Get Support
Recently active
Hi everyone, acutally I got the problem, that on FileVault encrypted Macs the input menu for keyboard layouts won't show up in the boot screen. The setting for the keyboard input menu is located in /Library/Preferences/com.apple.loginwindow with the key showInputMenu and a boolean value. If I try to set the value via defaults write, the checkbox in System Preferences is active and the input menu is shown in login window. BUT if the computer is FileVault encrypted, the input menu won't show up in the boot screen. Only if I set the checkbox manually in System Preferences, the input menu shows up in loginwindow and in boot screen. I tried Composer to evaluate which files are changed during clicking in System Preferences. The only valuable file is /Library/Preferences/com.apple.loginwindow. Does anyone have the same problems? Thanks in advice,Michael
Hi All, Our Adobe user base is around 300 and they do not have admin rights on their machines. I changed the deployment package to Self Service to allow the non admin users to install updates. If the users are already using the non admin Adobe Manager and then install the new Adobe Self Service one from Jamf Self Service, will this allow them to install updates with their non admin accounts. ThanksSimon
Hi All,im using the Content Filter ( Built-in: Limit Adult Content ) in jamf-PRO, to prevent private browsing in Safari,it's works but has presented me with a few issues.. eg. it blocks seems to block PDF's and also works like "straight" "pollen tube" "tube" With the message.Restrictted Siteyou cannot browse this page at "google.co.uk" because it is restricted.
Hello Everyone,My company is slowly moving into the Apply ecosystem and I was put in charge of setting up MDM with Jamf. I do already have some good experience with Apple itself from previous days working at the Genius Bar. But, not at the enterprise level. I want to set this up right initially so that it makes the lives of everyone else that interacts with it easier.I've gotten the bare minimum done(Setup Apple Business Manager, Jamf 100 cert). And we plan on using In-Tune for identity management. Which, at the moment will mainly be used for iOS devices.As the title says above, what are some best practices that I can follow now? What Automation's feel like magic? What pitfalls should I expect to run into?Any tips would be greatly appreciated.
Hi all, how do you all manage/handle the Azure AD registration, specifically on end-user devices?We've finally been able to get the registration to work, so objects are created in AAD and evaluated for Conditional Access. But the process is a bit fiddly. For example, if you don't press 'Always Allow' on the certificate box, it can kill it all.How do you all handle it in your environments?Thanks
Hi All,We have been able to get our AAD Registration to work again, so users can enrol their device with Azure, Azure deems the device is Compliant, and satisfies Conditional Access/allows users to sign in.Prior to the 10.43 update, this process would create an object in Azure AD under the user's name, and it would also show in Intune, with the "Managed by" field showing as Jamf. It would also create an attribute in Jamf Pro for the "Computer Azure Active Directory ID".After the 10.43 update, an object is still being created in AAD, and marked as Compliant, but I'm now not having anything come up in Intune. Not the end of the world, but we're also not getting an attribute in Jamf Pro now for the "Computer Azure Active Directory ID" - this is more problematic, as we use Smart Groups to determine which devices have registered - now we don't have any visibility of this in Jamf Pro.Has anyone seen this since the update?Thanks in advance.
Is there a way to use a configuration profile or script to disable browser caching similar to manually going into Developer tools and selecting "Disable cache". We have several remote Macs we want to disable browser caching on and would like to do it through Jamf.Thanks
We have our macs setup with a local admin account and student login with their AD info and creates a mobile account. Does anyone have a script they use that works to delete all the users minus the admin account?
My users are facing issues after Jamf connects is installed and the password sync.Once they restart or log out when they go back to login they are getting a choice of 2 accounts. When they select their previous account they are unable to log in however when they select the new account which is their Okat username why are now able to log in however since it's a new profile they have no data. Is there something that needs to be once to the config profile?
Today, Apple released macOS 13 Ventura. While many orgs may be ready to upgrade today, others may need time to do final testing and/or get verification from your vendor on the compatibility of your software. Apple has made some major improvements in the software update mechanism to make installing Ventura easier and faster for users. Instead of forcing the user to download the full installer and running it locally (like previous upgrades), a computer running macOS 12.3 or higher will perform the upgrade like a software update and only download the changes. In my testing, a full installer was over 12GB, but the new update only required 5.5GB of download. This is great news. However, there is a bug that Mac Admins needs to be aware of. Because this new upgrade process acts like an update, macOS 12.3 - 12.6 were only respecting the Minor Deferral time for Ventura, instead the Major Deferral. If you have different settings for these two deferrals, you may be surprised to find tha
I am new to Jamf Pro. I would like to get Mobile devices to enroll using a prestage or enrollment customization login.I have tried "require credentials for enrollment" , "SSO" and "LDAP" in enrollment customization. This options only work for direct users. I am using Azure Identity Cloud services. Which works find if i am searching for employee names and adding groups.
I'm having some trouble getting a few macs to report correctly on their firewall status. I've verified that the firewalls are enabled on all machines, that the firewall config profile is installed, but still getting several reporting back that the firewall is not enabled, which is messing with our security reports. Has anyone else run across this and have a fix? From everything I can tell, the report filter is correct, and the devices show enabled. Don't know what I'm missing here.
The DEP process where I work doesn't allow MDM Profile removal on some Mac devices.Which is fine etc....But currently after a Cyberattack in my organization my JAMF instance is offline.I need to remove the MDM configuration profiles as something in there is stopping our Trend Micro product from launching to configure its disk access, system extensions and so forth.I've booted into recovery, disabled SIP, gone into /var/db/Configuration Profiles, removed the files as suggested in a number of places online.They seem to have disappeared, yet the Trend application still refuses to launch to configure itself.I am completely stumped. Does anyone have any suggestions?On a machine that allows the MDM profile to be removed this removes the profiles and everything works as expected.They seem to
We're using erase-install v.28.1 and in testing so far it's been great, really enjoying the new script and swift GUI. I want to know if anyone else has used this or something similar in conjunction with a terminal command to delete the machine calling the script from Jamf. In this use case, the machine in question has a Self Service button to initiate a Factory Wipe, and we would like to call --postinstall-command that essentially runs: sudo jamf delete_computer ID=XXX where the machine we're running the command from is the one in question. I've tested a few 1 line commands in " "s and they work, but I've not tried including a small script inside yet. Unless there is an already easy way to show the machine's ID in a single line, I figured it would have to be nested in a small script, I just haven't put down the time yet to test, curious if anyone else has already done this or something similar.
Is anyone else having problems with using the feature in JAMF Admin for "Install only if architecture type is". It does not seem to work because it will not save the setting. The behavior from the application is it lets you set the setting, save. But then when you quit JAMF Admin and open it backup then open the same package you just saved the setting for it is not there. Currently using JAMF v10.43.1
Good morning, I've been looking into ways to get away from AD binding and have had some mild success in testing the SSO extension with Kerberos. I've found that i'm successfully getting a ticket and the majority of functionality is working as intended. However, I for the life of me have been unable to get it to prompt me to sync my local password with my AD password. I've created a brand new local account, and signed in via my AD account to the Kerberos app. I've tried this in Catalina and Big Sur to no avail. I've never been able to get that dialog to appear. Anyone run into this and have any ideas on how to resolve?
Hey everyone,Having an issue with jamf app catalog installations. Some machines just seem to randomly not want to install the app. These machines are very similar, it's a computer lab, but one machine will install successfully and its neighbor will fail.My question is how do I investigate this further plus all I see in the console is that it failed with no real information and also has anyone else experienced this and was able to fix it
We recently set up our JSS instance to use G Suite for Single Sign-On, following these instructions: https://www.jamf.com/jamf-nation/articles/440/configuring-single-sign-on-with-g-suite-google-apps Everything is working well, except after a certain amount of time, the user starts getting SSO errors like this when attempting to log into JSS: "An error occurred while processing your Single Sign-On request. Contact your administrator for assistance." When this happens, it appears that the only way to fix it is to log out of Google and back in, which is not the ideal user experience. It also prevents us from being able to use authentication in the Self Service app, since there's not an easy way to force a Google logout inside of it. I haven't tested the exact timeframe, but I believe this occurs after the SAML Token Expiration (which is defined in the JSS as 480 minutes). I can increase this, but I'm not sure what the ideal setting is, or if increasing it would just postpone this issue
I'm trying to make things really simple for our users with a script that does quite a few things, including enrolling them into the JSS. It seems to me that the easiest way to do this is to push a script onto the computer, put a LaunchDaemon entry into /Library/LaunchDaemons, and force a reboot. Up to this point everything works fine. However, rebooting AFTER the script does its thing invariably fails. The system log says: com.apple.xpc.launchd[1] (mil.navy.spawar.sd.stage1[113]): Service exited with abnormal code: 2 The timestamp is precisely when the "shutdown -r now" command is issued in the script. The script's process does get shut down, but the computer does not get restarted, and I have no idea why. Does anyone have any ideas as to what I can check?
Hello,We have an issue where we have an old version of Sophos which encounters automated installment issues when encountering Ventura versions of MacOS or carbon chipsets. In order to update the current 'SophosInstaller.pkg', do I need to manually create the new .pkg file? I downloaded the current version of Sophos Endpoint Protection but there are no .pkg files in the zip. Then I am reading that I need to create the package that contains all the necessary components and scripts. Is this something I can find that is pre-created to mitigate the hassle of figuring out how to create the .pkg file myself? Thank you for any help!Kerry
using jamfpro with office 365 for mail/calendar/contacts syncing and using the built in mail/calendar app for apple iPhones. How do I go about seeing shared calendars. Is this a issue with the apple built in calendar app? Would we have to use outlook app to be able to see shared calendars?
Hi all, Don't know if anyone observed this, or even care.Within JAMF inventory, any Macbooks running macOS Ventura will show random .0 to end the OS version number. Eg:13.113.1.013.213.2.0My observation is this is completely random. It doesn't matter if the Macbook is an old Intel, or the new Apple Silicon M1/M1Pro. It also doesn't matter if the Macbook was upgraded to macOS Ventura, or reimaged directly to macOS Ventura. The ".0" appearing at the end is completely random.What give? And does it even matter?I am thinking for the future, what happens if macOS 13.2.1 comes out, and I need to find all Macbooks 13.2 or older. Do I need to have seperate scoping because there's 2 ways to identify 13.2 & 13.2.0 ?
Hi folks, looking for a bit of help. I’m trying to update a custom extension attribute called "Lifecycle Status" for Jamf Pro Classic API by its serial number. xml = """<extension_attributes><extension_attribute><id>67</id><name>Lifecycle Status</name><type>String</type><multi_value>false</multi_value><value>Active</value></extension_attribute></extension_attributes>""" headers = {"Authorization": f'Bearer {token}', 'Content-Type': 'application/xml', 'Accept': 'application/xml'} res = requests.put(url, data=xml, headers=headers)res status from PUT is 409 error - "Conflict" : The request could not be completed due to a conflict with the current state of the resource You can get technical details http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10.4.10
Greetings, My apologies if this has already been discussed, searching this is very vague and I haven't found exactly what my goal is. Essentially I have a policy I want to flush, but I only want to flush it on a specific group or smart group. I can't find an interface option for this, I would think an option inside of the "Actions" menu would be ideal (Feature Request?). Does this require a script that runs a jamf policy command? I've found in older discussions that you cannot flush a single policy from the jamf command line, only the JSS web interface.
We recently setup federated MAIDs using MS Azure. We have a group of users needing to use iMessage on their district iPhones. iMessage and FaceTime are allowed in the profile restrictions. iMessage is enabled in ASM. Toggle is grayed out on phones. In ASM users are listed as students, but are in fact staff. Any help would be appreciated.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!