Get Support
Recently active
I am setting up ipads for a shared class environment using the Shared iPad prestage enrolement.I have set up a config profile to tie down the iPads. When the iPads log out they clear all the browsing data etc but I want to be able to disconnect the guest user from the wifi. Does anyone know a way of disconnecting from wifi automatically when the iPad logs out?Also does anyone know does they prestage enrolement timeout session actually work? Thanks
I've noticed that if you do a mass-action command to upgrade iOS devices (say 10k), the DB load increases a LOT for the next couple of days. My guess why this happens is because devices are locked and Schedule OS update is sent over and over. Or the OSupdatestatus command is instead sent over and over since the devices don't actually update for some time as the users don't explicitly do the update when prompted or the device remains locked for a few days.I'm assuming the increased load comes from that JAMF needs to keep track of all these devices until they update. But isn't there a smarter way to do this? For instance, why does it need to send the Schedule OS update over and over? Why does JAMF need to send OSupdatestatus over and over, especially since JAMF pro doesn't do anything with the data collected?Just thinking that this flow could and should be optimized as it is currently a bad idea to use for a larger number of devices. Any dev for JAMF pro that has any input on these thoug
Dear community,I'm trying to write a small script which helps me to automatically upload the photos of our students that our teachers can see them in the JAMF teacher app and the Classroom app. I found the following very promising endpoint: https://api.zuludesk.com/teacher/uploadPhoto (https://api.zuludesk.com/docs/#api-Teacher-uploadPhoto)Currently, I have the following issue: I'm trying to authenticate the teacher with the following route: https://api.zuludesk.com/teacher/authenticate (https://api.zuludesk.com/docs/#api-Teacher-Authenticate). Before doing that, I need to get the company ID with https://api.zuludesk.com/teacher/companies (https://api.zuludesk.com/docs/#api-Teacher-Get_companies) but I get the error "404 - Not found". The request is set to "POST" and authentication to "Basic Auth" with username "Network ID" and password "API Key". Other endpoints are working fine (i. e. https://api.zuludesk.com/users/groups).
At one point, I was able to create, edit, save Scripts in Jamf Pro using my Standard User account that had Full Access/Administrator. I am now using my LDAP User account that also has Full Access/Administrator. Now the LDAP account and my Standard User account are no longer able to create, edit, save Scripts.When I try to save the script, I get error "403 Access Denied. Contact your IT Administrator for assistance". From Jamf Pro User Accounts & Groups, I've confirmed all the checkmarks are there (although they're grayed out).Am I missing setting that will allow me to save scripts?
Hello all,I'm a new JAMF administrator for a University employing around 3500 individuals. Had a situation pop up last week with one of our departments, and while I'm finding similar threads in the JAMF community I haven't stumbled upon one quite in the situation we are in. We met with one of our department heads recently. The department has purchased approximately 60 new iPhones to replace 60 aging iPhones for her personnel. All are managed via JAMF Pro. Unbeknownst to us, Apple IDs were created by the department and setup on all 60 iPhones. These Apple IDs are being managed by the department head who is now finding its becoming quite tedious to manage all these Apple IDs. We as an organization have not restricted the ability to sign in with a personal Apple ID. I've been asked to look into if there's a way to remove the use of these 60 or so privately managed Apple IDs on the new phones that are going to be deployed. The department head though is asking if we have the
Hi, I would like to know if it is possible to download a report about the Jamf Users & Groups from the setting( not computer/device users), or if it is possible to create a smart group with only the Jamf users in it.
I'm attempting to switch computers from Jamf Now to Jamf Pro. I created a configuration profile for disk encryption and it's showing the device is encrypted. However when I view the settings on the device via inventory in Jamf, there's no Disk encryption configuration and the PRK is "unknown". When I try to reissue, the policy just sits at pending despite logging out/in or rebooting. I haven't been able to find anything helpful in documentation or on the web. Thanks.
We have just received our first M2 mac and it seems off the bat that there are some issues with enrolling it - usually during enrollment from our JAMF site (that we carry out with M1 and Intel macs) we could profiles installed onto the machines but with M2 I see for the first time it needs a QuickAdd package installed that completes installation. This always fails and then when I try manually enrolling with sudo jamf enroll -prompt I get the message - An error occurred while enrolling computer: The jamf binary could not connect to the JSS because the web certificate is not trusted. Checking in the background for policies that use the Enrollment Complete triggerEnroll return code: 70 We are currently using the in built JAMF CA cert...would this be causing it?
Hi,I was wondering if anyone can point me to a resource or a script that I can run via policy using Jamf Helper that will check the version of the installed O/S and if it's not equal to the latest we're supporting will advise the user how to upgrade and will potentially remind them once every week until it's done. I do not want to force the upgrade just remind users and give them the steps to update ie: Apple Menu-About This Mac-Update. If there's a better way to do this without a script I'm also open to that alternative but I think Jamf Helper might be the best way. Thanks in advance!
I have a case opened with support but hopeful maybe someone else has an idea for this. We have a few Apple TV 4k's we are trying to enroll in jamf. I was able to get it to show in AC2 and I prepared and wiped the device and it showed up in our DEP. The device shows up in my prestage in JAMF but no actual device exists in my inventory. When I try to step thru the apple TV, I get to the screen asking about remote management, when I click continue, I get an error saying Invalid Profile. Anyone seen this or how to fix this?
I understand the built in log out trigger is long gone, are there any newer workflows for running scripts at logoff?
Hi folks, hopefully someone can help. I've arrived in a new role at a new organisation and in the last week we have seen a huge increase in devices becoming unregistered from Intune - previously this happened at a rate of around 1 per week, but I'd say there's been 10-15 devices in the last week with this issue. Also, when users try to re-register their device via Self Service, it will go through all the steps (Self Service > Company Portal > Jamf Page) but not actually re-register the device. In most cases, the solution is to remove the MDM and re-enrol. I inherited this setup, but it was configured following this guide from Microsoft. Also, I don't have direct access to Intune (it's a financial company) but I can make requests for changes to be made on that end. So - where do I start trying to troubleshoot this? What logs am I looking in? What errors am I looking for? Thanks,David.
This morning my users started complaining that they could not log into their systems. I noticed that my JAMF Connect MenuBar ProfileJAMF Connect Login ProfileJamf Connect License Keyare missing from some of my users that I know were there.what happened?
Hi all,I’ve been asked to block AirDrop on some students iPads. There’s an option in profiles in Jamf Pro that says Allow AirDrop and I restrict it. The only thing that’s happening to me is that the AirDrop function in Settings disappears and the AirDrop option in the control centre is disabled but AirDrop is still enabled.Is there something I’m missing here? Can I enable AirDrop to Contacts Only via profile? Thanks
Good morning,At the end of the week we received some reports that several of our endpoints had missing profiles. This was caught because of one configuration profile that is used on a small number of machines is to set a custom background. That background was reverting back to the default Monterey one and forced an admin to check and see that all of the profiles we employ for that set of machines was missing. The MDM status was also reported back in the console as 'No'. On a couple of these, it seems like re-enrollment resolved the issue but we are still wondering what could have triggered this. Some of these machines were recently upgraded to Monterey over the past few weeks. Has anyone been seeing behavior like this? Anyone have any ideas on what could have caused it? Thank you!
What is the proper way to make a macOS Monterey Smart Group? Typically I put in the macOS number as the criteria (10., 11., etc) but that doesn't seem to work... It's catching OS X Sierra 10.12.x machines in it.
Hello, I want to enforce a password policy with existing computers. After creating the configuration profile. How do I go about forcing the user to reset their password to something that satisfies the password profile. Also taking into account that there is a hidden localadmin account on the machine and I do not want that account to be asked to change the password. Just the employees user account. Any thoughts? Thanks
Hi everyone, We have PreStage Enrollments and we now have 2 Macs which initially enrolled and I see them registered in Jamf. The problem is, they do not check in after the initial registration and does not get our standard apps (which deploy via smart group targeting a policy for installs). I see that the device does get the configuration profiles and it registers in Jamf but after that initial it seems to not check in any more.Any suggestions where to look?
No text available
While this is, arguably, a feature that Jamf should be able to handle at its core, what is the best method in 2021, across the gamut of supported OS's and architectures, to enforce Apple software updates? I understand that theres resistance to using any terminal commands for software updates. As stated in the Nudge channel, Since 2018 this has been a problem since Apple doesn't test softwareupdate commands that are triggered by a script. In addition to that, this requires a password if the computer is Apple Silicon. I recently rolled out the UEX-Tool-For-Jamf, and two of the components in it are no longer developed and throw gatekeeper issues in Big Sur. I would like to use Nudge, but, my confidence in my users is low enough to not expect Nudge to work fine on its own. Nudge cannot force the update to happen. What is the best way to handle software updates? Is there MDM magic I am missing? What is the downside to having the checkbox "keep my mac up to date"
I would like to upgrade to Ubuntu 20.04 LTS but do-release-upgrade forces me to prior install all updates for my current release. I hold back the mysql update because of the issues from Jamf 10.41 with mysql 8.0.30 using apt-mark hold mysql*.Any suggestions how to get to Ubuntu 20.04 and leave mysql on version 8.0.29?
Warning! With Jamf Parent, there is currently no way to unlink parent control of a device. There is a way to clear currently pushed settings, but the parent app still has the ability to reset those settings. This becomes a huge issue especially if one student's iPad is taken into Jamf Parent by another student, and now that second student has unvetted and unbreakable access to control the first student's iPad, without any sort of tracking available. Please +1 this feature request to help resolve this issue. Thanks
Hello, we have recently received complaints from multiple users saying their mac closes all applications which are not running when they lock their mac and log back after few min .And they are getting the below error message when they log in back
Anyone know of a way we can allow only "Security & Privacy / Privacy / Automation" without opening up the entire Security and Privacy area of System Preferences? Thanks!
Jamf pro cloud - ipads/Iphones not updating using mass action command download, install, and restart devices.They have full battery. One is on wifi, one connected ethernet using an adapter, another device is using mobile data. Under the management commands on the device, the scheduleOS update command is just pending, and there's hundreds of them. Like it's trying every day, all day long for the last week.I saw some posts from a couple years ago on the jamf nation forum discussing this issue with no resolution. Has anyone else experienced this?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!