Get Support
Recently active
I'm trying to set up a dashboard in PowerBI and seem to be hitting a roadblock with the Jamf API call. Specifically, when I go to attempt a call in PowerBI to site/JSSResource/advancedcomputersearches/id/# using JSON, I get: DataFormat.Error: We found extra characters at the end of JSON input. Details: Value= Position=0 The data returns in Postman if I test my API call there, but for whatever reason PowerBI doesn't like it. If I change the output to XML, some data comes back, but it's just the computer name and ID number, and doesn't include the other fields that I have set up in the Advanced Computer Search (extension attributes) that I'm actually interested in. I do get the column headers though, but they come in as a separate table, but none of the data related to them. I'm inclined to think it is indeed a PowerBI issue and not a Jamf issue, but I'm curious if anyone was able to get around this if they experienced it either with PowerBI or another tool that leverages API
I guess I don't have a connection to our iOS devices after renewing the push certificate, because of a wrong Apple ID.I have to re-enroll all devices, there are only 20, no problem, but the problem is, that there is a MDM Profile on the devices which I can't remove because, Jamf doesn't have connection to it. When I tried to re-enoll there is a error msg that I have to delete a profile with a MDM-Payload. Can someone help please?
I have an Excel file that I'd like to automatically retrieve Smart Group count information. I am eventually want to build charts in Excel with that data. If retrieving count info is possible, what steps do I need to make that happen? Thank you in advance!
Hi, I'm using JSS v9.92. I am trying to utilise some User-Level Configuration Profile (specifically, passcodes, but that's not important). I am testing on 3 Macbooks. One out of the three have a vaild "MDM Capable Users = local-user" within the Macbooks' General information. The other 2 have "MDM Capable users = <blank>" When enforcing the User-Level Configuration Profile, only the one with a valid MDM Capable User received the profile. The other 2 received nothing. Does anyone know any commands or how to fill in the MDM Capable Users fields within each computer? I've search JAMF Nation, all I read were people wanting to delete it.
Hello, wanted to ask if there was a way once a machine is done with the enrollment process it would log or restart to signal that is done with all policy's and profiles.
We will be replacing approximately 900 student ipads this year. Would anyone be willing to describe their workflow tips/processes for wiping the devices, deleting Jamf inventory records and releasing them from ASM? thanks in advance.Dale Beachy
This used to work and it is all of the sudden not working, preference is, to create the admin account in the Pre Stage and then skip local account and when prompted by a login screen be able to login as the AD user. As stated this was working, however it now is prompting to create the local user. Ideas?
Is there a way we can query a computer for its locked or unlocked state? I'm familiar with endpoints to get the command status.../JSSResource/computerhistory/id/{id}/subset/commands/JSSResource/computercommands/name/DeviceLock...but neither of these tell me if the device has been unlocked after it was successfully locked
All of our students have Macbooks and many of their parents set up screen time settings on their Macbooks using an Apple ID that's connected to their family account. Every so often, we run into the issue of the parents restricting apps that they need to use during the school day. Is there any way to prevent this using Jamf? Or is there a way for us as admins to go into the screen time settings and unlock it without the parents' passcode? This is mostly an issue with Macbooks running Monterey, although we do still have some with Catalina and Big Sur. We have experienced this issue with the older OS's as well. This is at a high school grades 8 - 12, so this mostly affects the 8th graders.
Hi All, Is anyone seeing issues with macOS Software Updates since 11.5? Specifically updates showing as not available when no deferral set and when showing available fail with "An error occurred while downloading the selected updates. Please check your internet connection and try again", in this instance only booting into safe mode resolves it. Thanks,Andy
Hi Everyone, With the announcement of the latest zero day, how is everyone going about upgrading there fleet? I have a policy to delay MacOS Minor Version for 30Days, Would that not delay our users receving this new update? or does enabling the box "Allow devices to install Rapid Security Responses (macOS 13 or later) " allow this to happen? Curious to know how everyone else is handling it. Worse case scenario I can remove the Delay 30 days policy upgrade and put the 30 days back into place
I don´t think I am the only one, but before in Catalina and earlier versions, it was possible with jamf connect in DEP deployment to login the user so a user account was created on the computer -and the user account was mdmcapable, so user certificates could be used (through ACDS) But now in big sur accounts created in jamf connect cannot anymore be mdmcapable, as the command does not exist anymore. So just wondering what are other doing to solve this issue ? or rather is there other workarrounds ? I actually thought of doing a auto re-enrollment of the mac when users enter for first time, as account then will be mdmcapable. But never managed to reach the goal for this, as it may also be a bit to creative. So wondering what other are doing. As Per today our users must create the account manually outside jamf connect starting up the first time. But not very smart way and spelling errors, wrong names etc can be entered there
Hello all,3 of our devices were supervised and managed, but the Jamf records on our end were deleted while the devices were still active. So the devices still have Jamf on the system, but now phoning home is pretty weird. We were able to restore one of the records, but it appears to be only managed now. On this restored record, we are unable to push any commands or policies to the device that are normally available by default (Lock Device, Send Blank Push, etc.).Is there any way to get these devices reconnected to our system, or should we bag it and just re-issue new devices to these users?I'll be checking this all day so please feel free to ask any questions about anything I might have left out. Thanks!
I've found we have about 1500 orphan classes from the previous year which were not cleaned up in our SIS before the import happened for this year. I know how to mass delete all classes using a script but I only want to delete the ones marked as N/A - is that possible?
Hi there, I dreamed up a way to create MDM-enabled users while at the same time using Jamf Connect and I am running in an annoying problem and I seem to not be an expert enough in Azure to fix it... if it is even possible...So I added an ENrollment Customisation Configuration to the PreStage requiring authentication with the Azure Account. That leads to the Mac being associated with the Azure user in Jamf Pro. I then have the PreStage pre-fill the primary account information using variables. Unfortunately I seem to only be able to pre-fill $FULLNAME or $EMAIL and both contain characters that macOS really does not like as a username. (either a space or @). So my question is: Is there a way for me to get only the part of the UserPrincipalName / E-Mail in front of the @ out of azure, through Jamf Pro and into that Account Name field? My plan continues with Authentication to Azure in the Jamf Connect Login Window and then connecting to the just creat
I can see my managed preferences being targeted to the computers in their management tab but I can't find the preferences themselves anymore.
So i have noticed that over the last few weeks my 12.6.2 and 12.6.3 machines are getting the macOS Ventura Delta update not upgrade anymore. Is this correct? I found this when running my weekly softwareupdate -iaR command on my classrooms/labs machines to keep them patched. According to Appel an Jamf this should not be happening. Did Appel release yet another bug? Or is this intended behavior and if ti is intended why only some of the machiens are doign this vs all of them in scope of my policy? While troubleshooting i ran this on a machine manually in terminal and it did it. I forgot to check what the Software Update Pref pane showed before i started, will check a few more machines.
Hi all! We are looking for a way to reduce the sudo timeout period as recommended by the Center for Internet Security. The only solution we can find online is to manually edit with visudo and add: Defaults timestamp_timeout=0 However, we were hoping to script this task and not disable SIP if possible. Has anyone accomplished something like this or am I asking the impossible? Thanks,Jim
HelloHas anyone had any success in disabling WiFi and the WiFi menu. Configuring our Monterey build for our labs environments.Have found a script to disable WiFi but struggling to disable the WiFi menu.Have found a few config profiles on here but can't seem to get them working. I think there for older version off OSX.A config profile would be ideal if anyone is able to help. It would need to work on both intel and M1 Imacs.Thanks
I'm trying to find Macs that have the Device Signature Error - computers where the certificate trust between Jamf and the endpoint is broken. Anyone already have a good way to do this? My thought was to make a Smart Group of computers with at least 7 days between the date of their last check-in and the date of their last inventory update, but I don't know how to get Jamf to compare those two fields. Ideas? Thanks!
Hello friends, So we are a very small team and I am very new to this admin role and we are realizing that we should have done this a few months back, but didn't do enough research at the time. So, excuses aside, here is the issue. We had our users upgraded to Monterey prior to Ventura releasing. We've deferred the updates for Ventura (per the following posts) as we haven't had the time to properly test things in our infrastructure. We also had turned off our forced system update policy that ran updates weekly.https://community.jamf.com/t5/jamf-pro/ventura-will-be-released-as-a-quot-minor-quot-update-bug/td-p/276218https://community.jamf.com/t5/jamf-pro/macos-ventura-update-major-amp-minor-update-deferrals-oh-my/td-p/276347We're still not ready for Ventura (getting a few things resolved, but have only had a couple accidental test cases).So we are sitting at a place where most users are running Monterey between 12.3 and 12.6, so if we turn the updates back on, majority of them
Hi all,Intune and Jamf Pro integration document includes: Important: You must exclude the User registration app for Device Compliance when creating the conditional access policy. Would someone be able to explain which applications should be excluded from conditional access policies?Because there is no app called User registration app for Device Compliance in Azure.My second question is : What is the frequency of Mac's Intune compatibility check?Thanks
Hello! Just hoping someone can help me out here, I currenty work for an organisation that holds about 140 IMacs, Trying to do a more automated switch from Monterey to Ventura, I've noticed that Jamf Pro has the 'Download & Install Updates feature' under management controls, I can send the command off and it will sit in pending commands for 5-10mins then just dissapear and do nothing... Any help would be great, or other solutions for a more remote Upgrade Path....
I am piloting Jamf Connect with Google as our IdP for some students in K-12. (with the hope of also doing staff)Currently if they forget their password, we need to reset their Google password, and then, as admin reset the local password on their computer.This requires physically having access to their computers. There's almost no point to have Jamf Connect if a password reset requires local login to finalize. (Further, after this process, it always requires the "verify" step... I think that's a different issue, but now some students have to type their PWs twice to get in.)Is this everyone else's experience too? Seems pretty untenable. What would people do with a globally disperse workforce where IT can't physically have access to the machine?)Would Azure or another IdP handle this better?
Hi so a few apps that auto update are still asking for admin credentials. We have either VPP or Autopkg grabbing the latest version and installing. Even though the user is on the latest version of slack or whatsapp it prompts them with the "new helper tool" popup. Slack has only been a few users. Though yes we allow our users to use whatsapp and spotify. Even though they are on the latest we still get the popup. Any recommendations?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!