Get Support
Recently active
We have a problem where our computers have been losing their profiles over time- we have a solution, running the command "profiles renew -type enrollment", but this requires us to get every single computer into our office one by one to manually run it. I attempted to automate this solution and have run into two new problems:1. In spite of the -forced flag, which Apple claims will skip over confirmation, it still asks the user to confirm the profile. Which our students would absolutely not do, if they even click on the notification.2. Even though the user should already be tied to the computer in JAMF, it asks us to put in their AD information again. Our students don't know* this information and we can only take a guess at this remotely, but we can't put it into that box as is.Is there any way to automate or skip over these issues somehow, or is there a better solution?Additional notes:Renew MDM profile in management fails on these computers- it returns a device signature error.They see
This has been an ongoing issue for months with no resolution and posting here to so if anyone knows a resolution. We know that this happens after updating from outdated OS to new version. we have tried turning off FDE, no installing AV at all, network wise - hotspot, ,home and corp network just to see what happens. it has always been same. we gotten to the point where all of our automations are self service just to make sure nothing is causing a issue. We do have an ongoing ticket but no available after numerous back and forth. Anyone out there knows anything about this? this has happened on v2.15-2.17 jamf connect.
I have just updated a student's iPad to 16.3, then tried to backup to iCloud. Since the update, it has defaulted iCloud backup and many of the iCloud toggles to off. when you try and switch them on, it says an error has occurred. reading online, it seems that 2FA needs to be on. All of the students use a managed Apple ID and there is no option to turn this on. Can anyone help?
How are others installing Adobe CC Shared packages in school labs? When I build the package within the Adobe Admin console, the pkg with almost all the products (media lab) is 28.2GB.
Hey All JS Friends - this is my first post. tl;dr background infoOver the scope of my time on this MDM (since Zuludesk...) I looked over my shoulder at Jamf Pro and wondered if we had made the correct choice (I was a total MDM newb and was taking information from a firehose). I knew that Jamf professional services supported best-practice engineer-assisted rollouts, but I "bit down and chewed on the low-budget choice and some learning as I went. Then Jamf purchased Zuludesk and voila I was now a Jamf customer. At a CITE conference Jamf session, I started asking about upgrading our School MDM to Pro to "use Jamf Connect." Instead, they helped us set up Pro services to review my MDM build and working conventions / set up Jamf Connect. end tl;drFast forward to my issue: Deploying Jamf Connect using Azure IDP (which also enhances security with MFA) is easy (Jamf Connect App, Custom Profile, and Logo image are added to a macOS Device Group). -in our environment, I a
I'm planning on taking the JAMF 300 course but before I do I wanted to work on familiarizing myself with scripting. Any good recommendations for a scripting course I can take? Thanks
Mac os Ventura 13.0 System preferences / System Settings(com.apple.systempreferences)key: SettingsExtensions type: <string> presence: optional rangelist: - com.apple.Accessibility-Settings.extension - com.apple.AirDrop-Handoff-Settings.extension - com.apple.Battery-Settings.extension - com.apple.BluetoothSettings - com.apple.CD-DVD-Settings.extension - com.apple.ClassKit-Settings.extension - com.apple.Classroom-Settings.extension - com.apple.ControlCenter-Settings.extension - com.apple.Date-Time-Settings.extension - com.apple.Desktop-Settings.extension - com.apple.Displays-Settings.extension - com.apple.ExtensionsPreferences - com.apple.Family-Settings.extension - com.apple.Focus-Settings.extension - com.apple.Game-Center-Settings.extension - com.apple.Game-Controller-Settings.extension - com.apple.HeadphoneSettings - com.apple.Internet-Accounts-Settings.extension - com.apple.Keyboard-Settings
I want to start enabling our users to upgrade their OS's through self service, however, there's a pretty wide gamut of different app versions that should be updated prior to an upgrade. Ideally I'd like to have a pop up with like a button to say XYZ app is out of date or need to be removed w/ an option click here to upgrade or remove as needed. Finally, if the device has an app like Centrify installed then to not allow the upgrade and instruct the user to reach out to IT.Currently we're using the erase/install DEPNotify package to handle an in place upgrade. This is checking for power, but not much else.
Started noticing this on machines for my enrollment script using jamfhelper. Doesnt seem to have any real bearing on outcome as the text prompts still show up, but in the logs, most, if not all, jamfhelper prompts are followed by com.apple.fonts not accessible. Excerpt from log with macOS Monterey with M1 pro Log from M1 with macOS Big Sur Any ideas why this is a thing?
Hey folks,Newer Jamf Pro user here. We've got about 230 devices enrolled, 98% of which are existing machines from the field (mostly remote) that we're using user-initiated enrollment for.We're doing pretty basic stuff, installing a few apps, issuing a password policy, and things like login screen message etc. One these machines, there is a local admin for our use, and the user is also a local admin.We've had two instances recently where, a user has rebooted, done the user-initiated enrollment, and then upon rebooting, is asked to change their password at login to comply with the password policy, and then the next time they try to login after this, they are told their password is wrong.I'm finding the same issue with the local admin, and the only way I can get in is if I push a new local admin account to the machine via a policy. But after I login, if I go to users & groups in sys prefs/settings, and I try to reset the password, I get "reset password failed."We are not using FileVau
Hi, I have just run into this issue recently whereby I try to remove vulnerable apps that are not installed to /Applications folder but copied and being run from Desktop or Downloads folders.Tried this easy command in terminal locally and worked like charm:rm -R ~/Downloads/Visual_Studio_Code.pkgSo then I created a policy that would use a script with the same exact command to remove the file and ended up having this:Script result: rm: /var/root/Downloads/Visual_Studio_Code.app: No such file or directoryCannot I just use tilde for specifying the currently logged in user's Download folder? Why does it say /var/root?I have 100+ users and not fancy writing a separate script for each of them where I just use the full path.I'm sure I'm overlooking some obvious scripting rules here so all advice would be greatly appreciated!
We just discovered that the portion of our fleet still running macOS Mojave (10.14.6) are no longer checking in, updating their inventory, or of course executing any policies or receiving any patches.When manually triggering a policy check-in or recon, we get this error:There was an error.Device Signature Error - A valid device signature is required to perform the action.This appears to have happened to all of these machines around the same time, all showing a last check-in/update on Friday 8/12 or Monday 8/15. It doesn't appear to be happening on any of our machines on 10.15 or later.The computers all still show they are managed, supervised, enrolled, and have MDM profile expiration dates far in the future.Initial spot testing using the Jamf binary self-heal with Jamf API seems to get it reenrolled successfully. Unfortunately we're unsure if this will stick since we have no idea what the cause was, nor do we know if there will be any other ill effects from this error or from the self-
Hello All, Please help me to get the MS link to download the latest version of office package for macOS so that I can make a script and use in my policy to install on macOS. I don't to do it from https://macadmins.software only MS link is needed. I will do curl to it.
Hello everyone,can someone tell me why the observe feature only exists in the classroom and not in the Jamf Teacher? Is it an apple thing?Thanks for clarifying.Peter
Is anyone currently having issues with Declarative Management and its rollout? I'm receiving a command failure with the following on all my systems which hit the base requirements of Declarative Management. Command: DeclarativeManagementError/Status: JSON text did not start with array or object and option to allow fragments not set. around line 1, column 0. JAMF Version: 10.42.1-t1667311080MacOS: 13.1Enrollment Type: DEP Any guidance would be greatly appreciated.
We just set up a cloud distribution point in AWS but no objects are replicating. The S3 bucket was created successfully and JAMF Admin says replication successful. It even showed the individual packages copying over the first time. However, there are no items in the bucket so something is failing somewhere along the way. I did find this (https://ideas.jamf.com/ideas/JN-I-16521) that appears to have similar issues but a fix was implemented. Still, the top comment is the only place I've seen the exact same problem listed. Plus, while server side encyption is enforced on AWS side I have nothing in any policies regarding encryption like they did. At this point, the only policy I have is the following test policy which is about as wide open as it gets:{"Version": "2012-10-17","Statement": [{"Sid": "AllowFullS3JAMFBucketsOnly","Effect": "Allow","Action": ["s3:*"],"Resource": ["arn:aws:s3:::jamf*"]},{"Effect": "Allow","Action": ["cloudfront:*"],"
Hi,I once again having issues using the new API / UAPI / Jamf Pro API.Getting error: "httpStatus" : 405, for which I cannot find description here: https://developer.jamf.com/jamf-pro/docs, anybody knows what it is?What I am trying to do is simply change computer's Site on JSS via the new API, any input would be appreciated ($id is current computer ID on JSS):curl -X PATCH "https://jss.MYCOMPANY.com:8443/uapi/v1/computers-inventory/$id" -H "accept: application/json" -H "Authorization: Bearer $token" -H "Content-Type: application/json" -d "{\\"general\\":{\\"site\\":[{\\"id\\":\\"6\\"}]}}"I have tried it using Site name as well:curl -X PATCH "https://jss.MYCOMPANY.com:8443/uapi/v1/computers-inventory/$id" -H "accept: application/json" -H "Authorization: Bearer $token" -H "Content-Type: application/json" -d "{\\"general\\":{\\"site\\":[{\\"name\\":\\"EMEA - London\\"}]}}" same error, the problem I suspect is with this: "{\\"general\\":{\\"site\\":[{\\"name\\":\\"EMEA - London\\"}]}}"
We are having a number of devcies that are not checking in. This is not a reoccuring thing but it is random.Example: I have one device that the MDM-SCEP Cert became invalid. By removing the MDM and then re-enrolling the device via User-initiaded the device is now communicating succesfully. Anyone have an idea why this is happening?
I'm trying to restrict access to Freeform on our K12 lab iMacs using Restricted Software payload in Jamf Pro. I was able to block the app on iPads in Jamf School using com.apple.freeform but that has not worked on Jamf Pro.I tried to block Freeform.app but have not had success. Anyone able to block this app from appearing?
I’m trying to package Citrix Workspace; I installed v2301, created the pkg with Composer, and uploaded it to JAMF. I also packed the Config file as DMG and set it to FUT & FEU. I installed Citrix Workspace and then replaced the Config file with my Config file, and I received an error message.If I uninstall Citrix Workspace with the included uninstaller and then install the original downloaded Workspace 2301 file and then run the Config settings policy to replace the Config file, then Citrix Workspace opens without any issues. I can’t figure out why the packaged version is causing so many issues; what am I missing?Any help is greatly appreciated!
We use Zoom a lot, so I modified a script that we were using for Firefox (Thanks Joe Farage!) to install or update to the newest version of Zoom. This one enables HD video, sets SSO logins to be default, and configures the URL for SSO. Below is the script: #!/bin/sh ##################################################################################################### # # ABOUT THIS PROGRAM # # NAME # ZoomInstall.sh -- Installs or updates Zoom # # SYNOPSIS # sudo ZoomInstall.sh # #################################################################################################### # # HISTORY # # Version: 1.0 # # - Shannon Johnson, 28.9.2018 # (Adapted from the FirefoxInstall.sh script by Joe Farage, 18.03.2015) # #################################################################################################### # Script to download and install Zoom. # Only works on Intel systems. # # Set preferences - set to anything besides "true" to disable hdvideo="true
When I trie to import placeholders I get an error.Could not update placeholder 'iPad xxxx' for serial 'XXXXXXXXXX', the DEP placeholder doesn't existCSV file for testing isSerialNumber,Identification,AssetTag,AssignToUser,MemberOfGroups,AutomatedDeviceEnrollmentProfile,DeviceName,LocationXXXXXXXXX,iPad xxxx,PADSX02,,BBBBBB - CCCCCC D,BBBBBB – DEP-profile,%AssetTag% - %SerialNumber%,Location XI have 'BBBBBB – DEP-profile' in Automated Device Enrollment Profiles and this works If I manually assign it to the devices. Profile name is double checked.AutomatedDeviceEnrollmentProfile is descibed in the documents https://docs.jamf.com/jamf-school/documentation/Placeholder_Devices.htmlThere's a CSV template in xxxx.jamfcloud.com/impex/devices.html but there's no AutomatedDeviceEnrollmentProfile and there are 7 labels but 8 colums???SerialNumber;Identification;AssetTag;AssignToUser;MemberOfGroups;DeviceName;Location2019XXXZDSK;Device001;Optional;Optional;Optional,Optional2;Optional;Optional2019X
Hi Folks, I've done some searching and noticed that there's been other folks who get 502 errors in the Casper Sync Log when transferring larger files from Jamf Admin to a Cloud Point. Unfortunately, we're stuck in a bad situation where we just bought cloud and we need to sync our 500+GB on prem point up to the cloud before we can make it the main point. We've tried everything on our side we can think of, switching DPs, making sure it's not some bizarre network issue or firewall thing. Small packages (usually under a GB) upload fine. Normally this is where I'd bring in JAMF support, and I did, but they've been basically sitting on it now for 2 months and all I've gotten from repeated escalations is "We're looking at it". Has anyone else ever gotten this happen recently? I noticed there were a lot of folks in 2020 (probably covid related when everyone was setting up cloud) but it doesn't seem to happen any more. I can't make it the primary point and try the web upload until I g
When applying a "Security & Privacy" config profile to a Mac with High Sierra with any combination of settings the Content Caching service is automatically disabled. I can work around this by applying a Restrictions profile and enabling "Allow Content Caching". I notified JAMF support of this, below is a snip from their response. I didn't find any existing discussions regarding this bug so I just wanted to make people aware. Turns out you were dead on right, this is reported Product Issue on our end (PI-004822) and we at this point we are trying to determine whether this is strictly a Jamf issue or if Apple has role as well. The workaround is also precisely what you indicated, adding a Restrictions payload and Allowing Content Caching. I have attached this case to the PI and the place to look for a future resolution would be via the Release Notes of the next JSS version
Hi, New admin looking for some advice. What is your typical stance on major upgrades such as Ventura? Do you guys have a normal workflow that blocks these updates for a certain amount of time or do you run with it on day 1? I am curious to see how other admins handle these updates.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!