Get Support
Recently active
Many software publishers provide static (non-changing) links that always point to the latest release.Consider this download link for Zoom:https://zoom.us/client/5.12.9.13190/zoomusInstallerFull.pkgIt works, but it always downloads version 5.12.9.13190, even if a newer version is available. Now, consider this download link.Zoom (Intel): https://zoom.us/client/latest/Zoom.pkg As the name suggests, it always points to the latest release. You can use that URL with a Universal Installer script (like the one found here) to create a Jamf policy that never needs to be updated.Similar static links are available for lots of other apps, but they're not always easy to find.That's why I created this thread. It is my hope that others will share these static links here, so that this thread can be a continuing resource to Jamf Admins.Here are a few more.Zoom (Apple Silicon):https://zoom.us/client/latest/Zoom.pkg?archType=arm64Coconut Battery: https://coconut-flavour.com/downl
Is it possible to have multiple instances use the same ADCS server at the same time? I've been told yes, but the ADCS deployment appears linked to a specific cloud instance. How do you generate an additional client certificate for use with the second cloud instance of Jamf Pro?Or maybe an additional client cert isn't needed?
I am the Mac admin for my company and we are thinking about using the Jamf Connect product. I was able to work with my Ping team and get my test environment setup properly, but I am having some connectivity trouble with setup for my production environment. The OIDC connects and validates with no issues. The ROPG test shoots me back an error message that states"ROPG test failure: Error from request to URL: https://idp.aa.com/as/token.oauth2, ERROR: Unknown error. Message: There are no access token managers available for the selected client and authentication context, STATUS: 400"Does anyone have any idea what this means or what I should have my Ping team try to change/correct for the successful test of ROPG? Any assistance or guidance would be greatly appreciated. Thank you
Before Ventura was released, we were testing out erase-install.sh and it worked pretty good and updated from to 12.6 pretty fast. We had to set to just install the latest version, but since Ventura is considered a minor update on 12.6, I had to change some of the install options. I added the os option, but the download is now installing the full installer and takes about 1hr and 15min to complete. Below are the options I'm using to install 12.6.1. In way to get this to update faster?/Library/Management/erase-install/erase-install.sh --pkg --reinstall --os=12 --update --min-drive-space=35 --current-user --check-power --no-fs --depnotify --cleanup-after-use
We have a 'Make Yourself an Admin for 10 Min" self service that stores logs for those 10 min. Issue is I am not sure how to grab them or get them somewhere where we can do spot checks. Is this possible?
Having a bit of a weird issue. So I have this script that pops a notification box open on check-in, and it's working fine, except that it won't display the branding icon in the box. It's probably easier to show than to tell, so see below (executing this script in macOS Ventura 13.0.1): jamfHelper="/Library/Application Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper" windowType="hud" description="Insert description here (edited for the sake of this forum post)" icon="~/Library/Application\\ Support/com.jamfsoftware.selfservice.mac/Documents/Images/brandingimage.png" #this path is accurate title="macOS Update Required" alignDescription="left" alignHeading="center" button1="OK" timeout="600" window=$("$jamfHelper" -windowType "$windowType" -lockHUD -title "$title" -timeout "$timeout" -icon "$icon" -description "$description" -alignDescription "$alignDescription" -alignHeading "$alignHeading" -button1 "$button1") What am I doing wrong?
We have deployed microsoft defender via Jamf. However it seems they got deployed in standalone mode and not managed mode.In defender portal the count is zero for MacOS. we followed https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-jamfpro-policies?view=o365-worldwideany suggestions?
Hi,We mainly use Jamf Connect with Azure AD for staff and student user accounts on our Macs. However, I'm thinking about using a generic local user account for consultants and guests because it is our school's policy to not create school domain accounts for consultants and guests. When I log into the local user account that I created, the user is logged in successfully, but the Jamf Connect login window pops up asking the user to authenticate to Jamf Connect. This login window can't be closed or ignored, unless I disable the setting "RequireSignIn" in the com.jamf.connect configuration profile plist. By disabling that setting, the login window will still pop up, but now I can close the window and ignore it. Are there any repercussions to disabling this setting? How will that setting affect other Jamf Connect with Azure users if I leave it disabled?
I'm looking for ways to migrate existing machines into our JAMF Pro implementation. Utopia would have us erase the machines and re-enrol through DEP. Out thinking is we will do this as part of our hardware refresh cycle. In the meantime I've been looking at using reenroller (GitHub - jamf/ReEnroller: Migrate macOS devices from one Jamf Server to another.) to migrate existing machines across. Although the migration is working the MDM profile is not downloaded for the user to approve. Am I missing something in the configuration or do I have to script a Profile to manually download and open "Self Service" to prompt the user to approve it.Thanks
Does anyone know how devices would become unsupervised? We've been running into issues and I noticed a lot of these computers weren't supervised, so I ran a report and somehow over 800 computers are reporting unsupervised. We will be wiping all the computers over the summer so it's not an urgent issue, I'm just curious how this could happen.
We have been running Jamf Connect 2.12.0 for many months just fine. I recently installed version 2.17 for testing and it seems to work ok. This morning I saw that 2.18 is available so I installed that for testing. As it just so happened, I needed to change my password, so I changed it via Jamf Connect and it worked great! I decided to restart my Mac to make sure the FileVault password also synced up but when I restarted my Mac running macOS 12.6.1 I no longer get the FileVault login with the icons to pick from. I only see the ID & PW boxes. No amount of restarts brings back the FV icons. It also seems to have forgotten out our desktop wallpaper that we use on the Login screen (without FV).Is this expected behavior?
I am looking for a way to create an extension attribute to show when the last inventory (Recon) was done on a computer. Any assistance would help and is appreciated.
Does anybody know a script to unlock Energy Saver prefs for non-admins? Thanks,Jared
We recently had a configuration change to our AD domain controllers which has caused an issue with our 10.5 clients. I'm looking at an easy way with Casper to turn off IPv6 on the 10.5 clients. If I take the /Library/Preferences/System Configuration/preferences.plist file from a machine I turned IPv6 off I also get the computer name and other unwanted data. Has anyone tried this before? I'm not a script guru so I haven't ventured down that path. This will be a temporary fix as we're updating the OS for out fall semester. Thanks for any suggestions or pointers.Brad ---------------------------------------------------------------------Brad GunnellsUniversity of IowaInformation Technology ServicesInstructional Services/Learning Spaces TechnologyIowa City IA 52242(319)335-5524 FAX (319)335-5505mailto:brad-gunnells at uiowa.edu---------------------------------------------------------------------
Hi,I have a question about Apple IDs. I am moving my group to JAMF as we purchase new Macs. I have restricted the Apple ID pane in the PreStage config. When migrating end user data from their old Macs their Apple ID info is automatically coming over as well. Is there a way to avoid this on future installs and how would I remedy this situation on the machines that are currently affected? Thanks for the advice.
We use Connect with Okta as our IDP and MFA is required for all accounts in Okta. Intermittently, on some devices, after a user enters their username and password the Connect login window will loop back to the username and password screen without prompting for MFA and the user is not allowed to log in. Digging into the Okta logs I can see that the users are entering their credentials correctly and Okta is waiting for a successful MFA response to allow the login. Has anyone else seen this in their environment and if so were you able to remediate it? More Details: We have seen this on devices running Jamf Connect 2.14 as well as 2.16 and macOS versions 12.6 and 11.7
My apologies if this exists elsewhere, I looked through the forum, but nothing seemed to match my scenario. I currently have been deploying OneDrive for Business via VPP (device), but I'm looking to migrate our users to the standalone version. In my experience it seems that the OneDrive VPP app doesn't update via Jamf/MAS, mainly because OneDrive needs to quit to perform the update. Since there is never an alert to the user to quit OneDrive, the app never updates. From my understanding the Standalone version keeps itself up to date, so no need for me to manage updates on it (outside of finding a user very out of date for whatever reason). So here is my question's, has anyone migrated their users from the VPP version to the Standalone version successfully? Are there any pitfalls or things that should be considered for such a change? In your opinion is the Standalone version better/easier to manage as it appears from my findings? Thank you for any help that you can provide!
Hi Getting error while running the below script for getting the macosmonterey installer in applicationsPlease suggest what i am missing here#!/bin/bashsoftwareupdate --list-full-installers | grep 'macOS' | awk '{print ++count " " $0}'softwareupdate --list-full-installerssoftwareupdate --fetch-full-installer --full-installer-version 12.6.1 Install failed with error: Installation failed Error Domain=PKDownloadError Code=8 "(null)" UserInfo={NSUnderlyingError=0x6000032f45a0 {Error Domain=NSURLErrorDomain Code=-999 "cancelled" UserInfo={NSErrorFailingURLStringKey=https://swcdn.apple.com/content/downloads/36/13/012-90254-A_BJQ1VMPD44/z225i7bzise31eo21e4kgfkafz7zq0q9tu/InstallAssistant.pkg, NSErrorFailingURLKey=https://swcdn.apple.com/content/downloads/36/13/012-90254-A_BJQ1VMPD44/z225i7bzise31eo21e4kgfkafz7zq0q9tu/InstallAssistant.pkg, _NSURLErrorRelatedURLSessionTaskErrorKey=( "LocalDataTask <F5729777-F5DD-4264-AE21-A87B94ACA121>.<1>" ), _NSURLErrorFailingURLSessionTa
Hi,Please check and suggest. getting the below error while running script for mac os ventura updateError running script: return code was 2. Install finished successfully Scanning for 13.0.1 installer Install finished successfully /Library/Application Support/JAMF/tmp/MacOSUpgrade.sh test 2: line 6: /Applications/Install macOS Ventura Beta.app.app/Contents/Resources/startosinstall: No such file or directory /Library/Application Support/JAMF/tmp/MacOSUpgrade.sh test 2: line 7: syntax error near unexpected token `|' /Library/Application Support/JAMF/tmp/MacOSUpgrade.sh test 2: line 7: `echo <password> |'/Applications/Install macOS Ventura Beta.app/Contents/Resources/startosinstall' --agreetolicense --nointeraction --forcequitapps --user <admin> --stdinpass'
I'm trying to set up remote management with Apple Remote Desktop on MacBooks The devices are on a different site, and I need to remotely enable the functions that you normally have to check box, like Generate reports, Restart/Shut Down, etc. Is there a way to do that remotely through a script or something?
Hi!Anyone here that has any experience in setting up Jamf Connect with CyberArk as a IDP for password sync?This password sync used to work in our configuration using a web app that sets a custom claim that is used by Jamf Connect, but this stopped working all of the sudden and both Cyberark en Jamf do not seem to know what is causing the issue and more importantly how to fix it.
Hello,I created managed Apple IDs for my students in Apple School Manager. After I imported the Users to Jamf Pro and assigned iPads to the users. Now my students need to log into their managed Apple ID on the iPad. But they are also able to log into their private Apple ID. Is there a smart way to only allow them to log into the managed Apple ID?Thanks for any ideas!M. Laurenz
Hi all, I have had to take over a JAMF Pro deployment that had been managed by an ex-colleague. We thought we'd covered everything in his handover, but of course the devil is in the detail!So, I'm trying to deploy Monterey to some of our Macs but the policies and groups aren't working as I would have expected. There is a policy to cache the installer to compatible machines, which shows 40 odd devices in the log. But the smart group to find these devices, which is the scope for the policy to pop the installer in Self Service only shows 4.Also have a problem with that second policy, but maybe it would be better to start another thread for that?I'll be guided by you on that though.Thanks
Hi all, we currently have a bunch of teachers wanting to install and test apps on their own. Previously I pushed the apps to the devices but that is too long of a wait for some. So I changed the restrictions in the profile for those iPads. I now have the app store enabled and installed. I enabled the 'Allow modifying account settings' so they could use their own account for the app store and I have enabled 'Allow app installation through the app store'. Users are now reporting that they can download and install app but they can't open them.I am currently out of ideas to fix this...
Hi there, I know this topic was covered quite a bit but I'm not able to find something that fits our requirements.I'm looking for a script that will rename a devices on jamf to the following format:"FirstName LastName - MacBookModel - S/N"And what is the best methodology to trigger this script, I found that with the previous script when the policy is set to run during enrolment and I left the device at the account creation page for 5 minutes, the device would be named "_mbsetupuser" so to avoid that is there any way to create a custom trigger for a device that was logged in for the first time and have the policy and script run on that trigger?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!