Get Support
Recently active
I have been working on this all day and cannot find a way to make this work. We want in our IT lab, to show ALL filename extensions for all users. Essentially, if we use the com.apple.finder.plist for the user template and enable it for one user, it is set for true. However, when we use this as our basis, new users logging in have it set to true, but the filename extensions is still unchecked in Finder preferences. There must be a trigger for this I am simply missing or overlooking. Has anyone done this successfully? Thanks for any insights you can offer me. Mick
Trying to get Autopkg installed, fresh install following all the steps and i keep getting the following error... google has got me no where so far. Using Autopkgr anything i do brings up this error... every error points back to default preferences. WARNING: Did not load any default preferences. WARNING: Could not set RECIPE_REPOS preference: Could not synchronize preference RECIPE_REPOS WARNING: Could not set RECIPE_SEARCH_DIRS preference: Could not synchronize preference RECIPE_SEARCH_DIRS
Hello Team,This is with regards to MAC performance testing .We are in process of streamlining and identifying a tool which would help us to benchmark MAC system performance across various models (PREFERABLY A LICENSED SOFTWARE) and various enrollment plan changes .Basically, we need a tool to benchmark system performance like CPU,GPU and Disk speed (Read/Write) after the every change we make to our environment.Can anyone suggest on the tools that we can use.Thanks,Manivannan
We have been through multiple phases launching Jamf Pro. We began on Jamf Now and migrated many users and now we are enrolling directly onto Jamf Pro. In the process, we discovered that a number of computers do not have Activation Lock Bypass configured. I have searched for ways to resolve this without success.Is there a Configuration Policy or Policy I can create that will enable that? If so, I am all eyes/ears.
Hello everyone,I have noticed that out macs local admin account has secure token disabled. Standard accounts are not admin and have secure token enabled.I wonder I can push a script on logged in accounts to enable secure token for local accounts.I ran below command locally: sudo sysadminctl -secureTokenOn "username" -password "password" -adminUser "username" -adminPassword "password"Got error: 2023-04-24 11:37:52.233 sysadminctl[2349:18595] ### Error:-14090 File:/AppleInternal/Library/BuildRoots/a0876c02-1788-11ed-b9c4-96898e02b808/Library/Caches/com.apple.xbs/Sources/Admin_sysadminctl/addremoveuser/main.m Line:3772023-04-24 11:37:52.234 sysadminctl[2349:18595] Operation is not permitted without secure token unlock.Grat stand account admin rights: same,Any idea?
Hey all, I'm looking to restrict our users (K-12 students) from enabling Full Keyboard Access in System Preferences - Accessibility - Keyboard. I've identified the plist key value, FullKeyboardAccessEnabled and FullKeyboardAccessFocusRingEnabled, created a plist and set the -int to 0 and uploaded it to Jamf in a profile with Application & Custom Settings. While I'm used to custom .plist files "graying out" the option to enable/disable items, this one doesn't seem to do anything to restrict the user. Thoughts? This would only be a temporary management profile to get our district through state testing. I don't like locking down Accessibility options, but a request has been made.
Education School in Reading Pa - Running into a issue for sevaral months now where I get the following error message - Oranage saying Jamf School is unable to communicate with the device in a timely manner. Also I have having a issue where the app's will not download or stay grayed out and awaiting download. Another issue i see is that my Device name is reverting back to "iPad" after a IOS update. Jamf School states it is a issue with Apple and not able to communciation with the device. Anyone else seeing these issues and are able to help ?
Hi folks.I try hard to get VPN On Demand to work. Unfortunately, it currently does not work with Jamf Pro's built-in way (PI-101098), so Jamf Support referred me to iMazing Profile editor. Getting bits and pieces from various web resources together, I tried to built a working VPNOnDemand.mobileconfig by myself, but as soon as I deploy it to my client, it does not have any affect.The VPN on Demand configuration should basically do the following:1.) If client connected to a certain company WiFi network ("SomeWifiNetwork" in the example), it should generally NOT use VPN at all.2.) If NOT connected to the WiFi network above, but any other network, it should ALWAYS establish a VPN connection while trying to connect to certain domains (example1.com and example2.com in the example).3.) Trying to connect to VPN server via L2TP ("1.2.3.4" in the example), shared secret included ("SHAREDSECRET" in example), user name and password should be prompted (hence not included in example).When I deploy i
If you have multiple virtual MDM's in apple school manager linked to different sites in Jamf, you assign a device to one of the MDM's in ASM and you have the setting Automatically assign new devices that is in the assigned MDM/Site's PreStage will it only assign devices linked to that MDM/Site in ASM? I.E. does the PreStage setting "Automatically assign new devices" work when you have more than one MDM in Apple School Manager?
Hello , I want to deploy Zscaler app using self service , but when standard user want to install it , need to type admin password for modify system keychain. Do you know some way how to solve this? or add more admin privileges to this app?Thank for help
I'm pondering the idea of leveraging a Extension Attribute that could theorietically report/verify the existence of a specific root CA certificate in the OS X System Keychain. Based on the results it yields, I could add/delete certificate(s) as needed via scripts/policies, etc. Has anyone invented this wheel yet?
Is there a way to remove the news previews from the Today View widgets? There are inappropriate news articles that show up for students and parents are wanting this blocked. I have the widgets blocked but it doesn't remove them from that view.
Hi, I know some of you are using Installomator to update third party software and since I need to clear some time I decided to give it a go on a small part of our Macs. They are more or less all the same under ventura. Works great on most of our macs, but for some reason, it does not work on several of them, the logs is giving the same error : firefoxesrpkg : ERROR : Error veryfying Firefox.pkg error : Firefox.pkg: rejectedsource =no usable signature. Any recommendations ?
Hi all,We are using Jamf Pro server on-prem in a network environment disconnected from the Internet.Jamf Pro servers and devices are communicating with Apple through a proxy.In this case, is there a way to use the ABM device as an ADE without the intervention of the administrator?Please, help me.
We have a fleet of mac and we're trying to prevent users from automatically upgrading their macs to macOS Ventura or any other new macOS that Apple releases. This prevents us from users accidentally breaking their software which do not work with the latest macOS. Is there a way to do this in Jamf? Thanks,
Is there a way to access the Control Pannel while in Single App Mode for Jamf Pro. I would like the ability for the users to be able to change the brightness, as well as lock the rotation of the screen when needed. Please advise.
I've started playing around with the Microsoft Enterprise SSO plugin to compliment Jamf Connect. For end users, this seems like an easy no brainer setup. The problem comes with our IT tiered accounts setup. In our environment, standard users have a mundane account while IT tends to have a Tier 2 account, server admins have a Tier 1, etc. This was done for various security reasons, and generally works well for us.This setup does not play nicely with the Microsoft Enterprise SSO though. For example, in my testing I effectively get locked out of Jamf because the Microsoft SSO auto applies the mundane account and Jamf doesn't have a built in account switcher I could use to swap to the appropriate tiered account.Does anyone have any recommendations on how to handle this edge case? The vast majority of our users won't have these tiered accounts, but those that do will be pretty vocal about things not working. I don't see a way to exclude specific sit
On occasion we have Macs repaired that require a motherboard swap. If we don't remove them from Jamf before the repair, then when we get them back it enrolls as a completely different computer that just so happens to have the same serial number. We are using a script to rename all computers to their serial numbers. This means that after repairs we will have 2 entries for basically the same computer. What I'm doing now is I will export the list of all computers and use Excel's conditional formatting to find duplicates for me. Then I locate the duplicates in Jamf and delete what is the old computer record and keep the new computer record. Is there a way to use a smart group to put together Macs that have the same name? Sure, I could build a smart group to look for all computers named "C02XXXXXXX" but that would require that I already know which ones I'm looking for. If I had a small number of computers then I could skim the list manually and pick out the duplicates, but with over 1300 Ma
Hi All, I am fairly new to scripting and am humbly requesting help. We use the following script to rename the Computer Name to Asset Name(via what is uploaded in Inventory Preload). What I found, is I also need this script to enable Dynamic Host Name and set that name to that same Asset Name. I cannot get that last piece to work and believe it was incorrect, so I have removed it and asking the community. Here is the script I am using to set Computer Name to Asset, which has been working great. I am hoping to be able to use this same script and add the piece to enable naming of the Dynamic Host name as well. #!/bin/bash#set the variables for the server and API accountjssUser=UserNamejssPass=PWjssHost=https://tenantname.jamfcloud.com#get the serial numberserialNumber="$(ioreg -l | grep IOPlatformSerialNumber | sed -e 's/.*\\"\\(.*\\)\\"/\\1/')"#get the asset tag from jamfassetTag=$(/usr/bin/curl -H "Accept: text/xml" -sfku "${jssUser}:${j
I am creating a Jamf Pro User group for our Help Desk, and I want them to have the ability to use some or all of the Management Commands available. Which privileges do I assign to the group? Right now all they have is Send Blank Push..
Does anyone has some working screensavers script that can be working on ventura. So in the script a folder is defined, that should make slideshowI used this one below, but it seems not anymore to work #!/bin/zsh # Get user logged into console and put into variable "user" user=`ls -l /dev/console | cut -d " " -f 4` export SYSTEM_VERSION_COMPAT=1 osMajor=$(sw_vers -productVersion | awk -F"." '{print $2}') osMinor=$(sw_vers -productVersion | awk -F"." '{print $3}') sudo -u $user defaults -currentHost write com.apple.screensaver CleanExit -string "YES" sudo -u $user defaults -currentHost write com.apple.screensaver PrefsVersion -int 100 sudo -u $user defaults -currentHost write com.apple.screensaver showClock -string "NO" sudo -u $user defaults -currentHost write com.apple.screensaver idleTime -int 700 if [[ $osMajor -eq 14 && $osMinor -ge 2 ]] || [[ $osMajor -ge 15 ]] ; then sudo -u $user defaults -currentHost write com.apple.screensaver moduleDict -dict m
Hi all,We have our Macs AD bound with mobile accounts, and starting with Big Sur we've had several users run into an issue when trying to use sudo in a terminal window. They'll get the error that they're not in the sudoers file. Normally they'll be standard users using Privileges and it will work, but for some, sudo has stopped working altogether.We've tried converting the mobile accounts to local accounts but this didn't solve the issue either. Has anyone run into similar issues?
My boss asked, "How much data do our users save on their Macs?"Anyone know how I can figure this out? I manage around 800 Macs with Jamf Pro and they don't all have the same size of internal drive, so looking at something like "boot drive percentage full" or "boot drive available MB" isn't too helpful.Thanks, --Jeff
We are working on a Secure Token policy and have traced the issue to the Parameter Labels not resolving. Here is the script we made to test it: #!/bin/sh ## Pass the credentials for an admin account that is authorized with FileVault 2 adminName=$4 adminPass=$5 userName=$3 ## Prompt for Password userPass=$(/usr/bin/osascript<<END application "System Events" activate set the answer to text returned of (display dialog "IT needs to Activate Encryption, Please Enter your Password:" default answer "" with hidden answer buttons {"Continue"} default button 1) END ) # create the plist file: echo '<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Username</key> <string>'$adminName'</string> <key>Password</key> <string>'$adminPass'</string> <key>AdditionalUsers</key&g
Hi,We need a way to stop dummy eicar malware files being downloaded from online in Chrome, Edge and Safari.It looks like Jamf Protect or Jamf Radar can not do this. It can only stop the files being executed after they have been downloaded to the Macbook. Is there a way we can implement download restrictions using Jamf Pro?thanks
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!