Get Support
Recently active
I have an iPhone 6 that is passed around to people who travel on behalf of our school. I just received it back from someone and wiped it out. Now during the setup at the Remote Management screen, it says the configuration could not be downloaded. Cancelled. It was originally enrolled in DEP with Apple Configurator 2 and added to Pre-Stage Enrollment with no problem. Is this a certificate issue?
Hi folks,I support a Fire Department and there's an iPhone assigned to each Company Officer. So the phone is not assigned to an individual but instead a whole crew. That crew is on a four shift rotation so from day to day, the person possessing the phone changes.So, the phones are basically used as kiosk devices- no Apple ID, no personal logins, no email, no messaging, just our organizational apps, and as a calling device. There are times when it would be useful to be able to send an email to a particular device, regardless of who is using it that day. And it would be useful to be able to receive mail from the user of the device if they take a picture in the field or a screen shot of something.Has anyone come up with a decent working process where devices can be used as user agnostic kiosk type devices, but also be able to send and receive email from the device? I've thought about creating accounts for each device, but then you throw in password management or MFA and things get complic
Hi,Just wondering if anyone has any guidance or advice for renewing external certs on jamf pro to our iPads. The way i'm thinking is to push out the new certs as separate configuration profiles and wait till they're deployed alongside the current profile. Then just removing the older cert once the new ones installed? Can't think of any other way of doing it but just wanting to see if anyone else had an opinion on this? Thanks,Paul
Hi all, I hope everyone had a great Christmas and New years? So we are in the middle a project to change our MDM provider from Mosyle to JAMF and Identity management from Jump Cloud to Okta. Now I am quite new to MDM solutions at least at this level (mostly apple based company I am at) so they went with an MDM solution over trying to use AD joining and such (I have managed a small number via Intune) But mostly I have been in Windows based companies with AD/SCCM imaging type set ups. So after looking trough the community I struggled to find anyone posting a similar question to me. My question is has anyone done the same moving from Mosyle to JAMF recently and how did you go about transitioning the machines (removing current profiles and un enrolling etc.) from Mosyle and then enrolling via JAMF? We will be using JAMF pro if that helps :) Thanks in advance
Hello everyone,I am having a problem where I need to block access to a specific Google Site on our school iPads. When I add the URL to the blocklist, it blocks ALL Google Sites. When I try to allowlist a different Google Site it apparently differs to the more restricitive and blocks access anyway. I am assuming it is blocking the root (https://sites.google.com) and not allowing anything past the lead in (https://sites.google.com/coolschoolstuff.com) <-made up URL for this example.Anybody have a solution?Thank you!
So, this is pretty straight forward for Jamf Pro, but I can't seem to figure out how to apply a custom icon to an in-house package deployed via Jamf School Self Service. Am I missing something obvious? Thanks!
I created buildings in my Jamf Pro instance, and then I created Device Smart Groups where the criteria is “Building..is…[select ellipsis to chose the building from the list of buildings]”.I created 20 Device Smart Groups with this criteria, and all but three have populated correctly. I have Prestages where I have selected the Building in the drop-down menu in the User & Location to be added to all devices in that Prestage. I have confirmed that the building has populated correctly in the inventory records for these devices.I’m so confused, I used the same process for the other groups and they populated just fine. Has anyone else come across this before?
Just curious if anybody has seen this. I've tried this at work and on my home wifi. When I go to run the 12.6.3 update, I'll get the network error. I'll try it 2 more times and then the update just goes away, but it eventually shows back up. This is happening on a bunch of Mac's on different networks. At the time I did it, I did check and there weren't any apple server issues. We do have a couple of security tools installed that could affect it, but there are some devices that can run it.
Hi all,Is anyone using super and running into errors when trying to apply updates on Apple Silicon Macs?The API keeps failing for me while waiting for the MDM command, ScheduleOSUpdateScan, to return a response. It auto times-out after 5 minutes. If I check the computer's record in Jamf I can see the command, but it sits in a Pending state for more than 10-15 minutes.Has anyone else run into this issue?
At initial launch, AC 1.7.4 launches a dialog box requesting the user to accept a license agreement. After acceptance, the dialog box is never seen again. I am trying to script the installation of this application and I have not yet figured out how to suppress this dialog box. I have used both fseventer and Composer to try to isolate the file and I have performed a "defaults read ~/Library/Containers/com.apple.configurator/Data/Library/Preferences/com.apple.configurator.plist" but I am not finding any clues. I would appreciate any guidance or clues. Thanks!
We've been having some sporadic Mac devices lose items/icons in their menu bar and both Chrome and Slack (main tools in the company) open but do not load anything. Just spinning wheel. Also Privacy & Security in System Prefs (Settings) would not load either. The devices still were connected to their wifi and could use Safari to browse the web. This has happened to about 5 users out of 45 macos devices.This started happening a few of weeks to our fleet after enrolling into Jamf. Trouble shooting included rebooting, shutting down, entering safe mode. Nothing in activity Monitor was taking up resources as the Mac was idle. I checked logs on all the devices and initially believed from the install.log's that it was a softwareupdate running in the background so i deactivated deffered updates and auto updates.With the last user, experiencing all these symptoms, i was able to get some time to dig further. We use Jamf Compliance Editor to upload plists and compliances to CIS Level 1 +
Hello, we where able to deploy a self signed certificate via JAMF configuration profile using the certificate manager. Unfortunately the certificate is not set to trust. I can set it to trust via command line but I would need to find a way to deploy the certificate file to the macbook laptop then run a trust command via script. Unfortunately there seem to be no documented way to do this. How can I achieve my goal. How can I deploy a self signed certificate and tell all our jamf computers to always trust that certificate.
Hello Jamf Nation! We recently released Jamf Protect 4.0.0 which includes significant enhancements to how analytics are managed, standardized versioning for the Endpoint Threat Prevention database, new accessibility theme options, and the ability to export a CSV report of your Insight Compliance Report dashboard. Analytic SetsAnalytic Set enhancements include an updated Analytics screen, and an improved workflow for managing groups of analytics and associating the analytic sets with plans. For more information, see Jamf Protect Analytics. Endpoint Threat Prevention Database VersioningThe threat database versioning has been standardized across all customers to improve version visibility and reporting. New Accessibility Theme OptionsAdditional accessibility theme options have been added to the user menu in the upper-right of the Jamf Protect web app. Insight Compliance Report CSV ExportYou can now export a CSV report of your current Insight dashboard view on the Insight dashboard and on
Well hello! Recently, I've been unable to upload Google's Chrome Enterprise PKG into Jamf School without getting the error "Could not parse payloads of product archive". I chatted with Jamf support quickly and it sounds like they know about it as its how Google packages the app but any of their 'solutions' didn't work. If I add it into Composer and try to convert to source I get "Converting to source failed". I am out of ideas so hoping someone else has come across this and figured out a solution.
Hi, we have recently set up a configuration profile for the Azure SSO Extension, and installed Microsoft Authenticator on all devices. - But I cannot verify if it is working or not.When I open Authenticator after enrollment, nothing seems different; I still have to sign in, as if I used it on my private device.What to expect, how is the sign-in procedure? - Or should I be able to see something in Authenticator's settings?I miss a lot of documentation on this.Thanks in advance.
We are trying to find out if there's a way to schedule configuration profiles to be pushed out and pulled back at specific times. Similair to what is done in Jamf Parent.It looks like this feature is available in Jamf School with a 'time filter'? but have not seen this in Jamf Pro. I am aware that there are other ways to accomplish this task via our firewall, and am aware that this feature has been widely reported as unreliable. Was tasked to investigate this feature if available.Thanks all!
Good morning,I am wondering if anyone has any tried and true method for searching for the existence of a file on a specified scope of machines? We are being asked to look for a specific file that would determine if a certain add-on pack is installed for Virtualbox. Any tried and true methods for running a process on a specific list of machines and determining if a file exists?ThanksD
We had been making use of the Content Caching Module in Jamf School for many years to take pressure off of our Internet, however this is still in beta and has been failing to cache files for some time (I can't be certain of the exact date). I have since uninstalled the Caching module as it does not appear to work anymore and appears to have been installing older settings and profiles on our devices that were cached before the module stopped working.At this time I have configured 2 Mac Minis and an iMac with Content Caching in order to take pressure off our Internet. I would like to make use of the Content Caching module rather as this was more efficient and reliable than the Content Caching feature available on networked Mac OSx devices. Is there any way to speed up the process of fixing this module? The message I have on the module (when enabled) is:Due to recent changes in the macOS system store download process, the Jamf School Content Caching daemon cannot currently deliver pa
Hi,we use the iPad as shared iPad.It can take days or weeks for updates to be completed on all devices. I can see only one reason: the update fails because a user is logged in. For these iPad a "temporary session" is shown. I suspect this is a guest. If I log off this account, then the update succeeds, at least sometimes. But sometimes it does not.Can I configure such an automatic logout in JamfSchool?Are there other reasons why the updates take so long?Best regards,Ralph
Hi AllWe recently enabled Auto-Enrollment on our Jamf Now and started testing our some auto-installed apps. One of the apps we are installing automatically is the Trend AV solution however it seems to keep on failing for some unknown reason. See below Install didFailWithError: Error Domain=PKInstallErrorDomain Code=112 "An error occurred while running scripts from the package “WFBS-SVC_Agent_Installer.pkg”." UserInfo={NSFilePath=./preinstall, NSURL=#tmsecurity.pkg -- file:///var/tmp/TrendMicro/WFBS-SVC_Agent_installer.pkg#Distribution, PKInstallPackageIdentifier=com.trendmicro.tmsm.application.trendMicroSecurity.tmsecurity.pkg, NSLocalizedDescription=An error occurred while running scripts from the package “WFBS-SVC_Agent_Installer.pkg”.}Aslo , /tmp/PKInstallSandbox.taKqhy/Scripts/com.trendmicro.tmsm.application.trendMicroSecurity.tmsecurity.pkg.HMedNp/preinstall: line 261: ./PE_InstallPluginPane: Bad CPU type in executableAny idea how this can be fixed? Note that this a
Hi all, we are trying to finalise a roll-out of Jamf for Mac management, with zero-touch from IT. Devices are enrolled automatically to our Jamf MDM server in Apple Business Manager, and ideally we'd like to send devices directly to users, for them to unbox and run through Jamf Pre-Stage Enrollment.The issue I have seen, maybe one in every 10 builds, is enrollment will not complete correctly. We have a device at the moment that hasn't renamed correctly, hasn't deployed all Enrollment Complete software/policies, and hasn't deployed all config profiles (including FileVault enablement).Running this command locally on the device will essentially re-run enrollment:sudo jamf policy -event enrollmentCompletebut my concern is sending a device to an end-user, the device doesn't enrol correctly, the user tries to work on the device but doesn't have Office apps, or the device doesn't meet security requirements, such as disk encryption.Does anyone have any advice please?Thank you
Hello all,We deploy Xcode Command Line Tools to all mac machines in our org, one issue is having to deal with Xcode CLI updates.When trying to update via command line using softwareupdate, it reports installed, then when checking again they will show back up.Is there a way to update on current macs, or is this just borked?
Is it possible to fully automate the wipe of an Apple Mac Mini?Currently, I have a lab of M1 Mac Mini's, these devices will be used by students in an open lab environment. they are configured in a prestage enrollment that seems to be working fine, but when I click the "wipe computer" button from the management tab of the device, it begins the process to wipe the computer correctly, but, it then stops after is activates the device. I have to physically go acknowledge the activation to move the process along. I'm hoping to find a way to automate this. Then, I have to manually start the os install which I would like to automate this too, and after I start the OS install, the device enrolls successfully, but then stops at the user creation screen, and requires me to create a user. Because this is an open lab environment, at the moment, we do not need to create a new user. I would rather JAMF fill this information for me, then JAMF configure that user to
Hi, I have been asked to look at packaging and deploying Python, with a numver of additional applications - TensorFlow 2, scikit-learn, PyTorch and Matplotlib. These are the only ones for now. Where I am stuck is that I am not unsure how I'd go about doing this. One suggestion is using Anaconda as the Python install and then adding each in its own Virtual Environment. I'm just wondering when to start. Would I potentially install on a reference Mac and then capture as one instance using Composer or could I package/deploy Anaconda and then use individual scripts to install the applications or somehow create individual packages of the applications that can be deployed individually and link into the Anaconda install, independently? If, of course, I am even on the right track here. Our build is macOS Catalina 10.15.7. Thanks for any help or advice.
Hello Everyone,I am still pretty new here so bear with me on this one. Our organization uses binds our Macs to AD and people sign in to create mobile accounts. These accounts have admin privileges but some things are restricted. For example, terminal access on mobile accounts is deactivated. When you open a prompt, the terminal window says "process complete" and doesn't let you enter anything. What kicked this all off is that we recently installed SPSS v. 29 on a machine and noticed that the local Admin account can run it fine but the mobile account cannot. In the local account, we noticed that SPSS launches a few terminal commands to load Java and launch SPSS. We suspect that the mobile account can't launch SPSS b/c the mobile account access to terminal is blocked.In the process of troubleshooting, we used the chmod 777 command on the SPSS folder in Applications to make sure the mobile user had rights to this program. Then we tried a few ways to modify access to Terminal (with a root
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!