hey allwhat's the user impact when you switch from conditional access to device compliance?Will the user notice anything?does it work very different?thnx
Hi All, does anybody have a working XML for Palo Alto GlobalProtect on IOS? I can get the client installed but not configured at all. Palo support punted it saying it's not a supported MDM :(
I currently have policies and configs pointing to a static group. I'd like to start using a smart group in place of it. If I add all my devices to the new smart group and start pointing the policies and configs to it, will it redeploy everything? I've added a few test devices to the new smart group (with criteria) and have not noticed any changes and do not get the prompt to push to only newly assigned devices, etc. The logs also do not show any activity. Just want to hear other peoples findings. Thanks
Is there a way to enable reasonable security audit log retention via script to comply with CIS Level 1 requirements? Thank in advance
Hi everyone, I'm stumped.One of the higher ups at my work noticed a "your screen is being observed" message on their mac over the weekend and they're a little concerned. I'm looking for clues.I used to be able to look for "screensharingd" in the system.log file and it would at least give me a time stamp and an IP address but that no longer seems to work (computer is on Ventura).Does anyone know where the logs for this have moved to?Thanks in advance. Please feel free to let me know if you have any questions or anything.
All my apps are failed whenever I try to install from Self Services. When I run sudo jamf policy it just said "There was an error. Message has no content". Does any one have any idea?
Hi, I would like to know which devices does not have a specific application for example keynote. Are there any ways to run a search and export the report using JAMF School?Thank you
Hello, I was under the assumption that Config Profiles in Jamf Pro would prevent even admin from changing the configuration defined. However, that doesn't seem to be a given. For example I have enabled the Firewall using the native settings under Security and Privacy in Jamf Pro config Profiles. However, Sudo user are still able to disable the firewall in the terminal for example using sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 1 Is it possible to completely block an admin from changing a specific subset of settings using jamf pro. Without removing admin rights all together.
Hello All,Apologies if this is the wrong audience. I am still fairly new to JAMF (and device management overall tbh). Both Jamf Pro and Intune have the concepts of Extension Attributes (EA) however, from my limited experience i don't believe Intune can validate the status of EAs in the Intune Compliance Policies. Is my assessment true or does anyone know of a way for Intune to validate an EA allowing the admins to broaden the set of criteria included in the Compliance Policies.
We are fitting a new Media room out with 20 Mac M2 pro mac mini units and everything is working fine apart from our power schedule. We have a config profile rolling a power off at 10:15pm and power on at 07:30am. It looks like the power off is working fine but is not powering on at the scheduled time.We have a new room (installed last month) of the M1 iMac's on the same version of Ventura (latest) and these power on and off fine.I have checked on the local Mac Mini with the pmset and the schedule is correct, is their anything I can check, assuming is not Ventura related as its working on M1 iMac's fine.Any ideas or help would be greatly appreciated. Cheers David
For new devices and troubleshooting older devices with an OS reinstall, we use the "enrollment" trigger for many of our Mac policies. We have been avoiding creating separate Intel and M1 packages for apps as much as possible. Rosetta has been capable of running all our Intel-based packages on M1s so it hasn't been an issue but I don't want to rely on Rosetta indefinitely. I would like to be able to install either the Intel or M1 versions of apps on enrollment. Is there any JAMF Pro setting I'm missing for the enrollment trigger being able to install the appropriate architecture/processor based package?Looking at alternative solutions: Eventually, our fleet wont have any Intel Macs but until then we still push a pool of default apps to our fleet and use Self Service to make non-essential/optional apps available. Without the enrollment trigger we have relied on having to flush once per computer policies for OS reinstalls or making policies set to "ongoing" at startup with smart groups to
We have begun using Twocanoes Xcreds, replacing NoMAD Login AD. In the process, we are also attempting to discontinue implementing a common local administrator account with a known password. This type of setup was demonstrated in a session at JNUC this year (although their example used Jamf Pro and Jamf Connect, not Jamf Pro and Xcreds... the principles should be the same though.)However, despite repeated attempts, I cannot reliably get the bootstrap token to escrow automatically at first interactive login, as I'm led to understand is supposed to happen. I can manually log in as a user on the system, then open Terminal, su to the Jamf Pro-created admin account, and initiate a sudo profiles install -type bootstraptoken, and it escrows without incident.I have to imagine it's SOME combination of settings that I don't have configured properly, but I don't know what.I currently have:In "User-Initiated Enrollment:""Username" is set to <admin user name>"Password" is set to <admin pas
The previous System Admin used a script to rename our laptops in AD, JAMF, and the local machine, which worked until a month or so back. I found the script we currently use in this thread answered by "luke_reagor" However, now, only part of the script works to rename in JAMF and the local machines, but, makes no changes in AD.Microsoft and Apple have been releasing more and more updates related to security and encryption and my thought is that the new updates have broken that script somehow. Has anybody seen or heard about this issue? I did notice that if I manually unbind/rebind to AD the computer name gets updated, but, that won't work in a 500+ employee environment. Any input will be greatly appreciated and if there are new ways to rename bound computers to AD, input your $0.02 cents here.
We have a lending program with around 100 Macbooks. We use the "Lock Device" feature to lock down late or lost machines. A few weeks back we had to lock a few machines. They were returned, unlocked, and loaned out a few more times. Yesterday and today we had those same machines lock on their own with the same code used before. 3 of them so far. Has anyone experienced this? How can I stop that from happening? I've checked logs and saw no command to lock the device a second time coming from JAMF. Only 3 people have access to lock devices and none of them sent the second command.We have these set to "Prevent Users from enabling activation lock" in prestage.
Hello,I am new to Jamf Pro and scripting and would like to know if there is a way for me to auto-name the computer by Building-Department-AssetTag#, Example: NY-LAB-01 the Asset# has to start from 1 and up for each department, not sure how to accomplish this, thank you for all the help in advance.
Hi,I'm currently configuring Jamf Connect and having a bit of difficulty. I am using Azure AD as an IdP.What I'm currently experiencing:Turn on new Mac > Select Country > Connect to Network > Remote Management hits > Authenticate with Microsoft Azure > Remote Management loads profiles/policiesOnce Remote Management configuration is complete it brings me to the standard/normal Mac login screen.I enter local administrator credentials. This user was created during PreStage Enrollment > Account Settings before the Setup Assistant.Jamf Connect Sign In pop's up and Jamf Menu also loads. I can enter my UPN and password and sync the local account which does not align with my AAD account name because it's the local-admin account.If I run the AuthChanger script from terminal I can log out of the local-admin account and the Jamf Connect GUI will appear. sudo authchanger -reset -JamfConnect I will receive 1 of two errors:If no ethernet is plugged in I receive err
Google Chrome has created a great tool for a user to cover their tracks after their browser session has concluded. I need to figure out how to turn it off or at least make it difficult to access. The web filter we have is outdated and we're awaiting a new device to pilot, but we're trying to stay ahead of this in the meantime. Thanks for any info. DVG
I have setup EFI password for a static group. The Policy was applied. I have pushed another policy to remove the EFI password. The 2nd policy not triggering:- Exclusions is not over scoping target.- No machine set in pending, no logs, sudo jamf policy "nothing found''.- Policy clone, retire exclusion, change target group to one signe machine : same- push another policy: ok
I have several users who do not want this option. We are using the AD functionality in JSS to bind the machines to the domain which creates mobile accounts. I have unchecked the "Use UNC path from Active Directory to derive network home location" But "Force local home directory on startup disk" is greyed out and selected. I am not sure if this is what is mounting that when they first log in and getting a "directory.org cannot be mounted" error. Any ideas?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!