Get Support
Recently active
Can someone please advise how or where to get this .pem cert? Do I need to be a dev? Thank you,
Currently each admin has their own apple business manager account. I have all the servers setup under my account and that also pairs with activation lock as well.How can I have a shared account act as the activation lock account so that I can share the creds/pw with the techs? How do you get by the mfa tied to your phone number?
I have a fun situation.M1 macBook Pro, Enrolled into JAMF, with a 5 day deadline for Pairing a SmartCard before automatic enforcement kicks in.The intel macBooks haven't been an issue, since once enforcement kicks in, the user can still login to FV2 using their PW and then the machine can get policies from JAMF. (Removing the configuration profile if we so choose)The M1 macBooks appear to finally support SmartCard login at the FV2 screen, the problem with this is that we cannot use a PW or the Recovery Key from JAMF to bypass this screen. As the macBook doesn't have network connectivity while at the FV2 login screen, we cannot remove the config profile.We tried booting into Recovery, unlocking the disk, opening terminal, and removing the folders below with no luck. /private/var/db/ConfigurationProfiles/Library/Managed Preferences Any suggestions? I both love and hate the FV2 support for SmartCard as it greatly simplifies login, but now means that getting past recovery has bec
Not real sure on this, can I jump from 12.3 to 12.6.2? My friend a while back an the 12.6 update on a 12.4 device, but it only updated the 12.5.1. He was using erase-install and had picked the specific version 12.6.
Our third party service provider is asking if our MDM allows UI configuration profile to be installed. Does JAMF Pro have a setting for this? Bill
When OneDrive version 22.248.1127.0001 is installed, it immediately updates itself to 23.002.0102.There is nothing about 23.002.0102 on MS official release notes page:https://support.microsoft.com/en-us/office/onedrive-release-notes-845dcf18-f921-435e-bf28-4e24b95e5fc0?ui=en-us&rs=en-us&ad=us#mac&OSVersion=MacAppStore also only offers 22.248Question - anyone can share the URL to download 23.002.0102, please?
When trying to wipe and restore a couple of DEP/JSS managed iPads I am getting a message: "The configuration for your iPad could not be downloaded from Long Road Sixth Form College" "cancelled" Does anyone know what might cause this? There's no firewall between the iPad and our JSS, they're both on the same network, same subnet. Is there some Internet related thing that has to happen when downloading a configuration profile via DEP? We already set up our JSS with an externally-trusted HTTPS certificate, and it hasn't expired, so it shouldn't be that. Thanks,Dan Jackson (Senior ITServices Technician)Long Road Sixth Form College
Hi all,Is there a way within JAMF to disable users from turning off specific startup items? For example, right now we have standard users on Ventura that can simply go in and uncheck the sensor.
I’m attempting to get NetSkope for iOS configured and running once pushed to a small test group of iOS devices. It’s easy enough to install NetSkope for iOS via Jamf Pro; that’s not the issue. I’m trying to configure NS on said devices so that they communicate back with my companies cloud instance of NS. This requires a couple certs and configuration profiles. I know this from reading through NS configuration workflow documentation, sadly it’s for InTune….I’ve attempted to translate the InTune workflow into Jamf but things are just not lining up. I’m hoping someone has some advice or configuration profile recipes to share 😁 ( side note - all devices are fully DEP enabled , and enrolled in ABM and managed in Jamf Pro ) so I already have full control.
We're making changes to how we manage Outlook/Exchange data, and are implementing a policy on PCs where users will only be allowed to read PST files. They won't be able to attach new ones, and already-attached ones will only allow them to read and they'll get a message that they don't have rights to add new data to it if they try (using the PSTDisableGrow setting).I'm implementing the DisableExport and DisableImport preference settings on Mac, but I'm not finding a macOS/Outlook setting that corresponds to the PSTDisableGrow setting in Windows. Is there such a thing on Mac?What else can we do to keep users from adding emails to local storage on their Macs?
Our wifi requires that a profile containing several certificates be installed, and Monterey+ requires admin credentials to do this. This creates an unnecessary burden in the case of sysprep, changed passwords, and certificate updates. I'd like to allow standard users to add/remove profiles (that aren't managed by Jamf Pro). I'd hoped this would be as simple as it was to enable standard users to modify date/time settings, but the "security authorizationdb" command did not work for Profiles.Any suggestions would be appreciated!
I've seen a couple of old threads regarding ways of enforcing macOS security updates but not much for the recent version of Jamf Pro 10.x We are exploring the use of Patch Management currently. Does anyone have any best practice recommendations on enforcing devices to update to the latest critical or security updates on macOS when they are released?
Hi All, I am trying to understand what is this profile supposed to do? Because i have deployed it on two Mac OS X 10.13.6 computers but they don't seem to be updating even after a week. Its being used remotely so its hard for me to tell what is going on the users end. I have set it as following :
Does anyone know when they changed the policy activation & expiration times to be hardcoded to UTC? It used to be based on the time zone you set in your account preferences.
Hello! I am new to JAMF and was thrown into the thick of things managing several hundred iPads and a couple of dozen Macs. Regarding mobile devices, the organization I work for uses Lightspeed as their mobile POS. Several sites have reported issues processing credit card transactions. After reaching out the Lightspeed developer (not done by me), the folks at Lightspeed said to make sure that iOS and the Lightspeed app are up-to-date on the iPads. I was under the impression that if there was an update to the application, JAMF would be aware of it, download it, and push it to all of the devices that have a Lightspeed profile. But it seems like it hasn't for all devices. On some of the devices, when the user opens Lightspeed, it reports an update is available. What is the best way to push these updates out to these devices? Is it possible to force a single app to update? Thanks!
Hello all. I am using JAMF Pro to manage a group of iPads and need to turn the default web browser from Safari to Google Chrome. We are using the iPads to canvass voters, and we are using an online form as opposed to an app. I have set it so the websites have been whitelisted and able to be loaded which works. After that I created home screen icons using webclips and set them to the home screen. Right now, from what I can tell, clicking the icons on the home screen first attempts to run them via Safari, then they transfer to chrome. I have tried just turning off Safari using the JAMF configuration profile, but instead of opening the webapps are inactive. I went into the setting of Google Chrome and switched it so it says it's the primary browser, and checked Safari which also said the same. Is there a way to set Google Chrome as the default without it attempting to open webclips via Safari first? If not, is there a better way to get these links to open in Google Chrome witho
Looking at Mac Apps section to update Acrobat Reader DC. If I set it to all managed computers, does it only update the devices that actually have it installed or does it install on 'all' of devices, regardless of if Acrobat Reader DC is installed or not?
My organization uses iPod Touches that are managed by Jamf Pro and I was wondering if there was a way to disable the ability to toggle Silent Mode on and off as I have users that are missing notifications and once or twice Silent Mode was found to be active on the Device. I spoke to Jamf themselves and they said that they do not have a way to talk to that layer of the Device. Are there any alternatives or workarounds to getting such a thing done?
Hi all!We are working on creating a pretty basic hostname convention: setting it to [firstname].[lastname][#]While it's of course simple enough to set the first.last and append with a number, the hard part is if a user receives a second machine (or 3rd, 4th, etc).If Bob Smith is hired and we set his machine to bob.smith1, that's fine, but if in 3 years he qualifies for a new machine, we don't know how to automatically have it set to bob.smith2.Is there a way to read hostnames from Jamf Pro? I've looked into reading from a csv or Google Sheet, but the problem is then keeping either of those regularly updated.We've also looked into [first].[last].[serial], as the serial is of course unique, but we occasionally have users with longer names and would run into issues trying to append the whole, or even parts, of the serial number.We're open to hostname conventions others use, but we found this to be the easiest to manage as everything else we need can be pulled from the Jamf entries of each
Hello All,I am having a very weird issue where all of a sudden, out of nowhere, all users that have the AuthoritzationAuthory attribute on their account within Directory Utility are having issues logging in. It just doesn't want to authenticate. users without this attribute work just fine.Here is a photo of the Attribute:Here is a photo of the account not allowing us to login:Here is a photo of a user without the attribute. When we log in it prompts us to enter a password:We are connected to the AD domain using the native Active Directory tool on MacOSNone of these accounts are locally cached/built on this machineI am able to create mobile accounts via terminal for both of the accounts but I am still unable to log into the account that has that AuthenticationAuthority attributeHas anyone seen anything like this? I feel like something changed on our Active Directory side and how accounts authenticate to it since we have accounts from 2018 with this same attribute and they don't work.&nb
Hi, We are trying to find a way to email an enrolment package to existing staff and have them install it manually (thus enrolling into Jamf) without needing to enter an admin password at any point. I.e like an ADE 0 touch but this is for machines already in use. Some research suggests this is possible but we are confused about the exact process. It seems this is possible via a prestage config however we are stuck with where to download the enrollment package from (or how to create it). Thanks, Simon
Update 31 January 2023: Today we released 10.43.1. Full details, including the Cloud Upgrade schedule, are posted here. Today we are releasing Jamf Pro 10.43. Highlights of this release include: Conditional Access Registration Improvements The process for registering computers with Microsoft Intune has been improved in the following ways: • The process name of the agent on client computers with Conditional Access has been renamed from "JamfAAD" to "Jamf Conditional Access". This change helps promote familiarity and confidence for end users when their computers prompt them to sign in with their Microsoft Azure account credentials. • When configured to use WKWebview, Jamf Conditional Access no longer displays the sign in window over the top of the information window, creating a clearer experience for end users. • When configured to use the WebAuth view, Jamf Conditional Access now includes instructions for end users to click OK on the browser's Select a C
Today we are releasing a maintenance version of Jamf Pro.Jamf Pro 10.43.1 fixes the following product issue:[PI110938] Jamf Pro no longer sends looping InstallProfile MDM commands to computers in the scope of automated deployments for Jamf Protect.For more information on what’s included in this release, review the release notes here.To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro.Cloud Upgrade ScheduleYour Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 10.43.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. Hosted RegionBeginsEndsap-southeast-23 February at 1300 UTC3 February at 2200 UTCap-northeast-13 February at 1400 UTC4 February at 0000 UTCeu-central-13 February at 2300 UTC4 February at 0900 UTCeu-west-24 February at 0000 UTC4 Febru
Helpful Links We know a few things have moved around. Here is a set of links to help you find what you need. Community Guidelines Jamf Account Jamf Homepage Product Documentation Search Training Courses Training Catalog Jamf Marketplace Jamf Swag Store dogs.Jamf.com Commonly Asked Questions How do I access Product Documentation/Knowledge Base articles? You can access these documents in two places within Jamf Nation: In this post under the Helpful Links. In the footer of Jamf Nation. Note: Knowledge Base articles have been converted into Technical Articles for consistency with the other product documentation that Jamf publishes. Where do I access My Assets? This lives within Jamf Account Where do I contact Support? You can access Support through Jamf Account Where do I access the training materials? You can easily access the training materials in Jamf Account How do I submit a Feature Request? The Feature Requests tile on the home page of Jamf Nation con
Anyone have best practices for redirecting the ~/Library folder to a network share for Mac OS End-users? I have an Educator that insists that this happens. With a script run at first login, we can easily achieve the redirection of the Library folder to a network server using a symbolic link that points "/User/Username/Library" to the End-users home share. We do this succesfully for allother folders (e.g., Documents, Music, Movies, etc.). The problem is that we don't want to point to an empty folder, so we try to copy the contents of the local folder to the Home Share before deleting the local folder and creating the symbolic link. The folder appears to be quite large (~18GB), and copying it is impractical at first login. Furthermore, I'm finding that the Mac OS doesn't want to read plist files in the redirected library folder, which means most of our JAMF policies fail. I'm open for any suggestions.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!