Get Support
Recently active
Anyone deploying Beyondtrust with PPPC config ?I have a really strange issue. I deploy a PPPC config for beyondtrust for accessbility enabled and Full disk access. First time when connecting to a jump client it prompts the user to activate screen recording. User go in and enable screen recording and mac prompt for quit and restart jump client to activate screenrecording, which is done.However, the jump client is not comming up and no icon in the top bar and when checking the the device is also offline in rep console. If I manual unload and load beyondtrust lanchagent it comes back up - but not something users can doIf I however, do NOT deploy any PPPC client and users manually have to activate accessibility, Full disk access and screenrecording it works. I have also tried just to add accessibility or Full disk access in the PPPC to see if it is one or the other that gives the issue, but the issue stays.So PPPC profile is a no go overall to get this working it seems. Any one seein
Hi all. Has anyone had any experience with the fontrestore default command to clear out non-standard fonts? Seems to work OK on OSes up to Mojave and then seems broken for me in Catalina and above. The command is:fontrestore default ...and usually results in this or similar output after asking for authentication:testMac:~ username$ fontrestore default These fonts are not part of the default system install. They have been removed to 'Fonts (Removed)': /Users/install/Library/Fonts/Skia.ttf /Users/install/Library/Fonts/SnellRoundhand.ttc /Users/install/Library/Fonts/Songti.ttc /Users/install/Library/Fonts/StencilStd.otf /Users/install/Library/Fonts/STIXGeneral.otfHowever on Catalina I get:username@testmac ~ % fontrestore default unable to create '/Users/username/Library/Fonts (Removed)' (1 -- Operation not permitted) The installed fonts are awesome. No problems found.I checked that Terminal has full disk access but still get the above failure, even though I know th
Hi All, I'm looking to do something clever, but my scripting knowledge is pretty limited. I want to create a script which pops a dialog box up on screen with a few options to select from: LondonAtlantaHong Kongetc. The option select would then install the relevant computer policy via a trigger. I want to use to this for RescueAssist to install the correct package depending on Office location when building the laptop. Cheers,Steve
Hello Everyone,When we try to update many devices remotely or manually, we get a warning like the one below. we did the necessary research for this but we could not find an uptodate and useful solution.Error : (com.apple.OSInstallerSetup.error error 702.)Restarting in safe modefirst aidRedownload the packageprocedures have been tried. remote and manual result error is the sameAnyone want to make suggestions on the subject?
Hello all.I am working on getting a project to upgrade Macs to Ventura (or Monterey if they wont support Ventura) and I am having trouble. I have reviewed a number of posts on Jamf Nation and setup what others seem to mention works. However, I am not able to get it working and I am hoping someone can help me understand what I am missing. Intel Macs update w/o issue but M1s will not update and error with the "must be volume owner" error.I have created a policy to install, erase-install and dialog packages, and then start the erase-install with the --reinstall --current-user --depnotify switches using dialog as the prompt. The notification pops up to start the update then I get the error regarding volume owner. I also reviewed the Apple document https://support.apple.com/guide/deployment/use-secure-and-bootstrap-tokens-dep24dbdcf9e/web and it appears our keys are escrowed. We do bind our Macs and use mobile accounts and I am wondering if that is the issue.I am by no means a Mac or J
Hello Everyone,I am pretty new to JAMF so forgive me if I am not using terms correctly. I work at a college and we have Logic Pro installed on 15 2020 M1 Mac Minis. We recently were hit by a blizzard, a pipe bust, and flooded that lab. Now those machines have been lost due to water damage. Naturally we are trying to find an alternative set up with different machines. I need to free up those license and apply them to different machines. Currently, we apply these licenses via the "Assign Content Purchase in Volume" option (as opposed to the VPP codes). Is there a way, using JAMF Pro, that I can strip these licenses from the old machines and apply them to new machines?Can I just go to Mac Apps-> Logic Pro -> Scope and remove the broken machines to free up licenses? We are just a bit unsure and I don't want to make matters worse by just clicking around and seeing what happens.Let me know what you think!-Matt
Hey Jamf Nation,In Jamf Pro 10.35 we announced the deprecation of Basic authentication in the Classic API scheduled for a future release of Jamf Pro (https://docs.jamf.com/10.35.0/jamf-pro/release-notes/Deprecations_and_Removals.html). We received some great feedback from the community, and there were some questions around why we chose to make this change. I’d like to address those here. The change in authorization mechanism in the Classic API was an effort to quickly mitigate the threat of brute force attacks against Jamf Pro instances. Today, the Classic API is the main target for attackers executing brute force attacks to attempt to gain access to a Jamf Pro instance. By using the same authorization mechanism as the newer Jamf Pro API, we're able to funnel all auth requests through a small number of endpoints that we can rate limit, without limiting every API request. We know that a change like this causes additional work for customers and partners to update API
Is this still a download option? I've used all my Google-fu up on this one.
Hello, Anyone here already tried to deploy LastPass extension in Safari? Any solutions on how we can enable/checked the last pass extension in Safari through JAMF? Thank you in advance!
We are reviewing the permissions given to people that need to enroll their device (macOS only) by either DEP/ADE or user initiated permissions.First question, do DEP/ADE and user-initiated require the same permissions?Second question, what are the minimum required permissions?The strange thing is that the permissions for :Allow User to EnrollAssign Users to ComputersAssign Users to Mobile DevicesEnroll Computers and Mobile Devicesare not assigned, but no one reports any issue.When looking to the default role that allows people to enroll their device it seems to assign way to much.Anyone that knows the ins and outs?
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 10.42.1 fixes the following product issues: [PI110600] Updated a third-party library to resolve a known vulnerability (CVE-2022-42889). [PI110632] The device inventory record no longer fails to load due to a blank "priority" value in a database column. Review the release notes here. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 10.42.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. Hosted Region Begins Ends ap-southeast-2 4 November at 1300 UTC 4 November at 2200 UTC ap-northeast-1 4 November at 1400 UTC 5 November
Long story, but I'll try to keep it short. We have Jamf Connect in our environment linked to Azure for user authentication. We wanted this product because it has built in password change features that would synchronize the local system password with the users Azure (network) password and remove the need to bind our Macs to on-prem windows domains. Also we're a mixed environment of Windows and Mac system moving towards Azure cloud services and this would allow us to us ZTI for mac users. When we click "Change Password" nothing happens. We were able to temporarily resolve this issue by updating our Jamf Connect installs, but this only resolves for maybe 2-3 weeks before we noticed the same issue return, this is effecting all our Jamf managed macs. I engaged with Jamf support and they requested logs, suggested updating (again) had me try different default browsers. All the same results. Nothing happens, EXCEPT for a short time after updating the Jamf Connect client when it
Hi, We have recently deployed Azure AD SSO (and Azure AD DS) to login to our Jamf Cloud instance. It works great apart from SSO, every 24 hours we have to reset our web browser data to login to Jamf Admin. Any ideas on how to make this more reliable? I's guessing its something to do with 'Token Expiration (Minutes)'. Should I just increase this to a few weeks?
Currently Running:iMac 21.5"macOS Big Sur 11.7.2 When attempting to log in, we receive a pop-up screen from "Managed Software Center" it has the loading bar bouncing back and forth and it is attempting to install "HPPrinterDriverxxx.dmg" and perform "Postflight Tasks..." Our postflight tasks are running jamJAR v1.1I have removed the HP Printer Driver from Munki and any other places it might be trying to pull from. But we are still getting this pop-up message at the login screen attempting to mount the DMG (HP driver) and perform the postflight task. Sometimes it's on the postflight task in the "Managed Software Center" pop-up.This pop-up is preventing users from logging in because it is stuck on a loop. It will disappear for a couple of seconds and then reappear. Restarting the computer resolves this issue for about 15-20 minutes but then the problem presents itself again.We have attempted to completely re-image these machines from JAMF to no avail. Removed any policies/packa
Hi All,Wondering if anybody else is seeing this. On two Macs running Sierra - one is on latest 10.12.1 beta, I'm getting a Killed: 9 error when trying to create USB install media using createinstallmedia command: $ sudo /Applications/Install macOS Sierra.app/Contents/Resources/createinstallmedia --volume /Volumes/Install macOS Sierra --applicationpath /Applications/Install macOS Sierra.app Ready to start. To continue we need to erase the disk at /Volumes/Install macOS Sierra. If you wish to continue type (Y) then press return: Y Erasing Disk: 0%... 10%... 20%... 30%...100%... Copying installer files to disk... Killed: 9 I can run the command over and over, sometimes it is killed immediately, other times after a few mins. Can't find a single thing in the logs about this. Any ideas? Just me? Thanks!Matt
Hi everyonei'm trying to understand the best way to configure Jamf Protect with our jamf instance. I set up a smart group in jamf to alert users about security issues and that works fine.Unfortunately the jamf protect documentation is a bit incomplete imho. What are the next steps i need to follow? Any suggestion or guide to suggest?Do i need to manually remove the mac from the smart group?Jamf Protect has some removing capabilities or i need to clean the mac manually?
created a new policy for a 2023 version of some software. Tested new policy in prd in a limited scope. result=successThen widened the scope of the new policy to include the actual production machines. In the logs for the new policy, I'm seeing results from the old policy. it shows completed but the dates caught my attention so I looked at the details and sure enough it's the logs from the previous policy for an earlier (2019 software version) package install.
Is anyone having an issue enrolling machine this morning?I get this error right after the remote management page, This Service is Temporary Unavailable.
Greetings Jamf Nation denizens, I've recently tried to begin utilizing Patch Management features within JAMF Pro but have met some issues. I'm attempting to use the automatic distribution method instead of administering it through Self Service. I have confirmed that the Patch Policy has a defined scope with an eligible machine, but it remains stuck on "Pending". In this particular example I'm trying to update Google Chrome. Upon reviewing the logs, it appears a patch policy called just called "macOS" is being distributed to the device. This particular patch policy is titled "Google Chrome Patch Policy" so I would expect to see that being pushed in the logs. There are no Patch Policies set up called macOS in our JAMF Pro server. Other Patch Policy logs show this same policy. When running a sudo jamf policy command on the machine, it returns the "No patch policies were found" message, and remains "pending" in JAMF Pro. Is there a way to fully reset or flush
Hi,Have a few computers with Visual Studio Code installed. Users do not have admin rights on the computers, And should not have this. Now the users want to run the debugging process in Visual Studio Code. But they are prompted to write credentials to be able to run Developer Tool. Users need to be part of Developer Tools group to be able to run this. How do I solve this from Jamf Pro ?
Hi,I need some suggestion for local account creation using Jamf Connect Prestage. I am using Azure SSO part for account creation. Now all the local accounts are created with Admin privileges. I am planing to bring admin restriction in place. No one get admin rights from the beginning. I am using below Jamf Connect Config profile to create local account. I need some suggestion to make changes here, by default users creation should be without admin privileges.-----------<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>CreateJamfConnectPassword</key><true/><key>EnableFDE</key><true/><key>LAPSUser</key><string>admin</string><key>OIDCAdmin</key><string>Admin</string><key>OIDCAdminAttribute</key><string>roles</string><key>OIDCClientID&
Im trying to create a self-service policy with a script that will disable the "smart quotes" system setting but am running into issues getting this to work. defaults write NSGlobalDomain NSAutomaticQuoteSubstitutionEnabled -bool false Above command seems to work fine when using it on my local device but when trying to use this command in a jamf policy, no luck. any ideas on how I can get this to work? Thanks in advance.
Godo evening,a quick question, please: One of our applications is available as pkg installer but also as a "Jamf App Catalog" application in the Devices > Mac Applications tab. My understanding is that for the Application install pathway I can "enforce" updates via a configuration profile for System updates (or it should be enabled as the specific app says "Auto update disabled: no" whereas for the pkg installer I can create a patch management with subsequent definition of the latest package and a corresponding Patch Policy. The pkg pathway has the benefit of more granule scoping, however I am wondering what the general consensu on best practices is here?
Nudge Post-install (0.0.17) includes updates for Nudge (1.1.10)AboutConfigures Nudge via the Nudge Post-install script to create:LaunchAgent: Opens NudgeLaunchDaemon: Redirect LogsLocal JSON: Configures NudgeHides Nudge: Finder & LaunchpadReset function: Policy Script ParameterContinue reading …
Hello!I'm trying to use VPN Idle timer for mobile devices in Jamf Pro. After setting Idle Timer parameter for "1 minute" example, after saving configuration profile, Jamf sets this back to "Do not disconnect". Does anyone have ideas why Jamf doesn't save my option correctly?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!