Get Support
Recently active
Hi, Tried to enable memcached across 3 servers. config as per documentation. memcached is communicating , however, i'm getting this error on the non primary servers Type Status Report https 404 - not found Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.
Right. Where do I begin.... I am going to try and be as constructive as possible rather than just complaining. We've been running Jamf Pro (currently 11.4.2) for almost two years. Since day one we had issues with out of the box or EACAS Macs fully completing enrolment. The usual state they would end up in was for the profiles to install fine, VPP apps to install, etc, but for no policies to run nor for Self Service to install. When I looked on Jamf Nation and other sources I saw that this can sometimes happen and so because I'm a scripting god I came up with an amazingly complex script that is installed as part of an PreStage Profile's enrolment package workflow. The script does the following:/usr/local/bin/jamf policyThis immediately caused enrolment to complete, the Self Service app appeared in /Applications and everything was once more right in the world. A reboot would achieve the same, but we didn't want to randomly reboot the Mac halfway through enrolment or ask the user to
I have discovered a new problem, new computers enrolled in jamf using Dep and onboarding are not fully enrolling also computers that are already enrolled when an inventory runs the computer record is not updated, looking at the logs the last inventory should have updated on the 11th / 9.on new Macs I can run recon, policy manage and renew profiles and even push the framework from the api they still don't get an enrollment complete policies and profiles get installed but no apps,on already enrolled Macs everything works except the inventory does not update I have tried stripping back the enrolling all different Macs also different networksthe jamf management daemon is not installed also self service does not launch bellow is a log from an new enrolled computer Sun Sep 28 03:12:45 iMac jamf[1139]: The SSL Certificate for https://xxxx.jamfcloud.com must be trusted for the jamf binary to connect to it.Sun Sep 28 03:12:45 iMac jamf[1139]: Enrolling computer...Sun Sep 28 03:12:46 iMac jamf[1
Good day, all! I have a couple of PreStages set up to configure newly purchased Macs for our environment that utilize JSM to install apps and configure the systems. I want to now tackle Macs already in our environment by having the customers, or our technicians, manually enroll them via the web, chiefly because they’ve already been in use and configured, and wiping them to put them in ASM isn’t an option. I want to utilize JSM to do some configuration and prompt for inventory information (ID, email, location info, etc.). Based on this discussion thread on JSM’s GitHub (https://github.com/jamf/Setup-Manager/discussions/88), I know that it’s possible to use JSM for user-initiated enrollments. My problem is that I cannot find anything on how to actually do it. Anyone out there have or know of a site, documentation, group discussion, or anything that would help me? Thanks in advance!-Terry
Hi all I’ve got an problem with my Jamf deployment at the moment and the way we use our iPads. Essentially, our filtering and monitoring solution relies upon an app being running in order to re-connect the filtering VPN if disconnected. When teachers restrict students to a specific app or apps, the filtering and monitoring app gets disabled and thus the VPN disconnects.Is there a way to force an app to never be able to be disabled by Jamf Parent or Jamf Teacher? ie. I’d like it so that if a teacher says “Right, no more anything other than Goodnotes” the filtering and monitoring app is not disabled and continues to run. Thanks in advance for any advice with this.
Hi All,I need to disable most of the "More Gestures" (third tab of System Pref>Trackpad ) for MN Online Assessments.I have tried a custom Config Profile/user level which I created by uploading the trackpad plist, but while I was able to save it, it would not deploy.The rest of my profiles appear to be working, and the test computer is receiving all other expected profiles.MCX Settings in this area specifically say 10.6 onlySo I'm trying to package using Composer>Monitor File System ChangesThe files it appears to effect are~/Library/Preferences/ByHost/.GlobalPreferences.xxxxxxxx.plist~/Library/Preferences/com.apple.driver.AppleBluetoothMultitouch.trackpad.plist~/Library/Preferences/.GlobalPreferences.plist I have tried packaging and deploying every combination of these filesDeploy via login policy with: FEU, FUT, Fix ByHost Files The settings are not applying on my target computer (and not after logging out and back in) On my package creator computer with all de
Looking for an alternative to Carddav to push a shared contact list out to shared devices. We have several shared devices that no one will log into M365 on so sharing a contact list to a group of M365 users won't work. What if I set up a shared M365 account, created a standard contact list, created an Exchange Activesync profile in Jamf, and pushed it out to the shared devices as that shared M365 user? In Activesync settings I could deselect everything except contacts.I could share that contact list from the shared account to the entire department so that everyone in the department had the shared contact list in Outlook when signed in to M365. And for the people with an assigned device and sign into M365 on that device, I could direct them to use the contact sync option in Outlook mobile to copy the shared contact list to the native IOS contacts app.Then, I could delegate access to the shared account to designated people in the department so they can manage the shared contact list that
We started implementing Homebrew packages in our deployments.and there are permissions needed for them to run smoothly. When I try get the CDHASH for the binary, they report as not signed. codesign --display -vvvvvv <binary>code object is not signed at allwhen running tccprofile on our test computer, (tccprofile) it reports cdhash for binary <dict> <key>Authorization</key> <string>Allow</string> <key>CodeRequirement</key> <string>cdhash H"5703c8d7d913bc20bb2e219173cd89267b200400"</string> <key>Identifier</key> <string>/usr/local/Cellar/restic/0.18.0/bin/restic</string> <key>IdentifierType</key> <string>path</string> </dict>my question is how to get the cdhash , or how does apple get it when its not signed?
Hi all,Anyone have any skills with deploying NinjaOne to Macs through Jamf?I’m having some troubles deploying Ninja to my environment in Jamf pro. I’m deploying the pkg using a policy. I pulled the pkg direct from my Ninja admin site using their method of acquiring the necessary file. I’m also deploying a config file to allow the necessary streamer application to run in the background and quiet install (see screenshot for config.) Every time I deploy through Jamf, the NC Streamer file does not go to the device, and the device does not enter my Ninja console. When I manually install the same pkg without Jamf, the NC Streamer installs fine and the device is added as a local machine. I’m trying to figure out where I’m going wrong with my install and why this is isn’t working through Jamf. It’s just a simple PKG in a policy and a small config file.Please let me know if anyone has suggestions for me or if I need to provide more info.I have contacted NInja support already. They claim it’s a
With Jamf Pro 11.21, administrators can see impact alert notifications when saving deployable objects, skip a new Setup Assistant pane in macOS Tahoe, and deploy even more configuration profile payloads with blueprints!Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements.Thank you for your continued support and feedback!
HiI am a teacher and have two Mac suites, each with 17 machines. Is there a way to store the machine in the cloud as at the moment pupils are tied to always using the same machine, which isn’t always feasible.
Hello everyone,We’ve encountered problems with personal hotspot in iOS/iPadOS 26.The option to activate it is dimmed on my colleges devices even though she has’t got any restriction profile. Before in OS 18 she used personal hotspot without password without any problem. Now she can (not the normal way) set a password for it but not activate the function/option. And she doesn’t seam to be alone with this problem. In my own case my devices don’t have the problem (have the same profiles as my college), if it matters I’ve always had a password set even when updating to 26.Anyone else encountered the same problem? Does it have to do with Jamf or the OS? Bottom selection of search results. Password set at the option at bottom of search results. Top option of search results, the normal place.
Okay we’ve never had this issue in the past. The prestage enrollment naming requirements ALWAYS take precedence...but for whatever reason, this is not the case. Workflow to replicate:Move device (currently named PS1-Serial) from one prestage to another Perform “wipe” command from Jamf Enroll device under new prestage with new name PS2-SerialUnfortunately on step 3, the device ends up with a PS1-Serial name for whatever reason. Did I miss a PI (product issue) behind this? Is this known behavior? Or am I just losing it from the week of crazy JAMF PIs that I’ve found?!
Don’t forget to sign into your Apple Manager …• Sign into ASM and ABM for updated agreements• Banner: Settings->Global ->Automated device enrollment Accepting updated agreementsAfter Apple updates one of these agreements, any Apple Business Manager Administrator, Apple Business Essentials Administrator, or Apple School Manager Administrator must sign in to the program website to accept any new agreements. If you're an Administrator in Apple School Manager, sign in to https://school.apple.com. If you're an Administrator in Apple Business Manager or Apple Business Essentials, sign in to https://business.apple.com.
Hello,I am having some troubles to connect Jamf Protect with Jamf Pro.Many computers don’t show up in Jamf Protect console despite having the policies generated by the Jamf Pro plan.I am currently debugging on one computer:the protectctl info -v command tell me the connection status is connected, the plan has the correct ID and the tenant point to the correct tenant.The only error I have is when running protect repair, I have a JamfProtect.ConfigProfileValidatorError error 1: no valid content filter profiles installed. (when verifying the daemon status)(I also have Jamf security cloud, and I tried with and without a content filter profile applied, both yield the same error)There are other computers on this plan that do show up in jamf protect console. What could be the issue and how to resolve this ?
Anybody have experience deploying the MyQ X Desktop Client through Jamf?
Now that Tahoe is out of beta, gremlins that I'd noticed earlier now feel more pronounced. During Build testing I find myself frequently running through sudo Jamf recon ; sudo Jamf policyBut since moving to the release of Tahoe they’re just painfully slow to report data. It doesn't matter if it’s an upgrade from Sequoia to Tahoe or fresh install via IPSW. Wired or wireless. ...S.L.O.W… Is it just me?
Hello Everyone, I got a sudden challenge on my desk to get a BYOD system working for our comapny. From my knowledge there isn't a BYOD set up so to say for MacOS. I see user enrollment is the method for this and it enters a un-supervised state. My questions are: how do we differentiate in a smart group who has these machines to get certain policies? How do we remove company data if said user is offboarded for any reason (we don't want to leave the control to the user)? In anyone's experience, what are some best practices from your BYOD setup you have started in your company. I am a small team and JAMF isn't our expertise (working on getting help to dive deeper with MacOS Administration) so any help is GREATLY appreciated. Thank you!
Pro Tip:If you have a need to take action on a a number of devices, no need to put them into a group.Use the blank search and enter serial numbers separated by a comma “ , “ and “ “ space example:serial1, serial2, serial3, serial4, serial5You’re welcome.
Since this came up during our meetup:The name "Jamf" is a reference to Laszlo Jamf, a character in the novel Gravity's Rainbow by Thomas Pynchon. It’s not an acronym. It’s not rude. It’s not what happens when you type “f” really hard.Knowing is half the battle. . .
Need help with Jamf Pro API automation. We're trying to bulk update computer inventory records using the Classic API, but getting conflict errors when posting device information updates.Can authenticate and pull device lists fine, but PUT requests to update asset tags and department fields are failing. Need someone familiar with Jamf's API endpoints and bulk device management.Should be 2-3 hours remote work to fix the API calls and test bulk updates. Need working this week for our asset audit.
Hi all, so we’ve had multiple Macs (all M1 or newer) that have had Tahoe as an update and afterwards the keyboard is unresponsive - built in or external USB keyboard. All you get is the ding noise and from reading, this can be an issue for some. Also seems there is no way to block the installer, just defer is that correct?Well for now I’m trying to see if there is a solid workaround to fix the issue without a reinstall but so far came across nothing that worked for me :( Anyone that knows about this issue, it would be great to get your input.
Does anyone have any suggestions on how we can disable the "add to homescreen" feature in Chrome? Many students are adding games to their homescreen.
Have you ever had to manage devices from a DEP instance you don’t control or even own? Or send DEP or BYOD devices to another campus where they need to be managed with a different MDM? This was the situation we encountered last year, and here’s how we solved it. Institutional ContextOur institution has expanded globally, adding new international campuses in Spain. These schools serve students from K–12, with management needs that differ significantly from those in the U.S. Because of local legal and operational differences, we chose to build independent technology stacks for each campus, modeled after our flagship U.S. campus. This provided consistency while allowing for flexibility.U.S. campus: Jamf Pro + Protect; BYOD model for students, DEP-managed devices for staff and faculty. Spanish campuses: Jamf Pro + Protect + Connect + Safe Internet; all DEP-managed, school-owned student devices.This design gave Spain the flexibility to support younger students in a day-school environment, w
Hello, Has anyone found a way to generate a report to find out if Screen Time is turned on on an iPad. From what I can tell that information does not seem to be available in Jamf Pro. Thanks! --Josh
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!