Get Support
Recently active
Hello all, I am noticing that after a Mac is sitting on a Jamf Connect Login screen after a restart for an unknown amount of time, when someone attempts to login, they get an error with a message to contact their administrator. If the user clicks "Refresh" they are then able to log in. My best guess as to what is happening is that the login website window is that is called up when a Mac restarts is timing out after a certain amount of time, and clicking restart loads it again and makes it active again. I've had to add a note to the login screen background for the user to click "Refresh" if they get an error. If my guess as to the cause is correct, then some type of automate refresh might be a solution. Has anyone run into this and come up with any other solution?
Hello everyone, I'm new to this community so please bare with me if this has been asked before. I'd like to deploy a script that can check what chip is installed on my Mac mini fleet and if needed, install it. Thanks in advance.
Hello all, It's come to my attention that students (mainly in the HS) have figured out that they can right-click in Chrome, select "Inspect", and somehow, manipulate how their grades look. The change what they want and take a screen shot to show their parents, teachers, or whomever. It's all to get out of work. I've not seen it done as of yet. Is there a way to disable this feature that you're aware of? I can't find much in Google Admin about it. Thank you for your insights!
Has anyone ran across a solution to hide the Wi-Fi icon in the menu bar on Catalina? Disabling Wi-Fi was an easily-fulfilled request but hiding the icon is proving to be challenging. I've ran through the suggestions linked below, but nothing has been successful yet: Hiding the WiFi icon in the menu barRemoving Wifi Menu Icon A common suggestion in those threads was editing /Library/Preferences/com.apple.systemuiserver.plist but that doesn't appear to be included in Catalina or Mojave from what I can tell.
The Mac OS X Security Checklist posted by JAMF Software (link below) is nice, but where's the accompanying technical paper that shows customers how to implement the recommendations referenced? Some community members have the knowledge to just run with the bulletpoints, but some don't. Even for those of us who do, it would be a great value add to have these things documented so all we have to do is test rather than research, create, and test. Mac OS X Security Checklist
I am hoping to be able to restrict using iCloud Drive and Find my Mac. I used iMazing Profile Editor to create a plist file that I could use in a configuration profile. The profile works as it should for iCloud Drive, but it does nothing for Find my Mac. I don't want users storing company documents in iCloud Drive, and I do not want Find my Mac turned on. FMM has made getting Macs repaired through Apple a pain if it's turned on. I found a thread here discussing restrictions for iCloud. It included a link to a Github page that has a profile that looks promising. It doesn't work either. That page is here: https://github.com/ducksrfr/mac_admin/blob/master/profiles/disable_icloud_services.mobileconfigI can totally lock out the ability to use iCloud completely, but I really don't want to. I'm trying to disable the things that can cause security issues, or difficulty for the users on the networks that we manage. Has anyone been able to successfully stop Find my Mac from being used
Upgraded to 10.18.0 and no longer getting mobile device app catalog updates? You're likely running into PI-007928. Below is a script you can run against your Jamf Pro instance to identify apps in your catalog that are out-of-date. Then, at least, you'll know which apps to manually update. https://github.com/cwmcbrewster/Jamf_API_Scripts/blob/master/JSS_API_check_app_versions.sh EDIT: Here is a second script that will update the app versions for you. The script waits for user input to verify the change but you could easily remove that if you're feeling confident. You'll need an API account that can read and update mobile device applications.https://github.com/cwmcbrewster/Jamf_API_Scripts/blob/master/JSS_API_update_mobileapp_versions.sh
Adobe Enterprise now has the option to create a pkg for Apple Silicon devices. With this option, I assume the below workflow for creating a pkg for Apple Silicon devices is no longer needed? I do not see the InstallationCheck when I go into resources. https://helpx.adobe.com/enterprise/kb/deploy-packages-to-arm-devices.html When I create a new pkg(Just Adobe CC) and run manually on a M1 device with Rosetta2 installed it installs correctly. I am also able to install necessary apps if needed. However when I upload the same pkg and run via a policy on the same device with Rosetta 2 installed it fails and I get the following message. Installation failed. The installer reported: installer: Package name is AdobeCreativeCloud_NamedM1_04162021installer: Installing at base path /installer: The install failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurred while running scripts from the pa
I did a search on this topic and the only thing I could find was almost three months old.We are beginning to introduce M2 computers into our company and before I move ahead with installing Jamf Pro, I wanted to check and see if there are any current issues with Jamf that I need to be aware of.Thanks.
Recently it's been discovered that once you upgrade to VenturaOS you have to re-apply full disk access permissions for Crowdstrike Falcon and Netskope security applications in system preferences even if they were enabled before the update. Would the only way to be to:1) Create a VenturaOS computer smart group2) Create a new policy/config profile to apply PPC settings for Netskope / CS3) Scope the new policy/config profile to the new smart group to apply once users update. Also, does anyone know a way to verify if the PPC went through once pushed from Jamf? Currently we're using Configuration profiles to enable PPC but not getting great results and hard to find where it fails since they don't provide logs like policies.
Hi All,I have just upgraded from Monterey to Ventura, has anyone seen where after the upgrade there is a list of items/app that was added to the "Login Item Settings"Is there a way to suppress these?
I am trying to create a smart group to find computers that have local user accounts that don't match the company standard user accounts. We have a specific format that our user accounts are so I need to be able to use wildcards.
As new macOS versions/updates are released, I create a a smart group for each version. As such, I created a smart group to keep track of which Macs have Ventura installed on them. The only criteria for this smart group is that the operating system version is 13.0.0. As I've done in the past for previous smart groups, I also set up this smart group to send me email notification on membership changes.The issue I'm having is that this smart group is CONSTANTLY sending me false-negative email notifications of Macs leaving the group and then shortly afterwards rejoining the group.Anyone have any idea why this is happening??
Does anyone know the correct Bash command to upgrade to Big Sur? I tried using "/Applications/Install macOS Big Sur.app/Contents/Resources/startosinstall --agreetolicense --forcequitapps --nointeraction" but it just hangs.
We have noticed with our Jamf pro system that at times when we send commands to our ipads not all of them receive the command. For example we push certain configurations profiles let say to a 100, 80 will get the configuration but 20 will fail. this kind os sporadic behavior happens quite often with us. we have looked and looked and not able discover what could be the issue. This morning our ipads refuse to talk back to Jamf, we pushed an application to 20 devices and Nothing, then push an inventory command and no result. 20 our 30 minutes later out of the 20 ipads 4 of them installed the app. Any suggestion or recommendations?Thank you Luis
So I have a request for assistance for 2 things. Is there a script or configuration to either lock or hide the Passwords Pane in the macos12 version?I have the same question above but for the erasing all contents option in the dropdown located in system prefs in macos12? Specifically, I don't want the admins to interact with it in any shape or form. Any assistance is appreciated.
Hi,I need to block all Mac OS upgrades for 30 days. I followed the document below to build a new Configuration Profile to defer updates of Only major software updates.Deferring a macOS Update - Managing macOS Updates | JamfI cannot find anything that tells me what is included in Major Software Updates. Is there a list of what is included in major software updates anywhere? Will building a configuration profile as described in the document block the Mac operating system from upgrading?Thank you!Rob
Have had a few occasions where certain team members at my office needed to uncheck the box to join networks automatically but then were given this admin prompt.
Hi All hoping someone might be able to help. We have been struggling with pushing out OSX updates for sometime.It does appear Apple want to make this more difficult than it should be. I understand on Ventura, mass action software update commands will run when the machine is ideal I.e not been used.However I can’t find anywhere in Apple documentation that this is the case. Is anyone able to confirm this?
Hi there,We're having an issue removing activation lock from one of our macs, the previous user was logged in to iCloud with their personal Apple ID meaning we can't reset the device.When booting into recovery we've selected - Recovery Assistant - Erase Mac - And proceeded with the eraseWhen it loads back up to the recovery menu - Recovery Assistant - Activate with MDM Key - we enter the activation lock key from Jamf but it says "this operation could not be completed because your apple ID or password are incorrect"The window where we are being asked for the key is definitely asking for the MDM key and not an apple id/password.Anyone seen this before/can shed any light?Thanks
Provide users with detailed feedback with this automated script to remove Acrobat's Add-in from Microsoft Office via Jamf Pro Self ServiceBackgroundWhen we implemented Microsoft’s recommended macro security in Office for Mac settings via a Configuration Profile some time ago, we also started offering users @pbowden's Office-Reset packages via Jamf Pro’s Self Service, which have been working like a champ.However, each time Adobe Acrobat Pro is installed or updated, the Acrobat Add-in silently finds its way back into the user’s Microsoft Office-related User Content folders, and since the Add-in relies on external dynamic libraries — which we purposely disable by setting DisableVisualBasicExternalDylibs to true — users observe error messages in the following applications:Microsoft WordMicrosoft ExcelMicrosoft PowerPointContinue reading …
HelloDoes any know how to Inventory collection a hidden folder in applications. Bomgar creates a .com folder that the user cant see.Thanks
Hi,maybe somebdy has a guide on how to remove / uninstall Jamf AD CS Connector, so i could set it up from scratch again?
As of macOS 11 (Big Sure) and macOS 12 (Monterey) the appstore extract script doesnt work due to changes in the directory structure and the manifest.plist files not being downloaded. This updated script (v.3.1) resolves this issue and prompts the script use to type in a name to name the PKG and DMG like that of the previous naming convention. https://github.com/blakeusblade/MacAdminHelpers/tree/master/AppStoreExtract
Hey Gang,My organization is trying to go passwordless by utilizing Touch ID and Ubikeys. Everything is working but there is an issue with chrome. It seems in chrome you are able to bypass MFA with Touch ID using your local password. Below is an example of what I am talking about. This defeats the purpose of MFA by allowing user to just use their password twice. I want to know if anyone else came across this issue or if there was any key value pair that can be deployed in a config profile via jamf to block this. Probably a long shot but thought I'd throw this out into the ether incase anyone else is facing the same challenges. I am also going to reach out to google and okta about this. The Touch ID interface in Chrome for Okta MFA Best regards,Cameron
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!