Get Support
Recently active
We had been making use of the Content Caching Module in Jamf School for many years to take pressure off of our Internet, however this is still in beta and has been failing to cache files for some time (I can't be certain of the exact date). I have since uninstalled the Caching module as it does not appear to work anymore and appears to have been installing older settings and profiles on our devices that were cached before the module stopped working.At this time I have configured 2 Mac Minis and an iMac with Content Caching in order to take pressure off our Internet. I would like to make use of the Content Caching module rather as this was more efficient and reliable than the Content Caching feature available on networked Mac OSx devices. Is there any way to speed up the process of fixing this module? The message I have on the module (when enabled) is:Due to recent changes in the macOS system store download process, the Jamf School Content Caching daemon cannot currently deliver pa
Hi,we use the iPad as shared iPad.It can take days or weeks for updates to be completed on all devices. I can see only one reason: the update fails because a user is logged in. For these iPad a "temporary session" is shown. I suspect this is a guest. If I log off this account, then the update succeeds, at least sometimes. But sometimes it does not.Can I configure such an automatic logout in JamfSchool?Are there other reasons why the updates take so long?Best regards,Ralph
Hi AllWe recently enabled Auto-Enrollment on our Jamf Now and started testing our some auto-installed apps. One of the apps we are installing automatically is the Trend AV solution however it seems to keep on failing for some unknown reason. See below Install didFailWithError: Error Domain=PKInstallErrorDomain Code=112 "An error occurred while running scripts from the package “WFBS-SVC_Agent_Installer.pkg”." UserInfo={NSFilePath=./preinstall, NSURL=#tmsecurity.pkg -- file:///var/tmp/TrendMicro/WFBS-SVC_Agent_installer.pkg#Distribution, PKInstallPackageIdentifier=com.trendmicro.tmsm.application.trendMicroSecurity.tmsecurity.pkg, NSLocalizedDescription=An error occurred while running scripts from the package “WFBS-SVC_Agent_Installer.pkg”.}Aslo , /tmp/PKInstallSandbox.taKqhy/Scripts/com.trendmicro.tmsm.application.trendMicroSecurity.tmsecurity.pkg.HMedNp/preinstall: line 261: ./PE_InstallPluginPane: Bad CPU type in executableAny idea how this can be fixed? Note that this a
Hi all, we are trying to finalise a roll-out of Jamf for Mac management, with zero-touch from IT. Devices are enrolled automatically to our Jamf MDM server in Apple Business Manager, and ideally we'd like to send devices directly to users, for them to unbox and run through Jamf Pre-Stage Enrollment.The issue I have seen, maybe one in every 10 builds, is enrollment will not complete correctly. We have a device at the moment that hasn't renamed correctly, hasn't deployed all Enrollment Complete software/policies, and hasn't deployed all config profiles (including FileVault enablement).Running this command locally on the device will essentially re-run enrollment:sudo jamf policy -event enrollmentCompletebut my concern is sending a device to an end-user, the device doesn't enrol correctly, the user tries to work on the device but doesn't have Office apps, or the device doesn't meet security requirements, such as disk encryption.Does anyone have any advice please?Thank you
Hello all,We deploy Xcode Command Line Tools to all mac machines in our org, one issue is having to deal with Xcode CLI updates.When trying to update via command line using softwareupdate, it reports installed, then when checking again they will show back up.Is there a way to update on current macs, or is this just borked?
Is it possible to fully automate the wipe of an Apple Mac Mini?Currently, I have a lab of M1 Mac Mini's, these devices will be used by students in an open lab environment. they are configured in a prestage enrollment that seems to be working fine, but when I click the "wipe computer" button from the management tab of the device, it begins the process to wipe the computer correctly, but, it then stops after is activates the device. I have to physically go acknowledge the activation to move the process along. I'm hoping to find a way to automate this. Then, I have to manually start the os install which I would like to automate this too, and after I start the OS install, the device enrolls successfully, but then stops at the user creation screen, and requires me to create a user. Because this is an open lab environment, at the moment, we do not need to create a new user. I would rather JAMF fill this information for me, then JAMF configure that user to
Hi, I have been asked to look at packaging and deploying Python, with a numver of additional applications - TensorFlow 2, scikit-learn, PyTorch and Matplotlib. These are the only ones for now. Where I am stuck is that I am not unsure how I'd go about doing this. One suggestion is using Anaconda as the Python install and then adding each in its own Virtual Environment. I'm just wondering when to start. Would I potentially install on a reference Mac and then capture as one instance using Composer or could I package/deploy Anaconda and then use individual scripts to install the applications or somehow create individual packages of the applications that can be deployed individually and link into the Anaconda install, independently? If, of course, I am even on the right track here. Our build is macOS Catalina 10.15.7. Thanks for any help or advice.
Hello Everyone,I am still pretty new here so bear with me on this one. Our organization uses binds our Macs to AD and people sign in to create mobile accounts. These accounts have admin privileges but some things are restricted. For example, terminal access on mobile accounts is deactivated. When you open a prompt, the terminal window says "process complete" and doesn't let you enter anything. What kicked this all off is that we recently installed SPSS v. 29 on a machine and noticed that the local Admin account can run it fine but the mobile account cannot. In the local account, we noticed that SPSS launches a few terminal commands to load Java and launch SPSS. We suspect that the mobile account can't launch SPSS b/c the mobile account access to terminal is blocked.In the process of troubleshooting, we used the chmod 777 command on the SPSS folder in Applications to make sure the mobile user had rights to this program. Then we tried a few ways to modify access to Terminal (with a root
I am trying to figure out a Smart Computer group that can see which Macbooks have not registered with AAD yet and need to.The setup guide says to use a group for if the Macbook has the Company Portal app. Which is great for the first run but what happens if user ignore or it fails part way.I have come across this past on an EA, but it seems this should no longer be needed: Solved: Intune Extension Attribute - Jamf Nation Community - 211981I also like this idea but no mention of how the smart group was done: Solved: Jamf policy frequency every hour - Jamf Nation Community - 263626I see the items that Intune adds, such as Computer Azure Active Directory ID, Conditional Access Inventory State and others.But I can't seem to get a group that works to show me Macs that do not have those. It seems to want to filter off a value that would be there versus not existing.Thanks
I've tested with empty packages and our Apps Package, there are no errors, there are also no references to it downloading in the install.log. It will then install during a policy trigger, but when done via prestage enrollment, it just skips over the package.I've run out of ideas.
Many of our users are complaining about MFA fatigue on their Macs. We are a Azure shop and use Microsoft Authenticator. What could be causing the multiple MFA prompts per day all of the sudden and what would a solution be? So far we have thought possibly Jamf Connect is improperly configured. Or potentially adding the "Windows Accounts" Chrome extension since that is a requirement on the PC side. Any thoughts on this issue?
This is probably a dumb question but I have not been able to find an answer.I was requested to remove an App which was purchased by a 3rd party and converted to a "dangerous" app. I am able to get the Bundle ID for the App but not the Name (IE: App Name "Keynote" would be Bundle ID "com.apple.Keynote.") When I type the name of the app in nothing related shows up. As long as I have the Bundle ID, can I substitute my own "App Name" and still have the App Restriction work?
I'd like to set a Configuration Profile or policy on my Mac mini servers to grey out or hide the Sleep, Restart, and Shut Down options on the Apple Menu (login window too, but I think I already know how to do that part). The purpose to this is to force someone to open a Terminal and issue a shut down or restart command which would ensure someone doesn't just click the wrong button. Is there a way to set this? it is for Mavericks 10.9.3. Thank you
Hi all, wondering if you can help, as I am at a loss as to why this is happening. We run jamf connect to sync our passwords with our AD accounts, and it is working fine for everyone except those running Ventura. For those on Ventura, it gives us an error every few hours saying our ldap password is out of sync and we must enter it, but when we try it gives en error on jamf connect: //ping.***.com/as/token.oauth2, ERROR: Unknown error. Message: grant_type is required, STATUS: 400Everything is working fine, we can get on our network shares, use teams and outlook fine, there is absolutely nothing wrong other than this error not disappearing. Has anyone seen this before and if so do you have a fix? I have updated to the latest version of Jamf Connect but that hasn't changed anything.
I'll try to keep this as short as possible folks, promise. I have two issues rearing their heads around the corner:First being that devices that have been enrolled for some time now have suddenly started asking the User to login with Jamf credentials in order to use Self Service. This is happening despite the fact that the mobile device in question has been using Self Service just fine until this point. Second is a device that is showing within School Manager as Supervised and Jamf as Managed, is suddenly denying access to Self Service altogether. For a little bit of background, our team just swapped from on On Prem to Cloud last week. I know it's easy to just say it's an issue that may have occurred during migration but I'm not so easy to jump to that conclusion with confidence. Any ideas and insights as to how to resolve these issues would be greatly appreciated; especially if this continues to pop-up with other devices. Thank you
For some reason, you don't need admin access to install Java games, it just installs a .jar file that you can open. Is there a way to block .jar files from opening?
Hi all, I have a application that is a DMG, and I have a license file that i need to drop into the users application folder. Any suggestions on the best way to deploy this app? I am not sure if using the built in payload in policy would be enough or to use composer? Any guidance appreciated.
How To from Jamf Nation that has pretty much all the info you need to do in Jamf, but since we use Godaddy for our Certificate, there are some extra steps. https://www.jamf.com/jamf-nation/articles/115/enabling-ssl-on-tomcat-with-a-public-certificate All of these Commands should be done on a Mac in Terminal. Open the command prompt or Terminal. Create a folder on your desktop named "Certs" and navigate to the directory using the following commands: mkdir /path/to/Desktop/Certscd /path/to/Desktop/CertsGenerate a Private Key and CSR by executing a command similar to the following: openssl req -out CSR.csr -new -newkey rsa:2048 -nodes -keyout privateKey.keyWhen prompted, enter the appropriate information. The certificate authority (CA) administrator should be able to provide the desired values for these fields. Ensure that you use a fully qualified domain name (FQDN), "[Your Jamf on prem URL]". Note: These values will also be used to generate a self-signed cer
I've seen three different values for FileVault recovery key: valid unknown invalid Valid and unknown are obvious, but how does a key become invalid?
Hi Everyone, We are having a really strange file vault issue here. We have some machines that encrypt with our config, everything looks fine then, out of the blue, the personal recovery will report as invalid and shows as invalid when I check on the client with fdesetup. Then sometimes, it will resolve itself. Ive even compared DB backups to see if the recovery key changes and it stays exactly the same. I hope someone might have some ideas because this could lead to some major issues. Thanks Dave
Hi there,We have some users who needed to run Mojave until recently. We went to upgrade them (all users are remote) and I noticed that every system running Mojave stopped checking in with Jamf on 8/13/22.We disable Admin access for end users and use either the Jamf Admin user or a policy to temporarily perform admin procedures.Unfortunately both of those options are not working (Jamf admin refuses password and zero policies in Self Service will work, they just error out).The last thing I want to do is ship the computers back in and manually wipe them and restore them. Does anyone have a solution for forcing check in on systems that seemed to have dropped off?
Hi all.Anyone have a quick shell script to rename computers by looking up the serial in a CSV file? Figure it should be easy to install a CSV on the computer and then run a script to rename?Of is there another easier way to do this? Why? I duplicated a renaming policy and then didn't remove "all computers" from scope, causing buggered computer names. It would be nice to not have to fix manually.
Retirement of selected ‘Legacy’ definitions. Back in February of 2021 we announced that we would be marking a number of Patch Management definitions as deprecated. This was quickly changed to adding the text of (Legacy Definition) in the publisher column of Patch Management due to the unintended consequence of the ‘Deprecated’ tag. Since that time we had been maintaining the Legacy Definitions in sync with new new replacement definitions, though we have recommended that customers use the ‘newer’ definitions in their Patch Management policies.We have now made the decision to formally deprecate a number of the legacy titles and remove them from the list of available Patch Management titles in Jamf App Catalog. This removal of legacy definitions will happen over time. The first step will be to change the text in the publisher column from ‘Legacy Definition’ to ‘Deprecated Definition’. Whilst the definitions will still be available for a short period of time in Jamf App
Hello!I'm trying to dream up the best method for our SRE team, who maintains our non-IT, product-focused, VPNs... to deploy the various VPN profile files out to all company machines. Without going through IT, so they can work during their normal hours (which are far greater than IT's current hours). And this allows them to manage the VPNs swiftly.They need to deploy a number of .OVPN files to a specific folder on machine. It looks like building a .DMG is a good way to do this if we want to use Jamf... but then I get a little stuck. I see through the API (Jamf docs here, great post here) that I can give the SRE team an API key that empowers them to push that file into our Jamf file repository. But... that still doesn't auto-deploy the file on-the-fly. I assume I could have a policy here, but policies don't deploy the .DMG every time it updates.Anyone have any nifty solutions here?
Hello, My users create shortcut icons on their home screen on the ipads from safari and then need to delete them and are unable to. This restriction seems to be enable as default as other configuration profiles restrictions on different scope are set to allow apps to be deleted and they also can not delete them. Is there a way to look at the global settings that seem to be locking down the configuration profiles?And/Or how do we check/change the ipads as supervised versus unsupervised?Thanks, TMAC
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!