Get Support
Recently active
Hello! I recently took over a Jamf environment hosted on-premise windows, Jamf Pro v10.34.2 and I have noticed a pretty high frequency(over 3000) of errors tied to a child Tomcat service, specifically this error in our logs com.jamfsoftware.jss.exceptions.mdm.InvalidMDMMessageException: Error processing request action:StatusUpdatePlist, CmdUUID:4eecbfdc-625b-4919-b3bc-19d00c3e1d9c, SigVerified: false. Returning 500. I would assume this is tied to HTTP 500 errors which indicate failed connections due to unexpected conditions, has anyone else experienced issues related to this?Thanks!
I have several Pre-Stage enrollments for devices and ant to make it so that iPads auto enroll in one and Apple TV's Auto-enroll in another. Is there a function to do this? I can't find anything.
TL;DR - You can use the recovery key to grant a token to a non-FileVault user (i.e. account with UID 501). Not sure if this is widely known, but thought I share my findings.So our workflow is probably similar to a lot of folks. We utilize JAMF to create a local administrator (let's called it macaddy) account with a PreStage enrollment. For 1:1 cases, we create a standard account in the Setup Assistant with a simple password (i.e. abcd). We then let policies roll out and configure the device, including installing NoMAD. Then we would reboot and let FileVault enable. From there, we would get with the user and sync their AD password using NoMAD. And that's it. Before we started using NoMAD, we were AD-bound, and it was causing headaches with passwords and FV syncing. So that's why we made the switch. We also recently started taking advantage of Prestage (I know we're pretty late) to make deployments more easier. What we didn't realize is when we needed to troubleshoot a MacBook and t
We're testing a way to make it a little faster for users when they come in to get their new Mac's. We setup a staging profile, login with that account, we sign in to self-service with the user who will be getting it, at the prompt to enter local password, we put in the staging password and then run a script that switches the user on the device. We then go in to Jamf and change the user info there. The Mac shows encrypted, filevault 2 is new user and the user has a secure token. We're able to change the password, but when you log back on to jamf connect, it says incorrect password with either the current or staging password. Not sure if there is a way around this.
Hi all,We newly set up Apple School Manager and connected it to Jamf Pro (We have two on-premise Jamf instances running behind a load balancer). Our newly purchased devices are showing up on ASM/ABM and are automatically assigned to our Jamf MDM.On Jamf we set up a prestage enrollment and assigned it to those devices, after a few minutes the devices showed up as "Assigned", however when turning on the mac, it doesn't seem to recognize that it is managed by an MDM, the Remote Management screen doesn't show up at all, and the setup assistant continue as if it was a normal mac setup.The network is working fine so is the ethernet adapter (we use Belkin USB-C to Gigabit Ethernet Adapter) however, I noticed that all the new devices are in the PST time zone and there's no way to change it (we're in CET)The only workaround is for me to get my iPad out and use Apple Configurator2 to manually re-add the device to ASM/ABM.is anyone else is facing a similar problem?
Hello guys,so I want to automate the VPN integration.Currently I have a policy that install the VPN Client pkg. file via policy, but to complete the processI also need to deploy the config file to the Macs and a script that includes the config file to the VPN Client. How is it possible to deploy a single .scx config file on the macs? Thank you guys.
Anyone having issues attempting to update Big Sur devices via Policy and using Apple's Software Update server? The policy is not working for Big Sur including intel machines. Attempting to get the latest update (20D74). With the terminal open, it states it downloads. It shows as completed in Jamf within the policy. Also within client history. Yet reboot does not install the update. Mojave and Catalina devices update fine.
Hey gang- Thought I had this one locked up, but was woefully incorrect. I'm trying to put something in Self Service that allows a tech to input a serial number and ticket number, and writes that into an extension attribute for the record.Everything's fine until it comes to populating the EA, then it returns error code 400. I'm assuming the format for the EA input is wrong.I've seen a few articles doing the same thing on JAMFNation, but they're a little on the old side, and some of them have unanswered questions.Here's what I have so far: #get device serial number serialNumber="$(osascript -e 'display dialog "Please enter the Serial Number" default answer "" with title "Serial Number" giving up after 86400 with text buttons {"OK"} default button 1' -e 'return text returned of result')" echo "serial number entered is $serialNumber" #get the ticket number ticketNumber="$(osascript -e 'display dialog "Please enter the Ticket Number" default answer "" with title "Service Now Tick
Hello everyone, we try to deploy "FortiClient VPN Only" via Jamf Pro. I saw in the forum that there is an existing tutorial for the licensed version of the FortiClient with the install.mpkg file but nothing for the "VPN Only"-Client wich has no install.mpkg.If we try to deploy this version we only get a blank window after starting FortiClient.Is there anybody who is deploying "FortiClient VPN Only"? Best regards,Felix
We have an iPad 4 from 2012 that runs on IOS 10.3.3, It seems to accept some commands from JamF School but most of the the command's we can send to our newer iPads do not work on this (e.g. it won't accept a background image or a webclip). It also says it's 'not supervised' although we did install it through AC2. Is this due to the iPad being old and the IOS is old or are we missing a step here?Thanks
Hello, I have a question. Has anyone else that has integrated Intune with Jamf get the JamfAA pop up continuously to re-register it? I have ours set to Self Service only and almost every morning all the users get that pop up which is quite annoying? any guidance would be greatly appreciated.Thanks,
The change password feature in the JC menu is not opening up for some users. License config is on all devices and verified license is good. Just odd its only some users and not all that are having the issue. Running on JC 2.8 currently. Change pwd should open to a url that we have defined in the config but clicking the link does nothing. All other menu options work. This is happening on Intel and M1 devices as well. Monterey for OS.
Is anyone using the "iboss cloud connector 2020" app with the iBoss content filter for off-site iPad filtering? I've tried it for a few weeks with our 11th and 12th grade 1-to-1 students this month, but eventually turned it off because students were repeatedly complaining of slowness, apps not allowing file transfer, and the connection mysteriously breaking and asking for a proxy password sometimes with no obvious explanation or method of troubleshooting it. If anyone else has used this, is my experience typical?
Has anyone developed an api or an option for an end user (iOS) to run the Update Inventory command?
Hello There. I am doing a move for 100+ Macs from the current PreStage to the ZeroTouch Prestage. was wondering if someone has an idea of how to move all these machines to a different Prestage without having to select them 1by1. Appreciate the help thanks
With a clean install of macOS 12.6 we are unable to print to Windows Server 2022 print queues over SMB. Local printer gets paused and CUPS shows error “unable to connect to printer”. Updating from 12.5.1 to 12.6 does not experience this issue, so far only clean installs are affected.
Hey all. I have a policy to place, once per computer, policybanner.rtfd in /library/security. I noticed the other day that these are missing on our Macs now after Monterey. Do OS updates remove policybanner.rtfd from this folder?Are people using other methods of using policy banner agreements?Thanks in advance!
Can someone tell me if its possible to remove company data only from a Mac computer when we want to unmanage a device from Jamf? the use case is if a user who has been working for the company, using their personal Mac, wants to now leave and get their device unmanaged by us. It seems the only options available are a full wipe, which aint gonna go down well with a user and their personal machine. Or running the sudo jamf removeFramework command, which seems to only remove the profiles and configs, but not the apps and their data. I am specifically thinking about Outlook for Mac and OneDrive for Mac. We cannot be in a situation where we are relinquishing management of a personally owned Mac but then leaving our corporate IP (Intellectual Property) on the device. Surely if Jamf are offering their service to enterprises this must be an option somewhere?In todays data security centric world it must be an option. Microsoft does this we
Has anyone had any luck with a good Configuration Profile for Spirion agent deployment? I'm on the struggle bus trying to deploy this software.
Since the beginning of this school year, we have been seeing some major issues with Airplay lag. It seems to hit Apple Silicon Macs the most but has affected some Intel systems. Systems are on different OS versions from Big Sur to Monterey. The common factor seems to be the Apple TVs and tvOS 16. The issue goes away for a period of time if we restart the Apple TV.Has anyone else experienced this recently?
Hi,How do we change the wording pushed out by Jamf App Catalog when there are updates?Thanks.
We have this issue ongoing for a long time now. Almost every morning, Outlook prompts our users and asking for credentials. I would say it happens when a computer has been for sleep i.e over the night and next coming morning the user open the lid and the pop up is already there. Probably because Outlook is pushing in the background while there is no connection to our domain? Is there any way to prevent or disable it? If I close the popup and wait 3-5sec, Outlook established a connection to the server and everything works as usual. This is very annoying for our users that have to enter their credentials every morning.We have tried with the office reset tool and nuking the keychain etc..The problem comes back after a whiel.We are running Exchange on Prem 2019.Running latest version of Outlook, macOS 12.6.x
Greetings and salutations! I have a script that displays a prompt to rename the Mac during provisioning to my org's naming convention. It was working until relatively recently and the policy logs show it fails with "Script result: 69:189: execution error: Application isn’t running. (-600)". my guess is some Apple update broke the script but scripting is a weaker part of my skills so help would be fantastic. Thanks! #!/bin/zshdefaults=/usr/bin/defaultsCurrentUser=$(/usr/sbin/scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ && ! /loginwindow/ {print $3}')MacName=$(sudo -u "$CurrentUser" /usr/bin/osascript -e 'tell application "System Events" to set MacName to text returned of (display dialog "Enter the new Computer Name:" buttons "Continue" default button "Continue" default answer "" with icon 1)')scutil --set ComputerName "$MacName"scutil --set HostName "$MacName"scutil --set LocalHostName "$MacName"defaults write /Library/Preferenc
I was wondering if there's an updated script on installing vlc on macOS Catalina machines. I have tried modifying older scripts with no luck. Any help would be appreciated. Thank you.
Anyone know how to return the value of <user_approved_mdm since="10.4.0"> using Powershell?I can get the info in bash using xpath, but I've tried pulling it via powershell (I've got limited knowledge) for one of our teams that only uses Windows. I know the value is under computer>general>management_status<management_status> <enrolled_via_dep>true</enrolled_via_dep> <user_approved_enrollment deprecated="10.4.0">true</user_approved_enrollment> <user_approved_mdm since="10.4.0">true</user_approved_mdm> </management_status>
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!