Get Support
Recently active
Wondering if someone could help me with Patch Management on Jamf Pro on version 10.42.1, Currently I am associating InstallAssistant.pkg's for the version i want to update to in patch management, i.e. installpackage.pkg for 13.1 from MrMacintosh's website and creating a patch policy to have it available in self service or force if not installed within 3 daysBut nothing is happening with either methods it downloads the package and does nothing with it. what would i need to do to make it actually install/update?
We’ve come across an issue with Cisco AnyConnect where the connection option we use (called client_installed_local) appears fine on Intel Macs, but does not appear at all using the same version of AnyConnect on M1 Macs. We’re using AnyConnect 4.10.04071.How our setup should work:User connects to the VPN serverUser is then prompted to choose options for connecting. Client_installed_local is the first option, and what the user will be choosing.This then kicks the user over to Azure MFA authentication.Once authenticated via Azure, the VPN connectsOther facts:The installer package is the webdeploy core vpn package, pulled from the predeploy package. I have been told we don’t need anything else.Our previous versions all used the webdeploy package. There is nothing special about these that I can see.Tested on macOS 12 and 13 on both the M1 and Intel sidesOlder versions ran on everything from 10.14 up to 11 without issue on IntelsHere’s what I’ve tried:Reviewing and implementing a Configurati
Hey guys, The management is thinking to move from Jamf Pro to Intune to manage our Macs, I've never worked with Intune before and would like someone who is using it to tell me about their experience : - Is it really good MDM for managing Macs?- Comparing to Jamf, which one is better?- Any downside of moving from Jamf to Intune?Hope someone can shed some light on these points.Thanks in advance
I've read through a few posts already, stating to compress the pkg as a zip first, then upload to JAMF, but I'm having the same issue. When I try to install the package directly on the machine, it works fine. But if I install it from JAMF via a policy, it errors:The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance.Not sure what else to try at this point. It happens on both Monterey & Ventura.
So I was getting this error constantly on every machine.When I checked the Approved System Extensions, I noticed there was 'Allowed Team Identifiers' for a few Applications, one being Cisco AnyConnect. So I created a new Approved System Extensions policy and removed the 'Allowed Team Identifiers' portion for Cisco AnyConnect. As you can see in the NEW policy, the 'Allowed Team Identifiers' is gone. Question for clarity... I assume if the Team Identifier is already being entered within Allowed System Extension Types, it would be unnecessary to also add Allowed Team Identifiers. That option seems to be for applications that do not need System Extension or System Extension Types. Is this correct? After I removed the Allowed Team Identifiers in the NEW policy, I didn't see anymore errors... So for clarity, is Allowed Team Identifiers necessary, or can I delete that portion without causing any harm?
I have a fleet of Macs that are enrolled in Microsoft Endpoint Manager via the Jamf connector and Company Portal. Upon adding the criteria "Computer Azure Active Directory ID", "User Azure Active Directory ID" and "Conditional Access Inventory State" to Inventory Display, all Macs show their status for each of these criteria as "Not present" from within the Computers > Search Inventory page in Jamf Pro. If we look at the actual Mac inventory record, the attributes are visible with their correct values And again, when viewing the contents of a smart group, the attributes are visible too I would expect these attributes to all be visible from within a computer search from the Computers > Search Inventory page in Jamf Pro. Is anyone else seeing this? Am I missing something?
We have 2 mac devices we want to trial in Jamf Now and wondered if we can use it for free as its under 3 devices but add on the Jamf Connect package ($2 per user per month) so we can use Azure AD logins?I wasnt sure if this was a package for one of the other bundles and wouldnt let you add it to the free package?
Hi all I am using API for the first time ever. The need to use API has crept up as I have discovered that apparently there is now the ability to flush a single policy for a single device by using the API protocols. It was apparently implemented in 9.96 - check it out here. Looking at the JSS REST API Resource Documentation, I have worked out that I can use it to obtain the necessary JSS IDs for a computer and a policy. However looking at the '/commandflush' aspect of the API, I just can't work out how I would get the specific policy for a specific computer to be flushed. Basically what I am after, is the ability to tell (or 'Put' in API language) for the status of a computer ID to be changed to 'Pending' for a particular policy ID. This is my early attempt of creating a bash script to achieve this.... #!/bin/sh jssAPIuser=[input a jss account] jssAPIpassword=[input the password] jssURL=[input your jss url] macName='systemsetup -getcomputername | awk '{print $3}'' policyName=[in
Just trying to run a script on machines that deletes all the garbage entries of printers that JAMF School has put onto systems while trying to manage/add printers in the JAMF Cloud web interface (which is actually a nightmare since there is no real documentation other than "just do this" and nothing is actually validated before it is pushed to systems). Even though I removed the printers in JAMF, the printers still show up as local entries on each machine and I can also do lplist which dumps all the printer entries that were added to CUPS from JAMF. I can also see all the printers in CUPS WebUI.Now, I just want to a simple bash script that is sent to each machine once to fully clear the printers so I can make one more push in JAMF as a clean slate for printers here on out. Scripting Module is enabled and works(already tested).Here are two versions of a simple looping script I have tried to run - both fail:#!/bin/bash lpstat -p | awk '{print $2}' | while read printer
I am trying to add another user to our mac fleet using a script. The script goes through without error and creates a user but no directory folder so when I attempt to log in as the "sub" it just spins and spins. Here is my script....what am I missing?sudo dscl . -create /Users/subsudo dscl . -create /Users/sub UserShell /bin/bashsudo dscl . -create /Users/sub RealName subsudo dscl . -create /Users/sub UniqueID 1000sudo dscl . -create /Users/sub PrimaryGroupID 20sudo dscl . -create /Users/sub NFSHomeDirectory /Users/sub sudo dscl . -passwd /Users/sub becker
This is more of a heads up post… after talking with Apple support today I have found that there is an emerging issue regarding USB-C to lightning cables, MacBooks, and restoring iPads. If you find yourself frustrated, restoring iPads with such a combination…. Two things of note. The workaround is simply to use a USB A to Lightning cable. And the second point of note is to please call AppleCare. My case number on the issue is 101888762488. Please let them know if you are impacted because we need them to get this fixed as soon as possible. Hopefully this helps someone not spend a bunch of time troubleshooting their Mac, trying replacement Macs and different USB C to lightning cables.
Sending the Enable Lost Mode, Lock Device, Wipe Device or Unmanage Device commands do no good if the mobile device is not checking in with Jamf. Until it checks in (which may be never), it continues to use a Jamf license. I don't see a way to release the Jamf license without deleting the record from Jamf, which I'd rather not do (as then we no longer have a record of the device). Or am I missing something?
Hi, Our schools are purchasing a huge amountof iPads end of the year with the purpose in mind to lend them to students fulltime, until the yare leaving. One of the few restrictions we are bound to set (via law) is a content filter per DNS. Since they can take the iPads home with them they are not bound to the school wifi and we would need to set a global DNS entry. Is there a way to set the DNS globally? I've seen workarounds with scripts, but is this possible on iOS?
Hi,I'm testing MDM commands to force software updates (12.6.x to 12.6.2) It's worked well, but it seems that if you click on the countdown timer for the reboot, it stops the computer from rebooting. Does it stop it indefinitely? Will it install the update on the next reboot? And if not, do you send the command again? I'm only asking because I have a limited number of computers I'm able to test on and I'm just trying to work out the kinks before having to actually do this in the wild. TIA
getting the 503 service unavailable while calling the API after getting the token successfully.
Is anybody here still running their JAMF pro instances on-prem? Our management is very anti moving things to the cloud.I am a super new Sys-admin for our Mac stuff and management has tasked me with researching what to replace our current hardware relating to our JAMF pro environment. I am having trouble finding super good data of how much hardware/specs we actually need to support what we have with some extra headroom.Management likes the idea of going VM for most of our JAMF stuff, but JAMF support seems is a little wishy-washy on if that's a good idea. I think they are really trying to push the cloud service (which I get). We're also running things mostly in Linux right now, but management has discussed going to Windows Server whenever we get new hardware.If any of you guys are still running JAMF pro on-prem, do you have any insight on how you have things structured, what hardware you are running, and how well it seems to run? Also you guys use any 3rd party applications to monitor y
Hey there, Does anyone have any experience with installing Adobe apps like Fresco, Reader, Photoshop, etc to a mobile device (iPad Pro)? I'm able to install other apps by adding them through VPP and scoping my device to them but with Adobe apps it doesn't work. The apps show up under Mobile Device Apps and it shows the license is used but they never show up on the device. I know that when installing on a computer they need to be packaged together but I'm not sure how it works with mobile apps.
Looked at dsconfigad hoping it would point upward to dsconfig.Looked at dscl which I think just lists them in alphabetical order.Looked at odutil which seems to only list connections and statistics. Any help appreciated.
I'm been running the script with success as long as the end user doesn't restart their mac before hand. I have a test mac on 12.3 and I deployed 12.6.2 via the script. I see in the logs that it selected 12.6.2, but the in the morning when I checked, the mac updated to 12.5.1. My question is, if the mac is older then a certain version, will it just update to the next big update regardless of selecting 12.6.2?
Hello, we have a local admin account for troubleshooting purposes on our macOS systems. We're seeing that we can login to a small percentage of some of them. No error message, just the password field shake. These accounts are not setup manually, so we're fairly certain that the password is correct. Logged in from another user, we can run "dscl . authonly <USER>" and then enter the password for the account when prompted. If we enter a purposefully incorrect password we get:Authentication for node /Local/Default failed. (-14090, eDSAuthFailed)<dscl_cmd> DS Error: -14090 (eDSAuthFailed) If we enter the correct password we get:Authentication for node /Local/Default failed. (-14167, eDSAuthAccountDisabled)<dscl_cmd> DS Error: -14167 (eDSAuthAccountDisabled) So from here it sounds like the account was disabled somehow. But if we run:dscl . -read /Users/<USER> AuthenticationAuthority | grep DisabledUser it doesn't have it flagged as Di
Has anyone seen a situation where the Jamf Pro UI won't accept adding a computer or group to the scope of a policy or profile right away? It usually takes multiple tries before it is finally added to the scope. Here's a screen recording demonstrating the issue:https://drive.google.com/file/d/1n3y9p5Po9BqT29bsVnh0fpZbwI4uJUFK/view?usp=sharingIt's fairly intermittent, i.e. one day it will work straightaway, but on most other occasions it will take multiple attempts. I've also seen similar behaviour when trying to add a package to a patch policy under Patch Management.This smells like a PI or if not, something specific to our DB. We run Jamf Pro v10.41.0 on a Windows Server 2019 VM.
When enrolling iOS devices using user initiated enrollment (sent via SMS), I had both options in settings checked (institutional and personal), per documentation this should prompt the user to pick one. This is important for us and it shows that it is supported by the docs. However, I was not being prompted and the device always showed institutional after enrollment in the device record. To test, I removed the device record, unchecked institutional and left personal as the only user initiated enrollment option. Re-sent the invitation. When I tapped the link, I get ACCESS DENIED. I sent all invitations without requiring a login, so I tried it with requiring a login. Same issue. Am I missing something? I've been through every setting and I can't see what would cause this?
In Jamf school, our iPads are set up as Shared iPads. We would love to see the students already be signed in to Teams, OneDrive,... no matter which iPad they grab. Is this possible?Is this possible in temporary guest mode? regards
Hello, I'm using DUTI to set default pdf reader as adobe instead of preview in all users and works great locally and admin accounts but for regular accounts with no sudo privileges it does not apply. Anyone know a fix? Here is my current script
I've following the instructions from the documentation to create a OS Ventura installer to test out manual OS Upgrades for our organization. I'm having issues with the command execution. The packager installs correctly and can be found in the /private/var folder, I can even go in and start the install from there. But I'm struggling with the command to get it to install. I've tried: /private/var/Install\\macOS\\Ventura.app/Contents/Resources/startosinstall --agreetolicense. This yield a result of: No such file or directory. This was how one of Jamf's training video said to do it and I followed the instructions exactly.I've also tried /private/var/Install macOS Ventura.app/Contents/Resources/startosinstall --agreetolicenseand the result of the command is: is a directory. I'm very inexperiences with the command line so any help is appreciated.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!