Get Support
Recently active
During the setup of Jamf connect, is there a way to push out the network info during setup, for example, Zero Touch? The user opens up and starts the Mac for the first time. Get to connect to Network, and then needs to choose which network to connect to. I understand that this can be done via configuration profile, but what about prior setup? I would like users to use the work network but don't want to give out any PW. Currently, I have to direct them to the Guest network, or home network. Is this something that is even possible during the Zero Touch process?
Hello everyone, Hope you are all enjoying the holidays. I (UNCA) need some help writing a script for the deployment of Monterey. I found a few guides for Big Sur. From Jamf, Github, and a few others. Thank you in advancehttps://community.jamf.com/t5/jamf-pro/mac-os-monterey-update-via-self-service/td-p/254256Jamf Pro - Upgrading Macs to latest operating system - IS&T Contributions - Hermes (mit.educhrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/viewer.html?pdfurl=https%3A%2F%2Fhcsonline.com%2Fimages%2FPDFs%2FUpgrade_Big_Sur_Jamf.pdf&chunk=true
Hi,I have a MacBook that seems to have lost any connection to the Jamf Pro Server (on premise). All SelfService Options Display a "failed" message if the user uses them. The last time it made an inventory update or a check in was almost two months ago.To make matters worse there are no credentials to the local admin account and the firmware password blocks access to the recovery mode. The OS is 10.14.6 because the user seemingly never updated it, but that cant be the reason for this all, or can it?Anyways some tips would be really appreciated.Kind regards
Hi is there anyone on here that has created a smart group for Macs that have CrowdStrike Endpoint protection installed? It doesnt install as a app so having trouble. Goal is to make a smart group to see which machines actually have it installed, since on my policy it says completed but in logs failed for some reason
Hello All,I am in need of assistance in regards to Trusting CA's on both Laptops and IPads,I been trying it via Configuration Profile, yet when scoping it the fleet of Laptops and Ipads, they seem to Fail to install,below are screenshots of the configure, any suggestions will be beneficial.(sorry for the links i dont yet have permissions to upload photos)Network Configuration and in the Certificate section i have uploaded the 2 certificates, would anyone know whats going on?The Laptop Configuration and Ipad Configuration are pretty much identical, and they both have the same issues Thanks
Hi :) My AVP discussed this yesterday, he wants to give Macs to some VIPs who use SAP as their main job tool. There are couple of apps that can be used to run SAP but I wanted to know if anyone has SAP for Mac users?Any challenge or suggestions will he helpful. Thanks much!! :))CS
Hi all,I'd like to have this available in Self Service. When I try it the way I have some applications set up, it just drops the DMG contents into the "/" directory. The DMG for Wireshark contains additional packages for ChmodBPF, so do I need to add those packages individually to Jamf? Should I use Composer to group the .app and the ChmodBPF packages into one Package? Just curious on how others are doing it, and if you have a good way, I'd rather not recreate the wheel here. TIA,Joey
Is anyone else having issues with the SSO extension just randomly stop working? This is happening more and more often, more so on M1 devices. The only way we have been able to resolve it is to wipe the device and set it up fresh. Seems like JAMF is pushing their other products and making it harder on us who choose not to use JAMF Connect which is becoming frustrating.
We are rolling out NXLog to our Macs. I have the installer working, but don't have any security info to configure things like PPPC or System Extensions. I was able to manually tick the box for Full Disk Access, but I am still getting an error message saying that im_maces|in NXLog requires Transparency, Consent, and Control (TCC) approval to connect to Endpoint Security.If I can find the Bundle ID and Identifier, I should be able to roll that info a PPPC configuration profile which will flip the switch to turn on the Full Disk Access during install, so I don't have to manually do that. Then to clear the error message I am getting above, I likely need a Team Identifier and/or System Extension type for the System Extensions portion of the Configuration Profile in JAMF.I have checked their website and don't seem to find anything there in the documentation or message boards about any identifier. Is there a way to find this info out by looking on a system that has the softwa
We have a set of loaner/multiuser Macs with touch ID. Users log in with AD accounts. I am noticing that each new user that logs in is asked to set up touch ID. Is there a way to turn off the Touch ID setup prompt? I have Restrictions payload > "Allow touch ID" unchecked. This does not disable the set up prompt. I see a setting within prestage enrollments, I am pretty confident that only turns the touch ID prompt off for new enrollments.
Hi all, We are seeing a problem deploying MacOS Monterey. We are running our employees as a standard user and when the Monterey update tries to run it gives them the following prompt: "You must provide authorization for this volume by setting it as your startup disk. You can relaunch the installer after authorization has been provided"Even when I unlock the startup disk and make sure to boot into it I receive the same error.
Hello,I have a script being run as a policy that uses the sudo jamf policy -event eventtrigger format multiple times to run multiple policies that install applications. Is there a way to have it wait for the previous process to finish installing before kicking off the next install, it seems that none of the apps are installing correctly even though it returns with a succesful in JAMF. Example of code: # Installs app1/usr/local/jamf/bin/jamf policy -event app1# Installs app2/usr/local/jamf/bin/jamf policy -event app2# Installs app3/usr/local/jamf/bin/jamf policy -event app3 echo " All done with installs" Thanks for any help in advance!!
Hey JAMF nation!I'm a fairly new JAMF admin that inherited an on-prem instance that is about to be retired. I've also been tasked with researching what to replace our current setup with. I know a lot of you guys are working in the cloud so it's been kind of hard to find a lot of info for on-prem JAMF setups. For the people with on-prem setups, what does your hardware look like? This is our Current setup: * 4 physical Servers (clustered) the JAMF Pro Web App on Red Hat enterprise. Dell Power Edge R430's * 1 Physical box we use as a load balancer on Ubuntu, Dell PowerEdge R610 * 3 physical distro points running Ubuntu, PowerEdge R430's * 4 Mac minis serving as distribution points at our “imaging” site * 14 mac minis that we have set up as Caching servers for Apple content * Our JAMF SQL database lives on a VM running Cent OS I think my main question is there any benefit
Hello, I have an Ipad working with Jamf Pro. I pushed to the device the Jamf Self Service App and on the Parent App scanned the QR code. While it looks like they are linked, the Parent app is not causing any changes to the Ipad. Under "Device" I see the battery usage is 100%, when it's actually much lower; so I don't think something is connected right. I am able to push policies and App's to the device but I'm not sure what I might be missing? Thanks!
Hello All, I am having a problem with the FileVault personal keys which are being saved to Jamf pro server. All keys appear with a long string of characters. I got stuck with recovery screen and need to have recovery key to proceed. I did check multiple articles but couldn't find much information on the key retrieval. Here are my FileVault configuration profile settings. Can you please help me on this?
Thanks to Mr Larkin's awesomest script ever :) I have now managed to geta report for Users and Macs by using Extension Attribute as below. Login to your JSS Settings Inventory Options Inventory Collection Preferences Extension Attributes Add Extension Attributes Input Type: Populated by Script Then copy and paste the script below in to "Mac OS X Script Contents" section #!/bin/sh echo "<result>`dscl . -list /Users UniqueID |awk '$2 > 500 { print $1}'`</result>" Click "OK" Click "Save" In Inventory create new Advance Search and in Display Fields select the Extension attribute that you have created. Thanks again Tom Cem
Hello,We are facing issue with dmg files only on intel macs. The error msg is " Error: An error occurred attempting to mount the package "ideaIC-2022.2.1-aarch64.dmg". ". But works fine with M1 Mac's. I had attached the logs screenshot .
Does anyone have recommendations for Mac OS-friendly hardware monitoring solutions? Whether they be custom scripts or tools within Jamf (preferred) or a 3rd party platform. I would like to be able to get alerts on common hardware and software issues such as: Hard drive capacity Fan status CPU/mobo temps Other critical hardware issues such as bad memory, bad HD sectors, etc. Application load time Application crash data I know Lithium was a great tool back in the day but I haven't seen much on this front in recent years. We currently use Zenoss Core for monitoring our server infrastructure, but it doesn't scale well to desktop compute. Any recommendations would be most appreciated, thanks!
I have traversed this site, looking for scripts or other means to provide users temporary admin rights. Most discussions provide two scripts, however, they do no show how to configure them from within Jamf JSS. One such example is from the github site JPDyson https://www.jamf.com/jamf-nation/discussions/6990/temporary-admin-using-self-service.My question is, how are these scripts set up in Jamf JSS, so that they will work? Or, if there is a better approach, that would be great to know...
I have a profile set to use Message as the screen saver. Dose anyone know how to set the message for the screen saver via script?Thanks
Hi there,I've had a request from our CISO about restricting the following command (and any others in the future):sudo -sWe still want to allow people to run sudo, but within their own shell, so restricting access to Terminal/iTerm2 is not an option.What we need to do is still allow people to run sudo commands, but not be able to open a root shell by using sudo -sAnyone have any ideas?
Hello,We're scheduling to update all our machines that can update to the latest macOS Monterey.Running across many issues, mac's prompt 'mac up to date' or 'no updates available', tried manually on the app store, but just keeps spinning.would love any advise
Is there a way to push out a new NTP server address to iPads? Our ISP has blocked access to all NTP servers in an attempt to mitigate exploits in the NTP protocol (there excuse) and the only on I have access to is theirs. I was looking around and could not find a way to push out a new server address...
Script works properly when launched from terminal, but fails after being executed as a policy. Self Service tries to open, then crashes. App version is 10.35.0, the OS it gets executed from is 10.14.6, fully patched. The same script fails on a manually upgraded Catalina as well. (Did it for testing purposes, just to see what happens; system is already running 10.15.7). #!/bin/zsh # ######################################## # Global Variables ######################################## loggedInUser=$( /bin/echo "show State:/Users/ConsoleUser" | /usr/sbin/scutil | /usr/bin/awk '/Name :/ && ! /loginwindow/ { print $3 }' ) # Get the current user - shell agnostic (sh, zsh, bash, dash) myJamfHelper="/Library/Application Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper" # Path to the jamfHelper binary - not part of PATH by default ######################################## ######################################## # XXXXXXX XXXX OIT Notification Variables
Hello, I am relatively new to working with JSS, but here is what I want to accomplish. I would like to set a Screensaver for all users that uses the Message screensaver with our custom text. How would I go about doing this? I assumed this would be a simple task, but there isn't any new information that I can find. Thanks in advance!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!