Get Support
Recently active
I haven't been able to find more recent documentation on this particular situation/issue so figured I'd ask directly.My predecessors encrypted our AD binded lab devices which created major issues with new network user sign ins. After I got these physically locked down, I put the lab computer group into the exceptions of the FV2 policy. However, I realize of course the policy was already previously pushed to the devices and there is no "undo" button. I need to decrypt for all users and if I can avoid reenrolling the device altogether, that would be great. I don't know if fdesetup has the ability to decrypt for all users without a more complex script I'm not sure how to put together (our senior analyst who managed this left before I came on and honestly, looking at some of his work, I'm not sure he knew how do this management himself lol). I really appreciate any help that can provided for a fresh college graduate who basically had to become the senior analyst within 6 months haha--
We recently purchased 3 x M2 Macbook Airs with 256GB of storage. They were installed and has been used by a single user on each machine between November 11th and December 1st.Within the last couple of days all 3 users have complained about disks running full. Neither user has large files, the one with the most data uses ~40Gb in total (*including* applications!). I have tried running both CleanMyMacX (yuck!) as well as Grand Perspective. Both apps show ~40GB storage used, and the rest is "invisible". We are running Jamf Cloud and Jamf Connect on all machines. Disk Utility shows no APFS Snapshots.All of them are running macOS 13.0.1 and neither user has enough available space to update to macOS til 13.1. What to do? I seem to be looking at 3 reinstalls, but I would REALLY like to avoid this option :-)
Hello All, Please help me to convert MS office package into source file by composer, all time it is getting failed, any reason to get failed and what is the resolution. I am using Jamf composer.
I'm relatively new to PPPC configs. I ran across a PPPC config profile for some old software that had been renamed, but the profile hadn't been updated. It's a softphone client and requires Accessibility permission and access to the mic. Since macOS doesn't allow us to enable the mic, this PPPC should only have one property to set. I figured this would be easy. 😂I used the Jamf PPPC Utility to create the config profile. I added the application on the right panel, picked the Accessibility property, set it to Allow, then uploaded it to our Jamf server. On the Jamf server, I assigned the config profile to my test laptop (running Ventura). On the laptop, I verified that the profile had been installed. When I check my work in System Settings -> Privacy & Security -> Accessibility, the toggle for this softphone is still disabled.Am I doing something wrong? It's a fairly simple workflow. Maybe my expectations are off? I expected to see the Accessibility toggle for the s
I know this may not be the place to ask, but I wonder if some of you can assist. When I go into Rec Mode (2021 MacBook Pro M1) I go in Term > resetpassword > however only ONE admin shows, when there's multiple. Can anyone advise why and how to solve? Thank you,
Hi folks,Does anyone have a reliable method for setting MS Edge as the default browser?I came across the below script that I added to a policy that runs once per computer, but it doesn't work half of the times and I cannot pinpoint the cause.#!/bin/bash#### https://github.com/palantir/jamf-pro-scripts/blob/main/scripts/Set%20Default%20Browser%20and%20Email...# Name: Set Default Browser and Email Client.sh# Description: Sets default browser and email client for currently logged-in user.# Created: 2017-09-06# Last Modified: 2020-07-08# Version: 1.4.3### Copyright 2017 Palantir Technologies, Inc.## Licensed under the Apache License, Version 2.0 (the "License");# you may not use this file except in compliance with the License.# You may obtain a copy of the License at## http://www.apache.org/licenses/LICENSE-2.0## Unless required by applicable law or agreed to in writing, software# distributed under the License is distributed on an "AS IS" BASIS,# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIN
Bonjour,Depuis la diffusion et le passage à ipadOS 16.2 (Pas de retour avec les version précédentes), je suis dans l’impossibilité de pouvoir donner des "Ordres" sur mes appareils... (Actions > Avancées > Redémarrer / Éteindre).Les schémas d’enrôlements fonctionnent, pas de message d'erreur, identité de supervision actif, aucun problème sur ipadOS 15.7.2Quelqu'un rencontre t-il un problème similaire sur cette version ?Apple configurator : 2.16 (8A14) / MobileDevice (1497.1.14.101.4)Merci pour vos retours d'expérience,Cordialement,
Hey Guys! Not sure if this is possible anymore, but is there a script/command to use to allow an app for Accessibility? Trying to see if this is possible since our lab machines do not allow admin access. macOS 10.13 Thanks all!
Hey guys, hopefully a quick and easy answer to this one. Looking to bring a new client into Jamf Pro (+Connect) who has around 25 existing Mac's deployed nationwide. If we go through user-initiated enrolment, would those devices then be Supervised in the same way they would had they gone through Automated Device Enrolment (DEP)? Or will the answer to that vary by end-user OS? All new Mac's purchased will of course be put through ADE/DEP to ensure they're Supervised from the outset. This is purely to onboard the clients existing devices with minimal disruption. Thanks in advance 🙂🙏
Looking to create a feature request? Go to the feature request portal. There you can submit a new request, review any existing feature requests, vote, or comment. Here are a few helpful tips about feature requests. The Jamf Product team and other supporting teams will update these with comments or statuses in the platform. Our process to review and provide feedback is streamlined, as we use capabilities to group, merge, and tag feature requests. Our SLA for initial feedback on new feature requests is 30 days. Add categories to help group feature requests. We may continue to add fields as needed to help capture your great ideas and feature requests. We look forward to hearing what you think and any feedback that you may have on our products or the feature request process!
Hi Did any one use zoom schema as configuration profile. I just create that and deploy to a test machine but following window pop up when policy pushed and zoom app is runningI use schema from here: https://github.com/talkingmoose/jamf-manifests/blob/master/Zoom%20(us.zoom.config).json and configure some instances and leave null others. And then I create a policy to deploy latest zoom to endpoint. But after deploy the policy if user click "Not Now" then policy will failed. The workaround I found that if Kill the process before run policy then that window will not pop up again. Did anyone face same issue? Any suggestion will helpful
I am trying to use JAMF School api for Teacher . It is working.The one endpoint that I am having trouble with is changing the student photoTeacher - Photo - Upload2.0.0Change a student photo item, type, descriptiontoken , String, (Placed in URL) Token obtained by the POST teacher/authenticate callid, Integer, (Placed un URL) Student IDphoto, File, Photo file This is the only place in all the API endpoints that has a file as a type. I am going to explain my question in terms of the language that I’m coding in, Swift. The endpoint is expecting a file, containing the photo, and it does not indicate how it is expecting the file in the http body. It can be expecting the body to contain the file converted to the Data type or it might be expecting multipart for the http body. I don’t know of any other option. request.httpBody = fileData // Either this for Content-Type Header request.addValue("image/jpeg", forHTTPHeaderField: "
Hi folks.I try hard to get VPN On Demand to work. Unfortunately, it currently does not work with Jamf Pro's built-in way (PI-101098), so Jamf Support referred me to iMazing Profile editor. Getting bits and pieces from various web resources together, I tried to built a working VPNOnDemand.mobileconfig by myself, but as soon as I deploy it to my client, it does not have any affect.The VPN on Demand configuration should basically do the following:1.) If client connected to a certain company WiFi network ("SomeWifiNetwork" in the example), it should generally NOT use VPN at all.2.) If NOT connected to the WiFi network above, but any other network, it should ALWAYS establish a VPN connection while trying to connect to certain domains (example1.com and example2.com in the example).3.) Trying to connect to VPN server via L2TP ("1.2.3.4" in the example), shared secret included ("SHAREDSECRET" in example), user name and password should be prompted (hence not included in example).When I deploy i
good day, i have created a new policy under JAMF which it activates the filevault disk encyption which works fine. when i go and uncheck ENABLE under the policy OR remove the unit from the SCOPE, when i restart the designated unit it keeps showing the POP-UP message on login that Administrator is requesting to Enable the filevault, noting that if i press ENABLE button and then i go to system pref, the filevault is not enabled. so to brief how to get rid of the pop-up message after disabling the Policy OR at least removing the unit from the Policy scope. thank you in advance
I hope someone is able to assist. I am a little bit new to using Jamf but I have been asked to assist with moving about 120 macOS devices from one Jamf instance to another, and we have thought of using the GitHub ReEnroller package as a mechanism to re-enroll devices in the new instance. I have configured all the details as per described in this guide: https://dazwallace.wordpress.com/2020/08/27/migrating-macos-devices-from-one-jamf-pro-instance-to-another-using-reenroller-part-1-setup/ I have also followed the ReEnroller help page. The issue is that I can see the package has been deployed to a test macOS devices (manually as Self-service), which appears to be installing successfully, however, after the package is "installed" nothing really happens on the test device. the device is still enrolled into the source Jamf tenant.is anyone able to share your experience with this tool? are there any further articles or information related to ReEnroller? are there any known issues with ReEnrol
We are deploying FMPro 19 to various groups within our org. I am using the script provided by Claris to build a custom built package, which is working fine, however one ask we have from the program manager is to try to set a Host URL in the client so that they do not have to assist every user in doing so. Its not that its terribly difficult to instruct users how to do this, but there is only 1 person to support nearly 1k users for this project. I found one document, referencing FM Pro 15, that suggests adding the following attribute to the Assisted Install.txt file:AI_PREFERREDSERVERFORCONNECTION=<host URL>Unfortunately this is not working, at least not in FMPro 19. I've tried the usual format of fmnet:/<hostdnsname> and just entering the dns name without the leading fmnet:/Neither worked.Has anyone had any success in setting the Host URL via Jamf?FWIW, when set manually the host URL is listed in a Pref file within ~/Library/Preferences.
In my state (NJ) the governor just issued a directive to (among other things) disallow certain apps on government-owned devices. This includes TikTok which is garnering all the press, as well as many other apps from developers such as Huawei and Tencent. So restricting an app with a config profile is straightforward (wish I could DELETE the apps, but...). However, I'd like to restrict a developer's entire suite of apps, which theoretically should be easier than one app at a time. I just can't figure out how. Has anyone out there done this? TIA.
This is probably something very simple, we never really utilized SS but I would like to start. I can't seem to figure out how to add custom apps to SS. I know how to do it for App store apps as it's pretty just right there. Example, I want to make Skype for Business available in SS, how do I get it to show up under software. It's probably something I am missing but I really don't see where to add it.
Hi everyone, We are needing to renew our SSL certs for our wifi networks in the coming weeks and are curious what other folks do when the time comes? We have about 300 iPads currently and had a rough time doing it last year so are looking for any tips. I inherited sort of a mess and am trying to clean up our configuration profiles and was thinking of deploying the new certificates as its own configuration profile to each location in this process. Is this something you do? Any suggestions would be great!
Getting this on some (but not all) of our Intune registered Macs that looks like it's coming from JamfAAD. Nothing triggers it that I can tell, totally random. We recently went through registering everyone in Intune and saw a similar message at the end of the procedure (when JamfAAD launches), but everything had been fine since then. The only thing that changed was we upgraded JSS to 10.25 last night and we changed the Intune connector this morning from Manual to Cloud Connector (which was pretty seamless). Anyone know what could be causing this?
When I enrolled a mac on my jamf portal before I had an mdm profile that I could install on a mac, now it only propose me a quickadd.pkg, where could this come from?
Hi,Location service is running and detecting correctly London/Europe. However the time still set to UTC. I cannot see any obvious payload in JamfSchool to update the time to London/Europe. Any other alternatives to set it up please? Thanks
Is there any way to disable Incognito Mode in Chrome on iPads? I really don't see the purpose of Chrome on iPads, if I'm being honest. Safari seems like a much better option. I recently had to disable Private Browsing in Safari on our iPads. I wish there was a better option to do this other than the built-in web filter as we've been running into sites with issues, but it works. Just asking to see if I can quiet the cries from people that lost their Chrome.
I need some quick and easy instructions on how to integrate Jamf Pro with Jamf Safe Internet.
Hello everybody,fdesetup authrestart seems to be broken for accounts that have never logged in.I created a new user “test” with password “test” via Users & Groups (so it got a secure token and is a volume owner) and tried to authenticate fdesetup authrestart -delayminutes -1 with that account. I got an error and fde prompt after the next restart. After signing in as “test”, signing out and signing back in as original user, fdesetup authrestart worked for user “test”. This also applies to startosinstall and softwareupdate on ASi Macs, when trying to get either working with a managed admin account that has a secure token, is a volume owner but was never used to sign in, I always get the fde prompt after the first restart. When I try the same with the logged in user and password it works.Any workarounds for this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!