Get Support
Recently active
We have SSO enabled (and working) in our environment, but the only thing that it does not work for is the Jamf Admin app. Is it possible to enable SSO for Jamf Admin? Or will it only accept Jamf account credentials?
HiI have a iPad Pro 12,9 - 2018 with iPadOS 14.0.1The Profile EDU fails to update.I'm looking for a solution. Thanks,Matthieu
HelloI have macOSc Monterey in my companyI want to configure 802.1X ethernet (based on computer authentication), my macOS are bind to ADI have already made a configuration that works but the connection is not automatic.Is it possible to configure this connection so that it is launched when the mac starts?thanks
Hello Jamf Nation, Wanted to bring awareness to this issue we've experienced with a few of our users. Each time, this issue happened on a M2 Macbook machine (one was a brand new one). I've been unable to find a solution to this issue with the exception of completely wiping the device. The most recent time this happened the user was attempting to install software from Self Service (more specifically Docker) and each time the install would keep hanging/spinning and would not complete or error out. This is most likely because it was stuck attempting to update inventory (as our policies have inventory update once an application is installed). Opening terminal and running sudo jamf recon yielded the following result (text/image below): sudo jamf recon Retrieving inventory preferences from https://*REDACTED*.jamfcloud.com/. Finding extension attributes... Locating package receipts... Locating hard drive information.. Locating applications... Locatin
Hello Jamfnation,Just wondering if anyone has had any luck with configuring the new settings for blocking access to preference panes in macOS Ventura? The old method is deprecated and produces some strange results if used: https://developer.apple.com/documentation/devicemanagement/systempreferencesOne example being that blocking 'users and groups' also blocks 'screen sharing' in General > SharingHopefully Jamf will be releasing a config profile setting soon?
My company has purchased and acquired one of our venders to make a more all in-house company.I am charged with on-boarding their computers, but I wanted to only enroll their computers in Jamf Pro but not apply any policies other than install our corporate anti-virus. I am only looking currently to monitor their computer and eventually tweak the computers, as a whole, over to our configuration.Is there a way to have a secondary Jamf Pro profile or exclude the policies to be applied?
Hello Everyone, I wanted to start up a convo around the changes coming to Microsoft Edge updates. Starting with Microsoft Edge version 113, Microsoft Edge for macOS will start using a new updater named EdgeUpdater. More details: https://learn.microsoft.com/en-us/deployedge/edge-learnmore-edgeupdater-for-macos Microsoft provided a configuration example, and it appears to use the same logic/keys as Google’s Keystone updater. Can anyone confirm this? Also, anyone know if we need to change our current MAU configuration to not include MS Edge? Thanks!
I'm new to JAMF and Mac, so I hope this is just something I'm overlooking.I'm tinkering in a new JAMF Cloud environment, and have enrolled two Monterrey machines and a Ventura machine. I've created a Configuration Profile, and when I try to add Computers to the scope, the Monterrey machines are listed and I can select them, but the Ventura machine is not listed (however, all machine are listed in the Policy I've made).Is there something special I need to do to be able to select Ventura machines as a target for Configuration Profiles?
Has anyone run into a situation where their users are prompted to change their password without a password expiration being defined in a policy? We had a policy last fall as we were onboarding with a new MSP that runs out Jamf instance, but that policy was disabled and the scope was changed to 0. I checked the Change Management Log and nothing jumps out at me. I checked the history of the impacted users and there's nothing new running. It's really bizarre. Any ideas on what could be causing this? It doesn't seem to be universal (at least not yet), but is impacting a good number of our users.
(Jamf Pro 10.41) This is the first I've had to manage any mobile device as the company usually puts them in InTune. But these users need more gradual control as the'll be using the phones mostly as cameras. But they're not going to be exclusively just using the camera app so can't use single-app mode. But there's no need for almost any of the built-in apps like Activity, Books, TV, Calendar, Health, Mail, Music, News, Podcasts, Reminders, Wallet.I can find previous questions about this from before Apple allowed the removal of built-in apps - the technique then was to hide (old) or rearrange (older). But I'm looking at ideally removing, or hiding if that's all I can do.I've tested trying to manage Podcasts, and set it to be managed if already installed. But the log says it can't be installed because it's already installed (duh. yeah). It doesn't even show up in Apps as managed or unmanaged - just failed. And I created a profile to restrict th
We have a couple dozen Sites defined with Macs assigned accordingly. The problem is we have a bunch of Macs that are NOT assigned to any Sites. I'm trying to figure out how to craft a search or smart group to show me all Macs that are assigned to "None" for the site. There doesn't appear to be any way to define Sites as search criteria. Is there a method I'm missing that will tell me what I need to know?
Not directly related to JAMF, is there a way to get a Mac's UUID info via ABM. We are deploying a large number of Macs and would like to get the UUID info before enrolling into Jamf.Thanks!Corbin
I have my device configured using Apple Business Manager, when I reset the device with my custom PreStage Enrollment, I should be creating a local account during the setup where the user is a non-admin, however every time it runs through my account is an admin.I've tried creating a new PreStage Enrollment, not working. The device also becomes managed by the 'administrator' account I pre-configure. Any help would be appreciated!!
I'm currently testing out a Jamf Now (Fundamentals) deployment for a couple of Macs we have. I haven't used Jamf before so not too sure how Jamf connect should work, but have a feeling mines not correct.I have setup the setting "Enable password sync with Jamf Connect" and done the setup in Azure for it. When a user first logs on it asks to type in both password (microsoft & then local password) so it could sync.Then we changed the password in Microsoft to see if it worked but on the macbook we have to login with the old local password and then in Jamf connect enter the email and the new microsoft password and it says they are out of sync and input the local password.I assume this should be a bit easier as its not exactly syncing the passwords currently?
Not really a Jamf problem, but maybe someone here knows something. For a few months now I have had the problem that some Macs just wont accept a users credentials after a few weeks or months. I have no idea what triggers this. One moment it works and one restart later the user just cant log in anymore. This happened with Monterey and Ventura. It also happened multiple times and I am sure it was not just typos.This really is a problem because the Macs are encrpyted, so the users cant access their data anymore.I cant really investigate this, because once the Macs are locked I cannot access the anymore.I am using AD bound Macs with network accounts.
We would like to check all MAC user whether they using default VPN configuration on MAC System Preferences. or they were using an App(e.g Cisco Anyconnect VPN)
I have a need to deploy goodsync. We use the script that downloads an install script (with the app base64 encoded into script) and installs. However, it fails to enroll to the good sync cloud. It all works fine when I run the script interactively from root.Anyone get the enrollment working when deployed with JAMF?
We have recently updated all our lab machines to the latest Adobe apps.Mostly everything has been ok, however we have had some machines the won't install Acrobat DC.The acrobat DC package has been installed on over 200 machines, so don't believe it's an issue with the package.I have created a new package from admin console and it just fails to install if you run in manually. On the problem machines.I have two policies one to cache the package and one to install packages from cache.Unsure if this ventura issue as thats where I'm seeing it currently. However.Probably worth saying this is site wide Adobe upgrade on over 300 machines. So it maybe that I have not found a Monterey machine yet from what I have checked.Does anyone have any ideas? I'm running out of idea on what it could be. Thanks
A customer of ours had an interesting question; they want to rename their Macs based on the color of the iMac. e.g "iMac Blue SerialNumber".I can't seem to find any place where the color is referenced. In network sharing and in the about this Mac screen it shows the correct color so I assume it does store it somewhere. I found the icons but I can't pinpoint how it detects what color it is.Any tips? Macs are running Ventura by the way
Hello Team,I was looking for a way to deploy all my organisation's certificate automatically on mac after enrolment, please keep in mind that my JAMF is in cloud and Azure AD is integrated with JAMF. So in this case I cant use AD-CS connector. If I use config profile then the main issue is that auto renew is not possible after it gets expired, we need to remove the expired cert and upload the new certificate again in config profile for deployment. For on-prem JAMF we can use SCEP server to avoid this auto renew stuff or we can use AD-CS connector. But if my JAMF is in cloud and Azure AD is integrated and no on-prem AD is there, and think user are enrolling the mac from their home then how the mac device will get the certificates. Please help me out on this.
We had been looking into using Github to push scripts and configuration profiles and manage changes but we've run into some issues implementing this concept. I was wondering if anyone has found a good solution to managing versioning on scripts and configuration profiles prior to pushing to Jamf or even within Jamf besides dating something ie: scriptname-4-14-23 or scriptver2?
Hi everyone,I am using Jamf Pro located on the cloud side and Azure integration is also done. This integration works well. As can be seen in the screenshot below a few days ago, the e-mail addresses of real persons belonging to the owners of MacOS devices began to be deleted. I add these addresses again and it pulls the necessary information from Azure AD and adds the email address. However, when users turn on their devices and connect to the internet, their email addresses are deleted again by Jamf Pro. Have you encountered such a problem? Any ideas on the solution? By the way, we also use the Jamf Connect product in the environment.
Does anyone have the details of what we need to set up in a configuration profile / PPPC to enable Remote Management for our admin account on ADE-enrolled Macs? Apple has an article that says it can be done, at https://support.apple.com/en-us/HT209161 but it is a bit light on detail. In particular I don't understand the last sentence.Basically we have a local admin account that exists on all our Macs (it's created via policy) and we need it to have Remote Management permissions without us needing to go to every Mac and click to enable it. All our Macs are now enrolled via ADE/DEP so the UAMDM state is considered to be on.
We are retooling our 802.1x and Network profiles in response to some forthcoming network changes in ISE/RADIUS. We are reevaluating all our payloads and settings.When configuring SCEP payloads, one of the options for both iOS and Mac is the Subject Alternative Name.Jamf recommends the RFC 822 type on Mac (not the DNS type), and they recommend leaving the RFC 822 Subject Alt Name BLANK on iOS. See links below.However, we have been using DNS type on both platforms for a couple of years - per a Jamf tech’s recommendation when we first set up 802.1x. We dont recall why. Examples: $COMPUTERNAME.my.domain and $DEVICENAME.my.domain.Any ideas on why Jamf recommends RFC 822 type?Thus far, using DNS type doesn’t seem to affect us in production, How do you all have your SCEP Subject Alt Name set?Any ideas on why the Subject Alt Name should be blank on iOS?Background: We are using our on-prem JSS as a SCEP proxy to our MS Windows NDES server. We use Cisco ISE for RADIUS.For Reference, Ja
I am trying to find a way to deploy VNC and Visual Studio Code. Was wondering if anyone has a way to do it and would be able to help me on this. Thank you in advance.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!