Get Support
Recently active
If you are using SSO configuration and receive the following notification in Jamf PRO or your Jamf Account:“ SSO configuration will be read-only from Thursday, Sept. 10, 5 p.m. CDT to Friday, Sept. 11, 10 a.m. CDT due to maintenance. Creating or editing connections will be unavailable. Login won't be affected. “ Please prepare a standard user account (not an SSO account) in Jamf Pro under:Setings → System → User Accounts and GroupsThis account can be used as a backup to ensure that you can still create or edit configurations in Jamf Pro if there are any issues with your SSO login.
Hello!I am building a package to install FortiClient vpn (the free vpn standalone client) for our users.After several tests, a policy authorizing the security extension is indeed present and allows to avoid blocking it during installation, but a popup asking me to authorize the addition of VPN configuration appears right after the installation.This popup is generated by the "FortiTray" binary and after several tries and I don't know how to authorize it ahead of time so that the installation is totally invisible.It says that ""FortiTray" would like to add VPN configurations"Any idea on how I can authorize this or setup ahead of time ?
Hello everyone,I'm one of our Admins (jPRo) and I work for a very large hospital chain and I've been tasked with exporting all of our mobile devices and asked to create a spreadsheet and a PDF file for presentation for our leadership team to review in their budget meeting coming up soon so they may plan on what we need to purchase as far as EOL devices are concerned.I don't know why, but I seem to be struggling with making this list based on exporting all of our devices which come out to 5,077 devices. I attempted to report my spreadsheet into AI and asking you to make me a list of EOL devices, Near-EOL, and future EOL devices. Well, the numbers that I ended up sending to my manager to review or not accurate, and I looked like a fool and was very embarrassed.Have any of you been tasked with this before and if so, how did you do it and do you have any advice on what the best way to go about doing it is besides trying to use AI. Or, if any of you have been successful in doing this using
Long ago we distinguished between our Staff and Student Macs by “installing” a DMG that just created a folder. We used the search term of “Packages Installed by Jamf Pro” with that DMG name. This has worked fine for us for the past 10+ years. We installed this package on Student Macs and didn’t install it on Staff Macs. If we needed to convert a MAc from Student to Staff, we just used the Jamf Pro capability to “Uninstall” that package. That removed it from the list of “Packages Installed by Jamf Pro”. It seems that with the (no longer recent) removal of Jamf Admin and the ability to index packages, the ability to “Uninstall” packages and DMGs has gone away as well. So we can still install that DMG to tag the Mac as a Student Mac. However, we can no longer “Uninstall” that DMG. Which brings me to my question: How do I remove an item from the “Packages Installed by Jamf Pro” list? This isn’t the same as the package receipt list that you get from running pkgutil --pkgs. I am hoping tha
We use Apple TVs with Playlister throughout our sites, and we’ve been having some audio/video sync issues that are resolved by rebooting the Apple TV. From what I’ve gathered, the only way to reboot all Apple TVs in a group is to manually navigate to the smart group in Jamf Pro > View > Action > Send Remote Commands > Restart Device. This is not ideal not only because it isn’t a process that can currently be automated, but because we would like to have these Apple TVs reboot outside of operating hours.
I’ve had people complain about not being able to get admin rights. It turns out they’ve hidden the Self Service plus app which Tahoe allows. It’s a stupid thing but is it even possible to prevent folks from removing certain apps from the menu bar. And if it’s possible, how do I do it?
The devices that I am managing Shows as MacOS 15.3.1 and shows as up to date. I don't have any restrictions on MacOS update. somehow users are unable to see any new MacOS update? When I try pushing the update through Software update, it's failing. possible it's because these devices were user enrolled. I am trying to get a MacOS 15.5 Pkg and make users download from Self service and update. How to get the latest Pkg or any script that i can use. It's been 2 days of me trying all sorts of scripts and nothing works. Thanks in advance
Does anyone have any guides for getting the dev environment setup for Jamf platform? I want to run a set of platform APIs to verify a user case.
I am looking to report the status of Location Services on our fleet. I found the following script online and tested it but it only reports back disabled even when LS is enabled. Does anyone have a working extension for this? Or can some assist in making this one work? #!/bin/bashuuid=$(system_profiler SPHardwareDataType | grep "Hardware UUID" | awk '{print $3}')domain="/var/db/locationd/Library/Preferences/ByHost/com.apple.locationd.${uuid}"plist="${domain}.plist"if [[ -f "${plist}" ]]then status=$(defaults read "${domain}" LocationServicesEnabled) if [[ "${status}" == "1" ]] then result="Enabled" else result="Disabled" fielse result="Unavailable"fiecho "<result>${result}</result>"
Recently, the ability to manually type in strings to smart group criterion has changed. Now, you have to hit the ellipsis (3 dots ...) button to match your entered string to a smart group before it is accepted and can be saved. Previously, I could just type in the name and if the name matched a smart group, I was able to save, otherwise, the UI would give me an error saying that group name couldn’t be found. But it was easier and quicker because I didn't have to deal with the lookup process.Has anyone else seen this? I submitted a support ticket on this and was told by multiple reps this is now the only supported option and is the expected behavior. Therefore, I have filed a feature request to bring back the old entry method so I (and you) can manually type in a group name. Please look at the request and upvote to get Jamf’s attention on this.https://ideas.jamf.com/ideas/JPRO-I-2243Thank you.
What is learning and do you like to learn?Do you know what content would be relevant for you?Hey, I thought you are here to teach me and not to ask questions.Yes, but questions are a method of teaching and I have a bunch of those.But what about learning, how do we learn or more precisely:What type of learner are you?Auditory / Visual / Read&Write / Kinesthetic(more acronyms, just like a Jamf Class on day one)"So let’s explore."Learning something new has so many options today, not all of them are made for you and me and sometimes I need multiple choices. Not because a resource is wrong, just it connects better with my brain. I remember teaching ski lessons to a bunch of teenagers and I was stuck with one of them on day two. No progress, tried it all, nothing clicked. So we decided to switch training groups. And it clicked, I saw them going down hill super nice. I asked my fellow ski instructor what he did, "same as you before" he said, "maybe just another perspective".While we can’t
I’ve been using iCloud Mail ever since, and I still can’t understand how a mail app can be so frustrating when it comes to basic things like text formatting, copy pasting and handling email attachments, working notifications,…On iPhone, the mail attachment is really horrible… If I want to attach an image the image, it is not separately attached as an own attachment but just lies below the text I wrote… Why??I’ve tried a few other mail apps, but either had security concerns or didn’t want to pay for the Pro features.So this is partly a rant and partly a question: how have you guys managed to make Apple Mail work for you? And if you’ve switched to another mail client that you really like, I’d love to hear your recommendations.
Hi everyone, I. HATE. PRINTERS. That being said, we have to work with them. and... Canon does not make it easy. Here is what I was able to find out from several places online, in order to get this "installer" to actually work. So let's jump on to our Macs and get this over with.Downloading the "Installer"1. Log into your Uniflow Online (web)2. Start Printing (Side Bar)3. Install Printer Driver > Click [Download macOS printer driver] Navigate to Download FolderOpen SmartClientMac.iso > Open SmartClientMac Volume > Notice here you only have 1 file. But actually there are 4. 3 are hidden.On your Keyboard us the show hidden files shortcut: Command+Shift+.(Period)Getting Files in the Right LocationYou will now see 3 other files. We only need the SmartClientForMac.pkg and tenantcfg.plist files.Next, Go to Finder > Go > Go to Folder (Shift+Command+G)Enter 'private/tmp'Next create a new folder called 'uniflowclient'Which is now located in private/tmp/un
I've got an issue with Screen Sharing on to a lab of Macs where the screen is completely black apart from the cursor moving being visable. Using Screen Sharing via Finder or using the Apple Remote Desktop application presents this issue. The only fix I've found so far is to send the "Disable Remote Desktop" command from Computers > Management > Management Commands, force the device to check into Jamf Pro, then send the "Enable Remote Desktop" command to the device. After these steps, the black screen issue is resolved and screen sharing/ARD works as expected. When this issue occurs, I can easily log into Jamf Pro, send the management command to a smart group of my lab Macs, another management command to force them to update inventory, then a third command to force them to re-enable Remote Desktop. Is there any way to automate this process into a policy so an engineer doesn't need to log in and manually run the commands?
I am using the “Mac Apps” to install and maintain a couple of apps. This includes Chrome.I noticed something weird there. For colleague X “Mac Apps” says her Chrome is up2date. But looking at her Macbook and at “Patch Management” she is a whole bunch of Chrome updates behind. Any idea where this comes from?
After wiping and re-enrolling lab machines, approximately 23 out of 29 are showing the native macOS username/password login window instead of the Jamf Connect Login OAuth window. The remaining 6 machines show the correct College branded Jamf Connect login screen. What I've confirmed on the broken machines:JamfConnectLogin.bundle is present in /Library/Security/SecurityAgentPlugins/ Jamf Connect Login is fully registered in the authorization database (security authorizationdb read system.login.console shows all JamfConnectLogin entries) Jamf Connect Login v3.10 and Jamf Connect v3.10 configuration profiles are both installed A StagedPlugins folder appears in /Library/Security/SecurityAgentPlugins/ after every restart but is always empty No autologin configured A conflicting LAB: Login Window Settings profile (com.apple.loginwindow payload) was previously scoped to these machines and has since been removed but this did not resolve the issueHas anyone experienced Jamf Connect Login silent
Hello all, We have been having huge issues with the standard account; cannot update software(Chrome), cannot add personal network printers, cannot add WiFi, etc. So it was the consensus to promote the standard account to an Admin account. I am hoping there is an script to perform this very act, because updating 900+ devices is a little daunting. I see there is a script to demote and we have it in the wings for deployment should this entire Admin rights thing go South. I am no scripter, but know enough to follow through what will happen when things are run. So any and all help is appreciated.
Hi everyone!We recently ran into an issue with our push certificate renewal on our Jamf Pro instance that I wanted to share, along with the workaround we found — in case it helps someone in the same situation.The problem:We had renewed our push certificate several times using different Apple accounts instead of the one originally used. This caused the Topic ID in Jamf Pro to no longer match, which broke our ability to send commands to our devices.It took us a while to notice, and by the time we did, MDM had expired on a large number of our Macs since no commands were getting through anymore.To make matters worse, we had disabled the ability to manually remove the MDM profile on the machines, so we ended up with a fleet of Macs stuck with an outdated/expired MDM profile that we couldn't remove or replace.We contacted Jamf support, and the only official solution was to recover the correct Topic ID by renewing the original certificate — but that wasn't possible for us since we no longer h
We are currently in the process of implementing Jamf Pro in our company environment. So far, we have successfully integrated several scripts, SMB shares, and other configurations, and everything was running smoothly.As the next step, we attempted to set up Jamf Connect in order to integrate a SAML authentication flow via our Entra environment. The goal was to allow users to log in with their Entra credentials during a fresh macOS installation.However, after configuring Jamf Connect, we started encountering a critical issue. The Microsoft 365 login window appears as expected, but after a few seconds, the entire Mac screen goes black and becomes completely unresponsive. The only way to recover from this state is by manually restarting the device.Additionally, since this issue started occurring, our previously working scripts and configurations are no longer functioning as expected.Has anyone experienced a similar issue or has any suggestions on how to troubleshoot or resolve this problem
Hi Nation,Product Office Hours #2 - Jamf @ Jamf Perspectives on AI Governance Next session: Thursday, 20th August - 9am CDT / 3pm BST / 4pm CESTSpeakers: Sam Johnson and Emily Kausalik (@dr_k)Register here: https://jamf.it/ProductOfficeHours 🧵 Got a question? Drop it in the comments below ahead of time if you want it on our radar, though you don't have to. We'll be taking questions live on the call! Anything we don't get to, we'll follow up right here within 24 hours.See you Thursday 20th!
Hello,Does anyone have a working method to install LsAgent-osx.dmg on computers with Jamf Pro and configure it with an agentkey? With no luck, I have tried making packages, scripts, and numerous other things, including Installomator. The only time the install works and the Mac communicates with our lsagentrelay is when I manually install the DMG, and even then, when I manually run LSAgent in the Application folder, I see an error that says "Configuration could not be updated: Access to the path '/Applications/LansweeperAgent/lsagentconfiguration.xml' is denied." Despite that error, it successfully communicates with Lansweeper. Any help would be appreciated, as I've tried everything I've found online so far. Thanks,Steve
Download the MATLAB DMG Installer:Visit MathWorks and log in with your MathWorks account.Download the MATLAB DMG installer for macOS.Mount the DMG and Run the Installer:Double-click the downloaded DMG file to mount it.Open the mounted DMG and run the InstallForMacOSX.app.Log In with Your Company Account:When prompted, log in using your company MathWorks account.Choose your license from the available options.Select Advanced Options:Before proceeding with the installation, click on "Advanced Options."Choose the option "I want to download without installing."Download the Installation Files:The installer will download the necessary installation files to a folder and then move to /private/tmp/MatlabR2024aCreate the Installer Input File:Navigate to the folder '/private/tmp/MatlabR2024a' and locate the installer_input.txt file. Edit this file to include the following parameters:destinationFolder=/ApplicationsagreeToLicense=yesoutputFile=/tmp/mathworks_install.logenableLNU=yesIf depl
So we have Apple TVs that are set up with a config profile to automatically go into Conference Room mode, which locks out the ability to use an Apple TV remote. Somehow, some of the Apple TVs got unenrolled from Jamf but are still stuck in Conference Room mode. There’s no way to get into Settings to reset them because the remote doesn’t work.I’ve tried the old method of resetting them by rebooting them 4-5 times until the Recovery menu comes up. That used to work, however, at some point they stopped going to that menu, and now only give the option to connect an iPhone or iPad to reset them. No problem, I thought, I can use my iPad. The problem is that now the ONLY option it gives is to upgrade the OS, and when choosing that option, it doesn’t actually go through the Apple TV setup again…. meaning it doesn’t re-enroll in Jamf. The Apple TV downloads and applies the OS upgrade… then puts me right back into Conferenced Room Mode, locked with no ability to use a remote.Is there anything I
Just wondering if anyone has seen this. The machine is Ventura (Mac OS 13.6) and trying to upgrade to Mac OS 14.1Machine is bound to an AD domain and the user has a secure token and is an administrator on the machine. The user is logged on with a domain account i.e. a mobile account. The machine is an M1I tried forcing the update/upgrade via Jamf using the MDM framework from the server as they are overseas but it got to the end of preparing and prompted them again
Dear Team,Anyone can address which domains or settings need to bypass in DNS settings to login cloudflare warp client successfully? My Jamf Web Protection only enable Internet Content Filtering, therefore MAC OS machine no need Jamf Trust, it only needs profile configuration , UEM connect settings in place.I have the issue that When the DNS settings disable I am able to login CloudFlare WARP client If the the DNS settings enable, i can not login the CloudFlare WARP client with the error message "CF_DNS_LOOKUP_FAILURE." and here is the solution Verify that the network the user is on has DNS connectivity.Verify that DNS resolution works when WARP is disabled.Ensure that no third-party tools are interfering with WARP for control of DNS.Ensure that no third-party tools are performing TLS decryption 5 on traffic to the WARP IP addresses 4.I already tried to bypass these domains without help in configuration proflie<string>*.cloudflareclien
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!