Get Support
Recently active
Hello there,Newer Jamf Pro user, I've got a system of about 200 devices setup and running right now which has been done basically with user-intitiated enrollment, but now I'm getting ready for us to start rolling out pre-stage.What I would like to do, is once setup assistant finishes, and the user gets to the desktop, I want to push a message with a policy using restart options that tells them to not touch their machine for 15 minutes at which point the machine will restart. Thought process here is to allow the computer to do all the software installs etc, so they don't mess anything up.I was trying to do this with "enrollment complete" but what happened is that the message would pop-up right overtop setup assistant if they didn't get through it quick enough. So I'm trying to get it to wait until it hits the desktop. I tried using "login" trigger, but it didn't seem to work, it says it ran, but never showed up.I appreciate any insight you could offer. Thanks!
Hi, i am looking to deploy Velociraptor via Jamf and wanted to know if anyone had any experience with this? Deploying Clients :: Velociraptor - Digging deeper!Curious what steps were taken to deploy it. Any help is appreciated. Thanks
So I've looked through various posts but haven't seen an exact way to do this yet. We've got Crowdstrike deploying properly but have two machines return the error below. We tried to re-install Crowdstrike, but I think it's a bad install, and we might need to remove it entirely and try again. Script result: Error: This machine is already licensed I tried to craft an uninstall to do it, but it's not working the way we had hoped. Hoping someone might know a quick fix or a best practice for silently uninstalling the sensor remotely.
Hi all! Question: we are sending out a policy using jamfHelpers "fs" window and I'm pretty sure in the past one was unable to exit out of it entirely (which is what we desire) but recently, I've seen (and tested) that hitting "command-Q" actually works to exit the fs window. Sometimes the fs window shows up then disappears after a few seconds on its own. Is this normal and/or anyone has seen before? Just curious. Test machines are M1 on Monterey. Here's our script: #!/bin/bash # Variables jamfHelper="/Library/Application Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper" # Message prompt "$jamfHelper" -windowType fs -heading "Test" -description "Hello! Try exiting this window" -icon /usr/local/jamf/logo.png
Happy 2023 from Jamf's Tech Thoughts team! We launched Tech Thoughts just a few months ago, and so far the response from the community has been incredible. We took a short hiatus over the holidays, but we're glad to be back and ready to kick off the new year with some new and interesting posts that we think you will enjoy. To kick things off, we wanted to take a look at where we've been and where we are going with Tech Thoughts. First of all, thank you to all of the Jamf employees and community members that have submitted posts, given us feedback, and helped to spread the word. We started this project with the idea to create a collaborative space where everyone can share ideas with the community, and we wouldn't be able to create that space without your help. We have some ideas for what types of topics and information that we might want to cover in the future, but we also want to hear from you about what you'd like to read about. Is there a particular theme, topic, or technology that y
We have to push a new certificate out to our config profile. We are able to push it out and it gets installed correctly as we can see it in our Keychain Access. The issue is we want it to be trusted always. How do we set that in our Config Profile to be set to trusted. Just a quick warning, I am not great at command line statements, so the simplest and easiest is best. Thanks
Just wondering if anyone has a list of the Abbreviations and its full name for the remote update managerSo we have it implemented as a script to download RUM and reveal to the user that a certain adobe app has updates available however when it prompts the user to install updates it shows in this format : (ACAI/0.5.3.1/macarm64)we know PHSP means Photoshop, IDSN means indesign but does anyone know of a full list of what all these abbreviations mean
So I'm hitting a wall with the last piece of my zero touch deployment.My organization is looking to begin deploying ~150 iPads each year to students. We've run a beta group and I've got the unboxing and setup experience all automated how we want where we just hand them the box and they're ready to go. My last hurdle is assigning the specific User in Jamf to the specific iPad they end up with in hand.For the Beta I just manually wrote on each box which student it would belong to and kept a spreadsheet with the the serial number/User assignments. Then after the devices powered on used MUT to bulk update the entries in Jamf to reflect the spreadsheet.Is there any way I can avoid having to write and keep track of ~150 names and serial numbers each year? It's not the end of the world but I'd like to eliminate as much human error as I can. Maybe there's a way the student can enter their User info when first setting up the device?Open to any recommendations!
Hey guys, hoping for a little advice as I think I'm missing something key here.We are a Jamf pro customer and looking at integrating SSO to be enable support staff to login to our Jamf portal using their enterprise credentials. We are also wanting to leverage Apple SSOE to allow our users to log into Jamf Setup using enterprise creds. This is currently in preview and requires Microsoft Authenticator.My question - The org prefers using Okta for IdP purposes - If we setup Okta as our IdP in Jamf to enable portal login, will we still be able to use Azure for device SSOE? Or, does Okta offer the same functionality for using the Apple SSOE?Even though it's in preview, the SSOE testing is quite handy for our use cases and don't want to lose that functionality if we choose to use Okta for our IdP.If federating with Okta blocks our ability to use the SSOE/Setup functionality would like to know so I can submit an exception for Azure.Thanks ahead of time.
Hi I have been testing the new Jamf Mac apps and I am loving it.Its working fine for some of the Microsoft apps I've been testing but strangely its not working for the Adobe Acrobat Reader DC Continuous.It seems to have installed on 10 machines but no more and these may have been logged into at the time.I have also noticed that if you are logged in when it fires up the silent installer you cannot restart the machine at all.If you try to restart you get the message the computer cannot be restarted because software is being installed.And the Acrobat DC installer box pops up at Running package scripts. But never goes' any further.Does anyone know where i can check the logs or any ideas why the installer is not working. Cheers all
For older macOS versions when swiftDialog isn’t an option, leverage Jamf Helper to provide your users actionable messagesBackgroundFor computers running macOS Big Sur 11 or later, swiftDialog is our go-to tool for displaying end-user messages.For the less than double-digit stragglers we still have running macOS Catalina, a fresh deployment of Nudge-Python seemed overkill, so we turned to our old friend jamfHelper and added some new racing stripes:Auto-terminate fullscreen mode (after a configurable duration)Auto-execute the specified action (when in fullscreen mode) Continue reading …
I am trying to troubleshoot why Zoom 5.8.3 installed fine but 5.8.4 is failing every time. I am pushing it out through Self-Service and it fails every time. I install it manually and it works fine but installing from Self-Service fails. I have tried both the Zoom.pkg and ZoomInstallerIT.pkg both seem to be failing to install from Self-Service. Anyone got any advice?
Hi Is there anyone suggest me that how I can Implemenet 100% Zero touch deployment for mac devices for our on Prem Jamf pro instences. Is there any one here implement have that successfully. And also macs are bound to Domain to use their AD asccount. So we setup our LDAP server in Jamf pro. In this situation I need suggestion that if we want to integrate Intune with Jamf pro how that will Impact though we didn't integrate our Azure AD with Jamf pro. I know it is little complex but any seggestion is appriceable.
I was in the process of testing the erase-install.sh file. I was modifying the same policy and forgot to change the policy back to specific computer and users. I added my device to the specific user and our jamf policy is set for 5min. Not realizing that until I got pinged, I disabled it. It was as 21 devices on Friday afternoon, but keeps growing. We did send out a communication to the Mac users, to not enter password. Is there some way to prevent the policy from running?
Hello, I'm trying to let non-admin users install Ventura using: eraseinstall script: https://github.com/grahampugh/erase-install.Policy is enabled in self-service. Install is not successful.Any idea?Thanks
Changing Port from 8443 to 443 on-prem hosted Windows Server clustered JSS environment running 10.41, we have been asked to make a change to the host port and currently have many devices enrolled, is there a way to preserve or re-enroll devices with a new MDM URL with minimal impact or this just wishful thinking?
I'm looking for clues on whether AoVPN using IKEv2 can be done and how. I can see that IKEv2 is available as a protocol for iOS in the VPN Configuration Profile settings but not for MacOS in the corresponding VPN Configuration Profile settings.There are hints here and there in Jamf Nation but mostly with 3rd party solutions.If anyone can point me at some info that could help I would really appreciate that
We're looking at migrating to HTTPS for our main file share distribution point from SMB. We've used SMB since we began with Jamf and have just had that port open on our state's firewall. Recently they've told us no more on that and have deleted/remove the rule, our only choice going forward would be to use port 8080. So, as of now our Mac's cannot mount our file share and get packages when off of our network. Not the end of the world but it was handy to have policies work from home, especially overnight. We followed the steps to migrate to HTTPS listed inUsing IIS to Enable HTTPS Downloads on a Windows Server 2016 or 2019 File Share Distribution Point - Technical Articles | Jamfhowever, we get a 503: Service Unavailable message when testing a download in browser and also when a Mac tries mounting to run a policy with a package. I spent several hours troubleshooting different settings as well as trying different read-only accounts, recreating certific
I am noticing that all devices encrypted before manual Enrollment in to JAMF Pro, are missing personal recovery keys. Does anyone know how can I issue a new key to already encrypted devices, bearing in mind encryption happened prior to Jamf enrollment. Thank you :)
Is there anyway to add a PM definition ourselves or we depends on Jamf?Application: TailscaleApp URL: https://apps.apple.com/us/app/tailscale/id1475387142?mt=12&uo=4The app is installed from App Store.
Trying to create something for my self-service for the end user to send the local Jamf log to the server for the team to be able to review - although I've never run into an error like this. Grateful for any input Script as follows: #!/bin/bash ##Get the serial number serialNumber=$(system_profiler SPHardwareDataType | awk '/Serial Number/{print $4}') ##Get computer ID id=$(curl -sku api:api -H "accept: text/xml" https://OURJAMFURL/JSSResource/computers/serialnumber/$serialNumber -X GET | xmllint --xpath '/computer/ general/id/text()' - ) ##API call to upload the system log to the computer running the policy curl -sku api:api https://OURJAMFURL/JSSResource/fileuploads/computers/id/$id -F "name=@/private/var/log/jamf.log; filename=system-`date +%F\\ %T`.log" -X POSTAnd the error is: ##Script result: <html> <head> <title>Status page</title> </head> <body style="font-family: sans-serif;"> <p style="font-size: 1.2em;font-weight: b
With the implementation of a recent feature request, Setup Your Mac (1.6.0) introduces additional policy validation options to help ensure critical enterprise applications are both installed and their related services are running.IntroductionApple’s Automated Device Enrollment helps to streamline Mobile Device Management (MDM) enrollment and device Supervision during activation, enabling IT to manage enterprise devices with “zero touch.”Setup Your Mac aims to simplify initial device configuration by leveraging @bartreardon's swiftDialog and Jamf Pro Policy Custom Events to allow end-users to self-complete Mac setup post-enrollment.Continue reading …
Hello all,3 of our devices were supervised and managed, but the Jamf records on our end were deleted while the devices were still active. So the devices still have Jamf on the system, but now phoning home is pretty weird. We were able to restore one of the records, but it appears to be only managed now. On this restored record, we are unable to push any commands or policies to the device that are normally available by default (Lock Device, Send Blank Push, etc.).Is there any way to get these devices reconnected to our system, or should we bag it and just re-issue new devices to these users?I'll be checking this all day so please feel free to ask any questions about anything I might have left out. Thanks!
Currently, app licenses get assigned when a user is scoped to a self service policy. I want to script an option that a user can “request” to have access to an application through self service and then automatically get added to a smart group that the application license and installation policy is scoped to. Has anyone done anything like this before? Thanks in advance!
Hi Pro,I am new to JAMF and looking in to get some help,I have to deploy the below code via JAMF and add it to the existing edge Plist defaults write com.microsoft.Edge AuthServerAllowlist org.kerberos.okta.comI have added this code to .sh and deployed it via JAMF policy and it didn't work TIA
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!