Get Support
Recently active
Hey, new to Jamf and Configurator, been working though it through trial and error and all has been well for the most partI recently set some iPads up for forcing a passcode to be used but all of a sudden after a day or so, all of the iPads this was pushed through were no longer reconnecting automatically to the wifi I setup a payload config profile for? Wifi was turned on, however nothing was showing in the listed networks... and since it wasn't joined to wifi, I couldn't do anything via JamfIs this a common issue and is there an easy resolution other than (what I assume is the only way to remedy this) not forcing an auto-join to a particular network?
Unsure if you will find this handy. I wanted to find a way to quit all Adobe processes and delete all adobe files. Made this script which seems to do the trick! #!/bin/bash ##kills all adobe processes pkill -f Adobe pkill -f adobe ##Removes all Adobe applications and files rm -rf /Applications/Adobe* /Applications/Utilities/Adobe* /Library/Application\\ Support/Adobe /Library/Preferences/com.adobe.* /Library/PrivilegedHelperTools/com.adobe.* /private/var/db/receipts/com.adobe.* ~/Library/Application\\ Support/Adobe* ~/Library/Application\\ Support/com.apple.sharedfilelist/com.apple.LSSharedFileList.ApplicationRecentDocuments/com.adobe* ~/Library/Application\\ Support/CrashReporter/Adobe* ~/Library/Caches/Adobe ~/Library/Caches/com.Adobe.* ~/Library/Caches/com.adobe.* ~/Library/Cookies/com.adobe.* ~/Library/Logs/Adobe* ~/Library/PhotoshopCrashes ~/Library/Preferences/Adobe* ~/Library/Preferences/com.adobe.* ~/Library/Preferences/Macromedia* ~/Library/Saved\\ Application\\ State/c
Hello all,Just wanted to know if anyone here has taken the Jamf 100 certification exam. I've been studying for about 3 weeks and wanted to know anyone's experience taking the exam in the past.Also I would like to know how accurate is the practice exam compared to the actual exam.
I took the great work that had already been done here: https://github.com/shbedev/jamf-recovery-lock and expanded on it to create an single file comand-line script that will allow you to supply a search parameter and it will return all Apple Silicon computers in your Jamf instance with names that match your search parameter. It has options for clearing or setting the Recovery Lock passcode, and you can specify the passcode to use or have it generate a random number.Here's the link to it:https://github.com/jcmbowman/jamf-scripts/blob/main/SetRecoveryLockJAMF.pyBefore you use it you'll need to edit the script to supply your Jamf url and a username and password that has access in Jamf to make api calls that can change the recovery lock. Since you're hardcoding your credentials into the script make sure to store the script in a secure location. This script is only for administrator use and should never be deployed to end-user computers. You will need Python3 installed, and a
Hi,Asset IT teams would like to receive a notification once a device is enrolled in Jamf.Required infos: User IDDevice Asset TagDevice S/NAny idea how to satisfy this request ?1) How to auto-populate an online Sharepoint sheet?2) Can we export to excel sheet and on a shared smb ?3) Can an API used to fulfil a web tool ?4) ....Any other trick is welcomeNote: Create and email an inventory report was not approved.
All,our internal auditor asked me to give her access to Jamf Protect. She already has acces to Jamf Pro, using the Jamf ID created for her. I set her rights to be able to use Jamf Protect there as well.I setup the account for her on Jamf Protect, with the identifier Jamf ID, but somehow she is not able to login. Username and/or password is incorrect. Funny thing is that we tried resetting the psw, using the supplied link, but that mail never arrives. And yes, her mail-address is correct en its not stuck in a junk-filter.Any thoughts?
I can't seem to find the answer to this on my own. If I set a deferral type of Date and set a date a month in the future, how do clients handle that policy when no user is logged in? Does the policy just run, or does it wait for a user to be logged in so they have the option to defer?
Hello,I have an issue linking JAMF API to Azure to automate reports sharing.API URL can be linked to MS Power Automate but stopped to a DLP strategy. How to convert the Jamf API to Microsoft API so it can be linked to Azure app ?Thanks,
After 2 full days of tinkering around with Jamf Connect, I successfully got it all working for our fleet of machines. I currently have a question: I wondered if it is possible to launch a browser window during the enrollment process. I ask this as since the MacBooks are utilizing Okta as an IdP for logging into Jamf Connect. The initial login would technically fail as the new user doesn't have a way to set his/her password until they are in the machine. Of course, they could do this on their laptop, but I would like to move from utilizing personal devices for Onboarding new employees. Launching a Browser window during enrollment would alleviate the issue of having Okta credentials synchronized which would be helpful when making the first login for the machine.
Hi there,We've recently migrated from Meraki to Jamf Pro using the jamf migration tools. Issue we're seeing is that for devices that are moved they exist in an unsupervised state and therefore we cannot do anything with the activation lock. i.e when we wipe devices and they trigger activation lock, we would have to contact apple and wait 2 weeks to get the activation lock removed.Our users use MAIDs which cannot release devices from activation lock and activation lock does not prompt local account credentials to release devices. If anyone has dealt with this issue what is the best practice in dealing with these devices or process to get around it?
Hey,I'm trying to find some way to suppress the autodiscover redirect popup. (YES I have search the forum here and tried the suggestions)We have an Exchange 2016 on prem hybrid solution.Autodiscover URL runs a split DNS. One points to an internal load balancer and the other points to an external reverse proxy load balancer, that points to the internal exchange servers.Our clients runs the latest version of Outlook 16.67 (O365 licensing), both on Monterey & Ventura.I have a configuration profile through Jamf with the TrustO365AutodiscoverRedirect key set to true with no luck. Have also tried with SuppressO365AutodiscoverOverride, same result as before. The popup appears again for those users who have nog pressed "always use my response for this server..."
A Big Hello to All,I have a very annoying issue with Self Service not deploying Patch Management apps. eg Zoom, Google Chrome, Microsoft office apps, Firefox etcI am running MacOS Ventura 13.0.1 across my fleet of Mac's and running JAMF Pro 10.42.1-t1667311080This happens very randomly and the Jamf.log does not have a lot of information...All of my Patch Management apps are PKG files.What happens is when a user opens up Self Service and clicks on Notifications and attempts to install an update the wheel spins and spins away.And the update is not installed.....It does not matter if the Mac is on a Corporate Ethernet network or a VPN (I am using Palo Alto Global Protect) or even a 4G internet connection.The only way I have been able to fix the issue is delete the Mac from JAMF, Azure and Active Directory and reload MacOS and log the user back onThis is a drastic solution but my only one at this time....I would be most grateful for any help!
Okay all. I searched through the community forums and saw some very helpful information but it also added more questions. I figured I'd make another post and detail everything out. Any help would be appreciated. Goal: Move around 280 MacOS devices from Intune to Jamf with as little interruption to the end user as possible.I know one of the first things that will need done is un-enrolling from Intune but this is where I start to get confused on best practice. I am new to both Jamf and Intune but one thing I understood from my previous company is that the check-in time for Intune could take as long as 24 hours. I also see how the MDM profiles are not removable by the end user for our Intune managed devices. While i totally understand why this needs done this leads me to my first question.What is the best way to allow for User-Initiated enrollment so that there can be a seamless transition from Intune to Jamf?If I am understanding what
I've noticed this on several units, an iMac, some MacMinis, and my MacBook Pro, half are on Monterey, and the others on Big Sur, all have a version of the M1 Chip, this also happens across accounts, both Admin and Standard. When the system is restarted OR on a Logout/Login several of the settings reset to the defaults. The ones I've specifically noticed are as follows. Mouse ScrollLight/Dark ModeLanguage Settings*There may be others but these are the settings I've personally confirmed between my own settings as well as what my impacted users have told me.Just wondering if anyone else has seen this.
Hi, since iOS 13.4 there is the option to log in as a guest user. We don't want our users to log in as guests.Is there a way to disable this option? We haven't found anything in the PreStage Enrollments or Configuration Profiles.
Hello all,I'm having seeing some weird issues with Adobe Remote Update Manager, which I use via policy to patch our Adobe Creative Cloud apps. For some reason, I have applications that will no longer update to their latest minor versions of Creative Cloud 2021. This includes my own personal workstation which has the Adobe suite installed. We haven't deployed CC 2022 apps yet, so this post is specific to continuing to patch CC 2021 apps. In any event, here's my scenario:Intel Macs (mostly iMacs)macOS Big Sur 11.6.1, and macOS Catalina 10.15.7Adobe Creative Cloud app version 5.6.0.788 (which seems to be the latest according to posted documentation)Adobe Remote Update Manager (/usr/local/bin/RemoteUpdateManager) version 2.6.0.9 (also seems to be the latest version)I've run the RemoteUpdateManager app via script, policy, logged in with Terminal, etc, and getting the same results. There are no errors returned when RUM is run. In addition, this is hap
I'm looking to distribute Apple Books and Audio Books to both one-to-one iPads and Shared iPads on Jamf School.We currently restrict most iPads and don't allow sign in to Apple Store. It looks like you need this. That's fine.I am able to deploy books to devices and make a user an owner of an iPad in order to deploy that content to the device.For Shared iPads I get the error: A volume purchasing license cannot be assigned because the device is not assigned to a user. I am not able to distribute content for Shared iPads.Also I am somewhat confused because I thought Apple Books and Audio Books needed to be assign to a user and it looks like the only option I have is to assign it to a Device Group.Does anyone know what to do about this?
Does anyone one have any learning resources for Jamf Pro, we recently got Jamf pro off the back off our parent company so we didn't get the whole integration thing or the mandatory training process, I managed to get a server up and running but now not sure how to configure certain things, so would like to find some self study material.
Wondering if there is any way to enable the Software Updates --> Automatic Updates switch on the iPads in our K-12 school district. We already defer updates by 45 days, but some of the devices fall WAY behind (some are still iOS 12) and it's hard to try to enforce updates on the devices whenA) kids have them at homeand B) kids don't want to update or don't know how to I try to force out Update / Restart via the Action command to all devices in a smart group from time to time, but for some reason we only get about 60% completion and the others will just continue to check in but never update themselves. Is this something that we can enable via configuration profile somewhere, or maybe a feature coming down the pipeline that I'm unaware of?
Hello, Jamf Nation! Today we released Jamf Protect 3.6.0, which includes two significant security capabilities: Telemetry log data and Jamf Protect Offline Mode Telemetry Log Data Telemetry log data is a new feature that sends device activity feeds to one or more security information and event management (SIEM) solutions in your environment. This helps you and your information security team proactively monitor and detect threats on macOS computers. Tiered Upgrade Schedule: Telemetry in the Jamf Protect web app will be made available based on a tiered upgrade schedule. Your tenant will be upgraded between December 12, 2022 and December 16, 2022. Introducing Offline Mode Jamf Protect's Offline Mode is a stand-alone implementation of Jamf Protect specifically for customers whose environments are restricted from accessing the Jamf Protect Cloud or any other Jamf Cloud environments. For licensing information, contact your Jamf Customer Su
I just released a project that I've been working on for a while, and mentioned during my JNUC API talk, that utilizes the JSS API to automatically merge changes that are made to git repositories. Effectively version controlling aspects of the JSS. I have included two git hooks, one to manage Extension Attribute objects and another to manage Script objects. I hope the JAMFNation community finds this useful. It requires JSS 9.62 due to required API calls. UPDATE:Unfortunatley, I was asked to pull down this repository for internal reasons. And, shortly thereafter, I transitioned onto a different team and no longer work with the JAMF toolset. I had hoped that my old team would have been able to Open Source this in my absence, but it doesn't appear like they have been able to, and I'm not at liberty to do so at this time. My apologies to everyone still looking for this. I know there's a few copies floating around prior to me having to pull it down, and it was released
How is everyone handling Patch Management for Apps that have two different packages for Intel and Apple Silicon? Example: Today there was an update for VLC but there are two different downloads for it, one is for Intel Macs the other for M1 & M2 chips, but Patch Management only allows 1 instance from the catalog to be added and only 1 package per version to be mapped.
HiI just discovered that i have a lot of macs with the red marks on jamf protect. This means that they did not connect to jamf protect since one month. This is strange because those computers regularly check in with jamf pro and jamf protect is pushed automatically from jamf pro.What can be the problem and how can i solve it?
I am trying to achieve the following steps. But unable to do so : 1.Launch Installer2.Place pipeline.json to the location in/Users/Shared/TheAPP3.Click Install button on Installer UI (/usr/local/theapp/macOS/installer)
Easily clear your users’ policy-specific deferrals when using Installomator with Jamf ProBackgroundSince fully embracing Installomator v10.0, which includes support for swiftDialog, we’ve been testing Mischa van der Bent’s approach to leveraging Jamf Patch Management Software Titles for versioning information, which, on the whole, seems to be working quite well.However, allowing users to defer Jamf Pro policies introduces its own set of challenges.Continue reading …
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!