Get Support
Recently active
I understand the built in log out trigger is long gone, are there any newer workflows for running scripts at logoff?
Hi folks, hopefully someone can help. I've arrived in a new role at a new organisation and in the last week we have seen a huge increase in devices becoming unregistered from Intune - previously this happened at a rate of around 1 per week, but I'd say there's been 10-15 devices in the last week with this issue. Also, when users try to re-register their device via Self Service, it will go through all the steps (Self Service > Company Portal > Jamf Page) but not actually re-register the device. In most cases, the solution is to remove the MDM and re-enrol. I inherited this setup, but it was configured following this guide from Microsoft. Also, I don't have direct access to Intune (it's a financial company) but I can make requests for changes to be made on that end. So - where do I start trying to troubleshoot this? What logs am I looking in? What errors am I looking for? Thanks,David.
This morning my users started complaining that they could not log into their systems. I noticed that my JAMF Connect MenuBar ProfileJAMF Connect Login ProfileJamf Connect License Keyare missing from some of my users that I know were there.what happened?
Hi all,I’ve been asked to block AirDrop on some students iPads. There’s an option in profiles in Jamf Pro that says Allow AirDrop and I restrict it. The only thing that’s happening to me is that the AirDrop function in Settings disappears and the AirDrop option in the control centre is disabled but AirDrop is still enabled.Is there something I’m missing here? Can I enable AirDrop to Contacts Only via profile? Thanks
Good morning,At the end of the week we received some reports that several of our endpoints had missing profiles. This was caught because of one configuration profile that is used on a small number of machines is to set a custom background. That background was reverting back to the default Monterey one and forced an admin to check and see that all of the profiles we employ for that set of machines was missing. The MDM status was also reported back in the console as 'No'. On a couple of these, it seems like re-enrollment resolved the issue but we are still wondering what could have triggered this. Some of these machines were recently upgraded to Monterey over the past few weeks. Has anyone been seeing behavior like this? Anyone have any ideas on what could have caused it? Thank you!
What is the proper way to make a macOS Monterey Smart Group? Typically I put in the macOS number as the criteria (10., 11., etc) but that doesn't seem to work... It's catching OS X Sierra 10.12.x machines in it.
Hello, I want to enforce a password policy with existing computers. After creating the configuration profile. How do I go about forcing the user to reset their password to something that satisfies the password profile. Also taking into account that there is a hidden localadmin account on the machine and I do not want that account to be asked to change the password. Just the employees user account. Any thoughts? Thanks
Hi everyone, We have PreStage Enrollments and we now have 2 Macs which initially enrolled and I see them registered in Jamf. The problem is, they do not check in after the initial registration and does not get our standard apps (which deploy via smart group targeting a policy for installs). I see that the device does get the configuration profiles and it registers in Jamf but after that initial it seems to not check in any more.Any suggestions where to look?
No text available
While this is, arguably, a feature that Jamf should be able to handle at its core, what is the best method in 2021, across the gamut of supported OS's and architectures, to enforce Apple software updates? I understand that theres resistance to using any terminal commands for software updates. As stated in the Nudge channel, Since 2018 this has been a problem since Apple doesn't test softwareupdate commands that are triggered by a script. In addition to that, this requires a password if the computer is Apple Silicon. I recently rolled out the UEX-Tool-For-Jamf, and two of the components in it are no longer developed and throw gatekeeper issues in Big Sur. I would like to use Nudge, but, my confidence in my users is low enough to not expect Nudge to work fine on its own. Nudge cannot force the update to happen. What is the best way to handle software updates? Is there MDM magic I am missing? What is the downside to having the checkbox "keep my mac up to date"
I would like to upgrade to Ubuntu 20.04 LTS but do-release-upgrade forces me to prior install all updates for my current release. I hold back the mysql update because of the issues from Jamf 10.41 with mysql 8.0.30 using apt-mark hold mysql*.Any suggestions how to get to Ubuntu 20.04 and leave mysql on version 8.0.29?
Warning! With Jamf Parent, there is currently no way to unlink parent control of a device. There is a way to clear currently pushed settings, but the parent app still has the ability to reset those settings. This becomes a huge issue especially if one student's iPad is taken into Jamf Parent by another student, and now that second student has unvetted and unbreakable access to control the first student's iPad, without any sort of tracking available. Please +1 this feature request to help resolve this issue. Thanks
Hello, we have recently received complaints from multiple users saying their mac closes all applications which are not running when they lock their mac and log back after few min .And they are getting the below error message when they log in back
Anyone know of a way we can allow only "Security & Privacy / Privacy / Automation" without opening up the entire Security and Privacy area of System Preferences? Thanks!
Jamf pro cloud - ipads/Iphones not updating using mass action command download, install, and restart devices.They have full battery. One is on wifi, one connected ethernet using an adapter, another device is using mobile data. Under the management commands on the device, the scheduleOS update command is just pending, and there's hundreds of them. Like it's trying every day, all day long for the last week.I saw some posts from a couple years ago on the jamf nation forum discussing this issue with no resolution. Has anyone else experienced this?
Happy Monday all (🤣) So last week after successfully making a script on the classic api to change a site for mac using bearer tokens and properly salted/hashed api creds, i'm now on to my next challenge of using the preview api to set the recovery lock ready for all these MBP M1 pro's that are arriving shortly :- https://developer.jamf.com/jamf-pro/reference/post_preview-mdm-commandsso after getting to grips and trying to utilise the nice example generator, i send this to it in a script but all i get back is " [ ] " so not even a proper rejection.can I assume first that the "managementid" is the UDID of the device and the clienttype is correct for a macOS device?? code below.. NB. its worth noting in actually passing the managementid as a "'"$UDID"'" as i am running this script locally grabbing the udid via the MBP's serial number from the classic api. I still get the same response.. curl --location --request POST "$jamfpro
Hi,I just noticed a bunch of my computers (about 75%) stopped checking in to Jamf Pro (cloud) on a specific day in August:On running sudo jamf policy I get:There was an error. Device Signature Error - A valid device signature is required to perform the action. Jamf log at /var/log/jamf.log on the client shows:Sat Aug 13 06:22:26 ServerXXX jamf[15424]: Error Domain=com.jamf.jamfsecurity.error Code=-25293 "unlockWithPassword:error: : The user name or passphrase you entered is not correct." UserInfo={NSLocalizedDescription=unlockWithPassword:error: : The user name or passphrase you entered is not correct.}Sat Aug 13 06:22:27 ServerXXX jamf[15424]: There was an error.Device Signature Error - A valid device signature is required to perform the action. The problem seems to be fixed on each client by running sudo jamf enroll -prompt on the client. It's a lot of busy owrk to do this on each client - is there a better way?Also, since this is possibl
User was recently removed from old AirWatch MDM and enrolled into Jamf using pre-stage command - sudo profiles renew -type=enrollment. Before I installed the Jamf profiles on the device, I had to re-bind the machine to the domain because the local password and Okta password did not sync. I then removed it from the domain again and verified the local password now matched the users Okta password. Restarted the device and had user log in with newly updated password. Ran command to install Jamf profiles, restarted the device and had user review and install profiles. After all profiles and policies installed I tested Jamf connect (desktop app) and was able to have the user sign in via Okta. On the next restart where the user has to connect the local account to Jamf connect for the first time it does not take the local mac password that was being used. Keeps saying invalid password. Had user try the old and new password that was on the device and still could not conn
I'm currently testing out a Jamf Now (Fundamentals) deployment for a couple of Macs we have. I haven't used Jamf before so not too sure how Jamf connect should work, but have a feeling mines not correct.I have setup the setting "Enable password sync with Jamf Connect" and done the setup in Azure for it. When a user first logs on it asks to type in both password (microsoft & then local password) so it could sync.Then we changed the password in Microsoft to see if it worked but on the macbook we have to login with the old local password and then in Jamf connect enter the email and the new microsoft password and it says they are out of sync and input the local password.I assume this should be a bit easier as its not exactly syncing the passwords currently?
Has anyone been able to install 1password 8? I have tried installing it on my build Mac and bundling it with Composer. The installer seems to finish, but is doesn't show up under Applications. I have tried pushing the installer to the computer and then running it with a script. the first time I tried the below script, it will download the program and then it asks for admin login.open /path/to/app.app & so I tried this scrip, but it just spins forever.su <admin user - not root> open /path/to/app.app & I know it can be installed via the Mac apps (at least 1Password 7 can), but that links to the App store and I have that locked out so the users are unable to access it.BTW, I'm wanting the app to be available in the SelfService portal.
I'm testing the Mass Action Update on a couple of Mac's. One is an Intel and the other is M1. They both have the 12.5 available update, but when I deploy the command to both, I don't see any prompts where it gives you options when to deploy it. It does show up under their device as pending, but goes away. For the M1, have the bootstrap token on our devices. For the Intel, it looked like it worked, because the Mac is now showing 12.5. Is there a log where I can look up to see if the command ran successfully?
Hi all, Somehow I am unable to install this driver from Apple website: https://support.apple.com/kb/dl1867?locale=en_US We use Papercut as our printer management, but we are unable to proceed due to the driver issues. Even the PPD driver from Ricoh website does not seem to work. Anyone using Ricoh MFP in their environment? How do you install printers on your users Macbook?
My client is going to be migrating from an in-house mail server (Kerio Connect) to Office 365 and I am trying to figure out how to leverage Jamf Pro for this project. The problem is that even though I have decades of experience with Mac administration and with using the VLA version of Office I have no experience with Office 365 and I am finding that some of the setup is frustratingly opaque. Take for instance the Exchange payload when setting up a User-specific Configuration Payload in Jamf: Is the Domain simply the organization's domain? More important, what do I enter for Internal/External Exchange Host, the Ports and the Internal/External Server Path fields?! I have looked at reams of documentation and I can't find a simple answer to those questions. I even asked the 3rd party company that is helping us perform the migration and they were not able to offer any suggestions other than "call Microsoft". If anyone here has any insight I would greatly appreciate it!BTW, this is spec
I remember being able to bypass all of the new user setup steps in macOS in the past, but I don't see how that's done now on newer versions of macOS. I remember there was a payload we could deploy in a configuration profile. We can do this during PreStage but if I setup a hidden admin account, and I later need to login using it, I would like to not have to click through all of the setup steps just to get in and do what needs to be done. Does anyone have a process for this to avoid the setup steps?
I have a LAPS solution running monthly to reset the local admin password but I also want to be able to trigger this after the password has been viewed.I have a custom trigger but without flushing the logs the custom trigger only runs monthly as well.Has anyone figured out a way to have a policy running on schedule but also be able to trigger it from a custom trigger on demand? The only way I see to do this is to create another policy which isn't best to duplicate things just for this.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!