Get Support
Recently active
Trying to spin up an on-prem trial and have been receiving the attached database error accessing the JSS portal via browser. 8443, 3306, 8080 ports are open. I've verified MySQL, Tomcat, Java, Jamf CLI tools are all installed and running. I've run through all the troubleshooting presented in the error. I've googled like a mad man, have tried many possible MySQL fixes with no luck. Has anyone seen this before? I ran through mostly manual steps for setting it up including tomcat. Then I ran the Jamfproinstaller.run file which also configures tomcat. Could that cause an issue if tomcat is already configured on the host? Any help is greatly appreciated.
When wiping iPads and selecting the option to clear the Activation Lock on ADE iPads, the device wipes as normal, but then users are prompted to enter the organization's Apple ID to unlock the device. The recorded bypass code in Jamf Pro still works, but I cannot figure out why it keeps failing to clear it. Server logs show this error message (serial has been removed): 2022-08-29 02:59:03,208 [ERROR] [ina-exec-45] [ActivationLockService ] - Failed to clear activation lock for (SERIAL). ActivationLockResponse [status=404, message=Device not found or activation lock bypass is invalid.] Is anyone else experiencing this problem or know what could be causing it? It's happening on multiple iPads.
The previous jamf guy disabled this feature, but now our CTO wants that feature enabled. Teachers and staff members would use their already existing district username and password as their apple id.Would this be a new config profile that would have to be created? Any input would be greatly appreciated.
I have been using the bellow command to perform updates from 13 to 13.01, to 13.1, to 13.2, to 13.2.1. What I have noticed and I might be wrong, is, instead of downloading the update installer which is generally less than 3Gb in size, it downloads the entire installer which is 13Gb. Users with slow internet connection at their homes generally get errors. How do make it so that it only downloads the update file and not the full installer? /Library/Management/erase-install/erase-install.sh --reinstall --version=13.2.1 --update --current-user --depnotify --cleanup-after-use
Hi all,I've had a look through previous posts, but most are dated 2021/2022, so I was just wondering if anyone has any recent solutions?We would like to enforce MacOS updates on our Silicon Macs, but we don't want to issue Remote Commands that will reboot devices with no user notification.Is there any viable method for ensuring Macs are on a specific OS and, if they're not, will notify the user and then begin downloading/installing the update after X days?Thanks in advance
I'm working on getting my companies Jamf instance onto Jamf Connect so we can move to zero-touch provisioning (I currently spend much of my week setting up devices which is silly). As a part of this, I'm messing around with PreStage Enrollments to get a better understanding of how those work. I noticed the PreStage has a payload for Configuration Profiles and Packages, but in our own current PreStage, as well as any examples I've seen, there are never any Configuration Profiles included. Why might this be?Right now we have all of our configuration profiles set to configure after enrollment (which is when Setup Assistant completes?). Is this the best way to do that? Why would the PreStage Enrollment have a Configuration Profiles section if none are typically used. Or should that be filled with profiles all devices will get?
Today we are releasing Jamf Pro 10.44. Highlights of this release include: End User Notifications for App Installers You can now customize push notifications to end users when an App Installer package has an available update and the app is open on the user's computer. Customizing these notifications will override any default notification settings in the App Installer package for a given software title. OS Update Reporting Jamf Pro now provides additional functionality, transparency, and reporting capabilities for managed software updates by MDM commands for both computers and mobile devices. The new Operating System category located within the Management tab displays the latest in-progress status report on managed updates to your devices. You can view the status of current updates, the number of user deferrals remaining, install action taken, and the next and past install notification dates. Additionally, the new Operating System History category within the History tab displays a recor
On our lab computers, we've diabled iCloud sign in, as students sign in using their Okta credentials via Jamf Connect and we typically don't want them junking up the computers with their personal iCloud stuff. We have a fair number of students with their own personal iPads and Apple Pencils, and they'd like to use those devices with the lab computers, but Apple requires both devices to be signed into iCloud with the same ID. I know I can re-enable iCloud sign in, but that seems like it opens up the computer to being "owned" by anyone who signs in and also allows iCloud syncing, which we don't want.So, my question is are there any established models for loosing up the restrictions enough to allow Sidecar?
This seems like it should be easy but I'll be darned if I can find an answer.We have site level technology coordinators at each of our schools. We've also set it up that site level coordinators only have access to assets at their site. Our issue is that any time a device changes hands and is erased, the site tech people can't have the new user enroll without one of the global admins first moving the device location back to the top level. Even if the new user is at the same site as the previous user. I'm assuming there's a setting someplace that I can't seem to locate but I'm hopeful someone here can give me a hand.
I'm in a little predicament whereby we receive "new user" requests that contain a display name (first and last) and email address (not connected to our Corporate domain) which is followed (once approved) by a Jamf enrollment invitation sent to said email address.Once the enrollment (of a device of which we currently have no information) is complete our process dictates that we continue to create email account and other app accounts for the new user.I'm using webhooks (computerAdded, and computerCheckin trigger=enrollmentComplete) to try to kick off the second part of the process, however I currently can't think of a way to link the enrolled computer to the invitation. I don't have the computer serial number from the request, and the local username won't necessarily equal what we will create for the user.I know I can see enrolled computers from the computerinvitations.html page in the Jamf console. Can I get this via the API?
Hello, since Ventura is now beyond it's 90 day deferral, is there anyway we can have those users still on Monterey upgrade to the latest security patch 12.6.3 within Monterey? We have used OSUpdateNotifier script in the past and used minor/major flags however the default update showing within System Preferences is now Ventura, not Monterey update.Curious how other orgs are proceeding with security only updates at this point.
Is there a way to get all of our LDAP users into the Jamf Users section? We have a Jamf Infrastructure Manager with the LDAP proxy set up, and it can search for users and find them from the test, but I can't see anyplace to import the users that we will be assigning devices and software to.
We use OpenDNS Umbrella client for web filtering on some student machines. Brief background info is that we have 2 DNS servers that are pushed out via DHCP (the DNS servers are the IP of the OpenDNS HA servers that allow web access). I've found a few students manually adding DNS servers like 8.8.8.8 etc to avoid using these pushed DNS servers. Looking for a way to lock the DNS tab of any service in Network preferences and then if I can get that to work, clear out any manual entries that may have been added. Locking the Network Preferences pane will probably not be an option, I'm hoping to go a little deeper.
Our config has a JIM server and LDAP connection to Azure AD. We leverage this only to require user authentication on enrollment to prefill the username etc for local account creation. I'm looking into using LDAP groups to give access to certain apps in policy scope as this is how it is done on the Windows side of things in SCCM.However, we DO have Okta and that is our primary IDP at this point so my question is should I even keep the LDAP and JIM integration around when I can leverage Okta to pull user data.... especially if using LDAP groups is not best practice in Jamf.
So, as I've expanded the testing of our Jamf on-prem to Jamf Cloud migration out to our "friends and family" in IT, I ran across an issue where the jamf removeMDMprofile command removed the profiles, but the device still would not perform ADE at reboot. (device loaded in ABM, assigned to our Jamf Cloud, and assigned a PreStage Enrollment)Creating a throw-away account in order to get through Setup Assistant and perform additional troubleshooting, we found the device still reported it was configured to look for our on-prem, per the output of the jamf checkJSSConnection command. manually running jamf deleteSetupDone and jamf removeFramework, followed by a reboot allowed the ADE process to perform properly on this device.Should I modify my script to check the output of this command for this potential state (and perform a removeFramework), or just change to use the jamf removeFramework command instead of (or after removeMdmProfile) for all users instead? Obviously I lose
According to Jamf documentation the user bypass code is only collected when a user has activation locked a device."Bypass code to use when Activation Lock is enabled by the user—This bypass code is collected if the device supports Activation Lock and the end user has enabled it."https://learn.jamf.com/en-US/bundle/technical-articles/page/Leveraging_Apples_Activation_Lock_Feature_with_Jamf_Pro.html This is not the case. All our devices regardless have a user based bypass code (along with device based) even if the user has not activation locked. This makes it confusing on what code should be used.I do have an activation lock status search which shows all of the devices as NO (Yes means personal apple ID locked). But not sure I can even trust that.
I am just curious if anyone has figured out a workaround for the issue with adding additional storage to existing Managed Apple IDs. I feel like this new strong arm tactic of only making it possible if you use their business essentials platform is ridiculous. We have too many devices to use the product and we are already using Jamf Pro. There is absolutely no reason for use to need a switch other than the iCloud storage situation.
Firstly, apologies if this is the wrong place to ask this question. I am a recently new admin to macOS and using JAMF (6mos now). We are being tasked with deploying ThousandEyes to our mac environment and I am having some challenges getting the package to deploy and register itself properly. Manually installing the TE agent and using our company registration file works flawlessly. I can run a sudo "/Applications/ThousandEyes Endpoint Agent.app/Contents/MacOS/te-agent" --applyconfig "/Applications/ThousandEyes Endpoint Agent.app/installation-config.te-endpoint-agent" after running the .pkg and the agent shows up in our TE console within just a few minutes. However, all my attempts to add it to jamf and deploy the package are just outright failing. I've followed through this TE Thread with no luck. Attempts:add .pkg directly to jamf, run script after to load the 'installation-config' - failedusing composer repackaged the .pkg with the 'installation-con
Hi allWe have installed latest version of jamf pro on a new virtual machine. The server was running fine so when we decided to restore it, after the database restore we get this message. The source is a mac mini and OS is big sur v11.6.8 and is running jamf pro 10.27.0 and server tools 2.7.7.Target is a VMware virtual machine and OS is ubuntu 22.04.2 and is running jamf pro 10.43.1 and server tools 2.7.14.Is it because the database version is an older version?appreciate any help.
Hello Jamf Community,I work with a University. In our department we run Mac labs that act as classrooms for a large variety of classes that are reserved daily. We are redesigning our Mac classroom "build" primarily with Jamf Pro. The biggest hurdle that we face is in determining a user account and maintenance method that meets the needs of our classrooms.Needs we have:Fast turn around times, 4 classrooms of 30 computers with a 15-minute gap between different classes -- and essentially 3-4 minutes per room to get every computer rebooted and ready for the next classThe previous team that designed our current system had disabled SIP in order to develop a user template that was copied over the existing user account that is used by students upon login with a login-hook. This happens upon restart (initiated by Apple Remote Desktop) and the user is auto-logged in. That worked fine for many years, but some systems have broken upon OS 12 Monterrey (the computers fail to complete 'optimization')
Hello everyone,I am still in the evaluation phase of JamfPro. While testing, I came across a question about whether the devices on which you want to perform Secure Erase must also be registered in the Apple Business Manager, or whether you only need to register devices in Jamf Pro to perform a Secure Erase. Devices that are already in use can only be registered in the Apple Business Manager if you completely erase them. This would not be feasible for my colleagues, so I would want to avoid registering in the Apple Business Manager. Therefore, it is important to know whether self-enrollment in Jamf Pro is sufficient for Secure Erase.Here a screenshot:Does 'Wipe Computer' in JamfPro perform a secure erase of the entire hard drive (i.e., the Secure Erase command built into macOS), or does it simply delete data from the device?Best regardsFloh
Hey everyone,Having an issue with jamf app catalog installations. Some machines just seem to randomly not want to install the app. These machines are very similar, it's a computer lab, but one machine will install successfully and its neighbor will fail.My question is how do I investigate this further plus all I see in the console is that it failed with no real information and also has anyone else experienced this and was able to fix it
Hi, Does anyone have a link to the latest list of Installers available?T.I.A
Hey there,is there a possibility to display an extension attribute either separately at another place or to hide the attribute and make it visible by mouse click? It is about the fact that we have a script in use that implements LAPS - so assigns a local admin password and stores it in an attribute for emergencies. But I don't want this to be visible directly, but that you have to click on it first to make it visible, at least similar to the recovery key. Is that possible?Thanks in advance,Michael
I Have been tasked with creating documentation on how our Jamfcloud.com is currently setup. So our first thought to find a way to print the pages from the bowser. Because of all the iframe going on I cannot find a way to print an entire page - or even just the frame from top to bottom. I really do not want to create 2 dozen screen shots and more for every policy and config.Looking for ideas.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!