Get Support
Recently active
Hi there, We've recently migrated all our devices to jamf Pro from Meraki MDM. Our concern is because of how the jamf migrate tool brings devices into jamf Pro as user initiated enrolments that we are not able to manage local accounts the same way we would in prestage/ade enrolled devices. Is anyone aware of a means of getting control of the local user account that would make it possible for us to either delete or change the password of that account of the employee leaves? Since 80% of our devices have been enrolled in this fashion we'd be willing to use a paid solution as well.
Attempting to create a new package but stops at 99%I created a ticket, but no resolution. we started troubleshooting last Thursday. Any ideas?
I am trying to set up JAWA (https://github.com/jamf/JAWA) to use within my organization for automated notifications to a Teams channel. We have an older Mac Pro we were going to use to host the RHEL server for JAWA. My organization's InfoSec department informed us they require this type of an application to be hosted by Azure for security and compliance purposes. I have not registered an application with Azure before, and I am also pretty foggy when it comes to certificates. I know it is a longshot as I would imagine JAWA is pretty niche, but if anyone has had to register an application with Azure before, or has successfully implemented JAWA in their organization I would immensely appreciate all the help I can get.
Hi, is there a CLI from MacOS client to fetch the Room info under Inventory/User and Location/Room?
We're in the process of testing out Ventura. I updated from Monterey 12.6.2 to Ventura and keep getting AppSSOAgent error and it says quit or report. Our SSO is working, but this keeps coming up. Has anybody else experienced this error and have a resolution? Thanks
Hi all,Has anyone had success using an Apple TV device on a touch screen monitor and gotten the touch feature to work? Looking to replace full blown PCs with Apple TV's for large touch screens that are used to display a webpage with different data navigable by touch.Any thoughts/successes you can share appreciated. So far all I have found out there is a bunch of "Apple TV is not a touch device" negative Nancy's. Hopefully some of you are creative and found a way.
Our setup has a generic local admin account to all enrolled macOS devices.We have a policy for FileVault that triggers on logout. I know this can be bypassed but the current workflow works for now until I can get my scenario to work.Our current fleet has encrypted and unencrypted devices.We also have a number of devices prepped, ready to be assigned and not yet encrypted. These prepped machines will have the local admin account and then get delivered to our assigned users. We use Jamf Connect's Microsoft 365 login to allow assigned users a way to create their local user profile.For the devices that are assigned and not yet encrypted, the assigned users have been canceling the encryption popup to bypass the encryption process. Ideal scenario:Do not enforce our FileVault policy to these devices that has not yet been logged in by the end users.After an end user has logged into the device, it will create a local user account which will not have administrator privileges. At this point
I have a room of M1 Mac Minis used for a Digital Art/Printing lab. The instructors like to use a plug-in that has not yet been updated to run natively on Apple silicon, so to use the plugin the students/users have been finding the Adobe Photoshop.app, getting info, and ticking the Rosetta box manually... nearly every time they go to run the app (the user account is removed upon log out and refreshed via script).I'm curious if anyone has any experience managing these settings. They appear to be set in a plist file in the user's Library folder: ~/Library/Preferences/com.apple.LaunchServices/com.apple.LaunchServices.plist; but I have not had any success trying to manage this with a custom config profile in Jamf, nor does dropping the preconfigured file into place during account creation keep that box checked.
Hi, Can anyone help me to provide the latest "SetTimeZone and SetTimeServer" Jamf script? as their old scripts are not working in M1+Monterey OS. Scripts are executing without any error but Time Zone>>"Set time zone automatically using current location" tick is not not enabled.
Hi, I'm running a script from Jamf that pulls a gitlab repo then executes a script from said repo that installs some packages leveraging brew install. The script works nicely on the intel laptop but not on M1The error showing in Jamf should the script executed other parts of the script but fails when calling brew.install.sh: line 10: brew: command not foundIf I run sh install.sh locally via terminal it works well. If I run brew in either bash to zsh it finds the command.What could be occuring differently when executing the script via Jamf Self Service that means it's completely oblivious to the brew installation?Jamf Script Snippet#!usr/bin/env bash #Get loggedInUser name loggedInUser=$( scutil <<< "show State:/Users/ConsoleUser" | awk '/Name 😕😕 && ! /loginwindow/ { print $3 }' ) #Execute script under loggedInUser #sudo -u "$loggedInUser" ~/devtools/install.sh #!usr/bin/env bash ############################ # installs homebrew packages # i
Hello all,I am having issues with the Okta Browser Plugin Chrome extension settings. When you open the plugin settings, the option "Disable browser password prompts" is toggled on and greyed out with the message "This feature is not available because your privacy related settings are managed by your organization or another extension". I want the users in the organization to be able to toggle this off but cant seem to find the cause of this blockage. I've spent hours working with Google Support and Okta Support trying to figure out what could be blocking this, iv ruled out both Okta and Google Browser Management and confirmed with Google support that none of my policies are blocking this setting. I did some digging in the "Chrome://policy" json file and found this warning along with the Okta Browser extension ID "warning": "This policy is working as intended but a conflicting value is set elsewhere and is overridden by this policy."My next steps are to lo
I just joined a new company that currently uses a combination of Addigy and Meraki for MDM. After spending the last three weeks with Addigy, I can point to only one advantage over Jamf Pro. Addigy is more MSP focused. We can create multiple tenants to manage clients separately. In the past I have used sites in Jamf Pro for this and dedicated Jamf Pro servers for clients who are setup with Apple Business Manager. While I was being interviewed for this position, I made it very clear that I feel that Jamf Pro is the best solution and that I prefer to work with it over other MDM solutions. Today we have a meeting scheduled to discuss how the company will move forward with MDM solutions. I am strongly pushing for Jamf Pro. I would love some advice on how to convince the owners of the company to go with Jamf. I could learn to use Addigy but I feel that this would be a huge time drain when I already know Jamf Pro extremely well. What are some good points I can make to help convince them that
Do you deal with compliance on macOS devices? Have you reviewed the macOS Security Compliance project (mSCP) but have more questions? Have you heard about Jamf Compliance Editor?Great news, there are Open Office hours on Wednesday, Nov 2nd @ 2pm ET! Please sign up here: https://forms.office.com/r/erLkfc42xR
I am trying to setup out JSS to relay messages out to Office 365. All of our mailboxes are in the cloud.I have it setup to use smtp.office365.com on port 587 with SSL. Anyone else set this up and have any info. I keep getting an error when sending a test email.
Is there a way to either delete Pre-installed Apple Apps through Jamf Pro or configure settings so that they do not install?
Hi folks, Enrolling some macs via the QuickAdd package, and while it works for 12.5.1, it fails for 12.6.2. Trying both a signed and unsigned package.Anyone else seen this behaviour yet? Package built using the latest Jamf Pro tools.Regards,Ally
Hello Jamf Nation, Looking for assistance for forcing password resets for our users who almost all have Standard User accounts. There are some exceptions in which some users have an Admin account. We are doing this to increase the complexity of passwords and the amount of characters needed.- Our current configuration profile has the old character count.- Our users are also using a static password as well (keeping static for now) How would we go about creating a policy that forces them to reset their passwords (once we've updated the config profile to include the new amount of characters needed)?
I want to make smart groups that pull user department info, that way the department determines the enrollment build. What I want is when someone from "Data Management" signs into a MacBook they will get the enrollment build custom to their software needs. Has anyone done this before?
Hello, I am trying to set desktop icons as visible with a script. I assume I can do a "defaults write ..." to some plist file to set these options, but after setting them myself while running Composer to try to see which file was edited, I was lost in plist confusion.To be clear, the settings are shown in the GUI under Finder settings (In Finder, type command comma and click the General tab) as:Hard DisksExternal DisksCDs, DVDs, and iPodsConnected Servers I would like to set those four as visible (checked) via command. Thanks for any help anyone can provide
Hello, I am having some problems with getting our Mac devices to register with Intune for compliance and Conditional Access. We are still in a phase of rolling out Jamf to our business, and we had it working at one point (with 3 devices enrolled successfully), however now we cannot get any devices to register. We have raised this with Microsoft, and with our Jamf support representative, and both seem to believe the issue lies with the other, so I'm wondering if anyone here has any advice please. For context, I have:Configured the Cloud Connector in Jamf with our Intune - this shows as connection successful - https://imgur.com/a/KS035gy Followed the documentation on Jamf here to:Download the Company Portal pkg and upload it as a Policy in JamfCreate a policy to register device with AAD with the Microsoft Device Compliance payload selected On new devices, I install the Company Portal app from Self Service first, then once installed, Install the Register device with AAD pol
I'm setting up a kiosk Mac with Mojave installed and need to remove the prompt to require a password after the screen saver begins. I would like to change the setting through a script so it doesn't have to be changed manually. I've tested a few scripts I found online but they didn't change the settings. Is anybody able to advice how to do through a script or terminal command.
Hi all,Is it possible to configure a focus for an ios device via jamf pro? I want to set a work focus to show and hide work apps.If it is possible, how does it work?Thanks and kind regards!Paul
I have been running into a couple instances where a user updates their password (Google), logs in on JAMF connect and their local account gets locked.I have run the unlock command on their account, but when they reboot, it gets locked out again.Is there a workaround that I an do so I can get my user back into their laptop? Our workforce is all remote so I don't have the luxury of getting my hands on the laptop.
When you use the erase-install package and I'm using it so the message is the full screen. When the full screen is used, does it stay up until the device restarts? I'm trying it in test mode, but the full screen only stays up for 30 sec and it goes back to the desktop. Could that be because I'm testing it? One of our issues is, when we have users kick it off using the --depnotify, they see the prompts and after the last one, some have been restarting it even though we've told them let it sit. Below is what I was testing./Library/Management/erase-install/erase-install.sh --reinstall --pkg --version=12.6.2 --min-drive-space=35 --current-user --fs --cleanup-after-use --test-run
I'm upgrading custom PDF options in both the root library and user library and need a way to delete the existing files I've come across a script working till it tries to use the user$ variable in the file path. Trying to figure out what I'm doing wrong or if there is a better way to do this. Here is the script: #!/bin/bash# Get a list of users, filtering out service accounts, root, daemon, and nobody...#users=$(dscl . list /Users | grep -v -e '_' -e 'root' -e 'daemon' -e 'nobody')# Loop through the list of users.for user in [$users]; do# Put the path to the directory in a variable.# The quotes escape the spaces.#[ $dir= ]"/Users/$user/Library/Application\\ Support/Adobe/Adobe\\ PDF/Settings"# For each $user, delete the directory if it exists.if [ -d "$dir" ]; thenrm -rf "$dir"fidone
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!