Get Support
Recently active
I'm new to JAMF and Mac, so I hope this is just something I'm overlooking.I'm tinkering in a new JAMF Cloud environment, and have enrolled two Monterrey machines and a Ventura machine. I've created a Configuration Profile, and when I try to add Computers to the scope, the Monterrey machines are listed and I can select them, but the Ventura machine is not listed (however, all machine are listed in the Policy I've made).Is there something special I need to do to be able to select Ventura machines as a target for Configuration Profiles?
Has anyone run into a situation where their users are prompted to change their password without a password expiration being defined in a policy? We had a policy last fall as we were onboarding with a new MSP that runs out Jamf instance, but that policy was disabled and the scope was changed to 0. I checked the Change Management Log and nothing jumps out at me. I checked the history of the impacted users and there's nothing new running. It's really bizarre. Any ideas on what could be causing this? It doesn't seem to be universal (at least not yet), but is impacting a good number of our users.
(Jamf Pro 10.41) This is the first I've had to manage any mobile device as the company usually puts them in InTune. But these users need more gradual control as the'll be using the phones mostly as cameras. But they're not going to be exclusively just using the camera app so can't use single-app mode. But there's no need for almost any of the built-in apps like Activity, Books, TV, Calendar, Health, Mail, Music, News, Podcasts, Reminders, Wallet.I can find previous questions about this from before Apple allowed the removal of built-in apps - the technique then was to hide (old) or rearrange (older). But I'm looking at ideally removing, or hiding if that's all I can do.I've tested trying to manage Podcasts, and set it to be managed if already installed. But the log says it can't be installed because it's already installed (duh. yeah). It doesn't even show up in Apps as managed or unmanaged - just failed. And I created a profile to restrict th
We have a couple dozen Sites defined with Macs assigned accordingly. The problem is we have a bunch of Macs that are NOT assigned to any Sites. I'm trying to figure out how to craft a search or smart group to show me all Macs that are assigned to "None" for the site. There doesn't appear to be any way to define Sites as search criteria. Is there a method I'm missing that will tell me what I need to know?
Not directly related to JAMF, is there a way to get a Mac's UUID info via ABM. We are deploying a large number of Macs and would like to get the UUID info before enrolling into Jamf.Thanks!Corbin
I have my device configured using Apple Business Manager, when I reset the device with my custom PreStage Enrollment, I should be creating a local account during the setup where the user is a non-admin, however every time it runs through my account is an admin.I've tried creating a new PreStage Enrollment, not working. The device also becomes managed by the 'administrator' account I pre-configure. Any help would be appreciated!!
I'm currently testing out a Jamf Now (Fundamentals) deployment for a couple of Macs we have. I haven't used Jamf before so not too sure how Jamf connect should work, but have a feeling mines not correct.I have setup the setting "Enable password sync with Jamf Connect" and done the setup in Azure for it. When a user first logs on it asks to type in both password (microsoft & then local password) so it could sync.Then we changed the password in Microsoft to see if it worked but on the macbook we have to login with the old local password and then in Jamf connect enter the email and the new microsoft password and it says they are out of sync and input the local password.I assume this should be a bit easier as its not exactly syncing the passwords currently?
Not really a Jamf problem, but maybe someone here knows something. For a few months now I have had the problem that some Macs just wont accept a users credentials after a few weeks or months. I have no idea what triggers this. One moment it works and one restart later the user just cant log in anymore. This happened with Monterey and Ventura. It also happened multiple times and I am sure it was not just typos.This really is a problem because the Macs are encrpyted, so the users cant access their data anymore.I cant really investigate this, because once the Macs are locked I cannot access the anymore.I am using AD bound Macs with network accounts.
We would like to check all MAC user whether they using default VPN configuration on MAC System Preferences. or they were using an App(e.g Cisco Anyconnect VPN)
I have a need to deploy goodsync. We use the script that downloads an install script (with the app base64 encoded into script) and installs. However, it fails to enroll to the good sync cloud. It all works fine when I run the script interactively from root.Anyone get the enrollment working when deployed with JAMF?
We have recently updated all our lab machines to the latest Adobe apps.Mostly everything has been ok, however we have had some machines the won't install Acrobat DC.The acrobat DC package has been installed on over 200 machines, so don't believe it's an issue with the package.I have created a new package from admin console and it just fails to install if you run in manually. On the problem machines.I have two policies one to cache the package and one to install packages from cache.Unsure if this ventura issue as thats where I'm seeing it currently. However.Probably worth saying this is site wide Adobe upgrade on over 300 machines. So it maybe that I have not found a Monterey machine yet from what I have checked.Does anyone have any ideas? I'm running out of idea on what it could be. Thanks
A customer of ours had an interesting question; they want to rename their Macs based on the color of the iMac. e.g "iMac Blue SerialNumber".I can't seem to find any place where the color is referenced. In network sharing and in the about this Mac screen it shows the correct color so I assume it does store it somewhere. I found the icons but I can't pinpoint how it detects what color it is.Any tips? Macs are running Ventura by the way
Hello Team,I was looking for a way to deploy all my organisation's certificate automatically on mac after enrolment, please keep in mind that my JAMF is in cloud and Azure AD is integrated with JAMF. So in this case I cant use AD-CS connector. If I use config profile then the main issue is that auto renew is not possible after it gets expired, we need to remove the expired cert and upload the new certificate again in config profile for deployment. For on-prem JAMF we can use SCEP server to avoid this auto renew stuff or we can use AD-CS connector. But if my JAMF is in cloud and Azure AD is integrated and no on-prem AD is there, and think user are enrolling the mac from their home then how the mac device will get the certificates. Please help me out on this.
We had been looking into using Github to push scripts and configuration profiles and manage changes but we've run into some issues implementing this concept. I was wondering if anyone has found a good solution to managing versioning on scripts and configuration profiles prior to pushing to Jamf or even within Jamf besides dating something ie: scriptname-4-14-23 or scriptver2?
Hi everyone,I am using Jamf Pro located on the cloud side and Azure integration is also done. This integration works well. As can be seen in the screenshot below a few days ago, the e-mail addresses of real persons belonging to the owners of MacOS devices began to be deleted. I add these addresses again and it pulls the necessary information from Azure AD and adds the email address. However, when users turn on their devices and connect to the internet, their email addresses are deleted again by Jamf Pro. Have you encountered such a problem? Any ideas on the solution? By the way, we also use the Jamf Connect product in the environment.
Does anyone have the details of what we need to set up in a configuration profile / PPPC to enable Remote Management for our admin account on ADE-enrolled Macs? Apple has an article that says it can be done, at https://support.apple.com/en-us/HT209161 but it is a bit light on detail. In particular I don't understand the last sentence.Basically we have a local admin account that exists on all our Macs (it's created via policy) and we need it to have Remote Management permissions without us needing to go to every Mac and click to enable it. All our Macs are now enrolled via ADE/DEP so the UAMDM state is considered to be on.
We are retooling our 802.1x and Network profiles in response to some forthcoming network changes in ISE/RADIUS. We are reevaluating all our payloads and settings.When configuring SCEP payloads, one of the options for both iOS and Mac is the Subject Alternative Name.Jamf recommends the RFC 822 type on Mac (not the DNS type), and they recommend leaving the RFC 822 Subject Alt Name BLANK on iOS. See links below.However, we have been using DNS type on both platforms for a couple of years - per a Jamf tech’s recommendation when we first set up 802.1x. We dont recall why. Examples: $COMPUTERNAME.my.domain and $DEVICENAME.my.domain.Any ideas on why Jamf recommends RFC 822 type?Thus far, using DNS type doesn’t seem to affect us in production, How do you all have your SCEP Subject Alt Name set?Any ideas on why the Subject Alt Name should be blank on iOS?Background: We are using our on-prem JSS as a SCEP proxy to our MS Windows NDES server. We use Cisco ISE for RADIUS.For Reference, Ja
I am trying to find a way to deploy VNC and Visual Studio Code. Was wondering if anyone has a way to do it and would be able to help me on this. Thank you in advance.
I came across this article recently about how to use Github to manage and push scripts and configuration profiles to Jamf however it seems a bit out of date:https://www.pixngeek.com/jamf-pro-use-github-to-deploy-scripts/ Does anyone have more current resources, references or recommendations to utilize Github to manage script updating in Jamf? Something that hopefully takes into account the latest version of Github actions so it doesn't generate any Node.js errors?
We have all our printers in Active Directory when computers were joined to AD they could see and add them. How do I connect to the Print Server and add printers on a Mac?
We are using Jamf Pro and are setup as shared devices using Setup and Reset. and microsoft authenticator.What is involved in switching over to user assigned still using reset for a device format and logging into a device with Azure creds?Is Jamf connect required for this?I am trying to achieve a shared device that users make their own for their shift and reset and wipe at the end, during their shift they can use outlook/teams/word/onedrive etc with app protection policies and conditional access.
Here are the direct Apple CDN download links for the Safari 16.4.1 update released today (2023-04-07) for macOS Monterey and Big Sur:Monterey: https://swcdn.apple.com/content/downloads/13/10/032-71505-A_VXEPHZXHA7/cceqmuarwutena64ohro71ydpukpip72i9/Safari16.4.1MontereyAuto.pkgBig Sur: http://swcdn.apple.com/content/downloads/47/23/032-72735-A_HUFOGBJPRZ/580izn9uc683ima5tc9fykya8lkbhkji4t/Safari16.4.1BigSurAuto.pkgThe macOS Ventura 13.3.1 update contains the Safari 16.4.1 update for macOS Ventura, and there is no standalone updater for it.
I am testing no-touch app installs and configuration with DEP Mac devices in JAMF.I have a DEP Mac that I registered with JAMF and initially the device info did note that YES it was enrolled via DEP. After testing many settings I wiped the MAC and deleted the entry in JAMF so it can be configured as a new machine. However, thereafter, in the JAMF computer info, the info states that NO it was not enrolled via DEP. The thing is I have a smart group to add devices enrolled via DEP so now this workstation cant be added and the policies i have created that are tied to the smart group do not apply to this machine.What is the trick to get JAMF to recognize that this mac was enrolled via DEP?I also have one error come up: Command requires DEP enrollment: UserList <MDMClientError:74>Thanks!
Does anyone know if and when Okta will be added as a Cloud Identity Provider in Jamf Pro?
Been searching around in integration, company portal, and azure documentation but the specific item I am trying to figure out is when it prompts for Admin elevation, is it possible to configure to use an Admin group from Azure AD to use Azure AD Admin Credentials? That way we aren't using a local account or logging into an Admin account each time. Similarly as we would do with UAC on a Windows device. Similarly if you were AD bound with an on prem, you could designate an Admin group so could use your credentials.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!