Get Support
Recently active
Does anyone know how to add apps to groups of ipads? I have several groups representing grades ( I work in a school district) for ipads. If I have 7 ipads per grade and I want specific apps for those 7 ipads, how do I set it up in jamf pro?Thanks
My company has been using Jamf Pro Cloud version since 2021 and I heard that every Jamf Pro Cloud version are entitle for 1 free sandbox environment.Is this true? If so, what is the process to set this one up?
Hi, I have 700+ macs that need timemachine backup (around 1TB each), but we have NetApp that is not AFP2+ compatible.Anyone has a solution that is scalable and Enterprise oriented for Mac backups in-house?Thanks Carmelo Lopez
I need to manage 2 macs, our Windows devices are in Azure / Intune. I'm looking at Jamf as I've heard its the best solution for macs.We only have 2 devices and a small business so was looking to use Jamf Now but have a few queries on this setup... Does Jamf Now work with Intune, all the documentation points to Jamf Pro?Why do you run Intune & Jamf? They both seem to be similar in what they do (encryption, policies, etc)Is it viable to just use Intune when its just a few macs? One key thing is we want them to sign into macs using AzureAD accounts?
We are looking for Laps implementation for our MacOS. we utilize jamf pro and jamf connect.our Macbook is binded to jamf connect. I had a look of MacOSLAPS however this solution require AD integration.is there another reliable laps solution that doesnt need AD integration?we do have intune subscription (but we only use that for our windows devices)
Is anyone able to remotely update iPadOS with Jamf School?I'm testing a 14.6 -> 16.2 and left it over night to fail.Jamf School cannot determine the OS update status. The update likely failed on the device.There is no passcode and it was left plugged in.
Hi all,Is anyone know if we can retrieve the "enforcedSoftwareUpdateMinorOSDeferredInstallDelay" from the com.apple.applicationaccess?
Clicking on an 802.1x EAP-TLS network in the Network Selection pane of the Jamf Connect login window prompts an end user for their username and password then blocks them from joining the network.This has been a known issue since 2.11.0--- because of this we can't use wifi connection using SCEP or AD creds at the login page (confirmed by Jamf Support).We currently use mac address whitelisting (with Clearpass) as an interim, thinking this would be resolved soon, but after doing some research and seeing how many versions this known issue has been a part of--idk if Jamf has any plans to fix this in the near future.Has anyone used another method of authentication for wireless besides regular PSK or mac address whitelisting that has worked with Jamf Connect at the login page?
Hello all,We enrolled a macbook pro via enrollment link. The MacOS is ventura 13.2.1. Everything looks to be ok except for the fact that the mac is not showing up in the JAMF console. Has anyone experienced this before? We have also unenrolled/deleted the profiles and re-added and still no luck. Thank you for your help!
https://tomsoderling.github.io/Disable-iOS-simulator-connections-popupI have a user that has asked to use this script (above) in order to prevent the annoying popup from appearing each time, however upon testing I get the following:Firewall settings cannot be modified from command line on managed Mac computers.> Add Xcode as a firewall exceptionFirewall settings cannot be modified from command line on managed Mac computers.> Add iOS Simulator as a firewall exceptionFirewall settings cannot be modified from command line on managed Mac computers.> Re-enable firewallFirewall settings cannot be modified from command line on managed Mac computers. A config profile exists to prevent everyone from turning off the firewall. I would like to use this script but unsure how to amend it in order to get it operational - is anyone able to offer any advice please?
Hey y'all, a query for the hive mind. We've been running into users installing Awesome Screenshots (horrible name), which beacons out to websites tens of thousands of times a day. As you can imagine, InfoSec is not happy about it. I'm trying to find a way to do reporting to find out what extensions are installed on machines. I found that the extensions are all stored in the same folder: ~/Library/Application Support/Google/Chrome/Default/Extensions/ But the names of the folders with are just random strings of letters and numbers:external image link Within the folder is a manifest.json file, which does have the app name in it:external image link So I'm assuming there is some way to grab that and throw it into an extension attribute or something. I think the main problem would be navigating through those extension folders, or at least finding a way to translate those folders into extension names. Has anyone found a way to successfully report installed extension
HelloI want my students to use emojis to represent themselves. The keyboard is present, but the function is disabled.I have opened the rights to iMessage and FaceTime so as not to limit the user.The emojii keyboard is still not working.
Hey Guys, as the subject header implies i've been trying to figure out how to configure multiple language locales. The thing is for my nudge policy i've created a custom message that the employees will get when they get the nudge, the thing is if i dont configure a user language locale it wont display my custom message but rather a standard one. And if i do configure a language locale it seems im only able to set one. Does anyone know how i cant set multiple user language locales so they all get the same message no matter which language they use?
In large enterprises and organizations with thousands of computers, it’s often necessary to break up software deployments into more manageable groups. Need to push a configuration profile out to 5,000 devices? You might want to break that into chunks of 1,000, so you don’t hammer your Jamf Pro server. When I was a customer, we had over 17,000 devices in each of our Jamf Pro instances, and we often wanted to deploy software in stages. Right now, there is no built-in method to do this in Jamf Pro. So, I came up with a way to generate semi-randomized Smart Groups by utilizing the UDID of the device. The UDID is a 32-character identifier (Unique Device ID) that all devices have and is what Jamf Pro uses to uniquely identify all devices. You can view a device’s UDID by navigating to the device’s inventory record and selecting Hardware from the sidebar. Each UDID contains HEX characters, which means 0 through 9 and A through F. Using a little bit of REGEX-fu, you can create a Smart Group th
I've been out of the Jamf loop for a little while in a company migration to Windows. Our parent company though wants to use our Jamf cloud to manage some Macs not setup in our DEP. It's about 150 machines and I know recently the Recon app was killed. So no QuickAdd packages or network scanners anymore from what I can tell. So I guess what I'm asking is, is the enrollment URL really the only way for Non-DEP machines to get enrolled? I'm sure I'm asking a dead horse question but couldn't find any comments in the forums. Thanks in advance for any ideas to make this more efficient than relying on users to enroll or bring in their machines one by one.
Jamf Cloud customer. Hybrid worker (partially at home, partially in the office). When I work from home, I can't upload Packages. I have Xfinity 1GB service and their Gateway router. No issues when I'm working in the office. The Package starts to upload, then stalls somewhere between 1-3% and just hangs indefinitely from that point. This happens both in the Jamf Pro cloud admin console, and when using the Jamf Admin application. I used the Xfinity App to setup port forwarding for ports 548/445, but I can't select AFB/SMB as a protocol. (Administrator work station connections: https://learn.jamf.com/en-US/bundle/technical-articles/page/Network_Ports_Used_by_Jamf_Pro.html) Jamf support is blaming Xfinity. Xfinity won't give me time of the day because the computer is connected to the internet and reporting no issues with their troubleshooting tool. Before running out to buy my own Router/ Modem, is there anything else I can try?
I created a guide on how to setup users account pictures via Jamf Connect check it out.https://www.ericsontech.com/2023/02/set-account-pictures-via-jamf-connect.html
I’m trying to enable lost mode and play sound on a group of iPads. I’ve found a way to enable lost mode, but I can’t figure out how to also send play sound command. xmlData="<mobile_device_command> <general> <command>EnableLostMode</command> <lost_mode_message>$lostModeMsg</lost_mode_message> <lost_mode_phone>$lostModePhone</lost_mode_phone> </general> <mobile_devices> <mobile_device> <id>$i</id> </mobile_device> </mobile_devices> </mobile_device_command> See here for full script: https://gist.github.com/talkingmoose/f44d0d87d08b48daa0e887a6239c1766
Hello! So, Currently I have been having issues with Naming of machines, this isnt happening on ALL the machines just a handful and i can't seem to fathum why... I'm using a policy that has a reccuring check-in, using the maintenance 'Reset Computer Names' to make the changes in jamf transfer onto the machine in question. Now, the names will change in jamf but after a few days it will revert back to something like 'imac(8)' and not what i previously set... Any help?
We are in the process of moving away from Enterprise Connect and pushing out the built in SSO. I was hoping there would be a way for me to see the logged in user for the SSO like I do with Enterprise Connect. I know it's just an extension attribute that grabs the logged in user from the EC app but I don't know where that data is stored for SSO. I just want another line like in the picture below but instead of Enterprise Connect, I want SSO Logged in User
I don´t know if there is a way to remove this, but If I make a update to a configuration profile and apply it to all devices, the screen of each device when the new configuration profile is pushed out is way of "flashing/refreshing" in a second - and quite annoying if changing scopes etc Is there a way to disable this. Can not understand why a configuration profile update must do like this as
After consulting with Eset, I've written the below Extension Attribute to spit out the version of Eset Security installed. When I try that script in terminal I get the result: 6.7.654. When I create a smart group in Jamf with operator is and value 6.7.654 I don't see any results in the group. In Extension Attribute I've chosen: Data Type: String and Input Type: ScriptIn short, the script does work but Jamf doesn't like it as Extension Attribute. Any idea? The script is: !/bin/bash esets_scan="/Applications/ESET Endpoint Security.app/Contents/MacOS/esets_scan" if [[ -e "$esets_scan" ]]; then esetversion=$("$esets_scan" -v | awk '{ print $5 }') echo $esetversion exit 0else echo "Not Installed"fi exit 0
Hello all,I wanted to share something that we ran into in the last week in case it helps another Mac admin. We use Google Workspace and Microsoft Edge as our default browser. Over the last week, we've had multiple reports that drag and drop attachment uploads were becoming "corrupted", but attachments using the file chooser dialog worked just fine. We discovered that since the release of Edge 110.0.1587.41, if a user has "Show all filename extensions" unchecked in their Finder preferences, drag and drop uploads would remove the extension from the file, even if it actually has one. I've confirmed this behavior across multiple sites that utilize drag and drop uploads. Enabling the Finder setting resolves the issue, and we've reported the issue to Microsoft.
Good morning,I wanted to share something we ran across in our environment over the last week in case it might help another admin.We use Google Workspace and Edge as our primary browser on macOS, and in the last week, several users have reported that drag and drop attachments were becoming "corrupted". We discovered that since the release of Edge 110.0.1587.41, if a user has "Show all filename extensions" unchecked in their Finder settings, drag and drop uploads would remove the extension from the file. Enabling the setting resolves the issue. I've sent feedback to Microsoft.
We have a few systems that are no longer communicating with Jamf pro. We are at the point were we need to re-enroll these systems. These are live systems that we do not want to wipe. What is the best way to re-enroll?Running: profiles renew -type enrollment locally on the systems? Does the MDM profile have to be removed before this command is run? Is there a need to delete the computer out of Jamf first? Most systems are 11 or higher though a few are on 10.15.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!