Get Support
Recently active
I have tried to upload the Adobe template pkg to Jamf cloud, but for some reason, the upload is always stuck at 99% no matter how many times I have tried.Is there any better way to deploy Adobe Acrobat DC here? Thanks!
Hey Everyone,I'm trying to find a way to suppress the new account setup assistant when logging into accounts for the first time. I'm currently using DEP with a pre-stage deployment profile to bypass the initial setup assistant and log in straight to the administrator account. When I create a users account, be it through Users & Groups or Jamf Connect, I'm greeted by the new account setup IE) Accessibility, Data & Privacy, Touch ID & Theme. Is there any way to skip this when signing into new accounts the first time?Thank you for your help!
I have been working on setting up our Lightspeed smart agent to push out using JAMF over the last couple of weeks and keep running into problems. My current dilemma is with Lightspeed Relay Agent 1.6 and the system extension. I have a configuration policy setup to allow both the KEXT and the system extension (KEXT was for Relay agent 1.5.2) and the Lightspeed Relay cert. When I grab a computer fresh out of the box and set it up, the agent installs but the system extension still asks for user authentication to approve it. I have played around with the setting, such as allowing user auth or no user auth, using the various system extension types drop down and adding Lightspeed Systems to the Allowed system extensions. The weird part to all of this is if I redistribute the configuration profile to the test computer while it is asking for the system extension to be allowed, it will authorize it no problem, however, if I do not do the redistribution, a user has to manually click on allo
I would like to trigger the same policy using different custom events.For example -jamf policy -event triggerAjamf policy -event triggerBwill both trigger policy XYZI've tried adding the custom event triggerA, triggerB to policy XYZ, but it didn't work.Is it a syntax issue, or is it simply not supported and I need to clone the policy instead?
I am trying to lock down the ability to have 'private wi-fi address'. I went to the enrollment link and successfully enrolled the tablet. However i can still toggle the private wi-fi address option on the tablet. Am i missing a step?
Through testing Notify I seem to have got my Mac stuck in an infinate loop... It never completes from the attached image. I manually installed a custom pkg with a post install script to activate the jamf notify machanism however I dont this it ingested the Notify script to tell it what to do. So now it is stuck here. I have tried reboot several times to no avail. Can someone help me recover from this?
Does anyone know of an effective way to Disable the Message app? It seems there is no way within a config profile to disable just the Messages app. I was able to "Disallow a folder" instead of an app which seems ridiculous. From what I have been reading the Software Restriction section looks for the actual binary being used, which is named "Messages" in /Applications/Messages.app/Contents/MacOS/Messages. This blocked the app but I then it gave me the option to allow it with admin creds. Some of our users have access to a Grant Admin rights policy which shuts off automatically after 24 hours so it would not be useful to them if they could allow it. Disabling Messages should be easier. Any thoughts?
Hello all, We're seeing iBoss causing issues when students are trying to load ANY page. We no longer use iBoss and were attempting to move over to Linewize. It worked perfectly fine and then stopped. We've narrowed it down to leftover iBoss files somewhere on the machines. If we use the iBoss uninstall script, it'll work for a short period, but then returns. Does anyone have a script or know of anything that we can use to COMPLETELY remove any instance of iBoss without having to wipe the machines? Wiping the machines does resolve the issue. TIA!
Hello!We are looking to federate our domain in Apple Business Manager so that our users cannot use their work emails as personal Apple IDs and to then create managed Apple IDs for all users in our enterprise. Currently, our Developers had Apple IDs created through App Store Connect. When we try to setup accounts in Apple Business Manager with Apple IDs for those developers, we receive errors about them already being created. Are these Apple IDs considered personal Apple IDs, or are they managed Apple IDs that do not populate in Apple Business Manager?
What is the best way to try and debug an EA script? I’ve implemented logCollection https://github.com/kc9wwh/logCollection/wiki , and that works fine, but I’m trying to make a smart group that reports on Macs that have an attachment. The EA from https://github.com/kc9wwh/logCollection/wiki/Reporting doesn’t seem do anything. https://github.com/kc9wwh/logCollection/blob/master/EA-NumAttachments.sh shows... "jamfProURL="https://jamfpro.acme.net:8443"I've tried that format, plus...https://jamfpro.acme.nethttps://jamfpro.acme.net/...and none of those work (of course I'm using my own JPro instance address). Is there a log I can check to see where this is failing? Also, I know the api_user works, because that is the same user + creds that runs logCollection in the first place, and adds the attachment to the Mac.
I wanted to know few things about Jamf connect.1. If I use Jamf connect then user will be able to change the password and sync with AD/local mac over internet, I mean if the mac is not in office network either physically or through VPN.?2. If I use Jamf connect then how many local user accounts will be created on mac after enrollment in JAMF console? Is it 3, one is for by prestage enrollment which is defined there with UID 501, another one is by jamf connect at the time of provisioning with UID 502 and another one is management account , am I correct?3. Jamf connect creates only standard account at the time of provisioning or admin? If end user put a wrong string at the time of provisioning then what will happen? 4. Jamf Menu bar app is ok to deploy for existing mac devices those are not deployed with jamf connect at the of provisioning or still I need to deploy Jamf connect app too?5. Jamf Menu bar app can give notification to end user when the user's AD password is going to be
For the life of me I can't figure out what keywords to use to find what I'm looking for. How can I read what proxy settings the system is using outside of the normal Network System Preference window? In Terminal there's the "export" option which sets the various proxies, but how can we then read what has been set before?
We recently had an employee leave the company and we received their machine, unfortunately we do not have his password. I booted the Macbook Air M1, into recovery mode went into terminal and performed the resetpassword command it de-activated the mac and reset the password to the new password. I rebooted the macbook and it brought up the activation windows and asked me to select the account for i know the admin password for and I entered the password that I used when I performed the resetpassword command and it does not work. Is there another way to bypass this because of now i cannot get into the machine at all without doing the erase mac option and we would like to try and get any data off of the macbook.
Greetings of peace,Does anyone know if the AirPrint profile in Jamf Pro for Mobile Devices is suppose to restrict what AirPrint printers show up to ONLY what is included in the profile?It doesn't appear to be doing that in my testing. In fact it appears to be doing nothing at all in iPadOS 16. I'm just not sure what the expected behavior is. A search for "AirPrint" in the Jamf Pro manual returns zero results. Thank you!
Trying to connect our AzureAD to Jamf Pro (Cloud) and this is the error we are seeing.The connection between Microsoft Intune and Jamf Pro could not be established. Try again.The Cloud Connector was created we can login and approve the app but get this every time. Any pointers of what I should be checking or changing please let me know.
I'm trying to set up a plist that will have defaults settings for the new OneDrive Sync Client released 1/27/17. This new client enables users to also sync SharePoint folders to their Macs just like the Windows client. So, following the instructions in the article "Configure the new OneDrive sync client on macOS," I've made the following plist. However, I'm not sure if I set the DefaultFolder path string correctly. After looking at other plists in my ~/Library/Preferences folder that point to specific file paths, I think I have the right syntax. I want to turn this plist into a custom Configuration Profile to deploy to all my clients once I can test that it works. If anyone has experience with setting a default file path in a plist, and can check my work, that would be great. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key&
Anyone know of a way to refresh the EDU profile on managed devices? We're experiencing an issue with Apple Classroom where student devices are claiming their EDU student/teacher certificates are expired, and refreshing the EDU profile appears to fix the problem, but currently the only method I'm aware of for doing so involves reassigning the device to a different user and then assigning it back to the original user. That's obviously not going to work for thousands of devices.
How do I add a EULA (Our own) agreement at the login screen?
Just curious if anybody has tried adding Monterey to the Mac Apps and updating that way. I added it to our Mac Apps and put it in self-service, but it seems like you have to click the install twice. When you go there, click install, when it's done, the button changes to Open. The only way to kick it off is by clicking the Open button.
Hello, Just wondering if anyone else that uses Memcached with their Jamf Pro environment has found a way to enable authentication with memcached? Been searching and have not found any documentation on this. Thanks
We use Carbon Black App Control on our macs and I also have Chrome set up in the Jamf App Catalog. When Jamf tries to push Chrome out Carbon Black blocks it. My question is if Jamf fails to install Chrome via the App Catalog does it delete the installer .pkg file? The issue with getting Chrome whitelisted in Carbon Black is we can't get the hash for the files because it's gone after it fails. Also, is there a standard directory where Jamf puts the installers that we would possibly whitelist?
Is there a way to add an Active Directory user account using a Terminal command? Our normal workflow when on site is to:- log in as admin- bind the Mac to AD- log out of the admin account- have the user sign into their AD account at the macOS login screen, thus creating their user account and user profile. If we have a computer outside of our local network and need to add a network user account to a Mac, we have no way to do it. If we connect to the VPN logged into the admin account, we can hit our AD servers. But as soon as we log out of the admin account, or if we try to switch users or go to "login window..." the VPN connection drops and then we cannot add the network user account to the Mac. So my question is, is there a way to add an AD user account from Terminal? Is there a way we could log in as admin, connect to VPN, bind to AD and then add the user somehow without logging out of the admin account. We are looking at getting away from AD binding with Jamf connec
I've been trying to get the trial version of Jamf Connect Login to work since Wednesday and can't seem to figure out what I'm doing wrong. I even tried following Traveling Tech Guy's blog post : https://travellingtechguy.eu/jamf-connect-login-with-azure/ But the results are the same. Here's what's happening: Azure login window pops up asking for credentials. I put in my credentials. Next screen says create a new local password and verify with a greyed out Create Account button. Thing is - the moment I start typing the app goes black and starts over from the beginning. Any ideas?
Has anyone who is running on-prem Jamf been able to successfully configure and run with HSTS enabled? If so, I'd love to see your configuration. The following will now load any sub-pages such as inventory or policies. <filter> <filter-name>httpHeaderSecurity</filter-name> <filter-class>org.apache.catalina.filters.HttpHeaderSecurityFilter</filter-class> <init-param> <param-name>hstsIncludeSubDomains</param-name> <param-value>true</param-value> <param-name>hstsMaxAgeSeconds</param-name> <param-value>31536000</param-value> </init-param> <async-supported>true</async-supported></filter> <filter-mapping> <filter-name>httpHeaderSecurity</filter-name> <url-pattern>/*</url-pattern> <dispatcher>REQUEST</dispatcher></filter-
I was wondering if anyone has this set up in their environment? Most machines are Monterey, but there are a few Big Sur machines. I tried setting it up and was encountering a few issues. When I restart the machine, it does not read the Yubikey. Will I need a 2nd piece of software to allow it to log in from restart? Is it possible to leave the account as a local user, and still enforce the verification of certificate?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!