Get Support
Recently active
I am dealing with this issue where some users created webclips using Safari on their iPads. How can I prevent users from doing this? Also I am not able to delete the webclips they have created with inappropriate names. I have started looking to see if there are any configuration profiles that are preventing me from deleting those web shortcuts. Any help or suggestions is appreciated.
I'm running into some problems with a Application & Custom Settings payload pushing a PLIST for Microsoft Edge where it refuses the values for ExtensionInstallAllowlist and ExtensionInstallForcelist.Anyone else seen this?
This is probably a dumb question but I have not been able to find an answer.I was requested to remove an App which was purchased by a 3rd party and converted to a "dangerous" app. I am able to get the Bundle ID for the App but not the Name (IE: App Name "Keynote" would be Bundle ID "com.apple.Keynote.") When I type the name of the app in nothing related shows up. As long as I have the Bundle ID, can I substitute my own "App Name" and still have the App Restriction work?
Does anyone have a good way to auto install homebrew for apple silicon and intel? Previously I used this script but it's getting stuck. #!/bin/sh# Set variables for the logged in userloggedInUser=$(stat -f "%Su" /dev/console)#Obtain processor type and add to variableprocessor=$(/usr/bin/uname -p)# Check for Homebrew if it exists then update it otherwise install Homebrewwhich -s brewif [ where brew ]; thenecho "Homebrew is installed ...moving on"elseecho "Homebrew is not currently installed. Installing..."/usr/local/bin/jamf policy -event brewfi# Create elevated permissions during installecho "$loggedInUser ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/elevated# Adjust permissions to elevatedchmod 440 /etc/sudoers.d/elevatedchown root:wheel /etc/sudoers.d/elevatedecho "$loggedInUser"# Check processor architecture type and run command according to processorif [ "$processor" = "arm" ]; thenecho "Installing brew app for M1"sudo -u "$loggedInUser" /opt/homebrew/bin/brew reinstall -
First time poster. Hopefully I'm doing this right. We are looking to implement Graylog in our environment (Mac/PC)To start, we are looking to just get logins and logouts. Is there a way to send Computer Usage Logs from Jamf Cloud to Graylog?Or, where does the Computer Usage Logs come from in macOS (10.13 or above)?Is there a login/logout script that I can run to send those specific logs to Graylog?
Hello! I recently updated the 'Master Mac' I use that runs jamf admin, This sits now on ventura with the most up to date version of Jamf Admin (At this time V10.44.1) and I cant for the life of me add new printers! When clicked it asked for my admin login, once given nothing appears... click again and the same issue... Anyone else had trouble with this?
Hi all,I'm creating a Google Chrome configuration for managing settings on multiuser computers (that have many users every day using the same computer and account). I am looking for ways to disable logging into the Chrome browser, and (if possible) a method for removing browsing history/cookies/cached data, etc. upon closing the browser.Right now, I'm using the iMazing Profile Editor to develop property lists for the settings. I have found many options for Chrome in iMazing for tweaking settings that will help, such as removing the ability to sign into the Google Chrome profile, and disabling autofill, etc.Then, I found these options for setting "Incognito Mode Availability":No ValueIncognito mode availableIncognito mode disabledIncognito mode forcedHaving incognito forced might give us all we need. A user can still sign into user accounts such as Gmail in incognito. Has anyone tried this before? Does using a forced incognito mode raise any red flags?I'd like to duplicate these efforts
When uploading a .mobileconfig to Jamf pro most setting are not displayed, nor configurable. This does not seem to be the case with jamf now. When will Jamf pro work like Jamf Now with .mobileconfig
I have an iPhone 6 that is passed around to people who travel on behalf of our school. I just received it back from someone and wiped it out. Now during the setup at the Remote Management screen, it says the configuration could not be downloaded. Cancelled. It was originally enrolled in DEP with Apple Configurator 2 and added to Pre-Stage Enrollment with no problem. Is this a certificate issue?
Hi folks,I support a Fire Department and there's an iPhone assigned to each Company Officer. So the phone is not assigned to an individual but instead a whole crew. That crew is on a four shift rotation so from day to day, the person possessing the phone changes.So, the phones are basically used as kiosk devices- no Apple ID, no personal logins, no email, no messaging, just our organizational apps, and as a calling device. There are times when it would be useful to be able to send an email to a particular device, regardless of who is using it that day. And it would be useful to be able to receive mail from the user of the device if they take a picture in the field or a screen shot of something.Has anyone come up with a decent working process where devices can be used as user agnostic kiosk type devices, but also be able to send and receive email from the device? I've thought about creating accounts for each device, but then you throw in password management or MFA and things get complic
Hi,Just wondering if anyone has any guidance or advice for renewing external certs on jamf pro to our iPads. The way i'm thinking is to push out the new certs as separate configuration profiles and wait till they're deployed alongside the current profile. Then just removing the older cert once the new ones installed? Can't think of any other way of doing it but just wanting to see if anyone else had an opinion on this? Thanks,Paul
Hi all, I hope everyone had a great Christmas and New years? So we are in the middle a project to change our MDM provider from Mosyle to JAMF and Identity management from Jump Cloud to Okta. Now I am quite new to MDM solutions at least at this level (mostly apple based company I am at) so they went with an MDM solution over trying to use AD joining and such (I have managed a small number via Intune) But mostly I have been in Windows based companies with AD/SCCM imaging type set ups. So after looking trough the community I struggled to find anyone posting a similar question to me. My question is has anyone done the same moving from Mosyle to JAMF recently and how did you go about transitioning the machines (removing current profiles and un enrolling etc.) from Mosyle and then enrolling via JAMF? We will be using JAMF pro if that helps :) Thanks in advance
Hello everyone,I am having a problem where I need to block access to a specific Google Site on our school iPads. When I add the URL to the blocklist, it blocks ALL Google Sites. When I try to allowlist a different Google Site it apparently differs to the more restricitive and blocks access anyway. I am assuming it is blocking the root (https://sites.google.com) and not allowing anything past the lead in (https://sites.google.com/coolschoolstuff.com) <-made up URL for this example.Anybody have a solution?Thank you!
So, this is pretty straight forward for Jamf Pro, but I can't seem to figure out how to apply a custom icon to an in-house package deployed via Jamf School Self Service. Am I missing something obvious? Thanks!
I created buildings in my Jamf Pro instance, and then I created Device Smart Groups where the criteria is “Building..is…[select ellipsis to chose the building from the list of buildings]”.I created 20 Device Smart Groups with this criteria, and all but three have populated correctly. I have Prestages where I have selected the Building in the drop-down menu in the User & Location to be added to all devices in that Prestage. I have confirmed that the building has populated correctly in the inventory records for these devices.I’m so confused, I used the same process for the other groups and they populated just fine. Has anyone else come across this before?
Just curious if anybody has seen this. I've tried this at work and on my home wifi. When I go to run the 12.6.3 update, I'll get the network error. I'll try it 2 more times and then the update just goes away, but it eventually shows back up. This is happening on a bunch of Mac's on different networks. At the time I did it, I did check and there weren't any apple server issues. We do have a couple of security tools installed that could affect it, but there are some devices that can run it.
Hi all,Is anyone using super and running into errors when trying to apply updates on Apple Silicon Macs?The API keeps failing for me while waiting for the MDM command, ScheduleOSUpdateScan, to return a response. It auto times-out after 5 minutes. If I check the computer's record in Jamf I can see the command, but it sits in a Pending state for more than 10-15 minutes.Has anyone else run into this issue?
At initial launch, AC 1.7.4 launches a dialog box requesting the user to accept a license agreement. After acceptance, the dialog box is never seen again. I am trying to script the installation of this application and I have not yet figured out how to suppress this dialog box. I have used both fseventer and Composer to try to isolate the file and I have performed a "defaults read ~/Library/Containers/com.apple.configurator/Data/Library/Preferences/com.apple.configurator.plist" but I am not finding any clues. I would appreciate any guidance or clues. Thanks!
We've been having some sporadic Mac devices lose items/icons in their menu bar and both Chrome and Slack (main tools in the company) open but do not load anything. Just spinning wheel. Also Privacy & Security in System Prefs (Settings) would not load either. The devices still were connected to their wifi and could use Safari to browse the web. This has happened to about 5 users out of 45 macos devices.This started happening a few of weeks to our fleet after enrolling into Jamf. Trouble shooting included rebooting, shutting down, entering safe mode. Nothing in activity Monitor was taking up resources as the Mac was idle. I checked logs on all the devices and initially believed from the install.log's that it was a softwareupdate running in the background so i deactivated deffered updates and auto updates.With the last user, experiencing all these symptoms, i was able to get some time to dig further. We use Jamf Compliance Editor to upload plists and compliances to CIS Level 1 +
Hello, we where able to deploy a self signed certificate via JAMF configuration profile using the certificate manager. Unfortunately the certificate is not set to trust. I can set it to trust via command line but I would need to find a way to deploy the certificate file to the macbook laptop then run a trust command via script. Unfortunately there seem to be no documented way to do this. How can I achieve my goal. How can I deploy a self signed certificate and tell all our jamf computers to always trust that certificate.
Hello Jamf Nation! We recently released Jamf Protect 4.0.0 which includes significant enhancements to how analytics are managed, standardized versioning for the Endpoint Threat Prevention database, new accessibility theme options, and the ability to export a CSV report of your Insight Compliance Report dashboard. Analytic SetsAnalytic Set enhancements include an updated Analytics screen, and an improved workflow for managing groups of analytics and associating the analytic sets with plans. For more information, see Jamf Protect Analytics. Endpoint Threat Prevention Database VersioningThe threat database versioning has been standardized across all customers to improve version visibility and reporting. New Accessibility Theme OptionsAdditional accessibility theme options have been added to the user menu in the upper-right of the Jamf Protect web app. Insight Compliance Report CSV ExportYou can now export a CSV report of your current Insight dashboard view on the Insight dashboard and on
Well hello! Recently, I've been unable to upload Google's Chrome Enterprise PKG into Jamf School without getting the error "Could not parse payloads of product archive". I chatted with Jamf support quickly and it sounds like they know about it as its how Google packages the app but any of their 'solutions' didn't work. If I add it into Composer and try to convert to source I get "Converting to source failed". I am out of ideas so hoping someone else has come across this and figured out a solution.
Hi, we have recently set up a configuration profile for the Azure SSO Extension, and installed Microsoft Authenticator on all devices. - But I cannot verify if it is working or not.When I open Authenticator after enrollment, nothing seems different; I still have to sign in, as if I used it on my private device.What to expect, how is the sign-in procedure? - Or should I be able to see something in Authenticator's settings?I miss a lot of documentation on this.Thanks in advance.
We are trying to find out if there's a way to schedule configuration profiles to be pushed out and pulled back at specific times. Similair to what is done in Jamf Parent.It looks like this feature is available in Jamf School with a 'time filter'? but have not seen this in Jamf Pro. I am aware that there are other ways to accomplish this task via our firewall, and am aware that this feature has been widely reported as unreliable. Was tasked to investigate this feature if available.Thanks all!
Good morning,I am wondering if anyone has any tried and true method for searching for the existence of a file on a specified scope of machines? We are being asked to look for a specific file that would determine if a certain add-on pack is installed for Virtualbox. Any tried and true methods for running a process on a specific list of machines and determining if a file exists?ThanksD
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!