Get Support
Recently active
Hey Jamf Nation,We are having issues with LockDown Browser not opening after students install the pkg or dmg created from composer. The message that pop up on their screen is "the application is damage- App installed from an unknown developer(notarization) ". Issue just happening with intel clients running on Ventura.
Does anyone know what specific permission/privilege in Jamf Pro allows a Jamf Pro user to view and scope existing policies? I can't seem to find the right checkbox in the privileges page of Users and Groups. The user in question just gets a blank page but there should be a bunch of policies showing.
Has anyone implemented the API for Superman? Specifically the api details. I am a little lost on the configuration of it any help would be appreciated. https://github.com/Macjutsu/superThanks!
Is Jamf using the "softwareupdate" command line tool to collect the details on the Mac client?I am just wondering because even on clients with a major software update deferral profile (90 days set),Jamf Inventory shows the macOS Ventura Upgrade on macOS 12.6.1 Clients?Thanks in advance, Bjoern
Hello all,we use Shared iPads on schools. It would be fine to enable location services on shared iPads or at least to set the time zone in the DEP profile, but it is not possible in Jamf School.Is there any solution for that?Thank you in advance.Best RegardsAngelo
Hello!Since November or so I see HTTP Downloads (from an HTTP-DP served by IIS on our Jamf Pro Server)Server is Jamf Pro 10.42.1 running on Windows 2016 Server (it is the "DMZ"-Server of our clustered pair)Jamf only logs a "Package not found" although the Packages are definitely there, and I get a "404 0 2" error in the http-Logs. That mostly happens when the machine is first set up (DEPNotify is started right after the Setup Assistant finishes and users see the Finder for the first time.When the machine retries after setup ist finished (Policies are triggered through custom triggers and have retries set) then everything downloads ok.I am really stumped, has anybody seen something similar? MIME-Types are all set, the IIS on that Server was working fine up until November, when we moved the main Server to a different Datacenter. Bye, Fridolin.
Hello , I've got problem with python script , first line of script have command to import :import os.path ,os , getpassbut Jamf PRO have problem like below:line 1: import: command not foundDo you have some tips how to solve it ?
I've had this issue since about January 2022. It hasn't been a huge issue because I am operating in an enterprise environment with less than 100 Macs. However, we are growing and this is steadily becoming more prevalent. The reason I post this here is because I'm the main point of contact for Jamf, but I'm still fairly new to setup in this environment so I'd love to hear if anyone has suggestions for this issue. Here's what's happening:I utilize SSO sign-in through Azure AD. Since about 12.2 and later, any new setup of Mac OS (brand new or refreshed) I have not been able to get users signed into their OneDrive app. We launch the app, put in their email, and then it is 'supposed' to go to the SSO splash page, but OneDrive does not go there. It just seems to refresh the page and ask for the email address again. Once you click next, the app does not ask for the password and then asks where the folder should be synced. You select a location, the app thinks for a moment, and then gives the
For a computer policy that has a script object in it, is it possible to update the script parameters via the API? I found in the classic api documentation (seen below) that you can update some parts of a policy with xml. Would it be possible to update a specific parameter (7 in this case) for a script. Ideally that would be the only thing that would change. <policy> <general> <name>Firefox</name> <enabled>true</enabled> <trigger>string</trigger> <trigger_checkin>false</trigger_checkin> <trigger_enrollment_complete>false</trigger_enrollment_complete> <trigger_login>false</trigger_login> <trigger_logout>false</trigger_logout> <trigger_network_state_changed>false</trigger_network_state_changed> <trigger_startup>false</trigger_startup> <trigger_other>string</trigger_oth
Hi, Which is the best practice to enroll the users via User Invitation Enrollment ?From Security Perspective it is not feasible to use share accounts amongst all users during enrollment process, would like to understand various approaches followed in other organisation
I'm been experimenting with some scripts that we want to run at each user's log in. We're using Outset to handle them now, but it's been unreliable for us and seems to break part way through our semester, every semester. In light of that, I've been exploring new ways to get our users files and other things set up for them.I've had luck calling scripts using Jamf's Login Trigger, but the commands in the script are processed as a root user, not the currently logged in user, which causes the scripts to fail. I've found some documented fixes, but they're from previous less secure OSes and earlier versions of Jamf/Casper and I'm not sure they'd be successful under Ventura.Does anyone have some suggestions on getting the scripts ran as the user at login? Should I be going down the launchd rabbit hole?
I’m at a loss here. I’ve been suddenly fighting Zoom screen sharing being completely “blocked” with my JAMF Pro setup on all new computers. All machines are running 12.4, Zoom 5.11, and I have a PPPC payload deployed on some that allows non-admins to allow screenrecording and the other half does not have this. No matter which configuration I use, even when I allow full disk access and screen recording, Zoom still tells me to open my Security & Privacy to whitelist the app to screen record. I have tried both the IT installer PKG and the regular PKG to no success. Does anyone have advice on what I need to check for?? I’m at a total loss right now. Thanks in advance!!
Hey I was wondering if anyone else was having issues with the new macOS Ventura update? After pushing the new update to the students none of them are able to use Safari. When Safari is launched it will open for a split second then close. I rebooted and reinstalled update macOS but no changes. Please advise on how to correct issue. I tried: Holding Shift and click on Safari to openRight click and open methodRebootReinstallUpdate Safari
I have "AutoRenewTickets" set to "True" in our Jamf Connect config profile, but it doesn't seem to be automatically renewing the tickets. Do we also need to configure the SSOe payload or something? Alternatively, I'm just gonna set up a launch agent to renew the ticket but that's really more of a last resort. Thanks, Matt
I hope anyone in Jamf Support or in the community can provide some guidance since Jamf Support takes forever to respond...Objective: Install CA certificate to Mac's processed Pre-Stage enrollment. Problem: The configuration profile used to install the CA to enrolled Mac's works great for "User-Enrolled" Mac's. For some reason it is not working with Pre-Stage enrollments. The configuration profile should be available for distribution from the profile settings section but it is not available for Pre-Stage. Troubleshooting:- After Pre-Stage enrollment I signed in and out of the Mac computer to see if that would trigger the config profile to run on the computer, but no success there.- For testing, I changed the distribution method from install automatically to Self Service and that did not worked as well. Config Profile Details:- Profile is configured with a Level of "User Level".- Distribution Method is "Install Automatically".- AD CS Server Integration configured and worki
Not being a troll, just want to know the real world options for me here.I have about 20 devices in JamfNow, and its going pretty well. I dabbled in Intune and there is just too much going on there, and I run into more issues than not.That said, Im looking to commit to either going back full time to JamfNow, which is where this question came from. Is there a value to going to Pro if Now seems to be just fine?
Hello, do we have any other way to block major os update aside from using the configuration profile (restriction - > functionality then defer for 90days) and restricted software in JAMF? Is there a plist that we can configure and upload or maybe a script to block the OS update and stop it from checking an available update?
I'd like to create a new user via policy that is enabled for FileVault 2/has SecureToken. As noted in the Local Accounts payload, the "Enable user for FileVault 2" no longer works in anything beyond 10.13. After doing some digging, the only solution I have come across to do this is using sysadminctl to grant SecureToken to the account after creation. This is something I'd like to avoid if possible since it requires passing not only the credentials for a SecureToken-enabled admin through a script, but also the credentials for the account to be enabled.Are there any secure methods to achieve this?
Hello all!We have been having an issue lately where machines will start their prestage installation process (policies, app installs, scripts, etc) that we run on first setup BEFORE the user is able to even log into the machine via Jamf Connect 2.Previously the user would boot the machine for the first time and it would go through language selection > warn them about Company MDM setup > ask for location > then prompt for a Jamf Connect 2 login. It would wait there until logged in by a user THEN begin the full 10-15 minute setup. It would finally end with a reboot and come back up to a local login and the user would be able to log in without issue because it created a local user for them during that 10-15 minute setup.Now, the setup will begin nearly immediately after warning them of the Company MDM setup (about the same time as it asks for location. If a user gets distracted and doesn't log in at the JC2, it will go through its install then finish with a reboot and come back to
Hi Jamf community. I've been having some trouble understanding if the following is even possible, so I thought I'd post here to see if anyone has any ideas or has tackled this in the past.I have an EA I created, which gets the expiration date of the machine 802.1x issued certificate. It converts the expiration date into a "Jamf friendly" format, such as 2023-08-10 10:05:00. It reports that (if found) as the result in the EA.The problem I'm having is, I want to build a Smart Computer Group that uses this information to show me any Macs that have these certificates that are going to expire in say, 30 days from now. I can't seem to use any of the built in date operators to make this work. Neither the more than x days ago or less than x days ago criteria will give me what I'm looking for. They seem to only work properly with dates in the past and not ones in the future. And the before (yyyy-mm-dd)and after (yyyy-mm-dd) options wouldn't make sense to me it seems, since these would be consta
So I'm distributing app via Policy + Package, but I'm not sure how to "enable" the option to install such app only when the user wants to, so something that people can click as "available to install", not mandatory installation that all pc get.
HiI'm looking at maybe using Jamf Connect, with our Okta environment.So if i understand this correctly, during a login process for a user, they would turn their MacBook on, already be connected to their wifi, and just login using their Okta creds.Our Okta environment is configured to only allow login from trusted IP's (e.g our VPN)How can our users login using Jamf Connect, if the VPN hasn't been activated/enabled yet (e.g before the macbook login process has occured)Thanks
Hi folks,for a few weeks now we've been getting messages that the inventory has failed. The log looks like this:An error occurred while running the policy "Update Inventory" on the computer "xxx". Actions from policy log: Executing Policy Update Inventory Running Recon... Retrieving inventory preferences from https://xxx.jamfcloud.com/... Locating accounts... Locating package receipts... Searching path: /System/Applications Locating software updates... Locating plugins... Locating printers... Searching path: /Applications Locating hardware information (macOS 12.2.1)... Software update timed out after 300 seconds. The complete policy log is available in the JSS at: https://xxx.jamfcloud.com/policies.html?id=1&o=l Computer Info: ID: xxx IP Address: xxx Serial Number: xxx Can someone tell me what's going wrong? The inventory there for too long and then he breaks it off?Regards
Hi Jamf nationFor user level configuration profile to get applied, is required that the account is MDM-enabled User.We no longer bind our Macs to the active directory, instead we use local admin account with Apple SSO Extension for the connectivity to the AD.Using ADCS, we were able to deploy certificates in computer-level configuration profile and everything works smooth and flawlessly.As most of our users still have incorrect MDM-Capable user, is a reenrollment to fix this issue not an option for us.Did someone find any solution for fixing the MDM-Capable user?Any other ideas to fix this without reenrolling the device?
Hey folks, Im trying to create a Self-Service policy that will Disable or Enable the "Smart Quotes" keyboard feature in system preferences. When I run this code in my Coderunner app it works perfectly, but as soon as I load the script in the into a Self-Service policy I seem to have issues. The policies behavior looks good, popup comes up but the setting does not change. Any ideas? Thanks in advance #!/bin/bash #Grab current logged in user user=`ls -la /dev/console | cut -d " " -f 4` #Check smartquote status currentstatus=$(defaults read NSGlobalDomain NSAutomaticQuoteSubstitutionEnabled) #SwiftDialog Location dialog="/usr/local/bin/dialog" #DISABLES if [ $currentstatus = 1 ]; then $dialog --message "You are about to disable Smart Quotes" --icon "/usr/local/images/deepwatch-Logo.png" --mini --button1text "Disable" --button2text "Cancel" sudo -u $user defaults write NSGlobalDomain NSAutomaticQuoteSubstitutionEnabled -bool false sudo killall Finder fi #
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!