Get Support
Recently active
The company i work for (as a contractor) is requiring me to install JAMF on my *personal* laptop and iMac because of "compliance requirements". While i would usually refuse on principle (since these are my own devices), i am enjoying my job so i'm not really planning to challenge it.As these are my personal devices, i do my banking and have my personal data on them so i'm wondering what can they actually access through JAMF. IT told me they will not have access any personal data, and that i can continue using my personal AppleID but after reading what i could find online, i am starting to doubt that.Another reason is they are refusing to buy the apps i purchased that speed up my work, but they don't consider essential. So if i create a new AppleID, i would lose access to my music and all the apps that i use daily (both for work and my own use).I wonder what is the actual capability of JAMF and what will they be able to access. Will they be able to access my photos, browser history, rec
I'm looking for a way to remove photos and videos from an iPad without doing a full wipe. We have iPads at our 2nd campus, but they are all pre-DEP and it would be nice to be able to just clear unnecessary data from them at the end of each term without having to do a full wipe, then drive myself there and configurate them all and log in to them again.
Hello,Can you please tell me how you manage MDM Capable Users with Jamf Connect?We use Jamf Connect but on all of our computers the Capable Users MDM is empty.This is very problematic, because no more VPP applications, no more user level configuration profiles, etc...Our devices are enrolled DEP, MacOS 11 or more recent.The un-enroll and re-enroll solution is not acceptable with us, we have hundreds of new computers per month.I'm amazed that it's so complicated for such basic and important things.Thank you for your help
I have been trying to update patch policies today and when I edit and save the definitions, they are not saving. The interface also looks like it has been updated. Tried on 2 different Macs and no luck.Anyone else having this issue?
I'm currently experiencing difficulties in installing the MuseScore deployment package through Jamf Apple Device Management on MacOS Ventura Version. I have tried multiple installation methods, including using a Jamf Pro policy and manually installing the package through the command line, but the installation process keeps failing with various error messages. https://fmwhatsapp.one Here are some additional details about my setup and troubleshooting steps:I am using Jamf Pro version 10.32.1 and have created a policy to install the MuseScore deployment package (version 3.6.2) on multiple devices running MacOS Ventura Version (12.0.1).I have confirmed that the package is compatible with the Ventura version of MacOS by testing the installation on a few individual devices outside of Jamf Pro.I have also checked that the MuseScore deployment package is properly signed and notarized by Apple.When attempting to install the package through the Jamf Pro policy, the installation process
Our users routinely snarf things up playing around with printers, trying to add home printers or change queue names to work with Printopia; or things just get hosed. I'm working on a Self Service policy to blow away the printers and re-add all those scoped to the user. When I do this manually, I use the "Reseting printing system..." option accessed by right-clicking the printer list in the System Preferences pane. Is there a way to invoke this action from the command line so that I could script it? In 10.4 and 10.5 there was a PrintingReset.sh script in the Printer Setup Utility bundle, but that tool is gone in later releases. I'm aware that I can simply kill the queues via lpadmin and reset cupsd.conf, but I think the OS is doing a bit more to "fully" reset cups. If you watch the system log, clicking "reset printing system" invokes printtool (found at /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/PrintCore.fra
Leverage switftDialog and Jamf Pro Policy Script Parameters to easily display engaging end-user messagesIntroductionUsing Bart Reardon’s swiftDialog and Jamf Pro Policy Script Parameters, creating engaging end-user messages is easy.When you really want to get your user’s attention, one of my favorite options is `--blurscreen`, which “will blur the background of the display while dialog is showing.”Continue reading …
We have used LDAP enrollment for years, but im wondering if preload would be easier and save classroom time the first week of school. So I have a couple questions-1) With LDAP, it uses their Active directory usernames. But- does it actually just pull the information from AD and then create a jamf user based on that information?2) If #1 is true, then I assume preload is basically creating those Jamf users and assigning a device to them without the need for an LDAP pull?3) If those Jamf users are created in #2, then will the ipad automatically enroll and start downloading apps when it is turned on for the first time? Or will it still ask for some information? (language, time zone etc?)Essentially- every student in the building seems to have some method of "wiping" their memory of usernames and passwords over the summer, so im hoping that the preload can "auto-assign" ipads to them so they dont need to recall their username and password the first week of school to get going (and also simi
Afternoon jamf nation.Just looking to get some insight, into how you are all dealing with restricting preference panes in macOS Ventura.I have created a config profile with a few bits I want to restrict.While most of it seems to work it's breaks the ability to remotely manage it via VNC.I think it has something to do with what Apple have depricated when re designing system preferences. I have raised a call with Jamf, they have confirmed it is product issues but that's about all. We are moving to jamf cloud soon so hoping that will better experience.
Hi all,Anyone know if it's possible to have entirely passwordless login to macOS using Jamf Connect and Okta? Would like to use TouchID and/or MFA Okta Verify Push.Thanks!
In the midst of testing and we have a Mac at the client site that was not properly assigned to a department when DEP enrollment completed (and the department being blank meant that the computer was out of scope). Since Enrollment is the only trigger, I'm trying to figure out another way to push all of the policies that should have fired under normal circumstances. Due to the lack of mass-editing functionality in Jamf, I'm not really excited about the thought of creating Self-service versions of the same policies or making dupe policies with only that machine in scope. Is there any non-destructive way to make JSS think that the device just completed enrollment so all of these policies will fire?
Hello all,Just wanted to know if anyone here has taken the Jamf 100 certification exam. I've been studying for about 3 weeks and wanted to know anyone's experience taking the exam in the past.Also I would like to know how accurate is the practice exam compared to the actual exam.
We have about 50/50 M1 vs Intel chip Macbooks.We are using Jamf Connect as well (not sure if relevant)We have a standard Admin account created and loaded for every computer during prestage enrollment.We are not able to run the MacOS Ventura Installer on the M1 macs because it does accept the Admin credentials provided. These same Admin credentials are working for installing apps, etc. The update does work if you switch to the mentioned Admin account on the computer and then run the update.The update has none of these issues for the Intel macs. I can run the update from the user's account using the same Admin credentials. Anyone know why the M1 would not let us run this update from the user's standard account, even providing the correct Admin credentials?
Blocked Messages app on a Mac with a plist:<key>familyControlsEnabled</key><true/><key>pathBlackList</key><array><string>/System/Applications/Messages.app</string></array><key>pathWhiteList</key>and it is indeed blocked, but evey time i log in i get the below:The extension is inside the Messages app in the Extension directory. Does anyone know where is this set up to run at every session start? It's not in Login Items...
Hey I want to achieve the following. If a certain local user logs in to open a terminal window and show the jamf.log file.What I have done so far create a policy. with the trigger Login that executes a script that looks the following #!/bin/bash# Check if the user is sadminif [ $(whoami) = "admin" ]; then# Open a new Terminal window and run 'tail -f /var/log/jamf.log'osascript -e 'tell app "Terminal" to do script "tail -f /var/log/jamf.log"'fi the policy is executed when user "admin" logs in and gives no errors but there is no terminal window being opened and displays the jamf.log fileI dont know where the error is or why it won't work!? How can I achieve this?
Hello !I'm managing the inventory preload for our organization. I wanted to remove an entry as the computer is no more there. I select the entry then click the delete data button but it removed everything ! I then searched how I could remove only the selected computers but I don't see where I may be. Is it a bug or did I miss something ?Thank you for helping me !
Is it possible to push the Change Management Logs and Jamf Pro Access Logs to a SEIM like SumoLogic? We currently have a ComputerCheckIn webhook event that's set up to send data to SumoLogic but I don't see an option under the Webhook Event types for the two logs I mentioned above.
Hello Everyone, do anyone has the same issue ?We have some devices in CHina, who has the Problem that the days couldnt reset the count and run in negative Days, in Germany we can handle it with reconnect VPN but in China its not allowed to use it.Is there any other way to handle this ?
Hello,I've noticed all of my package downloads are failing with error -1200. I checked the PKI cert, the Tomcat SSL cert, and the IIS cert (it's an on-prem windows server) and all are good. If we go directly to the link, we can download the file. It just does not download using Jamf. Has anyone seen this before? Thanks, AJ.
Hello everyone, I am trying to configure Screen Saver Corners Are Secure -tr-corner ( https://www.tenable.com/audits/items/CIS_Apple_macOS_13.0_Ventura_v1.0.0_L2.audit:d8e594473ad878254160a22990e7bb3a) and for solution I can create a profile.But there is mentioned that "the key to include is Forced". Can someone please explain what is this key and how you use it?Thanks,Traian
For anyone that prefers to make Safari updates available via Self Service, here are the standalone installer download links extracted from Apple's Software Update Server catalog for what Apple's Security update bulletins published today are calling Safari 16.3.1. Unfortunately what Apple actually released today were new builds of Safari 16.3 with updated Build numbers. This means you'll have to use an EA to extract the CFBundleVersion string from the Safari app bundle to figure out exactly what version of Safari you have installed (also posted below).Safari "16.3.1" for macOS Big Sur: http://swcdn.apple.com/content/downloads/30/47/032-38743-A_CT6YB7IU0E/etlliehrvoqmlrb8mso9d2lh8vtnb59e0o/Safari16.3BigSurAuto.pkgSafari "16.3.1" for macOS Monterey: https://swcdn.apple.com/content/downloads/61/07/032-38754-A_I6L5FGHO4W/6vezgtgkabm4112wd26y1moii3kak18ykb/Safari16.3MontereyAuto.pkgEA to report Safari CFBundleVersion: #!/bin/sh #
Hello All,We use a proxy on our network and we are trying to come up with a solution to allow devices to establish a connection to Apple without bypassing that proxy. Has anyone encountered a similar situation and has come up with a way to resolve it? Any and all help is appreciated. Thank you
I am trying to remove stale / inactive mobile acct from the workstations after a certain time period.I tried a script but for some reason it also seems to delete the accts that are not in the time range ( e.g. set to delete acct after 14 day and the current user that logged in yesterday gets deleted also )I am trying to use a Config Profile > Mobility > Account Expiry payload but whenever I save the CP, it reverts back to 0 Hours.I've downloaded the .mobileconfig file and checked with a CP editor and it also shows 0 sec.I've created an new .mobileconfig file with 604800 ( 7 days ) and upload to Jamf Pro. The uploaded CP shows up with the correct duration ( 7 days ) but when I click Save, it reverts back to 0 hours.
Hi, I want to change default font in Outlook desktop on our Mac's.I tried using the OutlookFontPoke from Github but it didn't worked. Here is the error message:"Script result: usage: dirname path/Library/Application Support/JAMF/tmp/Outlook Font: line 20: cd: HOME not set WARNING: Registry DOES NOT exist at path /Library/Group Containers/UBF8T346G9.Office/MicrosoftRegistrationDB.reg. Attempting to create... mkdir: /Library/Group Containers: No such file or directory cp: //TemplateRegDB.reg: No such file or directory ERROR: Registry could not be created."Is there any other way of changing it? I need to change to Arial 10pt #272727
I am using AC2.1 to move an iPad to supervised state - I go through the migration, see the iPad in ABM and edit the MDM server to JAMF pro, as well as I see it in Prestage enrollment in the MDM as assigned, but on the actual iPad I get to the remote management screen and the error I get is " The configuration for this iPad could not be downloaded from company A, the request timed out" any thoughts/resolutions?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!