Get Support
Recently active
I am teaching myself jamf on the fly it's going well so far. I just have one burning question. When I go to Devices> Prestage Enrollments> Scope> View should this always be populated with devices? I am just wondering why once the enrollment process is complete why they would stay populated in that list.
We have a few labs with Ventura 13.1 installed and need to update to 13.2. Is there a solution that works that does not require signing into each system, passing credentials through jamf policies to the endpoint, or using a script needing api access ran from a jamf policy? I've tried multiple times to use the "send remote commands" feature and it comes up with nothing when it's all said and done. Under Monterey this worked pretty bad where about 50% of the systems would work each time but under Ventura thus far it's been zilch.Is this common for everyone else or has anyone experienced this and have some insight or fix?Edit: Felt I should elaborate more...the process needs to be done without signing in. When I do the remote commands I can see "AvailableOSUpdates - Scheduled" show up as a pending command. It eventually disappears and nothing happens.
How can we get a User Group started in our area? Thanks in advance!
I want my computer groups to list the computer name, username and last check-in.A while back a co-worker showed me how to list the username, it was some sort of global settingbut I can't remember where it was.Can somebody point me in the right direction to set it so that when I create a computer group it will display the computer name, username and last check-in.Thanks
I have a similar issue to this yet decided to create a new post to hopefully get some assistance.I'm new to provisioning Chrome and don't know the components. Keystone?Basically I created a Composer snapshot on a machine that never had Chrome. I then packaged it with only the Google related settings/folders and I get the error Chrome may not be able to keep itself updated. When I try to manually change the setting on client testing machine after install, I get update errors.I need help to get the Chrome may not be able to keep itself updated banner removed and allow Chrome to auto update for all users, and then provision latest Chrome to all JAMF clients with or without Chrome. I'm hoping to just change a setting file and push that file with the Chrome app.Any help is greatly appreciated.
Hello, I had a config profile in place to disable Find My Mac in all company Macs. This was working as the option was greyed out for all users. With the release of macOS Ventura, this is no longer working and the option is not longer greyed out, and has become clickable. Has anyone else encountered this? Thank you!
I have been testing the Intune registration with Jamf and ran into a bit of an issue.Trying to do the correct workflow for the end user (install company portal in one policy, Self Service to register)However once I start the registration process:Safari Openscert is downloaded (always allow)brings you to a Jamf Self service splash screen about registering a device, where you can select "Register My Device"At this point, Self Service opens and nothing happens. I can click "Register my Device" over and over again, but it just keeps opening Self service and not completing registration.Not sure what is wrong in this process. Any insight would be helpful
I need to find a way to turn on the setting in Chrome: "Always use secure connectionsUpgrade navigations to HTTPS and warn you before loading sites that don't support it" Has any one tackled this before or know a command or plist to edit that will enable it remotely? Any help is very much appreciated.
Hi all, Am trying to create a script to copy files from /Library/Shared/TeamsBackground to the User's Microsoft Teams folder. As a test case, i deliberately do not have Backgrounds and Backgrounds/Uploads folders in the User's Teams directory. When i ran the script, it just went to the last Else statement "Teams Never Ran". I know for a fact that the Teams folder ~/Library/Application Support/Microsoft/Teams exist. What am I missing? Thanks #!/bin/sh CURRENTUSER=`python -c 'from SystemConfiguration import SCDynamicStoreCopyConsoleUser; import sys; username = (SCDynamicStoreCopyConsoleUser(None, None, None) or [None])[0]; username = [username,""][username in [u"loginwindow", None, u""]]; sys.stdout.write(username + " ");'` if [[ -f "/Users/"${CURRENTUSER}"/Library/Application Support/Microsoft/Teams/Backgrounds/Uploads/file1.jpg" ]] then echo "Already copied to the user's fo
I'm trying to send a notification to our users with SwiftDialog. I have set up the notification permission and deployed the mobileconfig with Jamf but it gives me the error "notifications are not available: couldn't communicate with a helper application".What could be the issue?
I am starting to hate macOS Ventura with a passion. Our users who are moving forward with Ventura are being prompted to login to their AppleIDs after they login to the computer. It's a Notification that pops up in the upper right,. The choices are to either click on the button in the notification that will take you to the AppleID login or you can click on the X... that also takes you to the AppleID login. We absolutely do not want our users logging in with their AppleIDs. I can't figure out how to stop this notification so I figured I could do a Config Profile that ONLY blocks access to the AppleID setting and/or the Internet Accounts setting. We are already using a config profile with the Restrictions settings configured. In theory I could just check the boxes to hide those, but we have a number of Macs that already have FindMyMac enabled and I really need users to disable that before I block their access to do so. So I thought maybe I can create a new profile in JamfPro that only con
Hi,I looking for how to enable "Detect Leaked Passwords".Does anyone know how I can enable it by Using Jamf Pro?System Preferences > Passwords > Security Recommendations > Detect Leaked PasswordsScreenshot below.Thank you.
Following on from the removal of Remote which was unbelievably useful and has no replacement, Recon has been removed and with it my ability to create a QuickAdd package to add a system into JAMF which is already set up and in operation.How are people dealing with this now if you did use QuickAdd now and then?
Hi,I'm trying to set the preference for Safari via a configuration profile. Is this possible with a config profile? I can't get it to take on Ventura.Many thanks in advance.
One of the many tasks under my scope is patching of vulnerabilities on macOS systems. Recently every single machine has been flagged for having a vulnerable version of "httpd" to which there doesn't appear to be a path toward remediation aside from upgrading to Big Sur. Alternatively I have been digging through options to see whether I could create an extension attribute which would check and alert me of any systems that have apache running. Sadly all command line options seem to be a dead end as the likely option of running "sudo apachectl status" will just return the following "Go to http://localhost:80/server-status in the web browser of your choice.Note that mod_status must be enabled for this to work." Has anyone else had to deal with addressing this vulnerability, and how have you gone about remediating the issue? Apache 2.4.x < 2.4.46 Multiple Vulnerabilities(Report on Tenable's website regarding the vulnerability)https://www.tenable.com/plugins/nessus/139574 Upgrade or R
Is there an API script that will un-enroll macs from jamf pro? Similar to web Management Commands of "remove mdm profile". I don't need the mac to be deleted from jamf entirely.I want to use the API so that jamf itself sends the MDM command to uninstall the profile. If I create a policy, it will package it up and run it on the device.Is it possible to use the API script to check for machines in a smart group? I want the script to be executed only on macs that have a certain PKG installed on it. Thank you
Up to now, we've been scoping apps either to everyone or to grade level, building, or individual users where applicable. But lately we've been getting a lot more requests from our teachers wanting us to assign apps specifically to their classroom students, and we've been telling them that it just isn't possible currently. Most departments understandably don't want to pay for licenses they don't actually need in order to accommodate 1,400 students across two grade levels when they've only got 150 students taking their class. It's frustrating that a smart device/user group has 200 criteria to filter by except something as useful as "Belongs to Class Name". We've got all our class rosters imported from our SIS into Jamf Pro, and it's unfortunate that nothing can really see them outside of specifically the Classes tab. Am I just dumb? Is there a way to do this that I'm not seeing? If not, I'd love if this could be a feature added in a future update.
Hi everyone,I'm currently trying to run an OS update to my environment for mostly M1 Macs that is supposed to allow my users to upgrade their machines to Monterey (as standard users) through Self Service. I'm trying to avoid the user's installing the update themselves since currently they cannot. Filevault 2 is enabled, and if users attempt to update to Monterey themselves, the error comes up that "You must provide authorization for this volume by setting it as your startup disk." I'm currently testing a Policy that contains two policies:1. softwareupdate --fetch-full-installer --full-installer-version 12.0.1 command to grab Monterey. This first one is working fine.2. I then have a second script set to run after this as follows:echo "adminpassword" | /Applications/Install\\ macOS\\ Monterey.app/Contents/Resources/startosinstall --nointeraction --agreetolicense --user My\\ IT --stdinpassYes, my admin username (changed here to a generic example) has a space in it. It gets applied du
Hi,Wondering if anyone else with Jamf Pro has seen this issue.We have around 1100 iPads on our Jamf Pro install and occasionally individual or groups of iPads will have some or all of the configuration profiles re-pushed to them even when the profile itself hasn't been modified or deployed.As an example a student had our wi-fi SCEP configuration profile re-pushed to their iPad (despite it not having been changed) on the 21st February for unclear reasons the certificate deployed to the iPad was not being used to wi-fi authentication and we had to manually exclude and then re-push the certificate, now this morning Jamf Pro has once again re-pushed the SCEP configuration profile (and all the others) to the same iPad resulting in once again the iPad not being able to connect to wi-fi.We've had the above issue sporadically for 3+ years but in the last month the number of occurrences has jumped and we've had 30+ students unable to connect to wi-fi until we re-push the profiles. Other is
Hoping to get some assistance on an issue I am having. We have a few iMacs that are setup for lab usage (Higher Education). The devices are binded to AD and confirmed. Login is successful. The issue I am having is some students will walk away from the device and not return. I have a Config Profile that will log the student out after 5 minutes. If the student has all apps closed it works fine. The device is logged out and a new student can login. However, if the student has an app open or an update is occurring at the time of force logout the login screen will show the student name in ID field and ask for credentials. It ID field is not blank as it would be if apps were closed. Only fix I see is to power off the device and reboot. Is there another Config Profile I can use or possibly a policy to logout/reboot?
Modified a script that does the same thing for chrome. But this script will download and install the latest version of Brave directly from their web site #!/bin/sh dmgfile="Brave-Broswer.dmg" volname="Brave Browser" logfile="/Library/LogsBraveInstallScript.log" url='https://brave-browser-downloads.s3.brave.com/latest/Brave-Browser.dmg' /bin/echo "--" >> ${logfile} /bin/echo "`date`: Downloading latest version." >> ${logfile} /usr/bin/curl -s -o /tmp/${dmgfile} ${url} /bin/echo "`date`: Mounting installer disk image." >> ${logfile} /usr/bin/hdiutil attach /tmp/${dmgfile} -nobrowse -quiet /bin/echo "`date`: Installing..." >> ${logfile} ditto -rsrc "/Volumes/${volname}/Brave Browser.app" "/Applications/Brave Browser.app" /bin/sleep 10 /bin/echo "`date`: Unmounting installer disk image." >> ${logfile} /usr/bin/hdiutil detach $(/bin/df | /usr/bin/grep "${volname}" | awk '{print $1}') -quiet /bin/sleep 10 /bin/echo "`date`: Deleting disk image." >> ${
Hello, So I am currently configuring these macs for students and staff. I thought when I first installed Google Drive for the Mac it had the Google Drive folder mapped as /Volumes/GoogleDrive. However then it changed it's now set to the "/Users/[username]/Library/CloudStorage/googledrive-[email]"The problem is students have subdomain while staff do not. I want to mount their drive to the Dock like if it were their home drive that was given in Active Directory. I did see that their was a spot in the Dock payload. But I believe that limited to static text? Meaning I cant put system variables like $User?
I’ve pushed the policy to Monterey and Ventura machines but application won’t launch in Ventura due to it being an unidentified developer.Even when I upgraded the Monterey machine to Ventura, it runs into the same issue.How can make it so that it’s able to launch in Ventura? Is there a config file that needs to be setup and pushed out to machines prior?
We have purchased iPhone upgrades for a few of our users. They all came out of the box with iOS 16.X. They are setup in Jamf Pro with prestage enrollments with configurations that do not restrict using messages or having their own individual Apple ID's on the device. We have 1 user who has reset and switched phones 3 times and had their messages populate on their "new" device (which was supervised in Jamf Pro with the same configurations) successfully with the only difference we can find being that those devices were on iOS 15.x at the time. We now have 4 users who have not been able to get their messages to load on their new device and have halted the remaining users from swapping until we can figure this out. Those users all have their settings->iCloud->messages turned on (sync this iPhone) and the manage storage is showing an amount that seems reasonable to what they have with messages. They all are either under the 5GB free limit for iCloud or ar
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!