Get Support
Recently active
We are in the middle of migrating between Sophos and Defender and have observed a large percentage of our devices don't have the right Defender Configuration profiles required to onboard our devices. Defender has installed fine through policy, but can't work without its settings which are applied via Config profiles.The Config profiles for Defender on a lot of active machines were discovered to be "Pending" from the Configuration Profiles view within Jamf, but for most Macs, there are no pending Management commands from the Inventory view, and for some they simply sit there indefinitely saying Pending.I've managed to replicate the problem with really simple config profiles, such as some Finder config, without finding a fix. We've just upgraded to 10.34.0 in the hope it magically fixed things, but it hasn't.The devices affected are all active, checking in and updating inventory. There's no obvious commonality between devices affected, almost everything comes in th
Anyone having issues with using the Activation Lock Bypass Code from Jamf on Monterey? I have three Macs now on Monterey that I can't unlock with the bypass code. Get an error saying: "The operation couldn't be completed. Your Apple ID or password is incorrect." Tried on a Mac running Big Sur and the bypass code from Jamf worked to activate the Mac. With the computer erased and activated I installed Monterey, enabled Activation Lock through Find My Mac, erased it through Recovery and tried to activate using the refreshed bypass key from Jamf - got the error again. So looks like it may be a Monterey issue?I would expect the bypass key to work regardless of whatever Apple ID the Mac has been connected to so not sure why this check fails or is even made.Thanks.
We have implemented Shared iPads in our environment, and for some reason the Markup feature in Safari has disappeared. We've found that our normal 1:1 iPads in the environment have the feature, so we're trying to figure out if this is another Shared iPad "quirk" or if it's merely a setting we have that's accidentally restricting the feature.
I manage a retail shop's point-of-sale iPads and the POS software they use sometimes causes weird glitches with new updates which are fixed quickly usually. I know I can delay iOS updates but I can not figure out how to delay individual app updates or I would be happy with delaying all 3rd party app updates for a certain time. Is this possible?
Here we go again. Just a discussion on Software updates in 2022 rather than necroing an old post.How are you guys keeping up with OS updates and figuring out if devices failed patching or still processing? I'm over here still needing to manually check each device that is not running the OS build I am expecting and digging through the install.log if the MDM commands are showing as completed.JAMF still has not given us a way to deploy software update MDM commands via policy. Even after saying it was a possibility 10 months ago. Checking status requires going device by device and checking inventory records and if OS updates fail you get nothing as JAMF is not using the StatusUpdate key. Managed Software Updates - using deferrals via a m... - Jamf Nation Community - 249821Example mass action/remote command workflows moving forward: (Existing) Admins can issue a remote command to a set of devices to download and install to an upgraded version of macOS ASAP, restarting end-user machine
Hi, every file I package with Composer comes up with "this package is incompatible with this version of macos" when I try to install it manually on the same Mac I created it on. All I can find on this are solutions related to Cisco installs, this is happening on everything I try to package, eg Brave browser, Firefox etc, the process I follow is download the dmg from the vendors site being careful to make sure it's either silicon or intel specific, drag it into composer, convert to source then in source select build as package and save it to the desktop. I am only doing this for software I can't get the pkg for obviously. I am sure I am missing something simple here?
Is there as easy way to deploy single hot corner config , i need disable screensaver when cursor is moved to bottom right corner.Regards
Everyone learns differently, and at Jamf we want to meet you where you are. This may mean comprehensive written documentation. It may take the form of multimedia content like videos or podcasts. One of the best ways to practice a tool is to use it – navigate the interface, explore objects, discover new features, make mistakes, and learn from the experience. That’s why we’re offering new opportunities to train with our products in the form of software simulations. We want to provide realistic and meaningful learning experiences for new and seasoned users. Software simulations allow you to familiarize yourself with the interface, objects, and workflows without the worry of compromising your own server. In a simulated environment, we can provide guidance and tooltips. If you lose your way, we can help get you back on track. You’re in the virtual driver’s seat, and in a safe environment to practice before returning to manage your own fleet. At the Jamf Nation User Conference
Been noticing that Self Service has been failing and saw this in /var/log/jamf.logDevice Signature Error - A valid device signature is required to perform the operation.I'm not seeing any expired certificates anywhere, in fact they were just renewed only a few months ago. I did sudo jamf -enroll -prompt. That got SS working again, but I need to understand what happened or where to check what might be expired, missing, etc.Some of these are machines that were JUST enrolled through the pre-stage enrollment that was set up by our Jamf consultant.
We'd like to remove having a local administrator account on our computers but I'm wondering how you might've addressed the issue of SSH/Remote Management/Screen Sharing access in your environments. The obvious answer seems to be a policy to create a temporary Admin and then remove it with another policy when it is done being used, but this isn't viable when there is an immediate need. I'd need to wait for the policy to run before getting access. Thoughts?
Can not find much on this, but hoping to find a way to send email to the assigned user of a client, as soon this client becomes part of a specific smart group.The user assigned to the device is in jamf Pro, so should somehow be possible. Wondering if anyone has something running ?
The university I work for has purchased Jamf Pro and as my department is in charge of physical device management and software I've been tasked with setting it up. However, it looks like they only purchased Jamf Pro and did not purchase Jamf Connect as well.It seems like half of what the Jamf team was selling us on with like Zero-Touch deployment was something you can only do by utilizing Connect as well, but then we were only quoted and purchased Jamf Pro.My question is, what can I realistically accomplish with Jamf Pro without Connect vs with Connect? Zero-touch deployment? Software management? Security? MDM?
Sorry, If this is a simple one. From Where I can download the Jamf Composer? I want to use the composer to package the Self Service application.
hello :),has anyone an idea why the command was not forwarded to the specific Self Service application to which I added below? Actually, I’ll be forwarded to the Self-Service home screen but not this specific URL. launchctl asuser $uid sudo -iu $loggedInUser open jamfselfservice://content?entity=policy&id=10&action=view oropen jamfselfservice://content?entity=policy&id=10&action=view
I have a supervised iPhone enrolled with a blueprint that has "Prevent Changes to Bluetooth" checked. Bluetooth was ON when settings were applied and I can see the Bluetooth option in Settings > Bluetooth is greyed out with the text "some restrictions are enforced by admin". This is the expected behavior but the issue is I can still turn on/off Bluetooth via the control center. Is there a way to restrict this?
Hello! I accidentally modified the Scope on my installation of Procreate, and by the time I fixed it, the app had been uninstalled and re-installed. The new installation works fine, but all of the saved app files (".procreate" art project files) are gone. I work with students, and a lot of them are very upset about their work being deleted. Is there any way to recover deleted app files like this through JAMF? Or to restore files from the "trash" on the device? I've already checked the "Recently Deleted" folder on the iPad. And its worth noting that these devices were NOT logged into an iCloud account, so restoring an iCloud backup is not an option here.
Hi Team,Did anyone tried to upgrade openSSL for all the mac Endpoints with the current version 3.0.7? I wanted to upgrade the same for all mac endpoints which are enrolled with jamf pro as the current or the older versions are detected with the vulnerability.Any help will be highly appreciated.
Hi All,Has anyone come across Crowdstrike Falcon failing to install on macOS Ventura? I have downloaded v6.44 from the Crowdstrike console and when trying to install it manually on my systems it fails.. It also fails on v.645. ThanksRob
So we don't give users admin for obvious reasons and Sketch comes out with updates almost weekly at this point. The problem is their files are only compatible with the version they were made in.I haven't worked autopkg into my workflow yet (I know!) so I wrote this todaySelf service update script is as follows !/bin/sh Update Sketch Application - Created by Justin Repasky 03-03-2016 #### Remove any older versions of sketch-updates folder and re-create if test -d "/Applications/Utilities/IT/sketch-updates/" then rm -Rf "/Applications/Utilities/IT/sketch-updates/" | mkdir -p "/Applications/Utilities/IT/sketch-updates/" ;else mkdir -p "/Applications/Utilities/IT/sketch-updates/"fi; cd "/Applications/Utilities/IT/sketch-updates/"sudo curl -O http://download.sketchapp.com/sketch.zip /Applications/Utilities/IT/sketch-updates/sketch.zip; sudo unzip sketch.zip; if test -d "/Applications/Sketch.app" then sudo rm -R
Greetings,I'm familiarizing myself with PreStage Enrollments, and while for the most part it's going well, there are a couple things I was hoping to get some feedback on.The first may be a simple setting that I'm just missing - applying a Mac's previous name once the enrollment is complete (or during if that's where it needs to take place). For example if I had a Mac called "Mac-99" that's in my Jamf Pro system, and I wipe it, once the PreStage Enrollment is complete (or during) is there a way to apply it's previous computer name "Mac-99" to it? Right now, it gets placed back into it's previous groups, and it get its previous Config Profiles applied back to it. However it does not receive its previous name, and now has the default macOS assigned name of "iMac".The second conundrum I'm facing it trying to get a post-enrollment script to run that correctly enables ARD, and grants all access to the local admin account that gets created during the enrollment. The ac
Hi,I try to enable Remote Control for Big Sur with a script. I try that : /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -configure -access -on -allowAccessFor -specifiedUsers /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -configure -users admin -privs -DeleteFiles -ControlObserve -TextMessages -OpenQuitApps -RestartShutDown -SendFiles -ChangeSettings /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -restart -agent -menu /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate With Apple Remote Desktop I have a black screen. I run this command :tccutil reset ScreenCapture No more black screen. But, I can observe, but not control! 😅
Hi, I'm looking for a way to bypass the SSO login so that supporters can log into Self Service to use policies assigned to them.Currently, the user is automatically logged in when the login button is pressed in Self Service, which is also desired, but logging in again, e.g. to log in a supporter in Self Service, is not possible, because the logon is immediately made to the user again.My only approach so far is a script in the JC Menubar with kdestroy and then open the Self Service.This would also be a good method if I could get a new Kerberos ticket after ~30 seconds (after the supporter could log in).However, if I put such a long running script in the JC Menubar, it completely blocks the execution of the JC Menubar for that period, which I want to avoid.Example from my tests:( kdestroy && open jamfselfservice:// ) && ( sleep 30 && open jamfconnect://gettickets )as I said ... it works, but it's not pretty and I hope someone already has a better method for this.T
When I click on a device in Jamf Pro, some of them refuse to open. All I get is the spinning wheel. Some devices I click on do open. It's rather hit or miss. I've left the page open for 30 minutes hoping it would eventually open...nope.
Might overlap https://jamfnation.jamfsoftware.com/discussion.html?id=4701 In the past when we made monolithic images (before the enlightened days of Casper) I would install the OSX Server tools and then use it to add all domain users - an AD group - to the local printer admin group on a bound machine. Then I'd unbind, remove the Server Tools, do all the other prep and make an image of it all. When the image was applied and the target Mac rebound to AD the Print Admin group was happily respected and I'd never get calls about paused print queues. Yay! I win!Ok, so now I want to push a configuration out via Casper. How do I emulate this process? I want to make an AD group a member of a local group during imaging or pushed out with Casper remote or Self Serve or maybe even good old' ARD.Can I? Thanks for reading.- Scott
I'm sick of JAMF timing out and already upvoted the feature request for adding a session timeout...My issue is that the logout takes me to a page (https://mydomain.biz:8443/logout.html) and I have to goto the address bar, remove the logout.html and hit return, then relog.It would be nice if it logged out to the login page for our JSS.Does anyone have any workarounds or know if a feature request in process, etc?Thanks for any help.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!