Get Support
Recently active
First time poster, looking for any help/direction.I have shared iOS devices that have a general use email account. I had everything set up using profiles and Exchange Active Sync with no issues. Username, Server, Password was auto installed on each device.We have recently moved to O365 and I'm unsure how, or if I'm able, to add a password to the email profile using either native iOS Mail or the Outlook app.For iOS Native Mail, is it as simple as changing the server URL?For the Outlook app I found a String parameter that will grab the email address from the device's User & Location Tab, but nothing for the password.Thanks in advanced!
Hi everyone, I know this is a swarm of bees, but... Is it at all recommended to use Patch Management to keep macOS up to date for cases where Software Update insists there are no further updates (from 13.0 and 13.1 for example). If it is recommended, what PKGs should be used? Certainly not the InstallAssistant.pkgs, right? And deltas, do you really set up incremental updates for each delta pkg? At least the Apple macOS Ventura patch management definition lists minimum OS 13.0 for all of the versions (and "Reboot required: No"?!) but which pkg could that possibly correspond to? ORShould we just consider Jamf Pro Patch Management to be a placeholder, a tracking method, when it comes to macOS versions?
Is it possible to deploy the youtube app but restrict its contents to certain channels. Would this be possible via plist? If so, anyone knows of Youtube's plist syntax?Tried the content filtering using safari. But even though I input a specific URL video link, I am still able to access the whole of youtube.com
I'm looking for a way to create a Smart Group in Jamf based on a large list of serial numbers via the API. For example, when I have a large amount of end of lease iPads to decommission, I'd like to be able to quickly create a Smart Group containing those serials using the API, rather than creating a Smart Group via the GUI and manually inputting a massive list of serials. I've seen some helpful posts explaining how to create a smart group via the API, just checking if someone has achieved something similar before I look into this further. Thanks!
Hello,I'd like to show the Data Disk Used in percentage on an EA so that I can extract a report with all my computers and how much percentage of our users are using their disk drive. I just can't find it in EA templates and the boot percentage is not what I want. Thanks
Hi there,I'm struggling. We are a vocational school (~1000 devices) and some of our students don't shutdown their Macs correctly (every day). They are still logged in or just did a logout but didn't shut down the machine.So I decided to script against that problem to save energy. My solution is:a script is invoked by an LaunchAgent every 5 Minutes the script checks the iMacs idle status if it is more than 20 min a jamfhelper dialog is shown to inform the user (with a timer to react)if the dialog it not canceled it (should) shutdown the MacI decided to use an LaunchAgent, because the dialog should also be shown if nobody is logged in (loginwindow).The problem is: shutdown has to be invoked with root privileges and LaunchAgents runs in user-context.Does anybody have an idea to get around this without giving all students root privileges (they aren't in the soduers file)
Good morning!I am trying to open up to view the contents (not install) of a pkg that is a part of the DEP process at my school. I downloaded the pkg (and cached it) from Jamf and I tried to Convert to Source using Composer but it fails. I have also tried using terminal using the 'pkgutil --expand' command and that fails as well. I also tried SuspiciousPackage app and that failed as well (The document “depnotify-with-installers.pkg” could not be opened. The item “depnotify-with-installers.pkg” is not a macOS Installer package, or has been corrupted or modified.).Any advice on how to view the contents would be great. I'm a semi-new Jamf Admin (6 months in this role) and I want to figure out what is being installed (this way I can edit it if need be).*I will add that I normally find cached pkgs in the Waiting Room folder and this time around I found it in Receipts (not sure if that matters).Thanks!
Hi, I see that a growing number of organizations are migrating on-premise AD to Azure AD. Therefore, I decided to share our experiences using Azure AD as a authorization provider for Jamf Pro. First, LDAP is necessary in order to get user and group lookups to work. This means, you have to set up the service Azure Active Directory Domain Services with external LDAPS support. At this time, this service is available for all Azure subscriptions except CSP subscriptions. It is easy to set up, but requires a DNS entry (a name that points to the public IP address of the new LDAP server) and an SSL certificate that works with the given DNS entry. So, with this working, you need to know that LDAP login with Azure ADDS is possible, but the users' passwords must be reset before it works. Also, the new passwords operate on another time schedule than Azure AD's password policy, so they may stop working. Bottom line: Don't use AD LDAP as login mechanism in Jamf unless you really have to. But use
Hi Community members,I am the IT and Apple Support Specialist for a high school with just under 900 students and have 300 classes in Apple School manager / Jamf School.Has anyone come across a way for me to view which teachers enabled restrictions on a particular student? Say a log of some sort like we have an audit log for changes made in Jamf School. Perhaps there is a way to do it through the API?I say this because there is often a case where several students come to me and says their apps are missing, so I remove teacher restrictions and they are back. This often occurs when a teacher forgets to leave a class and clear restrictions on either Jamf Teacher or Apple Classroom after their lesson ends. I need to check the logs and see whether it is any specific teacher that does this.
Does anyone know how to add apps to groups of ipads? I have several groups representing grades ( I work in a school district) for ipads. If I have 7 ipads per grade and I want specific apps for those 7 ipads, how do I set it up in jamf pro?Thanks
My company has been using Jamf Pro Cloud version since 2021 and I heard that every Jamf Pro Cloud version are entitle for 1 free sandbox environment.Is this true? If so, what is the process to set this one up?
Hi, I have 700+ macs that need timemachine backup (around 1TB each), but we have NetApp that is not AFP2+ compatible.Anyone has a solution that is scalable and Enterprise oriented for Mac backups in-house?Thanks Carmelo Lopez
I need to manage 2 macs, our Windows devices are in Azure / Intune. I'm looking at Jamf as I've heard its the best solution for macs.We only have 2 devices and a small business so was looking to use Jamf Now but have a few queries on this setup... Does Jamf Now work with Intune, all the documentation points to Jamf Pro?Why do you run Intune & Jamf? They both seem to be similar in what they do (encryption, policies, etc)Is it viable to just use Intune when its just a few macs? One key thing is we want them to sign into macs using AzureAD accounts?
We are looking for Laps implementation for our MacOS. we utilize jamf pro and jamf connect.our Macbook is binded to jamf connect. I had a look of MacOSLAPS however this solution require AD integration.is there another reliable laps solution that doesnt need AD integration?we do have intune subscription (but we only use that for our windows devices)
Is anyone able to remotely update iPadOS with Jamf School?I'm testing a 14.6 -> 16.2 and left it over night to fail.Jamf School cannot determine the OS update status. The update likely failed on the device.There is no passcode and it was left plugged in.
Hi all,Is anyone know if we can retrieve the "enforcedSoftwareUpdateMinorOSDeferredInstallDelay" from the com.apple.applicationaccess?
Clicking on an 802.1x EAP-TLS network in the Network Selection pane of the Jamf Connect login window prompts an end user for their username and password then blocks them from joining the network.This has been a known issue since 2.11.0--- because of this we can't use wifi connection using SCEP or AD creds at the login page (confirmed by Jamf Support).We currently use mac address whitelisting (with Clearpass) as an interim, thinking this would be resolved soon, but after doing some research and seeing how many versions this known issue has been a part of--idk if Jamf has any plans to fix this in the near future.Has anyone used another method of authentication for wireless besides regular PSK or mac address whitelisting that has worked with Jamf Connect at the login page?
Hello all,We enrolled a macbook pro via enrollment link. The MacOS is ventura 13.2.1. Everything looks to be ok except for the fact that the mac is not showing up in the JAMF console. Has anyone experienced this before? We have also unenrolled/deleted the profiles and re-added and still no luck. Thank you for your help!
https://tomsoderling.github.io/Disable-iOS-simulator-connections-popupI have a user that has asked to use this script (above) in order to prevent the annoying popup from appearing each time, however upon testing I get the following:Firewall settings cannot be modified from command line on managed Mac computers.> Add Xcode as a firewall exceptionFirewall settings cannot be modified from command line on managed Mac computers.> Add iOS Simulator as a firewall exceptionFirewall settings cannot be modified from command line on managed Mac computers.> Re-enable firewallFirewall settings cannot be modified from command line on managed Mac computers. A config profile exists to prevent everyone from turning off the firewall. I would like to use this script but unsure how to amend it in order to get it operational - is anyone able to offer any advice please?
Hey y'all, a query for the hive mind. We've been running into users installing Awesome Screenshots (horrible name), which beacons out to websites tens of thousands of times a day. As you can imagine, InfoSec is not happy about it. I'm trying to find a way to do reporting to find out what extensions are installed on machines. I found that the extensions are all stored in the same folder: ~/Library/Application Support/Google/Chrome/Default/Extensions/ But the names of the folders with are just random strings of letters and numbers:external image link Within the folder is a manifest.json file, which does have the app name in it:external image link So I'm assuming there is some way to grab that and throw it into an extension attribute or something. I think the main problem would be navigating through those extension folders, or at least finding a way to translate those folders into extension names. Has anyone found a way to successfully report installed extension
HelloI want my students to use emojis to represent themselves. The keyboard is present, but the function is disabled.I have opened the rights to iMessage and FaceTime so as not to limit the user.The emojii keyboard is still not working.
Hey Guys, as the subject header implies i've been trying to figure out how to configure multiple language locales. The thing is for my nudge policy i've created a custom message that the employees will get when they get the nudge, the thing is if i dont configure a user language locale it wont display my custom message but rather a standard one. And if i do configure a language locale it seems im only able to set one. Does anyone know how i cant set multiple user language locales so they all get the same message no matter which language they use?
In large enterprises and organizations with thousands of computers, it’s often necessary to break up software deployments into more manageable groups. Need to push a configuration profile out to 5,000 devices? You might want to break that into chunks of 1,000, so you don’t hammer your Jamf Pro server. When I was a customer, we had over 17,000 devices in each of our Jamf Pro instances, and we often wanted to deploy software in stages. Right now, there is no built-in method to do this in Jamf Pro. So, I came up with a way to generate semi-randomized Smart Groups by utilizing the UDID of the device. The UDID is a 32-character identifier (Unique Device ID) that all devices have and is what Jamf Pro uses to uniquely identify all devices. You can view a device’s UDID by navigating to the device’s inventory record and selecting Hardware from the sidebar. Each UDID contains HEX characters, which means 0 through 9 and A through F. Using a little bit of REGEX-fu, you can create a Smart Group th
I've been out of the Jamf loop for a little while in a company migration to Windows. Our parent company though wants to use our Jamf cloud to manage some Macs not setup in our DEP. It's about 150 machines and I know recently the Recon app was killed. So no QuickAdd packages or network scanners anymore from what I can tell. So I guess what I'm asking is, is the enrollment URL really the only way for Non-DEP machines to get enrolled? I'm sure I'm asking a dead horse question but couldn't find any comments in the forums. Thanks in advance for any ideas to make this more efficient than relying on users to enroll or bring in their machines one by one.
Jamf Cloud customer. Hybrid worker (partially at home, partially in the office). When I work from home, I can't upload Packages. I have Xfinity 1GB service and their Gateway router. No issues when I'm working in the office. The Package starts to upload, then stalls somewhere between 1-3% and just hangs indefinitely from that point. This happens both in the Jamf Pro cloud admin console, and when using the Jamf Admin application. I used the Xfinity App to setup port forwarding for ports 548/445, but I can't select AFB/SMB as a protocol. (Administrator work station connections: https://learn.jamf.com/en-US/bundle/technical-articles/page/Network_Ports_Used_by_Jamf_Pro.html) Jamf support is blaming Xfinity. Xfinity won't give me time of the day because the computer is connected to the internet and reporting no issues with their troubleshooting tool. Before running out to buy my own Router/ Modem, is there anything else I can try?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!