Get Support
Recently active
Does anyone have any advice on how to package JMP 17 and the license txt file in a silent install?
Hi AllMy problem is, I have restricted to "Only some Apps allowed", this works great, there is only one problem.I dont find how to allow Apple Sidecar on iPads.Please help me,thank you!
I have been using the erase-install.pkg successfully for some time, placing it within Self-Sevice and allowing users to install at their convenience. However, with one user, I have run into an issue where is appears that the step of grabbing the latest installer is failing.Background:This particular user attempted to install Ventura on their own through Software Update within System Preferences. It looks like the installer was downloaded, however they were blocked when they reached the prompt requiring an administrator to allow the installation.I directed them to Self Service where the erase-install.pkg is loaded (28.0). The attempt to install, the progress wheel begins to spin for a bit, stops, and nothing is installed.LogTaking a look at the applications installed on this user's machine, it looks like they have an older version of the installer present (Install macOS Ventura.app 18.0.02) likely from when the first attempted their own update. The script sees a newer version,
I know this has been asked many times, but I can't seem to find a specific script I can use in a policy to demote a specific user from admin to standard. All our accounts are local accounts. We have been doing some auditing and see too many admin accounts out there and are targeting specific users on specific remote/off site Macs. I have seen scripts that target all users except "admin123" and demote everyone else but that admin account. I need to specifically target a user by account name. I am not a good at scripting, which I why I am asking for help. Appreciate any feedback or suggestions.Thank You.
Just checking if anyone might help me find what I am overlooking.We got a new Cloud-instance and the migration is done. I would like to populate/edit the computer name field and has done so with MUT on other JAMF instances. But I´m getting a 401 error. The data loads in MUT and everything looks fine but when submitting the data to Cloud the log shows this and just runs threw the file without any PUT being set. </html> 2023-02-23 12:36:03 [INFO ]: Submitting a PUT to https://xxx.jamfcloud.com/JSSResource/computers/serialnumber/xxx 2023-02-23 12:36:03 [ERROR ]: Failed PUT. 401. 2023-02-23 12:36:03 [ERROR ]: <html> <head> <title>Status page</title> </head> <body style="font-family: sans-serif;"> <p style="font-size: 1.2em;font-weight: bold;margin: 1em 0px;">Unauthorized</p> <p>The request requires user authentication</p> <p>You can get technical details <a href="http://www.w3.org/Protocols/rfc2616
Hello,I am very stupid because this topic has been talked earlier, but I haven't been able to find it. My question is: Can you run two MDM solutions at the same time? I have both MS Intune and JamF available to me and I was wondering if it was possible? I don't think it is, but I want to make sure. TellCulvers
Happy Friday everyone! I'm sure that I'm probably missing something very obvious to the right person... My experience with bash is currently limited (hopefully not for too long!). I'm trying to mount an SMB share using the below script, there is more to the script, however I've removed it as I know the issue lies in this part.If I run the below locally on my machine replacing $3 with $USER the script works perfectly and the Apps share maps straight away. #!/bin/bash mkdir /Users/$3/Apps mount -t smbfs //userName:userPassword@myServer/Apps /Users/$3/Apps As soon as I deploy the above from the JSS and perform Sudo Jamf Policy on the targeted machine it creates the directory Apps and somewhat mounts the drive. The directory stays as just a folder and does not change to the intended SMB share, as soon as you click in it the folder then disappears and takes you up a level. If I run df in terminal you can see the SMB share is mapped to the folder created, run ls and you se
Hey guys, I have an old Mac 2018 that I wanted to add to ABM, I deleted .AppleSetupDone sudo rm /var/db/.AppleSetupDoneand I thought I would get the setup assistant but no, instead I got the login window, after I enter the password of the account it logins then reboots again and so forth !!it's like running in a loop, can't boot to the desktop and can't get the setup assistant !Any ideas please?
HelloI'm currently working a job where I need to connect several iPads to a jamf pro network. These iPads are either brand new or being formatted after previous usage. There have been details given to me on how I would get them to connect to jamf but there has been an odd batch that refuses to be picked up by the network proper.What I mean is when I input the proxy settings for the iPads, usually it would detect the jamf server and enroll into it. However I have been having an issue where it doesn't give me this at all and goes through a standard iPad set up procedure. I've formatted the iPads over and over again but results are generally the same.Is anyone able to determine my problem?
I'm currently working on the Jamf 100 course. Is there a simulator I can use to do the practice sections on Section 3 Lessons 19-21?
I’d like to get some more information on the recommendation for this setting from Jamf. A dedicated Password was the only option when we initially set this function up. I agree the concept of a randomly generated Password for each account makes sense going forward, but I would like to know if this change is added, whats the impact, and does this affect existing enrolled devices? Any recommendations?
We have started seeing an issue lately where devices get stuck on the Jamf Connect screen. It stalls on the part where it states "Passing command and control to Jamf Pro" and even after multiple reboots it gets stuck there. The most recent one was our CIO who got stuck at that screen after updating the OS. Previous users randomly just got there after rebooting.Has anyone seen this?
I have a new field tech whose LDAP account I need to add to several policy scopes. The policies are scoped using Static User Groups, and up until today have never had any issues.I can add the tech's LDAP account to the JSS console (Settings/User accounts and groups) without issue, so I know the LDAP lookups are working as expected. The tech has the same privilege set as all of my other field techs.I watched the tech log into the JSS console and self service app, so the LDAP account is active, they know their password and the login works.Our JSS is hosted in the cloud w/ Jamf Infrastructure Manager, which passes all communications tests, and we are using SSO with external 2fa, all of which works fine.What I cannot do, in any way, shape or form, is add the tech's LDAP account to a scope or a static group.When I try to add to a Static user group, I edit the group, go to "Assignments" tab, where I see a list of all users that can be added, enter their LDAP account to the search
I see that we can add assets like computers/iPads etc with a formatted CSV. I am looking to add over 650 printers for our college to JAMF. Ultimately want to have a new user who is receiving a new laptop have the appropriate printer assigned and the drivers installed. Being I have so many printers to add I was hoping that I could add them via a similarly formatted CSV but one for printers instead of the one for general assets. Thanks
For anyone that prefers to make Safari updates available via Self Service, here are the standalone Safari 16.3 installer download links extracted from Apple's Software Update Server catalog...Safari 16.3 for macOS Big Sur: http://swcdn.apple.com/content/downloads/57/34/032-13764-A_MOC2MSOQDD/v6gxu8f0t7pbxigu3bvlc269yyxunn7zvn/Safari16.3BigSurAuto.pkgSafari 16.3 for macOS Monterey: https://swcdn.apple.com/content/downloads/38/31/032-14452-A_5QLICQ7S0D/2ia268vj0urmw8tvwez004ngyeg0fepqse/Safari16.3MontereyAuto.pkg
I've created this script in an Extension attribute but it's not showing.#!/bin/bashecho "<result>$(system_profiler SPPowerDataType | grep "Maximum Capacity:" | sed 's/.*Maximum Capacity: //')</result>"exit 0Could someone see what's the issue?
First time poster, looking for any help/direction.I have shared iOS devices that have a general use email account. I had everything set up using profiles and Exchange Active Sync with no issues. Username, Server, Password was auto installed on each device.We have recently moved to O365 and I'm unsure how, or if I'm able, to add a password to the email profile using either native iOS Mail or the Outlook app.For iOS Native Mail, is it as simple as changing the server URL?For the Outlook app I found a String parameter that will grab the email address from the device's User & Location Tab, but nothing for the password.Thanks in advanced!
Hi everyone, I know this is a swarm of bees, but... Is it at all recommended to use Patch Management to keep macOS up to date for cases where Software Update insists there are no further updates (from 13.0 and 13.1 for example). If it is recommended, what PKGs should be used? Certainly not the InstallAssistant.pkgs, right? And deltas, do you really set up incremental updates for each delta pkg? At least the Apple macOS Ventura patch management definition lists minimum OS 13.0 for all of the versions (and "Reboot required: No"?!) but which pkg could that possibly correspond to? ORShould we just consider Jamf Pro Patch Management to be a placeholder, a tracking method, when it comes to macOS versions?
Is it possible to deploy the youtube app but restrict its contents to certain channels. Would this be possible via plist? If so, anyone knows of Youtube's plist syntax?Tried the content filtering using safari. But even though I input a specific URL video link, I am still able to access the whole of youtube.com
I'm looking for a way to create a Smart Group in Jamf based on a large list of serial numbers via the API. For example, when I have a large amount of end of lease iPads to decommission, I'd like to be able to quickly create a Smart Group containing those serials using the API, rather than creating a Smart Group via the GUI and manually inputting a massive list of serials. I've seen some helpful posts explaining how to create a smart group via the API, just checking if someone has achieved something similar before I look into this further. Thanks!
Hello,I'd like to show the Data Disk Used in percentage on an EA so that I can extract a report with all my computers and how much percentage of our users are using their disk drive. I just can't find it in EA templates and the boot percentage is not what I want. Thanks
Hi there,I'm struggling. We are a vocational school (~1000 devices) and some of our students don't shutdown their Macs correctly (every day). They are still logged in or just did a logout but didn't shut down the machine.So I decided to script against that problem to save energy. My solution is:a script is invoked by an LaunchAgent every 5 Minutes the script checks the iMacs idle status if it is more than 20 min a jamfhelper dialog is shown to inform the user (with a timer to react)if the dialog it not canceled it (should) shutdown the MacI decided to use an LaunchAgent, because the dialog should also be shown if nobody is logged in (loginwindow).The problem is: shutdown has to be invoked with root privileges and LaunchAgents runs in user-context.Does anybody have an idea to get around this without giving all students root privileges (they aren't in the soduers file)
Good morning!I am trying to open up to view the contents (not install) of a pkg that is a part of the DEP process at my school. I downloaded the pkg (and cached it) from Jamf and I tried to Convert to Source using Composer but it fails. I have also tried using terminal using the 'pkgutil --expand' command and that fails as well. I also tried SuspiciousPackage app and that failed as well (The document “depnotify-with-installers.pkg” could not be opened. The item “depnotify-with-installers.pkg” is not a macOS Installer package, or has been corrupted or modified.).Any advice on how to view the contents would be great. I'm a semi-new Jamf Admin (6 months in this role) and I want to figure out what is being installed (this way I can edit it if need be).*I will add that I normally find cached pkgs in the Waiting Room folder and this time around I found it in Receipts (not sure if that matters).Thanks!
Hi, I see that a growing number of organizations are migrating on-premise AD to Azure AD. Therefore, I decided to share our experiences using Azure AD as a authorization provider for Jamf Pro. First, LDAP is necessary in order to get user and group lookups to work. This means, you have to set up the service Azure Active Directory Domain Services with external LDAPS support. At this time, this service is available for all Azure subscriptions except CSP subscriptions. It is easy to set up, but requires a DNS entry (a name that points to the public IP address of the new LDAP server) and an SSL certificate that works with the given DNS entry. So, with this working, you need to know that LDAP login with Azure ADDS is possible, but the users' passwords must be reset before it works. Also, the new passwords operate on another time schedule than Azure AD's password policy, so they may stop working. Bottom line: Don't use AD LDAP as login mechanism in Jamf unless you really have to. But use
Hi Community members,I am the IT and Apple Support Specialist for a high school with just under 900 students and have 300 classes in Apple School manager / Jamf School.Has anyone come across a way for me to view which teachers enabled restrictions on a particular student? Say a log of some sort like we have an audit log for changes made in Jamf School. Perhaps there is a way to do it through the API?I say this because there is often a case where several students come to me and says their apps are missing, so I remove teacher restrictions and they are back. This often occurs when a teacher forgets to leave a class and clear restrictions on either Jamf Teacher or Apple Classroom after their lesson ends. I need to check the logs and see whether it is any specific teacher that does this.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!