Get Support
Recently active
Gather the data you need — on-demand — while eliminating the need for short-term Extension AttributesBackgroundFor long-term needs, Jamf Pro Computer Extension Attributes are indispensable, but during software pilots, you only occasionally need potential vendor data from endpoints and creating multiple EAs you’ll only use temporarily can lead to database bloat.Continue reading …
Head of security has asked me to investigate whether its possible to restrict the use of usb keys and firewire drives on company macs. Anyone got any ideas or had any exposure in this area? Of course can't fully disable them because of keyboards & mice (saw a script for this). I'm assuming some sort of 3rd party product in the end might be the best solution.
Hello, I'm unnable to use the automatic login after filevault (FDEautologin). Every time I reboot, the user as to authenticate twice, once for filevault and once for jamf connect. I know it use to work in previous version of connect we had installed. Though today I cant seem to understand why it's not working. Does the "Require Network Authhentication" needs to be disable for this to work ? As this part of the documentation suggests.But then it's seems rather stupid to have jamf connect and Okta in order to secure the user's connection, and you end up disabling the network connection.... What am I missing here ?
I'm trying to disable "Prevent Cross-Site Tracking" in Safari for a group of iOS student iPads and cannot find the setting in configuration profiles. Apologies if it's under my nose.
Hello All, I am going to setup a cloud JAMF system for a company, just curious to know what are the IP ranges has to be whitelisted for Apple to manage Apple devices(mac devices mainly) from company's firewall so that mac devices can speak to Apple and we can manage the mac devices through JAMF without any network blockage.
Hi,I would like to know if anybody knows how to hide the "Settings" app on Apple TV using Jamf Now or if it is possible to do so with this licence.Thanks alot!
I am having trouble with recording the LAPS for macOS passwords to the LAPS EA. Everything works and there is no error, yet the LAPS EA is blank every time. I can see the password if I look at log details so I know the rest of the process works pretty flawlessly. Here is the script I am using: !/bin/bash apiUser=""apiPass=""apiURL=$(/usr/bin/defaults read /Library/Preferences/com.jamfsoftware.jamf.plist jss_url | sed 's|/$||')udid=$(/usr/sbin/system_profiler SPHardwareDataType | /usr/bin/awk '/Hardware UUID:/ { print $3 }')extAttName=""LAPS"" LAPS_Password=$(curl -s -f -u $apiUser:$apiPass -H "Accept: application/xml" $apiURL/JSSResource/computers/udid/$udid/subset/extension_attributes | xpath -e "//extension_attribute[name=$extAttName]" 2>&1 | awk -F'<value>|</value>' '{print $2}' | tail -n +1) echo $LAPS_Password I hardcoded the api username and api password to the script. Here are screenshots of the resulting log and the EA
For some reason, our Management Action notification (triggered by User Action/Deferral in a policy) isn't showing ANY icon (By default I believe it should be the JAMF logo). Does anyone else have this issue or a fix to put the icon there?
Hello All, I have a rtfd file placed under /Library/Security to display a message with company logo to the end user, so that when end user will login to the mac, user will be able to read the message before login and using it. Interesting thing is that this policy banner with company logo and message is getting scattered, sometimes logo is moving to the left side of the corner, sometimes right or middle, message lines are misplaced randomly. I need a solution to fix this issue, so that company logo and message should be properly placed and aligned.
Hello,In using Configurator 2.5 to enroll devices in our DEP I encountered the below error on some of our iPads: An unexpected error has occurred with “iPad”. Provisional Enrollment failed.The cloud configuration server is unavailable or busy. [MCCloudConfigErrorDomain – 0x80EF (33007)] I called AppleCare Enterprise. They checked the devices that I was trying to add and indicated they are or were enrolled in our Parent School District DEP. This prevented the iPads from being added to any other DEP. Even if the devices were removed from their DEP they cannot be added to a new DEP. Sharing in case anyone else receives this error. CORRECTION - The person I initially spoke to at Apple Care Enter price was wrong.I was able to have our parent district go into Apple School Manager, input the serial number and choose "Release Devices." I am now able to add this to our DEP! It basically translates as : "This device is not eligible to add to your Company's DEP"
This may not be the place, but I saw the Jamf 200 post and I figured “what the hell?” I found out today they I too earned the Jamf 200 certificate and am super excited as my first experience with Jamf started less than 6 month ago. My question is…can anyone provide suggestions on what I should be proficient in before taking the 300 level course. Is there any go to Bash scripting classes or something else that will facilitate a passing 300 grade? Thank you in advance.
Hi,Curious for recommendations for our fleet of ~50 Mac devices.We're currently using Jamf Now which is great for enforcing basic security policies, but we are staring to outgrow it. Specifically in terms of what we are looking for:Support for Apple VPP. We are using that now via. Jamf, I noticed Fleetsmith surprisingly does not support this - this is probably a dealbreaker unless there are workarounds?Better security features, including ability to automate/enforce OS and software updates, logging/alerting on security events (authentication etc.). We are already doing malware detection so that is not necessary.Ability to deploy custom packages, scripts & resources (fonts come to mind here) as necessary.Reporting/Alerting/Automation - we don't have an IT team, I'd love a simplified view of which machines are in compliance and which need follow-ups, in addition to anything else which makes administration easier. Any integration with email/slack for messaging users would be a positive
I am using jamf pro to push a policy that will install new printers to users laptop. My question is for execution frequency does it matter which one i choose. What is the difference between once per computer and once everyday or once a week?
We have been using Jamf Connect for a couple years. It is connected to Okta for SSO login.We recently got Apple Business Manager and are starting down the path for Intune BYOD for iOS devices. We want to turn on federated authentication to our Azure AD for managed Apple ID's.Just want to double check this would have no effect on Jamf Connect. I am 99% sure it would not since Jamf Connect points to Okta only.
Hi,I'm trying to deploy Nudge in a mixt environment Intel/M1. It seems that the package is deployed in Utilities and the configuration profile is there and found on devices.I have a pile of devices with Monterey and Ventura; the test we want to accomplish is upgrading to 13.3. Even if the deadline is there the Nudge window does not appear and of course, no upgrade notification. This is my config profile and policy. I even added in the policy all the packages.Any specific reason why.The pile of devices consists in:Air M1 with Monterey 12.6.1MacBook Pro intel 15" Montery 12.6.3MacBook Pro intel 15" Montery 12.3.1MacBook Pro intel 15" Ventura 13.2.1
When creating a Jamf Pro login account in the console, there is a need for a feature that allows us to set a time period for credential expiration
Hello,We had McAfee/Trellix Firewall installed on all of our MacOS computers.We have to quickly uninstall it but during Firewall uninstall process, a prompt for admin username and pass is showing to uninstall the extension system.But none of our users is administrator and it is just not possible to go on more than 1600 computers for that.Do you know how it is possible to uninstall completely and silently?Thank you for your help
Could you please provide information on which OS builds are considered safe to use for BIG SUR, Monterey, and Ventura?
I am being tasked with sorting out a solution for macOS SysLog redirection. Security is wanting/needing macOS user Authentication logs among other logs. Most of the tools I am seeing died when Apple updated to Universal Logging. I'm working with our Splunk team to see what options we have with Splunk. However, I am wondering what other organizations and admins are doing for log redirection.
Customer Education has long pursued the goal of meeting you where you are. We create learning experiences for aspiring technicians and seasoned admins looking to expand their knowledge and better understand the tools available to them. We aim to provide context, use-cases, and additional resources to help you in your journey to support users. We created the Jamf 170 Course to respect the importance of keeping devices secure, remediating threats, and fostering a general understanding of attack vectors that malicious actors may leverage against your environment. I began at Jamf as a trainer delivering the Jamf 200 Course (and for you grizzled veterans, the CCT). The 200 covered everything from turning on your Mac for the first time to writing a custom script and deploying it with a policy. For new Mac users, this resulted in a deluge of information in a short amount of time. For Mac aficionados, much of the elementary subject matter felt irrelevant. Over time, the Customer Education team
Hello,I'm pretty sure one of you will know this. I stumbled upon a script left by the previous administrator in our Jamf instance. It's a script to name machines. The naming convention uses Building + Laptop or Workstation + Last 7 digits of serial. For example, a laptop in the San Francisco building should be named like this: SFOMLP-xxxxxxx. A workstation would be named SFOMWS-xxxxxxx. Everything works well except the part where it determines whether it's a laptop or a workstation. That part of the script looks like this:# Determine if portable or desktopcomptype=$(/usr/sbin/system_profiler SPBluetoothDataType | awk '/Complete/ { print $NF }')if [[ $comptype == 'Portable' ]];then base="MLP"elsebase="MWS"The problem is that it names everything with the base MWS, which suggests to me that the comptype variable needs to be edited because it's not grabbing the correct info from the system. Perhaps that line to grab info from System Profiler is no longer correct (?). Any in
I work in a school district and was wondering if anyone had used scripts to shut down apps after a certain time. We are looking for a way to stop students from accessing safari and google chrome after school hours. Any help would be appreciated. I'm new to scripting and haven't had much practice with it.
Hi All Does anyone know how to actually disable the Airdrop service on OSX Sierra ( I've tried the command "defaults write com.apple.NetworkBrowser DisableAirDrop -bool YES" ) dont the Mac's are still broadcasting via Airdrop I've restricted AirDrop using a configuration profile - But this only removes the AirDrop from Finder and not actually disables the service Any advice would be greatly appreciated
I feel like i'm missing something here. Aren't nested groups supported in v9? I don't see how to add a computer group to a static group.For example: If i have static groups called Lab1, Lab2, Lab3, etc. that all have specific computer assignments, then i'd like to have another static group called something like All Labs that have the static groups Lab1, Lab2, and so on. That way, if i want to push a config profile to all labs, i can just select All Labs as the scope, rather than listing all of the individual labs.
I just wanted to know if there is any restriction to use same Apple ID for push notification can be used for ABM login for any order for VPP app or DEP device assignment. Or this two Apple Id has to be different and it is must?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!