Get Support
Recently active
I'm new to Jamf Pro, and I asked our on-boarding solutions expert on some best practices for creating User Groups in Jamf to limit access for our Tier 1 IT Staff, but they were not to helpful. Are there any good tips on what permissions to setup for a least privileged model within Jamf Pro for our IT Staff?Ideally a setup that goes from Tier 1 (least privileged) to Tier 3 (most privileged) in terms of what these users can get to and modify on the Jamf Pro settings side and what harm they can do to devices. We don't want our Tier 1's to be able to wipe a device for instance.
Hello,My team and I are trying to release a new enrollment look for our greater team and we found that DEPNotify can really make it look good. Is it possible while depnotify is running to have a video come up and play? On the other hand is it possible to just have the depnotify screen toggle through images as it is running certain policies to give us the ability to share more information with our endusers.What we've tried:Inside the DEPNotify script towards the end after all the polices have completed it have the command -# Play the video file defaults write com.apple.QuickTimePlayerX MGPlayMovieOnOpen 1echo "open -a QuickTime\\ Player /usr/local/att/Mac_Welcome_Video_Test_3.mp4" >> /var/tmp/depnotify.logsleep 80defaults write com.apple.QuickTimePlayerX MGPlayMovieOnOpen 0We have also tried taking out of the DEPNotify script and gave it is own policy where it is called as the very last ticket item using the same script as shown above. Thank you in advance for the
Since the self service update (updated on my M2 test machine today) my non VPP items in self service are generating false negatives "item failed" errors. Even a simple inventory update will generate a false negative. They execute fine but users will absolutely report these false negatives believing them to be actual negatives. This doesn't appear to be true for all macs (seems to be fine on my intel) What are my next steps?Thank you
We have an iPad that is not getting the options that iPhones have to register with Azure ADWhen we add an iphone it immediately gets the option to register with Microsoft within the jamf app on the device. However, we are trying to add an ipad device and it does not get the option to register with Microsoft in the jamf app. I was able to register it with Microsoft through the settings in the Microsoft Authenticator app, however, this is not the normal process and the ipad does show in Azure ad, but its compliance shows as n/a. Because the compliance shows as n/a, we are unable to connect the device to email and other Microsoft apps. Is there something that we are missing? The only thing that we can see causing the problem is that the ipad did not get the option to register with Microsoft from within the jamf app for some reason.
Over the past couple days, we have looked at adding the few PC's we have in our office to JAMF so we can use JAMF as a master inventory of all machines in our office,but have seen you can no longer use Recon.exe to this. Is their another way to add the PCs to our inventory?
Hello, For some reason pagination for above call is not working as expected.Issue: receiving 500 error for random pages.For example. I have 200 records, then I am doing 10 page size when I am on page 14 no issues, when I am on 15 page receiving 500 error, then I am on 16 page everything working as expected. Can someone help?
Error: An exception of class NilObjectException was not handled. The application must shut down. Scenario: I was uploading the following file, using Jamf Admin, and it failed every time: Install macOS Big Sur.app.pkg Fix/Solution: Rename the file, the extra dot is causing the error FROM: Install macOS Big Sur.app.pkgTO: Install macOS Big Sur app.pkg (REMOVED dot before "app") NOTE: This error and solution may not help you. Other scenarios could also cause this. Also tried (non worked): - Updating file through Jamf Pro --> Settings --> Packages --> New Package --> Upload --> would not upload at all- Updating Jamf Admin- Changing file permissions
Does anyone know how to uninstall LanSchool Classic programmatically? There used to be an /uninstall command that I could send in a one-line script to uninstall in older versions on Catalina (possibly Big Sur). The file path I guess has changed and it no longer works. I have tried taking the Uninstall.app provided in the original DMG, pulling it out, and placing it in the Shared user's folder to try and run that uninstaller. The documentation all points to manually uninstalling it this way, but it fails to run due to Apple's Gatekeeper not being able to "check it for malicious software". I want to automatically uninstall (with a JAMF Policy) if the computer is no longer in the "Students" Smart Group. Thank you in advance.Dave W.
Wondering if anyone has a script that I can deploy via self service that will essentially allow a user to reset and remove all bluetooth devices? I know that Monterey requires a script and Big. Sur still goes through the bluetooth module settings. My fleet is mainly consisting of standard users.
Is there a way via the JSS GUI to find whether you have a username in the system but no assigned Mac?I've only ever been told this can be accomplished with a MySQL search
Is there any functionality to allow a standard Admin password for a supervised iOS device? We have users that forget their self-set passwords on the Supervised devices. However, the Clear Passcode commands are not working because the device is locked and the WiFi/Cellular status is unknown. We need a better solution for this... Devices shouldn't be able to be bricked, even off WiFi.
Hi all, Non-admin users cannot run this update. Is there a way to cancel/skip/run the update from jamf ?Re-packaging the app will cause user’s enrolment loss. Thanks,
Hello Everyone, I am having an issue with one of our technicians leaving Remote Desktop enabled. I thought that Jamf Pro would log the username of the Jamf user who enables it but the field is blank under management history. See attached picture. Is there a way through a smart group/script after so much time has elapsed that it would auto disable remote desktop? Thank you!
Today we released Jamf Connect 2.19.0. This release includes the following changes and improvements: • The Jamf Connect menu bar now reports to Jamf what settings are configured on computers.This data is used to assist our development teams and align with customer interests. This data does not include any Personally Identifiable Information (PII). • The Disable Update Watcher key for the Jamf Connect login window has been added to allow for the Update Watcher to be disabled. When the key is set to true, the login window will remain installed during any macOS updates rather than being uninstalled then reinstalled automatically after the update. The key is now available in Jamf Connect Configuration and the Application & Custom Setting configuration profile payload in Jamf Pro. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation &nb
I'm planning on taking the JAMF 300 course but before I do I wanted to work on familiarizing myself with scripting. Any good recommendations for a scripting course I can take? Thanks
Team,If, netskope is deployed through Jamf Pro then as an administrator... is it possible to disable it for a while in the new macOS ventura because in Ventura we are not able to find the option to disable this and earlier it was there in macOS Monterey
Hi all, I’ve recently set up and introduced Jamf Setup and Jamf Reset for use on our shared devices. I currently have Jamf reset set to a soft reset which should log the user out and end SSO session thus logging users out of any pages they signed into. However this doesn’t seem to work, the user is logged out of the JAMF Setup session but remains logged into any apps they signed in on specifically Google applications. I’ve attempted to have these apps uninstall and the reinstall when the user logs out and have also selected the option to prevent chrome saving data but as soon as the app is reinstalled the account is there again. Any ideas what I can do other than hard reset after each user? TIA
At JNUC, there was a presentation on an easy way to setup Wandera DNS filtering. I followed it and had a great configuration integrated into our Jamfcloud. It has deployed to all our clients and I'm seeing data. It was awesome.Is there anything like that for Jamf Protect? A quick walkthrough of setting it up, configuring it, linking it to Jamfcloud, and deploying? I know there's a lot of documentation, but it's a bit overwhelming. I'm looking for an easy deployment guide. Once it's deployed, I can go through more of the documentation and tune it.ThanksCyrus
Hello! I am very inexperienced with scripting, so tell me if i'm in the wrong place. I want to have a simple script execute the following (at a user level): defaults write com.apple.loginwindow TALLogoutSavesState -bool false I have a few scripts (for mounting network shares) that I run using Outset when the user logs in. I'd like to do the same with this one. Any guide on how to call this command as the user?
With Apple devices continuing to gain major prevalence within both educational institutions and businesses of all sizes, it’s becoming increasingly important for organizations to manage not only their devices but also the Apple ID that the user signs-in with. This is where Managed Apple IDs come in. While you can restrict the ability to sign-in to an Apple ID using an MDM solution (or our team can do this for members of our own managed service offerings), in doing so you are denying users key functionality and features, such as iWork collaboration and iCloud Backup. This article aims to highlight these benefits and discuss how to leverage your organization’s existing Microsoft 365 accounts as Managed Apple IDs to give your users one fewer log-in to remember. That said, it should be pointed out that it remains best practice to disable signing-in to any Apple ID on devices that aren’t permanently assigned to an individual user and Shared iPad isn’t being used. This is most common in smal
Certificates and the technologies surrounding them can be a difficult topic to understand. In this series, we’re going to break down the underlying concepts around these technologies in a straightforward, easy-to-understand way. In our first part we will cover the basics of certificates and how they work, and in the future we’ll talk about SCEP, AD CS, 802.1x, and more. What is a certificate? A certificate is a unique, digitally signed document which authoritatively identifies the identity of an individual or organization. What makes up a certificate? A signed digital certificate contains the owner’s distinguished name, the owner’s public key, the certificate authority’s (issuer’s) distinguished name, and the signature of the certificate authority over these fields. There are often other fields, such as Country, State/Province, City, Organization, Department, and more which can more accurately identify the certificate or the object which the certificate identifies. These fields aren
Welcome to Part 2 of our discussion of Certificates, SCEP, and 802.1x. In our first post we took a look at what certificates are and how they work. Today we will take a look at Active Directory and Active Directory Certificate Services. What is Active Directory? Active Directory (AD) is a set of roles and features which run on Windows Server. In essence, it is a database and set of services that connect users with the network resources they need to get their work done. Active Directory is often used as a broad term to describe several concepts and services. There is much, much more to AD but this isn’t a Microsoft AD course, so we’ll only cover what we need to know here. What does Active Directory do? At its core, AD helps administrators manage permissions and control access to network resources. AD uses several directory objects to do so: Users Groups Computers Security Policies (Group Policy Objects) Active Directory manages the security policies applied to its many moving parts
Easily allowing your end-users to opt-in or opt-out of your internal beta program is the first step to building your user-base of “trusted testers.” Let's take a closer look at how we implemented this via Self Service, and how we utilized the combination of an Extension Attribute and Inventory Update to populate our testing group, rather than the Jamf Pro API. This type of workflow can be used for implementing your own beta test group, or it can be used in conjunction with other workflows where you want users to self-report. This workflow was originally posted to my personal blog, which you can find by following this link. Additionally, I've documented some related workflows and spoken about our beta test program at JNUC. Feel free to take a look at the links below if you would like to learn more:Dan K. Snelson Blog - Your Internal Beta Test Program: Opt-in / Opt-out via Self Service (sans Jamf Pro API) Dan K. Snelson Blog - Invitation Only Betas JNUC 2019 - Your Internal Bet
What are Extension Attributes? Why were they added to Jamf Pro and why do they matter? These questions, and others, will be answered in this short post. Extension Attributes can be a powerful tool in the tool belt of the Jamf Pro admin, and we will dive into them a little deeper in this post. At the end, you should have a working knowledge of Extension Attributes, a few workflow ideas, and some further resources to continue on in your journey to become an Extension Attribute guru. So buckle up and let’s go on a journey! What Are Extension Attributes? Introduced in the Casper Suite days, Extension Atributes are a method for extending the data stored in Jamf Pro for an object (computer, mobile device, or user). From our developer documentation: Extension attributes allow Jamf Pro to store additional inventory information about a device beyond what is collected by default. Their values can be set via API call, or through the Jamf Pro console itself. While Jamf Pro is designed to co
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!