Get Support
Recently active
Hi - I have inherited a Jamf Pro environment with 1118 packages and 700-800 policies - maybe around 35% are actually being used. What is the best way (or some ways) to figure out what can be deleted and what can't? Is there a best-practice way to delete packages and policies?Similarly, there are around 550 computers that are probably out of service but still in Jamf. What is the best way to figure out which computers can be deleted and which can't? Is there a best-practice way to do something that will temporarily remove them so that I'm not exceeding my device count while I figure out if they indeed have been removed from service and can be deleted from Jamf?Thanks, --Jeff
We seem to have an issue with the configuration of our Jamf Connect.We are using the connection with Azure to create our users.Some Macs login with the Jamf Connect window, but some show the native MacOS window with 3 buttons. This last is not desired, since most of our users do not know their Local User account.The native MacOS login window only appears after a reboot. When the Mac sleeps, it pops up with the desired login window (the one with the user icon).The thing is that this does not happen on all our Macs. Out of about 30 Mac, this has happened once on a M1 13" pro running Monterrey and this week on 2 new M2Pro 16" machines.Our configuration has not changes, since we onboarded to Jamf last October.I am sure we are doing something wrong here, but I have no idea where to start looking. Hopefully someone can point me in the right direction.
I need some help in figuring out how to disable the TouchID feature on the new MacBook Pro for now. In testing we found that it's been causing some AD lockout issues, and since we want to deploy these Macs before the 12.2.3 hits that suppose to fix this - I figured it would be easier to just disable the TouchID option for now and enable it later. So, I fired up Composer and told it to snapshot both new and modified files and proceeded to disable the TouchID for unlocking the machine (the other two options wouldn't work anyway since we don't allow iCloud access). I then checked the files, and none of them seem to be related to the touchID feature. I'm assuming there is some plist file out there that keeps track of the options the user chooses. Ideally I'd like to lock that down with the options turned off, and then hide the touchID and Wallet system panel. Any ideas? Anyone else having these issues?
Hi All,I'm new to Jamf pro and heard about the re-enrollment. However, I got a question that if we delete the entry of the device rather than enabled the re-enrollment option. What makes the difference? Kindly help me to understand. Thanks.
Hello,Is it possible to prevent iPad users to remove JAMF profiles from their devices? iPads are enrolled through AC2 (not DEP). Users are able to reach the profile under their iPad settings and simply click "Remove profile". This is causing huge constrains in managing our iPad fleet.Thanks!
Morning!I'm currently trialing Jamf School. Want to test how to use Google authentication during enrollment. I believe I have everything set up: Built Google API Console Project, created credentials, added redirect URIs, copy and saved client ID/secret, then added all that into Jamf School under Authentication method.On iPads I'm using for trial, I wiped and reset. iPad went through enrollment easily enough. But I expected to come up on a Google sign in page which needed authentication. But nothing shows up. Just normal enrollment steps.My questions - What should I be expecting? How can I use Jamf School and Google in a 1-1 iPad setting? Thanks!- Kevin
Hello Jamf Nation, We would like to provide advanced notice that for the Jamf 300 and Jamf 400 Courses beginning on or after 1st September 2023, we will no longer accept certifications earned on Version 9 of Jamf Pro, previously the Casper Suite, to be used as prerequisites for training course enrollment. This applies to the Casper Certified Tech, Casper Certified Admin, and Casper Certified Expert certifications issued prior to the release of Jamf Pro version 10 in November 2017. The Jamf 200 Course prerequisites remain unchanged, where we continue to strongly recommend students complete the free, online Jamf 100 Course before attending. This change also does not affect the Jamf 370 Course, where we continue to accept any Version 10 issued certification as a prerequisite. Since the release of Version 10, we have all experienced five major macOS releases and forty-four Jamf Pro version updates. Furthermore, key concepts such as Patch Management, Device
Right now we use a certificate to join our district school devices to WiFi. This is delivered via a config profile with the network settings and the certificates. When the certificate is getting ready to expire we deploy a new config with the new certificate. All works fine till we try to remove the old network settings and certificate from the machine - we lose network. is there a way around this?
I am starting to use Self Service to push out Office Updates (primary concern), Flash player updates, run RUM to update CS 6 installs...pretty much all updates (even Apple Software Updates soon). I do this by promoting the updates through a series of smart groups. Is there any good way to notify a logged in user that they have new Self Service items waiting? So far I'm having no luck with scripting a decent solution.
Hey Jamf Nation! We've just released Jamf Pro 10.45.0 Beta. This release includes new features and enhancements including Google BeyondCorp Enterprise integration enhancements, Failover Login URL Update for single sign-on Integrations, App Installers deployment improvements and much more. How to join the beta: We’ve also made some changes to the Beta enrollment process with our new Jamf Nation platform. Please enroll in the Beta Program under Product Feedback at account.jamf.com. Once you’re enrolled you’ll see a link to the Beta Forum. There will be a short delay between enrollment and Jamf Nation beta forum access - you will receive a notification in Jamf Nation to join the beta forum. Once you receive the invitation click on "Join this group Hub" to access the forum. If you have any questions please email beta@jamf.com. As always, the beta program is operated under non-disclosure, so please do not share any information regarding
I'm attempting to create a Smart Group for "desktop Macs." We have a number of different iMacs and minis in our environment. But it appears I have to choose from predefined models (e.g., "Model IS iMac Intel (21.5-Inch, Late 2015) OR Model IS iMac Intel (21.5-inch, Mid 2017)," etc., in order to start seeing the Smart Group get populated.I was hoping/expecting to be able to construct criteria such as "Model LIKE 'iMac' OR Model LIKE 'Macmini' OR Model Like 'MacPro'" since the official Model Identifiers under the hood all use such strings, and they're unique enough across product lines. That way it wouldn't matter what exact iMac or mini models I've got in our environment, and don't have to add new Model criteria when, say, the M3 minis start showing up at some point.I don't think I'm missing anything obvious, but it wouldn't be the first time something escaped my eye.
I'm trying to get a smart computer group running to check for Java/java version. I can't seem to get it working. I use the script below in an Extension Attribute and have the group set for "is not" Java 8 Update 131 build 11 Any ideas? #!/bin/sh version=`defaults read /Library/Internet Plug-Ins/JavaAppletPlugin.plugin/Contents/Info CFBundleShortVersionString` echo "$version"
Hi gang,I'm trying to accomplish two things with Self Service. One policy will open Google Drive (this I have working in my script) followed by launching the location in a new Finder window upon clicking (ie: //Users/$loggedInUser/Google\\ Drive/Shared\\ drives/) for when people tell me "they lost their Google Drive." This new finder window is the piece that is not working. My error says location does not exist even though it does. So sounds like a permissions error?For my next trick I want to have a policy that opens a PDF file stored on a shared Google Drive.I have tried lots of ways to script this which all work locally for me fine but not when calling the policy through JAMF. I'm thinking permissions here too. Maybe a PPPC that I need to allowed Files and Folders access to JAMF or something else?Thanks!
Hey JAMF People! Our management is wanting to have iPads come out of the box with the Free (Pages, Numbers, Keynote, iMovie, GarageBand,) removed from the iPad and made available only in Self-service. Looking for some suggestions. I'm pretty sure if we set-up a restriction for those apps, they would not be able to downloaded from Self-Service? They would just be forever restricted right? If they wipe the device using a JAMF reset or we wipe it with MDM reset it does not reinstall them, but it is adding an extra set to our "enrollment" work flow. These are kindergarten student iPads so it's been deemed too much to ask them to remove the apps themselves. I guess the TLDR is there a way to remove an iPad app once, but not restrict it so it can be downloaded later through Jamf Self-Service? Too bad you can't just "rm -rf" on an iPad right?
Both CIS and Tenable provide a configuration profile method to undo any hot corner set to disable screen saver.CIS uses <≠6>Tenable uses <!=6>Neither seem to work. Anyone have any luck with this?
hi all,Jamf just spin off 1 free dev sandbox for me and i am looking to copy everything from my production jamf pro cloud to this cloud dev sandbox using jamf migrator. I am new to github - so can anyone help me on how to use Jamf Migrator in github (https://github.com/jamf/JamfMigrator)?I download the zip code and extract it but could not find any apps inside
tl;dr: I want to write a script to monitor the log JAMF generates when executing a policy.We are deploying macOS updates by pushing the installer version we want down, then executing "/Applications/Install macOS Monterey.app/Contents/Resources/startosinstall" --agreetolicense in the Files & Processes policy module. The problem with this method is that there is no feedback shown to the user to provide the status/progress. I'm going to write a script to use in combination with Octory & octory-notifier to display the current progress. I'd like to use the policy log output as it is generated, and monitor it with less -f -n0|grep... to trigger whatever update I want in Octory.Is it possible to monitor the policy log as it's generated?
Hello,Can anyone get Google Chrome to install from the Jamf App Catalog? I have three different Macs, and it doesn't work on any of them. I get the error "Unqualified for App Installer" on all three. I am deploying Microsoft Teams the same way, which works perfectly without any issues. I've tried many things and continue to get the same error. Thanks in advance for any help!Steve
In the olden days (Catalina and prior) we used the Software Update option to let users install any Apple software updates available (this doesn't include upgrades like 10.15 to 11.x, but just 10.15.x to 10.15.x+). But obviously this doesn't work now with Monterey (apparently).I'm aware of configuration policies to force updates down onto machines, but we can't do that. We're a 24/7 organization with users in every time zone, and many do not have Silicon Valley quality internet (literally leasing lines from sheep herders in some countries or using mobile satellite terminals with bandwidth measure in KB not MB or GB). So we've trained the users to run the update regularly from our self service portal.I've tried using the Files and Processes with... softwareupdate -iaR...but that doesn't even seem to work for Monterey.Any suggestions? Can't use a caching server, as sometimes these are the only users of ours in a location. Maybe a policy to cache the update and then install but they s
Hello Everyone,We have a department paying for a language interpretation service that comes with a corresponding iOS app (LanguageLine Insight). Currently we have the iOS app set to automatically install on all devices for that department, and if anyone in that department wants to use the app they must contact the department administrator for the authentication (license) code. They chose not to have us configure the auth code into the app during deployment for unknown reasons.Other departments have shown interest in this app so we are now looking at purchasing a site license for everyone to use. In order to facilitate easier billing for each department, the company is going to provide unique authentication codes for each department. The department heads however have shown interest in having the authentication codes pushed out with the app.The app itself does not support this feature. It supports a single authentication code during deployment only. My question is, can I simply add multi
We had a massive issue where all Mac's all the sudden stopped working in Self Service. When a user tried to run a policy from the SS it would fail after 1-2 sec, we created a support case that ended up taking more than 2 weeks to find the issue. We removed all configuration profiles, all policies, and all installed programs - the issue was still there.Just wanted to make a post about this so if someone else has this issue this might be the solution.We where using Jamf's JIM a while back, about 8 months ago we closed down that server but forgot to remove the configuration from Jamf Pro. The Self Service issue started about 1 month ago so therefore we didn't connect JIM and the SS problem.After removing all JIM configuration from our Jamf Pro SS started working again. Ticket number: CS0915102
Setup Your Mac (1.7.0) benefits from the latest swiftDialog 2.1 features and easily allows Mac Admins to specify a minimum OS version to help mitigate zero-day attacksIntroductionApple’s Automated Device Enrollment helps streamline Mobile Device Management (MDM) enrollment and device Supervision during activation, enabling IT to manage enterprise devices with “zero touch.”Setup Your Mac aims to simplify initial device configuration by leveraging swiftDialog and Jamf Pro Policy Custom Events to allow end-users to self-complete Mac setup post-enrollment.Continue reading …
I am setting up Nudge to be deployed via the Jamf App Catalog to facilitate keeping it up to date, but it does not appear to be installing the LaunchAgent even though the listing says it will 1) is this (or should it even be) the intended behavior? 2) Who manages the Jamf App Catalog entries? Honestly, I think having a separate Nudge Launch Agent in the App Catalog may be better (in order to Balance the ease of Auto-Updates and deployments vs managing the Agent separately if that is also wanted)
Here is the script I am currently using. I would like to convert it to Jamfhelper so I can use a logo which using the below console output workflow does not allow. Does anyone know how to convert this to use jamfhelper? #!/bin/bashuser=`/bin/ls -l /dev/console | /usr/bin/awk '{ print $3 }'`#get User IDuid=$(id -u "$user")#Display a message to the user and if they click OK it will open the Self Service Policy#Message I want to Display- Make labels in JamfmessageToDisplay="$4"policyIDtoExecute="$5"policyAction="$6"#This will use a here doc MUST PUT ENTER/RETURN AFTER EOF#EOF is an example. You can use ANY word.. IE SHUTTLECOCKbuttonClicked=$(launchctl asuser "$uid" /usr/bin/osascript << EOFbutton returned of (display dialog "$messageToDisplay" buttons {"Delay Upgrade", "Upgrade"} default button 1)EOF)echo "$buttonClicked"# For paramter six we are going to view or executeif [[ "$buttonClicked" == "Upgrade" ]];then/bin/launchctl asuser "$uid" /usr/bin/open "jamfselfservice
I have been trying to get a script working that will run jamf Helper and if the user agrees to the upgrade it will open Self Service at the policy and either view or install the app. So far I have the below which works. #!/bin/zsh ### msg="$4 $singleApp " singleApp="$5" jamfHelper="/Library/Application Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper" currentuser=$(stat -f "%Su" /dev/console) policyid="$6" action="$7" timeout="$8" title="Application Update" iconLoc="/private/var/tva/casper/scripts/mickey.png" userResponse=`$jamfHelper -windowType utility -title "$title" -description "$msg" -icon $iconLoc -button1 "Dismiss" -button2 "Upgrade Now" -defaultButton 0 -cancelButton 1 -countdown $timeout -timeout $timeout` #Self Service = 2 #OK = 0 if [[ $userResponse = "2" ]]; then su "$currentuser&
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!