Get Support
Recently active
I'm currently testing out a Jamf Now (Fundamentals) deployment for a couple of Macs we have. I haven't used Jamf before so not too sure how Jamf connect should work, but have a feeling mines not correct.I have setup the setting "Enable password sync with Jamf Connect" and done the setup in Azure for it. When a user first logs on it asks to type in both password (microsoft & then local password) so it could sync.Then we changed the password in Microsoft to see if it worked but on the macbook we have to login with the old local password and then in Jamf connect enter the email and the new microsoft password and it says they are out of sync and input the local password.I assume this should be a bit easier as its not exactly syncing the passwords currently?
Dear all, I have a recent problem with NOMAD.Before, a user would connect to Nomad and when his AD password was changed, NoMAD would detect it and ask the user to change his local password.Now, a user logs in to NoMAD but the AD password changes are no longer seen by NoMAD and the user remains logged in.Any luck on this one ?
This script checks for if the Mac is an M1 Chip, then if it is not, will check for the OS. Depending on these conditions, the year will be read differently.#!/bin/sh #Set variables for processor, apple chip, & operating system versionprocessor=$(/usr/sbin/sysctl -n machdep.cpu.brand_string )AppleChip="Apple M1"AppleChipYear=$(/usr/libexec/PlistBuddy -c "print :'CPU Names'" ~/Library/Preferences/com.apple.SystemProfiler.plist | tr ' ' ' ' | grep -e "M1, 20[0-9][0-9]" -e "20[0-9][0-9]" | sed 's/[[:punct:]]$//' )os_ver=$(sw_vers -productVersion | awk -F. '{print $2}')os_ver2=$(sw_vers -productVersion | awk -F. '{print $1}')#check if the machine is an Apple M1 processorif [[ "$processor" == *"$AppleChip"* ]]; thenecho "$AppleChipYear" else#Check which operating system version is on the mac if not an Apple M1 chip processorif [[ ${os_ver} -le 14 ]] && [[ ${os_ver2} -le 10 ]]; then plistFile="/System/Library/PrivateFrameworks/ServerInformation.framework/Versions/A/Resources
Hi, I'm looking to be able to allow pairing with our fleet of iPads to one specific iMac so that they can be restored in AC2 without each one having to be put into recovery. Is this possible?I can see in JAMF that our profile for our iPads has the pair to Mac option, but I don't know if that will only pair to Mac's with the supervisor identity cert or with any Mac.
Hello all,I have gotten Notify and connect to work with my deployments. However user's screen are turning off when Notify is running. 1. Is the computer sleeping or is the screen just turning off?2. If it is sleeping I want to make config profile to turn off sleep that will push initially, but removed via smartgroup after Notify has finished. What would you suggest for the smartgroup criteria?
The long version:Previously unmanaged Mac user population at my org. Spent the last 4 months aggressively chasing the users to get their devices enrolled and setup with management. This was a battle in itself. Many Mac users struggling with the the fact that these are company owned devices and not personal computers. This isn't helped by the fact that Mac computers are about 5% of the organizations total computer inventory, so these users feel some kind of prestige feeling about having a Mac.Had maybe 1 month of peace after completion before it got out of hand. Users are blaming Jamf for every single thing that goes wrong. Printer offline? Must be that Jamf thing you installed. Outlook crashed? Jamf. Network slow? jamf. Spilled coffee on the keyboard? Probably Jamfs fault. People's managers are complaining about the false perception of Jamfs impact and now the rumor has spread.The only people that recognize the nessecatiy for Jamf are the IT Security team and my manager. However, the o
We are new to Jamf Pro. I have several users who are coaches that use software specific to their sport. The software updates at weird times and when the coaches are on the road, they can't update their software due to not having admin privileges on their laptops. Is there a way using Jamf to automate these updates so they can install them as non-admins? Better yet, install them in the background?
Started doing some initial testing with ZScaler ZCC and noticed that while the installer didn't prompt for it, under Security and Privacy > Full Disk Access there is a ZscalerTunnel binary that's unchecked. Does anybody have a config profile for enabling that or is it okay to just have it disabled?
We were just made aware of this, and Jamf and Apple have confirmed. The Ventura release on Monday will be considered a minor update for anything 12.3 and higher, so major OS deferrals will not apply. Apple's recommendation is to defer all minor updates as well as major until you can get your clients to 12.6.1 (not released yet, maybe also on the 24th?). Jamf confirmed to us that you should have all your clients at 12.6.1 by Wednesday, November 23, 2022 if you wish to defer Ventura past that date. Just passing on info. Hopefully this helps someone avoid a rough Monday.Edit: Adding direct quote from our Jamf rep that explains better than I did:Ventura major deferral bug, in a nutshellOn macOS 12.2 or earlier? - You're all good. Not affected.On macOS 12.3 or later?There's a bug. It's fixed in 12.6.1 and Apple has made a change so even 12.3+ will be fine for 30 days - make sure to get 12.6.1 installedIf you don't get 12.6.1 installed, Ventura updates published after 30 days might
為了支援 macOS 使用者能完成工作,從部署各式各樣的第三方軟體,像是文書軟體、瀏覽器、程式編輯器、回報目前使用者所使用的軟體版本,一直到更新已裝在 Mac 上的第三方軟體,都能在 Jamf Pro 的幫忙下完成。然而,有別於 macOS 對於升級作業系統有延後最大 90 天的機制,第三方軟體在 macOS 作業系統上的更新方式顯得更為多元,但對於 IT 同仁來說也增加了理解的成本與選擇困難。這篇文章簡要的整理出,在 Jamf Pro 的幫忙下,能以哪些型式派發更新至 macOS 設備上,主要分成以下 3+1 點:Jamf App CatalogPatch ManagementSelf Updater使用 Mac App Store 部署的Jamf App CatalogJamf App Catalog 是一個非常方便的 Jamf Pro 功能,只要你是使用 Jamf Cloud 就能在 Jamf Pro > 電腦 > Mac App > 新增 > Jamf App 目錄下找到它。有別於以往部署軟體和更新軟體是兩件事情,Jamf App Catalog 將它整合在一起。IT 人員再也不需要去重新打包第三方軟體的安裝程式,也不用去追蹤某個軟體是否出了新版、不需要擔心這個軟體的安裝檔是否為合法正版。Jamf App Catalog 直接搞定所有的事情。Jamf App Catalog 是一個由 Jamf 維運的雲端服務,它會主動的去了解清單上的軟體有沒有最新版,如果有便會自動進行打包,確保軟體的來源合法。這個功能有幾個好處:IT 人員不用自己追蹤版本號、不用自己打包該第三方軟體在使用者電腦上永保如新當然,也帶來幾個不方便的地方:截至寫作當下,Jamf App Catalog 會自動更新電腦上的該應用程式,不能夠放在自助服務區給用戶自行選擇更新時間。因為會確保第三方軟體為最新,IT 人員無法控制更新時序。例如想要先測試過後才部署給用戶,這個就無法。Jamf App Catalog 的清單如列:https://docs.jamf.com/jamf-app-catalog/App_Installers_Software_Titles.htmlJamf App Catalog 的使用文件:https://docs.jamf.com/zh/jamf-pr
I'm having an issue uploading a configuration profile for nudge. When I install the profile locally, there are no issues and everything worksThis is the content. Not sure What I'm doing wrong here. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>PayloadContent</key> <array> <dict> <key>PayloadDescription</key> <string>Configures all Nudge preferences</string> <key>PayloadDisplayName</key> <string>Nudge Preferences</string> <key>PayloadIdentifier</key> <string>com.github.macadmins.Nudge.preferences.example</string> <key>PayloadOrganization</key> <string></string> <key>PayloadType</key> <string>com.github.macadmins.Nudge</string> <key>PayloadUUID<
Hello I'm still learning. I have created a smart group with systems that were compatible with Big Sur which I got this value(MacBook(10|9|8)|MacBookAir(10|[6-9])|MacBookPro1[1-7]|Macmini[7-9]|MacPro[6-7]|iMacPro1),\\d|iMac(14,4|1[5-9],\\d|20,\\d) I was wondering how I could get the opposite of it. Like create a smart group with systems that aren't compatible with Big Sur. I'm still new to this well at least with the regex stuff on finding the hardware. Thank you any help would be greatly appreciated.
One of the questions on the test exam is: "Supervision is available as part of a computer PreStage Enrollment configuration." Which the answer key says is false. I assume this is because it isn't part of the PreStage Enrollment settings but my question is if this is misleading because PreStage Enrollment requires DEP which can be used to supervise a device. Considering that DEP is a prerequisite is it not fair to say that PreStage Enrollment can supervise a device? Or is it somehow important to split hairs like this because of where the setting is even though the ultimate outcome is the same?
I have a test macbook that was enrolled into JAMF. I reimaged it via macOS Recovery, which installed a fresh new OS for Ventura. I thought maybe this was a Ventura issue, so I rolled back the OS to an earlier version (Big Sur) and the same issue occurs. I get this error: " An error occurred. Contact your IT Administrator " Note: For clarity, the MacBook installs any macOS just fine, and seems to gather the enrollment profiles/policies from JAMF, but upon first boot (when the user should enter their SSO credentials), it gives this screen.
So I worked a couple of years back with DEPNotify and it was working great for our purpose.Does it still work great? Would like to have it start after a user completes enrollment via Apple Business Manager into Jamf Pro.I read some conflicting experiences if DEPNotify still works with the enrollment complete trigger used by Jamf Pro.Anybody?
is there any script and setting in Jamf pro that I can configure all endpoints and users for getting automatic backup on their google drive space for specific folders like Documents etc...
Hello,We have been having lot of iPads in our school district getting an error in self service that states " Error loading Content". We updated configuration for self service, updated self service and removed self service and added it back. Removing SS and adding it back does resolve the issue, but I am looking for a permanent fix. Thank you !
Hey there,I have the problem that notifications in Self Service (new version of an app available) reappear after a computer restart - how can I prevent this from happening? I have already deleted the messages in Self Service, but they still reappear after a computer restart. WWhat can I do to stop these batch notifications from appearing?What can I do to stop these batch notifications from appearing? The tips found here with terminal commands, for example, did not work.Thank you!
Is it possible to disable a specific app on a Macbook? For example the app store?
So we have Installomator setup to install Office 365 to all devices. This seems to work without a hitch on newly enrolled M1 and M2 devices, however always fails when installing on an older Mac. After checking the logs I saw the error where it couldn't connect to https://go.microsoft.com/fwlink/?linkid=525133. I decided to manually navigate to the site on the device to see what happens and when i do, I get prompted to allow download on "officecdnmac.microsoft.com" with the option for me to allow. I choose Allow on the device, manually delete the pkg once it downloads, refresh Self Service and the script ends up working fine. Does anyone know a way around this? Is there a way i can automatically allow downloads?
Hello,I am looking for a way to update all of my current users name field in Jamf Pro to their full name.Currently we have our LDAP setup between OKTA, jamf connect, and Jamf Pro. So when a user takes their device out of the box, they have to sign in with their OKTA credentials and Jamf sets the device up for them. Their full name, username(email address), and email address come over to Jamf Pro correctly. But the (computer?) name field comes over to Jamf Pro as Macbook Air. Link to screenshot of what I am looking at https://imgur.com/a/MyT8BSKIs there a way to update this field to be their full name? And a way for future users to have it be their full name too? I assume you could script it somehow, but I am a scripting noob.Thank you for assistance.
I've got a weird one. Our company is implementing a policy that your account will become disabled after five login attempts. Our instance of Jamf Pro seems to submit two login attempts to our Active Directory domain when a user attempts to log in to it which therefore only gives the user three attempts to authenticate before their account gets locked in Active Directory instead of five. I haven't seen anyone else with this issue online. We previously had both of our domain controllers listed as LDAP servers in our instance of Jamf Pro but recently consolidated them in Jamf Pro to our single reachable domain. I would've thought that this would've fixed the issue since the login should only be attempted once per listed LDAP server, but nonetheless Jamf Pro is causing my account to be locked after three login attempts instead of the normal five. We also attempted to use Single Sign-On for awhile, but ran into unrelated issues with that and disabled it shortly thereafter. Does anyone have
Hi EveryoneI'm very new to the coding side of MacOs and currently need to create a LaunchAgent for our printer costing app. The app itself is just a normal app that can be manually launched from launchpad or set to auto launch per user, however I need to make sure it runs on every single log in inside our labs. Can someone give me some pointers or help in creating the plist file? I literally just need it to launch "/Applications/Monitor Popup.app" when someone logs in.Thanks
Hey Folks,I’ve had multiple conversations with both Jamf and Apple about their recommendations here, but neither have been able to give a definitive answer:We’re migrating iOS devices from Intune to Jamf, one-at-a-time as people come up for refresh.- All devices are DEP. We have “light touch” management: our company doesn’t push apps/data to devices that we’re concerned about, and users are technically able to remove Intune from their devices.- We are not moving existing devices to Jamf (only brand new or wiped devices)- We’re concerned with this being as seamless as possible for our users and getting their purchased apps and personal content positioned as they would expect.Our initial plan, that we now know won’t work (because the backup retains the device's Intune Enrollment): Intune Phone -> iCloud Backup -> Restore to brand-new iPhone -> Enroll in Jamf Initial tests indicate that Option 1 (below) does work, that Jamf correctly interacts with the device, an
I'd like to be able to add the iPads serial number or asset tag to the wallpaper as a standard barcode, instead of a QR code, so it can be easily scanned during a stocktake.Is this possible, or would we need to get QR capable scanners instead?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!