Get Support
Recently active
On Mojave, we deploy (lab) iMac using "kcpassword" method that auto login to an account upon enrolment completion which then runs DEPNotify to complete/start the initial setup. That same setup is not working for Catalina. Any help would be appreciated.
Hi All,I'm trying to use this script to determine if a Mac's uptime is 5 days or longer, then output results as "Yes" if so, and "No" if not. But when configured as an EA, it only gives the "No" result. What am I missing?#!/bin/bash# Get the system uptime in secondsuptime_seconds=$(awk '{print $1}' /proc/uptime)# Calculate the uptime in daysuptime_days=$(echo "$uptime_seconds/86400" | bc)# Check if the uptime is greater than or equal to 5 daysif [ $uptime_days -ge 5 ]; thenresult="Yes"elseresult="No"fi# Output the result in the correct format for Jamf Proecho "<result>$result</result>"
We have 150 managed iPads that are booked out on a lesson by lesson basis across school and we have 8 periods a day. When students sign out of their device the user profile remains, and at the end of the day we have to delete every user profile on Jamf (via management command) to free up disk space, otherwise lessons will be impacted the following day. The shared iPad settings are set to ‘number of users = 8’. Also, students sometimes forget to sign out so we have to log them out as well.This is very frustrating as there isn't a blanket command for all devices to 'delete user profiles' and 'log out users' which would be a much more effective method for managing shared devices and way less time consuming.
What is your opinion of Jamf? Do you like it? Do you hate it? What is its biggest weakness? Where does it excel? Who does Apple like most between Intune, Airwatch, and Tanium? How do end users benefit from Jamf over other support options? Pros and Cons. Who is better than Jamf?Interviewing for a position at my company and I am tasked with presenting Jamf. Specifically, I had the option to pick between W365, Tanium, and Jamf as my presentation.Any help would be greatly appreciated. I have enjoyed my research into the company so far and hope to get some real-world feedback from those who live it.Thanks in advance.
Hi All, I've been doing a lot of research on 802.1X certificates as we are looking to move away from AD-binding and move to a software such as JAMF Connect in the very near future. This has brought many challenges while researching, and I think I've just made myself more confused in the process. I'm a novice with networking, so please bear with me on that. Here is essentially what I need to do: I need to have some way to authenticate with the network at the login window on non-bound machines. I've read that using a machine-based certificate with distribution via SCEP is the way-to-go in this scenario, which is fine at the logon window.Our security policies require that we have user-based authentication when a person is actively using a machine. So if John Smith logs in, John Smith's credentials need to be used to authenticate against the network, not the machine-certificate used at the logon window. I read in Apple's documentation that you can use a Syst
A lot of my enrolled macs are not updating the user field. Its random but its really an inconvenience to have to update them manually.any command out there to update users and location field? when the field is not populated? My macs get named after user ID. We run a script to rename them and bind to AD based on LDAP userID.Again this is random as some work and others dont. Dont even know where to begin to look as to why.Im running latest but this happened before on all versions 9.x
Hi Everyone,I am wondering if its possible to allocating 5-10Gbs of storage of an device, to be allowed to used for updates,Thanks
Hello everyone, I want to send an "Advanced Computer Searches" result to another team using Power Automate.Whatever I do, the email body doesn’t show the result I want “mac address” Outlook result: Any idea ?
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 10.44.1 fixes the following product issues: [PI111020] Resolved a Cross-Site Scripting (XSS) issue. [PI111048] An error calculating scope no longer occurs when the scope of an Azure AD group contains 1000 or more users. For additional information on what's included in this release, review the release notes via the new Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 10.44.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. Hosted Region Begins Ends ap-southeast-2 3 March at 1300 UTC 3 March at 2200 UTC ap-northeast-1 3 March at 1400 UTC 4 March at 0000 UTC eu-cen
We use Azure. Azure is mapped to jmaf. When I click on a device I can manually assign an Azure user to it, but when I try and add an Azure user to a static group it says I don't have any users.
Is it possible to only use the Guest account on Business Shared iPad? Not allow any user to log into a managed Apple ID, but allow the use of the Guest account. We still want the Guest account to log in and log out, which will erase the patient data. We just don't want patients logging in with an Apple ID.
We have AD-bound Macs in our Jamf environment. Our AD passwords expire after 90 days. We would like to force the change of the local break glass accounts on the Macs every 90 days, as well. I'm trying to avoid flak from users who might have changed their AD password a couple of days ago.If we deploy a configuration profile that includes the Maximum Password Age set to 90 days (the same as our AD policy), does anyone know if that will conflict with the AD policy?
I have been using Jamf for about 5 months to lock down iPad with Web Clips. Over the past few weeks, I have struggled to get Chrome and Teams pushed out to a group of iPads.First, I logged into the Apple Business manager and Purchase 100 licenses of each.Second, I log into Janf and, on the mobile device apps page, update the apps to Install Automatically, set a scope to target a smart group, and under managed distribution, checked "Assign Content Purchased in Volume Assign" and selected a location. Chrome does install but does not take away from the license count. If I have the device in a locked-down configuration policy, I get "Pending - All licenses are in use or the license is not assigned yet".Have yet to get teams to install, just get "Device was busy. Will try again.", the device is just idle on my desk.Any suggestions?
Hello group, I'm attempting to create a custom ForcePoint ( WebsenseEndpoint ) installer for hosting on Self Service and automated deployment via policy. At present installing ForcePoint is a manual and tedious process that involves installing two separate packages with administrative privileges. These two packages require launching and installation to be done from within the directory that contains the required " ca.cer " , " DLPClientConfig.hsw " and " localConfig.xml " files ( listed below ) .... I've used ForcePoints " WebsenseEndpointPackageBuilder.exe " package builder application on Windows which creates the folder contents listed below, great but still requires manual installation ... Does anyone have any insight or had luck creating a custom package in composer ? I've tried multiple times with little to no luck...Any help would be greatly appreciated. ForcePoint direcoty contents - 1) ca.cer2) DLPClientConfig.hsw3)
Hi everyone,I've almost deployed Crowdstrike successfully on our fleet using Jamf Pro and the documentation available in the Crowdstrike support portal.However, I've found that I'm unable to successfully contain a host when I've deployed Crowdstrike via Jamf. If I deploy Crowdstrike manually without Jamf, the network containment works as expected.Crowdstrike support aren't being their usual helpful selves with this issue.Could someone who has a self-hosted instance of Jamf Pro and has deployed Crowdstrike via Jamf confirm that you can network contain a mac host? Thank you.
While testing ADFS SSO without LDAP integration in my sandbox environment, I discovered only LDAP groups can be used in policy scopes. I'm testing to see if my environment can be made SSO only without LDAP integration but so far, it works fine for Jamf Pro website and device enrollment website but not Self Service if the policy is limited by user group membership. Has anyone else encountered this problem too? I also submitted a feature request at https://ideas.jamf.com/ideas/JN-I-26871 and would like to invite everyone to review it and upvote it if they can.
Hi, We onboard our devices using a walled garden SSID and then deploy the production wi-fi as a configuration profile. Is there a way to set the preference order for the wi-fi networks on iPad Pros so that it uses the production wi-fi normally instead of the onboarding one? From searching the forum, the recommendation is to manually forget the onboarding SSID after everything is set up, but my problem is that these iPads will be locked down into Single App Mode.
Hi, currently we have JAMF Pro integrated into Splunk.We want to see the following logs but the API documentation is not clear on what logs they provide.List of API's: https://developer.jamf.com/jamf-pro/reference/jamf-pro-apiWe want log data that reflects the following activities:JAMF admin loginPermission changesMalicious Software pushExclusion groupsPresence of APIs What is the best way to figure out which API can give us these logs without trying out each API manually and digging through data.
I'm in a little predicament whereby we receive "new user" requests that contain a display name (first and last) and email address (not connected to our Corporate domain) which is followed (once approved) by a Jamf enrollment invitation sent to said email address.Once the enrollment (of a device of which we currently have no information) is complete our process dictates that we continue to create email account and other app accounts for the new user.I'm using webhooks (computerAdded, and computerCheckin trigger=enrollmentComplete) to try to kick off the second part of the process, however I currently can't think of a way to link the enrolled computer to the invitation. I don't have the computer serial number from the request, and the local username won't necessarily equal what we will create for the user.I know I can see enrolled computers from the computerinvitations.html page in the Jamf console. Can I get this via the API?
Hi Everyone, With the announcement of the latest zero day, how is everyone going about upgrading there fleet? I have a policy to delay MacOS Minor Version for 30Days, Would that not delay our users receving this new update? or does enabling the box "Allow devices to install Rapid Security Responses (macOS 13 or later) " allow this to happen? Curious to know how everyone else is handling it. Worse case scenario I can remove the Delay 30 days policy upgrade and put the 30 days back into place.
Hi, Just wondering if there is a way to do 802.1x to Wifi using Jamf in System Mode System Mode: Used for computer authentication and occurs even when a user isn’t logged in to the Mac See https://support.apple.com/en-au/guide/deployment-reference-macos/apd7b6d34790/web I have it configured currently to a different mode to those listed – we have a machine cert provided by Active Directory, A CA cert for the directory and a ICA cert for the directory. In addition I have a Wifi Config profile that forces the machine to use WPA 2 Enterprise as the security and EAP-TLS as the protocol for a particular SSID that the 802.1x is enabled on. With the way I have it set up, the connection works but only when the user logs in. The Network Team is asking if I can make it connect before logon so that new users can use the machine (they are all AD connected)
Today, we released a new feature: Removable Storage Controls Jamf Protect administrators can now manage or prevent the use of removable storage devices to protect against accidental data loss and unauthorized access. For example, USB devices can be restricted or allowed based upon encryption status, vendor ID, product ID or device serial number. Administrators can configure Removable Storage Control Sets to apply increasingly granular rules applied to all removable storage devices, as well as allow use of specific devices with optional overrides. End users will see a popup alert if they attempt to connect a restricted device. For more about Removable Storage Controls, see https://docs.jamf.com/jamf-protect/documentation/Removable_Storage_Controls.html. Note: This feature is only available for computers with macOS 10.15 or later. Also included in this release is agent 3.2.0, which resolves the following:Users can no longer uninstall Jamf Protect from c
We got some problems a way back when enrolling devices. We only get the MDM Profile, nothing more. Normally you should get about 8 to 15 profiles depending who you are and where you work. Anybody have any idea what causes this problem? For one week ago we moved to Jamf Cloud and I thought the problem should disappear, but it didn't.
Hey, So I work with a security minded company, who generally in the past has been burned by cloud services (we have around 1600 corp employees). We are looking at Jamf for our growing Mac population. I'm curious for those that run on prem, how do you like it? Any regrets from not going cloud based? What was your selling point to be on prem vs cloud? Just trying to get some information on all angles before we go to deeply into things. Any information or tips are appreciated.
I have used the documents tool to upload an Excel file to our managed iPads. I set the right group so that the file should be uploaded to every device we have.I did this yesterday. When I checked in just now I saw that there was no upload to the devices. I took one iPad and checked it. No sign of the document anywhere.The activity protocol of the device showed the following error message (in german):"Die Mobile Device Management-Anfrage ist ungültig." wich translates to MDM request is void. Any ideas here on how to solve this issue?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!