Get Support
Recently active
I am currently testing Crowdstrike to be deployed to our Macs in our environment and running into an oddity. I have the config profiles created (one for Apple Silicon, one for Intel) and once applied to a computer, I get a weird network issue. Hopefully I can explain this clearly. I have Jamf open in a Safari tab apply the config profile to my same computer, verify it completes by opening Log. I then open a second tab and attempt to open any website and it never will load the page (at least in a reasonable amount of time) but generates no error. The tab that Jamf is open in works for the Jamf console, but you can't navigate to any other website.I can either restart the computer or kill my network connection (in this case wifi) and it resolves the network issue. I am still WFH so I can't test a wired connection. I see no documentation that indicates this config profile needs a reboot.As of today, we only run Crowdstrike on our Windows Servers an
Hello,Question on the consequences of deleting a computer object in Jamf Pro, how will that affect Management commands sent to that computer? Context: For a missing macbook, I have sent a wipe command so that next time the macbook is connected to the internet again, it will erase sensitive data.In addition, to clean up our Jamf inventory, I want to delete the computer entry so it avoids un-needed. I'm wondering if I delete the computer object, it will cancel those commands. Currently they are pending when I check their status.Thanks
Hello everyone, My company is transitioning from Malwarebytes to Jamf Protect by (hopefully) the end of the month. We need to uninstall the Malwarebytes endpoints from employees' machines but we're running into some issues. The Malwarebytes Nebula console allows us to delete endpoints and remove them from computers, but the user is prompted to enter admin credentials. Due to company policy, no computer has admin privileges. My question is if there is a way to either remove the Malwarebytes endpoint without needing admin credentials, enter admin credentials remotely, or some other solution that I haven't thought of. I did find this article but it seems that the type of Malwarebytes endpoint we have does not have these files in users' computers so the script doesn't work.The users do have the option to make themselves admin temporarily but I want to make this as zero-touch as possible since people can't be trusted to do this properly. It's very likely they'll cancel out of the
So i've been searching everywhere for a simplified answer (and maybe i did find it but am too dumb to realize) but does Nudge play nice with the Delay Major Update restriction payload? Basically what I am wondering is this: I have the major update delay set to 90 days. This means Ventura will be allowed to be updated on Jan 22nd.I have Nudge setting the minimum required OS as 12.6.2. In a perfect world this means Nudge would upgrade any devices below 12.6.2 to that version and not anything newer. I was reading however that the restriction payload simply hides the option to update. Does this mean Nudge would override the restriction and simply update any devices to the newest OS? I ask this because I saw a device go from 12.5 to 13.1 today. I wasn't sure if that was from Nudge overriding or if it was due to the "feature" for devices running 12.3 to 12.6.1 which offers a different path for upgrading (https://support.apple.com/en-us/HT213471)&n
Hi guys Has anyone been able to setup an office 365 account via an email variable in the mobile device app configuration box? e.g. the iPad Microsoft word app. Is it even possible? Any help or guidance would be awesome.
As some students have installed IOS 16.2, they now have access to Freeform. I want to place the app in our Apple folder for all of the students, which was created using the layout profile in jamf school.However, Freeform hasn't yet appeared in the internal apps section in jamf school, so I don't have the ability to currently place it in any folder of my choosing. Is there anything I can do to get freeform into jamf school or is it just a case of waiting?Any help would be much appreciated.Thanks
Hello, Is there any way to update a specific app on specific devices? For example, I have an app running on 44 devices but I only want to update that app on a small portion of the 44 devices. Is there anyway to do that?
This one has me stumped. In the past when I've needed to run a bash script as the logged in end user I've simply used something along the lines of:userName=$(stat -f %Su /dev/console) sudo -u $userName -H bash -c "jamf recon"This method seems to still work just fine IF I manually call the policy (jamf -policy) or manually initiate an inventory update (jamf recon) but when it's called with the recurring policy action or daily recurring inventory action it fails, and seems to run as root. So:Logged in as sjobs, run 'jamf -policy' = Success, policy executes, relevant lines will successfully run as sjobsLogged in as sjobs, run 'jamf recon' = Success, EA executes, relevant lines will successfully run as sjobsLogged in as sjobs, Mac is not asleep or unattended, recurring policy trigger occurs in background = Failure, policy executes, relevant lines run as rootLogged in as sjobs, Mac is not asleep or unattended, recurring inventory trigger occurs in background = Failure, EA executes, relevan
Hello, We need to have a package installed on our Mac fleet, and while it works when the users get on VPN, the package fails when they are not on VPN. Thank you,
Hello,When enrolling Macs, a specific package is failing to install. In the Policy Logs I see - Installation failed. The installer reported: installer: Error - the package path specified was invalid: How do I change this path so I can direct it to Application folder? Thank you,
Hi,We are trying to enable Bluetooth option for authorized or allowed Bluetooth headsets and wanted to block other services. Please help us on providing the solution to enable in JAMF Pro. We dont find relevant document in Jamf website.
We need to authenticate our Mac on WiFi using PEAP ( username & password ) and we have AD on-premise, is there way to accomplish that without binding our Macs to AD ( please say yes ) ??
Anyone deploying Beyondtrust with PPPC config ?I have a really strange issue. I deploy a PPPC config for beyondtrust for accessbility enabled and Full disk access. First time when connecting to a jump client it prompts the user to activate screen recording. User go in and enable screen recording and mac prompt for quit and restart jump client to activate screenrecording, which is done.However, the jump client is not comming up and no icon in the top bar and when checking the the device is also offline in rep console. If I manual unload and load beyondtrust lanchagent it comes back up - but not something users can doIf I however, do NOT deploy any PPPC client and users manually have to activate accessibility, Full disk access and screenrecording it works. I have also tried just to add accessibility or Full disk access in the PPPC to see if it is one or the other that gives the issue, but the issue stays.So PPPC profile is a no go overall to get this working it seems. Any one seein
Hi all. Has anyone had any experience with the fontrestore default command to clear out non-standard fonts? Seems to work OK on OSes up to Mojave and then seems broken for me in Catalina and above. The command is:fontrestore default ...and usually results in this or similar output after asking for authentication:testMac:~ username$ fontrestore default These fonts are not part of the default system install. They have been removed to 'Fonts (Removed)': /Users/install/Library/Fonts/Skia.ttf /Users/install/Library/Fonts/SnellRoundhand.ttc /Users/install/Library/Fonts/Songti.ttc /Users/install/Library/Fonts/StencilStd.otf /Users/install/Library/Fonts/STIXGeneral.otfHowever on Catalina I get:username@testmac ~ % fontrestore default unable to create '/Users/username/Library/Fonts (Removed)' (1 -- Operation not permitted) The installed fonts are awesome. No problems found.I checked that Terminal has full disk access but still get the above failure, even though I know th
Hi All, I'm looking to do something clever, but my scripting knowledge is pretty limited. I want to create a script which pops a dialog box up on screen with a few options to select from: LondonAtlantaHong Kongetc. The option select would then install the relevant computer policy via a trigger. I want to use to this for RescueAssist to install the correct package depending on Office location when building the laptop. Cheers,Steve
Hello Everyone,When we try to update many devices remotely or manually, we get a warning like the one below. we did the necessary research for this but we could not find an uptodate and useful solution.Error : (com.apple.OSInstallerSetup.error error 702.)Restarting in safe modefirst aidRedownload the packageprocedures have been tried. remote and manual result error is the sameAnyone want to make suggestions on the subject?
Hello all.I am working on getting a project to upgrade Macs to Ventura (or Monterey if they wont support Ventura) and I am having trouble. I have reviewed a number of posts on Jamf Nation and setup what others seem to mention works. However, I am not able to get it working and I am hoping someone can help me understand what I am missing. Intel Macs update w/o issue but M1s will not update and error with the "must be volume owner" error.I have created a policy to install, erase-install and dialog packages, and then start the erase-install with the --reinstall --current-user --depnotify switches using dialog as the prompt. The notification pops up to start the update then I get the error regarding volume owner. I also reviewed the Apple document https://support.apple.com/guide/deployment/use-secure-and-bootstrap-tokens-dep24dbdcf9e/web and it appears our keys are escrowed. We do bind our Macs and use mobile accounts and I am wondering if that is the issue.I am by no means a Mac or J
Hello Everyone,I am pretty new to JAMF so forgive me if I am not using terms correctly. I work at a college and we have Logic Pro installed on 15 2020 M1 Mac Minis. We recently were hit by a blizzard, a pipe bust, and flooded that lab. Now those machines have been lost due to water damage. Naturally we are trying to find an alternative set up with different machines. I need to free up those license and apply them to different machines. Currently, we apply these licenses via the "Assign Content Purchase in Volume" option (as opposed to the VPP codes). Is there a way, using JAMF Pro, that I can strip these licenses from the old machines and apply them to new machines?Can I just go to Mac Apps-> Logic Pro -> Scope and remove the broken machines to free up licenses? We are just a bit unsure and I don't want to make matters worse by just clicking around and seeing what happens.Let me know what you think!-Matt
Hey Jamf Nation,In Jamf Pro 10.35 we announced the deprecation of Basic authentication in the Classic API scheduled for a future release of Jamf Pro (https://docs.jamf.com/10.35.0/jamf-pro/release-notes/Deprecations_and_Removals.html). We received some great feedback from the community, and there were some questions around why we chose to make this change. I’d like to address those here. The change in authorization mechanism in the Classic API was an effort to quickly mitigate the threat of brute force attacks against Jamf Pro instances. Today, the Classic API is the main target for attackers executing brute force attacks to attempt to gain access to a Jamf Pro instance. By using the same authorization mechanism as the newer Jamf Pro API, we're able to funnel all auth requests through a small number of endpoints that we can rate limit, without limiting every API request. We know that a change like this causes additional work for customers and partners to update API
Is this still a download option? I've used all my Google-fu up on this one.
Hello, Anyone here already tried to deploy LastPass extension in Safari? Any solutions on how we can enable/checked the last pass extension in Safari through JAMF? Thank you in advance!
We are reviewing the permissions given to people that need to enroll their device (macOS only) by either DEP/ADE or user initiated permissions.First question, do DEP/ADE and user-initiated require the same permissions?Second question, what are the minimum required permissions?The strange thing is that the permissions for :Allow User to EnrollAssign Users to ComputersAssign Users to Mobile DevicesEnroll Computers and Mobile Devicesare not assigned, but no one reports any issue.When looking to the default role that allows people to enroll their device it seems to assign way to much.Anyone that knows the ins and outs?
Today we are releasing a maintenance version of Jamf Pro. Jamf Pro 10.42.1 fixes the following product issues: [PI110600] Updated a third-party library to resolve a known vulnerability (CVE-2022-42889). [PI110632] The device inventory record no longer fails to load due to a blank "priority" value in a database column. Review the release notes here. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Products section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, including any free sandbox environments, will be updated to Jamf Pro 10.42.1 based on your hosted data region below. Review this guide if you need assistance identifying the Hosted Data Region of your Jamf Cloud instance. Hosted Region Begins Ends ap-southeast-2 4 November at 1300 UTC 4 November at 2200 UTC ap-northeast-1 4 November at 1400 UTC 5 November
Long story, but I'll try to keep it short. We have Jamf Connect in our environment linked to Azure for user authentication. We wanted this product because it has built in password change features that would synchronize the local system password with the users Azure (network) password and remove the need to bind our Macs to on-prem windows domains. Also we're a mixed environment of Windows and Mac system moving towards Azure cloud services and this would allow us to us ZTI for mac users. When we click "Change Password" nothing happens. We were able to temporarily resolve this issue by updating our Jamf Connect installs, but this only resolves for maybe 2-3 weeks before we noticed the same issue return, this is effecting all our Jamf managed macs. I engaged with Jamf support and they requested logs, suggested updating (again) had me try different default browsers. All the same results. Nothing happens, EXCEPT for a short time after updating the Jamf Connect client when it
Hi, We have recently deployed Azure AD SSO (and Azure AD DS) to login to our Jamf Cloud instance. It works great apart from SSO, every 24 hours we have to reset our web browser data to login to Jamf Admin. Any ideas on how to make this more reliable? I's guessing its something to do with 'Token Expiration (Minutes)'. Should I just increase this to a few weeks?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!