Get Support
Recently active
Hello all, We have been having huge issues with the standard account; cannot update software(Chrome), cannot add personal network printers, cannot add WiFi, etc. So it was the consensus to promote the standard account to an Admin account. I am hoping there is an script to perform this very act, because updating 900+ devices is a little daunting. I see there is a script to demote and we have it in the wings for deployment should this entire Admin rights thing go South. I am no scripter, but know enough to follow through what will happen when things are run. So any and all help is appreciated.
I created a guide on how to setup users account pictures via Jamf Connect check it out.https://www.ericsontech.com/2023/02/set-account-pictures-via-jamf-connect.html
I’m trying to enable lost mode and play sound on a group of iPads. I’ve found a way to enable lost mode, but I can’t figure out how to also send play sound command. xmlData="<mobile_device_command> <general> <command>EnableLostMode</command> <lost_mode_message>$lostModeMsg</lost_mode_message> <lost_mode_phone>$lostModePhone</lost_mode_phone> </general> <mobile_devices> <mobile_device> <id>$i</id> </mobile_device> </mobile_devices> </mobile_device_command> See here for full script: https://gist.github.com/talkingmoose/f44d0d87d08b48daa0e887a6239c1766
Hello! So, Currently I have been having issues with Naming of machines, this isnt happening on ALL the machines just a handful and i can't seem to fathum why... I'm using a policy that has a reccuring check-in, using the maintenance 'Reset Computer Names' to make the changes in jamf transfer onto the machine in question. Now, the names will change in jamf but after a few days it will revert back to something like 'imac(8)' and not what i previously set... Any help?
We are in the process of moving away from Enterprise Connect and pushing out the built in SSO. I was hoping there would be a way for me to see the logged in user for the SSO like I do with Enterprise Connect. I know it's just an extension attribute that grabs the logged in user from the EC app but I don't know where that data is stored for SSO. I just want another line like in the picture below but instead of Enterprise Connect, I want SSO Logged in User
I don´t know if there is a way to remove this, but If I make a update to a configuration profile and apply it to all devices, the screen of each device when the new configuration profile is pushed out is way of "flashing/refreshing" in a second - and quite annoying if changing scopes etc Is there a way to disable this. Can not understand why a configuration profile update must do like this as
After consulting with Eset, I've written the below Extension Attribute to spit out the version of Eset Security installed. When I try that script in terminal I get the result: 6.7.654. When I create a smart group in Jamf with operator is and value 6.7.654 I don't see any results in the group. In Extension Attribute I've chosen: Data Type: String and Input Type: ScriptIn short, the script does work but Jamf doesn't like it as Extension Attribute. Any idea? The script is: !/bin/bash esets_scan="/Applications/ESET Endpoint Security.app/Contents/MacOS/esets_scan" if [[ -e "$esets_scan" ]]; then esetversion=$("$esets_scan" -v | awk '{ print $5 }') echo $esetversion exit 0else echo "Not Installed"fi exit 0
Hello all,I wanted to share something that we ran into in the last week in case it helps another Mac admin. We use Google Workspace and Microsoft Edge as our default browser. Over the last week, we've had multiple reports that drag and drop attachment uploads were becoming "corrupted", but attachments using the file chooser dialog worked just fine. We discovered that since the release of Edge 110.0.1587.41, if a user has "Show all filename extensions" unchecked in their Finder preferences, drag and drop uploads would remove the extension from the file, even if it actually has one. I've confirmed this behavior across multiple sites that utilize drag and drop uploads. Enabling the Finder setting resolves the issue, and we've reported the issue to Microsoft.
Good morning,I wanted to share something we ran across in our environment over the last week in case it might help another admin.We use Google Workspace and Edge as our primary browser on macOS, and in the last week, several users have reported that drag and drop attachments were becoming "corrupted". We discovered that since the release of Edge 110.0.1587.41, if a user has "Show all filename extensions" unchecked in their Finder settings, drag and drop uploads would remove the extension from the file. Enabling the setting resolves the issue. I've sent feedback to Microsoft.
We have a few systems that are no longer communicating with Jamf pro. We are at the point were we need to re-enroll these systems. These are live systems that we do not want to wipe. What is the best way to re-enroll?Running: profiles renew -type enrollment locally on the systems? Does the MDM profile have to be removed before this command is run? Is there a need to delete the computer out of Jamf first? Most systems are 11 or higher though a few are on 10.15.
I'm trying to set up a dashboard in PowerBI and seem to be hitting a roadblock with the Jamf API call. Specifically, when I go to attempt a call in PowerBI to site/JSSResource/advancedcomputersearches/id/# using JSON, I get: DataFormat.Error: We found extra characters at the end of JSON input. Details: Value= Position=0 The data returns in Postman if I test my API call there, but for whatever reason PowerBI doesn't like it. If I change the output to XML, some data comes back, but it's just the computer name and ID number, and doesn't include the other fields that I have set up in the Advanced Computer Search (extension attributes) that I'm actually interested in. I do get the column headers though, but they come in as a separate table, but none of the data related to them. I'm inclined to think it is indeed a PowerBI issue and not a Jamf issue, but I'm curious if anyone was able to get around this if they experienced it either with PowerBI or another tool that leverages API
I guess I don't have a connection to our iOS devices after renewing the push certificate, because of a wrong Apple ID.I have to re-enroll all devices, there are only 20, no problem, but the problem is, that there is a MDM Profile on the devices which I can't remove because, Jamf doesn't have connection to it. When I tried to re-enoll there is a error msg that I have to delete a profile with a MDM-Payload. Can someone help please?
I have an Excel file that I'd like to automatically retrieve Smart Group count information. I am eventually want to build charts in Excel with that data. If retrieving count info is possible, what steps do I need to make that happen? Thank you in advance!
Hi, I'm using JSS v9.92. I am trying to utilise some User-Level Configuration Profile (specifically, passcodes, but that's not important). I am testing on 3 Macbooks. One out of the three have a vaild "MDM Capable Users = local-user" within the Macbooks' General information. The other 2 have "MDM Capable users = <blank>" When enforcing the User-Level Configuration Profile, only the one with a valid MDM Capable User received the profile. The other 2 received nothing. Does anyone know any commands or how to fill in the MDM Capable Users fields within each computer? I've search JAMF Nation, all I read were people wanting to delete it.
Hello, wanted to ask if there was a way once a machine is done with the enrollment process it would log or restart to signal that is done with all policy's and profiles.
We will be replacing approximately 900 student ipads this year. Would anyone be willing to describe their workflow tips/processes for wiping the devices, deleting Jamf inventory records and releasing them from ASM? thanks in advance.Dale Beachy
This used to work and it is all of the sudden not working, preference is, to create the admin account in the Pre Stage and then skip local account and when prompted by a login screen be able to login as the AD user. As stated this was working, however it now is prompting to create the local user. Ideas?
Is there a way we can query a computer for its locked or unlocked state? I'm familiar with endpoints to get the command status.../JSSResource/computerhistory/id/{id}/subset/commands/JSSResource/computercommands/name/DeviceLock...but neither of these tell me if the device has been unlocked after it was successfully locked
All of our students have Macbooks and many of their parents set up screen time settings on their Macbooks using an Apple ID that's connected to their family account. Every so often, we run into the issue of the parents restricting apps that they need to use during the school day. Is there any way to prevent this using Jamf? Or is there a way for us as admins to go into the screen time settings and unlock it without the parents' passcode? This is mostly an issue with Macbooks running Monterey, although we do still have some with Catalina and Big Sur. We have experienced this issue with the older OS's as well. This is at a high school grades 8 - 12, so this mostly affects the 8th graders.
Hi All, Is anyone seeing issues with macOS Software Updates since 11.5? Specifically updates showing as not available when no deferral set and when showing available fail with "An error occurred while downloading the selected updates. Please check your internet connection and try again", in this instance only booting into safe mode resolves it. Thanks,Andy
Hi Everyone, With the announcement of the latest zero day, how is everyone going about upgrading there fleet? I have a policy to delay MacOS Minor Version for 30Days, Would that not delay our users receving this new update? or does enabling the box "Allow devices to install Rapid Security Responses (macOS 13 or later) " allow this to happen? Curious to know how everyone else is handling it. Worse case scenario I can remove the Delay 30 days policy upgrade and put the 30 days back into place
I don´t think I am the only one, but before in Catalina and earlier versions, it was possible with jamf connect in DEP deployment to login the user so a user account was created on the computer -and the user account was mdmcapable, so user certificates could be used (through ACDS) But now in big sur accounts created in jamf connect cannot anymore be mdmcapable, as the command does not exist anymore. So just wondering what are other doing to solve this issue ? or rather is there other workarrounds ? I actually thought of doing a auto re-enrollment of the mac when users enter for first time, as account then will be mdmcapable. But never managed to reach the goal for this, as it may also be a bit to creative. So wondering what other are doing. As Per today our users must create the account manually outside jamf connect starting up the first time. But not very smart way and spelling errors, wrong names etc can be entered there
Hello all,3 of our devices were supervised and managed, but the Jamf records on our end were deleted while the devices were still active. So the devices still have Jamf on the system, but now phoning home is pretty weird. We were able to restore one of the records, but it appears to be only managed now. On this restored record, we are unable to push any commands or policies to the device that are normally available by default (Lock Device, Send Blank Push, etc.).Is there any way to get these devices reconnected to our system, or should we bag it and just re-issue new devices to these users?I'll be checking this all day so please feel free to ask any questions about anything I might have left out. Thanks!
I've found we have about 1500 orphan classes from the previous year which were not cleaned up in our SIS before the import happened for this year. I know how to mass delete all classes using a script but I only want to delete the ones marked as N/A - is that possible?
Hi there, I dreamed up a way to create MDM-enabled users while at the same time using Jamf Connect and I am running in an annoying problem and I seem to not be an expert enough in Azure to fix it... if it is even possible...So I added an ENrollment Customisation Configuration to the PreStage requiring authentication with the Azure Account. That leads to the Mac being associated with the Azure user in Jamf Pro. I then have the PreStage pre-fill the primary account information using variables. Unfortunately I seem to only be able to pre-fill $FULLNAME or $EMAIL and both contain characters that macOS really does not like as a username. (either a space or @). So my question is: Is there a way for me to get only the part of the UserPrincipalName / E-Mail in front of the @ out of azure, through Jamf Pro and into that Account Name field? My plan continues with Authentication to Azure in the Jamf Connect Login Window and then connecting to the just creat
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!