Get Support
Recently active
We have a question!We have for example 10 classes 5a,6a,7a, etc. with every same 71 teachers and diffrent 28 student per class and one teacher Group names NE16514teacher (see screenshot). All 71 teacher are Member of Group „NE16514teacher“ and Managable Groups 5a,6a,7a, etc. for Jamf School Teacher & Classroom App.So, if we put under a Member Group "NE16514teacher" teacher to catgegory „Teacher“, we could’t see all classes in the classroom app but only under Jamf Teacher. But if we move the Teacher from category „Teacher“ to „Students“ (see Screenshot), than it works and we can see all classes in the Jamf Teacher App and in the classroom App.Why is it so?FYI: In the screenshot you see the teacher Simon with "owner device: 0"please ignore that. We tested with the teacher and "owner device: 1" with the issue.
I am putting this out there because JAMF support has washed their hands in assisting us. We integrated JAMF Connect with Azure AD recently and are currently testing. The issue we are having is that Azure, and our MFA setup in Conditional Access, is requiring users to log in at EVERY restart. It also is requiring password verification after authenticating. As you might imagine, this would cause some inconvenience to macOS users, especially if their means of MFA authentication was not at hand: phone, Microsoft Authenticator app (iphone or ipad) or other means. MFA does not work this way for anything else requiring it. It is only required once per app, per device, until there is a password change. Support suggestion was to exempt macOS from requiring MFA, essentially. This did not go over well with our Sys Admin who is heading the rollout of our MFA requirement. This is a real frustration as JAMF Connect was touted as a solution for AD authentication, ability to provide zero-touch d
Hoping to get some assistance from the knowledge of the JAMF Nation. I am struggling to remove an individual configuration profile, that was installed manually, via the command line. Testing on Mavericks 10.9.1 currently. Used the profiles man page and this: https://developer.apple.com/library/mac/documentation/darwin/Reference/ManPages/man1/profiles.1.html Commands I've tried: sudo profiles -R -F /tmp/profilename.mobileconfig sudo profiles -R -p profileidentifier sudo profiles -R -p profileidentifier -U username No dice so far. Use case is that a profile is installed manually and it needs to be removed without removing all profiles. Any thoughts out there? Thanks!Ben
I have a goal this quarter to deploy Jamf Connect. Things are looking great and working. However, I have one big questions that I'm just not sure about.If we don't use the menu bar (which we don't because we're not on the right Google Workspace edition, and therefore it cannot be configured). Will the local password still sync with the Google Password if it's changed? I'm testing this and while I can log in with my new Google Password, I'm then prompted for the old local password, I thought maybe it would update, but so far, it still asks to verify with the old password.Does it eventually reconcile so the local password is updated to be the new Google Password or is this what the menu bar is for?
Has anybody created a presentation for their staff that explains WHY you're moving to Jamf? We're a non-profit org of 200 staff members who are mostly remote working and are moving to mobile device management. I don't want to reinvent the wheel if somebody has already created a presentation that explains why the move to Jamf and the benefits of an MDM. Many thanks!
I am in a healthcare environment and we are configuring the devices with Jamf Setup and different profiles based on the user login.I am trying to deploy some webclips but I am finding when users change profiles the webclips are multiplying each profile change. What am i dong wrong?
I am trying to deploy MuseScore 4 in self service to allow a lab of Mac’s to download the application. I first made it available via a policy, and the base package taken from MuseScore. The package would fail to install on my test device. It would download, and then just fail. I then went and made a package using composer(taking a snapshot>installing the app>opening app>finish capture>create package). I then deployed THAT package in self service and got the same results. I have done this so many times with other applications, what am I missing with this one? Have any of you successfully deployed this app?
Hi all, Is anyone having issues with users changing their AD password with NoMAD and macOS 10.15.5? The error we sometimes get is "Configuration file does not specify default realm." What I have done to resolve this in the past is simply reapply the NoMAD Config profile to the user's machine. With 10.15.5, I've found that reinstalling NoMAD is sometimes necessary. However, I have one user who is still getting the error even after a new reinstall of NoMAD and after reapplying the config profile. Has anyone else encountered this?
Beginning 02 February 2023, GitHub Atom 1.63.0 and 1.63.1 is no longer available.For detailed information about this change, see Action needed for GitHub Desktop and Atom users from the GitHub Blog.Jamf restored Github Atom 1.60.0 as the latest version available in the Jamf App Catalog. You do not need to take any action if you distributed GitHub Atom 1.63.0 or 1.63.1 using the App Installers service. Jamf will automatically distribute GitHub Atom 1.60.0 to computers in your scope.
Jamf connect installed on devices. Not binded to AD.User changed their password on a windows device. When they go to a Mac and try to login, the message stating "network password does not match your local password. Please type in your old password to sync.".What do you do if they don't remember their old password? Trying to deploy a password change for the local account through jamf has been unsuccesful.Is there a way to auto update the local password without having to type in the old one?
I want to install JAMF Connect on Macs that will have Multi-User. FileVault is enabled, we use Okta as our IDP, I tried every possible key and attribute and the JAMF Connect screen only appears after someone logged in from Local then JAMF Connect appears or when someone Log Off. It defeats the whole purpose of having JAMF Connect. I mean we want anyone to login into the computer even tho they never logged in before and for that we need JAMF Connect to show up after restart but it doesn't.Any solution please??
I am working on an Update Script to get our fleet of Macs (M1/M2/Intel) upgraded to Ventura. I am using swiftdialog to notify the users that they may need to input their password and erase-install to actually run the process. I have tested it on 3 or 4 Macs (Apple silicon) and the process worked without a hitch. However, on my last two test machines (we have a variety of hardware configurations) the process fails.I added the --overwrite and --cleanup-after-use flags but they do not seem to help. Any idea what I am missing Here is the script command I am using../Library/Management/erase-install/erase-install.sh --reinstall --os=13 --update --overwrite --current-user --min-drive-space=60 --check-power --depnotify --cleanup-after-use and here is the error in the log...Result of command:[erase-install] v27.1 script execution started: Mon Dec 12 08:16:10 CST 2022[erase-install] Caffeinating this script (pid=1207)[check_free_space] OK - 447 GB free/purgeable disk space d
I am starting to see users have issues where all of a sudden they cannot sign into their devices. Jamf Connect states their network password is incorrect. No password changes or anything. They can login elsewhere fine (Windows machines, work email on personal phones, etc) but just not their Macs when they are prompted to sign in. I have seen similar questions asked on here but none seemed to have an answer. Hoping maybe someone may know whats going on.
Can someone please advise how or where to get this .pem cert? Do I need to be a dev? Thank you,
Currently each admin has their own apple business manager account. I have all the servers setup under my account and that also pairs with activation lock as well.How can I have a shared account act as the activation lock account so that I can share the creds/pw with the techs? How do you get by the mfa tied to your phone number?
I have a fun situation.M1 macBook Pro, Enrolled into JAMF, with a 5 day deadline for Pairing a SmartCard before automatic enforcement kicks in.The intel macBooks haven't been an issue, since once enforcement kicks in, the user can still login to FV2 using their PW and then the machine can get policies from JAMF. (Removing the configuration profile if we so choose)The M1 macBooks appear to finally support SmartCard login at the FV2 screen, the problem with this is that we cannot use a PW or the Recovery Key from JAMF to bypass this screen. As the macBook doesn't have network connectivity while at the FV2 login screen, we cannot remove the config profile.We tried booting into Recovery, unlocking the disk, opening terminal, and removing the folders below with no luck. /private/var/db/ConfigurationProfiles/Library/Managed Preferences Any suggestions? I both love and hate the FV2 support for SmartCard as it greatly simplifies login, but now means that getting past recovery has bec
Not real sure on this, can I jump from 12.3 to 12.6.2? My friend a while back an the 12.6 update on a 12.4 device, but it only updated the 12.5.1. He was using erase-install and had picked the specific version 12.6.
Our third party service provider is asking if our MDM allows UI configuration profile to be installed. Does JAMF Pro have a setting for this? Bill
When OneDrive version 22.248.1127.0001 is installed, it immediately updates itself to 23.002.0102.There is nothing about 23.002.0102 on MS official release notes page:https://support.microsoft.com/en-us/office/onedrive-release-notes-845dcf18-f921-435e-bf28-4e24b95e5fc0?ui=en-us&rs=en-us&ad=us#mac&OSVersion=MacAppStore also only offers 22.248Question - anyone can share the URL to download 23.002.0102, please?
When trying to wipe and restore a couple of DEP/JSS managed iPads I am getting a message: "The configuration for your iPad could not be downloaded from Long Road Sixth Form College" "cancelled" Does anyone know what might cause this? There's no firewall between the iPad and our JSS, they're both on the same network, same subnet. Is there some Internet related thing that has to happen when downloading a configuration profile via DEP? We already set up our JSS with an externally-trusted HTTPS certificate, and it hasn't expired, so it shouldn't be that. Thanks,Dan Jackson (Senior ITServices Technician)Long Road Sixth Form College
Hi all,Is there a way within JAMF to disable users from turning off specific startup items? For example, right now we have standard users on Ventura that can simply go in and uncheck the sensor.
I’m attempting to get NetSkope for iOS configured and running once pushed to a small test group of iOS devices. It’s easy enough to install NetSkope for iOS via Jamf Pro; that’s not the issue. I’m trying to configure NS on said devices so that they communicate back with my companies cloud instance of NS. This requires a couple certs and configuration profiles. I know this from reading through NS configuration workflow documentation, sadly it’s for InTune….I’ve attempted to translate the InTune workflow into Jamf but things are just not lining up. I’m hoping someone has some advice or configuration profile recipes to share 😁 ( side note - all devices are fully DEP enabled , and enrolled in ABM and managed in Jamf Pro ) so I already have full control.
We're making changes to how we manage Outlook/Exchange data, and are implementing a policy on PCs where users will only be allowed to read PST files. They won't be able to attach new ones, and already-attached ones will only allow them to read and they'll get a message that they don't have rights to add new data to it if they try (using the PSTDisableGrow setting).I'm implementing the DisableExport and DisableImport preference settings on Mac, but I'm not finding a macOS/Outlook setting that corresponds to the PSTDisableGrow setting in Windows. Is there such a thing on Mac?What else can we do to keep users from adding emails to local storage on their Macs?
Our wifi requires that a profile containing several certificates be installed, and Monterey+ requires admin credentials to do this. This creates an unnecessary burden in the case of sysprep, changed passwords, and certificate updates. I'd like to allow standard users to add/remove profiles (that aren't managed by Jamf Pro). I'd hoped this would be as simple as it was to enable standard users to modify date/time settings, but the "security authorizationdb" command did not work for Profiles.Any suggestions would be appreciated!
I've seen a couple of old threads regarding ways of enforcing macOS security updates but not much for the recent version of Jamf Pro 10.x We are exploring the use of Patch Management currently. Does anyone have any best practice recommendations on enforcing devices to update to the latest critical or security updates on macOS when they are released?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!