Get Support
Recently active
Hello All, I deploy macOS update through Nudge, I can see those mac devices are getting updated successfully but it is not getting Safari v16 update, it is showing me pending, I need a help how can I deploy that pending Safari v16 update on all mac clients.
Okta is an identity and access management platform and whilst not identical it can be considered as an alternative to Active Directory.The basic setup involves systems being configured to redirect logins via Okta usually using SAML so that Okta handles who is allowed to login to that system and also to enforce MFA. It is however also possible to enforce device trust so that this can be further restricted to approved devices. This later aspect could be considered as equivalent to 'binding' the device to Okta like one might bind to AD.Okta Device Trust therefore uses a script to enrol the Mac and make it 'trusted'. The following is a link to Okta's documentation on this. https://help.okta.com/en-us/Content/Topics/Mobile/Okta_Device_Trust_Jamf_macOS_Devices.htmThe 1.2.x version of this script uses Python2, this is no longer included in macOS as of macOS 12.3. As Apple warned for some time they did not replace it with Python3 but now require developers and admins to organise installin
We have an exciting update regarding the Jamf Toolkit! During our JNUC Presentation, we launched a new product meant to be a one-stop shop of scripts, tools, and workflows for Mac admins. There was a lot of excitement around this product, and have had a lot of great conversations with people over the past couple of weeks. One of the biggest pieces of feedback we received was, although these tools were all developed internally by our team, many of the original concepts were created by other individuals in the Mac Admin community, which were released free of charge. Because of this, we’ve decided to make the Jamf Toolkit Open Source! You can now access all of these tools on our GitHub page: https://github.com/Rocketman-TechThe paid subscription of the Jamf Toolkit has the following added benefits:A Two-Hour Onboarding SessionQuarterly 60-minute reviews of your Jamf Pro server and implementation of these toolsThe Jamf Toolkit web portal: https://www.rocketman.tech/jamf-tool
Hey all,For awhile now we have had an issue with Google Chrome in which the icon just bounces up and down a few times and does not open when a user tries to open Chrome after it installs via enrollment/check-in. We build the policy ourselves which may be the problem, but I believe the person who builds it just scans the package and uploads it directly to Jamf...Anyway, we came up with a solution that uses a script to give the login user access to the folder $HOME/Library/Application Support/Google/Chrome, and that seems to work.The only problem is, this has to be run for every user that's logged in, and what's worse we can only seem to get it to run from Self Service, which I think may have something to do with it running from root rather than as the user. We have hundreds of shared machines that are logged into by multiple users, and it's not feasible to have every user run this. Here is the current command we are using:#!/bin/shloggedInUser=$( scutil <<&l
Hello, We want to have all of our PDFs open in adobe acrobat across all users when they login to our computers. Right now it is defaulted to preview. Is there any script that will change the default for all the users in AD?
I am gathering some information around using these two products together, and so if you're using BOTH of these, I would be really grateful if you wouldn't mind sharing a few details with me: How many devices do you have?How often teachers are using Jamf Teacher?Do you have a influx of pending commands when it’s used?Are there any features that show up, but don’t actually work?I really appreciate you taking the time to check this out and respond :)
We use several mac minis as caching servers in some of my company's locations around the world. To be able to access them remotely, we need our screensharing utility (Bomgar) to be approved in Security & Privacy > Screen Recording. It is important this happens BEFORE it ships out, because otherwise we've got a headless mac mini that we can't access remotely. To ensure it gets approved, I have an until loop set to prompt the end user and bring up the appropriate preference pane until access is granted. However, it looks like the osascript prompt I'm using throws an error: 020-08-04 19:19:12.566 osascript[5461:27615] -[__NSCFConstantString objectAtIndex:]: unrecognized selector sent to instance 0x7fff8f3960e0 2020-08-04 19:19:12.567 osascript[5461:27615] *** Terminating app due to uncaught exception 'NSInvalidArgumentException', reason: '-[__NSCFConstantString objectAtIndex:]: unrecognized selector sent to instance 0x7fff8f3960e0' *** Fir
Hi All,Can anyone know what is this error "availability Pending" I can't create any package with any size of the .dmg file. Does cloud DP have any space limit?
I want to add application in screen recording in Security & Privacy pane - Privacy. Can anyone suggest how to add using JAMF Pro Regards,Md Khaja Zahed.
Hi everyone,We deployed Jamf Connect to a few users in our organisation, but what we see on these computers' records in Jamf Pro, more specifically under Inventory - Local User Accounts, is a double entry for that user. One has the type local, one has empty. The other accounts on the computer (management ones) are also local and fine. The two of the user's accounts have the same names, home directories, sizes, and FileVault enabled status. Is this normal behavior for Jamf Connect?
Guys, We are moving to Intune from Jamf due to less count of device. When we register the MacBook in company portal getting 'The device is not managed'. The device is in ABM but not assigned to Jamf pro server. We did not wipe the device. We just removed the Jamf profile from system preference, deleted certificate from Keychain. Also, we are having Azure AD so no device in Azure under user information. Kindly help. Thanks.#JamfPro #Intune #ABM
Hi, looking for help in producing a report that shows the version of zoom installed on each of our Macs ?
I've been following @erikgmez 's Nudge app for macOS 11 for a while now, and I'm finally trying to jump in to it. There seems to be a lot of configuration options but they all seem pretty similar to me when reading the wiki I tried running it just with defaults and it made the nudge window active constantly... what settings are recommended to kind of tone down the aggressiveness of behavior? Our patches prior to macOS 11 would run once a day and prompt to install or defer. In hindsight that seems not aggressive enough, so maybe every couple hours? I'm open to suggestions, but with all the different timer options I'm getting a little lost and confused.
Good afternoon!I have a Sophos Kernel that is applied via Configuration Profile to to both Intel and Silicon macs. The issue is that the Silicon Macs show a failure to install but the Kernel does install on the Mac profile when I check on each Mac. The problem is that the configuration sees it as a failure so it continues to try and install it and piles up lots of failures on each Silicon mac. The status error is "The current system configuration does not allow the requested operation". As far as what I have researched, Silicon Macs don't really use external kernels. If this is true, is this kernel actually needed (It does install)? Bonus Question: Sophos will only install on 2/3rds of my Silicon Macs. The other third won't take it (the kernel is installed on all of them and they are all on Monterey). If you have any idea why it won't install then please let me know (Jamf shows that it installs but that's not the case).
I feel like a complete bone head but can’t get past this issue. Any help would be appreciated.I am studying for the JAMF 100 and setup a simple trial account. I want to enroll an iPhone to test it. When I go to /enroll it prompts for my jamf account, then my managed Apple ID. No matter what I do I cannot get past this step and skip the managed Apple ID like they do in the training videos as I don’t use managed Apple id’s. Below are the settings I verified:1. I created a test user with enrollment rights2. under settings > global management > user-initiated enrollment under iOS I selected ‘enable personally owned devices’ via profile driven enrollment via url. The two other boxes are unchecked. 3. under settings > global management > user-initiated enrollment under access the group is set to “all ldap users”, allow group to enroll personally owned devices is the only option set.note: I do not have an ldap server setup for
What could be done if all of a sudden student ipads are disconnecting from the internal wifi and they connect to the guest wifi and when you try to connect back to the internal its asking for a password. The ipads are setup with student information at the MDM so when the profile is in pulled in the internal wifi is in place. As of now the ipad has to be erased and re-setup in order for the device to connect back to the internal wifi. Is there a way within Jamf to tell the ipad to connect back to the internal wifi and what could be causing this issue.
I'm trying to get Nudge working with a JSON file but based on this older post:https://community.jamf.com/t5/jamf-pro/having-issues-uploading-a-config-profile-for-nudge/m-p/246960#M231095 My JSON configuration profile doesn't look the same. My understanding is that it should say Nudge and allow me to modify osVersion Requirements, userExperience,etc Also if I use a JSON I don't also need a separate mobile config is that correct?
I took over my previous admin and now this is coming to haunt me... I am very new at server, SSL, CA, etc.Since 10.42 deprecates HTTP distribution points, I am going to prepare my Mac distribution points for the transition. to HTTPS. One of the challenge I am having is how to issue SSL for HTTPS for internal non-FQDN host names?Since the hostnames we use internally does not resolve in public, therefore external CA is not going to resolve the issue. I am reading the instructions for Windows to use CSR with JAMF built-in CA to establish trusts. Does the same process still apply to Big Sur w/ built-in Apache? I assume the process is the same as signing profiles?The reason for this usage on Mac because I have M1 Mini at all sites as content caching. They are not going away nor I am very confident in my Linux skills to run NGINX or Node.JS yet.Thanks.
Hi,I tried to use the API to validate and then upload a CSV file to the Inventory preload:https://developer.jamf.com/jamf-pro/reference/post_v2-inventory-preload-csv-validatehttps://developer.jamf.com/jamf-pro/reference/post_v2-inventory-preload-csvI am able to use other API calls. Just these with the file upload I can not figure out and always get a 400 error.Could someone share some example code on how to use those 2 API endpoints?Thanks,Christian
I'm setting up SSO for the first time and need to map groups created in Azure to groups I have within Jamf in order to separate out Admins, techs, auditors etc - although I can't find anything on that in the documentation. Grateful for any guidance
Hey Jamf Nation!We've just released Jamf Pro 10.42.0 Beta 2. We've added support for Apple's Declarative Device Management along with a few refinements and fixes. Jamf Pro 10.42.0 Beta features many fixes and some exciting new enhancements including redesigns of Jamf Pro Settings and iOS Self Service. It also features new background profiles which prevent users from disabling apps and new support for Cisco Identity Services Engine (ISE) 3.1. Please refer to the release notes for more details. We're excited to hear what you think!How to join the beta: We’ve also made some changes to the Beta enrollment process with our new Jamf Nation platform. Please enroll in the Beta Program under Product Feedback at account.jamf.com. Once you’re enrolled you’ll see a link to the Beta Forum. There will be a short delay between enrollment and Jamf Nation beta forum access - you will receive a notification in Jamf Nation to join the beta forum. Once you receive the invitation click on "Join t
I set up a snipe-it instance and was able to get Google LDAPS connected. I would like to use the Jamf2snipe between my snipe-it instance and our jamf school account. Does anybody know if the Jamf2Snipe works with Jamf school?
Since Jamf Pro Restricted Software records never quite seem to work for us as we originally expect, we’ve found that adding the ID Number in the text of the error message will help us track down which record is blocking what. Error 4: macOS Ventura 13 is currently being tested.Please see KB0070400. (If this message is repeatedly displayed, please restart your computer.)
Hello We currently have in our company laptops on different OS, and I would like to know if a method to block the latest update exists? Each new update is tested before deployment, but I could only lock the update for people who are on the previous update (12.2 in this case) via a smart group and locking access to the update via a profile configuration. So if a user is not on 12.2, he has access to 12.3. Do you have an idea ?
Update:Decided to push via Self Service using DEPNOTIFY. Sending out reminders to users to run updates.Way easier than trying to automate the process. I am currently trying to automate upgrading our macs M1 to Monterey.I have had success with our Intel macs but stuck at the following stage where to install the OS on our M1 macs I get the following message in the logs.Background:I have set up two policies:“Monterey Cache M1 Policy” caches the installer onto the machine.“Monterey Install M1 Policy” installs/updates the OS. “Monterey Cache M1 Policy” caches the installer onto the machine. “Monterey Install M1 Policy” installs/updates the OS. +
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!