Get Support
Recently active
I know there are some topics and solutions to lock Profiles, but none of them are working right now to prevent users from removing MDM Profile and uninstall Jamf from the company laptop.May be someone can advise and help what is the solution for Ventura to lock removing MDM Profile option? We are not using ADE, thats why cant select option to disallow removing MDM. Please help guys.
The following is a conversation between myself and Jamf, trying to get some more detailed information surround the Jamf Installer Preview. I hope this conversation is helpful to other admins who are exploring this new functionality.Me:I know that this feature is still in preview and more work is still being done before Jamf pulls it out of Preview.I've been communicating with other Mac Admins within the MacAdmins Slack Community regarding app installers and there was a little bit of confusion regarding some of the backend processes of how Jamf App Installers are being pushed down to end-user systems.I've read through the following links trying to dig deeper into app installers:https://community.jamf.com/t5/jamf-pro/jamf-pro-10-37-is-now-available/td-p/261726https://www.jamf.com/solutions/app-lifecycle-management/https://www.modtitan.com/2022/03/in-weeds-with-app-installers-preview.htmlhttps://www.jamf.com/blog/jamf-app-installers-faq/So my question presently, is if Jamf can provide eit
I'm looking to see if there is a way to configure Microsoft Teams notifications in Jamf, specifically the notification style. For those unfamiliar, in Microsoft Teams, there is a setting where users can choose either the Mac APNS notification, or the built-in notification system in Teams. To change this, click on the three dots next to your icon in the header bar in Teams, and choose Settings. In the Settings window, click on Notifications, and select the Notification style. I've scoured the internet to see if there is a way to configure the notification style within Jamf to deploy to managed Macs, and unfortunately I have not had much luck. It appears Teams sets the notification style to "Teams built-in" by default. In this case, I 'm looking to accomplish two things:1. Change the default notification style to "Mac" instead of "Teams built-in"2. Deploy the aforementioned setting in Jamf so that ea
Hello everyone, We have a really frustrating issue and so far nothing worked. We are moving from Intune MDM to Jamf MDM, but we are using Conditional access so the integration between Jamf and Intune must exist. The problem is that if you forget to remove the entries from Intune after resetting the device and you try to run the integration script you will receive an error, and from that point nothing will work.Steps to reproduce: Have an entry of an macbook enrolled with intunewipe the macos and add it to Jamf serverRun the integration scripCompany portal will opensign in with AAD usercomplete the steps on screen and you will receive an errorReset the logs for integration scripRun again the script and after finishing company portal steps "Authentication for JamfAAD" prompt will openA browser should open at this point, but nothing happens What we tried so far:Change default browserDelete the entries from Jamf/Intune/AAD of the targeted device, Wipe de device and ret
Hi folks, just curious if anyone has come across an easy graphic matrix indicating the difference between Jamf Now and Jamf Pro licenses?Thank you!
Significantly enhanced Completion Action options help to provide your users a seamless post-enrollment experience when setting up their new MacsIntroductionSetup Your Mac aims to simplify initial device configuration by leveraging swiftDialog v2 (or later) and Jamf Pro Policy Custom Events to allow end-users to self-complete Mac setup post-enrollment via Jamf Pro’s Self Service.Completion ActionsIn addition to the previous wait and sleep options, Setup Your Mac (1.4.0) introduces nine new Completion Action options (and you'll end up only using one). Continue reading …
It seems the value of the "Date Lost Mode Enabled" column in device inventory is incorrect in my Jamf Pro.The value of the device which has never been enabled Lost Mode seems to be the enrollment time instead of lost mode enabled.This problem happens on all 4000 devices in my environment. Is this a known bug?
We are seeing the expiration password counter. But some of our end-users see a -22 (for example) counter in the menu bar, or after a successful password change, there is a wrong number of days.How to fix it.
Hi there, I'd like to know if it's possible to configure smart groups in a way to apply a specific smart group ONLY when a device has just been enrolled. The issue we're having is Sophos Endpoint has 2 custom mobileconfig policies. 1 for MacOS Monterey and 1 for MacOS Ventura. I have a simple smart group setup that separates Monterey and Ventura devices Problem is, if someone were to upgrade their OS, their current Sophos installation will still be installed but the configurations for Sophos mobileconfig for Monterey will be removed and replaced with the Ventura mobileconfig. Since the configs are applying AFTER Sophos has already been installed this would undoubtedly break Sophos' permissions on the machine. Is there any way to have a smart group only apply immediately after enrolment and no other time? This is to make sure that when devices with Ventura installed have been freshly installed that they get the Ventura configuration only and not devices that upgrade
Hello everyone,I have created configuration profile, that has network pane and scep certificate pane.The network pane has all the settings for connecting to the 802.1x wifi and scep certificate pane is used for distributing the certificate to the system so that it could be used for authenticating the wifi .Now the problem here is ,everything is working fine except the prompt that we are getting to select the certificate for connecting the wifi .We should not get that prompt while connecting the wifi that is what I believe.Note : Our certificate is getting deployed on the system keychain and also when we manually select the certificate then we are able to connect the wifi network ,but the only thing is that we need to skip that certificate selection process.Any help would be much appreciated !
Hey everyone,Is there any good resources on how to setup/test Connect?I've confirmed that the Azure AD Client ID and tenant info are correct when using the Jamf Connect Config tool. It gives me tokens for OIDC and ROPG and shows successful each time. I also can confirm there is a login entry within Azure for the user.I read that it's best to have 3 config profiles pushed to the device: Connect, Login, and License.However, the license isn't applied and sign in is greyed out.Is there any best practices/guide that could be shared?
I already know that Jamf protect have Analytics for MRT but its not pulling any information on Antivirus. Does anyone have any custom Analytics for that? We have mix environment where different machine have different AVs and we want to find out if there is a way to tell if the AV is installed and which one.
Can I have some help, please? I am using the google apps script and I wanted our URL for JAMF we wanted to connect with our username and password so we can auth to JAMF to help us get the data into the Google app script. I wanted to get some data from the app script I can use this data on google data studio, please? Thank you
I am fairly new to Jamf and inherited a system that someone else set up. I am looking for guidance with regards to Local Admin accounts.We have one account that is set up in Global > User-initiated enrollment > macOS. This works fine on enrollment.However, there is a second Local Admin account that is created by a Policy that runs at enrollment, startup and check-in.To me this seems like overkill, but to make sure I wanted to get some insights from the community.Do we need two Local Admin accounts? Would the first one be sufficient? What are the advantages and disadvantages of having two?Thanks.
So we have a user who lost her local password, and it's now out of sync with the online account.What are our options?
I'm trying to create a plist for adobe reader to remove the cloud storage options to remove Add File storage. I found some links and an old thread here back from 2020, but thought I would start a new one. I created a plist file using Xcode with some examples I found online. I created a package in composer to add it to /Library/Preferences. I deploy it and it adds the plist com.adobe.Reader.plist to the location, but doesn't remove any options. I've tried restarting as well. This is first .plist I've tried creating. Old ThreadFeatureLockdown on Acrobat Reader DC. - Jamf Nation Community - 229645Solved: Disable online services/features in Acrobat Reader... - Adobe Support Community - 7113756
How is the below code / script to be used in conjunction with the Jamf API?Also, the url "yourserver".jamfcloud.com - I've tried our server name but no go. We used to be on-prem and now we're jamfcloud, anyone know of to get the name it's looking for?Thank you! curl --request POST \\--url https://yourserver.jamfcloud.com/api/v1/macos-managed-software-updates/send-updates \\--header 'accept: application/json' \\--header 'content-type: application/json' \\--data '{"skipVersionVerification": false,"applyMajorUpdate": false,"forceRestart": false}'
When I try to upload Microsoft Office BusinessPro installer it gets to 99% and then hangs. I don't seem to have any issue with any other packages, just this one. I tried leaving overnight on one attempt and it was still on 99% in the morning.Microsoft_Office_16.67.22111300_BusinessPro_Installer.pkg I had the same issue last month with the previous released package. (sourced from https://macadmins.software)I've tried this from our work network and from home and have the same issue. Also tried redownloading the package a couple of times. Even tried renaming it. Still the same issue.Oddly enough, a colleague of mine was able to upload without any issue.
My company recently updated their Keynote template. I used Jamf Composer to create a snapshot package where I used the Keynote app to manually save the theme as a template. I saved it as a DMG, and applied it to a policy that Fills existing users. It does exactly what I expect, placing the .kth file in the user Keynote directory (~/Library/Containers/com.apple.iWork.Keynote/Data/Library/Application Support/User Templates). However, upon opening Keynote.app, the theme does not appear in the Theme Chooser. The final strange detail is that on the same computer I've been testing the policy on, if I create a new user before running the policy that has never opened Keynote before, the template does appear in the Theme Chooser on that second account, but will still not appear in Keynote on the first account. I'm very new to this so please don't hesitate to suggest that I've made a mistake that seems dumb or obvious to you, it's entirely possible. I'll take any and all advice and appreciate
Before I make my first ever post, I checked to see if anyone else has posted this. I did not see anything. Hopefully I searched correctly. I can add printers to my Macs, using the Terminal command line, or create a script in Jamf to add the printers. Same result. Here is an example of the command. lpadmin -p Tech_Room_55_Printer -L "Tech Room 55" -E -v lpd://10.100.105.92 -P /Library/Printers/PPDs/Contents/Resources/HP Color LaserJet M651.gz -o printer-is-shared=false I don't think I need to explain the contents of that command to any of you. Except to say, I want to add a Xerox printer in this case that uses AirPrint. I am connecting Macs, not iOS. When I add the printer manually, using the IP address, I end up with a default printer icon. When I use AirPrint, I get the full icon that represents the actual printer. My question is, how would I add a printer using a command line and tell configure it with AirPrint. I will keep tinkering.
Hi All,Does anyone know if it is possible to lock iPads which are in a certain group?We have a 'No Owner' smart group and we would like to be able to lock iPads inside this group to prevent use. I've searched through the various profile settings and nothing is jumping out at me sadly...Cheers
I am able to get CBDefense to install just fine however with Apple newest updates we have to go to security preferences and hit Allow. They have a recommendation on their site for this issue it says: " For enterprise deployments where it is necessary to distribute software that includes kexts without requiring user approval, you will need to configure the Apple Team IDs for our Carbon Black Products in your MDM Profile" My question is how am I able to do that? This is my first time having to do anything like that. Thanks!
Hi there, Is there a simpler way to install Ventura via self-service without the admin credentials? I've added Ventura from the Mac apps section on Jamf and it is available on self service but it requires admin credentials to install.
I have a user that made an iCloud backup before wiping his iPhone 12 and reinstalling it. During the following setup the device was enrolled into Jamf (DEP + prestage). He also restored the iCloud backup and everything seemed to work ok. I can see it was enrolled 9/7/22 0907 am and last inventory update was 9/7/22 0908 am. Since then the iPhone doesn't communicate with Jamf anymore.It's running iOS 15.0, Jamf is v10.39.1. the device is still managed and supervised.
Can anyone guide me on how to use jamf pro and add devices to Jamf pro on a windows device. Any Help will be appreciated
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!