Get Support
Recently active
Hallo everyoneNeed some help with understanding how the printing works on the macos.Previously I always have set up the printers in our jamf Pro Server and it works all fine. We need only the standard printing(keeping it simple).Now I have to set up a new canon Uniflow printer available in every office with different models. How do I get the printer driver, which can be different for each printer?The Printers in our company are configured on a win print server and the driver used on windows devices is: Canon Generic Plus PCL6. How do I get the driver for the printer?I can access the smb share where the printers are. While configuring the printer, I couldn't figure one which ppd file to choose from the list. So I chose the Generic.ppd.Again the question, which PPD file shoud be chosen for the various printer?I have been digging for Information on how the printing works on macos. really confusing for something very simple.Can someone show me the right path for this?Thanks Best
Hi all,i'm trying to deploy configuration profile with a screen recording enable for Flameshot.the issue is i cant create a configuration profile due to missing signature.when i try to create a profile from the PPPC utility i get error " the executable may not be signed" and by running is someone managed to work it with it and/or managed to create a configuration profile for unsigned application?Thanks in advance
Hello Jamf Nation, I've just recently become the Systems Admin of the school district I work in. I was recently tasked with coming up with suggestions for replacing the our school servers with something "new". We currently only need a single ESXi host to serve Netsus Netboot server and a Casper Distribution server. We have gigabit networks in our schools for file transfers. The busiest time for our servers is during the summer where the school technicians will re-image laptops up to 15-20 at a time. Our distribution points are using ~120 GBs of space for packages at this time. I don't expect this to grow very fast at all in the future. I'm hoping you guys could recommend a solution that can maximize data transfer for imaging, have some sort of redundancy for protection, and is affordable for a public school system. I'm totally okay with refurbished gear that comes with a 3-5 year warranty. I've looked at hardware here. Any information would v
We have just over 1,000 iPhones in Jamf for our staff. Our staff are responsible for repairs themselves by contacting Apple directly. We have experienced some very confusing and convoluted issues with Apple in this regard, and I'm still unclear how to avoid future issues.I myself have sent a few iPhones for repairs over the past 2 years. The only information Apple provides is to "Remove your iPhone from your Apple ID". Well, I can't do that if the iPhone was set up by another employee, and we have our PreStage Enrollment profile configured with "Prevent user from enabling Activation Lock" set to enabled, and "Enable Activation Lock on the device (ASM/ABM)" set to disabled. Yet, inevitably, after we send the iPhone in for repair, we get the iPhone returned to us with a note that they couldn't do the repair or replace the device because either the iPhone has remote management, or it's assigned to ABM/ASM. My question is, how do I know which of these actions I need to do prior t
Hello Everybody,our School has managed IPads since 8 month. The first classes, that get devices, are provided with managed apple ids. That worked very fine, every user got an automatic ID. Now we added some additional devices, but for them no id is generated and we dont know why. All works fine, the device is registered in apple school manager and jamf. Only the ID is missing. We have synchronised SFTP several times. Can someone help us?Thank you!Marius
No mention of this one on the forum yet, so either this software is perfect (hahaha) or I’m on an island. I may need to mass deploy and maintain the Nexthink Collector. Never heard of it before, but it looks like a client side agent (ugh) that collects and sends analytics to a central repository. Anyone here have experience with this one you can comment on?
I have an installer that will prompt the user to accept incoming network connections.However they don't have administrative rights. Allowing this will add this to the application firewall but I can't figure out how to do this (automate) with JAMF.I tried to add this to my firewall configuration profile however this is a executable and I don't think it has bundle ID. I tried this command and it came up null. osascript -e 'id of app "/usr/local/bmc-software/client-management/client/bin/mtxagent"' I tried to add this to the application firewall from the this command line sudo /usr/libexec/ApplicationFirewall/socketfilterfw --add /usr/local/bmc-software/client-management/client/bin/mtxagent But this command gives me reply, "Firewall settings cannot be modified from command line on managed Mac computers"I'm stuck, any ideas?
I am installing the new Carbon Black Sensor and out of three machines, 2 did not get installed and I cannot figure out why. The policy does show installed and completed with no errors. I am using system ext mode as all three machines are running Monterey. Any ideas?
Today we released Jamf Connect 2.14.0 for general availability; this release includes the below details. Key Feature ContentDisable password syncing for specific local accounts: The Password Sync Block List (PasswordSyncBlockList) setting is now available for configuration in Jamf Pro and Jamf Connect Configuration. IT allows you to specify a list of local macOS accounts that you do not want to go through password synching (typically admin accounts). You can specify one or more local accounts as an array of strings using their local macOS account names (i.e., short names). Configure custom local account full names: The Full Name (OIDCFullName) setting is now available for configuration in Jamf Connect Configuration. It was added to Jamf Pro in the 2.13.0 release. This setting allows you to specify a single different claim for full name, such as firstName, lastName, or another custom value unique to your environment. This preference overrides the default attributes used to set
Hello All. I am a relatively new admin, thanks for your time and please redirect me if this topic has been covered before. I will try and be as thorough as possible. I am attempting to deploy Cylance Protect 3.0.1 using Jamf Pro to new M2 Macbooks. Following all of the documentation I can find with both Jamf and Cylance here is what I have done to this point.1. Created a configuration profile with a system extension payload.This policy is set to deploy in the prestage. 2. I have the package deploying from a cloud share point, also in the prestage.Results: The software is installed on the test machine. It did not run on its own and when I attempt to start it manually I get the following result.I need the program to install and run on its own. I think that the solution to this issue might involve some scripting, which is something that I don't have much experience with. Does anyone have any experience with this collection of variables or have a direction they can point me in? T
Is there anyway to exclude an iPad that's been scoped via group to an app? I want the group to still receive the app, except for certain iPad(s), but they still need to remain in that group to receive other configs and/or apps.This can easily be done in Jamf Pro, but I'm not seeing anyway to do this in Jamf School. Am I missing something? Or is it just not possible?Thanks for any help!
I'm trying to work with support to figure this issue out...We have a bunch of iPads/iPods in our pre-stage enrollment that are assigned but don't have device names/aren't in our inventory to manage. Some of the device names just show up blank and are unmanageable. The devices appear to have the jamf mdm profile on them and are completely locked down so I can't factory reset/restore them/log out of the apple ID even after removing the mdm profile on Apple Business Manager. I can't find them in Jamf to unmanage either.Does anyone have any idea how this could have happened? Not sure if it was an issue when they were initially enrolled or if it was a configuration we did that would cause them to disconnect from jamf somehow? Has anyone had anything like this happen to them? They are kind of stuck in limbo and I'm unable to do much of anything with the devices.
I have a MacBook Pro here, but the user forgot his password, so i want to restore it with my Personal Recovery Key in JAMF. Now the problem i got a Personal Recovery Key in jamf but it doesnt work on the device. (says its wrong)So I have no possibility to log in to that device + another problem the firmware password doesn't work either. My question is there any way to force the macbook to send te Personal Recovery Key to JAMF without logging in.
Hello,we use Jamf Pro Cloud 10.30 at the moment. With Jamf Pro Tools (Composer 10.31) and even older Composer versions, it is apparently no longer possible for me to include files on the user's desktop in the package, so that I can deploy these files to the user desktops via DMG and fut. The error message as shown in the picture always appears. Does anyone know the problem or has a workaround?Thank you!
We did have LDAP working with a Linux infrastructure manager server, but it stopped working. We suspect the server may have been deleted from AD, but because no one here is a Linux expert we couldn't do any real troubleshooting - we couldn't even login to it. We decided to just build a new Infrastructure manager server but this time do it on a Windows server. We gave it the exact same hostname and IP as the previous one that we decommissioned so the firewall rules would all still point to the same location. At first we thought the new server could just slide in and pick up the role and restore LDAP but I found that when this new server enrolled, it created a new instance. I figured that's ok. I'll just give it a difference display name so I'll know where to point the new LDAP config. I cloned the existing LDAP config but changed the display name and pointed it to the new infrastructure manager instance. The new infrastructure manager (on Windows server) is listed as a viable Jamf
Hi,I am trying to set the push certificates privilege to read only for a single user. The user privileges are set to custom.I go and untick the create, update and delete boxes leaving only read ticked, then go and save.. and when looking at the list, all the boxes are ticked again.I am certain that there is another privilege that I have set, that might be forcing this. Spoke with JAMF Support, and all they could say is its a bug, then just closed my case, so coming here for some advice.Can anyone help?Thanks
Hello all,I wanted to share my experience with a few devices running into this error. This only became an issue after erasing the Mac and reinstalling the OS. Below is the response I received from support and this solved my issue. "After reviewing your logs it seems as though you have quite a few smart groups. There are a few things we can definitely do here. If its more than one MacBooks that are receiving this error please try the pre-stage enrollment again with no smart groups. If the error is only happening to only one MacBook please attempt a PRAM reset by doing the following steps: -Shut down your Mac. -Turn it on and immediately press and hold these four keys together: Option, Command, P, and R. -You can release the keys after about 20 seconds, during which your Mac might appear to restart."
Hello, was wondering is there a away to have a Progress bar on the desktop to know whats being installed and what is missing as far as Policies during the enrollment.
When using the API to pull out some policies, I discovered a good amount of policies that don't show in the web front end. They appear to be old policies but all have the naming scheme similar to "2016-07-29 at 9:42 AM | user-name | 1 Computer". If I enter the ID in the policy URL I'm able to view them. They appear in any policy API call, e.g. ../JSSResource/policies. Some of them still have a scope and enabled is checked which is concerning. Has anyone come across this? Is this on purpose for deleted policies? Is my DB messed up? Are they still active?
Hi All , very new to this and really trying to get my head around stuff.it doesnt helping that I get to work on it for 1 day a month. Anyhow, i need to enable ssh for all user, all the computers have ssh enabled but for some reason, it changed to only this users. can someone explain step by step how to create a policy for it to change to all users or to add the local admin account to the list?
Hey all, here's a question.We are transitioning from utilizing our DEP Notify provisioning script to enable filevault, to instead use configuration profiles to manage/enable filevault.If we enabled the config profile to enforce fielvault on next login and scoped it to machines, should I ensure to not scope it to a machine with FV already turned on and enabled? I would assume this could cause some weirdness with the profile. Obviously I would test with a few machines, but just wondering before we started.Thanks for any answers!
Experts, I am new to the Casper and struggling second day with dock util on 10.10.OS. Since that functionality was removed in JAMF casper work around like custom script with dockutil 2.0.2 needs to be enabled. !/bin/bash sudo dockutil --remove 'Launchpad' --allhomessudo dockutil --remove 'Mail' --allhomessudo dockutil --remove 'Contacts' --allhomessudo dockutil --remove 'Calendar' --allhomessudo dockutil --remove 'Notes' --allhomessudo dockutil --remove 'Maps' --allhomessudo dockutil --remove 'FaceTime' --allhomessudo dockutil --remove 'Photo Booth' --allhomessudo dockutil --remove 'iPhoto' --allhomessudo dockutil --remove 'Pages' --allhomessudo dockutil --remove 'Numbers' --allhomessudo dockutil --remove 'Keynote' --allhomessudo dockutil --remove 'iBooks' --allhomessudo dockutil --add /Applications/Firefox.app --after 'Safari' --allhomessudo do
I've been trying to wrap my brain around what to do to get four .crt files from our SSL provider into the JSS. The file names are as follows: AddTrustExternalCARoot.crt COMODORSAAddTrustCA.crt COMODORSADomainValidationSecureServerCA.crt <our domain>.crt What's the easiest way to get these into the PCKS12 or JKS format? I've been Googling and it seems I'm probably missing something. For the CSR I needed to generate on the server, I have the .csr file along with a .jks file they had me generate (From these instructions: https://www.namecheap.com/support/knowledgebase/article.aspx/9422/0/tomcat-using-keytool) Anyone who can shed some light on what I can do? I'm out of options that I'm aware of.
Hello All, I have been attempting to implement a level one CIS Benchmark and I haven't figured it out just yet. Any advice would be great. Also, I have stumbled across a script that was made for BigSur has anyone adjusted this script to work for Monterey?https://github.com/gocardless/CIS-for-macOS-BigSur-CP Thank you in advance !!
In Chrome ( 105.0.5195.127 64bit, windows) When I go to any system > history and click on policy, the page loads but does not show the history. If I do this in firefox or safari it loads fine
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!