Get Support
Recently active
Hey everyone, how can I go about zero touch macOS deployments? What are the Pre-Reqs for it? I have my Policies and apps build out. But device seems to still require a lot of “touch” by IT before providing it to the user.Any suggestion would be appreciated
Hi, i am sending a popup message to my users with SwiftDialog.In the logs i see a lot of these: Script result: 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: failed to connect - Error Domain=NSCocoaErrorDomain Code=4099 "The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process." UserInfo={NSDebugDescription=The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process.}2023-01-25 12:17:12.598 Dialog[29366:629409] Font server protocol version mismatch (expected:5 got:0), falling back to local fonts 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: unable to make a connection to the font daemon! 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: XTFontStaticRegistry is enabled as fontd is not available. 2023-01-25 12:17:23.919 Dialog[29366:629433] Spell server connection invalidated Pressed Button 1 OrScript result: 2023-01-25 09:24:55.813 Dialog[1302:12330] XType:
Hi, i am seeing a lot of errors in the logs of my swiftdialog message policy: Script result: 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: failed to connect - Error Domain=NSCocoaErrorDomain Code=4099 "The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process." UserInfo={NSDebugDescription=The connection to service named com.apple.fonts was invalidated: failed at lookup with error 3 - No such process.}2023-01-25 12:17:12.598 Dialog[29366:629409] Font server protocol version mismatch (expected:5 got:0), falling back to local fonts 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: unable to make a connection to the font daemon! 2023-01-25 12:17:12.598 Dialog[29366:629409] XType: XTFontStaticRegistry is enabled as fontd is not available. 2023-01-25 12:17:23.919 Dialog[29366:629433] Spell server connection invalidated Pressed Button 1Script result: 2023-01-25 09:42:37.936 Dialog[11101:217909] Spell server connection invali
For anyone that prefers to make Safari updates available via Self Service, here are the standalone Safari 16.2 installer download links extracted from Apple's Software Update Server catalog...Safari 16.2 for macOS Monterey: https://swcdn.apple.com/content/downloads/56/51/012-74032-A_9J5DGEGRED/y2js2pclu7syop1z68wtptdnaddeog4u7f/Safari16.2MontereyAuto.pkgSafari 16.2 for macOS Big Sur http://swcdn.apple.com/content/downloads/36/08/012-82248-A_SAHUHK0ROJ/z04kizckik61f8z4fzyer6gw9mh50pbm9l/Safari16.2BigSurAuto.pkg
Does anyone have a script to set Outlook 365 to the default mail client on Big Sir and Monterey? I have the native mail program locked out so it can't be done through there.
The original logitech options (green icon) was easy to package because you could download the full 200mb installer.The new options plus (purple icon) has a "streaming installer" were you get a 20mb file at first then it kicks of the download for 200mb-ish installer.Anybody know how to package this?Grabbing the app from Application folder doesnt work due to other hidden files being installed.
We are currently having an issue with our Jamf Pro enrollment link. When users try to access the are receiving a 403 Forbidden Error message. No other details are included on the error page. These are Macbooks that have not been registered with jamf previously. My coworker found that reformatting and visiting our enrollment link seemed to fix the issue. The problem is we have close to 200 laptops that would need this done, all remote. I am trying to find another way to get this working again without walking 200 people through a reformat. I don't usually work with Jamf, but the workload right now is considerable so I'm trying to help out. Not sure where to start with this. We do use Okta for SSO, and we do have a group that assigns jamf to a user (we did check group membership for affected users). Any help is greatly appreciated.
After the advice I found on this sub, I switched from DEPNotify to swiftDialog (thank you all for that). However, I am having the same problem that I had with DEPNotify:Most of the policies in the array run without any issues - these are application install policies. They complete consistently without any problems.The policies that do not run correctly are the ones that set the Dock, rename the computer, apply the wallpaper, and (most annoyingly) Log Out the user via swiftDialog. It seems like they are the ones that rely on SystemEvents or osascript, etc... When I check in the Jamf Pro Policy logs, they are not even showing as being triggered so I can't get the cause for failure.Once the user logs out, enables FileVault, and logs back in, the policies run correctly (except for the fact that I need to give PPPC policies to Finder, which I don't seem to need on first login).Is there something that is either running or supposed to be running within macOS on first login that is causing the
So in the past I've used a mac mini running VMware Fusion 12 and creating images for everything from Catalina to Ventura. I can even test our Automated Device Enrollment which is great since we can record it to teach people about it.As we're moving to a Silicon chip world I've been trying to find a solution to do this on a Silicon machine. I've tried testing both VMware Fusion Technical Preview and even the latest version of Parallels...nothing seems to work as well as an intel machine. I know the world is changing and VM vendors are trying to catch up. But has anyone figured a good VM solution for Silicon that will let you adjust the host to input ADE stats like hw.model and serial numbers?
We are currently in the process of changing our antivirus software and deploying defender 365 on every mac in the office.The problem is that randomly on some macs there is a message that says: no licence foundIf anyone knows the solution or has experienced this type of problem.
I bought a used Macbook and have updated it to the latest Mavericks. From when I first powered it on I have been getting prompts to enroll the device. I can't get them to go away...only cancel them and they reappear dozens of times per day. I guess the folks who sold the machine have it in their DEP server? Or there is an agent that keeps checking? How can I disable the agent that keeps prompting me to join? Could not figure out after 30 minutes searching JAMF and other sites discussions of the various woes of school IT admins. :(
Wondering if anyone can help with this, we have Jamf Connect and I would like to roll it out to all of our users. I have it set up and it all works the way I want it to. However, each and every login requires you to verify your second authentication factor, even if you have previously trusted the device. (Device trust is enabled in Google Admin) Also, the user consent screen is displayed every time (less of an issue but from looking at the other discussions this seems an inherent issue with Jamf connect at the moment)
I haven't been able to find more recent documentation on this particular situation/issue so figured I'd ask directly.My predecessors encrypted our AD binded lab devices which created major issues with new network user sign ins. After I got these physically locked down, I put the lab computer group into the exceptions of the FV2 policy. However, I realize of course the policy was already previously pushed to the devices and there is no "undo" button. I need to decrypt for all users and if I can avoid reenrolling the device altogether, that would be great. I don't know if fdesetup has the ability to decrypt for all users without a more complex script I'm not sure how to put together (our senior analyst who managed this left before I came on and honestly, looking at some of his work, I'm not sure he knew how do this management himself lol). I really appreciate any help that can provided for a fresh college graduate who basically had to become the senior analyst within 6 months haha--
We recently purchased 3 x M2 Macbook Airs with 256GB of storage. They were installed and has been used by a single user on each machine between November 11th and December 1st.Within the last couple of days all 3 users have complained about disks running full. Neither user has large files, the one with the most data uses ~40Gb in total (*including* applications!). I have tried running both CleanMyMacX (yuck!) as well as Grand Perspective. Both apps show ~40GB storage used, and the rest is "invisible". We are running Jamf Cloud and Jamf Connect on all machines. Disk Utility shows no APFS Snapshots.All of them are running macOS 13.0.1 and neither user has enough available space to update to macOS til 13.1. What to do? I seem to be looking at 3 reinstalls, but I would REALLY like to avoid this option :-)
Hello All, Please help me to convert MS office package into source file by composer, all time it is getting failed, any reason to get failed and what is the resolution. I am using Jamf composer.
I'm relatively new to PPPC configs. I ran across a PPPC config profile for some old software that had been renamed, but the profile hadn't been updated. It's a softphone client and requires Accessibility permission and access to the mic. Since macOS doesn't allow us to enable the mic, this PPPC should only have one property to set. I figured this would be easy. 😂I used the Jamf PPPC Utility to create the config profile. I added the application on the right panel, picked the Accessibility property, set it to Allow, then uploaded it to our Jamf server. On the Jamf server, I assigned the config profile to my test laptop (running Ventura). On the laptop, I verified that the profile had been installed. When I check my work in System Settings -> Privacy & Security -> Accessibility, the toggle for this softphone is still disabled.Am I doing something wrong? It's a fairly simple workflow. Maybe my expectations are off? I expected to see the Accessibility toggle for the s
I know this may not be the place to ask, but I wonder if some of you can assist. When I go into Rec Mode (2021 MacBook Pro M1) I go in Term > resetpassword > however only ONE admin shows, when there's multiple. Can anyone advise why and how to solve? Thank you,
Hi folks,Does anyone have a reliable method for setting MS Edge as the default browser?I came across the below script that I added to a policy that runs once per computer, but it doesn't work half of the times and I cannot pinpoint the cause.#!/bin/bash#### https://github.com/palantir/jamf-pro-scripts/blob/main/scripts/Set%20Default%20Browser%20and%20Email...# Name: Set Default Browser and Email Client.sh# Description: Sets default browser and email client for currently logged-in user.# Created: 2017-09-06# Last Modified: 2020-07-08# Version: 1.4.3### Copyright 2017 Palantir Technologies, Inc.## Licensed under the Apache License, Version 2.0 (the "License");# you may not use this file except in compliance with the License.# You may obtain a copy of the License at## http://www.apache.org/licenses/LICENSE-2.0## Unless required by applicable law or agreed to in writing, software# distributed under the License is distributed on an "AS IS" BASIS,# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIN
Bonjour,Depuis la diffusion et le passage à ipadOS 16.2 (Pas de retour avec les version précédentes), je suis dans l’impossibilité de pouvoir donner des "Ordres" sur mes appareils... (Actions > Avancées > Redémarrer / Éteindre).Les schémas d’enrôlements fonctionnent, pas de message d'erreur, identité de supervision actif, aucun problème sur ipadOS 15.7.2Quelqu'un rencontre t-il un problème similaire sur cette version ?Apple configurator : 2.16 (8A14) / MobileDevice (1497.1.14.101.4)Merci pour vos retours d'expérience,Cordialement,
Hey Guys! Not sure if this is possible anymore, but is there a script/command to use to allow an app for Accessibility? Trying to see if this is possible since our lab machines do not allow admin access. macOS 10.13 Thanks all!
Hey guys, hopefully a quick and easy answer to this one. Looking to bring a new client into Jamf Pro (+Connect) who has around 25 existing Mac's deployed nationwide. If we go through user-initiated enrolment, would those devices then be Supervised in the same way they would had they gone through Automated Device Enrolment (DEP)? Or will the answer to that vary by end-user OS? All new Mac's purchased will of course be put through ADE/DEP to ensure they're Supervised from the outset. This is purely to onboard the clients existing devices with minimal disruption. Thanks in advance 🙂🙏
Looking to create a feature request? Go to the feature request portal. There you can submit a new request, review any existing feature requests, vote, or comment. Here are a few helpful tips about feature requests. The Jamf Product team and other supporting teams will update these with comments or statuses in the platform. Our process to review and provide feedback is streamlined, as we use capabilities to group, merge, and tag feature requests. Our SLA for initial feedback on new feature requests is 30 days. Add categories to help group feature requests. We may continue to add fields as needed to help capture your great ideas and feature requests. We look forward to hearing what you think and any feedback that you may have on our products or the feature request process!
Hi Did any one use zoom schema as configuration profile. I just create that and deploy to a test machine but following window pop up when policy pushed and zoom app is runningI use schema from here: https://github.com/talkingmoose/jamf-manifests/blob/master/Zoom%20(us.zoom.config).json and configure some instances and leave null others. And then I create a policy to deploy latest zoom to endpoint. But after deploy the policy if user click "Not Now" then policy will failed. The workaround I found that if Kill the process before run policy then that window will not pop up again. Did anyone face same issue? Any suggestion will helpful
I am trying to use JAMF School api for Teacher . It is working.The one endpoint that I am having trouble with is changing the student photoTeacher - Photo - Upload2.0.0Change a student photo item, type, descriptiontoken , String, (Placed in URL) Token obtained by the POST teacher/authenticate callid, Integer, (Placed un URL) Student IDphoto, File, Photo file This is the only place in all the API endpoints that has a file as a type. I am going to explain my question in terms of the language that I’m coding in, Swift. The endpoint is expecting a file, containing the photo, and it does not indicate how it is expecting the file in the http body. It can be expecting the body to contain the file converted to the Data type or it might be expecting multipart for the http body. I don’t know of any other option. request.httpBody = fileData // Either this for Content-Type Header request.addValue("image/jpeg", forHTTPHeaderField: "
Hi folks.I try hard to get VPN On Demand to work. Unfortunately, it currently does not work with Jamf Pro's built-in way (PI-101098), so Jamf Support referred me to iMazing Profile editor. Getting bits and pieces from various web resources together, I tried to built a working VPNOnDemand.mobileconfig by myself, but as soon as I deploy it to my client, it does not have any affect.The VPN on Demand configuration should basically do the following:1.) If client connected to a certain company WiFi network ("SomeWifiNetwork" in the example), it should generally NOT use VPN at all.2.) If NOT connected to the WiFi network above, but any other network, it should ALWAYS establish a VPN connection while trying to connect to certain domains (example1.com and example2.com in the example).3.) Trying to connect to VPN server via L2TP ("1.2.3.4" in the example), shared secret included ("SHAREDSECRET" in example), user name and password should be prompted (hence not included in example).When I deploy i
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!