Get Support
Recently active
Has anyone possibly put together a best practices list for how to deploy Zoom is a school environment for a district that has not used it since the advent of PPPC profiles? (you know, on the off chance there was a global pandemic and they needed to do a quick rolllout...)
You can now further configure your content policy with additional categories and subcategories under Policies > Content policy.Schools can use the changes to enforce a stricter overall policy by blocking all content and then allowing just the sites that students may need. They can also use to have more granular control over what sites students may have access to.Admins will be able to block all the same categories in JSI as they would be in Data Policy. This gives schools more granularity when deciding the sorts of content that students should be able to access.For example, one of the requested categories was "Other Shopping" as schools found students using iPads for online shopping during schools hours.The "Uncategorized" category will also be made available. This would allow admins to block all content that isn't in a JSI content category. Schools can use the above changes to enforce a stricter overall policy by blocking all content and then allowing just the sites that stude
I have to fill in for a co worker and have to renew the push certificate on several Jamf Pro instances of customers. Believe it or not, I have never done this before. And although it's not a difficult task I'm having trouble renewing these certs.The problem I run into is that the customers don't have a Jamf ID (or is not known to them/me). Two questions:- Do I have to configure the Cloud Connection Services in order to obtain the CSR?- Does the Jamf ID that's being used have to be a unique ID that's connected to the customer's Jamf subscription? Or can I just use a generic ID (mine for instance) and use that one to generate a CSR for all customers?
I am looking for some examples for launchagent projects which can help my mac fleet. Any idea which can help my mac fleet in regards will be appreciated. Thanks in advanced.
Is there such a tool that you can use to tell you the health of your mac, like battery life, how long the machine has not shut down, if the security as well as the other softwares are updated or not.I am trying to have a tool that will just pop-up to inform users that they need to update their software or to shut down the machine once in a while.
We have good number of mac clients in Intune and Munki, what is the best way to migrate those mac clients in JAMF Pro without interrupting end user?
Hi all,We've recently deployed Jamf Pro on-premises and made it available on the DMZ. We're planning on having an HTTPS DP available on the DMZ (Apache running on Debian) However, when I try to add the DP to Jamf Pro, it keeps asking me for the SMB Share info and credentials which this distribution point doesn't have. Is there any workaround for this issue? We do have a samba share on the internal network but I can't have an SMB share on the DMZ and even if I could our security team will laugh in my face. Does anyone know how to get around this issue? Cloud Distribution points are not an option for us.Thanks in advance!
Hey EveryoneI am working in a multiuser lab environment and I have been asked to create a shared folder space on the local machine then provide a desktop shortcut/Dock icon to this folder. What is the best way to achieve this?
I am restarting the mac via a policy, I used shutdown command to restart, User are getting popup to select restart operation now, after 1 min, after 5 mins, after 1 Hrs or after 2 Hrs. If user select 1 Hr or 2 Hrs then before going to be restarted user should get a popup window that mac is going to be restarted in some mins/time. So that user can be ready to save all opened item. May I know which command will help me or any flag is there for shutdown command? Warn-ing command is showing message in terminal but no popup window, any idea for this?
Hi, How do we restrict users to not remove the profiles on iphone enrolled via User-Invitation enrollment method
I'm seeing a lot of machines that when booted into recovery, Ventura is not being presented. Usually it's Monterey. Appears to be the OS the machine is shipped with. All of these machine were previously on Ventura. When can fix it with AC2, but that's not scalable. Anyone seen this?
Hi all,Long time lurker, first-time poster. Hope everyone is doing well :DI've got this really weird issue with our config profiles and I'm wondering if anyone can point me in the right direction.It started around a week ago, I noticed that apps were downloading onto our devices ok, but the profiles themselves that carry the payloads for restrictions kept erroring out. I get quite an unhelpful error message.
Good Afternoon,I've opened a support case with JAMF but haven't heard anything so I thought I'd try here until I do.We're running JAMF 10.35.x and are unable to upload any pkgs to the cloud with JAMF Admin. The error is as follows: There was a problem uploading the package to Jamf Cloud. Connection failure: "The operation couldn't be completed. ( error 504.)This happens with any pkg file at any size.
Just wondering whether anyone else has seen any performance issues on an on-premise instance of Jamf Pro running on Windows Server 2019?We recently upgraded to v10.37.2 but since ~10.34.2 we’ve seen a lot of unresponsiveness at various points throughout the day, such as no response when trying to log in, or lots of white space and blue circles when moving around the web UI, say from Policies to Configuration Profiles for example. After 10-15 minutes of unresponsiveness, everything is fine until it happens again. When this happens, our platform guys report “100% CPU caused by Apache Commons Daemon Service Runner”. There's nothing conclusive in the Jamf logs.The VM has 4 x 2.40GHz CPUs and has 16GBs of RAM, 8GB of which is allocated to Tomcat. Java and MySQL is fully up to date. Our (internet facing) DP is also hosted on the same server.I have a case open with Jamf who have logged in and run various MySQL commands, but they’re not really sure what is going on. Therefore I’d really apprec
I was wondering if we can build a smart group for devices based on the devices country?at the moment, we have our devices scattered around the globe (USA[Chicago/NewYork/SanFrancisco/Florida/Houston], United Kingdom, South Africa, Japan, New Zealand, Australia [Sydney/Melbourne/Brisbane/Perth]
Hi all,My goal is to delete any files or folders on the desktop when the user logs out.I'm using this command in bash script: rm -Rf /Users/<currentuser>/Desktop/*The sript is set to run at logout.Unfortunately it does not work.When I try the command in the users Terminal it prompts "sure you want to delete all X files in /Users/<currentuser>/Desktop [yn]?"According to this post under Jamf Pro the script should work if the script is set to run at 'startup', but this option is not available in Jamf School.Is there any way to get it to work?
Hi,Sorry if this is the wrong place to ask this or if has already been answered. We have purchased a large number of M2 Macbook pros from an authorised reseller. They show in ABM and in prestage, however when I go to enrol them it does not work how it should! Sometimes after the Remote Management screen it goes straight to a log in screen (even though I have not set up an account yet!) or it allows me to create the local user account but does not configure the laptop as it should do (does not clean up the dock and enable filevault). I have resolved some of them by erasing the entire disk and then reinstalling the OS, however for osme of this even this does not have any effect (tried 4 or 5 times!) Any ideas or suggestions as to how we can resolve this would be appriciated. Thanks
It's not quite a problem, and so I didn't enter it on the "issues" page for the Jamf Migrator (https://github.com/jamf/JamfMigrator/issues) but is anyone else bothered by the 2 different colors of green used for "successful" get/send jobs? I feel that has to be an error, right? #jamfmigrator
Hello Team, We are stuck in upgrading the OS version on the MAC system with the Apple Silicon processor. We are trying to upgrade the MAC system with the Apple Silicon processor with the Bash command.When we initiate installation on the system using the Bash command, it prompts credentials for the root user to proceed further even if we are executing the command using the root user. Bash script executes using the Root user and the installation on the MAC system with an Apple Silicon processor will not work until we pass credentials for the root user.Do we have steps/commands for the Bash script to perform a macOS upgrade by bypassing the password requirement on the MAC system with the Apple Silicon processor?
Hello,I can't find an exact answer for this question so i'm sorry if the answer already exists but we are about to go live with Jamf Pro and our security team have a potential issue with Gatekeeper that I wonder if anyone else is able to advise on?If we set Gatekeeper to "Mac App Store and identified developers", how are users without admin permissions able to install an app that is not covered by this setting but is approved by the organisation to be installed? Our security department are not happy with the "Anywhere" setting so they want some control of what users can install. Is there a configuration that can be applied to say that if a user tries to install something that is not in "Mac App Store and identified developers" that if informs IT and then the IT department can approve/deny?I know that there is a temporary override function but this is only for admins?Any advice much appreciatedThanks
Hi all, Am seeing the below on my jamf logs. How do i find the device with the UDID? Thanks com.jamfsoftware.jss.exceptions.operations.MDMActionCreationException: com.jamfsoftware.jss.mdm.actions.exceptions.DeviceNotFoundException: Unable to find device with UDID: 9B937110-2A49-5BA5-B2EA-E35381D6BB2A at com.jamfsoftware.jss.mdm.actions.MDMActionFactory.createActionForRequest(MDMActionFactory.java:326) at com.jamfsoftware.jss.mdm.enrollment.MDMController.parseRequestAction(MDMController.java:313) at com.jamfsoftware.jss.mdm.enrollment.MDMController.getMdmRequestAction(MDMController.java:231) at com.jamfsoftware.jss.mdm.enrollment.MDMController.process(MDMController.java:123) at com.jamfsoftware.jss.mdm.enrollment.MDMController.doPut(MDMController.java:105) at javax.servlet.http.HttpServlet.service(HttpServlet.java:664) at javax.servlet.http.HttpServlet.service(HttpServlet.java:742) at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(Ap
We have a migration requirement and we have around 300 devices are managing from Jamf On-prem. Upon checking, we are planning for the custom DNS option where we don't need to re-enroll those devices to the cloud. But, when the AWS can validate the URL via email, it will send an email to the domain manager of the environment. If the Jamf on-prem URL is 'jss.company.com' it would be easier to do the custom DNS because when sending an email first part of the URL 'jss.company.com' will be choked off and sent to 'admin@company.com.' But our on-prem URL is 'jss.it.companyname.com' will there be any problem in doing custom DNS?
Hello, I update the mac mini (2020 M1) to VenturaAnd it looks like the content cache is having an issue. where the setting is grey out and says "Your system administrator is managing Content Caching" This was working on Monterey - the same mac mini nothing has changed except for the macOS version. I want to know if this is anything related to the previous jamf bug that did the same thing. Or this is Apple Issue?
Provide your users more detailed feedback on CrowdStrike Falcon’s built-in falconctl diagnose commandBackgroundTesting software from potential vendors frequently involves providing vendor support with client-side logs.How easily — and timely — you can provide the requested logs will certainly influence the success of your pilot.We leveraged swiftDialog to provide our users more detailed feedback on CrowdStrike Falcon’s built-in falconctl diagnose command.Continue reading …
Here's the scenario:We have a classroom of computers. Between class sessions, we run a restart on those computers. This happens at varying times.To run this restart we used to use Apple Remote Desktop. Since that is becoming/is unsupported, we want to move away from it.To run the command to restart/shutdown, etc., we have a staff computer that is separate from the other classroom computers.So... from what I've read it is possible to call a policy from a separate policy. Say:(Policy 1) has a custom trigger, and(Policy 2) uses Files and Processes to call the custom trigger 'sudo policy -trigger [triggername]'I created (Policy 1) to deliver a restart command. I scoped it to all of the computers that I want to have restarted. I created a custom trigger 'restartComputers10'I created (Policy 2), have it call the 'restartComputers10' trigger, scoped it only to the staff computer, made the command available in Self Service.Now that policy is only visible in Self Service from the staff computer
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!