Get Support
Recently active
good day, i have created a new policy under JAMF which it activates the filevault disk encyption which works fine. when i go and uncheck ENABLE under the policy OR remove the unit from the SCOPE, when i restart the designated unit it keeps showing the POP-UP message on login that Administrator is requesting to Enable the filevault, noting that if i press ENABLE button and then i go to system pref, the filevault is not enabled. so to brief how to get rid of the pop-up message after disabling the Policy OR at least removing the unit from the Policy scope. thank you in advance
I hope someone is able to assist. I am a little bit new to using Jamf but I have been asked to assist with moving about 120 macOS devices from one Jamf instance to another, and we have thought of using the GitHub ReEnroller package as a mechanism to re-enroll devices in the new instance. I have configured all the details as per described in this guide: https://dazwallace.wordpress.com/2020/08/27/migrating-macos-devices-from-one-jamf-pro-instance-to-another-using-reenroller-part-1-setup/ I have also followed the ReEnroller help page. The issue is that I can see the package has been deployed to a test macOS devices (manually as Self-service), which appears to be installing successfully, however, after the package is "installed" nothing really happens on the test device. the device is still enrolled into the source Jamf tenant.is anyone able to share your experience with this tool? are there any further articles or information related to ReEnroller? are there any known issues with ReEnrol
We are deploying FMPro 19 to various groups within our org. I am using the script provided by Claris to build a custom built package, which is working fine, however one ask we have from the program manager is to try to set a Host URL in the client so that they do not have to assist every user in doing so. Its not that its terribly difficult to instruct users how to do this, but there is only 1 person to support nearly 1k users for this project. I found one document, referencing FM Pro 15, that suggests adding the following attribute to the Assisted Install.txt file:AI_PREFERREDSERVERFORCONNECTION=<host URL>Unfortunately this is not working, at least not in FMPro 19. I've tried the usual format of fmnet:/<hostdnsname> and just entering the dns name without the leading fmnet:/Neither worked.Has anyone had any success in setting the Host URL via Jamf?FWIW, when set manually the host URL is listed in a Pref file within ~/Library/Preferences.
In my state (NJ) the governor just issued a directive to (among other things) disallow certain apps on government-owned devices. This includes TikTok which is garnering all the press, as well as many other apps from developers such as Huawei and Tencent. So restricting an app with a config profile is straightforward (wish I could DELETE the apps, but...). However, I'd like to restrict a developer's entire suite of apps, which theoretically should be easier than one app at a time. I just can't figure out how. Has anyone out there done this? TIA.
This is probably something very simple, we never really utilized SS but I would like to start. I can't seem to figure out how to add custom apps to SS. I know how to do it for App store apps as it's pretty just right there. Example, I want to make Skype for Business available in SS, how do I get it to show up under software. It's probably something I am missing but I really don't see where to add it.
Hi everyone, We are needing to renew our SSL certs for our wifi networks in the coming weeks and are curious what other folks do when the time comes? We have about 300 iPads currently and had a rough time doing it last year so are looking for any tips. I inherited sort of a mess and am trying to clean up our configuration profiles and was thinking of deploying the new certificates as its own configuration profile to each location in this process. Is this something you do? Any suggestions would be great!
Getting this on some (but not all) of our Intune registered Macs that looks like it's coming from JamfAAD. Nothing triggers it that I can tell, totally random. We recently went through registering everyone in Intune and saw a similar message at the end of the procedure (when JamfAAD launches), but everything had been fine since then. The only thing that changed was we upgraded JSS to 10.25 last night and we changed the Intune connector this morning from Manual to Cloud Connector (which was pretty seamless). Anyone know what could be causing this?
When I enrolled a mac on my jamf portal before I had an mdm profile that I could install on a mac, now it only propose me a quickadd.pkg, where could this come from?
Hi,Location service is running and detecting correctly London/Europe. However the time still set to UTC. I cannot see any obvious payload in JamfSchool to update the time to London/Europe. Any other alternatives to set it up please? Thanks
Is there any way to disable Incognito Mode in Chrome on iPads? I really don't see the purpose of Chrome on iPads, if I'm being honest. Safari seems like a much better option. I recently had to disable Private Browsing in Safari on our iPads. I wish there was a better option to do this other than the built-in web filter as we've been running into sites with issues, but it works. Just asking to see if I can quiet the cries from people that lost their Chrome.
I need some quick and easy instructions on how to integrate Jamf Pro with Jamf Safe Internet.
Hello everybody,fdesetup authrestart seems to be broken for accounts that have never logged in.I created a new user “test” with password “test” via Users & Groups (so it got a secure token and is a volume owner) and tried to authenticate fdesetup authrestart -delayminutes -1 with that account. I got an error and fde prompt after the next restart. After signing in as “test”, signing out and signing back in as original user, fdesetup authrestart worked for user “test”. This also applies to startosinstall and softwareupdate on ASi Macs, when trying to get either working with a managed admin account that has a secure token, is a volume owner but was never used to sign in, I always get the fde prompt after the first restart. When I try the same with the logged in user and password it works.Any workarounds for this?
I have been tasked with creating a Policy to push out ActivTrak to MacBooks. It installed just fine the problem I'm running into is it asks the user to grant Accessibility access. Obviously with ActivTrak being a tracking software to see what our employees are doing we want to push it out silently and we don't want to depend on the user to grant access.This is the first PPPC Configuration Profile I've attempted. It says completed on the machine but it isn't setting the access that ActivTrak needs. Below are the settings I created for the PPPC payload. I got the CodeRequiment with the codesign -display command. I also added an Extension payload of com.bgrove.scthost not sure if this is necessary. Any help would be appreciated.Identifier: com.bgrove.scthostIdentifier Type: Bundle IDCode Requirement: identifier "com.bgrove.scthost" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2
Just getting started w/ Protect. Can it also stop the addition or use of browser extensions? Thanks!-Kevin
Hey all! Just updated my M1 Mac mini to 11.5.1. Everything installed just fine, however when it booted back up it could not connect to any network. When attempting to open an application it looks like Rosetta 2 was uninstalled from the machine. My attempts to install it failed since I couldn't connect to a network (only tried internal networks) I rebooted, then every time I attempted to login with Jamf connect it rebooted the computer (still no network connection, used local login). I booted through safe mode and I could get a network connection. Then the screen went pink and it rebooted to recovery. Attempting to reinstall now. Anyone seeing this on their end / know how to prevent rosetta from uninstalling during a software update? For now I have set our update policy for the company to defer for 90 days. UPDATE - Attempted the same update on the M1 MacBook Pro. The same issue occurred. This time I attempted connecting to a hotspot. Still no network connecti
Jamf connect installed on devices. Not binded to AD.User changed their password on a windows device. When they go to a Mac and try to login, the message stating "network password does not match your local password. Please type in your old password to sync.".What do you do if they don't remember their old password? Trying to deploy a password change for the local account through jamf has been unsuccesful.Is there a way to auto update the local password without having to type in the old one?
In testing, the managed TVOS slideshow app Exhibit (https://marketplace.jamf.com/details/exhibit/) looks for perfect for our needs, with one critical drawback. In single-app mode it does not load its slides. This kind of defeats the whole point of Exhibit for us. I'm wondering if anyone has found the same bug, and if there's a workaround.
Hello, I would like to grant user admin right for some time.I have created a policy using: https://github.com/jamf/MakeMeAnAdmin/blob/master/MakeMeAnAdmin.shLogs error: Any idea ?Thanks
We have an app installed on devices in our org that needs relatively frequent removal and reinstall. Most frequently, the user provides their serial number, sometimes the asset tag associated with the device (which is in the jamf pro device inventory record). jss_url='identifier.jamfcloud.com/' username=apiuser password=apipassword authToken=$(curl -su "$username":"$password" https://"$jss_url"/api/v1/auth/token -X POST) api_token=$( /usr/bin/plutil -extract token raw - <<< "$authToken" ) #response=$(read -p "enter s/n: ") response=1070 #this is added for testing adding the device by inventory id apidata="<mobile_device_application><scope><exclusions><mobile_devices><mobile_device><id>$response</id></mobile_device></mobile_devices></exclusions></scope></mobile_device_application>" curl -ks https://"$jss_url"JSSResource/mobiledeviceapplications/id/77 -d "$apidata" -x PUT -H "Authorization: Bearer $
Weird thing. All our iPads that updated to 16.2 in JAMF PRO no longer have the ENABLE LOST MODE button in the management tab.I always seem to have strange issuesSara
We are trying to set up our Macs with a Software update policy from this link. I've set that up and deployed it to my test machine (M1 Mac running 11.2.1). I ran a 'sudo jamf policy' to kick it off and see what the process would look like. After the initial password to run the sudo command I was prompted again for my password and then it took awhile to I assume download the update (11.6). After downloading in terminal it says the update is complete and that it does not require a restart or a shutdown. However the update never installs, the Mac is still running 11.2.1, I rebooted the machine and it didn't apply any updates. Any thoughts on why its downloading but not installing?
I need someone help from pro here on how to deploy the below config on all firefox browsers via JAMF have to enter the network.negotiate-auth.trusted-uris = .kerberos.okta.com here are the manual stepsOpen the Firefox web browser,enter about:config in the Address bar, and press Enter. If the Proceed with Caution message appears,click Accept the Risk and Continue. In the Search preference name field,enter network.negotiate-auth.trusted-uris.Click Edit, enter .kerberos.okta.com, and click Save.your help is much appreciatedThank you
Hi everyone, This seems to be very hit and miss on Yosemite. Traditionally, we enable fast users in Managed Preferences. User level enforcedDomain : .GlobalPreferencesKey: MultipleSessionEnabledValue: True This works perfectly on 10.9 and below. 10.10 seems to have problems with user level enforced mcx, sometimes it applies, sometimes it doesn't. How is everyone else managing fast user switching in yosemite? I have tried defaults write /Library/Preferences/.GlobalPreferences MultipleSessionEnabled -bool 'YES'which doesn't seem to work either. I have also tried a custom setting via configuration profile but no luck with that also. Any ideas?
Hello All,Running the following command:/Applications/Privileges/Contents/Resources/PrivilegesCLI --status > /private/tmp/status.txtcreates the file named status.txt but it is empty (stdout is not redirecting to the file)I was wondering if someone that has Privileges and or those that would be willing to install it on a machine and try the command can get it to work? I've tested this on Big Sur, Monterey, and Ventura all with the same result.For what it's worth, I've tested the commandls -al > /private/tmp/filename.txtand it works with no issue. It's as if the PrivilegesCLI binary is missing something to be able to redirect the stdout to a file.
I am looking at wanting a Powershell script to access the JAMF School API to pull a list of devices and their WiFi Mac addresses.Any hints or directions for a start with he JAMF API?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!