Get Support
Recently active
I am reaching out to see if anyone is running into the issue about SSO not working on Beta Versions in Ventura. Thinking this will work when fully released? Not sure if this a normal when testing the Beta OS's. Ignore or Cancel it still prompts right away or sometime after 15 mins or so. AppSSOAgent looks like is not even running since it keeps quitting. Any Ideas be helpful, thanks
I have a static group created that is used for my students communication app needs. One of my students continually deletes the app from his iOS device. How can I keep him from deleting the app? Under device functinality - I do have Allow removing apps unclicked.
Hi all,We have one iPad Air 2 which is connected to JamF School and successfully updating, sending profiles, apps etc - but it's stuck in Lost Mode. We've tried the Disable Lost Mode command, and it goes from Pending to Sent, then to NotNow. Has anyone seen this before and been able to get a device out of Lost Mode? We've tried clearing the restrictions, clicking clear pass code, restarting the device multiple times - but it's still in Lost Mode. It auto-connects to the WiFi on restart and pulls down the latest profiles from JamF - so it's not a connection issue to the server. Is there any way we can find out what NowNow means?! Thanks, James
I just want to change our password policy to 12 characters length. And we wanted to to know who it will affect. Meaning if I have a password that is 16 length will it make me change it. I Wanted to see if there was a smart group or attribute that we can make to make sure that it won’t affect the people who have more than what is needed. Also I wanted to know if I do change the policy will it only affect new users or make everyone change it.
We installed ARD for several new hires and in one instance the set of buttons that include UNIX are greyed out.This was installed using the App Store which claims 6 installations under "Family Sharing" but doesn't seem to list machines like I see for my iCloud.I don't think enabling Family Sharing is the fix since the problem machine wasn't the most recent installation.Any ideas?
Hi there, how can I add a shortcut, to open the camera in QR scan mode, to the home screen? Would be nice if it would had a custom icon too.Best, Volker
Hi Everyone,I am looking to see if anyone has a JSON handy for using with Google Chrome on macOS so that we can configure items on it like default home page, blocking chrome extensions & blocking chrome sign in ability ? Thanks in advance :-)
We have enrolled a good number of macs without the Prevent user from enabling activation lock setup in our pre-stage.We will be turning this on in the pre-stage, but for existing Jamf enrolled macs we will be using a mass action: Disable and prevent Activation Lock remote command. Is any way to verily on the mac that the command is working and user is prevent from activation locking the mac? I see in Systems information it a says activation lock is disabled but I want to confirm the user can not enable it by logging into icloud.
Good morning,So I'm not that familiar with certs, but we are setting up ISE system, and we need each machine to have its own trusted cert from our PKI. While i use JAMF I'm not that familiar with Certs. I have read trough the below, but still not sure how to push out a Unique trusted cert to each MAC. I have done things with JAMFs internal CA for the mac but never an PKI.https://docs.jamf.com/10.25.0/jamf-pro/administrator-guide/PKI_Certificates.htmlAny Documentation or resources? EDIT: I did find the below. Would Setting up AD CS allow us to generate a Unique Cert Per machine? https://docs.jamf.com/technical-papers/jamf-pro/integrating-ad-cs/10.40.0/Distributing_a_Certificate_Using_a_Configuration_Profile.html
Hi Jamf Nation,We have released Jamf Teacher 6.1.1/3.1.1This latest Jamf Teacher update includes the ability to launch a remote class via FaceTime to support video conferencing from within the appCheck out the full release notesAutomatic URL meeting links for Remote Classes using FaceTimeTeachers can now create automatic URL meeting links for Remote Classes using FaceTime.The following enhancements were also added:Teachers can create a remote class for specific students using FaceTime.After creating a Remote Class, teachers can now choose to immediately open the class by clicking Open Class , or they can continue in the FaceTime app.Students can now receive notifications to join Remote Classes using FaceTime.Teachers can now configure the duration of a Remote Class.Improved FaceTime error messages.Bug Fixes and Enhancements:Wallpapers no longer display unexpectedly in the sidebar.Teachers can now navigate back to the sidebar after accessing the Discover section.When navigating to
We use DEPNotify pretty heavily for onboarding. I do have a custom script I have been using for almost 2 years now. We had the 12.3 issue so we removed the python line from all of our scripts. Now the registration screen is showing blank all of a sudden even with the default script from here. https://github.com/jamf/DEPNotify-Starter/blob/master/depNotify.sh and the latest version of DEPNotify. Just shows Register the Mac now with no textbooks or no dropdowns very similar to the 12.3 issue but it is getting the appropriate current user. This happens confirmed on MacOS 12.5 and 12.6 \\
Hi everyone,I just enrolled devices into a Smart Group in JAMF Pro but I did not mean to. I did it via adding a new criteria and adding everything that wasn't already in the group. Does anyone now how to undo this or at least how I can go through the group and manually take out the devices I don't want in the SG? When I go into the History tab in the SG, I can see what I've done:ID 4 Name .................. EFB iPad Prestage Type Smart Group Membership Criteria ... 'Enrollment Method: PreStage enrollment' is not 'EFB iPads'
Safe and secure Mac management worldwide The world has changed during COVID times. Nearly all of us work at remote locations for multiple days a week. Our devices travel along and pop up at any location anywhere on earth. And also, because of the general availability of the internet, this behavior is now generally accepted. As Apple admins, we must think about managing Macs and rethink which switches to flip. We have already covered a lot of security policies: our devices are registered in Apple Business Manager, they are managed in a device management server, we implemented security policies based on CIS benchmarks, and we enforce FileVault encryption — just to name a few steps we already have taken to increase the level of management and security. Apple admins need to keep all devices as secure as possible, so next, we decided to rethink those local admin accounts. No account, no risk These are accounts on the Macs with a — hopefully — secure password and administrative acce
I was using Patch Managment to install zoom and when this ran on my workstation I received a Popup to allow Jamf access to Installer.We are running JAMF 10.41.0 (cloud instance) and I have had PPPC for JAMF agent for a long time. not sure what has changed.
does anyone have any experience/feedback using google AD?
Hi, I use a script to stop the Office 2016/2019/2021 first run popups but the only popup that still appears is the 'YOUR PRIVACY MATTERS'. What would i need to add to the script to not have this popup appear?#!/bin/sh# Office 2016/2019/2021 for Mac presents "first run" dialogs to the user to market some of its new features.# This script will suppress these "first run" dialogs using the following settings:## Setting: kSubUIAppCompletedFirstRunSetup1507 – boolean value (true / false)# Function: Suppresses the "What’s New" dialog for Office 2016 applications' first launch## Setting: FirstRunExperienceCompletedO15 – boolean value (true / false)# Function: Suppresses additional "What’s New" dialog for Outlook and OneNote.# Note: That is a capital letter O in "O15", not zero15.## Setting: SendAllTelemetryEnabled – boolean value (true / false)# Function: Suppresses the offer to send crash reports to Microsoft## Source for settings:# http://macops.ca/disabling-first-run-dialogs-in-office
Hello! I recently took over a Jamf environment hosted on-premise windows, Jamf Pro v10.34.2 and I have noticed a pretty high frequency(over 3000) of errors tied to a child Tomcat service, specifically this error in our logs com.jamfsoftware.jss.exceptions.mdm.InvalidMDMMessageException: Error processing request action:StatusUpdatePlist, CmdUUID:4eecbfdc-625b-4919-b3bc-19d00c3e1d9c, SigVerified: false. Returning 500. I would assume this is tied to HTTP 500 errors which indicate failed connections due to unexpected conditions, has anyone else experienced issues related to this?Thanks!
I have several Pre-Stage enrollments for devices and ant to make it so that iPads auto enroll in one and Apple TV's Auto-enroll in another. Is there a function to do this? I can't find anything.
TL;DR - You can use the recovery key to grant a token to a non-FileVault user (i.e. account with UID 501). Not sure if this is widely known, but thought I share my findings.So our workflow is probably similar to a lot of folks. We utilize JAMF to create a local administrator (let's called it macaddy) account with a PreStage enrollment. For 1:1 cases, we create a standard account in the Setup Assistant with a simple password (i.e. abcd). We then let policies roll out and configure the device, including installing NoMAD. Then we would reboot and let FileVault enable. From there, we would get with the user and sync their AD password using NoMAD. And that's it. Before we started using NoMAD, we were AD-bound, and it was causing headaches with passwords and FV syncing. So that's why we made the switch. We also recently started taking advantage of Prestage (I know we're pretty late) to make deployments more easier. What we didn't realize is when we needed to troubleshoot a MacBook and t
We're testing a way to make it a little faster for users when they come in to get their new Mac's. We setup a staging profile, login with that account, we sign in to self-service with the user who will be getting it, at the prompt to enter local password, we put in the staging password and then run a script that switches the user on the device. We then go in to Jamf and change the user info there. The Mac shows encrypted, filevault 2 is new user and the user has a secure token. We're able to change the password, but when you log back on to jamf connect, it says incorrect password with either the current or staging password. Not sure if there is a way around this.
Hi all,We newly set up Apple School Manager and connected it to Jamf Pro (We have two on-premise Jamf instances running behind a load balancer). Our newly purchased devices are showing up on ASM/ABM and are automatically assigned to our Jamf MDM.On Jamf we set up a prestage enrollment and assigned it to those devices, after a few minutes the devices showed up as "Assigned", however when turning on the mac, it doesn't seem to recognize that it is managed by an MDM, the Remote Management screen doesn't show up at all, and the setup assistant continue as if it was a normal mac setup.The network is working fine so is the ethernet adapter (we use Belkin USB-C to Gigabit Ethernet Adapter) however, I noticed that all the new devices are in the PST time zone and there's no way to change it (we're in CET)The only workaround is for me to get my iPad out and use Apple Configurator2 to manually re-add the device to ASM/ABM.is anyone else is facing a similar problem?
Hello guys,so I want to automate the VPN integration.Currently I have a policy that install the VPN Client pkg. file via policy, but to complete the processI also need to deploy the config file to the Macs and a script that includes the config file to the VPN Client. How is it possible to deploy a single .scx config file on the macs? Thank you guys.
Anyone having issues attempting to update Big Sur devices via Policy and using Apple's Software Update server? The policy is not working for Big Sur including intel machines. Attempting to get the latest update (20D74). With the terminal open, it states it downloads. It shows as completed in Jamf within the policy. Also within client history. Yet reboot does not install the update. Mojave and Catalina devices update fine.
Hey gang- Thought I had this one locked up, but was woefully incorrect. I'm trying to put something in Self Service that allows a tech to input a serial number and ticket number, and writes that into an extension attribute for the record.Everything's fine until it comes to populating the EA, then it returns error code 400. I'm assuming the format for the EA input is wrong.I've seen a few articles doing the same thing on JAMFNation, but they're a little on the old side, and some of them have unanswered questions.Here's what I have so far: #get device serial number serialNumber="$(osascript -e 'display dialog "Please enter the Serial Number" default answer "" with title "Serial Number" giving up after 86400 with text buttons {"OK"} default button 1' -e 'return text returned of result')" echo "serial number entered is $serialNumber" #get the ticket number ticketNumber="$(osascript -e 'display dialog "Please enter the Ticket Number" default answer "" with title "Service Now Tick
Hello everyone, we try to deploy "FortiClient VPN Only" via Jamf Pro. I saw in the forum that there is an existing tutorial for the licensed version of the FortiClient with the install.mpkg file but nothing for the "VPN Only"-Client wich has no install.mpkg.If we try to deploy this version we only get a blank window after starting FortiClient.Is there anybody who is deploying "FortiClient VPN Only"? Best regards,Felix
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!