Get Support
Recently active
Before I explain the problem I should probably mention I'm very new to scripting. I'll happily accept "operator error" if it leads to an answer.I have a script that I wrote that sets the Mobile Device Name of an Apple TV via the Classic API. It's run via a policy in Self Service. It prompts for a Serial Number, the name you want to set it too, url encodes the name, and then sets the name.I've started noticing that after the Apple TV does an Update Inventory, the name will revert to whatever it was previously. That's usually a serial number when the Apple TV is first configured, or if it's something that we had set through the jamf website it'll revert to that as well.We use a dedicated Jamf account for this, but I've even tried the script with my own account which is a full admin account. The script is using basic authentication but I tried it with a bearer token as well with the same result. I've also tried running it via Self Service or via the terminal directly.I don't know if it's
I need a little help my company is new to Jamf Pro and we are trying to setup our Jamf Pro. We have just about everything working, our Jamf Pro is connect to our Azure with Cloud Identity Providers we also have Single Sign-On configured. The problem we are having is when we are going through the setup of a new IOS device and it reach the remote management screen asking for the username and password the users cant authentication to get past the remote management screen. we also use duo so I don't know if that is blocking users from authentication, but If I turn off Require Credentials for Enrollment the phone enrolls just fine. We can not figure out how to get remote management to allow users to authenticate please help.
Hey Everyone!I want to grey out the "remote login" option under Sharing preferences for users so they won't be able to switch it on again.can someone please advise what is the best way to make it with Jamf pro?thanks!
Hi all,Just seeing if anyone can help with this, we've gone from Symantec Endpoint Protection 14.3 RU3 to RU6 and upgraded our Mac estate to Ventura at the same time. These work fine but when trying to setup a new Mac or a re-formatted Mac and installing Symantec Endpoint Protection 14.3 RU6 on a clean Ventura Mac the screen doesn't display the extension to allow itIt should popup Privacy & Security and ask to allow Symantec Endpoint Protection but it doesn't.I have created a Allowed System Extension and checked and the Mac has this installedTeam Identifier: Y2CCP3S9W7Allowed System Extension: com.broadcom.mes.systemextensionWhen I retry setup on Symantec Endpoint Protection it just comes back to this issue and I can't get past it. Has anyone else experienced this and managed to get it working on Ventura on a clean install?
On the iPad: General > VPN & Device Management only displayed VPN - not anything to do with MDMUpgraded to the latest OS from the device and now I see all the Configuration Profiles in General > VPN & Device Management but still when I try and do anything that uses a remote command from Jamf Pro such as restart or Inventory it stays with a status of "Pending". The MDM Profile looks to be current.Before upgrading iOS there were a bunch of failed commands like this in JamfThe UUID for the profile “Self Service Web Clip” is not unique.My current idea is to wipe it and rebuild with Apple Configurator.If it was a Mac I'd try a "profiles renew -type enrollment" command but I can't see how to do that for an iPadThis is 1 of 80 but the only one that is misbehavingIt, like the other 80 received a new config profile to access the wifi a week or so ago changing from user authentication to certificate authentication. It can access the internet fine so it's not simply a network
Our students are their own iPads and take them home (well, the parents bought them). At school, we experienced problems students playing private games or using YouTube during breaks (and even sometimes during classes).We created a location based profile in Jamf School (Organisation - Settings - Regions), that is dependent on the IP address and the geographic location. Unfortunately, that profile isn't 100 % reliable, only 70-80 %.We saw that we can give an IP address range by omitting some parts of the IP address. Is there a way to use a geographic range rather than an exact latitude and longitude?We tried omitting some numbers on the latitude and longitude, but it didn't help. Not all present students show up in the smart group that is based on the geo location.Any help would be appreciated.Thank youKai
Hi All.We would like to block access to YouTube between certain hours for our iPads. It is obviously possible to do this via the Jamf Teacher App. I'm surprised that it isn't possible on a global level via the main Jamf interface.Or am I missing something? Is there some way to achieve this?CheersNick
When I look at individual computers I'm able to see the installed applications, however, when I use the 'Search Inventory' feature and the 'Applications' filter there are no results. It's the same if I enter a known application or leave it blank. Any suggestions?
I've performed a number of zero-touch distributions for a hardware refresh I've been working on with my colleague. Randomly we have users that are getting locked out of their machines and that number continues to grow by the day. At first, we believed it to be a Local User Admin script I was running that would create a user admin for troubleshooting things locally, but there have been some machines that are getting locked out and haven't run the script. In some cases, a resetPassword in recovery mode reset fixes it (2 cases). In the cases that it doesn't, we'll be able to get through an initial login window only to follow up with the same user behind it and the password we just set, won't work. In this case, we are having to wipe the drive and install a fresh copy of Mac OS. Have any of you encountered this before? Is it something to do with Keychain? Any suggestions on how to troubleshoot this? Best Regards,Baker
We use Google login to enroll our users in JAMF. We were told by JAMF engineers during our setup, that we could use Google SSO for the login OR leverage Google LDAP. If we setup LDAP, then we'd have an extra step of pre-populating users and groups in the JAMF settings in order to use SSO. We don't want to have to pre-populate or manage users in the settings. So LDAP is not currently enabled. When our users login through SSO for the first time, their Username (which is their email address) is automatically captured in "User and Location", which is great. However, we have another system that will sync asset information, but it is hard coded to use the Email Address field. Is there any way to easily script setting the Email Address field to what is already populated in the Username field?
Looking through the archives has done me no favors, I need a way to find out which users/Macs have iCloud enabled. At some point I need to disable iCloud outright and knowing how many users have it enabled would be extremely helpful.
When I enroll my INTEL macs they keep on loading up the system preference page to the appearance section. Also I noticed when I click the system preference icon and hold it brings up a long list of items. My M1s don't do this. What do I do?
We have a problem where our computers have been losing their profiles over time- we have a solution, running the command "profiles renew -type enrollment", but this requires us to get every single computer into our office one by one to manually run it. I attempted to automate this solution and have run into two new problems:1. In spite of the -forced flag, which Apple claims will skip over confirmation, it still asks the user to confirm the profile. Which our students would absolutely not do, if they even click on the notification.2. Even though the user should already be tied to the computer in JAMF, it asks us to put in their AD information again. Our students don't know* this information and we can only take a guess at this remotely, but we can't put it into that box as is.Is there any way to automate or skip over these issues somehow, or is there a better solution?Additional notes:Renew MDM profile in management fails on these computers- it returns a device signature error.They see
This has been an ongoing issue for months with no resolution and posting here to so if anyone knows a resolution. We know that this happens after updating from outdated OS to new version. we have tried turning off FDE, no installing AV at all, network wise - hotspot, ,home and corp network just to see what happens. it has always been same. we gotten to the point where all of our automations are self service just to make sure nothing is causing a issue. We do have an ongoing ticket but no available after numerous back and forth. Anyone out there knows anything about this? this has happened on v2.15-2.17 jamf connect.
I have just updated a student's iPad to 16.3, then tried to backup to iCloud. Since the update, it has defaulted iCloud backup and many of the iCloud toggles to off. when you try and switch them on, it says an error has occurred. reading online, it seems that 2FA needs to be on. All of the students use a managed Apple ID and there is no option to turn this on. Can anyone help?
How are others installing Adobe CC Shared packages in school labs? When I build the package within the Adobe Admin console, the pkg with almost all the products (media lab) is 28.2GB.
Hey All JS Friends - this is my first post. tl;dr background infoOver the scope of my time on this MDM (since Zuludesk...) I looked over my shoulder at Jamf Pro and wondered if we had made the correct choice (I was a total MDM newb and was taking information from a firehose). I knew that Jamf professional services supported best-practice engineer-assisted rollouts, but I "bit down and chewed on the low-budget choice and some learning as I went. Then Jamf purchased Zuludesk and voila I was now a Jamf customer. At a CITE conference Jamf session, I started asking about upgrading our School MDM to Pro to "use Jamf Connect." Instead, they helped us set up Pro services to review my MDM build and working conventions / set up Jamf Connect. end tl;drFast forward to my issue: Deploying Jamf Connect using Azure IDP (which also enhances security with MFA) is easy (Jamf Connect App, Custom Profile, and Logo image are added to a macOS Device Group). -in our environment, I a
I'm planning on taking the JAMF 300 course but before I do I wanted to work on familiarizing myself with scripting. Any good recommendations for a scripting course I can take? Thanks
Mac os Ventura 13.0 System preferences / System Settings(com.apple.systempreferences)key: SettingsExtensions type: <string> presence: optional rangelist: - com.apple.Accessibility-Settings.extension - com.apple.AirDrop-Handoff-Settings.extension - com.apple.Battery-Settings.extension - com.apple.BluetoothSettings - com.apple.CD-DVD-Settings.extension - com.apple.ClassKit-Settings.extension - com.apple.Classroom-Settings.extension - com.apple.ControlCenter-Settings.extension - com.apple.Date-Time-Settings.extension - com.apple.Desktop-Settings.extension - com.apple.Displays-Settings.extension - com.apple.ExtensionsPreferences - com.apple.Family-Settings.extension - com.apple.Focus-Settings.extension - com.apple.Game-Center-Settings.extension - com.apple.Game-Controller-Settings.extension - com.apple.HeadphoneSettings - com.apple.Internet-Accounts-Settings.extension - com.apple.Keyboard-Settings
I want to start enabling our users to upgrade their OS's through self service, however, there's a pretty wide gamut of different app versions that should be updated prior to an upgrade. Ideally I'd like to have a pop up with like a button to say XYZ app is out of date or need to be removed w/ an option click here to upgrade or remove as needed. Finally, if the device has an app like Centrify installed then to not allow the upgrade and instruct the user to reach out to IT.Currently we're using the erase/install DEPNotify package to handle an in place upgrade. This is checking for power, but not much else.
Started noticing this on machines for my enrollment script using jamfhelper. Doesnt seem to have any real bearing on outcome as the text prompts still show up, but in the logs, most, if not all, jamfhelper prompts are followed by com.apple.fonts not accessible. Excerpt from log with macOS Monterey with M1 pro Log from M1 with macOS Big Sur Any ideas why this is a thing?
Hey folks,Newer Jamf Pro user here. We've got about 230 devices enrolled, 98% of which are existing machines from the field (mostly remote) that we're using user-initiated enrollment for.We're doing pretty basic stuff, installing a few apps, issuing a password policy, and things like login screen message etc. One these machines, there is a local admin for our use, and the user is also a local admin.We've had two instances recently where, a user has rebooted, done the user-initiated enrollment, and then upon rebooting, is asked to change their password at login to comply with the password policy, and then the next time they try to login after this, they are told their password is wrong.I'm finding the same issue with the local admin, and the only way I can get in is if I push a new local admin account to the machine via a policy. But after I login, if I go to users & groups in sys prefs/settings, and I try to reset the password, I get "reset password failed."We are not using FileVau
Hi, I have just run into this issue recently whereby I try to remove vulnerable apps that are not installed to /Applications folder but copied and being run from Desktop or Downloads folders.Tried this easy command in terminal locally and worked like charm:rm -R ~/Downloads/Visual_Studio_Code.pkgSo then I created a policy that would use a script with the same exact command to remove the file and ended up having this:Script result: rm: /var/root/Downloads/Visual_Studio_Code.app: No such file or directoryCannot I just use tilde for specifying the currently logged in user's Download folder? Why does it say /var/root?I have 100+ users and not fancy writing a separate script for each of them where I just use the full path.I'm sure I'm overlooking some obvious scripting rules here so all advice would be greatly appreciated!
We just discovered that the portion of our fleet still running macOS Mojave (10.14.6) are no longer checking in, updating their inventory, or of course executing any policies or receiving any patches.When manually triggering a policy check-in or recon, we get this error:There was an error.Device Signature Error - A valid device signature is required to perform the action.This appears to have happened to all of these machines around the same time, all showing a last check-in/update on Friday 8/12 or Monday 8/15. It doesn't appear to be happening on any of our machines on 10.15 or later.The computers all still show they are managed, supervised, enrolled, and have MDM profile expiration dates far in the future.Initial spot testing using the Jamf binary self-heal with Jamf API seems to get it reenrolled successfully. Unfortunately we're unsure if this will stick since we have no idea what the cause was, nor do we know if there will be any other ill effects from this error or from the self-
Hello All, Please help me to get the MS link to download the latest version of office package for macOS so that I can make a script and use in my policy to install on macOS. I don't to do it from https://macadmins.software only MS link is needed. I will do curl to it.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!