Get Support
Recently active
Hi All, I am trying to understand what is this profile supposed to do? Because i have deployed it on two Mac OS X 10.13.6 computers but they don't seem to be updating even after a week. Its being used remotely so its hard for me to tell what is going on the users end. I have set it as following :
Does anyone know when they changed the policy activation & expiration times to be hardcoded to UTC? It used to be based on the time zone you set in your account preferences.
Hello! I am new to JAMF and was thrown into the thick of things managing several hundred iPads and a couple of dozen Macs. Regarding mobile devices, the organization I work for uses Lightspeed as their mobile POS. Several sites have reported issues processing credit card transactions. After reaching out the Lightspeed developer (not done by me), the folks at Lightspeed said to make sure that iOS and the Lightspeed app are up-to-date on the iPads. I was under the impression that if there was an update to the application, JAMF would be aware of it, download it, and push it to all of the devices that have a Lightspeed profile. But it seems like it hasn't for all devices. On some of the devices, when the user opens Lightspeed, it reports an update is available. What is the best way to push these updates out to these devices? Is it possible to force a single app to update? Thanks!
Hello all. I am using JAMF Pro to manage a group of iPads and need to turn the default web browser from Safari to Google Chrome. We are using the iPads to canvass voters, and we are using an online form as opposed to an app. I have set it so the websites have been whitelisted and able to be loaded which works. After that I created home screen icons using webclips and set them to the home screen. Right now, from what I can tell, clicking the icons on the home screen first attempts to run them via Safari, then they transfer to chrome. I have tried just turning off Safari using the JAMF configuration profile, but instead of opening the webapps are inactive. I went into the setting of Google Chrome and switched it so it says it's the primary browser, and checked Safari which also said the same. Is there a way to set Google Chrome as the default without it attempting to open webclips via Safari first? If not, is there a better way to get these links to open in Google Chrome witho
Looking at Mac Apps section to update Acrobat Reader DC. If I set it to all managed computers, does it only update the devices that actually have it installed or does it install on 'all' of devices, regardless of if Acrobat Reader DC is installed or not?
My organization uses iPod Touches that are managed by Jamf Pro and I was wondering if there was a way to disable the ability to toggle Silent Mode on and off as I have users that are missing notifications and once or twice Silent Mode was found to be active on the Device. I spoke to Jamf themselves and they said that they do not have a way to talk to that layer of the Device. Are there any alternatives or workarounds to getting such a thing done?
Hi all!We are working on creating a pretty basic hostname convention: setting it to [firstname].[lastname][#]While it's of course simple enough to set the first.last and append with a number, the hard part is if a user receives a second machine (or 3rd, 4th, etc).If Bob Smith is hired and we set his machine to bob.smith1, that's fine, but if in 3 years he qualifies for a new machine, we don't know how to automatically have it set to bob.smith2.Is there a way to read hostnames from Jamf Pro? I've looked into reading from a csv or Google Sheet, but the problem is then keeping either of those regularly updated.We've also looked into [first].[last].[serial], as the serial is of course unique, but we occasionally have users with longer names and would run into issues trying to append the whole, or even parts, of the serial number.We're open to hostname conventions others use, but we found this to be the easiest to manage as everything else we need can be pulled from the Jamf entries of each
Hello All,I am having a very weird issue where all of a sudden, out of nowhere, all users that have the AuthoritzationAuthory attribute on their account within Directory Utility are having issues logging in. It just doesn't want to authenticate. users without this attribute work just fine.Here is a photo of the Attribute:Here is a photo of the account not allowing us to login:Here is a photo of a user without the attribute. When we log in it prompts us to enter a password:We are connected to the AD domain using the native Active Directory tool on MacOSNone of these accounts are locally cached/built on this machineI am able to create mobile accounts via terminal for both of the accounts but I am still unable to log into the account that has that AuthenticationAuthority attributeHas anyone seen anything like this? I feel like something changed on our Active Directory side and how accounts authenticate to it since we have accounts from 2018 with this same attribute and they don't work.&nb
Hi, We are trying to find a way to email an enrolment package to existing staff and have them install it manually (thus enrolling into Jamf) without needing to enter an admin password at any point. I.e like an ADE 0 touch but this is for machines already in use. Some research suggests this is possible but we are confused about the exact process. It seems this is possible via a prestage config however we are stuck with where to download the enrollment package from (or how to create it). Thanks, Simon
Update 31 January 2023: Today we released 10.43.1. Full details, including the Cloud Upgrade schedule, are posted here. Today we are releasing Jamf Pro 10.43. Highlights of this release include: Conditional Access Registration Improvements The process for registering computers with Microsoft Intune has been improved in the following ways: • The process name of the agent on client computers with Conditional Access has been renamed from "JamfAAD" to "Jamf Conditional Access". This change helps promote familiarity and confidence for end users when their computers prompt them to sign in with their Microsoft Azure account credentials. • When configured to use WKWebview, Jamf Conditional Access no longer displays the sign in window over the top of the information window, creating a clearer experience for end users. • When configured to use the WebAuth view, Jamf Conditional Access now includes instructions for end users to click OK on the browser's Select a C
Today we are releasing a maintenance version of Jamf Pro.Jamf Pro 10.43.1 fixes the following product issue:[PI110938] Jamf Pro no longer sends looping InstallProfile MDM commands to computers in the scope of automated deployments for Jamf Protect.For more information on what’s included in this release, review the release notes here.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro.Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 10.43.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. Hosted RegionBeginsEndsap-southeast-23 February at 1300 UTC3 February at 2200 UTCap-northeast-13 February at 1400 UTC4 February at 0000 UTCeu-central-13 February at 2300 UTC4 February at 0900 UTCeu-west-24 February at 0000 UTC4 Febru
Helpful Links We know a few things have moved around. Here is a set of links to help you find what you need. Community Guidelines Jamf Account Jamf Homepage Product Documentation Search Training Courses Training Catalog Jamf Marketplace Jamf Swag Store dogs.Jamf.com Commonly Asked Questions How do I access Product Documentation/Knowledge Base articles? You can access these documents in two places within Jamf Nation: In this post under the Helpful Links. In the footer of Jamf Nation. Note: Knowledge Base articles have been converted into Technical Articles for consistency with the other product documentation that Jamf publishes. Where do I access My Assets? This lives within Jamf Account Where do I contact Support? You can access Support through Jamf Account Where do I access the training materials? You can easily access the training materials in Jamf Account How do I submit a Feature Request? The Feature Requests tile on the home page of Jamf Nation con
Anyone have best practices for redirecting the ~/Library folder to a network share for Mac OS End-users? I have an Educator that insists that this happens. With a script run at first login, we can easily achieve the redirection of the Library folder to a network server using a symbolic link that points "/User/Username/Library" to the End-users home share. We do this succesfully for allother folders (e.g., Documents, Music, Movies, etc.). The problem is that we don't want to point to an empty folder, so we try to copy the contents of the local folder to the Home Share before deleting the local folder and creating the symbolic link. The folder appears to be quite large (~18GB), and copying it is impractical at first login. Furthermore, I'm finding that the Mac OS doesn't want to read plist files in the redirected library folder, which means most of our JAMF policies fail. I'm open for any suggestions.
So our Security department has found a major bug with all Git Clients that access Git repositories. https://github.com/blog/1938-vulnerability-announced-update-your-git-clients Im wondering if anyone knows what the most popular Git Clients are on Mac OS x. Thanks!
Hello all, I'm new to JAMF and I was wonder if there's a way to change the option names in Self-Service? For example, when you open Self-service and on the left you see HOME, BROWSE, NOTIFICATIONS, HISTORY as the default, is there a way I can change those to say something else? I'm sure there's a resolution to this, but I can't seem to find it. Thanks for the help.
Hi everyone, Pulling my hair out in regards to implementing Jamf Connect in a PreStage Enrollment. The SSO mechanism is using Azure. If we don't implement any PreStage Enrollment, the DEP MacOS device will prompt for our Azure credentials and then prompt for a Local Account to be created. Once logged in, we can then push all the Jamf Connect profiles and policies to the device, reboot and Jamf Connect works like a dream. This is the same for User Enrolled devices using the web enrolment URL. The issue comes when I try to get it built closer to a Zero touch solution by adding in the PreStage enrollment. It goes through the Azure Authentication prompt, installs all the profiles (can't see if it is installing the Jamf Connect package, but I'm guessing it is because it is in the PreStage).Then I get a prompt, "Hello (User). Please re-enter my password". I can see that this is pulling the correct User from Azure because I've changed the claims to ve
Hi, we are currently using our jamf pro istance to manage some iPads. They are shared among our users (mainly as drawing devices for our graphic designers or to present the proposals to the clients).The issue i would like to solve is this: sometimes users downlaod and log in to gmail or to the synology drive app with their personal account. This is correct because they are sometimes needed.I would like to reset those apps every day or when needed. Is there a way to do that without resetting the ipad each time?
So I'm looking at this guide on Office templates. I created a DMG and did FUT/FEU to deploy the templates. I see them in the "/Users/username/Library/Application Support/Microsoft/Office/User Templates/My Templates" folder. But I want my end users to just open Word, Excel or whatever and have the templates show up in the main screen along with the rest of the templates: Has anyone done this before in Office 2016?
Hey Guys,is there a way to build a smart group for "not used" Apps in the last (maybe) 10 days?We want to shorten our Browser List and remove Firefox, but first to all Devices that don't use Firefox.I checked the box for "Collect Application Usage" and we see the Usage Information in the Computer Objects. I just need a way to collect all information into one Group to scope the removal script.Thanks for some Advice!
hellow community, i need your help today with a DEALY issue after applying the following script in Jamf Pro. after adding the script into Jamf there is a delay with the logon for the end user.username="$3"serialnumber="$(ioreg -c IOPlatformExpertDevice -d 2 | awk -F\\" '/IOPlatformSerialNumber/{print $(NF-1)}')"ip="$(ifconfig | grep 'inet 10' | grep -m1 -o '\\d\\{1,3\\}\\.\\d\\{1,3\\}\\.\\d\\{1,3\\}\\.\\d\\{1,3\\}' | grep -m1 '10')"#echo ${username} >> /usr/local/bin/Logs/logs.txt#echo ${serialnumber} >> /usr/local/bin/Logs/logs.txt#echo ${ip} >> /usr/local/bin/Logs/logs.txt
Our clever students are now switching their bluetooth off so that Apple Classroom doesn't work on their iPads. Is there a way for me to force it to be always on? At least whilst they are on campus? Or maybe get a notification if it's turned off? Just strategizing first to see what you guys say for an easier option.
Hello,we are facing the following situation:In a 1:1 Scenario (sponsored BYOD) the provided iPads belong to the students, so we are not allowed to fully manage them with Jamf. Nevertheless we use User Registration and deploy some profiles with settings like WLAN Access etc.What we are looking for is an option for location based WLAN Access and/or deployment of profiles: The students should be able to apply a profile (automatically) when entering the WLAN at school and also the profile should be deleted when leaving school (or the WLAN).I did some experiments with Jamf places, but it did not really work well. Some experiments with the external IP Adress of our school and various subnets/places did not work either.So is it possible to establish a workflow like described above or are there third party products to provide these functionality?We use Jamf School. i have no experience with Jamf Pro - is this possible within Jamf Pro?An help or suggestions would be very welcome&nbs
We are having numerous (but not all) Macbooks failing to enroll in jamf when they are first being setup. They are not installing self-service app and do not show under computers after setup. Weird thing is that config profiles are being installed. Some of these are M1's and others are Intel based systems.Can someone point me to what logs we could look at to see why these are failing?
Hi all We have an EA in place to retreive the Apple update server CatalogURL that's set on each Mac, it works consistantly on all our 10.9 machines but i'm getting incosistent results from 10.10 and 10.11 machines. We're pushing out the CatalogURL in a computer level Configuration Profile so it adds the CatalogURL to /Library/Managed Preferences/com.apple.SoftwareUpdate.plist andnot to /Library/Preferences or /var/root/Library/Preferences If i run jamf recon the EA reports back with no result on about half of the machines if i then run the command directly on that Mac in terminal (the plist definitely has a CatalogURL key within it) As root defaults read /Library/Managed Preferences/com.apple.SoftwareUpdate CatalogURL i get Segmentation fault: 11 as admin sudo defaults read /Library/Managed Preferences/com.apple.SoftwareUpdate CatalogURL i get no result as admin without sudo defaults read /Library/Managed Preferences/com.apple.SoftwareUpdate CatalogURL i either
I'm trying to run Crowdstrike on a VM for macOS Ventura 13.0 but it fails to install - when I check the logs in jamf I get this error:Installation failed. The installer reported: installer: Cannot install on volume / because it is disabled.installer: The version of macOS is too new.Does anybody know how to fix this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!