Get Support
Recently active
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 10.44.1 fixes the following product issues: [PI111020] Resolved a Cross-Site Scripting (XSS) issue. [PI111048] An error calculating scope no longer occurs when the scope of an Azure AD group contains 1000 or more users. For additional information on what's included in this release, review the release notes via the new Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 10.44.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. Hosted Region Begins Ends ap-southeast-2 3 March at 1300 UTC 3 March at 2200 UTC ap-northeast-1 3 March at 1400 UTC 4 March at 0000 UTC eu-cen
We use Azure. Azure is mapped to jmaf. When I click on a device I can manually assign an Azure user to it, but when I try and add an Azure user to a static group it says I don't have any users.
Is it possible to only use the Guest account on Business Shared iPad? Not allow any user to log into a managed Apple ID, but allow the use of the Guest account. We still want the Guest account to log in and log out, which will erase the patient data. We just don't want patients logging in with an Apple ID.
We have AD-bound Macs in our Jamf environment. Our AD passwords expire after 90 days. We would like to force the change of the local break glass accounts on the Macs every 90 days, as well. I'm trying to avoid flak from users who might have changed their AD password a couple of days ago.If we deploy a configuration profile that includes the Maximum Password Age set to 90 days (the same as our AD policy), does anyone know if that will conflict with the AD policy?
I have been using Jamf for about 5 months to lock down iPad with Web Clips. Over the past few weeks, I have struggled to get Chrome and Teams pushed out to a group of iPads.First, I logged into the Apple Business manager and Purchase 100 licenses of each.Second, I log into Janf and, on the mobile device apps page, update the apps to Install Automatically, set a scope to target a smart group, and under managed distribution, checked "Assign Content Purchased in Volume Assign" and selected a location. Chrome does install but does not take away from the license count. If I have the device in a locked-down configuration policy, I get "Pending - All licenses are in use or the license is not assigned yet".Have yet to get teams to install, just get "Device was busy. Will try again.", the device is just idle on my desk.Any suggestions?
Hello group, I'm attempting to create a custom ForcePoint ( WebsenseEndpoint ) installer for hosting on Self Service and automated deployment via policy. At present installing ForcePoint is a manual and tedious process that involves installing two separate packages with administrative privileges. These two packages require launching and installation to be done from within the directory that contains the required " ca.cer " , " DLPClientConfig.hsw " and " localConfig.xml " files ( listed below ) .... I've used ForcePoints " WebsenseEndpointPackageBuilder.exe " package builder application on Windows which creates the folder contents listed below, great but still requires manual installation ... Does anyone have any insight or had luck creating a custom package in composer ? I've tried multiple times with little to no luck...Any help would be greatly appreciated. ForcePoint direcoty contents - 1) ca.cer2) DLPClientConfig.hsw3)
Hi everyone,I've almost deployed Crowdstrike successfully on our fleet using Jamf Pro and the documentation available in the Crowdstrike support portal.However, I've found that I'm unable to successfully contain a host when I've deployed Crowdstrike via Jamf. If I deploy Crowdstrike manually without Jamf, the network containment works as expected.Crowdstrike support aren't being their usual helpful selves with this issue.Could someone who has a self-hosted instance of Jamf Pro and has deployed Crowdstrike via Jamf confirm that you can network contain a mac host? Thank you.
While testing ADFS SSO without LDAP integration in my sandbox environment, I discovered only LDAP groups can be used in policy scopes. I'm testing to see if my environment can be made SSO only without LDAP integration but so far, it works fine for Jamf Pro website and device enrollment website but not Self Service if the policy is limited by user group membership. Has anyone else encountered this problem too? I also submitted a feature request at https://ideas.jamf.com/ideas/JN-I-26871 and would like to invite everyone to review it and upvote it if they can.
Hi, We onboard our devices using a walled garden SSID and then deploy the production wi-fi as a configuration profile. Is there a way to set the preference order for the wi-fi networks on iPad Pros so that it uses the production wi-fi normally instead of the onboarding one? From searching the forum, the recommendation is to manually forget the onboarding SSID after everything is set up, but my problem is that these iPads will be locked down into Single App Mode.
Hi, currently we have JAMF Pro integrated into Splunk.We want to see the following logs but the API documentation is not clear on what logs they provide.List of API's: https://developer.jamf.com/jamf-pro/reference/jamf-pro-apiWe want log data that reflects the following activities:JAMF admin loginPermission changesMalicious Software pushExclusion groupsPresence of APIs What is the best way to figure out which API can give us these logs without trying out each API manually and digging through data.
I'm in a little predicament whereby we receive "new user" requests that contain a display name (first and last) and email address (not connected to our Corporate domain) which is followed (once approved) by a Jamf enrollment invitation sent to said email address.Once the enrollment (of a device of which we currently have no information) is complete our process dictates that we continue to create email account and other app accounts for the new user.I'm using webhooks (computerAdded, and computerCheckin trigger=enrollmentComplete) to try to kick off the second part of the process, however I currently can't think of a way to link the enrolled computer to the invitation. I don't have the computer serial number from the request, and the local username won't necessarily equal what we will create for the user.I know I can see enrolled computers from the computerinvitations.html page in the Jamf console. Can I get this via the API?
Hi Everyone, With the announcement of the latest zero day, how is everyone going about upgrading there fleet? I have a policy to delay MacOS Minor Version for 30Days, Would that not delay our users receving this new update? or does enabling the box "Allow devices to install Rapid Security Responses (macOS 13 or later) " allow this to happen? Curious to know how everyone else is handling it. Worse case scenario I can remove the Delay 30 days policy upgrade and put the 30 days back into place.
Hi, Just wondering if there is a way to do 802.1x to Wifi using Jamf in System Mode System Mode: Used for computer authentication and occurs even when a user isn’t logged in to the Mac See https://support.apple.com/en-au/guide/deployment-reference-macos/apd7b6d34790/web I have it configured currently to a different mode to those listed – we have a machine cert provided by Active Directory, A CA cert for the directory and a ICA cert for the directory. In addition I have a Wifi Config profile that forces the machine to use WPA 2 Enterprise as the security and EAP-TLS as the protocol for a particular SSID that the 802.1x is enabled on. With the way I have it set up, the connection works but only when the user logs in. The Network Team is asking if I can make it connect before logon so that new users can use the machine (they are all AD connected)
Today, we released a new feature: Removable Storage Controls Jamf Protect administrators can now manage or prevent the use of removable storage devices to protect against accidental data loss and unauthorized access. For example, USB devices can be restricted or allowed based upon encryption status, vendor ID, product ID or device serial number. Administrators can configure Removable Storage Control Sets to apply increasingly granular rules applied to all removable storage devices, as well as allow use of specific devices with optional overrides. End users will see a popup alert if they attempt to connect a restricted device. For more about Removable Storage Controls, see https://docs.jamf.com/jamf-protect/documentation/Removable_Storage_Controls.html. Note: This feature is only available for computers with macOS 10.15 or later. Also included in this release is agent 3.2.0, which resolves the following:Users can no longer uninstall Jamf Protect from c
We got some problems a way back when enrolling devices. We only get the MDM Profile, nothing more. Normally you should get about 8 to 15 profiles depending who you are and where you work. Anybody have any idea what causes this problem? For one week ago we moved to Jamf Cloud and I thought the problem should disappear, but it didn't.
Hey, So I work with a security minded company, who generally in the past has been burned by cloud services (we have around 1600 corp employees). We are looking at Jamf for our growing Mac population. I'm curious for those that run on prem, how do you like it? Any regrets from not going cloud based? What was your selling point to be on prem vs cloud? Just trying to get some information on all angles before we go to deeply into things. Any information or tips are appreciated.
I have used the documents tool to upload an Excel file to our managed iPads. I set the right group so that the file should be uploaded to every device we have.I did this yesterday. When I checked in just now I saw that there was no upload to the devices. I took one iPad and checked it. No sign of the document anywhere.The activity protocol of the device showed the following error message (in german):"Die Mobile Device Management-Anfrage ist ungültig." wich translates to MDM request is void. Any ideas here on how to solve this issue?
Trying to spin up an on-prem trial and have been receiving the attached database error accessing the JSS portal via browser. 8443, 3306, 8080 ports are open. I've verified MySQL, Tomcat, Java, Jamf CLI tools are all installed and running. I've run through all the troubleshooting presented in the error. I've googled like a mad man, have tried many possible MySQL fixes with no luck. Has anyone seen this before? I ran through mostly manual steps for setting it up including tomcat. Then I ran the Jamfproinstaller.run file which also configures tomcat. Could that cause an issue if tomcat is already configured on the host? Any help is greatly appreciated.
When wiping iPads and selecting the option to clear the Activation Lock on ADE iPads, the device wipes as normal, but then users are prompted to enter the organization's Apple ID to unlock the device. The recorded bypass code in Jamf Pro still works, but I cannot figure out why it keeps failing to clear it. Server logs show this error message (serial has been removed): 2022-08-29 02:59:03,208 [ERROR] [ina-exec-45] [ActivationLockService ] - Failed to clear activation lock for (SERIAL). ActivationLockResponse [status=404, message=Device not found or activation lock bypass is invalid.] Is anyone else experiencing this problem or know what could be causing it? It's happening on multiple iPads.
The previous jamf guy disabled this feature, but now our CTO wants that feature enabled. Teachers and staff members would use their already existing district username and password as their apple id.Would this be a new config profile that would have to be created? Any input would be greatly appreciated.
I have been using the bellow command to perform updates from 13 to 13.01, to 13.1, to 13.2, to 13.2.1. What I have noticed and I might be wrong, is, instead of downloading the update installer which is generally less than 3Gb in size, it downloads the entire installer which is 13Gb. Users with slow internet connection at their homes generally get errors. How do make it so that it only downloads the update file and not the full installer? /Library/Management/erase-install/erase-install.sh --reinstall --version=13.2.1 --update --current-user --depnotify --cleanup-after-use
Hi all,I've had a look through previous posts, but most are dated 2021/2022, so I was just wondering if anyone has any recent solutions?We would like to enforce MacOS updates on our Silicon Macs, but we don't want to issue Remote Commands that will reboot devices with no user notification.Is there any viable method for ensuring Macs are on a specific OS and, if they're not, will notify the user and then begin downloading/installing the update after X days?Thanks in advance
I'm working on getting my companies Jamf instance onto Jamf Connect so we can move to zero-touch provisioning (I currently spend much of my week setting up devices which is silly). As a part of this, I'm messing around with PreStage Enrollments to get a better understanding of how those work. I noticed the PreStage has a payload for Configuration Profiles and Packages, but in our own current PreStage, as well as any examples I've seen, there are never any Configuration Profiles included. Why might this be?Right now we have all of our configuration profiles set to configure after enrollment (which is when Setup Assistant completes?). Is this the best way to do that? Why would the PreStage Enrollment have a Configuration Profiles section if none are typically used. Or should that be filled with profiles all devices will get?
Today we are releasing Jamf Pro 10.44. Highlights of this release include: End User Notifications for App Installers You can now customize push notifications to end users when an App Installer package has an available update and the app is open on the user's computer. Customizing these notifications will override any default notification settings in the App Installer package for a given software title. OS Update Reporting Jamf Pro now provides additional functionality, transparency, and reporting capabilities for managed software updates by MDM commands for both computers and mobile devices. The new Operating System category located within the Management tab displays the latest in-progress status report on managed updates to your devices. You can view the status of current updates, the number of user deferrals remaining, install action taken, and the next and past install notification dates. Additionally, the new Operating System History category within the History tab displays a recor
On our lab computers, we've diabled iCloud sign in, as students sign in using their Okta credentials via Jamf Connect and we typically don't want them junking up the computers with their personal iCloud stuff. We have a fair number of students with their own personal iPads and Apple Pencils, and they'd like to use those devices with the lab computers, but Apple requires both devices to be signed into iCloud with the same ID. I know I can re-enable iCloud sign in, but that seems like it opens up the computer to being "owned" by anyone who signs in and also allows iCloud syncing, which we don't want.So, my question is are there any established models for loosing up the restrictions enough to allow Sidecar?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!