Get Support
Recently active
Can we add packages to the JSS thru the API?
So I am using the API calls to Pull a computer ID. Here is the API Page with the Computer information. JSSURL:8443/JSSResource/computers/serialnumber/#########/subset/general -----<computer> --<general> <id>3258</id> <name>Hugonaut</name> <mac_address>##:##:##:##:##</mac_address> <alt_mac_address>##:##:##:##:##</alt_mac_address> <ip_address>#.#.#.#</ip_address> <last_reported_ip>#.#.#.#</last_reported_ip> <serial_number>########</serial_number> <udid>########</udid> <jamf_version>10.#</jamf_version> <platform>Mac</platform> <barcode_1/><barcode_2/> <asset_tag></asset_tag> <remote_management></remote_management> <mdm_capable>true</mdm_capable> <mdm_capable_users/> <report_date></report_date> <report_date_epoch></report_date_epoch> <report_date_utc>#</report_date_utc>
Using AutoPkg 2.7 and Git 2.21.1 and JamfUploader with AutoPkgr 1.6 and trying to use a recipe for Zoom.Running into a lot of deprecated messages. Does anyone have a working recipe?
Hello fellow Jamfs,Attempting to enroll AppleTvs for the first time, iPads are enrolling fine. I have a seperate Pre-Stage for my AppleTvs and manually assigning TVS to TV pre-stage I created. But when I try to enroll TVs I get "Invalid Profile" anyone seen this and any possible solutions? I'm skipping all the tvos options in the pre-stage so not sure where the invalid profile is coming from. Thanks everyone
I am attempting to install a printer via self service. It fails each time. I am installing through a policy which would install the drivers from a Xerox package then add the printer via Jamf to the print list. I have added the logs below. Any ideas? Mon Feb 11 12:46:00 iMac jamf[331]: Failed to set the attributes of Library/Preferences/com.jamfsoftware.selfservice.plist: Error Domain=NSCocoaErrorDomain Code=4 "The file “com.jamfsoftware.selfservice.plist” doesn’t exist." UserInfo={NSFilePath=Library/Preferences/com.jamfsoftware.selfservice.plist, NSUnderlyingError=0x7f85cbe04a90 {Error Domain=NSPOSIXErrorDomain Code=2 "No such file or directory"}}Mon Feb 11 12:46:03 iMac jamf[3387]: Checking for policy ID 85...Mon Feb 11 12:46:05 iMac jamf[3387]: Executing Policy MS-MFP-809Mon Feb 11 12:46:06 No Name jamf[3387]: Verifying package integrity...Mon Feb 11 12:46:07 No Name jamf[3387]: Installing Xerox Print Driver 4.22.2.pkg...Mon Feb 11 12:46:16 No Name jamf[3387]
We have found the lock command for computers in Jamf is letting our students around the lock by restarting their computers. With an Intel Big Sur machine the lock command will restart it to the EFI password screen, we can enter the EFI password and continue to the white passcode screen or we can restart and get returned to the EFI password screen again. Intel Monterey machines shut down and restart to the EFI password screen; if we put in the EFI password it goes to the gray passcode screen showing the message we set with the code, if we hold the power button and restart it the Mac will boot normally and the student can continue using it despite us having locked it.
Apple released an update for Safari and my guess is there will be Security updates shortly.How are admins updating these?Thanks for any help.
Hi, We are trying to find a way to un-install BitDefender via JAMF, and not use the manual uninstaller on 180 users. Has anyone had any experience on doing so?
Hello,we're starting to deploy Jamf Connect and it went well so far for the employees at home, but today I noticed that we cannot connect to our offices wifi from the Jamf Connect Login window, meaning that we can't connect from Jamf Connect to our macbook pros at the office.We use Radius wifi at the offices with AD credentials. If we login local offline on the macbook, we can then connect to the wifi from mac preference system, but the Jamf Connect Login window refuses the same credentials to connect to the wifi.The network department have no idea why the login window could be restricted from using the radius wifi. Note that we tried 3 different accounts and different macbooks ending with the same results.We also tried with the "devices" network, which is WPA2, doesn't require a username, only a password and this one works. But this network is not supposed to be used by employee macbooks.Am I missing something ? To my understanding, it doesn't make any sense at all.
Hey All, Has anyone been able to get DEP with Directory Binding to work. We are using Active Directory, that is only accessible internally. We are only trying to get this to work for internal use. Meaning we will be having employees set up their computers internal only. The weird part is the machines will go through the DEP process successfully. Install the Framework, and run the enrollment scripts. The only thing it won't do is Bind the machine to AD so that the user can log in with an AD account, instead of a Local account. Im using the same Binding settings we use in our Casper Imaging WorkFlows, so I'm confused on why it doesn't work. Any suggestions/thoughts would be greatly appreciated. Also what logs can I look at for DEP specifically. Thanks Shawn
Anyone running JAMF Connect with Microsoft O365 backend? Looking to see what experiences people are seeing. We are wanting to login to JAMF Connect (with Azure AD) and then pass that SSO token to all apps (Outlook, Teams, Onedrive) so the users do not have to authenticate to each app.
I am trying to create an extension attribute to grab the currently logged in user on my student machines. I am using a similar script to the Last User extension script template: #!/bin/sh user=`ls -l /dev/console | awk '/ / { print $3 }'` if [ $lastUser == "" ]; then echo "<result>Current User</result>" else echo "<result>$user</result>" fi I have my inventory set to check at login so I can set the extension attribute to the user short name as they sign on. However, when I collect inventory at login, I only get "root" as the currently signed in user. After the user signs in, I can run "sudo jamf recon" from an ssh session as the local admin and it appropriately records the current user in the extension attribute. Why does it show "root" when I run the script at login, vs when I run the script after the user has signed in? Is the inventory collected prior to a user technically be
Hello Jamf Nation, Today we are releasing Jamf Pro 10.42. Highlights of this release include: Declarative Device Management Support Apple's Declarative Device Management is a modern management protocol that allows managed devices to proactively and autonomously apply their own management settings with less communication from the Jamf Pro server. When you upgrade to Jamf Pro 10.42.0, Declarative Device Management is automatically enabled on eligible devices. Configuration Profiles for Managed Login Items Jamf Pro now includes two predefined configuration profiles containing Managed Login Items payloads, installed by default on eligible computers in System Settings > Privacy & Security > Profiles. These configuration profiles prevent end users from disabling certain background services of apps installed by Jamf in System Settings > General Settings > Login Items > Allow in the Background. App Installers Enhancements This release introduces s
How do I enable BonjourI have a script to disable it,#! /bin/bash defaults write /Library/Preferences/com.apple.mDNSResponder.plist NoMulticastAdvertisements -bool truedo I just reverse it or delete the .plist file
Hello, When trying to activate a new Mac that was added to the PreStage Enrollment we get the following error : Mac Activation - The request timed out. Which ports needs to be opened in order to activate Mac for PreStage Enrollment on our Proxy?Would it be the albert.apple.com:443 as mentioned in this article? https://support.apple.com/en-ca/HT210060 Any help would be appreciated. Thank you!
When I try to log-in to Jamf admin app on my mac, it just shakes and says my username & password isn't correct.
Hi, can someone provide guidance on how i can collect data on if someone is using mail app for google or microsoft exchange setup through internet accounts. and if they are force logout. thank you
Good afternoon,I am doing some research into why a small number of machines in our fleet were missing a specific product that should have been installed upon enrollment. I've determined a couple of things already but there are a number of endpoints that are checking in that seem to have this specific policy stuck in a 'pending' state. I was hoping to be able to remotely flush each log for the affected machines but those options are greyed out since its in the 'pending' state. Is there a simple way for me to clear out the pending status on each and force it to run again from the backend?ThanksD
Hello All, If there is already another thread dedicated to this please point me in that direction, I don't mean to duplicate them.I'm very new to Jamf prestage enrollments, so I am doing a lot of testing. Basically I have taken one of our new Macbooks out of the box and am using it as the testing device. I have been enrolling it, then making changes, then wiping from Jamf Pro, then enrolling again. Sometimes this works as if the computer is new out of the box and sometimes it doesn't. Many times it is as if Jamf remembers the machine even though I delete it. I have also tried unassigning the device in apple manager, sometimes this works sometimes not. Does anyone have a workflow for this that works every time? Basically I want to enroll the device see what happens, then make changes and do it again.
Hi, I registered a few devices via Self Service and the Device Compliance to our Azure AD. The registration process is fine and the devices show up after 2-3 min in Azure, but it takes many hours or a day that the device is marked as compliant? There is just "N/A". As long as the status isn't marked as compliant the user can't access apps which are restricted to company devices that must be compliant. Does somebody have the same issues? I think it is not related to AzureAD because Jamf checks the compliance criteria by itself and send it to AAD. The devices are listed in the Smart Group with the compliance criteria's. Best regards, Jonny Update: As you can see in the following image, the device was not updated until the next day. The screenshot is from the AAD Audit Log. First the device is marked as "managed" and on the next day as "compliant".
I have an environment where we are deploying Chrome Enterprise, not enrolled in CBCM, and we need to enforce the RelaunchNotification Chrome policy. I have the following plist for you viewing pleasure:<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>updatePolicies</key> <dict> <key>global</key> <dict> <key>UpdateDefault</key> <integer>0</integer> </dict> <key>com.google.Chrome</key> <dict> <key>UpdateDefault</key> <integer>0</integer> <key>TargetVersionPrefix</key> <string/> <key>RollbackToTargetVersion</key> <string/> <key>TargetChannel</key> <string/>
I am using shared iOS devices using Setup/Reset and Microsoft Authenticator.I would like to get one of the profiles the ability to delete and reinstall apps on demand due to the problem of app configs only being deployed as a part of app deployment.I found I am able to uninstall an application not through long hold and delete but only settings general storage then deleting the app. The app isnt reinstalling on its own however. I tried deploying the self service app but that app doesnt seem to see any configurations and isnt showing any catalog.Is this possible, or is there a better way?
Hello everyone.I am deploying Snapcomms, a screensaver-type application to be used by our communications department. The pacakge is installed successfully, but it needs access to PPPC settings. I am using the command codesign -dr - /Applications/Snap\\ Client.app to get information about what settings to utilize. These are the settings I got: However, the deployment errors with this message:In the payload (UUID: EF17794A-9081-4D7B-944F-EAA52BDA761F), the key 'CodeRequirement' has an invalid value.I contacted the company's support, but we don't have any new information yet.I am looking for suggestions in case someone has already deployed Snapcomms with Jamf or suggestions about troubleshooting this issue.Regards!
I have been trying to get auto cert selection working in Safari for a bit. I could not see a solution in a plist, so I believe an Identity Preference in Keychain would be the next bet.I have been struggling to find any type of documentation on this. I basically am looking for a solution to auto select the Microsoft Office cert for all Office logins. I have tried using *.microsoftonline.com (with and without slash), and several other variations... To the full URL and it does not seem to work.Anyone have any tips on auto cert selection for Safari? Much appreciated in advance
I have been using Cisco Security Connector for iOS without issue for the past year. After updating to iOS 16, it is no longer filtering Safari. It does appear to be filtering system level web traffic, but Safari is bypassing the filter. Has anyone else experienced this issue? I've been looking through the changes in JAMF related to iOS 6 and cannot find anything pertinent to the issue.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!