Get Support
Recently active
This appears to be happening to all our devices. Many times when a user or even myself goes to our iPhone and open up teams it is grayed out and is need to update. This is happening constantly, at first i thought "oh wow, they are doing lots of updates to this app." but that isn't the case. when this happens we are not getting notifications for the app. When i checked my phone, i am on the latest iOS still the issue.I do have in JAMF setup to push updates automatically, make app managed if not managed, and the scope of the app is for all devices. We are not out of licenses as i still have around 198 available still.
Hey all,I just wanted to share something I have been working on. In my environment we have a lot of developers with many versions of Java installed. Of these users none of them are local admins. In an effort to cut down on the users reaching out on a daily basis for temporary admin rights to import a new certificate I pieced together this script to let the user choose their certificate, ask the user to choose an Alias for this certificate and then import it to all Java Home locations. Feel free to use or offer improvement.EDIT: This will only allow certificates to be uploaded from a location Jamf can access. I have a note for my end users to ensure the certificates are either on their OneDrive or /Users/Shared/..loggedInUser=$( echo "show State:/Users/ConsoleUser" | scutil | awk '/Name :/ && ! /loginwindow/ { print $3 }' )JAVA_VERSIONS=$(sudo -u "$loggedInUser" /usr/libexec/java_home -V 2>&1 | awk -F'"' '{print $5}')theSelectedFile="$(osascript -l JavaScript -e 'a=Applic
I'm publishing an EDGE plist, that were created by iMazing Profile Editor. Defined the "RestoreOnStartupURLs" setting. Set to 4 (open a list of URLs). Additionally added the setting "RestoreOnStartupUserURLsEnabled" = true. Problem is: The User can add & remove their own startup urls, but not remove the defined ones from "RestoreOnStartupURLs". Is it possible to accomplish that?On Windows you can change this behavior. Microsoft Edge Browser Policy Documentation | Microsoft Learn
When I try to upload a VPP token to Jamf Pro (On Premise, Version 10.43) I receive an error message "Unable to handle file upload". I downloaded the VPP token again and tried to upload using Safari, Chrome and even Edge with Windows 11. Every time I get the same message. The log only shows the same error.Has anyone encountered the same problem and has a solution to this issue?
Hello Jamf Nation!I am looking forward to configuring Jamf Protect for our org. I fully understand the concept of the CIS benchmarks and that I should, at the very least, have the endpoint threat prevention in my plan set to block and report. Since this is my first time after researching with the software, I was wondering how it has been working for you all and if anyone is willing to share how they have their plans configured, so I could get some real-world examples on how this software has worked for others.I appreciate any assistance or insight you can provide, and thanks for your time!-Frank S.
Hi all,I hope someone can help me to find a solution.Within FireEye HX I could create an alert with "fileWriteEvent/fileName starts-with xxx"I try to rebuild this within Jamf Protect.I have created a custom analytic with the following analytic filter: (($event.isNew == 1 OR $event.type == 0) AND$event.prevFile == "protecttest")I have also added this to a smart group called "protect-ProtectTest". I have created a smart group with the criteria Jamf Protect smart groups like protect-ProtectTest and assigned this smart group to a policy where a script removes the group from the client: rm /Library/Application\\ Support/JamfProtect/groups/protect-ProtectTestI don't know where my fault is that it doesn't work.I hope for your answers or hints what I did wrong.Thx, Mario.
Hi,we tried to add Mapping's from host to REALM's ( MIT Kerberos ) placing the mapping into /etc/krb5.conf.The respective kdc of the realm's are having DNS entries.Unfortunately the mapping does not work.How host realm mapping's are configured on Jamf MAC Clients ?Can we distribute such settings through JAMF policy ? Thank you
Hello -Our organization recently purchased Jamf Connect for our macOS devices to manage SSO and the local accounts/their roles.I have this being pushed to the devices through Microsoft Endpoint. It worked the first couple times, but seems to be causing an issue now.I have the macOS devices to automatically be picked up upon azure registration to a dynamic group, that the Jamf Connect software and mobileconfig files push through.During the macOS setup we get to the local admin account creation. Previously, if we let it sit at this screen for a bit then restart the device through endpoint, it would pull up the Jamf Connect login page to authenticate with azure.Whenever we restart it now, the mac devices fall into a bootloop and the only way to fix it, is by erasing the drive and reinstalling the OS.Has anyone run into this issue? Am I able to skip the local admin account creation step?We had an implementation session with a Jamf consultant, but he seemed to be more of a sales guy than an
Today we are releasing Jamf Pro 10.45. Highlights of this release include: Google BeyondCorp Enterprise Integration The Google BeyondCorp Enterprise integration now includes the following enhancements: macOS, iOS, and iPadOS platforms are available from the BeyondCorp Enterprise Settings pane. The zero trust secure access solution developed by Google, enhanced with data from Jamf Pro, is available for iOS and iPadOS devices. Failover URL Update for Single Sign-On Integrations New instances of Jamf Pro 10.45.0 or later enabling single sign-on (SSO) for the first time will have a failover login URL that includes a randomized string of characters for improved security. If you enabled SSO in Jamf Pro 10.44.0 or earlier, you can choose to retain your current failover URL or opt-in to use a randomly generated URL. Click Regenerate to create a randomly generated URL, or generate a new failover login URL using the Jamf Pro API /v1/sso/failover/generate endpoint. After regenerating your URL,
Sometime between November 16th and 17th something changed and the two PowerShell scripts I run to connect to our JAMF instance and maintain data sync with our SIS started failing because PowerShell can no longer connect to JAMF.Annoyingly the script works fine on newer Windows operating systems, but our SIS is still hosted on Server 2012, and I also can no longer connect from ye'olde Windows 7. This hardware is scheduled for replacement, but we need to finish out the school year and for some reason the scripts have suddenly failed. A local policy change? A Microsoft policy change? A JAMF update? Anyone have any idea?This is the code I got from someone at JAMF, possibly even this forum or a predecessor, in a bygone era, with obvious redaction:$JSSAPIURL = "https://##########.jamfcloud.com/JSSResource" $JSSAPIUser = "##########" $JSSAPIPass = "##########" $VerbosePreference = "SilentlyContinue" #First we need to setup the shell to ignore self-signed certs for non-PKI Casper installs: ad
We're trying to setup an ipad to use to track some airtags but we can't add them. We get "Cannot set up AirTag. Your device management settings do not support AirTag pairing on this iPad." We have no restrictions in JAMF for this yet sure enough if you look at the profiles there's one that says "Devices tab in Find My app is disabled" but we don't have any restriction for that turned on. If we wipe it and remove it from our enrollments it works fine but then we're not managing it.
Possible be moving from Jamf Pro to Intune.How does the TeamViewer integration between Intune and Jamf Pro compare?We really like how TeamViewer integrates with Jamf Pro, but can't find if Intune works in the same manner.Someone can share their light on it?
I'm looking to transition from having our MSP provision brand new laptops to having the end-user run through the setup. We look to be all setup for auto-enrollment into our MDM. I don't see any reason not to go this route other than we can't seem to setup a local admin account remotely that has access on machines with filevault enabled. Any other reasons not to go this route?
Hi all, I am hoping someone can help me with a query regarding JAMF. I have been tasked with the rebranding of the company JAMF portal. We have about 500+ devices in JAMF and are going through a company name change. We want to rebrand all the current settings to the new company name, without impacting currently enrolled users. I have never used JAMF, so I have very little knowledge of it. Is this possible? i.e changing the enrolment URL to the new company name and any other branding we might have set and not impact currently enrolled devices?
For individual computers we gather application usage logs. For every computer I can check what applications have ran at: Computer > History > Application Usage Logs.Is it also possible to query these logs over all computers? I want to know if an specific application (Microsoft Outlook) is actually being used, say last month.
I would like to deploy an backup agent (commvault) on all computers managed by our JamfPro solution.I create the package and the policies and it works fine except that I have to enter my crendentials once it has been installed.I then wonder whether if it's possible (and how) to integrate a variable ($EMAIL) into the deployement policies of the package in order to configure the installation package with the user credential?Thank's
Hello, Im attempting to install Jamf pro trial version on my mac M1 computer. When I go to download, it's asking me to run a jamfproinstaller.run, but it's not showing any application to run that. What's next step? Thanks
So im' trying to push this configuration profile: <?xml version="1.0" encoding="utf-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PayloadContent</key> <array> <dict> <key>familyControlsEnabled</key> <true /> <key>pathBlackList</key> <array> <string>/Users/</string> </array> <key>pathWhiteList</key> <array> <string>/Applications</string> <string>/System Library</string> <string>/Library</string> <string>/bin</string> <string>/usr/bin/</string> <string>~/Library/Application Support/Microsoft/EdgeUpdater/</string> <string>~/Library/Application Support/Google/GoogleUpdater/</string> </array> <
Happy 2023 all, yeah, I know, it's nearly the end of March and the first day of spring, but this is my first post of the year.... I'm looking for a way to have mac users, and eventually mobile users, to be forced to create an apple ID that uses their domain email address. has anyone tried this, and/or succeeded? with a script or a profile? not by giving them the forceful "Do this or else we'll forbid you access to your account" email.....
With recent discussions of the Canadian Government blocking and removing TikTok from mobile devices, I would like to explore how this can be accomplished in case our institution decides to do the same. While researching this topic, I came across articles that suggest flagging the device as non-compliant or "restricting" the app through its bundle ID, but these methods do not actually remove or block the app.When you add a restriction, it only hides the icon from launching the app. The app can still be downloaded from the App Store, and although it will hide the icon, it will still be present on the device.
Hi,I've deployed a policy to force Password Required To Wake Computer From Sleep Or Screen Saver. On the mac where it was deployed I see its active. Under JamfProtect I still see the insight says it's not active. Can I force the Insights to be updated on the computer so it detects the changes? Regards,
Hello, I am looking to see if there is a way to rename devices in Jamf Pro's Devices tab. I have looked all over and have found no way to rename the iOS and iPadOS devices. I must be missing something. Would anyone be able to guide me through this? I have DEP devices in Jamf so I should have access to change the device name.
Hi Everyone! is there a way through Jamf to change default browser to chrome automatically? or how can we do that? as I don't see any config profile in Jamf for that specific task. We do have a lot of Macs that we need to change their default browser to chrome silently. Thank you!
Hi, I accidently deleted an iPhone from Jamf without first removing the MDM from the phone. The phone is now locked to a generic account thats password was stored within Jamf. Is there a way to recover the deleted phone in Jamf?
A while back, I sent a mass action for computers to update the OS and 'Download and allow macOS to install later'. The smart group I sent it to though had a few computers that were already updated, and those computers keep getting a popup saying 'Required managed update, an update is scheduled to automatically install tonight...', but clicking on the popup just makes it disappear and won't do anything. Has anyone else experienced this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!