Get Support
Recently active
I am trying to figure out a way to authenticate my AD admin user accounts while doing 'su' or 'sudo' commands. (or even unlocking the System Pref) Our Macs are bound to AD and we add a few AD Groups to the local Admin group. This is setup and working while the mac is on-network. (and had been for years) We can run sudo with an AD admin account, while on-net and it can reach the AD servers to auth.My goal is to be able to do this while the mac is at home / off network. We do use JAMF Connect with PingFederate, so I'm thinking there should be a way to do this. I'm just not sure how to get the pam.d to go to Jamf Connect while trying to auth our admin account.Anyone out there done anything like this?
Hi all, I have setup Azure AD SSO for accessing our JAMF Pro Cloud host. Each time I login I get this error: It only works if I use an incognito window from Chrome. Any way I can get it to work using our default browser (Edge) or at least without having to use an incognito window?
Hello All I am having an issue where it seems securetoken is not being enabled on our accounts, thus FV2 enablement window shows up and asks to enable but it doesnt work after entering the users password. We are using jamf connect with OneLogin for user accounts. What process is everyone here using to enable FV2?
I wish to download a 50Mb pkg installer from a website onto macs. when I run the bellow command it only downloads 152 bytes of the pkg instead of 50Mb. What am I doing wrong?curl https://somewebsite.com/packname.pkg -o /Users/Shared/packagename.pkg
I recently update my AutoPkgr server to 12.6 and I am not getting an error. Looks like a Python error. I did replace the "is not" with "!=" in the 2 scripts but then got a "Failed Local Trust" error. Anything I can do to get this fixed?? /Library/AutoPkg/JSSImporter/jss/auth.py:61: SyntaxWarning: "is not" with a literal. Did you mean "!="? if r.status_code is not 401:/Library/AutoPkg/JSSImporter/jss/jssobject.py:531: SyntaxWarning: "is not" with a literal. Did you mean "!="? if self.can_put and self.id is not "0":Failed local trust verification.
After removing Admin rights from local users, they cannot update some apps. They're getting a popup to enter Administrator rights and click on Add helper. Not sure what this is. Please advise.
I’m trying to add iOS update compliance to jamf when the iOS device is first setup. So if the iPhone is on 15.4 it will check and say device needs to be updated to 16.0.2 whatever.. is this something I can do or anyone have any experience with this?
Hi All,Been using Jamf School for a while now with AD binding, this is really slowing down the log in time so have switched to Jamf connect with Azure AD, I've followed the training videos and done some googling, and have managed to get it to work but not ideally how I want the experience.Currently user is greeted with a Microsoft log in, put details in, then it wants to create a local account password, and possibly creates a local account.Would like microsoft log in then it just goes straight to the desktop, no local account, almost want the same experience that AD binding gave but authenticate with microsoft account.In Jamf connect config under authentication I have ticked Always require network authentication, but this has made no difference.Is this possible, am I not understanding the mechanics?Any ideas, suggestions, help is very much appreciated.
Scenario: Some iOS devices that have been set to lost mode, including always enforce lost mode, aren't actually in lost mode. The reason why that has happened seems to be due to the following: 1. An administrator enabled lost mode in JAMF. The device was offline at the time.2. Sometime later, all pending and failed commands are cleared (regular maintenance of JAMF, good to do when you have a large environment with 60k iOS devices, where some are more active than others)3. Sometime later, the device comes online and never receives enable lost mode because the pending command was deleted. Now, JAMF still believes that this device is in lost mode, but it isn't.I understand this is probably due to limitations in the implemented logic in JAMF. For instance, if a configuration profile was never installed because it was cleared when it was still pending, JAMF detects that and reissues the install command for the missing configuration profile on the next inventory update. However, it
Hi everyone,I recently joined an IT team using jamf and I'm in charge of automating small tasks to relieve the load of the support one of them was to check the installed application on every computer.The script is done and running fine the only problem is that since the list of apps is in the script output the only way for me to access it is by going into the policy logs and then click on the details button.Is there a faster way to do this with the platform or the API because we would need a monthly report on installed apps and the fleet is growing exponentially (if not I'll build something else to do it for me but a legit way would be nice)Thank you all in advance
Just throwing this out there to see if anyone has had any similar experiences. We have Managed Apple IDs created through ASM. Our iPads are in Shared iPad mode. This small school district that is using a set of 30 iPads (which are managed by us through Jamf Pro) will not let students log in with their Managed Apple IDs. It will let them use the "Guest" option though. When you go to the wi-fi network, this "no internet connection" error shows up. However, they do have internet and are able to work within GChrome, etc without issues. Their I.T. Director says that other devices (desktops, etc) tend to have this same error populate at random moments. It is my understanding that this usually means there is a good connection from the device to the Access Point, but there is a routing issue from the Access Point to the gateway. I have not been able to determine the hardware this district uses yet (awaiting email from him on that). He did say the following: "We have replaced all the switc
I am messing around with Jamf pro and trying to add a printer. I go through settings>Computer Management>Printers How do I find the CUPS name for my printer?
Hello, Cyber Sec have asked me to limit people adding add-ins via Jamf. I cant seen anything pages that anyone has done this before. Any help would be appreciated please.
So, what is the best way of creating a pkg from the installers that are just drag and drop but dont contain actual pkg files? Edit I am asking as installing the package, and then capturing changes takes about 10 minutes on the machines I use to build, as they have so much other stuff on them
Hey all, Currently trying to do this via Jamf. What I have done -Compiled the script and tried to add it to a policy to my Mac via Jamf. It worked as expected. I tested with a user and it failed. The only difference between us that I have noted is I grabbed gcloud cli tools via homebrew; the user grabbed it via tar. I've tried which gcloud config set core/custom_ca_certs_file ~/ca.pem and various other methods to get this going. Have you tried anything similar and gotten it going for your environment?
HelloJust unwrapped 2 Ipad and assigned them to JAMF thru Business Manager.Everytime I start them, I'm getting "SCEP Server configuration is not supported". I don't actually use SCEP, all default configurations in JAMF Pro.Do I really need a SCEP Server ? I'm not generating any certificate from another CA server, etc.Thanks
I recently setup an iPad with the SSOe instructions for Jamf Setup/Reset.When I signed in with Setup, I had to sign into some of the apps until I was able to login into other apps automatically.When I tried to sign out with Reset, some of the apps were still logged in. Teams did prompt to sign back in with my password, but it still showed my email address.Outlook looked like the Reset didnt do anything and I am also assuming the same for several other programs. What is the best way to fix this (besides enabling hard reset via Reset).
Hi, Recently, ExpressVPN announced that that are EOL L2TP end of this month. Does anyone know how to package the desktop app with activation code for mass deploy via jamf pro. When i use composer, its not getting signed
We have a strange proxy-bug on Monterey in Safari. Once a user connects to our corporate network, Safari can' t reach any pages. (Safari Can't Connect to the Server) If the user then opens Chrome, Safari immediately works again. Clearing the cache in Safari also solves the problem. Our proxy is configured correctly, on Big Sur everything works. Does anyone have the same Issue? Or already a solution?
Hi! Would anyone be able to help with a script that would help me uninstall CrowdStrike Falcon from all machines via JAMF?
Here is the scenario:1.) I scope a computer a policy that they can run in self-service.2.) I scope another policy to another computer that can be run in self-service.3.) Both computers DON'T run the policies.4.) I want to figure out which computer, has what policy, but not do it in a gui platform, I want to instead report out what computer has what policy scoped to them that they are able to run.These seems "easy" enough, but no matter what I look at, I can't seem to find anything that can just spit out a "list" outside of going to the asset individually or looking at the policy itself.Use case: I have a policy that is a template, I create a policy each time for each computer/user that needs this policy. I need to have a list of all users that have this policy associated with a device for auditing purposes. You're probably thinking, why can't you just put everyone in the same policy (great question), this is due to the nature of how we are trying to limit who has access to what. I don'
Hi,whenever students try to download an application in their students app the following error occurs:"Licenses cannot be assigned because the service token is invalid." Funfact: Every Token is valid...Any suggestions what I am doing wrong :-D
Hi All,Sorry if this has been asked before.I'm using this script with zero modifications except for the parameter changes as shown in screen shots below:https://github.com/kc9wwh/macOSUpgrade/blob/master/macOSUpgrade.shI pulled the installer for 12.6 from Mr. Macintosh. The installer will attempt download from self service but I get this error: We were unable to prepare your Computer for OS Monterey.
Does anyone have AppNeta Silent uninstall script or could anyone help with it, please? AppNeta needs to be removed from all mac machines via JAMF.
Getting fond memories of Sim City 2000, but not necessarily having the best time with Jamf Pro at the moment... So I have the jamf connect metapackage going out and being installed - yes, all the permissions have been set to wheel/root, yes, it is signed, yes, by an apple developer ID cert, and yes, the cert is valid. It contains the jamfconnect PKG, branding assets, postintall script, and the notify script. It is being installed, as booting into the machine we are getting the jamfconnect login screen, which works normally. However, after logging in, at the point where the notify script should be run, I am getting the generic notify screen and the "reticulating splines Again.." status message, to which I have to command +control + X to get past.After the fact I check that the depnotify.log file does indeed exist in /var/tmp/, but it is blank. So it is appearing that the script is not running to update it - hence the splines.I have tried several scripts, thinking that maybe I
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!