Get Support
Recently active
Hi there gurus, Can anyone provide information on how a well functioning Jamf managed mac network should perform? Especially in regards to user login times. We've been plagued by slow login times for years but told by our IT support team that it's 'normal'. In the worst case i've seen 5min+ delays from login to desktop. We just got $100k of new M1 iMacs, and logins are still 2-3min from login to desktop. It just doesn't seem right to me. I used to have old 2010 macs not managed by Jamf, but bound to the directory, and they'd login in 30sec or less... Anyone care to share some insight that I can push back with?Thank you.
we're having random issues for which the app jamf self service in ios is getting the below error , it doesn't happen with all the devices and even always , sometimes after an upgrade, sometimes not. Welcome to Self Service Mobile Self Service Mobile is a component of the Casper Suite, developed by JAMF Software. This app must be associated with a JAMF Software Server. Contact your IT administrator for information. Do you guys are having the same issues or is it just me?
Hi all,I will like the help some help in getting Extension Attributes up to grep SSHD. /bin/launchctl print-disabled system | grep sshd com.openssh.sshd => true Sorry that scripting is new to me.So the <result>True<result/> or False. Please help.
We are testing Jamf Connect 2.20 using OKTA and configured OIDCAdminClientID to a group of approved admin users but we noticed that when we update to a computer that had the admin user to Jamf Connect 2.20 they lost there admin rights and are not sudoer anymore as well. This has been working fine in 2.18. Seems to work fine when creating a new user but existing users they lose it.
Today we are releasing a maintenance version of Jamf Connect. Jamf Connect 2.20.1 addresses the following product issue: [PI110994] Resolved an issue that caused the OIDCAdminClientID setting to incorrectly demote local accounts from administrator to standard when configured in the Jamf Connect login window. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the new Jamf Learning Hub, a one-stop shop for all our product technical content. Thank you!The Jamf Connect team
Good day, all. I'm attempting to resolve an issue with Jamf Pro and install Sophos (Cloud) in our MacBook environment. We had a working Configuration Profile and a Policy in place at one time. For some unknown reason, the job fails with exit code 1 but no details. Our environment is Monterey and Ventura. "sophosCBR.bundle" is an app downloaded from the internet. Are you sure you want to open it? Chrome downloaded this file on (date). Apple Checked it for malicious software, and none was detected.” The options it gives are cancel or open.One just had to select Open, and the Sophos install would continue. When the Open option was selected, the installation would fail. Again, in the past, Open would work, and installation would be complete.This is our current script:#!/bin/bash"/Library/Application Support/SophosInstall/Sophos Installer.app/Contents/MacOS/Sophos Installer" --install#rm -Rf "/Library/Application Support/SophosInstall" Via the terminal would get:Verifying package
Dear Forum Members, I have been getting Sign-in errors for Mac users and I have no clue where to start for the troubleshooting. The configuration on the JAMF side looks solid. We use NoMAD and the error is not occurring at the OS sign-in. Below are the errors I have been getting from AAD Sign-in section on Intune, and they are for the same user. Those errors all point to the JAMF Native MacOS Connector. The user experience is that they are constantly getting prompted to sign in to Microsoft when using O365 Apps on the Mac. The Microsoft Sign-in windows will just stuck on the page saying "Help us keep your device secure" with no errors. The App ID on this page also points to the same MacOS Connector, but Device State shows as: Unregistered. The same Mac device in Intune actually shows up as enrolled and compliant. Does that mean we need to re-register the device with Intune? Thank you all very much! StatusInterruptedSign-in error code50097Device Authentication Required - DeviceId -D
I'm trying to deploy Symantec DLP MP2 (tried MP2, HF1 and HF2) on macOS 11+ and can't seem to get the SEHA app to work. It always shows with a no access symbol on the icon and says it's not compatible. A google search showed that I needed to include the certificate in the mobileconfig supplied by Symantec, which I did, but same result.Any thoughts why this would be?
Hello all.I am currently trying to implement a security group sync to our devices where the user is a member of the security group created in AD specifically for that device using the following in the Files and processes payload. dsconfigad -groups "local-$HOSTNAME-Administrators" The user is logging in with their Admin account via Jamf Connect which creates the account locally on the device and this account is a member of the security group for this device.However no matter which order I do this in (user creates account first and then we add the security group OR vice versa) the user does not seem to receive elevated local admin and remains standard.We also have Global Admin security groups pushed to each device during the AD bind and using this method any Global Admin creating an account on the device via Jamf Connect does immediately have local Admin.I was just wondering if I am missing something to perform the additional security group addition correctly. My understanding
Our ediscovery team has us pushing out an agent. After the install, we see a prompt to allow the agent svc to allow incoming connections. We are force enabling the Firewall with the Firewall payload in a configuration profile. I know I can add Applications to the list with its bundleID. How can I add a file to the allow connections? Since we are pushing the config to turn on the firewall, whenever I run /usr/libexec/ApplicationFirewall/socketfilterfw I get a message "Firewall settings cannot be modified from command line on managed Mac computers."Any help would be greatly appreciated!
Hello Jamf Nation team, I am creating this post because we need some help to configure our jamf server behind nginx load balancer, due to our Security policies, we have jamf working behind a load balancer with nginx, but, we can access jamf directly on port 8443. We have jamf configured to work with a load balancer but we still access the application directly, bypassing the load balancer. Can you send us an example of jamf configuration working with a load balancer? It is critical for us and our security to be able to access through port 8443 directly to the application, all traffic must go through 443 and be the load balancer in charge of communicating with jamf. Our nginx configuration is correct and performs such communication. - Please could someone help us if someone have something similar configured? Thank you so much in advance.
Hi there, I've been sitting with this issue for a couple weeks now with no end in site with support, so I figured I'd ask others. We've just started up our Jamf Pro tenant. When we attempt to enable the Cloud Services Connection and input the Jamf ID email address and password, it throws an error saying "Incorrect Jamf ID email address or password". There's only one user in the tenant, the same admin account that set everything up, and that's the jamf ID address and password I'm using. Support has had me try different test accounts and even reset the tenant, but it hasn't changed anything, and I can't seem to find any record of others having this issue. Has no one else run into this problem? This is holding back our implementation projections in a big way given the slow speed of support's communication.
So my father's company is in the transition to Microsoft 365 and now we are looking how to manage about 15 Macs. I'm fairly familiar with Mac management with Jamf Pro, but the MSP wants only Intune to manage all the devices in the environment.Will we miss out on something by using Intune, and not Jamf Pro, to manage our Macs?Our users are admin and know their way on macOS.For us it's most important security is in place (Conditional Access, Compliance, passcode, FileVault and Firewall) and there is a decent onboarding with Apple Business Manager.Will Intune suffice, or is it still better to have a decent MDM like Jamf Pro for Mac management?Someone know their way on both solutions!?
I work in a computer lab that utilizes our AD. I was wondering if there was any way to make some sort of template so that each new user that logs on can automatically have applications such as Microsoft Word or Adobe Photoshop on the desktop specifically. Perhaps I've not looked hard enough but I thought I'd at least ask. Thank you
Looking for input and help :)We have identified a number of systems that were enrolled with a dodgy push cert which is causing config profiles to be extremely slow when being deployed.. Is there a way to fix the identified systems without having to unenroll and re-enrol? but .. if we need un-enroll and re-enrol - is there a way to do it smoothly? and what the best way to approach itThanksRob
I have a script that is running a lot of commands starting with su "$currentuser" -cWhen the policy is run locally or via Self Service the script runs as expected. When I let it run via check-in, all the lines that start with the above command do not run. Any ideas?
I've deleted a mac 3 times and it re-enroll after a new installation every time. From the GUI I've removed MDM and deleted it. What could cause it to re-join and can I stop this from happening? Thanks,
We're having a problem where managed Apps keep reinstalling themselves on our iOS devices. My understanding is that starting with iOS 14, managed apps could be deleted by end users, but my testing has revealed that iOS 14.0 and iOS 15.0 will reinstall the apps of their own accord. Looking at Google Sheets as my test example, I have the following set:- Install Automatically/Prompt Users To Install- Automatically Force App Updates- Make App Managed When Possible (greyed out)- Make App Managed if Currently Unmanaged- Allow users to remove app (iOS 14 or later) and in in a Configuration Profile that is assigned to the device, we have - Removing Apps: Allowed I suppose I can go to the Scope tab for the App and add an exclusion for the device in question to keep it from reinstalling itself, but that doesn't scale. Where should I look next?
Hi All,is it possible to withdraw a Quick Actions in the Jamf School?Best Regards and Thanks for a fast answerPeter
I have a policy with the command below to install macOS updates for high priority updates like 12.5.1. softwareupdate --install --os-only -R However, I have a bunch of machines that state there are no updates available in the logs.Eligible device:Command result ("No updates are available."):We have an SLA for zero-day patches like this of 7 days once it's released to hit 90% of eligible devices, and we've missed that, but I'd like to wrap this up ASAP.My original command is below, but was installing things like Xcode command line tools, so I modified it slightly:softwareupdate -i -r -R
Is there a payload that would allow one to force a device name? I know you can do it via an enrollment profile but I'm looking to do this via a configuration profile.
What exactly is http://kickstart.apple.com/ ? Googling "Apple kickstart" just gives me ARD results, or the man page.
We have the skip TouchID setup for our new enrollments which works great for new machines, however as we upgrade to Monterey after reboot that setup wizard runs again. I have tried many of the scripts and profiles out there but they all look old and non still work, especially with Monterey. I am hoping someone else has worked through this already as part of their Monterey Upgrade? Any solutions out there that have been tested and are working in Monterey? Thanks in advance.
Ok so we have a very weird issue here in my org and I wanted to see if anyone else has ever run into this. On some of our late-2016 and mid-2017 15" Pros, users are having login issues post Monterey upgrade (12.1 and 12,2). When they attempt to login to their account it accepts their password but then just sits there with the progress bar and never logs in. Sometimes the account will let you in, but the users have no menu bar, extremely limited access to the keyboard, and it just never really logs in all the way. But you can use the keyboard shortcut to logout and then log back in with no issues. So given these experiences and after troubleshooting further, we have pinpointed that this issue is with FileVault. We can also go through a password reset with the recovery key, but never change their password, and the users can login with no problem; they can also login fine if we turn off FV and decrypt the drive. But then as soon as we turn FV on again and the drive encrypts the issue is b
Hello, So I am trying to get the wallpaper login policy to set the wallpaper, it works on one of my test machines Mac Book Air that running a M1 chip but the iMac that I have thats running a intel i5 chip is not handling the osascript. It errors with this: 33:48: execution error: Finder got an error: AppleEvent handler failed. (-10000) #!/bin/bash #Create Directory for Custom Image mkdir '/Library/Wallpaper' # Change directories cd '/Library/Wallpaper/' # Download the wallpapercurl -k -Os https://linktowallpaper.com -s cd '../..' currentUser=$(/bin/ls -l /dev/console | /usr/bin/awk '{print $3}') sudo -u "$currentUser" -H osascript -e 'tell application "Finder" to set desktop picture to "/Library/Wallpaper/Background.jpg"'
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!