Get Support
Recently active
I have deployed Jamf Safe Internet to my macOS and when I click to see how many devices there is, it doesn't say the name on the device or the user. Is there something I need to do so I can see who is trying to access certain websites?
Hello community,thank you all for your engagement and the time, you spent here to help me and others. I wish you all a Merry Christmas with your families and a happy, carefree 2023. This will be my last post so far, because we have decided to use a different MDM System and discontinued Jamf.Best regardsMichael Maier, aka NOVELLUS
Trying to get Jamf Pro AD CS Connector working... keep seeing these the Jamf Pro logs. Does anyone know where problem is?2022-12-17 04:23:20,017 [ERROR] [na-exec-122] [dmControllerProcessorImpl] - Could not create MDMResponseAction, returning 5002022-12-17 04:27:58,303 [INFO ] [eralPool-11] [tionPointInventoryUpdater] - Updating inventory files2022-12-17 04:55:48,943 [INFO ] [duledPool-0] [PendoEventPublisher ] - Failed to send Jamf Engage API Track Event to Pendo. For more info, turn on debug logs.2022-12-17 05:01:01,016 [INFO ] [duledPool-9] [rentProfileCleanupMonitor] - Running parent profile cleanup.2022-12-17 05:23:22,640 [INFO ] [duledPool-2] [PendoEventPublisher ] - Failed to send Jamf Engage API Track Event to Pendo. For more info, turn on debug logs.2022-12-17 05:27:00,385 [WARN ] [na-exec-132] [Credentials ] - We don't want to return an X509 Cert from a PKCS12 data blob2022-12-17 05:27:00,431 [WARN ] [na-exec-132] [Credentials ] - We don't want to return an X509 Cert fr
I have found a number of older discussions asking for a way to allow non-admins the ability to manage individual system preferences but I'm not having luck on utilizing them on 10.13 (did not try all recent macOS major releases). Hoping to find something that can apply to machines running macOS 10.10-10.13. Does anyone have a up-to-date script or configuration profile to all non-admin users (not sure if it matters but they are also AD mobile users) to control Network System Preferences? Specifically hoping to allow non-admin users to be able to remove remembered networks. When trying this process I get an error: bash: /tmp/system.preferences.plist: Permission denied
We have Jamf configured on 99% of Macs so Gatekeeper will only allow apps from "App Store" and "App Store and identified developers".When we get an app from an unidentified developer and it's not signed we install it in the applications folder on a Mac that has Gatekeeper set to allow apps from "Anywhere" (the 1%). Click it to open, gatekeeper asks if we want to allow it and we click yes.Once installed we then make a pkg of that app, (we don't sign it) upload to Jamf, create a policy and the 99% who couldn't install it previously now can.My question is how does that work? Whats happened to the app to allow that to work? Thanks.
Hello, I have an EA which reports back the version of Firefox installed on client machines in JAMF. The question is, what do you do with that once you want to take action (such as updating the version)? JAMF does not allow one to test the version for greater than or less than, only "is/is not" "like/not like" or regex, which is not helpful here that I can tell. The goal here is to get everyone running less than Firefox 108 to be updated, but I'm not seeing how to do that with JAMF—at least not in a straightforward way. I'd appreciate any insight, thanks.
(EDIT: I neglected to note that we're using AAD authentication. This change is to comply with the deprecation of the ADAL and migrate our configs to use MSAL.)Most of our Jamf Connect clients are version 2.6.0. We also have a small group of clients upgraded to version 2.18.0. These clients are using the same configs as the 2.6.0 clients. Everything seems to be working.For testing with the 2.6.0 clients, I cloned the working config profiles, added the TenantID value in the two places it needs to be added, and everything seems good. For the 2.18.0 clients, I did the same thing. The menu bar client seems to be working fine in my limited testing, but when I try to log in with the 2.18.0 client, the "An error occurred. Contact your IT administrator" message pops up, and the web panel seems to spin forever. If I SSH into the test VM and stream the com.jamf.connect.login subprocess logs with the -debug option, this message appears around the same time that the "An error occurred" po
We have JAMF Connect for Office365 but everytime we run a MacOS update it breaks the authchanger and we have to run sudo authchanger -reset -JamfConnect. I was thinking of running a script that runs this every restart but assuming it doesn't run until after the login which won't work. What are others doing for this?
We currently have Activation Lock disabled in PreStage, and users are prevented from logging on to System Preferences with their Apple ID (personal Apple IDs, not MAIDs). However, we have not always had this in place and some users have enabled Find My. Further, for some Macs we are looking to fully decommission them and either sell to a reseller or give to employees (that is, remove from Jamf and ABM). An important note here is that a user isn't necessarily getting their old Mac, so they won't have the Apple ID creds.. So I have some questions on how this works to try to minimize work in either getting these out of Find My or identifying the ones that we can't clear:1. If I wipe via Jamf and clear Activation Lock, does that also remove it from a user's Find My, or is that separate? That is, once that device is no longer in Jamf or my org's ABM and the device is wiped, will the user get either notice that it's in another user's Find My or be activation locked?2. If the device is in a u
Might someone have some insight and clarity on how to deploy Digital Guardian via Jamf.I have a lot of experience with security agents in Jamf: Crowdstrike, FireEye, Tanium, Netskope, but it seems Digital Guardian is a mystery. I have a shell script and I believe the are some Config Profiles to configure. It could be extensive or rather straight forward, but from the version 7 documentation it's not clear at all. And I believe version 8 is for Big Sur 11.6x and Monterey, using SYSEX.... Thanks so much....
Hi All,I did integration between Intune with JAMF pro with could connect. Both sides the connections show as the active state. But mac machines "Machine Azure Active Directory ID" , "User Azure Active Directory ID" and "conditional access inventory state" are empty. I followed below steps and the connections showing as active. may I know any other steps need to be done to get the machine Azure ID in JAMF.?1. created app registration from Azure2. Created conditional access from JAMF ( Global settings -> Conditional Access) 3. Partner device management the connection showing as active
We just rolled out jamf connect to a test environment and we're noticing a few things.If you restart you don't get the jamf connect login window. It wants a user to login with their password. What is the workaround for this? Is there a way to force user log out after a restart or power outage?Also our file vault settings are set to personal (individual), but jamf is not recording the key. It says no key present. Any ideas?I saw a post on jamf Nation saying the only option is to disable file vault on computers running jamf connect. Is this true?
HiHelloI am looking for a solution to the problem of retrieving user information from google cloud.The problem is that I am connected to Cloud Identity Providers -> company name - mapping. I can perform a test and find people from my organization there, there is a full list of data from google cloud - what I need.However when enrolling a laptop where the user has to log in after SSO. Policies are downloading, laptop is configuring but I don't have any information either in user data or in Computer -user and location.What could be wrong here?I tried to wait, wait a long time (more than 24 hours even though I have a checkin for 5 minutes) - I tried sudo jamf recon and nothing.
We had a bunch of devices stop checking-in, seems Jamf process had hung but we are not sure why.I’ve managed to get most up and running by asking user to restart or issuing a self heal via API which reinstall Jamf silently on the Mac, just had to exclude those devices from any enrolment triggers.I’ve still got 30 devices that look active as I can cross check in our IDP to see when the Mac last signed in.Self heals are pending on these Macs I’m guessing not running as also a APNS cert issue(?) and as said no check-in or inventory updates.Any other ways to silently fix, ssh is not an option. I don’t fancy raising 30 tickets internally for our Service Desk to look at.
Hello,We have noticed that several of our M1 MacBook Air are not accepting user password even though it is correct. Now we do have another admin profile that is added during enrollment for password reset. When we try to rest password for that user through other admin profile it says password reset failed. We have tried password reset with terminal same issue occurs. The OS is Monterey on most. This is happening with devices that have been enrolled almost year ago and newly enrolled device. Solution is to wipe it set it up again but we don't want to lose data. Any suggestions ?
I've added "Number of Available updates" to my Computer Inventory display, and noticed every computer lists 0 for SWUS. This is very suspicious and in my experience pretty improbable with over 75 computers. On my own laptop I can see in system preferences:"Updates are available for your mac"macOS 10.14.5 UpdateiTunes Device Support Update After running a sudo jamf recon and policy for good measure, I've confirmed my computer information is up to date in jamf, but still says SWUS = 0. I'm not sure whats going on here, I've never had this problem with past organizations.
nwresolverstartquerytimerblockinvoke[C1] Query fired: did not receive all answers in time for API ADDRESSShows the same error even while using HTTP or HTTPS.Error persists even after updating info.plist with the security settings of the app transport Anything?Arlo login my.arlo.com
Hi all, i'm working on the CIS benchmarks for Monterey and i'm stuck at these points : Ensure Security Auditing Flags For User-Attributable Events Are Configured Per Local Organizational Requirements (Automated) Ensure install.log Is Retained for 365 or More Days and No Maximum Size (Automated) Ensure Security Auditing Retention Is Enabled (Automated) Ensure Access to Audit Records Is Controlled (Automated) Ensure Sealed System Volume (SSV) Is Enabled (Automated) Ensure Appropriate Permissions Are Enabled for System Wide Applications (Automated) Ensure the Sudo Timeout Period Is Set to Zero (Automated) Ensure a Separate Timestamp Is Enabled for Each User/tty Combo (Automated) Ensure the "root" Account Is Disabled (Automated) Alert when the log capacity is over 75% Alert user & admin about audit logging failures Dedicated user to decrypt the hard disk upon startup Shut down the system if audit logging stoppe
Hi,I've been trying to automate my package Management using AutoPKG but I could not find a solution to automate the Patch Management completely. I am using Title Editor for my patch definitions.However, I can not find a solution to automate the creation of new patches on Title Editor and without that the automation of the rest is not nearly as useful as it would be with that part also automated. Can anyone point me in a direction where I can find a solution for this?Also: What is your workflow for patch management? I am fairly new to this and could use some tips.Kind regards
Thanks to @brysontyrrell for all his hard work. Extending the JSS via the API. https://github.com/brysontyrrell/StaticGroupFromSearch
Hi everyone,I've set up a test PreStage Enrollment, where a local admin account is created. In addition to that account, the local user account that gets created during the Setup Assistant, is a standard account (we don't allow our users to be admins). Our FileVault 2 configuration profile is set to be enabled at login, which works fine for the standard user. The first time this user logs out and logs back in, the FV2 is enabled. However, that leaves the admin user, which is still not FV2 enabled. How can we remotely enable FV2 for this user, without the end user having access to the admin user's credentials and logging into that account, just to enable FV2?Thanks!
I'm wondering if there's the ability to apply a Mac's previous name as it is in Jamf, at the time it is reenrolled or as a post-re-enrollment process after it has been wiped and reloaded with a fresh OS. Right now there is the ability to create a policy to run with the “Enrollment Complete” trigger and possess a Maintenance payload with the “Reset Computer Names” checked.Unfortunately though when enrollment completes, before the aforementioned policy has a chance to run, an inventory update is run (a built-in part of the enrollment process) which of course causes the Mac’s existing name in Jamf to be changed and overwritten to the default “iMac” name it automatically gets when installing an OS.By the time the above "Reset Computer Name" policy runs, the Mac’s name in Jamf has already been set to the generic “iMac” due to the forced inventory update at the time of enrollment.We currently name our Macs based on location (building and room number) along with the asset tag
We are trying to find a way to block the Freeform app on iPadOS 16.2 for our K12 District. We normally would use a Restriction Profile using the SafeList and Blocklist Payload but I do not see an option for that app. Does anyone have a script or way to block?
When our Devices are wiped and setup for a new teacher the EDU Profile is not installing, thus Classroom will not show student devices online. I have had the profile installed on the device, but the moment we wipe the device the profile will not reinstall. I have checked the Inventory Profiles / Mangement Configuration Profiles / and Management Groups - Smart and static. I have insured all the profiles are setup the same way. same groups, etc. We are refreshing our teacher fleet of ipads and this is causing issues and making them unusable for classroom.
Is there a way to restrict End Users from viewing Profiles in Ventura?We usually block this on Monterey Macs, however on our test Ventura devices it appears to have been moved to Legacy Disabled Preferences:The only issue we have with people being able to see these is they can add profiles.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!