Get Support
Recently active
I'm trialling PSSO at the moment, appears to work well, and the workflows are fairly good in terms of steps to follow post enrolment. There is a prompt after Intune registration to use passkeys and passwords from Company Portal - a toggle on requiring manual intervention, does anyone know if this is configurable with plist/other Jamf config?Also, we're only using PSSO to improve auth to Microsoft products, I'm seeing wholly conflicting statements around extending that to macOS logon itself - has anyone done anything with this, i.e. override and control OS sign in/password sync, etc.
At the moment, site admins are not able to create or edit any configuration profiles with the SCEP payload, when an existing one is selected or created by a Site Admin, the page just loads the spinning loading wheel and finally errors out after some minutes. Is there a permissions setting that needs to be selected for this to work for Site Admins? Full admins work without issue, thanks.
I'm sure there is something silly I'm missing, but I was doing a test of exporting our list of devices from our ACE agreement and then using that to populate the mut template to update jamf. It seems to grab teh serial number and Coverage number and populates it, but it leaves the Coverage End Date (aka Warranty Expiration) does not populate. It shows properly in the preview of what will change, but it doesn't update field in jamf. I checked the verbose logs and it doesn't show any failures. I did see in the field that it was putting a specific time into the csv field once I expanded the field to see it. I've tried with and without the specific time.
Jamf Nation is about to enter a bold new chapter. We’re excited to launch a redesigned platform this summer to better support connections and help community members more easily succeed with Apple and Jamf. The upgraded community space will offer a refreshed look, easier navigation and more ways to interact – with Jamf and other Jamf Nation members. Stay tuned for the official launch date, and get ready to enjoy a richer, more engaging Jamf Nation experience. Learn more here.
Back at it again with a (potentially) useful script. This script is designed to extract all of the system scripts from your JAMF server. Why do you want to do this? Make a backup of your scripts in case your existing backup files is missing/corrupted (or you don't have one!) You inhereited a JAMF server from another person, and this can do a "brain dump" so you can review the scripts. Why not? It is another example of what you can do with API scripts.. Source: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/BackupJAMFScripts Welcome screen Process screen Errors screen if problems found:
As many of you have requested, we have added the ability to change the benchmark mode (enforcement type) between Monitor only and Monitor and enforce, and also change the scope by selecting a different smart group. Editing of these settings works the same as managing benchmark rules - just open the created benchmark, make required changes, and click Deploy. Refer to the documentation if needed: https://learn.jamf.com/en-US/bundle/jamf-compliance-benchmarks-configuration-guide/page/Benchmark_Management.html Since compliance benchmarks is delivered into Jamf Pro as micro frontend, the new capability is available right away in all supported Jamf Pro instances!Looking forward to hear your feedback on the updates, and of course any general feedback on what is the next addition you would like to see.
Hi all,At System Settings -> Display -> Advanced -> Energy you can this turn off or on "Prevent automatic sleeping when the display" Any idea of this is possible to control this with Jamf? thanks
I literally jumped out of my chair when I realized that this ages-old issue is going to be working now ;) I played around with this enhancement and it's not working for us unfortunately. These are the combinations that I tested: These combinations are only returning one value instead of ~120 for my user: transitiveMemberOf.displayName as LDAP mapping, "Allow Attribute Multiple Values" disabled transitiveMemberOf.displayName as LDAP mapping, "Allow Attribute Multiple Values" enabled memberOf.displayName as LDAP mapping, "Allow Attribute Multiple Values" disabled memberOf.displayName as LDAP mapping, "Allow Attribute Multiple Values" enabled These combinations are returning nothing (as expected, this was just tested to make sure I'm not missing something) transitiveMemberOf as LDAP mapping, "Allow Attribute Multiple Values" disabled transitiveMemberOf as LDAP mapping, "Allow Attribute Multiple Values" enabled memberOf as LDAP mapping, "Allow Attribute Multiple Values" disab
As we deployed new AppleTVs we got the old AppleTVs back, some were not MDM enrolled (teacher donated). Now we are tasked with enrolling those OLD devices in our MDM. Mostly we were successfull in adding the devices to our MDM (via USB-C), but, we have a hard time with some Wi-Fi ONLY AppleTVs that were found in the mix. The apple instructions for enrolling the Wi-Fi only devices with Configurator 2 don't make any sence: Connect Apple TV HD using Wi-Fi Apples instructions require the AppleTV to be reset/erased and left at the "Hello" screen, then, Configurator needs to PAIR to the device in order to process the enrollment, but, there is no Wi-Fi setup on the device...??? ... Anyone has any bits of advice? is MDM enrollment not possible on Wi-Fi only Apple TVs?
We have a handful of applications that are required to be on our laptops at all times. Currently, we have smart groups set with criteria for the app not being installed and a policy scoped to that group. The downside is it only updates when an automatic inventory update is done every day. Has anyone done something similar that runs more frequently?
saw this 3 times this week, pattern looks like a change in password, then MS authenticator shoots this up a few days later. using Jamf connect and entra integration, reset MS office to complete deletion, no change, tried unenrolling, and re enrolling, cant do that at all... profile fails to install. anyone else?
I'm working with my mate AI, to write a clever script, to keep my kids in line from using VPN in the school, which will present them with any annoying re-petative pop up on their screen, when ever they engage the use of a VPN. it runs for 14 minutes on loop, running a 2 minute intervals check on if the local ip of the client, is within one of our networks subnets, and then checks for the reported current public IP from amazon, and if it doesn't come from one of our own, if it flags as being within one of our subnets and not with our public IP, it will proceed to prompt the end user, to turn off VPN, repetitiously, checking in every 3 minutes to see if the vpn has been turned off.basically they are using VPN to by pass, and play games in class, the constant prompt will ongoingly interrupt their games.its run every 14 minutes, so that next policy run, it will start over again. my issue is, I want it to run separately to the remaining polices, I want it to run the script seperate to
Hello all. When I use the following API point: --url $JAMFServer/api/v1/managed-software-updates/update-statuses/ I get a long list of info. This indicates I have permissions to access this data. However if I use "--url $JAMFServer/api/v1/managed-software-updates/update-statuses/filter=status=="installing" " I get a 403 error. Which is "Forbidden". It doesn't matter what filter I use, no go. Anyone know what permission needs to be set to get access to this info? Thanks.
We’re excited to share that Jamf's Network Relay service - our Jamf solution for transforming the network connectivity experience on Apple devices, is now available as a Release Candidate (RC) for production use on Apple mobile platforms (iPhone, iPad, Apple TV, Vision Pro) and Mac devices.Built on Apple native technologies - including MASQUE and Managed Device Attestation, and powered by Jamf’s global private mesh network and conditional access engine, Jamf's Network Relay service is a next-generation remote access solution that delivers pervasive, policy-driven connectivity from the moment a device boots, all configured via MDM and completely invisible to the end user.Ready to Try It?We’re offering limited access during this Release Candidate phase to ensure a great customer experience as we continue scaling the service.👉 If you're interested in enabling Network Relay for your production Apple mobile and Mac fleet, please fill out this short survey outlining your use case and deploy
Hey ya'll, I am currently in the middle of developing the process for converting my users over from using the Kerberos Extension to using Platform SSO on our Macs. I've got the profiles ready and all the local apps and such prepped to deploy, but when I perform the process I run into a few errors during the PSSO registration process. In particular I run into an issue at the end of the PSSO registration where it states that the "Sign in is currently unavailable", which does not happen when I enroll a device and have it go direct to the PSSO process and excluded from any of our KE profiles/policies. I was wondering if there is anyone here that went through the migration process and if anyone had any tips/tricks as to what they did to ensure a smooth user experience. I have every other piece ready to go and working flawlessly, just need to get my users in there and as we all know, the easier the experience is, the more likely users will do it quickly. Thank you!
Hello Teamwhile we expect inventory checkin to run every 15 minutes when device is On, this is not happening consistently for a few devices.Anyone observed this issue?
We are finding that when we run "Return to Service" on an iPad the location services is not turned on when it re-enrolls. Because of this the date and the time is not set correctly. Is there a way to force this to be ON, or a way to turn it on remotely?
hello all, I took advantage of Der Flounders excellent script to backup SS icons and made some enhancements to it. This script is designed to extract all of the icons from all Self Service policies and store them on a local folder. Great for when Self Service starts to display generic icons...you can restore them with your backup. repo: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/BackupSSIcons Initial Welcome screen Progress dialog Der Flounder's original script idea: https://derflounder.wordpress.com/2022/01/12/backing-up-self-service-icon-graphic-files-from-jamf-pro/
OK..this has been a couple years in the making, but I think I finally have something ready to distribute. In our environment (probably like yours to), the users don't have admin rights (which means they cannot run Apple's Migration Assistant), so I had to come up with a method for an end user to backup/migrate their data to another computer if they want. Designed to be run from Self service.... Source Code: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/MigrationWizard We use Microsoft OneDrive for our environment, but it can be used on SMB (legacy) networks as well...I used the tar method of backup, but can easily be adapted for rsync if you want to use that... If you want to add/remove items from the migration list, it can very easily be done using the JSON blob construct (details on my website).
Hey Jamf Nation, We're excited to announce the release of Jamf Pro 11.18.0 Beta! With this version we're releasing return to service in the Jamf Pro interface, a new Enable authentication with Jamf ID setting and more. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you’ll receive an invitation to join the Beta Forum, click “Join this group Hub” to gain access. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Morning all, I've found an issue a BETA Jamf tenant where policies don't appear in Self Service if the execution frequency is set to once per user per computer Changing the same policy to one per computer makes the policy appear, and changing it back to once per user per computer means that is disappears again. When the policy isn't appearing, it works if I call it with the policy ID from the binary: sudo jamf policy -id n Anyone else seeing this? It means that once per user per computer policies aren't running in macOS Onboarding. Using SS Classic, if it matters, but it shouldn't as this is still supported until March 2026
Hi Everybody! Just throwing this one out there in hopes that someone has been in this situation before. This morning I had a report from a user that they couldn't connect to our secure Wi-Fi and upon investigating, I found that their Mac was no longer in the JSS/Jamf Pro Server (JPS?). Someone has deleted it!!! Do any of you know of any logs that may show when a Computer is deleted from the JSS/JPS and by whom? Obviously I can't check the Computer record as it is non-existent. I have of course asked the team if anyone deleted computer "X" and surprise surprise the response was "Nope, don't think so". Not looking to catch anyone out, just would like to know who to do some additional training with or in the unlikely event if there is no record of it being deleted, then maybe we have an issue with the JSS/JPS. Thanks in advance!
Hello all, We are working on leveraging the DDM managed-software-uodate API feature for pushing out enforceable updates to our endpoints. One of the issues we are seeing, however, is that some machines get stuck where the machine never updates but when I try to push and check a new plan, I get the error EXISTING_PLAN_FOR_DEVICE_IN_PROGRESS My question is, how do we go about canceling a plan that is already in progress? Thank you, Alex Weiner
This one grew out of necessity at my old job. The higher level VPs didn't want to go into each browser settings and clear their cache/cookies/history when asked to do so, so I tried to create a "one stop shop" to work on all installed browsers with a single click. The goal was to keep their bookmarks, extensions & tabs intact...and it works "for the most part". If anyone knows critical directories / files that should be kept during a cleanup, by all means, let me know and I can get it put into the code. Hopefully you find this app useful. Code is here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/blob/main/ClearBrowserCache.sh
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server: Security Issues Jamf provides the CVE-ID for security issues with high or critical severity when possible.[PI124081] Fixed: A known vulnerability in a third-party library. (CVE-2024-47554) Jamf Pro Server [PI135204] Fixed: After device re-enrollment, some configuration profiles may fail to install automatically even when properly scoped to the device. [PI135884] Fixed: Smart user groups that use excluding criteria (e.g., "is not", "not like", "does not match regex") to match roster data fail to match users with no associated Apple School Manager roster data due to a smart group calculation error. [PI135942] Fixed: An update to Log4j introduced a threading issue that could cause silent thread failures during server operations. [PI135944] Fixed: When "Last Reported IP Address" is selected as a display field for an advanced computer search, the disp
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!