Get Support
Recently active
I'm looking for a way to find out how many licenses I need for apps without having to note which smart groups are assigned to every single app. Ideally it would be a query (API or SQL, doesn't matter) to find an App Name and its license count, as well as the number of devices it is scoped to. In my mind it seems like such a simple thing, but I don't quite have the knowledge of what each table lists or even which is the correct table to pull that information from in the database. Does anyone have a script or query that they use themselves to pull this information? Any help is appreciated!
HIIm trying to setup a custom path on the inventory collection i want it to collect everything in the Users application folder but i dont know the syntax i need to use users/johndoe/applications ??
Hello,As of right now we enroll MacOS Devices in these steps.Depnotify -> Self Service opens -> Sign in with Microsoft account -> Click Register Device (This is a register to intune policy) -> Sign in with Microsoft again -> Keychain popup opens -> Sign in with Microsoft again -> Type local password to approve saving in keychain -> done.I already attempted to trigger the register to intune policy after depnotify ends, this should already prepare SSO so a login to the Self service is no longer needed. However, this seems to break the SSO. For some reason only triggering the policy from the Self service portal seems to work fine. Has anyone found a way to run the register to intune before opening the self service? And does that work? Additionally, any other tips to reduce the amount of times you need to sign in? Is there a way to automatically allow the keychain popup rather than having to type your local password? Thanks!Tobias
Hi all,We have Jamf ADCS Connector setup and everything is working fine. Certificates can be delegated and no issue there but..We have recently realised under PKI Certificates -> And under the Certificate Authority then under Active there is a lot more issued certs and a lot on "Pending Revoke" than there is devices. And so far we have only seen iPads on status "Pending Revoke".So we have a iPad and we tested this out - we added the iPad on the profile that delegates WiFi and the Certificates and the iPad is on and connected to a WiFi so it has internet but it is in locked screen. What we see is that Jamf asks the ADCS Connector for a cert while the iPad is on locked screen -> the Connector does its job and asks the CA for a cert and retrieves it -> and then i assume it ships it back to Jamf and then when Jamf tries to deliver the cert it cant because the iPad is on locked screen. It then waits and waits for the iPad to be unlocked but if it takes too long eventually the certi
Hi all,I've been working on the OneDrive deployment some time ago, but it wasn't something we want to use at that time.Things changed and now we want to look into deploying OneDrive and a nice config to a set of test machines.Deployed the standalone version to a machine from here.https://support.microsoft.com/en-us/office/onedrive-release-notes-845dcf18-f921-435e-bf28-4e24b95e5fc0#OSVersion=MacPushed our desired config to the machine and nothing happens... updated our plist to a very simple one:<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>OpenAtLogin</key> <True/> </dict> </plist>Still the app won't open at login.Does it require a user to initially sign-in first or missing something else??Thanks!
Hello everyone, We use JAMF School to manage our iOS devices. We are primarily a Windows environment when it comes to laptops and desktops. We currently have new and older MacBook’s(iMacs too) that are not in the domain. They are stand-alone. For security reasons we need to start authenticating users when it comes to macOS devices. I have read some documentation regarding authentication via Azure or LDAP. What would be the pro and cons of going with either one? Also, would it join the domain after the Device enrollment? If so, would those configurations be done in the organization settings or within the profiles? I also read about directory binding. Would this need to also be configured, or is it something not related? I have several questions to have a better understanding before moving forward. Any help would be greatly appreciated.
Jamf pro cloud - ipads/Iphones not updating using mass action command download, install, and restart devices.They have full battery. One is on wifi, one connected ethernet using an adapter, another device is using mobile data. Under the management commands on the device, the scheduleOS update command is just pending, and there's hundreds of them. Like it's trying every day, all day long for the last week.I saw some posts from a couple years ago on the jamf nation forum discussing this issue with no resolution. Has anyone else experienced this?
We want to be able to send notifications to our iOS devices. We have about 50 of them enrolled in Jamf Pro currently. We have not tried to use self service until now. I went to the settings and under the Self Service section went to iOS and selected the "Automatically install self service app" option, then on the app options selected "no login" as we have several devices where there isn't one user and those are setup sort of like a kiosk but with more than one app available. Of all the devices, the only one that immediately installed self service was an iPhone 6 running iOS 12 (which is the latest iOS it will install). All other devices are on iOS 15 and have a command under the completed commands in management history that says "Install App - Self Service" but nothing was actually installed on the device. What do I need to do to get the self service app to install on all the devices?
In preparation for the JAMF bind apocalypse... I'm looking to find machine certificate alternatives for 802.1x wired and wireless.Currently, for 802.1x wired and wireless, we use machine certificates requested from a Windows PKI server. It has worked quite well. However, in the future when we are unable to bind MAC's to AD... we are looking at alternatives.Has anyone been able to use the machine certificates generated from the JAMF PRO Built-in CA for 802.1x using configuration profiles??
I have 10 MAC device which i have already joined to Active directory. My question is how to control MAC device like windows PC which is mention below through Active directoryGroup PolicyPatchingSCCMPassword Sync with ADUser & Machine certificateI need help badly. Thank you
I want to take an exported list of SNs from jamf and run a command in terminal against it, what's the easiest way to do that?
We are deploying and running a bunch of policy and scripts to computers, but if these run into errors you need to open the logs for that policy and look for any errors.Is there a way of creating dashboards which shows recent errors in scripts or a way to forward the errors to an external app for processing and dashboard creation.
Hi, I'm trying to Download the latest version of Adobe Express and while its listed in the App store with this name and we pushed out previous version called Adobe Spark its not updating on the iPads and Jamf is only recognising Adobe Sparc . It's a free App and have test the App sync with another Adobe App and it has synced in Jamf Pro without any issue. Any ideas on this would be much appreciated. Kind Regards, Ger Keane
We're experiencing NilObjectException Errors while imaging our MacbookAir6,2's using ThunderBolt to Ethernet from our 10.8.4 NetBoot Image. Is there any sufficient documentation to fix this on the 8.72 JSS. It's almost 50/50 as to when it occurs, I can image get the error then re-image and not get the error. It's then about 50/50 as to whether it will be able to recon and enroll itself properly. We've also seen a less common IOException Error. We've had to manually delete the JAMF Keychain in the Library/App Support/JAMF folder to get these machines to enroll. We're not sure if they're going to pose additional errors in the future. We thought it may have been a bad NBI so we built a second one, and same occurrence.
I have a dmg from a vendor and you run it and drag the app into the applications folder (nothing new, we all know this is process). Is there a way to have JAMF do this using the same dmg?
I am having trouble packaging and deploying macOS Monterey. Should you upload the installer as a DMG or PKG file on JAMF? How do you deploy Monterey installer silently to a user's machine and have the installer run automatically without any user interaction?
First post. Be kind, please! What do you do when when the driver always pops up a window at install to find the ip of the DFE? The current crop of Fiery drivers for Xerox (looked at both V80 and C70 entry production level machines) are different, I feel, when its time to auto deploy them. You see, in the .dmg, there's a .pkg. So many will automatically say "Put that in Casper and you're done". Well, close, but no cigar. When you do put the pkg in casper, it deploys, yet you still get the window appearing to locate the ip of the printer (anyone who installed a Fiery driver will know what I'm talking about). Thus you exhale a silent curse to the gods, and you proceed to unpack again the dmg to examine it more closely. What you find is that there's actually two scripts in there, one calling the other. There is, however, a glimmer of hope in the sense that installer.sh script can apparently be passed arguments. If you look at the first image below, at line 31 to 35, you get t
Hi there,is there any Documentation from Jamf how to set Azure Correctly to enable oAuth2 for Exchange ActiveSync Payload in Mobile Device Config?OAuth Sign In URL: https://login.microsoftonline.com/TENANT-ID/oauth2/v2.0/authorizegives me an Error: OAuth Sign In URL contains an invalid Value.
The school I work for wants to block students from accessing youtube.com/shorts. If I add that URL to the Blocked list in the configuration profile, it blocks all of YouTube as well. That we don't want to block. Is there a way to do this?
Hello all,We leverage Jamf Connect via Microsoft Azure without any AD binding. What is the standard procedure if an end user forgets their local signed password to get back into their account on their machine?I linked an article which walks through the standard process with a special callout to step 3 in the process. Has anyone encountered this and how would you resolve?https://confluence.appstate.edu/display/ATKB/How+Jamf+Connect+Syncs+Your+Mac+Password+After+a+Password+Change
Hi there,I have tried to search for an answer but have not found anything relevant. We are wanted to use the patch definition to find computers that need security updates applied.While Catalina and BigSur patch definition only contains their versionsApple macOS Catalina: 10.15 (19A583) to 10.15.7 (19H2026)Apple macOS Big Sur: 11.0.1 (20B29) to 11.7 (20G817)Monterey contains all macOS versions Apple macOS Monterey: 10.9.0 to 12.6.0This causes the UI to show more computers needing Monterey security updates than the number of computers actually running Monterey.Why the definition of Monterey does not follow the same patters as Catalina or BigSur where they only show the versions application to their own.Will it be possible for Jamf to fix the definition for either Monterey or Catalina and BigSur so they follow the same pattern.Note: We have used Smart Groups to find the actual numbers of computers needing security updates for Catalina, BigSur and M
This is my end goal:1. User plugs in USB (which will probably be a launchdaemon)2. If not encrypted prompts user to encrypt3. If selects Encryption, encrypt USB. 4. If not it is read only (which is set up in JAMF currently).Will need this to be internal and not a software purchase so a script is what I am working on. I am having issues figuring out how to encrypt the USB. Below are some articles I've read but doesn't actually show how to encrypt the USB. There are options within diskutil man page but I may be reading or doing something wrong as it does not encrypt the USB and fails. Any assistance would be appreciated. https://www.jamf.com/jamf-nation/discussions/8306/eject-usb-if-its-not-encryptedhttps://www.jamf.com/jamf-nation/discussions/21629/restrict-external-usb-devices-but-allow-encrypted-usb-devices
Hello, I am fairly new to JAMF Pro and have had mostly good results. My new devices auto enroll fine and get all required policies. Most of my older devices have also been fine when completely reloading them before enrolling. I am however having some issues with devices that are in the wild getting policies after I enroll. So I have been visiting offices and manually installing the enrollment profile on devices that used to be enrolled in our Mac Server MDM instead. While the profile installs fine and it auto pulls the MDM profile and another, the rest of my JAMF configs in at least 1 case haven't installed after 12 hours and multiple reboots and terminal command sends. Looking in JAMF pro the devices still shows just basic enrollment but no group memberships or config profiles and policies for the device (but the device HAS been added to several static groups). I don't know what to do in these cases? What is a normal
Our jamfcloud instance was updated over the weekend to 10.41.0. This morning I created a new policy and tried to upload an icon for self service, but when I click Upload icon > Choose File > pick the icon > Click Upload, the entire page for that policy reloads and it doesn't actually upload anything. I've tried a dozen times with different .png files (all created using known good methods and tools I've used a hundred times before). If it makes a difference, we do have Cloud Services Connection enabled.Is anyone else experiencing this after updating to 10.41.0?
This is my script to notify user that app will be closed.It is working without trying to use parameters while configuring script. With coded data to processName and appName notification is working flawlessly.But I don't want to create script for each app that needs this functionality, that's why I'm asking for help with this script.#!/bin/bash #set -x processName=$4 appName=$5 message="$appName app is currently open. By pressing <Proceed> app will be closed and process will continue." echo "$(date) | Waiting for other [$processName] processes to end" while ps aux | grep "$processName" | grep -v grep &>/dev/null; do HELPER=`/Library/Application\\ Support/JAMF/bin/jamfHelper.app/Contents/MacOS/jamfHelper -defaultButton 1 -lockHUD -description "$message" -windowPosition c -title "$5 Update/Installation" -windowType hud -button1 "Proceed" -alignDescription center -alignHeading center` if [ "$HELPER" == "0" ]; then
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!