Get Support
Recently active
I never used JAMF protect in production. I was looking for some example in our daily life where JAMF protect is useful and JAMF Pro wont be able to do it.
Is it possible to manage the Airdrop and Bluetooth app through JAMF in such a way that it will function only on those mac devices enrolled in the same JAMF Pro console but it wont work on other Apple devices those are on different JAMF or not enrolled in any JAMF or MDM. It is for security purpose only.
I'm looking for a way to properly suppress the Ventura upgrade, as it has started appearing for our end users. We currently have a config profile scoped to defer major updates by 90 days pushed to all users, but I've gotten reports that users are getting the Ventura upgrade in Software Update. We have Ventura blocked from installing via restricted software, but I need a way to stop it from showing in Software update as the config profile to defer it by 90 days is not working. Any advice?
We for many years have used individual recovery keys for jamf. But every now and then we see issues with the individual recovery keys that is listed in jamf. Sometimes few times we are experienced the keys rapported in Jamf is not working, we stand with a unusable client that may cause data loss.Why the keys is not valid is of course the question, but somehow rapporting keys to jamf may not always happen in time from the client ?So thinking on actually setting an additional key and using a institutional recovery key - and then every month create a new institutional recovery key for mac, so it will not give security issuesIs anyone else using institutional keys also together with individual keys ?
We have a user-level configuration profile set up for students with the "Restrict which apps are allowed to launch" checkbox checked and a whitelist of applications. We are finding that this doesn't take effect on the first login. The configuration profile is applied and other restrictions in the profile take effect (System Preferences panels are grayed out, for example) but the user is able to launch all apps until they log out and log back in again. After that second login, everything works as intended and the user can only launch apps on the whitelist. Jamf gave me the workaround of using Restricted Software to block certain applications but this doesn't work for us since it can only be scoped to computers and not users. Any ideas?
Hello!I am trying to change the mail.app settings on multiple Macs, but it is not working.If anyone knows how to solve this problem, please let me know.What I would like to achieve.-Check "Mark addresses not ending with" (mail.app>Settings>Composing)- Put any address in the blank field- Achieve the above two points using the payload function of the configuration profileWhat I have triedI thought the following plist was relevant for the configuration.~/Library/Preferences/com.apple.mail-shared.plistHowever, when I uploaded the plist reflecting the settings from Jamf>Configuration Profiles>Application & Custom settings>Upload, it was not reflected in mail.app.
Searched Jamf Nation but couldn't find anything close enough to my use case. I'm querying the Jamf API for computer IDs by way of usernames:jamfUserURL="https://[company].jamfcloud.com/JSSResource/users/name/$username" computerID="$(curl -X GET -s -k -u "$jamfUser":"$jamfPass" "$jamfUserURL" | xmllint --xpath '/user/links/computers/computer/id/text()' - )" echo $computerID This works great except for end users who have more than one computer in the environment. Then I get a result with all IDs combined into one return. Would it make sense to stick this in a for loop to iterate through the multiple IDs? If so, can someone please assist?
Where do we find the download link for the Jamf Pro admin tools?
We have a rather small Mac fleet of a few dozen MacBook Pro, a handful of iMacs. We implemented jamf with a minimum of features. The users have administrative privileges, our environment is scientific and has to be open in that way. We have to provide the best support and also want to limit the workload, while restricting the least.How do we get the most out of our jamf instance?Which policies, profiles, scripts, apps and packages do you consider must-have?
Is there any ability to suppress the Quick Start functionality in iOS for DEP/Supervised devices? The Quick Start feature is what allows you to setup one iOS device by holding another iOS device you already use near the new one and allowing them to share settings.
Hello, Can anyone tell me why this script will not work when deployed through the JSS? rm -Rf /Applications/Install macOS High Sierra.app I've also tried: rm -Rf "/Applications/Install macOS High Sierra.app" When I run these commands in terminal, it works fine. When I push these commands as scripts through the JSS, they do nothing. Any ideas?
I have scoured the threads and the inter-webs and can't find much on this. I know how to show the uninstall package option on on-prem, I index the package in admin and voila.But such option is not possible on cloud.Please advise. Thank you,
I notice that the Jamf Pro board history logs for the instances hosted on the Western European clouds are offset by 1 hour.Daylight Savings Time will change in Europe at 01:00 UTC on 26 March 2023.Until then, the logs should show the Standard Time of day.Kind Regards,Alberto CassoliBES/BAPS ICT Services
I am just starting with Apple Business Manager and Jamf Now. All devices were purchased independently so there are no devices in ABM. As a test, I used Open Enrollment in Jamf Now on one device. It appears in the Jamf dashboard but not in ABM. Should I be enrolling in ABM first using Apple Configurator 2and then syncing? Is there any downside to just using Open Enrollment vs Apple Configurator 2?Thank you.
A Read-only Friday post by William Smith Every word is precious. You shouldn’t waste them. Let’s keep this one short and sweet to let you get on with your homework. A few Apple admins conferences, including the Jamf Nation User Conference (JNUC), have already opened their calls for proposals. Each conference may go by a slightly different name for submissions, but they’re all asking you for the same thing. They want to hear about your story. By now, you should have a good idea if your story fits with the theme of the conference or conferences you’ve chosen. Remember, all you need to do is go watch some of the videos they’ve posted online from past conferences to see if your idea fits. If you’re in the Apple management or security space, you’re going to fit just fine. What you’re going to submit is commonly known as an elevator pitch. Imagine you have this great idea and just so happen run into the decisionmaker on an elevator in a tall building. It’s now or never. As you ascend the bui
Is Jamf Migration specialist is part of license plan or need to pay for Jamf migration specialist?
Hi Everyone!I help manage macs for a university and lately we've been having some issues with our local admin account created during prestage enrollment. It's become an issue where the account will create, and we will be able to login to the local account for a while and then suddenly without any indication we won't be able to login to the account or use it for admin privileges. Has anyone else had this issue? I haven't been able to find anything in the records for computers that this happens on and am lost now.
Has anyone possibly put together a best practices list for how to deploy Zoom is a school environment for a district that has not used it since the advent of PPPC profiles? (you know, on the off chance there was a global pandemic and they needed to do a quick rolllout...)
You can now further configure your content policy with additional categories and subcategories under Policies > Content policy.Schools can use the changes to enforce a stricter overall policy by blocking all content and then allowing just the sites that students may need. They can also use to have more granular control over what sites students may have access to.Admins will be able to block all the same categories in JSI as they would be in Data Policy. This gives schools more granularity when deciding the sorts of content that students should be able to access.For example, one of the requested categories was "Other Shopping" as schools found students using iPads for online shopping during schools hours.The "Uncategorized" category will also be made available. This would allow admins to block all content that isn't in a JSI content category. Schools can use the above changes to enforce a stricter overall policy by blocking all content and then allowing just the sites that stude
I have to fill in for a co worker and have to renew the push certificate on several Jamf Pro instances of customers. Believe it or not, I have never done this before. And although it's not a difficult task I'm having trouble renewing these certs.The problem I run into is that the customers don't have a Jamf ID (or is not known to them/me). Two questions:- Do I have to configure the Cloud Connection Services in order to obtain the CSR?- Does the Jamf ID that's being used have to be a unique ID that's connected to the customer's Jamf subscription? Or can I just use a generic ID (mine for instance) and use that one to generate a CSR for all customers?
I am looking for some examples for launchagent projects which can help my mac fleet. Any idea which can help my mac fleet in regards will be appreciated. Thanks in advanced.
Is there such a tool that you can use to tell you the health of your mac, like battery life, how long the machine has not shut down, if the security as well as the other softwares are updated or not.I am trying to have a tool that will just pop-up to inform users that they need to update their software or to shut down the machine once in a while.
We have good number of mac clients in Intune and Munki, what is the best way to migrate those mac clients in JAMF Pro without interrupting end user?
Hi all,We've recently deployed Jamf Pro on-premises and made it available on the DMZ. We're planning on having an HTTPS DP available on the DMZ (Apache running on Debian) However, when I try to add the DP to Jamf Pro, it keeps asking me for the SMB Share info and credentials which this distribution point doesn't have. Is there any workaround for this issue? We do have a samba share on the internal network but I can't have an SMB share on the DMZ and even if I could our security team will laugh in my face. Does anyone know how to get around this issue? Cloud Distribution points are not an option for us.Thanks in advance!
Hey EveryoneI am working in a multiuser lab environment and I have been asked to create a shared folder space on the local machine then provide a desktop shortcut/Dock icon to this folder. What is the best way to achieve this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!