Get Support
Recently active
Can anyone guide me on how to use jamf pro and add devices to Jamf pro on a windows device. Any Help will be appreciated
I have a policy that joins a computer to the domain automatically when it is enrolled. This policy worked up until today and now I am receiving the same error message on all new Macs. I searched the error code and it says that 5103 usually means that the hostname is too long for AD but our hostnames are all 10 characters long... Has anyone run into this issue before? We tested windows machines and they work fine so I am not sure if this issue is from the AD server side or MacOS. Here is the error message. Thank you to anyone with suggestions
i see an article for Jamf School but i couldn't find anything for Jamf Pro. if available, can you provide a link for the documentation, we are trying to identify induvial users IDs for proxy server exemptions.
Hi,I now had two of my Users being locked out of their devices a day or so after turning on FileVault via Jamf. Nothing could get me back in. Has anyone had similar problems? Kind regardsAndreas Baumeister
Hi all,Just trying some API integration and the local Jamf account we have configured for API will not authorize to generate a token on our API page:https://mycompany.jamfcloud.com/api/doc/It just keeps saying "Authorization failed." and wondered if it's the privileges on the account. We have it set as follows:Read-Only on all Server Objects (apart from API intergrations which is set to create, read and update).No permission for any Server SettingsNo permission for any Server ActionsAm I missing something? Any help appreciated!
Hi all,Just started using Jamf connect with Google login. Our Jamf Connect login configuration profile is using the option to "Create all new users as local administrator."That is working. When it creates a new user it makes them a local admin. problem is if you do a "Network login" with the same user, it converts it back to a Standard user.If you do a "Local login," it works and does not remove administrator rights
Hello All,Do we have a method or Script to make changes in the Software Update Pop-up window?I would like to change the word "administrator" to something "your login credentials"Thank you.
A user has left their iPad in a location they cannot recall on the way back to the office. I am attempting to set lost mode, but it isn't staying enabled. I am assuming it is nowhere near or connected to wifi hotspot so the command cannot be sent to the device. Kind of a useless feature if this is the case. I am not sure location services are setup on the device either.
Apple has changed where Time Machine data is stored in the latest OS and how that data is organized. I've modified the original JAMF Extension Attribute to accommodate Apple's changes in Mavericks. The XML is ready for upload. I've only tested this in the Casper Suite 9.2 but it should work fine in any version that supports Extension Attributes. https://dl.dropboxusercontent.com/u/874171/TimeMachineLastBackupCompleted.xml.zip Cheers,Chad NielsenForget Computers
Hi,since our mac mini caching servers are run out of storage we're curious if it's possible to have an external volume for cache storage or other options. We#Ve already tried to use the "Content Caching" payload and entered Data Path "/Volumes/nameofexternaldisk/Cache" which didn't work with the error that the profile wouldn't install because of a wrong Data Path. Does anybody have a suggestion here?Best RegardsJonas
I have a scenario whereby I need the Jamf Pro server to execute some action, and pass on this information to the client.It should work like this -client is triggered to install 'policy A' --> client asks Jamf Pro server for infromation X (which is needed by the client to complete the policy installation) --> Jamf Pro executes some script/API call to a separate internally-hosted webservice --> Jamf Pro recevies the output from the webservice and passes it to the client The webservice is not publicly accessible, thus the client is unable to reach it, and has to rely on the Jamf Pro server to make the API call on its behalf. Is this somehow possible?
I have a policy to install a package, which I want to make available to all computers via Self Service, but I only want it to automatically install (e.g. via enrollment trigger) for some computers only.Can this be done somehow, without having 2 different policies? (e.g. 1 policy for Self Service, another policy for enrollment trigger) I presume, when configuring the scope of a policy, it applies to both 'trigger' and 'Self Service' scenarios.
Has anyone had this issue with Jamf Connect? It is becoming a widespread problem within our organization. This (attached photo) will pop up upon login and you can't make it go away. We thought updating everyone 2.12 would solve this problem but it's still happening. The only fix that we've found that works is going in and manually re-installing (via Jamf id site) the latest version. I'd like to avoid manually re-installing for our whole environment so any help/ideas would be greatly appreciated.
This morning we had a student lose their iPad. It was found and it was in lost mode, and I was able to remove the lost mode. The problem is, it didn't make a sound. We would have found it hours before if it played the sound. It was on and the volume was up. Also, the location wasn't showing up in Jamf. Any ideas on why, or how we can fix it?
I am setting deferred updates from jamf the com.microsoft.autoupdate2 configuration profile and typically pause the updates to give time for testing. Does anyone know if I send select to Pause the update at like 16.66 will jamf profile push any of the patches for that version?Recently Office 16.66.0 was released and the next day the 16.66.1 patch came out to resolve a launch issue. I rather not pause at 16.66.0 and then have a bunch of launch issues since it doesn't send the patch update.
I've been tasked with some CIS recommendations for our apple estate. I am currently mulling over the firewall parts of this. Do you guys enable firewalls in your estate? It seems like a no-brainer, but this isn't windows and i don't know how much it really helps on the mac side. There are a lot fewer programs actively listening for ports and connections. Also with that, if i implement it now, what programs would it break? How do you guys handle this? Do you find its good to have one or not worth it?
While trying to send data from Jamf to SCCM, I am getting the following errors:- [ 5] ERROR Jamf.ProxyService.Plugins.SCCM.SccmReports - There was an unexpected error sending the device to SCCM.- System.InvalidOperationException: Invalid registration state: Error. Cannot continue.We are using version 3.70 of the plug-in and SCCM version is 2111I have look through quite a few of the support articles and I am seeing various information, but none of them ever offer a solution and they just end. When I use the Jamf SCCM Proxy Service Helper and try to just send one machine manually I get different error.- [ 67] ERROR Jamf.ProxyService.Plugins.SCCM.Utilities.Certificates - There was an unexpected error sending the device to SCCM.- System.InvalidOperationException: Invalid registration state: Error. Cannot continue.
On Windows, you can set general DNS search suffixes (i.e. suba.domain.com, subb.domain.com, etc). Then there is also a "Connection-specific DNS suffix" setting the DNS server can share when the machine connects to the network (i.e. site1.suba.domain.com) depending on your office location. On Macs it seems to let you either take what the network gives you (which is limited to 1 entry) or use a longer list of manually specified options. Is there a way to mimic the Windows functionality of having a few general search domains which are set by script or config profile, but let the local network set a local search domain?
Hello Jamf experts! I am primarily a Microsoft Intune/SCCM admin. I also manage our Jamf Pro environment for MacOS. We currently use a SCEP Cert Profile in intune tied to an NDES server to deploy an 802.1x certificate to allow our azure joined Windows devices access to our on premise domain. We currently have our macs bound to the domain to allow a cert request for this. We recently got our Jamf Connect setup going and have no reason to bind to the domain anymore. I have read the documentation on how to set up Jamf Pro as a SCEP Proxy but I am NOT a mac expert and don't really understand what needs to be put in the fields of this setup. I'm assuming the URL is the Scep Server Url . I'm not sure what to put in for Name, Subject, Subject alternative Name Type, or what options I should choose, or what Certificate I should use as the Signing Certificate. I'm lost. I opened a ticket with Jamf Support and they sent me the link to the
i have a script that runs software update via JamfHelper, however I cannot get the actual software update command (via API) to run untiless the JamfHelper window is quit. Anyone know how to run a process while still keeping the JamfHelper window open/active? my syntax is as follows: /Library/Application\\ Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper \\ -windowType hud \\ -lockHUD \\ -title "macOS Security Updates" \\ -heading "macOS Updates Now Installing" \\ -description "Installation can take up to 45 minutes.. Close and save your work now." /usr/bin/curl -s -X POST -H "Content-Type: text/xml" -u ${apiUsername}:${apiPassword} ${jamfProURL}/JSSResource/computercommands/command/ScheduleOSUpdate/action/install/id/${jamfProCompID}
I am working to update our Lightspeed Relay cert and need to create a folder to house the .pem files. And I’m in over my head on this one. Kinda, sorta adept at Composer, but not enough to pull this off. Any help will be appreciated.
Hello,I'm having an issue with an app which is Downloaded from the Mac app store through VPP on Jamf. The app MSG viewer for Outlook creates files in /private/var/folders/.../T/.....Cwd.bundle. Several of the files that get created in this temporary folder are quarantined including Cwd.bundle. If the quarantine flag is removed from the Cwd.bundle file it works until next reboot when the files are removed. I have tried working with the vendor but they believe it has something to do with 3rd party security software on our Macs. I though the problem might be related to translocation, but I don't see how that would be an issue with an app directly from the app store. If I download their software directly from their site the problem does not occur AND no files are written in /private/var/folders at all. I'm just looking for a solution. I've tried various profiles to allow apps from this vendor including using PPPC utility and allowing all but this does not resolve. Any sugge
Hi all, I know this isn't the NoMAD Login support channel but just asking on the off chance anyone else out there has found a workaround to this issue since Jamf Connect is the commercial version of NoMAD. When using a Macbook Air (M1), the NoMAD Login screen randomly goes off center with black bars on 2 sides as if the resolution of the background image is smaller than the screen's and it isn't "stretching" to fill. No other Google result out there except for a single report here about 9 months ago which remains open.
Here is how I check for macOS updates, install the recent available and reset Jamf Connect login window.- Requires a local admin username, PID and password.Create a Script in Jamf Pro. #!/bin/zsh -i vers=$(sw_vers -productversion) install=$(softwareupdate --list-full-installer | sed -n '3p' | tr : '\\n' | tr , '\\n') name=$(echo "$install" | sed -n '2p' | sed -e 's/^[ \\t]*//') number=$(echo "$install" | sed -n '4p' | sed -e 's/^[ \\t]*//') if ls /Applications/Install\\ macOS* 1> /dev/null 2>&1 ; then rm -rf /Applications/Install\\ macOS* fi if [[ "$number" > "$vers" ]] ; then echo "Installer available $name $number." launchctl asuser <ADMINPID> sudo -u <ADMINUSERNAME> softwareupdate --fetch-full-installer --full-installer-version $number if [[ -d "/Applications/Install $name.app" ]]; then echo <ADMINPASSWORD> | "/Applications/Install $name.app/Contents/Resources/startosinstall" --agreetolicense --forcequitapps --nointeraction --user <AD
just curious if anyone has ran into this scenario. before purchasing jamf, i already had filevault enabled for my mac users, I was saving the recovery key to a safe somewhere in our environment. now that i have jamf, i want jamf to manage those keys with its filevault profile. would i need to decrypt my devices? and re-encrypt upon enrollment so that jamf can manage those encryption keys?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!