Get Support
Recently active
I am at a loss with this issue. I have uploaded a PLIST to JAMF and I am scoping it to my test machine. Chrome is showing that the policy is taking affect but it is not being enforced. ( I have attached a screen shot of the policy within Chrome). Here is the PLIST that I have configured <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict> <key>RestrictSigninToPattern</key> <array> <string>scsd2.com</string> </array></dict></plist> Anyone who could offer some advice would be greatly appreciated.
I have a new iMace that the user edits pages and numbers files off a windows SMB share. She is constantly getting a message that the file cannot be saved. I had assumed it was autosave, so I disabled that via the general settings in the system preferences. but the issue is still happening. the windows share is on a windows 2019 server. this was not a problem on her previous iMac that was replaced. any suggestions?
Hello, I am just starting with Jamf and was wondering if there is a way to put different options in configuration profile in order, set by me.Here's what I mean:We are trying to deploy a profile with 2 options:- Network, with PEAP configured to 'any ethernet'- Certificate with, well. A certificate. Our intention is to have users authenticate on the login screen, so they don't receive any additional pop ups. So far it looks like it works just fine, when the certificate is on the machine.However, because I deploy both certificate and network configuration in the same profile, it looks like sometimes the network part applies before the certificate is installed, which causes pop-up with 'choose certificate' to appear. So the question is - is there a way to deploy both options in 1 configuration profile, but delay the network part until the certificate is installed?If not, is there maybe any other way to achieve what we are trying to do? Thanks in advance
We currently use LANDesk/Ivanti for Windows management, but they're moving towards Intune. With that, they want to have one MDM for all devices. In the meeting I was just in, I explained briefly that when we tried that years ago pre-Jamf it was an awful experience for us and the users. Remote only worked 50% of the time, no ability to push software, etc.There's another meeting next week to discuss that more in-depth, and I'm currently writing up a justification for what we use Jamf for as I don't know if Intune can do all of it. They also mentioned that Ivanti might now be able to do better software packaging/remote access for Macs now compared to 6 years ago before we got Jamf. I really want to convince them to not go the Ivanti route, and only go with Intune if it can actually replace Jamf properly. We have about 450 Mac clients, plus at least 50 iPads, various iPhones, and a few Apple TVs we're managing through Jamf. Anyone who can speak on experience with this would be appreicated.
Example of today's headline: School bus driver who raped a 14yr old won't go to prison. We have suppressed the News App, we have turned off the Notifications for News. And still, the News Widget is splashing these "Headlines" across Student iPads.I have searched through Config Profile options for any reference to Widgets, not finding anything.Has anyone found a way to make it stop?
Has anyone managed to get IPP printing working from macOS?We are predominately a Windows shop and our print server is hosted on a Windows 2019 Server VM. As SMB is no longer a possibility, I set up an IPP queue on it and am attempting to send jobs to it from test Macs but nothing appears in the printer queue on the server.On the client side, when sending the job I see an information pop-up appear but I can't work out what it is saying as it disappears after half a second. I don't get the printer icon in the Dock like we used to with SMB printing.Is the IPP version on Windows compatible with later macOS revisions, or is this where third-party solutions come in (such as PaperCut etc.)?
I have to imagine this is coming, or maybe I missed something, but I cannot find a way in JAMF Pro 10.36.1 , to stop a user from connecting an iPad via Universal Control to their computer without restricting iCloud accounts. Does anyone has anyone have any knowledge on how to prevent this?
Does anyone have experience deploying printers in JAMF with Mojave? I've tried to use JAMF Admin to capture it, built a script using lpadmin, etc, and none of it works. There seems to be something missing. #!/bin/sh sudo lpadmin -p "PRINTER" -L "Location" -D "Printer Name" -E -v "ipp://<local_ip>" -P "/Library/Printers/PPDs/Contents/Resources/HP Color LaserJet M750.gz" There always seems to be something missing. When attempting to open the Print Queue, I'm prompted that the printer is missing software. When you try to install it, it looks like it is going to load, but never does anything beyond this.
We are thinking about switching from Apple MDM to JAMF and the municipality already has a JAMF server with regular Pro licenses, so my question is, can we add EDU licenses to the same server and select on device basis or do we need 2 separate servers. Can't find any clear info on it so I'll just ask here if anyone knows.
Hello Team,The project I am currently working in, has got some vulnerabilities with installed Apache Tomcat into the JSS serverThe Apache Tomcat needs to be upgraded. Could you please guide with the instruction process of upgrading the Apache? Thanks,Abhik
We are in the middle of migrating between Sophos and Defender and have observed a large percentage of our devices don't have the right Defender Configuration profiles required to onboard our devices. Defender has installed fine through policy, but can't work without its settings which are applied via Config profiles.The Config profiles for Defender on a lot of active machines were discovered to be "Pending" from the Configuration Profiles view within Jamf, but for most Macs, there are no pending Management commands from the Inventory view, and for some they simply sit there indefinitely saying Pending.I've managed to replicate the problem with really simple config profiles, such as some Finder config, without finding a fix. We've just upgraded to 10.34.0 in the hope it magically fixed things, but it hasn't.The devices affected are all active, checking in and updating inventory. There's no obvious commonality between devices affected, almost everything comes in th
Anyone having issues with using the Activation Lock Bypass Code from Jamf on Monterey? I have three Macs now on Monterey that I can't unlock with the bypass code. Get an error saying: "The operation couldn't be completed. Your Apple ID or password is incorrect." Tried on a Mac running Big Sur and the bypass code from Jamf worked to activate the Mac. With the computer erased and activated I installed Monterey, enabled Activation Lock through Find My Mac, erased it through Recovery and tried to activate using the refreshed bypass key from Jamf - got the error again. So looks like it may be a Monterey issue?I would expect the bypass key to work regardless of whatever Apple ID the Mac has been connected to so not sure why this check fails or is even made.Thanks.
We have implemented Shared iPads in our environment, and for some reason the Markup feature in Safari has disappeared. We've found that our normal 1:1 iPads in the environment have the feature, so we're trying to figure out if this is another Shared iPad "quirk" or if it's merely a setting we have that's accidentally restricting the feature.
I manage a retail shop's point-of-sale iPads and the POS software they use sometimes causes weird glitches with new updates which are fixed quickly usually. I know I can delay iOS updates but I can not figure out how to delay individual app updates or I would be happy with delaying all 3rd party app updates for a certain time. Is this possible?
Here we go again. Just a discussion on Software updates in 2022 rather than necroing an old post.How are you guys keeping up with OS updates and figuring out if devices failed patching or still processing? I'm over here still needing to manually check each device that is not running the OS build I am expecting and digging through the install.log if the MDM commands are showing as completed.JAMF still has not given us a way to deploy software update MDM commands via policy. Even after saying it was a possibility 10 months ago. Checking status requires going device by device and checking inventory records and if OS updates fail you get nothing as JAMF is not using the StatusUpdate key. Managed Software Updates - using deferrals via a m... - Jamf Nation Community - 249821Example mass action/remote command workflows moving forward: (Existing) Admins can issue a remote command to a set of devices to download and install to an upgraded version of macOS ASAP, restarting end-user machine
Hi, every file I package with Composer comes up with "this package is incompatible with this version of macos" when I try to install it manually on the same Mac I created it on. All I can find on this are solutions related to Cisco installs, this is happening on everything I try to package, eg Brave browser, Firefox etc, the process I follow is download the dmg from the vendors site being careful to make sure it's either silicon or intel specific, drag it into composer, convert to source then in source select build as package and save it to the desktop. I am only doing this for software I can't get the pkg for obviously. I am sure I am missing something simple here?
Is there as easy way to deploy single hot corner config , i need disable screensaver when cursor is moved to bottom right corner.Regards
Been noticing that Self Service has been failing and saw this in /var/log/jamf.logDevice Signature Error - A valid device signature is required to perform the operation.I'm not seeing any expired certificates anywhere, in fact they were just renewed only a few months ago. I did sudo jamf -enroll -prompt. That got SS working again, but I need to understand what happened or where to check what might be expired, missing, etc.Some of these are machines that were JUST enrolled through the pre-stage enrollment that was set up by our Jamf consultant.
We'd like to remove having a local administrator account on our computers but I'm wondering how you might've addressed the issue of SSH/Remote Management/Screen Sharing access in your environments. The obvious answer seems to be a policy to create a temporary Admin and then remove it with another policy when it is done being used, but this isn't viable when there is an immediate need. I'd need to wait for the policy to run before getting access. Thoughts?
Can not find much on this, but hoping to find a way to send email to the assigned user of a client, as soon this client becomes part of a specific smart group.The user assigned to the device is in jamf Pro, so should somehow be possible. Wondering if anyone has something running ?
The university I work for has purchased Jamf Pro and as my department is in charge of physical device management and software I've been tasked with setting it up. However, it looks like they only purchased Jamf Pro and did not purchase Jamf Connect as well.It seems like half of what the Jamf team was selling us on with like Zero-Touch deployment was something you can only do by utilizing Connect as well, but then we were only quoted and purchased Jamf Pro.My question is, what can I realistically accomplish with Jamf Pro without Connect vs with Connect? Zero-touch deployment? Software management? Security? MDM?
Sorry, If this is a simple one. From Where I can download the Jamf Composer? I want to use the composer to package the Self Service application.
hello :),has anyone an idea why the command was not forwarded to the specific Self Service application to which I added below? Actually, I’ll be forwarded to the Self-Service home screen but not this specific URL. launchctl asuser $uid sudo -iu $loggedInUser open jamfselfservice://content?entity=policy&id=10&action=view oropen jamfselfservice://content?entity=policy&id=10&action=view
I have a supervised iPhone enrolled with a blueprint that has "Prevent Changes to Bluetooth" checked. Bluetooth was ON when settings were applied and I can see the Bluetooth option in Settings > Bluetooth is greyed out with the text "some restrictions are enforced by admin". This is the expected behavior but the issue is I can still turn on/off Bluetooth via the control center. Is there a way to restrict this?
Hello! I accidentally modified the Scope on my installation of Procreate, and by the time I fixed it, the app had been uninstalled and re-installed. The new installation works fine, but all of the saved app files (".procreate" art project files) are gone. I work with students, and a lot of them are very upset about their work being deleted. Is there any way to recover deleted app files like this through JAMF? Or to restore files from the "trash" on the device? I've already checked the "Recently Deleted" folder on the iPad. And its worth noting that these devices were NOT logged into an iCloud account, so restoring an iCloud backup is not an option here.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!