Get Support
Recently active
This seems like it should be easy but I'll be darned if I can find an answer.We have site level technology coordinators at each of our schools. We've also set it up that site level coordinators only have access to assets at their site. Our issue is that any time a device changes hands and is erased, the site tech people can't have the new user enroll without one of the global admins first moving the device location back to the top level. Even if the new user is at the same site as the previous user. I'm assuming there's a setting someplace that I can't seem to locate but I'm hopeful someone here can give me a hand.
I'm in a little predicament whereby we receive "new user" requests that contain a display name (first and last) and email address (not connected to our Corporate domain) which is followed (once approved) by a Jamf enrollment invitation sent to said email address.Once the enrollment (of a device of which we currently have no information) is complete our process dictates that we continue to create email account and other app accounts for the new user.I'm using webhooks (computerAdded, and computerCheckin trigger=enrollmentComplete) to try to kick off the second part of the process, however I currently can't think of a way to link the enrolled computer to the invitation. I don't have the computer serial number from the request, and the local username won't necessarily equal what we will create for the user.I know I can see enrolled computers from the computerinvitations.html page in the Jamf console. Can I get this via the API?
Hello, since Ventura is now beyond it's 90 day deferral, is there anyway we can have those users still on Monterey upgrade to the latest security patch 12.6.3 within Monterey? We have used OSUpdateNotifier script in the past and used minor/major flags however the default update showing within System Preferences is now Ventura, not Monterey update.Curious how other orgs are proceeding with security only updates at this point.
Is there a way to get all of our LDAP users into the Jamf Users section? We have a Jamf Infrastructure Manager with the LDAP proxy set up, and it can search for users and find them from the test, but I can't see anyplace to import the users that we will be assigning devices and software to.
We use OpenDNS Umbrella client for web filtering on some student machines. Brief background info is that we have 2 DNS servers that are pushed out via DHCP (the DNS servers are the IP of the OpenDNS HA servers that allow web access). I've found a few students manually adding DNS servers like 8.8.8.8 etc to avoid using these pushed DNS servers. Looking for a way to lock the DNS tab of any service in Network preferences and then if I can get that to work, clear out any manual entries that may have been added. Locking the Network Preferences pane will probably not be an option, I'm hoping to go a little deeper.
Our config has a JIM server and LDAP connection to Azure AD. We leverage this only to require user authentication on enrollment to prefill the username etc for local account creation. I'm looking into using LDAP groups to give access to certain apps in policy scope as this is how it is done on the Windows side of things in SCCM.However, we DO have Okta and that is our primary IDP at this point so my question is should I even keep the LDAP and JIM integration around when I can leverage Okta to pull user data.... especially if using LDAP groups is not best practice in Jamf.
So, as I've expanded the testing of our Jamf on-prem to Jamf Cloud migration out to our "friends and family" in IT, I ran across an issue where the jamf removeMDMprofile command removed the profiles, but the device still would not perform ADE at reboot. (device loaded in ABM, assigned to our Jamf Cloud, and assigned a PreStage Enrollment)Creating a throw-away account in order to get through Setup Assistant and perform additional troubleshooting, we found the device still reported it was configured to look for our on-prem, per the output of the jamf checkJSSConnection command. manually running jamf deleteSetupDone and jamf removeFramework, followed by a reboot allowed the ADE process to perform properly on this device.Should I modify my script to check the output of this command for this potential state (and perform a removeFramework), or just change to use the jamf removeFramework command instead of (or after removeMdmProfile) for all users instead? Obviously I lose
According to Jamf documentation the user bypass code is only collected when a user has activation locked a device."Bypass code to use when Activation Lock is enabled by the user—This bypass code is collected if the device supports Activation Lock and the end user has enabled it."https://learn.jamf.com/en-US/bundle/technical-articles/page/Leveraging_Apples_Activation_Lock_Feature_with_Jamf_Pro.html This is not the case. All our devices regardless have a user based bypass code (along with device based) even if the user has not activation locked. This makes it confusing on what code should be used.I do have an activation lock status search which shows all of the devices as NO (Yes means personal apple ID locked). But not sure I can even trust that.
I am just curious if anyone has figured out a workaround for the issue with adding additional storage to existing Managed Apple IDs. I feel like this new strong arm tactic of only making it possible if you use their business essentials platform is ridiculous. We have too many devices to use the product and we are already using Jamf Pro. There is absolutely no reason for use to need a switch other than the iCloud storage situation.
Firstly, apologies if this is the wrong place to ask this question. I am a recently new admin to macOS and using JAMF (6mos now). We are being tasked with deploying ThousandEyes to our mac environment and I am having some challenges getting the package to deploy and register itself properly. Manually installing the TE agent and using our company registration file works flawlessly. I can run a sudo "/Applications/ThousandEyes Endpoint Agent.app/Contents/MacOS/te-agent" --applyconfig "/Applications/ThousandEyes Endpoint Agent.app/installation-config.te-endpoint-agent" after running the .pkg and the agent shows up in our TE console within just a few minutes. However, all my attempts to add it to jamf and deploy the package are just outright failing. I've followed through this TE Thread with no luck. Attempts:add .pkg directly to jamf, run script after to load the 'installation-config' - failedusing composer repackaged the .pkg with the 'installation-con
Hi allWe have installed latest version of jamf pro on a new virtual machine. The server was running fine so when we decided to restore it, after the database restore we get this message. The source is a mac mini and OS is big sur v11.6.8 and is running jamf pro 10.27.0 and server tools 2.7.7.Target is a VMware virtual machine and OS is ubuntu 22.04.2 and is running jamf pro 10.43.1 and server tools 2.7.14.Is it because the database version is an older version?appreciate any help.
Hello Jamf Community,I work with a University. In our department we run Mac labs that act as classrooms for a large variety of classes that are reserved daily. We are redesigning our Mac classroom "build" primarily with Jamf Pro. The biggest hurdle that we face is in determining a user account and maintenance method that meets the needs of our classrooms.Needs we have:Fast turn around times, 4 classrooms of 30 computers with a 15-minute gap between different classes -- and essentially 3-4 minutes per room to get every computer rebooted and ready for the next classThe previous team that designed our current system had disabled SIP in order to develop a user template that was copied over the existing user account that is used by students upon login with a login-hook. This happens upon restart (initiated by Apple Remote Desktop) and the user is auto-logged in. That worked fine for many years, but some systems have broken upon OS 12 Monterrey (the computers fail to complete 'optimization')
Hello everyone,I am still in the evaluation phase of JamfPro. While testing, I came across a question about whether the devices on which you want to perform Secure Erase must also be registered in the Apple Business Manager, or whether you only need to register devices in Jamf Pro to perform a Secure Erase. Devices that are already in use can only be registered in the Apple Business Manager if you completely erase them. This would not be feasible for my colleagues, so I would want to avoid registering in the Apple Business Manager. Therefore, it is important to know whether self-enrollment in Jamf Pro is sufficient for Secure Erase.Here a screenshot:Does 'Wipe Computer' in JamfPro perform a secure erase of the entire hard drive (i.e., the Secure Erase command built into macOS), or does it simply delete data from the device?Best regardsFloh
Hey everyone,Having an issue with jamf app catalog installations. Some machines just seem to randomly not want to install the app. These machines are very similar, it's a computer lab, but one machine will install successfully and its neighbor will fail.My question is how do I investigate this further plus all I see in the console is that it failed with no real information and also has anyone else experienced this and was able to fix it
Hi, Does anyone have a link to the latest list of Installers available?T.I.A
Hey there,is there a possibility to display an extension attribute either separately at another place or to hide the attribute and make it visible by mouse click? It is about the fact that we have a script in use that implements LAPS - so assigns a local admin password and stores it in an attribute for emergencies. But I don't want this to be visible directly, but that you have to click on it first to make it visible, at least similar to the recovery key. Is that possible?Thanks in advance,Michael
I Have been tasked with creating documentation on how our Jamfcloud.com is currently setup. So our first thought to find a way to print the pages from the bowser. Because of all the iframe going on I cannot find a way to print an entire page - or even just the frame from top to bottom. I really do not want to create 2 dozen screen shots and more for every policy and config.Looking for ideas.
Hi - I have inherited a Jamf Pro environment with 1118 packages and 700-800 policies - maybe around 35% are actually being used. What is the best way (or some ways) to figure out what can be deleted and what can't? Is there a best-practice way to delete packages and policies?Similarly, there are around 550 computers that are probably out of service but still in Jamf. What is the best way to figure out which computers can be deleted and which can't? Is there a best-practice way to do something that will temporarily remove them so that I'm not exceeding my device count while I figure out if they indeed have been removed from service and can be deleted from Jamf?Thanks, --Jeff
We seem to have an issue with the configuration of our Jamf Connect.We are using the connection with Azure to create our users.Some Macs login with the Jamf Connect window, but some show the native MacOS window with 3 buttons. This last is not desired, since most of our users do not know their Local User account.The native MacOS login window only appears after a reboot. When the Mac sleeps, it pops up with the desired login window (the one with the user icon).The thing is that this does not happen on all our Macs. Out of about 30 Mac, this has happened once on a M1 13" pro running Monterrey and this week on 2 new M2Pro 16" machines.Our configuration has not changes, since we onboarded to Jamf last October.I am sure we are doing something wrong here, but I have no idea where to start looking. Hopefully someone can point me in the right direction.
I need some help in figuring out how to disable the TouchID feature on the new MacBook Pro for now. In testing we found that it's been causing some AD lockout issues, and since we want to deploy these Macs before the 12.2.3 hits that suppose to fix this - I figured it would be easier to just disable the TouchID option for now and enable it later. So, I fired up Composer and told it to snapshot both new and modified files and proceeded to disable the TouchID for unlocking the machine (the other two options wouldn't work anyway since we don't allow iCloud access). I then checked the files, and none of them seem to be related to the touchID feature. I'm assuming there is some plist file out there that keeps track of the options the user chooses. Ideally I'd like to lock that down with the options turned off, and then hide the touchID and Wallet system panel. Any ideas? Anyone else having these issues?
Hi All,I'm new to Jamf pro and heard about the re-enrollment. However, I got a question that if we delete the entry of the device rather than enabled the re-enrollment option. What makes the difference? Kindly help me to understand. Thanks.
Hello,Is it possible to prevent iPad users to remove JAMF profiles from their devices? iPads are enrolled through AC2 (not DEP). Users are able to reach the profile under their iPad settings and simply click "Remove profile". This is causing huge constrains in managing our iPad fleet.Thanks!
Morning!I'm currently trialing Jamf School. Want to test how to use Google authentication during enrollment. I believe I have everything set up: Built Google API Console Project, created credentials, added redirect URIs, copy and saved client ID/secret, then added all that into Jamf School under Authentication method.On iPads I'm using for trial, I wiped and reset. iPad went through enrollment easily enough. But I expected to come up on a Google sign in page which needed authentication. But nothing shows up. Just normal enrollment steps.My questions - What should I be expecting? How can I use Jamf School and Google in a 1-1 iPad setting? Thanks!- Kevin
Hello Jamf Nation, We would like to provide advanced notice that for the Jamf 300 and Jamf 400 Courses beginning on or after 1st September 2023, we will no longer accept certifications earned on Version 9 of Jamf Pro, previously the Casper Suite, to be used as prerequisites for training course enrollment. This applies to the Casper Certified Tech, Casper Certified Admin, and Casper Certified Expert certifications issued prior to the release of Jamf Pro version 10 in November 2017. The Jamf 200 Course prerequisites remain unchanged, where we continue to strongly recommend students complete the free, online Jamf 100 Course before attending. This change also does not affect the Jamf 370 Course, where we continue to accept any Version 10 issued certification as a prerequisite. Since the release of Version 10, we have all experienced five major macOS releases and forty-four Jamf Pro version updates. Furthermore, key concepts such as Patch Management, Device
Right now we use a certificate to join our district school devices to WiFi. This is delivered via a config profile with the network settings and the certificates. When the certificate is getting ready to expire we deploy a new config with the new certificate. All works fine till we try to remove the old network settings and certificate from the machine - we lose network. is there a way around this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!