Get Support
Recently active
Hi,I looking for how to enable "Detect Leaked Passwords".Does anyone know how I can enable it by Using Jamf Pro?System Preferences > Passwords > Security Recommendations > Detect Leaked PasswordsScreenshot below.Thank you.
Following on from the removal of Remote which was unbelievably useful and has no replacement, Recon has been removed and with it my ability to create a QuickAdd package to add a system into JAMF which is already set up and in operation.How are people dealing with this now if you did use QuickAdd now and then?
Hi,I'm trying to set the preference for Safari via a configuration profile. Is this possible with a config profile? I can't get it to take on Ventura.Many thanks in advance.
One of the many tasks under my scope is patching of vulnerabilities on macOS systems. Recently every single machine has been flagged for having a vulnerable version of "httpd" to which there doesn't appear to be a path toward remediation aside from upgrading to Big Sur. Alternatively I have been digging through options to see whether I could create an extension attribute which would check and alert me of any systems that have apache running. Sadly all command line options seem to be a dead end as the likely option of running "sudo apachectl status" will just return the following "Go to http://localhost:80/server-status in the web browser of your choice.Note that mod_status must be enabled for this to work." Has anyone else had to deal with addressing this vulnerability, and how have you gone about remediating the issue? Apache 2.4.x < 2.4.46 Multiple Vulnerabilities(Report on Tenable's website regarding the vulnerability)https://www.tenable.com/plugins/nessus/139574 Upgrade or R
Is there an API script that will un-enroll macs from jamf pro? Similar to web Management Commands of "remove mdm profile". I don't need the mac to be deleted from jamf entirely.I want to use the API so that jamf itself sends the MDM command to uninstall the profile. If I create a policy, it will package it up and run it on the device.Is it possible to use the API script to check for machines in a smart group? I want the script to be executed only on macs that have a certain PKG installed on it. Thank you
Up to now, we've been scoping apps either to everyone or to grade level, building, or individual users where applicable. But lately we've been getting a lot more requests from our teachers wanting us to assign apps specifically to their classroom students, and we've been telling them that it just isn't possible currently. Most departments understandably don't want to pay for licenses they don't actually need in order to accommodate 1,400 students across two grade levels when they've only got 150 students taking their class. It's frustrating that a smart device/user group has 200 criteria to filter by except something as useful as "Belongs to Class Name". We've got all our class rosters imported from our SIS into Jamf Pro, and it's unfortunate that nothing can really see them outside of specifically the Classes tab. Am I just dumb? Is there a way to do this that I'm not seeing? If not, I'd love if this could be a feature added in a future update.
Hi everyone,I'm currently trying to run an OS update to my environment for mostly M1 Macs that is supposed to allow my users to upgrade their machines to Monterey (as standard users) through Self Service. I'm trying to avoid the user's installing the update themselves since currently they cannot. Filevault 2 is enabled, and if users attempt to update to Monterey themselves, the error comes up that "You must provide authorization for this volume by setting it as your startup disk." I'm currently testing a Policy that contains two policies:1. softwareupdate --fetch-full-installer --full-installer-version 12.0.1 command to grab Monterey. This first one is working fine.2. I then have a second script set to run after this as follows:echo "adminpassword" | /Applications/Install\\ macOS\\ Monterey.app/Contents/Resources/startosinstall --nointeraction --agreetolicense --user My\\ IT --stdinpassYes, my admin username (changed here to a generic example) has a space in it. It gets applied du
Hi,Wondering if anyone else with Jamf Pro has seen this issue.We have around 1100 iPads on our Jamf Pro install and occasionally individual or groups of iPads will have some or all of the configuration profiles re-pushed to them even when the profile itself hasn't been modified or deployed.As an example a student had our wi-fi SCEP configuration profile re-pushed to their iPad (despite it not having been changed) on the 21st February for unclear reasons the certificate deployed to the iPad was not being used to wi-fi authentication and we had to manually exclude and then re-push the certificate, now this morning Jamf Pro has once again re-pushed the SCEP configuration profile (and all the others) to the same iPad resulting in once again the iPad not being able to connect to wi-fi.We've had the above issue sporadically for 3+ years but in the last month the number of occurrences has jumped and we've had 30+ students unable to connect to wi-fi until we re-push the profiles. Other is
Hoping to get some assistance on an issue I am having. We have a few iMacs that are setup for lab usage (Higher Education). The devices are binded to AD and confirmed. Login is successful. The issue I am having is some students will walk away from the device and not return. I have a Config Profile that will log the student out after 5 minutes. If the student has all apps closed it works fine. The device is logged out and a new student can login. However, if the student has an app open or an update is occurring at the time of force logout the login screen will show the student name in ID field and ask for credentials. It ID field is not blank as it would be if apps were closed. Only fix I see is to power off the device and reboot. Is there another Config Profile I can use or possibly a policy to logout/reboot?
Modified a script that does the same thing for chrome. But this script will download and install the latest version of Brave directly from their web site #!/bin/sh dmgfile="Brave-Broswer.dmg" volname="Brave Browser" logfile="/Library/LogsBraveInstallScript.log" url='https://brave-browser-downloads.s3.brave.com/latest/Brave-Browser.dmg' /bin/echo "--" >> ${logfile} /bin/echo "`date`: Downloading latest version." >> ${logfile} /usr/bin/curl -s -o /tmp/${dmgfile} ${url} /bin/echo "`date`: Mounting installer disk image." >> ${logfile} /usr/bin/hdiutil attach /tmp/${dmgfile} -nobrowse -quiet /bin/echo "`date`: Installing..." >> ${logfile} ditto -rsrc "/Volumes/${volname}/Brave Browser.app" "/Applications/Brave Browser.app" /bin/sleep 10 /bin/echo "`date`: Unmounting installer disk image." >> ${logfile} /usr/bin/hdiutil detach $(/bin/df | /usr/bin/grep "${volname}" | awk '{print $1}') -quiet /bin/sleep 10 /bin/echo "`date`: Deleting disk image." >> ${
Hello, So I am currently configuring these macs for students and staff. I thought when I first installed Google Drive for the Mac it had the Google Drive folder mapped as /Volumes/GoogleDrive. However then it changed it's now set to the "/Users/[username]/Library/CloudStorage/googledrive-[email]"The problem is students have subdomain while staff do not. I want to mount their drive to the Dock like if it were their home drive that was given in Active Directory. I did see that their was a spot in the Dock payload. But I believe that limited to static text? Meaning I cant put system variables like $User?
I’ve pushed the policy to Monterey and Ventura machines but application won’t launch in Ventura due to it being an unidentified developer.Even when I upgraded the Monterey machine to Ventura, it runs into the same issue.How can make it so that it’s able to launch in Ventura? Is there a config file that needs to be setup and pushed out to machines prior?
We have purchased iPhone upgrades for a few of our users. They all came out of the box with iOS 16.X. They are setup in Jamf Pro with prestage enrollments with configurations that do not restrict using messages or having their own individual Apple ID's on the device. We have 1 user who has reset and switched phones 3 times and had their messages populate on their "new" device (which was supervised in Jamf Pro with the same configurations) successfully with the only difference we can find being that those devices were on iOS 15.x at the time. We now have 4 users who have not been able to get their messages to load on their new device and have halted the remaining users from swapping until we can figure this out. Those users all have their settings->iCloud->messages turned on (sync this iPhone) and the manage storage is showing an amount that seems reasonable to what they have with messages. They all are either under the 5GB free limit for iCloud or ar
Hello all,I have a strange behaviour here: I have enough licences of Pages, Numbers, Keynote and iMovie via Apple School Manager and assigned them to two Smart Computer Groups via "Mac Apps". So far this has always worked, even without the computers being logged in with an Apple ID.Now, however, I update the computers to Ventura and suddenly the Mac Apps no longer install automatically. I have also set the distribution method to "Make available in Self Service" as a test, but nothing happens other than the circle turning.Under the Mac Apps in the History tab, the software is set to pending. I also removed my test computer from the scope, executed "sudo jamf policy", brought the computer back into the scope and executed "sudo jamf policy" again. The programmes still don't want to install.Do I now have to give the computers an Apple ID for this to work or can this also have other causes?Thank you in advanceRobert
Hello,I was wondering if its possible to retake the jamf 200 exam. I was close to passing but still failed. This was my first 200 exam. Do they allow retests or will i have to pay full price again?
Hello Everyone, I am attempting to figure out what is causing issues with my testing deployment of our IKEv2 VPN Profile. I am trying to deploy a User Level installation of an IKEv2 VPN profile in JAMF Self Service. I have it all configured in the JAMF Pro Cloud and deployed in Self Service to a small scope of a few test computer objects. When I attempt to install the item in Self Service on my test mac, it runs for about 2 seconds and reports an error "Item Failed". I have tried this on Catalina and Big Sur with same results. My questions is are:1. Were can I look at logs to find out what is happening/failing? -I checked /var/log/jamf.log -The mdm verb is not available on this version of macOS.2. Am I doing something wrong to cause this to fail in the deployment?
I would request someone from the community to help deploy Jamf connect 2.19 via Jamf policy step by step as I am new to wide deployment configuration.
We tried to enroll a few BYOD devices today and we are now seeing this screen: I have never seen this prompt before for the BYOD enrollment process. Usually, we send Enrollment Invitations via email and the user can download the CA Cert and MDM Profile without signing into anything. Today, we discovered this was happening.How can we turn off this requirement? Current iOS Enrollment settings
Hey All!I'm trying to remove the Bootstrap Token from the computer and the mdm server, I keep getting and error message tho.I'm using command line: sudo profiles remove -type bootstraptokenI've tried on an intel Mac running 13.1 & on an M1 Mac running 12.6.3, both returning the same error message.It looks like the Token is being deleted from the computer successfully but is unable to clear the bootstrap token escrowed in Jamf I've attached a photo of the error, any tips/tricks would be greatly appreciated! Thanks!
Can someone explain what "Declarative Device Management" is? All I can find are vague descriptions and I just don't understand what it is. With that, what's the deal with this failed command? DDM is not showing as being enabled on any of our devices. It seems like this is supposed to be done automatically? TIA
Hello, I'm looking at managing iOS and iPadOS soon (have only managed macOS previously). Has anyone used Jamf AD CS Connector to issue certs for 802.1X on iOS/iPadOS? Jamf documentation seems to show SCEP is the only option for cert-based authentication on iOS, but I can't get confirmation on that and Jamf Support suggested I try AD CS Connector (without clarifying if it should work or not) I'd rather not prompt users for wifi passwords with PEAP. I believe I could setup a service ID for PEAP so authentication is automatic, but wouldn't want to use a single credential for everyone if I could avoid it. So certificate based authentication with unique certs is my preferred option if there is a way to do it. If that means only SCEP, then that'd mean I need to setup a SCEP infrastructure and that's not ideal either. Any guidance is appreciated, thank you!
I've poked around Nation a bit, but haven't seen anyone with this exact problem. Trying to connect to our 802.1x wireless network in Jamf Connect's "Network Connection" dialog with no luck. Entering network credentials does nothing, and no feedback is given from the dialog. All other devices (Windows machines, phones, etc) connect to this network by initially authenticating with domain credentials (even devices not joined to domain). The Apple OSX devices using Connect are not domain bound. I'm guessing this may be an issue of pushing out correct certs with Jamf Pro. If so, I'm exactly sure on what certs are needed, and in which manner they should be pushed to machines. Thanks!
Hello JamfNation, I’m trying to connect to our 802.1x wireless network in Jamf Connect's "Network Connection" dialog with no luck. Entering network credentials does nothing and I’mleft with the dreaded “No network connection”. The computers I’m testing/will deploy Jamf Connect with are currently domain bound, but won’t be after I get Jamf Connect working. The current computer-based config profiles I’ve tried don’t seem to work. I’m looking for a way to get authenticated to our wireless pre-boot, so Jamf Connect willwork. We don’t have a scep server btw. Anyone out there have any ideas? I’m stuck.
Hello,Does anyone know how to change the server name for Jamf Admin? I've tried holding down the option key while launching the app, deleting com.jamfsoftware.admin.plist file in /Library/Prefrences/, and running 'sudo tccutil reset All com.jamfsoftware.JamfAdmin', with no success. I also uninstalled and reinstalled it multiple times as well. Thanks in advance for any help,Steve
This might be a little long, but I'm trying figure a faster way of deploying our monthly patching apps. We currently use 2 smart groups, one listed as members that is using the Patch Reporting Application and set it to Latest version. The second group includes the members group and the deployment group like alpha, beta, etc. In the application deployment policy, we point to the update group and set it to ongoing. When it gets updated, it drops out of the list. That works fine, but I tried creating another smart group that includes the monthly patching update groups hoping it would work the same. When I look the list of groups in the console, everything looks good, but even though the update group shows 0 devices, it still pushes the application. For example, Rectangle doesn't have any devices reporting Rectangle, but it's still deploying it. Here is how the smart groups are added.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!