Get Support
Recently active
Hi all,I have enrolled 25x ipad before I upload the inventory preload csv, is there a method for jamf pro to sync/update the data information from inventory preload?
We are having issues connecting to Monterey Macs with ARD suddenly. We enable Remote Management during setup with a script (down below) that uses the kickstart command to activate, set access to specified users, specify the local Administrator account that is on all machines, and finally allow that account all privileges. This allows us (IT) to remote into machines while they are in one of our buildings/on our network to work on them or help users. Some of our machines run a second script that allows another local account on them for teachers to access but with fewer privileges (basically observe and message only). When connecting to a machine, ARD will give the following error:Screen Sharing is grayed out in System Preferences as usual, but unchecked. We're not really sure what caused this sudden change. We do get the occasional 'black screen with mouse only' issue, which we resolve by sending the Disabled Remote Desktop command from the Mac's manag
Hello Team, Our organization's mac devices are getting managed by JAMF but device has to be registered in Intune/AAD to implement conditional access policy, and this process is manual, I mean users are supposed to open Self-Service app and run the Intune registration app to follow the next steps to register their mac in Intune/AAD. My question is that, is it possible to automate this job so that all mac devices will be registered automatically in Intune/AAD at the time of enrollment in JAMF?
Dear Community! I am having a hard time finding a solution for scheduled machine restarts. I have plenty of mac devices in my fleet and my users tend not to restart their machines once in a while so I wish to set a two week / 1 restart schedule for instance every second week wednesday 17:00 in the afternoon - so they dont come complaining that they are out of memory and their machines are slowing by the day. Does anyone have any ideas on how to do this? I even wish to have a countdown and a notification to save everything because your machine will automatically reboot in 30 minutes (for instance). Is this possible to do in Jamf? Thank you in advance!David
Hello,Our institution is using Jamf | Pro. One of the requirements for computers in our labs is that we ensure we have the same keyboard input options (with many different languages available as inputs) across all of our Macs, while maintaining the standard U.S. keyboard as the default input.I understand there are many ways of producing the .mobileconfig files for delivering a custom payload as a configuration profile. I'm beginning to learn the options provided by iMazing profile editor, for example; however, I haven't found any configurations within it for managing keyboard inputs.So, I used a test computer and made the keyboard input preferences on it that we want (via System Settings, Ventura). I then pulled the com.apple.HIToolBox.plist containing those preferences. If I were to attempt using that .plist as a method, I then need to get the file into the .mobileconfig format for Jamf | Pro's payload. I'm not quite sure how to go about this.Jamf has documentation available online th
Hi allI have setup our Jamf Protect tenant and have integrated it with Jamf Pro.Ive setup Jamf Pro to automatically install the Jamf Protect Plan. When it trys to install the configuration profile on a macbook I get the following error message“The certificate could not be verified (authentication error)”Also, when I save the Jamf Protect configuration profile, it says Error Check your Jamf Server Software logs. When I look at the logs it doesn’t make much sense to me.Thanks,
Wondering if this is just an issue with my tenant or if others have noticed the same problem with Ventura. We use Jamf Connect for our Azure IDP and it works great on all Macs that have not updated to Ventura. My own device and Ventura test users are noticing that Jamf Connect no longer prompts for Azure Credentials when signing into computer. We only get the File Vault login and then it logs directly into user account. I had to update my password this morning and I did it with the Reset Password option from the Jamf Connect Menu. It changed my Azure password, but not my File Vault password and now Jamf Connect gives me an error and says I need to sign into my account again. The problem with that is the username and password fields are greyed out and I can't type in them.
We typically use Jamf to send a lock command to our MacBooks on. We have one MacBook that has the "Incorrect PIN entered too many times. Please try again in x minutes" where x = 24,321,071.Does anyone know of a way to get past this besides waiting 46 years?
Trying to write a replacement for SetDefaultMailApp which implies LaunchServices but seems to be part of CoreServices now and I've installed the python module but have no idea how to import it so I can use LSSetDefaultHandlerForURLSchemeThanks for any Python 3.11 help.
Hi EveryoneI am facing issues with Pulse Secure in macOS Ventura. Hostchecker.app is blocked by macOS as it is not from an identified developer. Any Idea how this can be allowed as this is causing SAML authentications to fail.Message in system Settings: "HostChecker.app" was blocked from use because it is not from an identified developer.Error: "HostChecker.app" is damaged and can't be opened. You should move it to the Bin.
Hi AllI am facing challenges in setting up conditional access for JAMF Pro on premise instance with intune as we are seeing following error. Could not retrieve the access token for Microsoft Graph API. Check the configuration for macOS Intune Integration.This connection was working before and it started showing terminated in intune and we couldnt figure out the root cause for the same as the terminal timelines are not matching with any other changes performed on the jamf side. We have tried deleting the old connector and settings in intune as suggested by Microsoft teams and recreated another app with fresh id and secret keysJAMF pro is hosted in windows environment and connecting to azure via proxy ( SSL inspection is bypassed and there are no blocking logs seen in proxy for the mentioned traffic)proxy setting is configured via JVM properties and we dont see any issue with the proxy setting as jamf pro application can communicate with jamf cloud and ABM using the same channe
My Push Certificate is expiring in several days. I have access to the account used for the certificate, however when I try and sign in to the Push Certificates portal I'm given the error "Your Apple ID is not allowed to sign in to this application":I have no issues using this account to sign in to other Apple services such as Apple School Manager. Apple has no idea what is causing this. I'd rather not re-enrol devices as this would be a huge amount of work. Has anyone had a similar problem? What can I do to fix this?
I am wondering if we are able to set a default homepage on Safari for our manged IOS devices, I have had a look through the configuration and cannot see anything referencing it
Before I explain the problem I should probably mention I'm very new to scripting. I'll happily accept "operator error" if it leads to an answer.I have a script that I wrote that sets the Mobile Device Name of an Apple TV via the Classic API. It's run via a policy in Self Service. It prompts for a Serial Number, the name you want to set it too, url encodes the name, and then sets the name.I've started noticing that after the Apple TV does an Update Inventory, the name will revert to whatever it was previously. That's usually a serial number when the Apple TV is first configured, or if it's something that we had set through the jamf website it'll revert to that as well.We use a dedicated Jamf account for this, but I've even tried the script with my own account which is a full admin account. The script is using basic authentication but I tried it with a bearer token as well with the same result. I've also tried running it via Self Service or via the terminal directly.I don't know if it's
I need a little help my company is new to Jamf Pro and we are trying to setup our Jamf Pro. We have just about everything working, our Jamf Pro is connect to our Azure with Cloud Identity Providers we also have Single Sign-On configured. The problem we are having is when we are going through the setup of a new IOS device and it reach the remote management screen asking for the username and password the users cant authentication to get past the remote management screen. we also use duo so I don't know if that is blocking users from authentication, but If I turn off Require Credentials for Enrollment the phone enrolls just fine. We can not figure out how to get remote management to allow users to authenticate please help.
Hey Everyone!I want to grey out the "remote login" option under Sharing preferences for users so they won't be able to switch it on again.can someone please advise what is the best way to make it with Jamf pro?thanks!
Hi all,Just seeing if anyone can help with this, we've gone from Symantec Endpoint Protection 14.3 RU3 to RU6 and upgraded our Mac estate to Ventura at the same time. These work fine but when trying to setup a new Mac or a re-formatted Mac and installing Symantec Endpoint Protection 14.3 RU6 on a clean Ventura Mac the screen doesn't display the extension to allow itIt should popup Privacy & Security and ask to allow Symantec Endpoint Protection but it doesn't.I have created a Allowed System Extension and checked and the Mac has this installedTeam Identifier: Y2CCP3S9W7Allowed System Extension: com.broadcom.mes.systemextensionWhen I retry setup on Symantec Endpoint Protection it just comes back to this issue and I can't get past it. Has anyone else experienced this and managed to get it working on Ventura on a clean install?
On the iPad: General > VPN & Device Management only displayed VPN - not anything to do with MDMUpgraded to the latest OS from the device and now I see all the Configuration Profiles in General > VPN & Device Management but still when I try and do anything that uses a remote command from Jamf Pro such as restart or Inventory it stays with a status of "Pending". The MDM Profile looks to be current.Before upgrading iOS there were a bunch of failed commands like this in JamfThe UUID for the profile “Self Service Web Clip” is not unique.My current idea is to wipe it and rebuild with Apple Configurator.If it was a Mac I'd try a "profiles renew -type enrollment" command but I can't see how to do that for an iPadThis is 1 of 80 but the only one that is misbehavingIt, like the other 80 received a new config profile to access the wifi a week or so ago changing from user authentication to certificate authentication. It can access the internet fine so it's not simply a network
Our students are their own iPads and take them home (well, the parents bought them). At school, we experienced problems students playing private games or using YouTube during breaks (and even sometimes during classes).We created a location based profile in Jamf School (Organisation - Settings - Regions), that is dependent on the IP address and the geographic location. Unfortunately, that profile isn't 100 % reliable, only 70-80 %.We saw that we can give an IP address range by omitting some parts of the IP address. Is there a way to use a geographic range rather than an exact latitude and longitude?We tried omitting some numbers on the latitude and longitude, but it didn't help. Not all present students show up in the smart group that is based on the geo location.Any help would be appreciated.Thank youKai
Hi All.We would like to block access to YouTube between certain hours for our iPads. It is obviously possible to do this via the Jamf Teacher App. I'm surprised that it isn't possible on a global level via the main Jamf interface.Or am I missing something? Is there some way to achieve this?CheersNick
When I look at individual computers I'm able to see the installed applications, however, when I use the 'Search Inventory' feature and the 'Applications' filter there are no results. It's the same if I enter a known application or leave it blank. Any suggestions?
I've performed a number of zero-touch distributions for a hardware refresh I've been working on with my colleague. Randomly we have users that are getting locked out of their machines and that number continues to grow by the day. At first, we believed it to be a Local User Admin script I was running that would create a user admin for troubleshooting things locally, but there have been some machines that are getting locked out and haven't run the script. In some cases, a resetPassword in recovery mode reset fixes it (2 cases). In the cases that it doesn't, we'll be able to get through an initial login window only to follow up with the same user behind it and the password we just set, won't work. In this case, we are having to wipe the drive and install a fresh copy of Mac OS. Have any of you encountered this before? Is it something to do with Keychain? Any suggestions on how to troubleshoot this? Best Regards,Baker
We use Google login to enroll our users in JAMF. We were told by JAMF engineers during our setup, that we could use Google SSO for the login OR leverage Google LDAP. If we setup LDAP, then we'd have an extra step of pre-populating users and groups in the JAMF settings in order to use SSO. We don't want to have to pre-populate or manage users in the settings. So LDAP is not currently enabled. When our users login through SSO for the first time, their Username (which is their email address) is automatically captured in "User and Location", which is great. However, we have another system that will sync asset information, but it is hard coded to use the Email Address field. Is there any way to easily script setting the Email Address field to what is already populated in the Username field?
Looking through the archives has done me no favors, I need a way to find out which users/Macs have iCloud enabled. At some point I need to disable iCloud outright and knowing how many users have it enabled would be extremely helpful.
When I enroll my INTEL macs they keep on loading up the system preference page to the appearance section. Also I noticed when I click the system preference icon and hold it brings up a long list of items. My M1s don't do this. What do I do?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!