Get Support
Recently active
Hello Anyone could help me on this? Iooks like it needs user intervention before the installation will proceed anyway to bypass it? or any known fix on this? i tried several commands and im still stucked on this one. Thank you very much for your usual assistance.
This command works from the Terminal when I activate my Admin button beforehand:#sh /Applications/Zscaler/.Uninstaller.shAnd then it prompts the password. If I enter:#sh /Applications/Zscaler/.Uninstaller.sh <password>And put in the actual password, it will go straight to uninstalling it, but only from the Terminal.If I put this same script in a Jamf policy, it won't push. I'll hit my sync button and it will fail. Has anyone figured this out before? Thanks.I followed the instructions here already: Uninstalling Zscaler Client Connector | Zscaler
I'm using ASM as the user truth.Interestingly, as we switch to the new year I see a range of student user records that flip to manual. (It's most likely because those who leave the school are still assigned a device at this point, so if they disappear from ASM they can't yet be removed from Jamf School).However, there isn't a Filter option to be able to see just those records that are manual (or ASM).Sure, I can sort the list by Source but it would be more efficient to have a filter. It is currently cumbersome to clean up student records in the following year. I've run into the issue where I do have two user records for the same person - one from ASM and one manually.
Newbie MDM user here. Signed up for Jamf Now and have 6 iPhone 14's being managed for work. The iPhones are not signed into an iCloud account. What is the best/easiest way to push a managed list of contacts to the phones?
Leverage MDM-delivered Configuration Profiles and a custom Bash script for dynamic, yet consistent Sensor Grouping Tags in CrowdStrike FalconBackgroundAs we’ve considered deploying CrowdStrike Falcon on macOS, we’ve wanted to leverage Sensor Grouping Tags in a way which was dynamic, yet consistent across our fleet.However, learning about any new software product also includes learning about its limitations.Yet another job for system engineers.Continue reading …
Since I migrated Jamf to a Windows 2019 server two weeks ago, I have been troubleshooting the primary distribution point. The distribution point and jamf server are running on the same VM. I have tried and failed with https, probably because of the same root cause... so I am trying to simplify the issue by first troubleshooting the SMB dist point problem.I am able to mount the share both from Windows and Mac clients using the jamf service accounts. I have been able to validate that the accounts work as-should... one read-only, the other read-write. I don't know what the jamf binary and jamf admin do differently to mount the distribution point, but both fail without any helpful messages.I'm wondering if any of you have had a similar experience, and whether you have been able to locate your root cause and resolve. I have a packet capture out to Jamf support right now. I have been working with them for two weeks without resolution. I just re-built my Jamf server a second time with the sam
Does anyone know of a way to join a WiFi connection before a user logs in? We have a situation in which our users travel quite frequently, so when a password reset policy has to be pushed due to a forgotten password, they are unable to pick up the policy. We're hoping there is some way we can have them join a wireless network from the login screen from wherever they are working.
Hi,I’m hoping someone can help.I went to renew my push certificate, but on logging into Apple the original one isn’t there - don’t know why.Anyway, my issue is that my push certificate is now expired and can’t be renewed and now my iOS devices aren’t reachable via push and when I went to wipe them with Configurator 2 they’re showing as locked so I can’t do that either.My installed profile isn’t user removable and doesn’t allow for wiping from the device.so far I’m stuck with 60 odd unusable iPads - any help would be greatly appreciated.thank you in advance
Is there any way to invoke a forced update of user information from LDAP with out the device needing to be check in?we have status of our users directly maped in our user details of AD which is imported through ldap, and updates overnight providing the device is checking in, if the device doesn't checkin this information never updates, putting critical information which we leverage in the MDM for app and setting distribution etc. But also helps us insure the statistics of things are accurate due to the status information we map into fields like room and department and phone of the users ldap which.I have used API to update MacBook information before, however I am trying to workout how I can force this process that occurs nightly with devices check in, without their need to check in, so that stale devices are showing the correct status of our users, or at the very least, collect the user assigned to the device, and leverage this against a CSV to update the fields through a manual csv.Fo
Worked this out with @rtrouton based on both his installation script as well as the one located at cobbservations.wordpress.com Wanted to offer Xcode 8 (requires OS X 10.11.5 or later) to our user population via Self Service. Downloaded the Xcode 8 installation package from the App Store using the App Store Capture Methodology (yes, VPP would be better), described at: https://derflounder.wordpress.com/2013/10/19/downloading-microsofts-remote-desktop-installer-package-from-the-app-store/ Added the 4.43GB installation package to the JSS, created a Self Service policy to install it, and used this script below (set to Run After) to handle all of the post-installation processing (so that users are not prompted for admin credentials). You may want to customize the script for your environment (we don't disable the Gatekeeper validation, and our users are already developers, nor do we have multiple versions of Xcode installed, so those line-items are disabled, but it's your call): #!/bin/
Hello, recently I've been asked to take over Jamf due to losing our Jamf admin at my work.I already have a little experience with Linux and Bash scripting but the administration of the tool is what I need to learn.Any suggestions on what resources would help me learn Jamf, outside of Jamf themselves?
I am looking at building a script for an Extension Attribute for Falcon | Crowdstrike with the desired result:Read the CID of an installed Falcon Sensor Compare the CID to one of two Pushed by the JSSOne CID falls in 'Complete' - Managed by Falcon Complete TeamOne CID falls in 'Lite' - AV/ED/Reporting/Remediation functions only; which is managed by our team/department.Upon comparison - output either 'Lite' or 'Complete' to the extension attribute based on the CID detected on the client/endpoint.I have found many of the other Crowdstrike EA's that folks have put out; but have not run across any that are able to complete a process as I've described above.Any ideas or food for thought anyone can think of to help me kick it off/get started on it? Possible existing resources I can use to build off of?
I was asked today to "audit" app deployments at one of our buildings. Is there a way to search our app database by the building scope? Otherwise I have to grab a device from that building, and copy a text list of apps in scope to a word document or something since there's no export either.
We've finally got approval to transition to the Jamf Cloud when our contract renews at the end of September. I'd really like to start fresh and run an enrollment package on existing devices to not carry over the bloat from our current JSS and make sure only active Macs get registered. We have 905 Macs in our inventory, but only 797 have checked in within the last 90 days (what we consider to be active). Being charged per-device, I want to get a true look at our numbers when we move over. I would also like to clean up some of the inventory data and only track what is absolutely necessary and not all the extension attributes that we have now. I know Jamf offers a day long migration with them, but I'm wondering what people have done when they migrated. My main questions are: Is there any advantage to just essentially copying/pasting the existing DB and then trying to clean up that? Does re-enrolling devices bring the FileVault recovery key over, or would I have to run a
I just noticed that the PRINTERS section of the computer inventory is missing. Has anyone else noticed this?How are we supposed to now see what printers are installed on a mac?version: 10.42.1-t1667311080
The previous jamf guy disabled this feature, but now our CTO wants that feature enabled. Teachers and staff members would use their already existing district username and password as their apple id.Would this be a new config profile that would have to be created? Any input would be greatly appreciated.
Customer Education is excited to share our first Jamf Pro Release Notes video!Join us for an overview of some of the new features and enhancements that are available in Jamf Pro 10.44. We hope this new resource provides additional details to support your use of the features in this release.Once you’re done reviewing it, we’d love to get your feedback. Feel free to leave a comment and let us what you liked and how we can make it even better next time.We look forward to hearing from you!
Jamf has updated our Hosted Services Availability Commitment effective May 15, 2019. For more information, please review the full document here: Hosted Services Availability Commitment
HelloI want to pass a multiline description as a parameter from the policy to a script.The script is using the jamfHelper app. How can I define a manual line break in the description parameter? btw, is there a way to get the policy name or id to a script? thanks
Hi,I have On my iPad General > VPN & Device Management only displayed VPN - not anything to do with MDM Upgraded to the latest OS from the device and now I see all the Configuration Profiles in General > VPN & Device Management but still when I try and do anything that uses a remote command from Jamf Pro such as restart or Inventory it stays with a status of "Pending". The MDM Profile looks to be current. Before upgrading iOS there were a bunch of failed commands like this in Jamf The UUID for the profile “Self Service Web Clip” is not unique. My current idea is to wipe it and rebuild with Apple Configurator. If it was a Mac I'd try a "profiles renew -type enrollment" command but I can't see how to do that for an iPad This is 1 of 80 but the only one that is misbehaving It, like the other 80 received a new config profile to access the wifi a week or so ago changing from user authentication to certificate authentication. It can access the internet fine so it's n
I am using Jamf Admin to try and add printers. When I click on the add printer the printer window does not open. Any ideas why it is not opening? When i click on the add dock items the little pop up window to add items pops up, just not for the add printers.Thank You
Hello! I am trying to create a script that would remove certain lines/strings from a .txt file. I have tried: sed "/$String/ d" File.txtBut had no luck, any thoughts or tips?
https://community.jamf.com/t5/jamf-pro/macos-ventura-amp-blocking-access-to-users-amp-groups-pane-in/td-p/276553here there are some good suggestions regarding blocking panes inside the system settings.My question is- can you block the System Settings app altogether from launching? Like PathBlackList magic?So that it'd require admin password to launch? <key>pathBlackList</key>this doesn't seem to work.
EDIT: Removing the usual rant, worked with a Wacom dev team contact, verified these settings work with Monterey on Intel and M1:Codesign commands, to gather the info needed for the PPPC configuration profile:$ codesign -dr - /Applications/Wacom\\ Tablet.localized/Wacom\\ Desktop\\ Center.app Executable=/Applications/Wacom Tablet.localized/Wacom Desktop Center.app/Contents/MacOS/Wacom Desktop Centerdesignated => anchor apple generic and identifier "com.wacom.Wacom-Desktop-Center" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = EG27766DY7)$ codesign -dr - /Applications/Wacom\\ Tablet.localized/Wacom\\ Display\\ Settings.app/Executable=/Applications/Wacom Tablet.localized/Wacom Display Settings.app/Contents/MacOS/Wacom Display Settingsdesignated => anchor apple generic and identifier "com.wacom.Wacom-Di
Hello, Today I setup Licensed Software titles using Software Identification Tags as per the kb article and cross-referencing Adobe's documentation. I need to get license counts for all Adobe products as we need those counts to purchase and true-up on licenses. The funny thing is that the Software Identification Tag method, and the Application search method does not come out even close to eachother. I know that both searches are probably incorrect. What have others out there done to ensure your software counts are good? Thanks,Ken Edgar
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!