Get Support
Recently active
Is there a way to find out the bundle ID of a web clip? I would like to open a web clip in Single App Mode. "com.apple.webapp" opens a web clip, but an empty one.I can't view the .mobileconfig either since it's encrypted.
Anyone still using a script to manage order of preferred wireless networks in MacOS 11 or above? If so is it working?We were using the script from Paul Nelson, but since Apple separated the /Library/Preferences/\\SystemConfiguration/com.apple.airport.preferences.plist and put the known-networks in a separate file in /Library/Preferences/com.apple.wifi.known-networks.plistit seems like all the old scripts to do this are broken
I would like to be able to globally set a few of the Account Preferences for new users that are created. Currently, new users do not inherit any global preferences for their Language & Region, Search Preferences, and Interface Preferences.Ideally, as an administrator I would be able to set the default Search Preferences for Computers, Devices, and Users to "Contains" instead of "Exact Match". Other preferences would be ideal to set, too.Please consider this an enhancement request for Jamf Pro.Thanksrustycc: @duanemaas
So JCL is working for me in general...I am presented with the login window, I enter my credentials, and my account is created. The real issue is coming from the OIDCAdmin key and my configuration of that. So just to run down everything I have done:- Created JCL enterprise app and made manifest with standard/admin group- Assigned myself as an Admin for the app in AAD- For OIDCAdmin key in the config profile, I have role as Admin. That is the name of the Admin assignment from before on AAD- I set OIDCAdminAttribute to the key in the manifest for admin users With all of those set, I login with that AAD account at the login window, and every time I still appear as a standard user. In Directory Utility, the NetworkUser is set to the correct email. any ideas?
This post is for people who are looking to name their computers to it's serial number. The script can be run with a policy at recurring check-in. Obviously there are multiple ways to set the computer name and the jamf binary can do it as well. If anyone wants to add in the comments what they use for naming computers, I'm sure fellow Jamf Admin's would not mind. #!/usr/bin/env bash # Get the Serial Number of the Machine sn=$(system_profiler SPHardwareDataType | awk '/Serial/ {print $4}') # Set the ComputerName, HostName and LocalHostName scutil --set ComputerName $sn scutil --set HostName $sn scutil --set LocalHostName $sn
I've been using JAMF for nearly two years now, and the feature I lack the most is to make JAMF pro into a fully automated management solution with zero admin intervention on a daily basis. IMO, the number one reason this isn't currently possible is because some actions can only be done manually or through some third party workflow engine that leverages the API, which is impractical to say the least.So, I was wondering if that's just me or if the wider admin community also lacks a few key features that would remove the need of the most recurring and brainless tasks, such as repeatedly scheduling OS updates via MDM commands or clearing failed/pending commands on devices.For that purpose, I've submitted a feature request to create the ability to take those actions you can take from a search/list of devices, but get JAMF to take those actomatically instead of interactively. If you also feel that this would be a great feature to have, please vote for it here: https://ideas.jamf.com/ide
Hi,I'm new to JAMF / Schools / Apple and have been able to work out most things but I am stuck on this one issue. I have an iPad that is in our Apple School Manager instance but I cannot see it in Jamf and on the iPad the management parts are missing.In Apple School Manager the device is not listed as released and the mdm server is the same as where I am looking for the device but it does not appear.How can I get the iPad into JAMF to be fully managed? I went to the enroll URL of JAMF but we are unable to change a lot of settings as it says it needs to be in supervisor mode. Do I need to use apple configurator or am I missing something?Chris
Hello,Looking for guidance. My co-worker who was supporting Jamf left so I have taken over. Our MDM Push Notification Certificate expires the first week of January. I was reading the guides on how to renew the certificate (see steps below) But I'm confused on step 4. How do I know if the server hosting JAMF has an outbound connection? Also do I need to download the token from ABM prior to renewing the certificate. In Jamf Pro, click Settings ,in the top-right corner of the page.In the Global section, click Push certificates Click the push certificate, and then click Renew Choose a method for renewing the push certificate:If the server hosting Jamf Pro has an outbound connection, select Download signed CSR from Jamf Account. Jamf Pro connects to Jamf Nation over port 443 and obtains the signed CSR.If the server hosting Jamf Pro does not have an outbound conn
I can't update our iPads (6 gen and 9 gen). Everyone currently has iOS 15 installed and communication between the iPad and jamf school is working. All other commands and app installations etc work. These are shared iPads with guest access...does it matter?
We do not use a cloud distribution point for our Jamf pro instance (nor do we want to) We would like to be able to upload packages using the Jamf Pro console and not the clunky admin app. Why isn't this an option when having a https enabled File share distribution point?
I've had this come up a number of times on the admin site, but this is a first for the Self Service app. I don't want my users to have to run into this. When I run into it, I have to clear all cache related to login.microsoftonline.com, or open in private/incognito. Not something that can be done with the app. What can I do to keep this from happening in the app at least?We're Azure IdP. I have Self Service set to require login, and to use SSO.
I know this has come up a few times in the past but mostly for iOS devices. I'm having an issue that started today where I deployed around 10 new configuration profiles to around 500 Macs and it started out fine with computers completing the installation but now as computers check in, they're all showing "Device was busy. Will try again." I've cleared all of the pending and failed commands but this is all I get now. We're on Jamf 10.19 cloud. The computers are running various operating systems, mostly 10.14 but some 10.15 and some below 10.14.
Hello. i am new here. How to install Symantec DLP on macbooks?
I have tried to upload the Adobe template pkg to Jamf cloud, but for some reason, the upload is always stuck at 99% no matter how many times I have tried.Is there any better way to deploy Adobe Acrobat DC here? Thanks!
Hey Everyone,I'm trying to find a way to suppress the new account setup assistant when logging into accounts for the first time. I'm currently using DEP with a pre-stage deployment profile to bypass the initial setup assistant and log in straight to the administrator account. When I create a users account, be it through Users & Groups or Jamf Connect, I'm greeted by the new account setup IE) Accessibility, Data & Privacy, Touch ID & Theme. Is there any way to skip this when signing into new accounts the first time?Thank you for your help!
I have been working on setting up our Lightspeed smart agent to push out using JAMF over the last couple of weeks and keep running into problems. My current dilemma is with Lightspeed Relay Agent 1.6 and the system extension. I have a configuration policy setup to allow both the KEXT and the system extension (KEXT was for Relay agent 1.5.2) and the Lightspeed Relay cert. When I grab a computer fresh out of the box and set it up, the agent installs but the system extension still asks for user authentication to approve it. I have played around with the setting, such as allowing user auth or no user auth, using the various system extension types drop down and adding Lightspeed Systems to the Allowed system extensions. The weird part to all of this is if I redistribute the configuration profile to the test computer while it is asking for the system extension to be allowed, it will authorize it no problem, however, if I do not do the redistribution, a user has to manually click on allo
I would like to trigger the same policy using different custom events.For example -jamf policy -event triggerAjamf policy -event triggerBwill both trigger policy XYZI've tried adding the custom event triggerA, triggerB to policy XYZ, but it didn't work.Is it a syntax issue, or is it simply not supported and I need to clone the policy instead?
I am trying to lock down the ability to have 'private wi-fi address'. I went to the enrollment link and successfully enrolled the tablet. However i can still toggle the private wi-fi address option on the tablet. Am i missing a step?
Through testing Notify I seem to have got my Mac stuck in an infinate loop... It never completes from the attached image. I manually installed a custom pkg with a post install script to activate the jamf notify machanism however I dont this it ingested the Notify script to tell it what to do. So now it is stuck here. I have tried reboot several times to no avail. Can someone help me recover from this?
Does anyone know of an effective way to Disable the Message app? It seems there is no way within a config profile to disable just the Messages app. I was able to "Disallow a folder" instead of an app which seems ridiculous. From what I have been reading the Software Restriction section looks for the actual binary being used, which is named "Messages" in /Applications/Messages.app/Contents/MacOS/Messages. This blocked the app but I then it gave me the option to allow it with admin creds. Some of our users have access to a Grant Admin rights policy which shuts off automatically after 24 hours so it would not be useful to them if they could allow it. Disabling Messages should be easier. Any thoughts?
Hello all, We're seeing iBoss causing issues when students are trying to load ANY page. We no longer use iBoss and were attempting to move over to Linewize. It worked perfectly fine and then stopped. We've narrowed it down to leftover iBoss files somewhere on the machines. If we use the iBoss uninstall script, it'll work for a short period, but then returns. Does anyone have a script or know of anything that we can use to COMPLETELY remove any instance of iBoss without having to wipe the machines? Wiping the machines does resolve the issue. TIA!
Hello!We are looking to federate our domain in Apple Business Manager so that our users cannot use their work emails as personal Apple IDs and to then create managed Apple IDs for all users in our enterprise. Currently, our Developers had Apple IDs created through App Store Connect. When we try to setup accounts in Apple Business Manager with Apple IDs for those developers, we receive errors about them already being created. Are these Apple IDs considered personal Apple IDs, or are they managed Apple IDs that do not populate in Apple Business Manager?
What is the best way to try and debug an EA script? I’ve implemented logCollection https://github.com/kc9wwh/logCollection/wiki , and that works fine, but I’m trying to make a smart group that reports on Macs that have an attachment. The EA from https://github.com/kc9wwh/logCollection/wiki/Reporting doesn’t seem do anything. https://github.com/kc9wwh/logCollection/blob/master/EA-NumAttachments.sh shows... "jamfProURL="https://jamfpro.acme.net:8443"I've tried that format, plus...https://jamfpro.acme.nethttps://jamfpro.acme.net/...and none of those work (of course I'm using my own JPro instance address). Is there a log I can check to see where this is failing? Also, I know the api_user works, because that is the same user + creds that runs logCollection in the first place, and adds the attachment to the Mac.
I wanted to know few things about Jamf connect.1. If I use Jamf connect then user will be able to change the password and sync with AD/local mac over internet, I mean if the mac is not in office network either physically or through VPN.?2. If I use Jamf connect then how many local user accounts will be created on mac after enrollment in JAMF console? Is it 3, one is for by prestage enrollment which is defined there with UID 501, another one is by jamf connect at the time of provisioning with UID 502 and another one is management account , am I correct?3. Jamf connect creates only standard account at the time of provisioning or admin? If end user put a wrong string at the time of provisioning then what will happen? 4. Jamf Menu bar app is ok to deploy for existing mac devices those are not deployed with jamf connect at the of provisioning or still I need to deploy Jamf connect app too?5. Jamf Menu bar app can give notification to end user when the user's AD password is going to be
For the life of me I can't figure out what keywords to use to find what I'm looking for. How can I read what proxy settings the system is using outside of the normal Network System Preference window? In Terminal there's the "export" option which sets the various proxies, but how can we then read what has been set before?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!