Get Support
Recently active
Hi guysI am out of ideas, I'm hoping someone here can help me.We use Global Protect in our company, and have set up the jamfconnector to retrieve the certificates.We have an ADCS configuration profile, which has been working fine up until now. Newly enrolled computers aren't getting their certificates anymore. When I go to check this in 'management' for that computer, I get the error 'Failed to inject certificates into the profile'. Any ideas where the issue could be? Connection to the jamfconnector and issueing server should still be ok. Thanks!Valérie
Just ran into this for the first time when trying to boot an M1 Pro into Recovery mode-- laptop was just reset using "Erase all content and settings" and has macOS 13.2.1 installed. I was intending to update the macOS to the latest by reinstalling the operating system from the Recovery console-- but alas, I ran into this "Recovery lock" blocker for the first time. So, with a little research, I find that the password should be cached in Jamf Pro, and I look it up-- a freaking 39-character password??? And when you type it in slowly on the computer in question, it doesn't show up as you type. Is this all the default behavior Apple has created? What a fricken pain in the butt.I don't see the need for this overbearing security roadblock. All my users are local admins and living remote, and in eight years of managing Macs with Jamf, I have not regretted that once. Everyone's remote now, and they need to be able to do some troubleshooting, Jamf Pro helps us keep the drives encrypted, no auto-
I have a policy to push some new printers we installed after login and startup . I have tested and it seems to be working. On this one specific user her laptop has not "checked in" or had an inventory update since early march. I have tried restarting multiple times to see if the policy pushes but I see nothing in the logs. Why hasn't the laptop checked in or had an inventory update since March? Could that be part of the issue as to why the policy is not pushing?Thanks
Hello,We would like to enable FileVault when preparing our Macs, during the enrollment prestage.We would like to know the best way to do this knowing that:- We have a support team that pre-configures the computers.- During the enrollment of the computers, a management account is automatically created with a random password and a local administrator account.- During enrollment, Jamf Connect is installed.- Once the computer is enrolled, our support team logs in to the local admin account to install applications and do some different settings according to the targets.- Once finished, the end user will come to pick up his computer or the computer will be sent to the user.Today, we are beginning to deploy Filevault through a configuration profile with encryption at logout.Thank you for your help.
Looking to do a binding to a LDAP server. I can get the base binding with this commanddsconfigldap -a lookup.example.com -n lookupThe problem I'm running into is that I can't find a programatic way to set the LDAP Mapping to RFC2307 with the associated search base suffix.Can do it manually in the LDAPv3 settings in the Directory Utility UI no problem.
Hi everyone, I was looking at the various Jamf training & certs, and the X00 certs are geared for Jamf Pro, and the X70 certs are mainly security/Jamf Protect. Are there any training/certs for Jamf School or Connect?
Ever since updating our student iPads to iOS ver. 16 or later their iPads no longer "Automatically join Classroom classes without prompting" as configured in Jamf Pro under configuration profiles > restrictions > functionality. Instead of joining classroom classes automatically student iPads now show as offline in the Apple Classroom app until the teacher selects a student and clicks connect, at which time student iPads receive a notification to join the class and students have an option of either accepting or declining the invitation. Obviously this is a huge issue because students can decline the invitation and not join the class. I find it a little strange that a Jamf Pro configuration profile stopped working after an iOS update but it doesn't surprise me at all since Apple is notorious for releasing updates before giving developers time to update things on their end.Has anyone else experienced this?
Gather the data you need — on-demand — while eliminating the need for short-term Extension AttributesBackgroundFor long-term needs, Jamf Pro Computer Extension Attributes are indispensable, but during software pilots, you only occasionally need potential vendor data from endpoints and creating multiple EAs you’ll only use temporarily can lead to database bloat.Continue reading …
Head of security has asked me to investigate whether its possible to restrict the use of usb keys and firewire drives on company macs. Anyone got any ideas or had any exposure in this area? Of course can't fully disable them because of keyboards & mice (saw a script for this). I'm assuming some sort of 3rd party product in the end might be the best solution.
Hello, I'm unnable to use the automatic login after filevault (FDEautologin). Every time I reboot, the user as to authenticate twice, once for filevault and once for jamf connect. I know it use to work in previous version of connect we had installed. Though today I cant seem to understand why it's not working. Does the "Require Network Authhentication" needs to be disable for this to work ? As this part of the documentation suggests.But then it's seems rather stupid to have jamf connect and Okta in order to secure the user's connection, and you end up disabling the network connection.... What am I missing here ?
I'm trying to disable "Prevent Cross-Site Tracking" in Safari for a group of iOS student iPads and cannot find the setting in configuration profiles. Apologies if it's under my nose.
Hello All, I am going to setup a cloud JAMF system for a company, just curious to know what are the IP ranges has to be whitelisted for Apple to manage Apple devices(mac devices mainly) from company's firewall so that mac devices can speak to Apple and we can manage the mac devices through JAMF without any network blockage.
Hi,I would like to know if anybody knows how to hide the "Settings" app on Apple TV using Jamf Now or if it is possible to do so with this licence.Thanks alot!
I am having trouble with recording the LAPS for macOS passwords to the LAPS EA. Everything works and there is no error, yet the LAPS EA is blank every time. I can see the password if I look at log details so I know the rest of the process works pretty flawlessly. Here is the script I am using: !/bin/bash apiUser=""apiPass=""apiURL=$(/usr/bin/defaults read /Library/Preferences/com.jamfsoftware.jamf.plist jss_url | sed 's|/$||')udid=$(/usr/sbin/system_profiler SPHardwareDataType | /usr/bin/awk '/Hardware UUID:/ { print $3 }')extAttName=""LAPS"" LAPS_Password=$(curl -s -f -u $apiUser:$apiPass -H "Accept: application/xml" $apiURL/JSSResource/computers/udid/$udid/subset/extension_attributes | xpath -e "//extension_attribute[name=$extAttName]" 2>&1 | awk -F'<value>|</value>' '{print $2}' | tail -n +1) echo $LAPS_Password I hardcoded the api username and api password to the script. Here are screenshots of the resulting log and the EA
For some reason, our Management Action notification (triggered by User Action/Deferral in a policy) isn't showing ANY icon (By default I believe it should be the JAMF logo). Does anyone else have this issue or a fix to put the icon there?
Hello All, I have a rtfd file placed under /Library/Security to display a message with company logo to the end user, so that when end user will login to the mac, user will be able to read the message before login and using it. Interesting thing is that this policy banner with company logo and message is getting scattered, sometimes logo is moving to the left side of the corner, sometimes right or middle, message lines are misplaced randomly. I need a solution to fix this issue, so that company logo and message should be properly placed and aligned.
Hello,In using Configurator 2.5 to enroll devices in our DEP I encountered the below error on some of our iPads: An unexpected error has occurred with “iPad”. Provisional Enrollment failed.The cloud configuration server is unavailable or busy. [MCCloudConfigErrorDomain – 0x80EF (33007)] I called AppleCare Enterprise. They checked the devices that I was trying to add and indicated they are or were enrolled in our Parent School District DEP. This prevented the iPads from being added to any other DEP. Even if the devices were removed from their DEP they cannot be added to a new DEP. Sharing in case anyone else receives this error. CORRECTION - The person I initially spoke to at Apple Care Enter price was wrong.I was able to have our parent district go into Apple School Manager, input the serial number and choose "Release Devices." I am now able to add this to our DEP! It basically translates as : "This device is not eligible to add to your Company's DEP"
This may not be the place, but I saw the Jamf 200 post and I figured “what the hell?” I found out today they I too earned the Jamf 200 certificate and am super excited as my first experience with Jamf started less than 6 month ago. My question is…can anyone provide suggestions on what I should be proficient in before taking the 300 level course. Is there any go to Bash scripting classes or something else that will facilitate a passing 300 grade? Thank you in advance.
Hi,Curious for recommendations for our fleet of ~50 Mac devices.We're currently using Jamf Now which is great for enforcing basic security policies, but we are staring to outgrow it. Specifically in terms of what we are looking for:Support for Apple VPP. We are using that now via. Jamf, I noticed Fleetsmith surprisingly does not support this - this is probably a dealbreaker unless there are workarounds?Better security features, including ability to automate/enforce OS and software updates, logging/alerting on security events (authentication etc.). We are already doing malware detection so that is not necessary.Ability to deploy custom packages, scripts & resources (fonts come to mind here) as necessary.Reporting/Alerting/Automation - we don't have an IT team, I'd love a simplified view of which machines are in compliance and which need follow-ups, in addition to anything else which makes administration easier. Any integration with email/slack for messaging users would be a positive
I am using jamf pro to push a policy that will install new printers to users laptop. My question is for execution frequency does it matter which one i choose. What is the difference between once per computer and once everyday or once a week?
We have been using Jamf Connect for a couple years. It is connected to Okta for SSO login.We recently got Apple Business Manager and are starting down the path for Intune BYOD for iOS devices. We want to turn on federated authentication to our Azure AD for managed Apple ID's.Just want to double check this would have no effect on Jamf Connect. I am 99% sure it would not since Jamf Connect points to Okta only.
Hi,I'm trying to deploy Nudge in a mixt environment Intel/M1. It seems that the package is deployed in Utilities and the configuration profile is there and found on devices.I have a pile of devices with Monterey and Ventura; the test we want to accomplish is upgrading to 13.3. Even if the deadline is there the Nudge window does not appear and of course, no upgrade notification. This is my config profile and policy. I even added in the policy all the packages.Any specific reason why.The pile of devices consists in:Air M1 with Monterey 12.6.1MacBook Pro intel 15" Montery 12.6.3MacBook Pro intel 15" Montery 12.3.1MacBook Pro intel 15" Ventura 13.2.1
When creating a Jamf Pro login account in the console, there is a need for a feature that allows us to set a time period for credential expiration
Hello,We had McAfee/Trellix Firewall installed on all of our MacOS computers.We have to quickly uninstall it but during Firewall uninstall process, a prompt for admin username and pass is showing to uninstall the extension system.But none of our users is administrator and it is just not possible to go on more than 1600 computers for that.Do you know how it is possible to uninstall completely and silently?Thank you for your help
Could you please provide information on which OS builds are considered safe to use for BIG SUR, Monterey, and Ventura?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!