Get Support
Recently active
Hello all,I have a strange behaviour here: I have enough licences of Pages, Numbers, Keynote and iMovie via Apple School Manager and assigned them to two Smart Computer Groups via "Mac Apps". So far this has always worked, even without the computers being logged in with an Apple ID.Now, however, I update the computers to Ventura and suddenly the Mac Apps no longer install automatically. I have also set the distribution method to "Make available in Self Service" as a test, but nothing happens other than the circle turning.Under the Mac Apps in the History tab, the software is set to pending. I also removed my test computer from the scope, executed "sudo jamf policy", brought the computer back into the scope and executed "sudo jamf policy" again. The programmes still don't want to install.Do I now have to give the computers an Apple ID for this to work or can this also have other causes?Thank you in advanceRobert
Hello,I was wondering if its possible to retake the jamf 200 exam. I was close to passing but still failed. This was my first 200 exam. Do they allow retests or will i have to pay full price again?
Hello Everyone, I am attempting to figure out what is causing issues with my testing deployment of our IKEv2 VPN Profile. I am trying to deploy a User Level installation of an IKEv2 VPN profile in JAMF Self Service. I have it all configured in the JAMF Pro Cloud and deployed in Self Service to a small scope of a few test computer objects. When I attempt to install the item in Self Service on my test mac, it runs for about 2 seconds and reports an error "Item Failed". I have tried this on Catalina and Big Sur with same results. My questions is are:1. Were can I look at logs to find out what is happening/failing? -I checked /var/log/jamf.log -The mdm verb is not available on this version of macOS.2. Am I doing something wrong to cause this to fail in the deployment?
I would request someone from the community to help deploy Jamf connect 2.19 via Jamf policy step by step as I am new to wide deployment configuration.
We tried to enroll a few BYOD devices today and we are now seeing this screen: I have never seen this prompt before for the BYOD enrollment process. Usually, we send Enrollment Invitations via email and the user can download the CA Cert and MDM Profile without signing into anything. Today, we discovered this was happening.How can we turn off this requirement? Current iOS Enrollment settings
Hey All!I'm trying to remove the Bootstrap Token from the computer and the mdm server, I keep getting and error message tho.I'm using command line: sudo profiles remove -type bootstraptokenI've tried on an intel Mac running 13.1 & on an M1 Mac running 12.6.3, both returning the same error message.It looks like the Token is being deleted from the computer successfully but is unable to clear the bootstrap token escrowed in Jamf I've attached a photo of the error, any tips/tricks would be greatly appreciated! Thanks!
Can someone explain what "Declarative Device Management" is? All I can find are vague descriptions and I just don't understand what it is. With that, what's the deal with this failed command? DDM is not showing as being enabled on any of our devices. It seems like this is supposed to be done automatically? TIA
Hello, I'm looking at managing iOS and iPadOS soon (have only managed macOS previously). Has anyone used Jamf AD CS Connector to issue certs for 802.1X on iOS/iPadOS? Jamf documentation seems to show SCEP is the only option for cert-based authentication on iOS, but I can't get confirmation on that and Jamf Support suggested I try AD CS Connector (without clarifying if it should work or not) I'd rather not prompt users for wifi passwords with PEAP. I believe I could setup a service ID for PEAP so authentication is automatic, but wouldn't want to use a single credential for everyone if I could avoid it. So certificate based authentication with unique certs is my preferred option if there is a way to do it. If that means only SCEP, then that'd mean I need to setup a SCEP infrastructure and that's not ideal either. Any guidance is appreciated, thank you!
I've poked around Nation a bit, but haven't seen anyone with this exact problem. Trying to connect to our 802.1x wireless network in Jamf Connect's "Network Connection" dialog with no luck. Entering network credentials does nothing, and no feedback is given from the dialog. All other devices (Windows machines, phones, etc) connect to this network by initially authenticating with domain credentials (even devices not joined to domain). The Apple OSX devices using Connect are not domain bound. I'm guessing this may be an issue of pushing out correct certs with Jamf Pro. If so, I'm exactly sure on what certs are needed, and in which manner they should be pushed to machines. Thanks!
Hello JamfNation, I’m trying to connect to our 802.1x wireless network in Jamf Connect's "Network Connection" dialog with no luck. Entering network credentials does nothing and I’mleft with the dreaded “No network connection”. The computers I’m testing/will deploy Jamf Connect with are currently domain bound, but won’t be after I get Jamf Connect working. The current computer-based config profiles I’ve tried don’t seem to work. I’m looking for a way to get authenticated to our wireless pre-boot, so Jamf Connect willwork. We don’t have a scep server btw. Anyone out there have any ideas? I’m stuck.
Hello,Does anyone know how to change the server name for Jamf Admin? I've tried holding down the option key while launching the app, deleting com.jamfsoftware.admin.plist file in /Library/Prefrences/, and running 'sudo tccutil reset All com.jamfsoftware.JamfAdmin', with no success. I also uninstalled and reinstalled it multiple times as well. Thanks in advance for any help,Steve
This might be a little long, but I'm trying figure a faster way of deploying our monthly patching apps. We currently use 2 smart groups, one listed as members that is using the Patch Reporting Application and set it to Latest version. The second group includes the members group and the deployment group like alpha, beta, etc. In the application deployment policy, we point to the update group and set it to ongoing. When it gets updated, it drops out of the list. That works fine, but I tried creating another smart group that includes the monthly patching update groups hoping it would work the same. When I look the list of groups in the console, everything looks good, but even though the update group shows 0 devices, it still pushes the application. For example, Rectangle doesn't have any devices reporting Rectangle, but it's still deploying it. Here is how the smart groups are added.
Hi there gurus, Can anyone provide information on how a well functioning Jamf managed mac network should perform? Especially in regards to user login times. We've been plagued by slow login times for years but told by our IT support team that it's 'normal'. In the worst case i've seen 5min+ delays from login to desktop. We just got $100k of new M1 iMacs, and logins are still 2-3min from login to desktop. It just doesn't seem right to me. I used to have old 2010 macs not managed by Jamf, but bound to the directory, and they'd login in 30sec or less... Anyone care to share some insight that I can push back with?Thank you.
we're having random issues for which the app jamf self service in ios is getting the below error , it doesn't happen with all the devices and even always , sometimes after an upgrade, sometimes not. Welcome to Self Service Mobile Self Service Mobile is a component of the Casper Suite, developed by JAMF Software. This app must be associated with a JAMF Software Server. Contact your IT administrator for information. Do you guys are having the same issues or is it just me?
Hi all,I will like the help some help in getting Extension Attributes up to grep SSHD. /bin/launchctl print-disabled system | grep sshd com.openssh.sshd => true Sorry that scripting is new to me.So the <result>True<result/> or False. Please help.
We are testing Jamf Connect 2.20 using OKTA and configured OIDCAdminClientID to a group of approved admin users but we noticed that when we update to a computer that had the admin user to Jamf Connect 2.20 they lost there admin rights and are not sudoer anymore as well. This has been working fine in 2.18. Seems to work fine when creating a new user but existing users they lose it.
Today we are releasing a maintenance version of Jamf Connect. Jamf Connect 2.20.1 addresses the following product issue: [PI110994] Resolved an issue that caused the OIDCAdminClientID setting to incorrectly demote local accounts from administrator to standard when configured in the Jamf Connect login window. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the new Jamf Learning Hub, a one-stop shop for all our product technical content. Thank you!The Jamf Connect team
Good day, all. I'm attempting to resolve an issue with Jamf Pro and install Sophos (Cloud) in our MacBook environment. We had a working Configuration Profile and a Policy in place at one time. For some unknown reason, the job fails with exit code 1 but no details. Our environment is Monterey and Ventura. "sophosCBR.bundle" is an app downloaded from the internet. Are you sure you want to open it? Chrome downloaded this file on (date). Apple Checked it for malicious software, and none was detected.” The options it gives are cancel or open.One just had to select Open, and the Sophos install would continue. When the Open option was selected, the installation would fail. Again, in the past, Open would work, and installation would be complete.This is our current script:#!/bin/bash"/Library/Application Support/SophosInstall/Sophos Installer.app/Contents/MacOS/Sophos Installer" --install#rm -Rf "/Library/Application Support/SophosInstall" Via the terminal would get:Verifying package
Dear Forum Members, I have been getting Sign-in errors for Mac users and I have no clue where to start for the troubleshooting. The configuration on the JAMF side looks solid. We use NoMAD and the error is not occurring at the OS sign-in. Below are the errors I have been getting from AAD Sign-in section on Intune, and they are for the same user. Those errors all point to the JAMF Native MacOS Connector. The user experience is that they are constantly getting prompted to sign in to Microsoft when using O365 Apps on the Mac. The Microsoft Sign-in windows will just stuck on the page saying "Help us keep your device secure" with no errors. The App ID on this page also points to the same MacOS Connector, but Device State shows as: Unregistered. The same Mac device in Intune actually shows up as enrolled and compliant. Does that mean we need to re-register the device with Intune? Thank you all very much! StatusInterruptedSign-in error code50097Device Authentication Required - DeviceId -D
Hello,Does anyone have a working method to install LsAgent-osx.dmg on computers with Jamf Pro and configure it with an agentkey? With no luck, I have tried making packages, scripts, and numerous other things, including Installomator. The only time the install works and the Mac communicates with our lsagentrelay is when I manually install the DMG, and even then, when I manually run LSAgent in the Application folder, I see an error that says "Configuration could not be updated: Access to the path '/Applications/LansweeperAgent/lsagentconfiguration.xml' is denied." Despite that error, it successfully communicates with Lansweeper. Any help would be appreciated, as I've tried everything I've found online so far. Thanks,Steve
I'm trying to deploy Symantec DLP MP2 (tried MP2, HF1 and HF2) on macOS 11+ and can't seem to get the SEHA app to work. It always shows with a no access symbol on the icon and says it's not compatible. A google search showed that I needed to include the certificate in the mobileconfig supplied by Symantec, which I did, but same result.Any thoughts why this would be?
Hello all.I am currently trying to implement a security group sync to our devices where the user is a member of the security group created in AD specifically for that device using the following in the Files and processes payload. dsconfigad -groups "local-$HOSTNAME-Administrators" The user is logging in with their Admin account via Jamf Connect which creates the account locally on the device and this account is a member of the security group for this device.However no matter which order I do this in (user creates account first and then we add the security group OR vice versa) the user does not seem to receive elevated local admin and remains standard.We also have Global Admin security groups pushed to each device during the AD bind and using this method any Global Admin creating an account on the device via Jamf Connect does immediately have local Admin.I was just wondering if I am missing something to perform the additional security group addition correctly. My understanding
Our ediscovery team has us pushing out an agent. After the install, we see a prompt to allow the agent svc to allow incoming connections. We are force enabling the Firewall with the Firewall payload in a configuration profile. I know I can add Applications to the list with its bundleID. How can I add a file to the allow connections? Since we are pushing the config to turn on the firewall, whenever I run /usr/libexec/ApplicationFirewall/socketfilterfw I get a message "Firewall settings cannot be modified from command line on managed Mac computers."Any help would be greatly appreciated!
Hello Jamf Nation team, I am creating this post because we need some help to configure our jamf server behind nginx load balancer, due to our Security policies, we have jamf working behind a load balancer with nginx, but, we can access jamf directly on port 8443. We have jamf configured to work with a load balancer but we still access the application directly, bypassing the load balancer. Can you send us an example of jamf configuration working with a load balancer? It is critical for us and our security to be able to access through port 8443 directly to the application, all traffic must go through 443 and be the load balancer in charge of communicating with jamf. Our nginx configuration is correct and performs such communication. - Please could someone help us if someone have something similar configured? Thank you so much in advance.
Hi there, I've been sitting with this issue for a couple weeks now with no end in site with support, so I figured I'd ask others. We've just started up our Jamf Pro tenant. When we attempt to enable the Cloud Services Connection and input the Jamf ID email address and password, it throws an error saying "Incorrect Jamf ID email address or password". There's only one user in the tenant, the same admin account that set everything up, and that's the jamf ID address and password I'm using. Support has had me try different test accounts and even reset the tenant, but it hasn't changed anything, and I can't seem to find any record of others having this issue. Has no one else run into this problem? This is holding back our implementation projections in a big way given the slow speed of support's communication.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!