Get Support
Recently active
Hello and Thank you in advance for any assistance. I purchased some apple devices through my apple business account at full price. Two of the devices need to be handed off to others outside of the company and we no longer want to manage the devices or have anything to associate us with them. I was able to remove the profile from the devices and no longer can see them in our inventory of devices. They are effectively unmanaged through JAMF. In the settings on the actual device there is still a flag at the top that says "device is being managed by... (and our company name)" How do I remove this flag from the device?
Hi,I'm trying to disable the sync options in the browsers mentioned above.For Chrome I've found <key>SyncDisabled</key> https://chromeenterprise.google/policies/#SyncDisabled but for some reason is not working, not sure if this is happening because I'm not editing the correct file or saving in the correct path.Can somebody help me out with this issue?Thanks in advance.
good day.after applying the Policy to enable the FV2 in JAMF, when the user restarts the machine he still have to 1- login to decrypt the disk2- sign in again with the AD user name and password.can someone offer a solution to have the password registered?well, let me break it down in other words.1- the devices/laptops are connected to the AD.2- users always use there AD credentials to login.3- the user now login twice, first login is to decrypt the disk and the second one is to login to the device itself.4- so the problem is what if the user forgets his AD password and i did a reset on the AD, he will not be able to decrypt the disk in order to login. so my question is that if i can just bypass the 1st login requested to decrypt the disk or i should be switching to a different method of enabling the FV2.
I finally ran across the 1st application we use that needs a separate installer for ARM64 and x64 platforms that we used Patch Management for. Here we are 3 years in to Apple Silicon, and JAMF still does not have a solution for this. The best JAMF has is to package both the ARM64 and x64 packages in to a temp directory, and run the correct package with a post install script which detects the platform. Take that package and use it for the Patch Management package. If anyone wonders why I almost never recommend using Patch Management and say just use polices, this is one of the reasons. After 3 years this is just lazy and we deserve better. Here is a feature request from 2 years ago with 4 votes. Lets see if we can give it some traction. Architecture Specific Patch Definitions | Jamf Nation Feature Requests
It's been a while and I have a question about Self-Service.Can Self-Service be accessed by a user via a URL on an unmanaged computer or even a mobile app on an unmanaged mobile device?Ideally, there are some areas that would be great to make available via Self-Service for a user when they're not necessarily on their managed Mac. For example, after being strongly authenticated into Self-Service, I would like to get my personal FileVault recovery token because as a user, I forgot my local password to my managed Mac.Please let me know if you have good direction here or if this just doesn't exist today. Thanks All!
I am doing testing and I don't want to wait for the recurring checkin trigger to time out. Is there a command that forces a checkin right now?
We have iPad Air 2 devices that we are trying to enroll. The devices are 7 years old, but the organization is requesting we use them.1. Unable to push applications to the devices (application licensing error)2. Verified we have plenty of licenses available and the devices contain the serial number in the portal3. Older devices that still have apps on them get an error in Teams when they try to open a new document.Is there a known issue with these devices in JAMF Pro?
We have some Macs that were "gifted" to departing staff and I need to remove them from management without wiping them. I am referencing the Unmanaging Computers from Jamf Pro article but it assumes having physical or direct network access, which I don't have. Is it possible to effect this using a Policy?I was thinking I could use the "nohup" utility to allow the commands to continue running without being terminated as the Jamf utility itself is removed. Something like this:nohup bash -c "sleep 30; jamf removeMDMProfile; jamf removeFramework; reboot" &This seems to work if I initiate the Policy from Self Service, but not if it is triggered by the Recurring Check-in. What am I missing?
Hi Everyone, new here! Does anyone know where I can find an administrators guide for Jamf School? The one for Jamf Pro is there but nothing for school? Any documents/pdf's welcome :)
I am encountering some issues with Jamf School and our iPads. I needed to erase and reset a device yesterday and the apps would not load. After erasing and resetting numerous times, I noticed that the profile was pulling in on our guest network. This profile shouldn't pull through until I put the device on the dedicated network. I also am having an issue with the weblinks on the devices not opening. It shows a black screen then changes to a white screen, but the weblink never loads.
so after applying the Policy for enabling the FV2, all works fine but the user password isn't synced with the AD, in another word, when the user restarts the machine he still have to 1- login to decrypt the disk2- sign in again with the AD user name and password.can someone offer a solution to have the password registered?
Using ABM, Intune and Jamf Connect, things are happy and deploying I think correctly but could use a second opinion on the Connect installation.On first boot, Mac os laptops ask to sign in via SSO (Azure AD), then it still asks me to create a local account. That local account once all the config profiles and Jamf menu bar install get back ground synced and the password to log into laptop becomes the AzureAD passwords. Jamf Connect is registered to correct user in menu bar etc after signing in once local user is created. Is this correct? should we still have to create a local user?
When I try to turn on "Enable Activation Lock on the device (Apple School Manager, Apple Business Manager)" in PreStage Enrollments, and the Shared iPad option is also selected, when I click Save it always ends up clearing that Activation Lock option. I can only turn it on if I disable the Shared iPad option. Do you guys see this as well?
Hey everyone, how can I go about zero touch macOS deployments? What are the Pre-Reqs for it? I have my Policies and apps build out. But device seems to still require a lot of “touch” by IT before providing it to the user.Any suggestion would be appreciated
Hi, i am sending a popup message to my users with SwiftDialog.In the logs i see a lot of these: Script result: 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: failed to connect - Error Domain=NSCocoaErrorDomain Code=4099 "The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process." UserInfo={NSDebugDescription=The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process.}2023-01-25 12:17:12.598 Dialog[29366:629409] Font server protocol version mismatch (expected:5 got:0), falling back to local fonts 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: unable to make a connection to the font daemon! 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: XTFontStaticRegistry is enabled as fontd is not available. 2023-01-25 12:17:23.919 Dialog[29366:629433] Spell server connection invalidated Pressed Button 1 OrScript result: 2023-01-25 09:24:55.813 Dialog[1302:12330] XType:
Hi, i am seeing a lot of errors in the logs of my swiftdialog message policy: Script result: 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: failed to connect - Error Domain=NSCocoaErrorDomain Code=4099 "The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process." UserInfo={NSDebugDescription=The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process.}2023-01-25 12:17:12.598 Dialog[29366:629409] Font server protocol version mismatch (expected:5 got:0), falling back to local fonts 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: unable to make a connection to the font daemon! 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: XTFontStaticRegistry is enabled as fontd is not available. 2023-01-25 12:17:23.919 Dialog[29366:629433] Spell server connection invalidated Pressed Button 1Script result: 2023-01-25 09:42:37.936 Dialog[11101:217909] Spell server connection invali
For anyone that prefers to make Safari updates available via Self Service, here are the standalone Safari 16.2 installer download links extracted from Apple's Software Update Server catalog...Safari 16.2 for macOS Monterey: https://swcdn.apple.com/content/downloads/56/51/012-74032-A_9J5DGEGRED/y2js2pclu7syop1z68wtptdnaddeog4u7f/Safari16.2MontereyAuto.pkgSafari 16.2 for macOS Big Sur http://swcdn.apple.com/content/downloads/36/08/012-82248-A_SAHUHK0ROJ/z04kizckik61f8z4fzyer6gw9mh50pbm9l/Safari16.2BigSurAuto.pkg
Does anyone have a script to set Outlook 365 to the default mail client on Big Sir and Monterey? I have the native mail program locked out so it can't be done through there.
The original logitech options (green icon) was easy to package because you could download the full 200mb installer.The new options plus (purple icon) has a "streaming installer" were you get a 20mb file at first then it kicks of the download for 200mb-ish installer.Anybody know how to package this?Grabbing the app from Application folder doesnt work due to other hidden files being installed.
We are currently having an issue with our Jamf Pro enrollment link. When users try to access the are receiving a 403 Forbidden Error message. No other details are included on the error page. These are Macbooks that have not been registered with jamf previously. My coworker found that reformatting and visiting our enrollment link seemed to fix the issue. The problem is we have close to 200 laptops that would need this done, all remote. I am trying to find another way to get this working again without walking 200 people through a reformat. I don't usually work with Jamf, but the workload right now is considerable so I'm trying to help out. Not sure where to start with this. We do use Okta for SSO, and we do have a group that assigns jamf to a user (we did check group membership for affected users). Any help is greatly appreciated.
After the advice I found on this sub, I switched from DEPNotify to swiftDialog (thank you all for that). However, I am having the same problem that I had with DEPNotify:Most of the policies in the array run without any issues - these are application install policies. They complete consistently without any problems.The policies that do not run correctly are the ones that set the Dock, rename the computer, apply the wallpaper, and (most annoyingly) Log Out the user via swiftDialog. It seems like they are the ones that rely on SystemEvents or osascript, etc... When I check in the Jamf Pro Policy logs, they are not even showing as being triggered so I can't get the cause for failure.Once the user logs out, enables FileVault, and logs back in, the policies run correctly (except for the fact that I need to give PPPC policies to Finder, which I don't seem to need on first login).Is there something that is either running or supposed to be running within macOS on first login that is causing the
So in the past I've used a mac mini running VMware Fusion 12 and creating images for everything from Catalina to Ventura. I can even test our Automated Device Enrollment which is great since we can record it to teach people about it.As we're moving to a Silicon chip world I've been trying to find a solution to do this on a Silicon machine. I've tried testing both VMware Fusion Technical Preview and even the latest version of Parallels...nothing seems to work as well as an intel machine. I know the world is changing and VM vendors are trying to catch up. But has anyone figured a good VM solution for Silicon that will let you adjust the host to input ADE stats like hw.model and serial numbers?
We are currently in the process of changing our antivirus software and deploying defender 365 on every mac in the office.The problem is that randomly on some macs there is a message that says: no licence foundIf anyone knows the solution or has experienced this type of problem.
I bought a used Macbook and have updated it to the latest Mavericks. From when I first powered it on I have been getting prompts to enroll the device. I can't get them to go away...only cancel them and they reappear dozens of times per day. I guess the folks who sold the machine have it in their DEP server? Or there is an agent that keeps checking? How can I disable the agent that keeps prompting me to join? Could not figure out after 30 minutes searching JAMF and other sites discussions of the various woes of school IT admins. :(
Wondering if anyone can help with this, we have Jamf Connect and I would like to roll it out to all of our users. I have it set up and it all works the way I want it to. However, each and every login requires you to verify your second authentication factor, even if you have previously trusted the device. (Device trust is enabled in Google Admin) Also, the user consent screen is displayed every time (less of an issue but from looking at the other discussions this seems an inherent issue with Jamf connect at the moment)
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!