Get Support
Recently active
I have a test macbook that was enrolled into JAMF. I reimaged it via macOS Recovery, which installed a fresh new OS for Ventura. I thought maybe this was a Ventura issue, so I rolled back the OS to an earlier version (Big Sur) and the same issue occurs. I get this error: " An error occurred. Contact your IT Administrator " Note: For clarity, the MacBook installs any macOS just fine, and seems to gather the enrollment profiles/policies from JAMF, but upon first boot (when the user should enter their SSO credentials), it gives this screen.
So I worked a couple of years back with DEPNotify and it was working great for our purpose.Does it still work great? Would like to have it start after a user completes enrollment via Apple Business Manager into Jamf Pro.I read some conflicting experiences if DEPNotify still works with the enrollment complete trigger used by Jamf Pro.Anybody?
is there any script and setting in Jamf pro that I can configure all endpoints and users for getting automatic backup on their google drive space for specific folders like Documents etc...
Hello,We have been having lot of iPads in our school district getting an error in self service that states " Error loading Content". We updated configuration for self service, updated self service and removed self service and added it back. Removing SS and adding it back does resolve the issue, but I am looking for a permanent fix. Thank you !
Hey there,I have the problem that notifications in Self Service (new version of an app available) reappear after a computer restart - how can I prevent this from happening? I have already deleted the messages in Self Service, but they still reappear after a computer restart. WWhat can I do to stop these batch notifications from appearing?What can I do to stop these batch notifications from appearing? The tips found here with terminal commands, for example, did not work.Thank you!
Is it possible to disable a specific app on a Macbook? For example the app store?
So we have Installomator setup to install Office 365 to all devices. This seems to work without a hitch on newly enrolled M1 and M2 devices, however always fails when installing on an older Mac. After checking the logs I saw the error where it couldn't connect to https://go.microsoft.com/fwlink/?linkid=525133. I decided to manually navigate to the site on the device to see what happens and when i do, I get prompted to allow download on "officecdnmac.microsoft.com" with the option for me to allow. I choose Allow on the device, manually delete the pkg once it downloads, refresh Self Service and the script ends up working fine. Does anyone know a way around this? Is there a way i can automatically allow downloads?
Hello,I am looking for a way to update all of my current users name field in Jamf Pro to their full name.Currently we have our LDAP setup between OKTA, jamf connect, and Jamf Pro. So when a user takes their device out of the box, they have to sign in with their OKTA credentials and Jamf sets the device up for them. Their full name, username(email address), and email address come over to Jamf Pro correctly. But the (computer?) name field comes over to Jamf Pro as Macbook Air. Link to screenshot of what I am looking at https://imgur.com/a/MyT8BSKIs there a way to update this field to be their full name? And a way for future users to have it be their full name too? I assume you could script it somehow, but I am a scripting noob.Thank you for assistance.
I've got a weird one. Our company is implementing a policy that your account will become disabled after five login attempts. Our instance of Jamf Pro seems to submit two login attempts to our Active Directory domain when a user attempts to log in to it which therefore only gives the user three attempts to authenticate before their account gets locked in Active Directory instead of five. I haven't seen anyone else with this issue online. We previously had both of our domain controllers listed as LDAP servers in our instance of Jamf Pro but recently consolidated them in Jamf Pro to our single reachable domain. I would've thought that this would've fixed the issue since the login should only be attempted once per listed LDAP server, but nonetheless Jamf Pro is causing my account to be locked after three login attempts instead of the normal five. We also attempted to use Single Sign-On for awhile, but ran into unrelated issues with that and disabled it shortly thereafter. Does anyone have
Hi EveryoneI'm very new to the coding side of MacOs and currently need to create a LaunchAgent for our printer costing app. The app itself is just a normal app that can be manually launched from launchpad or set to auto launch per user, however I need to make sure it runs on every single log in inside our labs. Can someone give me some pointers or help in creating the plist file? I literally just need it to launch "/Applications/Monitor Popup.app" when someone logs in.Thanks
Hey Folks,I’ve had multiple conversations with both Jamf and Apple about their recommendations here, but neither have been able to give a definitive answer:We’re migrating iOS devices from Intune to Jamf, one-at-a-time as people come up for refresh.- All devices are DEP. We have “light touch” management: our company doesn’t push apps/data to devices that we’re concerned about, and users are technically able to remove Intune from their devices.- We are not moving existing devices to Jamf (only brand new or wiped devices)- We’re concerned with this being as seamless as possible for our users and getting their purchased apps and personal content positioned as they would expect.Our initial plan, that we now know won’t work (because the backup retains the device's Intune Enrollment): Intune Phone -> iCloud Backup -> Restore to brand-new iPhone -> Enroll in Jamf Initial tests indicate that Option 1 (below) does work, that Jamf correctly interacts with the device, an
I'd like to be able to add the iPads serial number or asset tag to the wallpaper as a standard barcode, instead of a QR code, so it can be easily scanned during a stocktake.Is this possible, or would we need to get QR capable scanners instead?
I have deployed Jamf Safe Internet to my macOS and when I click to see how many devices there is, it doesn't say the name on the device or the user. Is there something I need to do so I can see who is trying to access certain websites?
Hello community,thank you all for your engagement and the time, you spent here to help me and others. I wish you all a Merry Christmas with your families and a happy, carefree 2023. This will be my last post so far, because we have decided to use a different MDM System and discontinued Jamf.Best regardsMichael Maier, aka NOVELLUS
Trying to get Jamf Pro AD CS Connector working... keep seeing these the Jamf Pro logs. Does anyone know where problem is?2022-12-17 04:23:20,017 [ERROR] [na-exec-122] [dmControllerProcessorImpl] - Could not create MDMResponseAction, returning 5002022-12-17 04:27:58,303 [INFO ] [eralPool-11] [tionPointInventoryUpdater] - Updating inventory files2022-12-17 04:55:48,943 [INFO ] [duledPool-0] [PendoEventPublisher ] - Failed to send Jamf Engage API Track Event to Pendo. For more info, turn on debug logs.2022-12-17 05:01:01,016 [INFO ] [duledPool-9] [rentProfileCleanupMonitor] - Running parent profile cleanup.2022-12-17 05:23:22,640 [INFO ] [duledPool-2] [PendoEventPublisher ] - Failed to send Jamf Engage API Track Event to Pendo. For more info, turn on debug logs.2022-12-17 05:27:00,385 [WARN ] [na-exec-132] [Credentials ] - We don't want to return an X509 Cert from a PKCS12 data blob2022-12-17 05:27:00,431 [WARN ] [na-exec-132] [Credentials ] - We don't want to return an X509 Cert fr
I have found a number of older discussions asking for a way to allow non-admins the ability to manage individual system preferences but I'm not having luck on utilizing them on 10.13 (did not try all recent macOS major releases). Hoping to find something that can apply to machines running macOS 10.10-10.13. Does anyone have a up-to-date script or configuration profile to all non-admin users (not sure if it matters but they are also AD mobile users) to control Network System Preferences? Specifically hoping to allow non-admin users to be able to remove remembered networks. When trying this process I get an error: bash: /tmp/system.preferences.plist: Permission denied
We have Jamf configured on 99% of Macs so Gatekeeper will only allow apps from "App Store" and "App Store and identified developers".When we get an app from an unidentified developer and it's not signed we install it in the applications folder on a Mac that has Gatekeeper set to allow apps from "Anywhere" (the 1%). Click it to open, gatekeeper asks if we want to allow it and we click yes.Once installed we then make a pkg of that app, (we don't sign it) upload to Jamf, create a policy and the 99% who couldn't install it previously now can.My question is how does that work? Whats happened to the app to allow that to work? Thanks.
Hello, I have an EA which reports back the version of Firefox installed on client machines in JAMF. The question is, what do you do with that once you want to take action (such as updating the version)? JAMF does not allow one to test the version for greater than or less than, only "is/is not" "like/not like" or regex, which is not helpful here that I can tell. The goal here is to get everyone running less than Firefox 108 to be updated, but I'm not seeing how to do that with JAMF—at least not in a straightforward way. I'd appreciate any insight, thanks.
(EDIT: I neglected to note that we're using AAD authentication. This change is to comply with the deprecation of the ADAL and migrate our configs to use MSAL.)Most of our Jamf Connect clients are version 2.6.0. We also have a small group of clients upgraded to version 2.18.0. These clients are using the same configs as the 2.6.0 clients. Everything seems to be working.For testing with the 2.6.0 clients, I cloned the working config profiles, added the TenantID value in the two places it needs to be added, and everything seems good. For the 2.18.0 clients, I did the same thing. The menu bar client seems to be working fine in my limited testing, but when I try to log in with the 2.18.0 client, the "An error occurred. Contact your IT administrator" message pops up, and the web panel seems to spin forever. If I SSH into the test VM and stream the com.jamf.connect.login subprocess logs with the -debug option, this message appears around the same time that the "An error occurred" po
We have JAMF Connect for Office365 but everytime we run a MacOS update it breaks the authchanger and we have to run sudo authchanger -reset -JamfConnect. I was thinking of running a script that runs this every restart but assuming it doesn't run until after the login which won't work. What are others doing for this?
We currently have Activation Lock disabled in PreStage, and users are prevented from logging on to System Preferences with their Apple ID (personal Apple IDs, not MAIDs). However, we have not always had this in place and some users have enabled Find My. Further, for some Macs we are looking to fully decommission them and either sell to a reseller or give to employees (that is, remove from Jamf and ABM). An important note here is that a user isn't necessarily getting their old Mac, so they won't have the Apple ID creds.. So I have some questions on how this works to try to minimize work in either getting these out of Find My or identifying the ones that we can't clear:1. If I wipe via Jamf and clear Activation Lock, does that also remove it from a user's Find My, or is that separate? That is, once that device is no longer in Jamf or my org's ABM and the device is wiped, will the user get either notice that it's in another user's Find My or be activation locked?2. If the device is in a u
Might someone have some insight and clarity on how to deploy Digital Guardian via Jamf.I have a lot of experience with security agents in Jamf: Crowdstrike, FireEye, Tanium, Netskope, but it seems Digital Guardian is a mystery. I have a shell script and I believe the are some Config Profiles to configure. It could be extensive or rather straight forward, but from the version 7 documentation it's not clear at all. And I believe version 8 is for Big Sur 11.6x and Monterey, using SYSEX.... Thanks so much....
Hi All,I did integration between Intune with JAMF pro with could connect. Both sides the connections show as the active state. But mac machines "Machine Azure Active Directory ID" , "User Azure Active Directory ID" and "conditional access inventory state" are empty. I followed below steps and the connections showing as active. may I know any other steps need to be done to get the machine Azure ID in JAMF.?1. created app registration from Azure2. Created conditional access from JAMF ( Global settings -> Conditional Access) 3. Partner device management the connection showing as active
We just rolled out jamf connect to a test environment and we're noticing a few things.If you restart you don't get the jamf connect login window. It wants a user to login with their password. What is the workaround for this? Is there a way to force user log out after a restart or power outage?Also our file vault settings are set to personal (individual), but jamf is not recording the key. It says no key present. Any ideas?I saw a post on jamf Nation saying the only option is to disable file vault on computers running jamf connect. Is this true?
HiHelloI am looking for a solution to the problem of retrieving user information from google cloud.The problem is that I am connected to Cloud Identity Providers -> company name - mapping. I can perform a test and find people from my organization there, there is a full list of data from google cloud - what I need.However when enrolling a laptop where the user has to log in after SSO. Policies are downloading, laptop is configuring but I don't have any information either in user data or in Computer -user and location.What could be wrong here?I tried to wait, wait a long time (more than 24 hours even though I have a checkin for 5 minutes) - I tried sudo jamf recon and nothing.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!