Get Support
Recently active
Hi,I need to block all Mac OS upgrades for 30 days. I followed the document below to build a new Configuration Profile to defer updates of Only major software updates.Deferring a macOS Update - Managing macOS Updates | JamfI cannot find anything that tells me what is included in Major Software Updates. Is there a list of what is included in major software updates anywhere? Will building a configuration profile as described in the document block the Mac operating system from upgrading?Thank you!Rob
Have had a few occasions where certain team members at my office needed to uncheck the box to join networks automatically but then were given this admin prompt.
Hi All hoping someone might be able to help. We have been struggling with pushing out OSX updates for sometime.It does appear Apple want to make this more difficult than it should be. I understand on Ventura, mass action software update commands will run when the machine is ideal I.e not been used.However I can’t find anywhere in Apple documentation that this is the case. Is anyone able to confirm this?
Hi there,We're having an issue removing activation lock from one of our macs, the previous user was logged in to iCloud with their personal Apple ID meaning we can't reset the device.When booting into recovery we've selected - Recovery Assistant - Erase Mac - And proceeded with the eraseWhen it loads back up to the recovery menu - Recovery Assistant - Activate with MDM Key - we enter the activation lock key from Jamf but it says "this operation could not be completed because your apple ID or password are incorrect"The window where we are being asked for the key is definitely asking for the MDM key and not an apple id/password.Anyone seen this before/can shed any light?Thanks
Provide users with detailed feedback with this automated script to remove Acrobat's Add-in from Microsoft Office via Jamf Pro Self ServiceBackgroundWhen we implemented Microsoft’s recommended macro security in Office for Mac settings via a Configuration Profile some time ago, we also started offering users @pbowden's Office-Reset packages via Jamf Pro’s Self Service, which have been working like a champ.However, each time Adobe Acrobat Pro is installed or updated, the Acrobat Add-in silently finds its way back into the user’s Microsoft Office-related User Content folders, and since the Add-in relies on external dynamic libraries — which we purposely disable by setting DisableVisualBasicExternalDylibs to true — users observe error messages in the following applications:Microsoft WordMicrosoft ExcelMicrosoft PowerPointContinue reading …
HelloDoes any know how to Inventory collection a hidden folder in applications. Bomgar creates a .com folder that the user cant see.Thanks
Hi,maybe somebdy has a guide on how to remove / uninstall Jamf AD CS Connector, so i could set it up from scratch again?
As of macOS 11 (Big Sure) and macOS 12 (Monterey) the appstore extract script doesnt work due to changes in the directory structure and the manifest.plist files not being downloaded. This updated script (v.3.1) resolves this issue and prompts the script use to type in a name to name the PKG and DMG like that of the previous naming convention. https://github.com/blakeusblade/MacAdminHelpers/tree/master/AppStoreExtract
Hey Gang,My organization is trying to go passwordless by utilizing Touch ID and Ubikeys. Everything is working but there is an issue with chrome. It seems in chrome you are able to bypass MFA with Touch ID using your local password. Below is an example of what I am talking about. This defeats the purpose of MFA by allowing user to just use their password twice. I want to know if anyone else came across this issue or if there was any key value pair that can be deployed in a config profile via jamf to block this. Probably a long shot but thought I'd throw this out into the ether incase anyone else is facing the same challenges. I am also going to reach out to google and okta about this. The Touch ID interface in Chrome for Okta MFA Best regards,Cameron
Can we add packages to the JSS thru the API?
So I am using the API calls to Pull a computer ID. Here is the API Page with the Computer information. JSSURL:8443/JSSResource/computers/serialnumber/#########/subset/general -----<computer> --<general> <id>3258</id> <name>Hugonaut</name> <mac_address>##:##:##:##:##</mac_address> <alt_mac_address>##:##:##:##:##</alt_mac_address> <ip_address>#.#.#.#</ip_address> <last_reported_ip>#.#.#.#</last_reported_ip> <serial_number>########</serial_number> <udid>########</udid> <jamf_version>10.#</jamf_version> <platform>Mac</platform> <barcode_1/><barcode_2/> <asset_tag></asset_tag> <remote_management></remote_management> <mdm_capable>true</mdm_capable> <mdm_capable_users/> <report_date></report_date> <report_date_epoch></report_date_epoch> <report_date_utc>#</report_date_utc>
Using AutoPkg 2.7 and Git 2.21.1 and JamfUploader with AutoPkgr 1.6 and trying to use a recipe for Zoom.Running into a lot of deprecated messages. Does anyone have a working recipe?
Hello fellow Jamfs,Attempting to enroll AppleTvs for the first time, iPads are enrolling fine. I have a seperate Pre-Stage for my AppleTvs and manually assigning TVS to TV pre-stage I created. But when I try to enroll TVs I get "Invalid Profile" anyone seen this and any possible solutions? I'm skipping all the tvos options in the pre-stage so not sure where the invalid profile is coming from. Thanks everyone
I am attempting to install a printer via self service. It fails each time. I am installing through a policy which would install the drivers from a Xerox package then add the printer via Jamf to the print list. I have added the logs below. Any ideas? Mon Feb 11 12:46:00 iMac jamf[331]: Failed to set the attributes of Library/Preferences/com.jamfsoftware.selfservice.plist: Error Domain=NSCocoaErrorDomain Code=4 "The file “com.jamfsoftware.selfservice.plist” doesn’t exist." UserInfo={NSFilePath=Library/Preferences/com.jamfsoftware.selfservice.plist, NSUnderlyingError=0x7f85cbe04a90 {Error Domain=NSPOSIXErrorDomain Code=2 "No such file or directory"}}Mon Feb 11 12:46:03 iMac jamf[3387]: Checking for policy ID 85...Mon Feb 11 12:46:05 iMac jamf[3387]: Executing Policy MS-MFP-809Mon Feb 11 12:46:06 No Name jamf[3387]: Verifying package integrity...Mon Feb 11 12:46:07 No Name jamf[3387]: Installing Xerox Print Driver 4.22.2.pkg...Mon Feb 11 12:46:16 No Name jamf[3387]
We have found the lock command for computers in Jamf is letting our students around the lock by restarting their computers. With an Intel Big Sur machine the lock command will restart it to the EFI password screen, we can enter the EFI password and continue to the white passcode screen or we can restart and get returned to the EFI password screen again. Intel Monterey machines shut down and restart to the EFI password screen; if we put in the EFI password it goes to the gray passcode screen showing the message we set with the code, if we hold the power button and restart it the Mac will boot normally and the student can continue using it despite us having locked it.
Apple released an update for Safari and my guess is there will be Security updates shortly.How are admins updating these?Thanks for any help.
Hi, We are trying to find a way to un-install BitDefender via JAMF, and not use the manual uninstaller on 180 users. Has anyone had any experience on doing so?
Hello,we're starting to deploy Jamf Connect and it went well so far for the employees at home, but today I noticed that we cannot connect to our offices wifi from the Jamf Connect Login window, meaning that we can't connect from Jamf Connect to our macbook pros at the office.We use Radius wifi at the offices with AD credentials. If we login local offline on the macbook, we can then connect to the wifi from mac preference system, but the Jamf Connect Login window refuses the same credentials to connect to the wifi.The network department have no idea why the login window could be restricted from using the radius wifi. Note that we tried 3 different accounts and different macbooks ending with the same results.We also tried with the "devices" network, which is WPA2, doesn't require a username, only a password and this one works. But this network is not supposed to be used by employee macbooks.Am I missing something ? To my understanding, it doesn't make any sense at all.
Hey All, Has anyone been able to get DEP with Directory Binding to work. We are using Active Directory, that is only accessible internally. We are only trying to get this to work for internal use. Meaning we will be having employees set up their computers internal only. The weird part is the machines will go through the DEP process successfully. Install the Framework, and run the enrollment scripts. The only thing it won't do is Bind the machine to AD so that the user can log in with an AD account, instead of a Local account. Im using the same Binding settings we use in our Casper Imaging WorkFlows, so I'm confused on why it doesn't work. Any suggestions/thoughts would be greatly appreciated. Also what logs can I look at for DEP specifically. Thanks Shawn
Anyone running JAMF Connect with Microsoft O365 backend? Looking to see what experiences people are seeing. We are wanting to login to JAMF Connect (with Azure AD) and then pass that SSO token to all apps (Outlook, Teams, Onedrive) so the users do not have to authenticate to each app.
I am trying to create an extension attribute to grab the currently logged in user on my student machines. I am using a similar script to the Last User extension script template: #!/bin/sh user=`ls -l /dev/console | awk '/ / { print $3 }'` if [ $lastUser == "" ]; then echo "<result>Current User</result>" else echo "<result>$user</result>" fi I have my inventory set to check at login so I can set the extension attribute to the user short name as they sign on. However, when I collect inventory at login, I only get "root" as the currently signed in user. After the user signs in, I can run "sudo jamf recon" from an ssh session as the local admin and it appropriately records the current user in the extension attribute. Why does it show "root" when I run the script at login, vs when I run the script after the user has signed in? Is the inventory collected prior to a user technically be
Hello Jamf Nation, Today we are releasing Jamf Pro 10.42. Highlights of this release include: Declarative Device Management Support Apple's Declarative Device Management is a modern management protocol that allows managed devices to proactively and autonomously apply their own management settings with less communication from the Jamf Pro server. When you upgrade to Jamf Pro 10.42.0, Declarative Device Management is automatically enabled on eligible devices. Configuration Profiles for Managed Login Items Jamf Pro now includes two predefined configuration profiles containing Managed Login Items payloads, installed by default on eligible computers in System Settings > Privacy & Security > Profiles. These configuration profiles prevent end users from disabling certain background services of apps installed by Jamf in System Settings > General Settings > Login Items > Allow in the Background. App Installers Enhancements This release introduces s
How do I enable BonjourI have a script to disable it,#! /bin/bash defaults write /Library/Preferences/com.apple.mDNSResponder.plist NoMulticastAdvertisements -bool truedo I just reverse it or delete the .plist file
Hello, When trying to activate a new Mac that was added to the PreStage Enrollment we get the following error : Mac Activation - The request timed out. Which ports needs to be opened in order to activate Mac for PreStage Enrollment on our Proxy?Would it be the albert.apple.com:443 as mentioned in this article? https://support.apple.com/en-ca/HT210060 Any help would be appreciated. Thank you!
When I try to log-in to Jamf admin app on my mac, it just shakes and says my username & password isn't correct.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!