Get Support
Recently active
We recently had a configuration change to our AD domain controllers which has caused an issue with our 10.5 clients. I'm looking at an easy way with Casper to turn off IPv6 on the 10.5 clients. If I take the /Library/Preferences/System Configuration/preferences.plist file from a machine I turned IPv6 off I also get the computer name and other unwanted data. Has anyone tried this before? I'm not a script guru so I haven't ventured down that path. This will be a temporary fix as we're updating the OS for out fall semester. Thanks for any suggestions or pointers.Brad ---------------------------------------------------------------------Brad GunnellsUniversity of IowaInformation Technology ServicesInstructional Services/Learning Spaces TechnologyIowa City IA 52242(319)335-5524 FAX (319)335-5505mailto:brad-gunnells at uiowa.edu---------------------------------------------------------------------
Hi,I have a question about Apple IDs. I am moving my group to JAMF as we purchase new Macs. I have restricted the Apple ID pane in the PreStage config. When migrating end user data from their old Macs their Apple ID info is automatically coming over as well. Is there a way to avoid this on future installs and how would I remedy this situation on the machines that are currently affected? Thanks for the advice.
We use Connect with Okta as our IDP and MFA is required for all accounts in Okta. Intermittently, on some devices, after a user enters their username and password the Connect login window will loop back to the username and password screen without prompting for MFA and the user is not allowed to log in. Digging into the Okta logs I can see that the users are entering their credentials correctly and Okta is waiting for a successful MFA response to allow the login. Has anyone else seen this in their environment and if so were you able to remediate it? More Details: We have seen this on devices running Jamf Connect 2.14 as well as 2.16 and macOS versions 12.6 and 11.7
My apologies if this exists elsewhere, I looked through the forum, but nothing seemed to match my scenario. I currently have been deploying OneDrive for Business via VPP (device), but I'm looking to migrate our users to the standalone version. In my experience it seems that the OneDrive VPP app doesn't update via Jamf/MAS, mainly because OneDrive needs to quit to perform the update. Since there is never an alert to the user to quit OneDrive, the app never updates. From my understanding the Standalone version keeps itself up to date, so no need for me to manage updates on it (outside of finding a user very out of date for whatever reason). So here is my question's, has anyone migrated their users from the VPP version to the Standalone version successfully? Are there any pitfalls or things that should be considered for such a change? In your opinion is the Standalone version better/easier to manage as it appears from my findings? Thank you for any help that you can provide!
Hi Getting error while running the below script for getting the macosmonterey installer in applicationsPlease suggest what i am missing here#!/bin/bashsoftwareupdate --list-full-installers | grep 'macOS' | awk '{print ++count " " $0}'softwareupdate --list-full-installerssoftwareupdate --fetch-full-installer --full-installer-version 12.6.1 Install failed with error: Installation failed Error Domain=PKDownloadError Code=8 "(null)" UserInfo={NSUnderlyingError=0x6000032f45a0 {Error Domain=NSURLErrorDomain Code=-999 "cancelled" UserInfo={NSErrorFailingURLStringKey=https://swcdn.apple.com/content/downloads/36/13/012-90254-A_BJQ1VMPD44/z225i7bzise31eo21e4kgfkafz7zq0q9tu/InstallAssistant.pkg, NSErrorFailingURLKey=https://swcdn.apple.com/content/downloads/36/13/012-90254-A_BJQ1VMPD44/z225i7bzise31eo21e4kgfkafz7zq0q9tu/InstallAssistant.pkg, _NSURLErrorRelatedURLSessionTaskErrorKey=( "LocalDataTask <F5729777-F5DD-4264-AE21-A87B94ACA121>.<1>" ), _NSURLErrorFailingURLSessionTa
Hi,Please check and suggest. getting the below error while running script for mac os ventura updateError running script: return code was 2. Install finished successfully Scanning for 13.0.1 installer Install finished successfully /Library/Application Support/JAMF/tmp/MacOSUpgrade.sh test 2: line 6: /Applications/Install macOS Ventura Beta.app.app/Contents/Resources/startosinstall: No such file or directory /Library/Application Support/JAMF/tmp/MacOSUpgrade.sh test 2: line 7: syntax error near unexpected token `|' /Library/Application Support/JAMF/tmp/MacOSUpgrade.sh test 2: line 7: `echo <password> |'/Applications/Install macOS Ventura Beta.app/Contents/Resources/startosinstall' --agreetolicense --nointeraction --forcequitapps --user <admin> --stdinpass'
I'm trying to set up remote management with Apple Remote Desktop on MacBooks The devices are on a different site, and I need to remotely enable the functions that you normally have to check box, like Generate reports, Restart/Shut Down, etc. Is there a way to do that remotely through a script or something?
Hi!Anyone here that has any experience in setting up Jamf Connect with CyberArk as a IDP for password sync?This password sync used to work in our configuration using a web app that sets a custom claim that is used by Jamf Connect, but this stopped working all of the sudden and both Cyberark en Jamf do not seem to know what is causing the issue and more importantly how to fix it.
Hello,I created managed Apple IDs for my students in Apple School Manager. After I imported the Users to Jamf Pro and assigned iPads to the users. Now my students need to log into their managed Apple ID on the iPad. But they are also able to log into their private Apple ID. Is there a smart way to only allow them to log into the managed Apple ID?Thanks for any ideas!M. Laurenz
Hi all, I have had to take over a JAMF Pro deployment that had been managed by an ex-colleague. We thought we'd covered everything in his handover, but of course the devil is in the detail!So, I'm trying to deploy Monterey to some of our Macs but the policies and groups aren't working as I would have expected. There is a policy to cache the installer to compatible machines, which shows 40 odd devices in the log. But the smart group to find these devices, which is the scope for the policy to pop the installer in Self Service only shows 4.Also have a problem with that second policy, but maybe it would be better to start another thread for that?I'll be guided by you on that though.Thanks
Hi all, we currently have a bunch of teachers wanting to install and test apps on their own. Previously I pushed the apps to the devices but that is too long of a wait for some. So I changed the restrictions in the profile for those iPads. I now have the app store enabled and installed. I enabled the 'Allow modifying account settings' so they could use their own account for the app store and I have enabled 'Allow app installation through the app store'. Users are now reporting that they can download and install app but they can't open them.I am currently out of ideas to fix this...
Hi there, I know this topic was covered quite a bit but I'm not able to find something that fits our requirements.I'm looking for a script that will rename a devices on jamf to the following format:"FirstName LastName - MacBookModel - S/N"And what is the best methodology to trigger this script, I found that with the previous script when the policy is set to run during enrolment and I left the device at the account creation page for 5 minutes, the device would be named "_mbsetupuser" so to avoid that is there any way to create a custom trigger for a device that was logged in for the first time and have the policy and script run on that trigger?
Is there a way to find out the bundle ID of a web clip? I would like to open a web clip in Single App Mode. "com.apple.webapp" opens a web clip, but an empty one.I can't view the .mobileconfig either since it's encrypted.
Anyone still using a script to manage order of preferred wireless networks in MacOS 11 or above? If so is it working?We were using the script from Paul Nelson, but since Apple separated the /Library/Preferences/\\SystemConfiguration/com.apple.airport.preferences.plist and put the known-networks in a separate file in /Library/Preferences/com.apple.wifi.known-networks.plistit seems like all the old scripts to do this are broken
I would like to be able to globally set a few of the Account Preferences for new users that are created. Currently, new users do not inherit any global preferences for their Language & Region, Search Preferences, and Interface Preferences.Ideally, as an administrator I would be able to set the default Search Preferences for Computers, Devices, and Users to "Contains" instead of "Exact Match". Other preferences would be ideal to set, too.Please consider this an enhancement request for Jamf Pro.Thanksrustycc: @duanemaas
So JCL is working for me in general...I am presented with the login window, I enter my credentials, and my account is created. The real issue is coming from the OIDCAdmin key and my configuration of that. So just to run down everything I have done:- Created JCL enterprise app and made manifest with standard/admin group- Assigned myself as an Admin for the app in AAD- For OIDCAdmin key in the config profile, I have role as Admin. That is the name of the Admin assignment from before on AAD- I set OIDCAdminAttribute to the key in the manifest for admin users With all of those set, I login with that AAD account at the login window, and every time I still appear as a standard user. In Directory Utility, the NetworkUser is set to the correct email. any ideas?
This post is for people who are looking to name their computers to it's serial number. The script can be run with a policy at recurring check-in. Obviously there are multiple ways to set the computer name and the jamf binary can do it as well. If anyone wants to add in the comments what they use for naming computers, I'm sure fellow Jamf Admin's would not mind. #!/usr/bin/env bash # Get the Serial Number of the Machine sn=$(system_profiler SPHardwareDataType | awk '/Serial/ {print $4}') # Set the ComputerName, HostName and LocalHostName scutil --set ComputerName $sn scutil --set HostName $sn scutil --set LocalHostName $sn
I've been using JAMF for nearly two years now, and the feature I lack the most is to make JAMF pro into a fully automated management solution with zero admin intervention on a daily basis. IMO, the number one reason this isn't currently possible is because some actions can only be done manually or through some third party workflow engine that leverages the API, which is impractical to say the least.So, I was wondering if that's just me or if the wider admin community also lacks a few key features that would remove the need of the most recurring and brainless tasks, such as repeatedly scheduling OS updates via MDM commands or clearing failed/pending commands on devices.For that purpose, I've submitted a feature request to create the ability to take those actions you can take from a search/list of devices, but get JAMF to take those actomatically instead of interactively. If you also feel that this would be a great feature to have, please vote for it here: https://ideas.jamf.com/ide
Hi,I'm new to JAMF / Schools / Apple and have been able to work out most things but I am stuck on this one issue. I have an iPad that is in our Apple School Manager instance but I cannot see it in Jamf and on the iPad the management parts are missing.In Apple School Manager the device is not listed as released and the mdm server is the same as where I am looking for the device but it does not appear.How can I get the iPad into JAMF to be fully managed? I went to the enroll URL of JAMF but we are unable to change a lot of settings as it says it needs to be in supervisor mode. Do I need to use apple configurator or am I missing something?Chris
Hello,Looking for guidance. My co-worker who was supporting Jamf left so I have taken over. Our MDM Push Notification Certificate expires the first week of January. I was reading the guides on how to renew the certificate (see steps below) But I'm confused on step 4. How do I know if the server hosting JAMF has an outbound connection? Also do I need to download the token from ABM prior to renewing the certificate. In Jamf Pro, click Settings ,in the top-right corner of the page.In the Global section, click Push certificates Click the push certificate, and then click Renew Choose a method for renewing the push certificate:If the server hosting Jamf Pro has an outbound connection, select Download signed CSR from Jamf Account. Jamf Pro connects to Jamf Nation over port 443 and obtains the signed CSR.If the server hosting Jamf Pro does not have an outbound conn
I can't update our iPads (6 gen and 9 gen). Everyone currently has iOS 15 installed and communication between the iPad and jamf school is working. All other commands and app installations etc work. These are shared iPads with guest access...does it matter?
We do not use a cloud distribution point for our Jamf pro instance (nor do we want to) We would like to be able to upload packages using the Jamf Pro console and not the clunky admin app. Why isn't this an option when having a https enabled File share distribution point?
I've had this come up a number of times on the admin site, but this is a first for the Self Service app. I don't want my users to have to run into this. When I run into it, I have to clear all cache related to login.microsoftonline.com, or open in private/incognito. Not something that can be done with the app. What can I do to keep this from happening in the app at least?We're Azure IdP. I have Self Service set to require login, and to use SSO.
I know this has come up a few times in the past but mostly for iOS devices. I'm having an issue that started today where I deployed around 10 new configuration profiles to around 500 Macs and it started out fine with computers completing the installation but now as computers check in, they're all showing "Device was busy. Will try again." I've cleared all of the pending and failed commands but this is all I get now. We're on Jamf 10.19 cloud. The computers are running various operating systems, mostly 10.14 but some 10.15 and some below 10.14.
Hello. i am new here. How to install Symantec DLP on macbooks?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!