Get Support
Recently active
We had a bunch of devices stop checking-in, seems Jamf process had hung but we are not sure why.I’ve managed to get most up and running by asking user to restart or issuing a self heal via API which reinstall Jamf silently on the Mac, just had to exclude those devices from any enrolment triggers.I’ve still got 30 devices that look active as I can cross check in our IDP to see when the Mac last signed in.Self heals are pending on these Macs I’m guessing not running as also a APNS cert issue(?) and as said no check-in or inventory updates.Any other ways to silently fix, ssh is not an option. I don’t fancy raising 30 tickets internally for our Service Desk to look at.
Hello,We have noticed that several of our M1 MacBook Air are not accepting user password even though it is correct. Now we do have another admin profile that is added during enrollment for password reset. When we try to rest password for that user through other admin profile it says password reset failed. We have tried password reset with terminal same issue occurs. The OS is Monterey on most. This is happening with devices that have been enrolled almost year ago and newly enrolled device. Solution is to wipe it set it up again but we don't want to lose data. Any suggestions ?
I've added "Number of Available updates" to my Computer Inventory display, and noticed every computer lists 0 for SWUS. This is very suspicious and in my experience pretty improbable with over 75 computers. On my own laptop I can see in system preferences:"Updates are available for your mac"macOS 10.14.5 UpdateiTunes Device Support Update After running a sudo jamf recon and policy for good measure, I've confirmed my computer information is up to date in jamf, but still says SWUS = 0. I'm not sure whats going on here, I've never had this problem with past organizations.
nwresolverstartquerytimerblockinvoke[C1] Query fired: did not receive all answers in time for API ADDRESSShows the same error even while using HTTP or HTTPS.Error persists even after updating info.plist with the security settings of the app transport Anything?Arlo login my.arlo.com
Hi all, i'm working on the CIS benchmarks for Monterey and i'm stuck at these points : Ensure Security Auditing Flags For User-Attributable Events Are Configured Per Local Organizational Requirements (Automated) Ensure install.log Is Retained for 365 or More Days and No Maximum Size (Automated) Ensure Security Auditing Retention Is Enabled (Automated) Ensure Access to Audit Records Is Controlled (Automated) Ensure Sealed System Volume (SSV) Is Enabled (Automated) Ensure Appropriate Permissions Are Enabled for System Wide Applications (Automated) Ensure the Sudo Timeout Period Is Set to Zero (Automated) Ensure a Separate Timestamp Is Enabled for Each User/tty Combo (Automated) Ensure the "root" Account Is Disabled (Automated) Alert when the log capacity is over 75% Alert user & admin about audit logging failures Dedicated user to decrypt the hard disk upon startup Shut down the system if audit logging stoppe
Hi,I've been trying to automate my package Management using AutoPKG but I could not find a solution to automate the Patch Management completely. I am using Title Editor for my patch definitions.However, I can not find a solution to automate the creation of new patches on Title Editor and without that the automation of the rest is not nearly as useful as it would be with that part also automated. Can anyone point me in a direction where I can find a solution for this?Also: What is your workflow for patch management? I am fairly new to this and could use some tips.Kind regards
Thanks to @brysontyrrell for all his hard work. Extending the JSS via the API. https://github.com/brysontyrrell/StaticGroupFromSearch
Hi everyone,I've set up a test PreStage Enrollment, where a local admin account is created. In addition to that account, the local user account that gets created during the Setup Assistant, is a standard account (we don't allow our users to be admins). Our FileVault 2 configuration profile is set to be enabled at login, which works fine for the standard user. The first time this user logs out and logs back in, the FV2 is enabled. However, that leaves the admin user, which is still not FV2 enabled. How can we remotely enable FV2 for this user, without the end user having access to the admin user's credentials and logging into that account, just to enable FV2?Thanks!
I'm wondering if there's the ability to apply a Mac's previous name as it is in Jamf, at the time it is reenrolled or as a post-re-enrollment process after it has been wiped and reloaded with a fresh OS. Right now there is the ability to create a policy to run with the “Enrollment Complete” trigger and possess a Maintenance payload with the “Reset Computer Names” checked.Unfortunately though when enrollment completes, before the aforementioned policy has a chance to run, an inventory update is run (a built-in part of the enrollment process) which of course causes the Mac’s existing name in Jamf to be changed and overwritten to the default “iMac” name it automatically gets when installing an OS.By the time the above "Reset Computer Name" policy runs, the Mac’s name in Jamf has already been set to the generic “iMac” due to the forced inventory update at the time of enrollment.We currently name our Macs based on location (building and room number) along with the asset tag
We are trying to find a way to block the Freeform app on iPadOS 16.2 for our K12 District. We normally would use a Restriction Profile using the SafeList and Blocklist Payload but I do not see an option for that app. Does anyone have a script or way to block?
When our Devices are wiped and setup for a new teacher the EDU Profile is not installing, thus Classroom will not show student devices online. I have had the profile installed on the device, but the moment we wipe the device the profile will not reinstall. I have checked the Inventory Profiles / Mangement Configuration Profiles / and Management Groups - Smart and static. I have insured all the profiles are setup the same way. same groups, etc. We are refreshing our teacher fleet of ipads and this is causing issues and making them unusable for classroom.
Is there a way to restrict End Users from viewing Profiles in Ventura?We usually block this on Monterey Macs, however on our test Ventura devices it appears to have been moved to Legacy Disabled Preferences:The only issue we have with people being able to see these is they can add profiles.
Wondering if someone could help me with Patch Management on Jamf Pro on version 10.42.1, Currently I am associating InstallAssistant.pkg's for the version i want to update to in patch management, i.e. installpackage.pkg for 13.1 from MrMacintosh's website and creating a patch policy to have it available in self service or force if not installed within 3 daysBut nothing is happening with either methods it downloads the package and does nothing with it. what would i need to do to make it actually install/update?
We’ve come across an issue with Cisco AnyConnect where the connection option we use (called client_installed_local) appears fine on Intel Macs, but does not appear at all using the same version of AnyConnect on M1 Macs. We’re using AnyConnect 4.10.04071.How our setup should work:User connects to the VPN serverUser is then prompted to choose options for connecting. Client_installed_local is the first option, and what the user will be choosing.This then kicks the user over to Azure MFA authentication.Once authenticated via Azure, the VPN connectsOther facts:The installer package is the webdeploy core vpn package, pulled from the predeploy package. I have been told we don’t need anything else.Our previous versions all used the webdeploy package. There is nothing special about these that I can see.Tested on macOS 12 and 13 on both the M1 and Intel sidesOlder versions ran on everything from 10.14 up to 11 without issue on IntelsHere’s what I’ve tried:Reviewing and implementing a Configurati
Hey guys, The management is thinking to move from Jamf Pro to Intune to manage our Macs, I've never worked with Intune before and would like someone who is using it to tell me about their experience : - Is it really good MDM for managing Macs?- Comparing to Jamf, which one is better?- Any downside of moving from Jamf to Intune?Hope someone can shed some light on these points.Thanks in advance
I've read through a few posts already, stating to compress the pkg as a zip first, then upload to JAMF, but I'm having the same issue. When I try to install the package directly on the machine, it works fine. But if I install it from JAMF via a policy, it errors:The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance.Not sure what else to try at this point. It happens on both Monterey & Ventura.
So I was getting this error constantly on every machine.When I checked the Approved System Extensions, I noticed there was 'Allowed Team Identifiers' for a few Applications, one being Cisco AnyConnect. So I created a new Approved System Extensions policy and removed the 'Allowed Team Identifiers' portion for Cisco AnyConnect. As you can see in the NEW policy, the 'Allowed Team Identifiers' is gone. Question for clarity... I assume if the Team Identifier is already being entered within Allowed System Extension Types, it would be unnecessary to also add Allowed Team Identifiers. That option seems to be for applications that do not need System Extension or System Extension Types. Is this correct? After I removed the Allowed Team Identifiers in the NEW policy, I didn't see anymore errors... So for clarity, is Allowed Team Identifiers necessary, or can I delete that portion without causing any harm?
I have a fleet of Macs that are enrolled in Microsoft Endpoint Manager via the Jamf connector and Company Portal. Upon adding the criteria "Computer Azure Active Directory ID", "User Azure Active Directory ID" and "Conditional Access Inventory State" to Inventory Display, all Macs show their status for each of these criteria as "Not present" from within the Computers > Search Inventory page in Jamf Pro. If we look at the actual Mac inventory record, the attributes are visible with their correct values And again, when viewing the contents of a smart group, the attributes are visible too I would expect these attributes to all be visible from within a computer search from the Computers > Search Inventory page in Jamf Pro. Is anyone else seeing this? Am I missing something?
We have 2 mac devices we want to trial in Jamf Now and wondered if we can use it for free as its under 3 devices but add on the Jamf Connect package ($2 per user per month) so we can use Azure AD logins?I wasnt sure if this was a package for one of the other bundles and wouldnt let you add it to the free package?
Hi all I am using API for the first time ever. The need to use API has crept up as I have discovered that apparently there is now the ability to flush a single policy for a single device by using the API protocols. It was apparently implemented in 9.96 - check it out here. Looking at the JSS REST API Resource Documentation, I have worked out that I can use it to obtain the necessary JSS IDs for a computer and a policy. However looking at the '/commandflush' aspect of the API, I just can't work out how I would get the specific policy for a specific computer to be flushed. Basically what I am after, is the ability to tell (or 'Put' in API language) for the status of a computer ID to be changed to 'Pending' for a particular policy ID. This is my early attempt of creating a bash script to achieve this.... #!/bin/sh jssAPIuser=[input a jss account] jssAPIpassword=[input the password] jssURL=[input your jss url] macName='systemsetup -getcomputername | awk '{print $3}'' policyName=[in
Just trying to run a script on machines that deletes all the garbage entries of printers that JAMF School has put onto systems while trying to manage/add printers in the JAMF Cloud web interface (which is actually a nightmare since there is no real documentation other than "just do this" and nothing is actually validated before it is pushed to systems). Even though I removed the printers in JAMF, the printers still show up as local entries on each machine and I can also do lplist which dumps all the printer entries that were added to CUPS from JAMF. I can also see all the printers in CUPS WebUI.Now, I just want to a simple bash script that is sent to each machine once to fully clear the printers so I can make one more push in JAMF as a clean slate for printers here on out. Scripting Module is enabled and works(already tested).Here are two versions of a simple looping script I have tried to run - both fail:#!/bin/bash lpstat -p | awk '{print $2}' | while read printer
I am trying to add another user to our mac fleet using a script. The script goes through without error and creates a user but no directory folder so when I attempt to log in as the "sub" it just spins and spins. Here is my script....what am I missing?sudo dscl . -create /Users/subsudo dscl . -create /Users/sub UserShell /bin/bashsudo dscl . -create /Users/sub RealName subsudo dscl . -create /Users/sub UniqueID 1000sudo dscl . -create /Users/sub PrimaryGroupID 20sudo dscl . -create /Users/sub NFSHomeDirectory /Users/sub sudo dscl . -passwd /Users/sub becker
This is more of a heads up post… after talking with Apple support today I have found that there is an emerging issue regarding USB-C to lightning cables, MacBooks, and restoring iPads. If you find yourself frustrated, restoring iPads with such a combination…. Two things of note. The workaround is simply to use a USB A to Lightning cable. And the second point of note is to please call AppleCare. My case number on the issue is 101888762488. Please let them know if you are impacted because we need them to get this fixed as soon as possible. Hopefully this helps someone not spend a bunch of time troubleshooting their Mac, trying replacement Macs and different USB C to lightning cables.
Sending the Enable Lost Mode, Lock Device, Wipe Device or Unmanage Device commands do no good if the mobile device is not checking in with Jamf. Until it checks in (which may be never), it continues to use a Jamf license. I don't see a way to release the Jamf license without deleting the record from Jamf, which I'd rather not do (as then we no longer have a record of the device). Or am I missing something?
Hi, Our schools are purchasing a huge amountof iPads end of the year with the purpose in mind to lend them to students fulltime, until the yare leaving. One of the few restrictions we are bound to set (via law) is a content filter per DNS. Since they can take the iPads home with them they are not bound to the school wifi and we would need to set a global DNS entry. Is there a way to set the DNS globally? I've seen workarounds with scripts, but is this possible on iOS?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!