Get Support
Recently active
I'm trying to automate our deployment process using Jira webhooks and the Jamf API and webhooks.I want to generate a unique invitation URL when a user is added using our existing Jira workflow.Jira (fully approved) > Webhook to cloud function > Call Jamf API computerinvitations and send to user > Jamf webhook on computer added to site > cloud function to complete user setup. The docs for the computerinvitations endpoint are sparse (https://developer.jamf.com/jamf-pro/reference/computerinvitations). My particular question is related to the XML payload i need to pass in the request body. There is a sample in the docs, however I'm wondering what of this sample is required/mandatory and what is optional?For instance the SSH user/password and some other details are set at the org level in settings in "User-initiated enrollment". Also when setting the site in the XML payload, the invitation info in the portal does not show the site i set in the payload. Any help is appr
I have an app that sometimes can be problematic and will require a removal of the app off the iPad and then reinstall. It seems that currently when using the Self Service App, and tapping on "Reinstall" it does simply that reinstall overtop of the app. I need to have Home Screen Layouts configured on these devices because I hide all apps minus a handful that I require and a few of the default apps. These iPads are quite locked down and I am hoping there is a good solid way to have this accomplished where Self Service will do a remove and reinstall.
In doing some testing today I've uncovered a rather odd situation. In our environment, our computers flow in via DEP, through a prestage that creates a hidden local admin account. This is the same prestage we've always used since we started using JAMF. It seems the correct location for a hidden admin account home is /private/var. I'm not sure if this is correct or not, but reading on the community I believe it to be correct. For a hidden admin account called JSSAdmin, you'd obviously have the home folder as /private/var/JSSAdmin.This has not been my experience in the past. Up until I'd say Big Sur, our hidden admin account has always resided in the /Users directory. I noticed in doing some testing for Big Sur that the admin account had moved to /private/var. I assumed this was a change from Apple and moved on. Fast forward to today, and it seems like there's more going on. I have a machine I enrolled a month ago that has the admin account in /Users, and I h
We are looking into Digital Signage but we have an immediate need to be able to display a welcome type message on an AppleTV while offline. So if there a way to configure an AppleTV while online then have it display some type of custom welcome message on a TV while offline? We're looking at Carousel for Digital Signage but looking to get something for next week so not sure if I can get everything working with Carousel in that time. Any recommendations appreciated.
Hello,We are moving MacOS units from JSS to Cloud. 1) Tried the JAMF Migrator tool. Moved Computers first, seemed to be working but not seeing the result in the Cloud instance. 2) Testing to move Static groups after, not working as the JAMF Migrator does not seem to pick up any (none show in the box), nothing moves. Version 7.1.2 3) I was reading the suggested moving order is Devices, Smart Groups, Policies. Anything else to add or that I may be missing? Anything to ensure we do after these have moved? 4) I was reading JAMF provides a Re-Enroll feat. Is this something I can download or JAMF provides? Thank you,
Hi, Does anyone have a DN script with a solution to the above?? TIA
Hello All, I was looking for the best way to set homepage and start up page set for Safari and Firefox browsers through JAMF. I am able to do it for Google Chrome through a JSON file and config profile, but JSON is not working for both Safari and Firefox, please help me to do it.
Hi I am failry new to Jamf. we have devices that are not checked it (mostly its because the users got it at home)do we need to go to Jamf in cloud to be able to manage these Macs?
Hello Anyone could help me on this? Iooks like it needs user intervention before the installation will proceed anyway to bypass it? or any known fix on this? i tried several commands and im still stucked on this one. Thank you very much for your usual assistance.
This command works from the Terminal when I activate my Admin button beforehand:#sh /Applications/Zscaler/.Uninstaller.shAnd then it prompts the password. If I enter:#sh /Applications/Zscaler/.Uninstaller.sh <password>And put in the actual password, it will go straight to uninstalling it, but only from the Terminal.If I put this same script in a Jamf policy, it won't push. I'll hit my sync button and it will fail. Has anyone figured this out before? Thanks.I followed the instructions here already: Uninstalling Zscaler Client Connector | Zscaler
I'm using ASM as the user truth.Interestingly, as we switch to the new year I see a range of student user records that flip to manual. (It's most likely because those who leave the school are still assigned a device at this point, so if they disappear from ASM they can't yet be removed from Jamf School).However, there isn't a Filter option to be able to see just those records that are manual (or ASM).Sure, I can sort the list by Source but it would be more efficient to have a filter. It is currently cumbersome to clean up student records in the following year. I've run into the issue where I do have two user records for the same person - one from ASM and one manually.
Newbie MDM user here. Signed up for Jamf Now and have 6 iPhone 14's being managed for work. The iPhones are not signed into an iCloud account. What is the best/easiest way to push a managed list of contacts to the phones?
Leverage MDM-delivered Configuration Profiles and a custom Bash script for dynamic, yet consistent Sensor Grouping Tags in CrowdStrike FalconBackgroundAs we’ve considered deploying CrowdStrike Falcon on macOS, we’ve wanted to leverage Sensor Grouping Tags in a way which was dynamic, yet consistent across our fleet.However, learning about any new software product also includes learning about its limitations.Yet another job for system engineers.Continue reading …
Since I migrated Jamf to a Windows 2019 server two weeks ago, I have been troubleshooting the primary distribution point. The distribution point and jamf server are running on the same VM. I have tried and failed with https, probably because of the same root cause... so I am trying to simplify the issue by first troubleshooting the SMB dist point problem.I am able to mount the share both from Windows and Mac clients using the jamf service accounts. I have been able to validate that the accounts work as-should... one read-only, the other read-write. I don't know what the jamf binary and jamf admin do differently to mount the distribution point, but both fail without any helpful messages.I'm wondering if any of you have had a similar experience, and whether you have been able to locate your root cause and resolve. I have a packet capture out to Jamf support right now. I have been working with them for two weeks without resolution. I just re-built my Jamf server a second time with the sam
Does anyone know of a way to join a WiFi connection before a user logs in? We have a situation in which our users travel quite frequently, so when a password reset policy has to be pushed due to a forgotten password, they are unable to pick up the policy. We're hoping there is some way we can have them join a wireless network from the login screen from wherever they are working.
Hi,I’m hoping someone can help.I went to renew my push certificate, but on logging into Apple the original one isn’t there - don’t know why.Anyway, my issue is that my push certificate is now expired and can’t be renewed and now my iOS devices aren’t reachable via push and when I went to wipe them with Configurator 2 they’re showing as locked so I can’t do that either.My installed profile isn’t user removable and doesn’t allow for wiping from the device.so far I’m stuck with 60 odd unusable iPads - any help would be greatly appreciated.thank you in advance
Is there any way to invoke a forced update of user information from LDAP with out the device needing to be check in?we have status of our users directly maped in our user details of AD which is imported through ldap, and updates overnight providing the device is checking in, if the device doesn't checkin this information never updates, putting critical information which we leverage in the MDM for app and setting distribution etc. But also helps us insure the statistics of things are accurate due to the status information we map into fields like room and department and phone of the users ldap which.I have used API to update MacBook information before, however I am trying to workout how I can force this process that occurs nightly with devices check in, without their need to check in, so that stale devices are showing the correct status of our users, or at the very least, collect the user assigned to the device, and leverage this against a CSV to update the fields through a manual csv.Fo
Worked this out with @rtrouton based on both his installation script as well as the one located at cobbservations.wordpress.com Wanted to offer Xcode 8 (requires OS X 10.11.5 or later) to our user population via Self Service. Downloaded the Xcode 8 installation package from the App Store using the App Store Capture Methodology (yes, VPP would be better), described at: https://derflounder.wordpress.com/2013/10/19/downloading-microsofts-remote-desktop-installer-package-from-the-app-store/ Added the 4.43GB installation package to the JSS, created a Self Service policy to install it, and used this script below (set to Run After) to handle all of the post-installation processing (so that users are not prompted for admin credentials). You may want to customize the script for your environment (we don't disable the Gatekeeper validation, and our users are already developers, nor do we have multiple versions of Xcode installed, so those line-items are disabled, but it's your call): #!/bin/
Hello, recently I've been asked to take over Jamf due to losing our Jamf admin at my work.I already have a little experience with Linux and Bash scripting but the administration of the tool is what I need to learn.Any suggestions on what resources would help me learn Jamf, outside of Jamf themselves?
I am looking at building a script for an Extension Attribute for Falcon | Crowdstrike with the desired result:Read the CID of an installed Falcon Sensor Compare the CID to one of two Pushed by the JSSOne CID falls in 'Complete' - Managed by Falcon Complete TeamOne CID falls in 'Lite' - AV/ED/Reporting/Remediation functions only; which is managed by our team/department.Upon comparison - output either 'Lite' or 'Complete' to the extension attribute based on the CID detected on the client/endpoint.I have found many of the other Crowdstrike EA's that folks have put out; but have not run across any that are able to complete a process as I've described above.Any ideas or food for thought anyone can think of to help me kick it off/get started on it? Possible existing resources I can use to build off of?
I was asked today to "audit" app deployments at one of our buildings. Is there a way to search our app database by the building scope? Otherwise I have to grab a device from that building, and copy a text list of apps in scope to a word document or something since there's no export either.
We've finally got approval to transition to the Jamf Cloud when our contract renews at the end of September. I'd really like to start fresh and run an enrollment package on existing devices to not carry over the bloat from our current JSS and make sure only active Macs get registered. We have 905 Macs in our inventory, but only 797 have checked in within the last 90 days (what we consider to be active). Being charged per-device, I want to get a true look at our numbers when we move over. I would also like to clean up some of the inventory data and only track what is absolutely necessary and not all the extension attributes that we have now. I know Jamf offers a day long migration with them, but I'm wondering what people have done when they migrated. My main questions are: Is there any advantage to just essentially copying/pasting the existing DB and then trying to clean up that? Does re-enrolling devices bring the FileVault recovery key over, or would I have to run a
I just noticed that the PRINTERS section of the computer inventory is missing. Has anyone else noticed this?How are we supposed to now see what printers are installed on a mac?version: 10.42.1-t1667311080
The previous jamf guy disabled this feature, but now our CTO wants that feature enabled. Teachers and staff members would use their already existing district username and password as their apple id.Would this be a new config profile that would have to be created? Any input would be greatly appreciated.
Customer Education is excited to share our first Jamf Pro Release Notes video!Join us for an overview of some of the new features and enhancements that are available in Jamf Pro 10.44. We hope this new resource provides additional details to support your use of the features in this release.Once you’re done reviewing it, we’d love to get your feedback. Feel free to leave a comment and let us what you liked and how we can make it even better next time.We look forward to hearing from you!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!