Get Support
Recently active
Hello,I been trying to remove local admin privilege for all users, but with an exception of two Local accounts. I was able to find a script from a previous post. For the most part it works, but one of the local admin account name has spaces in it. So when I run the script it takes in each word as a separate user. For example: if the admin account name is "The Admin" it would run as "The" as one account name and "Admin" as another account name. Not sure why the space is a delimiter. Any help would be appreciated! #!/bin/sh adminUsers=$(dscl . -read Groups/admin GroupMembership | cut -c -18) for user in $adminUsers do if [ "$user" != "root" ] && ( [ "$user" != "The Admin" ] || [ "$user" != "secondAdmin" ] ) then dseditgroup -o edit -d $user -t user admin if [ $? = 0 ]; then echo "Removed user $user from admin group"; fi else echo "Admin user $user left alone" fi done
Please tell me we're going to be able to suppress these and a million notifications aren't the future for end users:
I’ve been at my company for alittle over a year now, we have a bit of a apple environment with a fleet of iPads, some iPhones and apple TV’s. I have became the de facto jamf guy and throughout my tenure at the company so far attended jnuc 2022 (virtually) and completed the jamf 100 certification, I am now looking into the Apple Device support and the Apple deployment and management certification and then possibly jamf 200. Just wanted to get your insights to see if that is a good game plan (ps we have 2 test macs in our environment as well + a unmanaged Mac mini)
I was severely disappointed with Apple's new push to treat Ventura an "update" instead of an upgrade. Luckily I was able to block the upgrade on our Macs via Restricted Software and a Profile to delay the major updates for 90 days and it seemed to work very well until suddenly one day in December I started seeing lots of Macs appear with the new OS. I have not changed anything with the existing measures to kill and delete the Ventura installer, so I can only imagine that Apple changed something in the ASU mechanism to slip it through when Macs install Monterey updates. I think I can narrow it down to the 13.1 update. Now we're up to 50+ Macs running Ventura and I have no way to stop it from proliferating through our organization. It's worse than a virus! We aren't even close to being able to test all our apps and tools with Ventura. Is anyone else out there having success at stopping Ventura from getting installed?
I feel like I'm missing something fundamental about plist files and I could use a little education. I understand plist files are basically settings files with key value pairs so you can save/push configurations for the system and apps. What I don't really understand is how you would determine what settings are supported? For example, if I want to allow Microsoft Teams access to screen recording for all users; how would I know what key:value pairs are? I found JAMF's privacy preferences control utility, but is that showing me every option? Is it up to an individual app to publish it's settings somewhere? Does Apple publish there's for Screen Recording for example? I can find lots of how-to's on creating/editing plist files, but I think I must be missing something fundamental.
Hello all,I currently have an active ticket with Jamf pertaining to this infamous issue. Currently I have around 78 devices that have not checked into Jamf, and we suspect that are are more devices than what I listed that are impacted. I have tried several commands, such as sudo jamf reenroll -prompt, and removing the profiles, but they either error out or return with the same error. I have created an EA that monitors this issue, but, only four computers return with the MDM is broken error and the rest of the impacted machines do not return anything at all. It is a little frustrating, because I am worried that this issue might just keep reoccurring over and over. I was told that the best way to fix this solution is to wipe the machines whose MDM profiles cannot be removed, and I just really can't wrap my head around that, neither do I think that is the most professional solution in our case (since it impacts an educational environment). Does anyone have any more information o
For anyone who wants to put the Safari 15.4 updates for Catalina or Big Sur into Self Service:Catalina: http://swcdn.apple.com/content/downloads/38/11/002-79202-A_MMXLIHTSU2/nka279pyfdmd11tm36dds4jysecfq7b732/Safari15.4CatalinaAuto.pkgBig Sur: http://swcdn.apple.com/content/downloads/27/58/002-81938-A_JGLR6R7D8U/kfpfiwbr575oxwvs6quv4oova5gu6l6y0c/Safari15.4BigSurAuto.pkg
HEy jamfnation we are having a major issue with clients not being able to mount the share 4 out of 5 times. I have been working with JAMF support and they thought it may be related to a patch but I removed that patch and I am still having issues. The system log on the client shows: Sep 18 11:03:40 ARNC02P904PFVH7 kernel[0]: smb2fs_smb_validate_neg_info: Server capabilities do not match Sep 18 11:03:40 ARNC02P904PFVH7 kernel[0]: smbfs_mount: smb2fs_smb_validate_neg_info failed 80 Sep 18 11:03:40 ARNC02P904PFVH7 mount_smbfs[81969]: smb_mount: mount failed to 10.40.34.26/CasperShareNBK, syserr = Authentication error Has anyone else run into this?
I'm going down the rabbit hole of fixing our devices that stopped checking in due to the invalid device signature issue that has been seemingly plaguing customers. I've had great success using Jamf API commands (jamf-management-framework) to get active devices re-enrolled and talking again.I have a sizable chunk of devices that I've marked as "Unamanged", to reclaim licenses from devices that may have fallen to the wayside. However, now that I know the device signature issue is a thing, I recognize that some of these devices could still be active and not actually stale.My plan was to send the API command to re-enroll to all the devices that are unmanaged. Based on a test, it appears that the re-enrollment just latches onto the exact same computer record in Jamf Pro, and it carries on with life.So on that note, how long do these API commands stay queued up before they time out or otherwise clear out? Or do they stay queued indefinitely? Because my line of thinking right now is to
Here is the app configuration I have deployed for CISCO Anyconnect. A user meant to move the icon and somehow ended up deleting it.I have since gone back in and specifically added their device's SG, however, the device never receives a deployment push.I assume I need to somehow tell JAMF the app is no longer on the device, and I remember this in training, but I have never had to use it in the field and now I need some help lol Below are the settings used, if anyone has any idea or sees anything I have done wrong please let me know.
Hi!I have a MacBook Pro (16-inch, M2 Max, 2023) and a MacBook Pro (13-inch, M2, 2022) that did not let the user set up their own user in Setup Assistant. They went trough Setup Assistant and it never went to the user screen, and the only account on the computer is the Management Account which is set up to have the randomly-generated password. These computers are Prestaged with Apple Business Manager.My solution was having them erase the device, I delete the Jamf record, and they reinstall. I'm wondering if anyone has any direction, since more M2s will be hitting out Fleet shortly as people upgrade, and I'd like to get to the root of why they are not being prompted to create their user in the Setup Assistant. Thanks!
Hi all, I am trying to get a macbook registered with intune, it was all working fine until last week and then we slowly started having issues with devices getting conditional access errors when trying to use outlook and teams. Looking into it, seemed to be that the issue is that the APNS cert for intune expired yesterday. However, we reupped that cert it is now all good, but I still can't get new devices to register with intune, and jamf is also being weird with Azure registration, as it says the device is registered with azure but the pop up requiring you to register it keeps showing up on the macbook. I can see the device in azure, but it never registers with intune. But then also I have machines that do show up in intune but users still getting the conditional access errors when trying to use teams/outlook! On the fresh built mac I have I get the Authentication for JamfAAD pop up but it never actually tries to sign me in. Anyone who could point me in the right di
I've got a package that JAMF installs with every Mac Startup. It contains a plist file and bash script which gets placed in /Library/LaunchAgents/. The Package was created with Composer. All works fine except I had to modify the script and create a new version of the package. Even though the package on the JAMF Distribution Share shows that it is the newer version (i.e., by the date modified and by the contents of the script), JAMF continues to install the older version. The older version no longer exists on the Distribution point, and I'm deleting it from the destination folders of the macs, but after each startup, the old version continues to get installed. I've even recreated the Package in JAMF, and recreated the Policy that deploys it. Is there a cache or tmp folder somewhere that I need to look for?
Hi everyone, acutally I got the problem, that on FileVault encrypted Macs the input menu for keyboard layouts won't show up in the boot screen. The setting for the keyboard input menu is located in /Library/Preferences/com.apple.loginwindow with the key showInputMenu and a boolean value. If I try to set the value via defaults write, the checkbox in System Preferences is active and the input menu is shown in login window. BUT if the computer is FileVault encrypted, the input menu won't show up in the boot screen. Only if I set the checkbox manually in System Preferences, the input menu shows up in loginwindow and in boot screen. I tried Composer to evaluate which files are changed during clicking in System Preferences. The only valuable file is /Library/Preferences/com.apple.loginwindow. Does anyone have the same problems? Thanks in advice,Michael
Hi All, Our Adobe user base is around 300 and they do not have admin rights on their machines. I changed the deployment package to Self Service to allow the non admin users to install updates. If the users are already using the non admin Adobe Manager and then install the new Adobe Self Service one from Jamf Self Service, will this allow them to install updates with their non admin accounts. ThanksSimon
Hi All,im using the Content Filter ( Built-in: Limit Adult Content ) in jamf-PRO, to prevent private browsing in Safari,it's works but has presented me with a few issues.. eg. it blocks seems to block PDF's and also works like "straight" "pollen tube" "tube" With the message.Restrictted Siteyou cannot browse this page at "google.co.uk" because it is restricted.
Hello Everyone,My company is slowly moving into the Apply ecosystem and I was put in charge of setting up MDM with Jamf. I do already have some good experience with Apple itself from previous days working at the Genius Bar. But, not at the enterprise level. I want to set this up right initially so that it makes the lives of everyone else that interacts with it easier.I've gotten the bare minimum done(Setup Apple Business Manager, Jamf 100 cert). And we plan on using In-Tune for identity management. Which, at the moment will mainly be used for iOS devices.As the title says above, what are some best practices that I can follow now? What Automation's feel like magic? What pitfalls should I expect to run into?Any tips would be greatly appreciated.
Hi all, how do you all manage/handle the Azure AD registration, specifically on end-user devices?We've finally been able to get the registration to work, so objects are created in AAD and evaluated for Conditional Access. But the process is a bit fiddly. For example, if you don't press 'Always Allow' on the certificate box, it can kill it all.How do you all handle it in your environments?Thanks
Hi All,We have been able to get our AAD Registration to work again, so users can enrol their device with Azure, Azure deems the device is Compliant, and satisfies Conditional Access/allows users to sign in.Prior to the 10.43 update, this process would create an object in Azure AD under the user's name, and it would also show in Intune, with the "Managed by" field showing as Jamf. It would also create an attribute in Jamf Pro for the "Computer Azure Active Directory ID".After the 10.43 update, an object is still being created in AAD, and marked as Compliant, but I'm now not having anything come up in Intune. Not the end of the world, but we're also not getting an attribute in Jamf Pro now for the "Computer Azure Active Directory ID" - this is more problematic, as we use Smart Groups to determine which devices have registered - now we don't have any visibility of this in Jamf Pro.Has anyone seen this since the update?Thanks in advance.
Is there a way to use a configuration profile or script to disable browser caching similar to manually going into Developer tools and selecting "Disable cache". We have several remote Macs we want to disable browser caching on and would like to do it through Jamf.Thanks
We have our macs setup with a local admin account and student login with their AD info and creates a mobile account. Does anyone have a script they use that works to delete all the users minus the admin account?
My users are facing issues after Jamf connects is installed and the password sync.Once they restart or log out when they go back to login they are getting a choice of 2 accounts. When they select their previous account they are unable to log in however when they select the new account which is their Okat username why are now able to log in however since it's a new profile they have no data. Is there something that needs to be once to the config profile?
Today, Apple released macOS 13 Ventura. While many orgs may be ready to upgrade today, others may need time to do final testing and/or get verification from your vendor on the compatibility of your software. Apple has made some major improvements in the software update mechanism to make installing Ventura easier and faster for users. Instead of forcing the user to download the full installer and running it locally (like previous upgrades), a computer running macOS 12.3 or higher will perform the upgrade like a software update and only download the changes. In my testing, a full installer was over 12GB, but the new update only required 5.5GB of download. This is great news. However, there is a bug that Mac Admins needs to be aware of. Because this new upgrade process acts like an update, macOS 12.3 - 12.6 were only respecting the Minor Deferral time for Ventura, instead the Major Deferral. If you have different settings for these two deferrals, you may be surprised to find tha
I am new to Jamf Pro. I would like to get Mobile devices to enroll using a prestage or enrollment customization login.I have tried "require credentials for enrollment" , "SSO" and "LDAP" in enrollment customization. This options only work for direct users. I am using Azure Identity Cloud services. Which works find if i am searching for employee names and adding groups.
I'm having some trouble getting a few macs to report correctly on their firewall status. I've verified that the firewalls are enabled on all machines, that the firewall config profile is installed, but still getting several reporting back that the firewall is not enabled, which is messing with our security reports. Has anyone else run across this and have a fix? From everything I can tell, the report filter is correct, and the devices show enabled. Don't know what I'm missing here.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!