Get Support
Recently active
Today we are releasing Jamf Pro 10.45. Highlights of this release include: Google BeyondCorp Enterprise Integration The Google BeyondCorp Enterprise integration now includes the following enhancements: macOS, iOS, and iPadOS platforms are available from the BeyondCorp Enterprise Settings pane. The zero trust secure access solution developed by Google, enhanced with data from Jamf Pro, is available for iOS and iPadOS devices. Failover URL Update for Single Sign-On Integrations New instances of Jamf Pro 10.45.0 or later enabling single sign-on (SSO) for the first time will have a failover login URL that includes a randomized string of characters for improved security. If you enabled SSO in Jamf Pro 10.44.0 or earlier, you can choose to retain your current failover URL or opt-in to use a randomly generated URL. Click Regenerate to create a randomly generated URL, or generate a new failover login URL using the Jamf Pro API /v1/sso/failover/generate endpoint. After regenerating your URL,
Sometime between November 16th and 17th something changed and the two PowerShell scripts I run to connect to our JAMF instance and maintain data sync with our SIS started failing because PowerShell can no longer connect to JAMF.Annoyingly the script works fine on newer Windows operating systems, but our SIS is still hosted on Server 2012, and I also can no longer connect from ye'olde Windows 7. This hardware is scheduled for replacement, but we need to finish out the school year and for some reason the scripts have suddenly failed. A local policy change? A Microsoft policy change? A JAMF update? Anyone have any idea?This is the code I got from someone at JAMF, possibly even this forum or a predecessor, in a bygone era, with obvious redaction:$JSSAPIURL = "https://##########.jamfcloud.com/JSSResource" $JSSAPIUser = "##########" $JSSAPIPass = "##########" $VerbosePreference = "SilentlyContinue" #First we need to setup the shell to ignore self-signed certs for non-PKI Casper installs: ad
We're trying to setup an ipad to use to track some airtags but we can't add them. We get "Cannot set up AirTag. Your device management settings do not support AirTag pairing on this iPad." We have no restrictions in JAMF for this yet sure enough if you look at the profiles there's one that says "Devices tab in Find My app is disabled" but we don't have any restriction for that turned on. If we wipe it and remove it from our enrollments it works fine but then we're not managing it.
Possible be moving from Jamf Pro to Intune.How does the TeamViewer integration between Intune and Jamf Pro compare?We really like how TeamViewer integrates with Jamf Pro, but can't find if Intune works in the same manner.Someone can share their light on it?
I'm looking to transition from having our MSP provision brand new laptops to having the end-user run through the setup. We look to be all setup for auto-enrollment into our MDM. I don't see any reason not to go this route other than we can't seem to setup a local admin account remotely that has access on machines with filevault enabled. Any other reasons not to go this route?
Hi all, I am hoping someone can help me with a query regarding JAMF. I have been tasked with the rebranding of the company JAMF portal. We have about 500+ devices in JAMF and are going through a company name change. We want to rebrand all the current settings to the new company name, without impacting currently enrolled users. I have never used JAMF, so I have very little knowledge of it. Is this possible? i.e changing the enrolment URL to the new company name and any other branding we might have set and not impact currently enrolled devices?
For individual computers we gather application usage logs. For every computer I can check what applications have ran at: Computer > History > Application Usage Logs.Is it also possible to query these logs over all computers? I want to know if an specific application (Microsoft Outlook) is actually being used, say last month.
I would like to deploy an backup agent (commvault) on all computers managed by our JamfPro solution.I create the package and the policies and it works fine except that I have to enter my crendentials once it has been installed.I then wonder whether if it's possible (and how) to integrate a variable ($EMAIL) into the deployement policies of the package in order to configure the installation package with the user credential?Thank's
Hello, Im attempting to install Jamf pro trial version on my mac M1 computer. When I go to download, it's asking me to run a jamfproinstaller.run, but it's not showing any application to run that. What's next step? Thanks
So im' trying to push this configuration profile: <?xml version="1.0" encoding="utf-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PayloadContent</key> <array> <dict> <key>familyControlsEnabled</key> <true /> <key>pathBlackList</key> <array> <string>/Users/</string> </array> <key>pathWhiteList</key> <array> <string>/Applications</string> <string>/System Library</string> <string>/Library</string> <string>/bin</string> <string>/usr/bin/</string> <string>~/Library/Application Support/Microsoft/EdgeUpdater/</string> <string>~/Library/Application Support/Google/GoogleUpdater/</string> </array> <
Happy 2023 all, yeah, I know, it's nearly the end of March and the first day of spring, but this is my first post of the year.... I'm looking for a way to have mac users, and eventually mobile users, to be forced to create an apple ID that uses their domain email address. has anyone tried this, and/or succeeded? with a script or a profile? not by giving them the forceful "Do this or else we'll forbid you access to your account" email.....
With recent discussions of the Canadian Government blocking and removing TikTok from mobile devices, I would like to explore how this can be accomplished in case our institution decides to do the same. While researching this topic, I came across articles that suggest flagging the device as non-compliant or "restricting" the app through its bundle ID, but these methods do not actually remove or block the app.When you add a restriction, it only hides the icon from launching the app. The app can still be downloaded from the App Store, and although it will hide the icon, it will still be present on the device.
Hi,I've deployed a policy to force Password Required To Wake Computer From Sleep Or Screen Saver. On the mac where it was deployed I see its active. Under JamfProtect I still see the insight says it's not active. Can I force the Insights to be updated on the computer so it detects the changes? Regards,
Hello, I am looking to see if there is a way to rename devices in Jamf Pro's Devices tab. I have looked all over and have found no way to rename the iOS and iPadOS devices. I must be missing something. Would anyone be able to guide me through this? I have DEP devices in Jamf so I should have access to change the device name.
Hi Everyone! is there a way through Jamf to change default browser to chrome automatically? or how can we do that? as I don't see any config profile in Jamf for that specific task. We do have a lot of Macs that we need to change their default browser to chrome silently. Thank you!
Hi, I accidently deleted an iPhone from Jamf without first removing the MDM from the phone. The phone is now locked to a generic account thats password was stored within Jamf. Is there a way to recover the deleted phone in Jamf?
A while back, I sent a mass action for computers to update the OS and 'Download and allow macOS to install later'. The smart group I sent it to though had a few computers that were already updated, and those computers keep getting a popup saying 'Required managed update, an update is scheduled to automatically install tonight...', but clicking on the popup just makes it disappear and won't do anything. Has anyone else experienced this?
Just wanted to share this. I've had some specific use case scenarios where people have enabled FileVault outside of Jamf, and it's necessary to decrypt the machine and then perform encryption over again to get the recovery key escrowed in Jamf properly. It's not perfect, but I wrote this script to be used in Self Service by the user. Since the fdesetup disable command requires the user's password, you can't remotely disable FileVault (unless you know a FV enabled user's password or recovery key on the machine, which chances are you won't know if FV was enabled improperly). This seemed to be the next best option in my case so I didn't have to go around to every machine and run it. Tested on 10.13 and 10.14 machines. Cheers. #!/bin/sh # Get logged in user USER=$( ls -l /dev/console | awk '{print $3}' ) # Check if FileVault is already off - no need to run script if so if fdesetup status | grep -q Off; then /usr/bin/osascript <<EOT tell application "System Events" activate displa
I would like to know how many are using TouchID to unlock their macs.My EA is working pretty good. However, i am not able to exclude who have the fingerprint set but not used. Any idea please?
HelloI would like to allow network credentials to login for Jamf console and self service . We have already enabled cloud identity provider and SSO but still we are unable to sign in on Jamf console using network credentials . Is it mandatory to configure LDAP server configurations on Jamf pro settings to allow network credentials to sign in on Jamf pro console ? If yes can we use with Microsoft IDP for LDAP server or we need to allow the traffic to onprem LDAP through Jamf cloud hosted server ? . I believe for any cloud or SAAS instances we prefer to use Microsoft IDP with OAUTH2 or SAML SSO for authentication and authorization.
I'm looking for recommendation for scripting installs with Brew to deploy software. Whenever I try to do an install from Jamf using brew it fails stating cannot be run as a root user or something like that. I've found several recommended ways do it but never seem to work.
We have an interesting situation.Last year we discovered an issue where about 630 of our devices never renewed their mdm profile, and they are now unable to get any management commands or profile updates. We have a decent solution that takes about 5 min per device to turn of csrutil and then remove the profiles and then re-enroll, however we have also found that one of the profiles is causing issues for testing that is currently going on. The profile in question adjusts the "Parental Controls" to try to block adult websites with its content blocker. We turned this one on back in 2020 and it originally allowed parents of students to use the screen time function. This appears to no longer be necessary since you dont now need this feature on to turn on screen time, but now since the mdm is expired we cannot remove or adjust this setting without many steps. Im hoping someone in the community can tell me a way to write the plist or a defaults command that can su
Hello all. So I'm witnessing some odd behavior when attempting to scope or exclude computers. I've tried this in both Safari and Brave. I'll select a policy or profile and either include or exclude a device. When I click the edit button, go to "Add" (or remove) a device the bottom scroll bar in the browser disappears. If I zoom out to about 25% of size I can finally click the Add button but this is quite inconvenient. I was just wondering if anyone else had run into this. Thanks
Hello Team,How do I Prevent uninstallation of Symantec DLP Agent/App from all login user on managed Mac?Note:- I'm looking a way that Jamf can control over the uninstallation of DLP.Thank you.
I see there are layouts that can be configured and assigned to devices. I'd like for this to be the initial layout but allow users to change it how they want. Is there a way to apply a layout and not have it be sticky or reapply itself after a user modifies it? Thanks in advance.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!