Get Support
Recently active
Hello, Experiencing a strange issue and was wondering if the community have seen this before. We run our users as Standard users, no admin access. We use a script to enable certain permissions, including printer management and wifi management. On a standard user account on a 2020 macbook pro, having run the following terminal commands as part of a script: /usr/bin/security authorizationdb write system.preferences.network allow /usr/bin/security authorizationdb write system.services.systemconfiguration.network allow /usr/bin/security authorizationdb write com.apple.wifi allow I am now able to "Forget" SSIDs, but it still prompts me for administrator username and password. Weirdly, you can see that it forgets the network regardless of whether I hit Cancel or put in local admin creds. Is this just a weird glitch that we'll have to deal with telling users "Just hit cancel", or is there something else I can do to fix this?
Hi, Does anyone know if it is possible to increase the 'nettimeout=1' argument that Jamf Connect passes to ldapsearch after performing kerberos authentication to return user LDAP attributes? This is the full command built by Jamf Connect: /usr/bin/ldapsearch -N -Q -LLL -o nettimeout=1 -o ldif-wrap=no -H ldap://dc2.realm-name.net -b DC=realm-name,DC=net sAMAccountName=shortname pwdLastSet msDS-UserPasswordExpiryTimeComputed userAccountControl homeDirectory displayName memberOf mail userPrincipalName dn givenName sn cn msDS-ResultantPSO msDS-PrincipalName Is it possible to change the default nettimeout=1 to a higher number? This is causing us issues when trying to get the menu bar updated with user state after successful TGT. I have tried adding NETWORK_TIME 60 to /etc/openldap/ldap.conf , but Jamf Continues to build the command line using the same argument of nettimeout=1
Hi everyone, We are currently using Jamf Connect integrated with Entra ID, and our environment is configured to use Pass-through Authentication (PTA). This means user passwords are validated directly against our on-premises Active Directory (AD). The issue: When a user's AD password expires and they are logged out of the system, they essentially become locked out. Jamf Connect prompts for login, but since the password is expired, the user is required to change it. However, password change fails with the following error: Entra ID error 120013"The user's Active Directory password has expired. Reset the user's password in your on-premises Active Directory to resolve the issue or have the user use the Self Service Password Reset (SSPR) functionality if it is enabled." This means users can’t change the password from the Jamf Connect login window. They can only reset it using an external method connected directly to AD. What we tried: We implemented a custom SSPR portal that connects direc
Earlier I got a blank Dock in macOS after enrollment if I waited to long during the steps of macOS setup with account creation and everything. But now I get it most of the time. The only icon showing in the Dock is Finder.Anybody been having the same problem and/or know how to solve it for future enrollments?We’re in Jamf Cloud and fort the moment in version 11.15.1.
I am having issues with editing random configuration profiles in Jamf Pro. When I click the name of the profile in the list of profiles, the details of the profile will load. When I click 'Edit' at the bottom, I just get a never ending spinning progress ring and the 'edit' page never actually loads. Has anyone else experienced this? I tried to search for the topic, but its such a generic search I couldn't find anything related to this specific thing..
Jamf Pro has built-in dashboards, but many admins want the flexibility of Business Intelligence (BI) or reporting tools. JNUC 2019 introduced integrations with some of the most popular tools. We have been hard at work creating resources to help you get the most out of your data, and now we want to see your dashboard! If you have a great dashboard to share, please post it here! If you have tips or tricks that helped you build it, share it with your fellow admins. Remember to sanitize any sensitive data before posting. Integrating Jamf with Splunk
I would like to ask a question: How does Jamf retrieve the installation count, usage duration, and user information of Office software?
If you were an organization that deployed remote Macs using a MDM profile and a local admin account for the first technician setting it up. And then a second local admin account for the user it is assigned to. How would you change this to be more secure and modern? Jamf Connect? Any other apps, policies, or settings you would recommend?
So I've followed the documentation here: https://support.techsmith.com/hc/en-us/articles/115007344888-Enterprise-Install-Guidelines-for-Snagit-on-MacOSAnd I can't get this thing to install. Specifically, i'm just trying to push Snagit out to our machines, and will follow up with the license file after I can verify the installer is actually installing the DMG/PKG.I'm getting mixed answers between the Jamf console and the actual log file.Jamf: "Verifying DMG...Verifying package integrity...Installing Snagit.dmg...Closing package...In the logs all I see is.. "Instaling Snagit.dmg..."The Dashboard indicates a successful policy push, the logs indicate a lengthy install time, longer than expected at least.Reviewing the applications folder, it's apparent that it ISNT installed. I've used the .DMG file directly from TechSmith, as well as trying to use Composer to create one with the same results.Any ideas?
Hi all, How can I disable System Prefs -> sharing -> airplay receiver via a script? I don't really know the libraries to the point which would allow me to go and locate them. It auto turns on when the machine comes online
Last September, I joined the Jamf Community team to help build out a User Group program. As I was getting to know the community, one thing was abundantly clear: Apple Admins have a lot to share and a strong desire to connect, especially in person. It’s been an exciting challenge to work with admins across the globe and build a structure that supports in-person and online meetings. One of the many joys of working in Community is getting to help bring the idea of “Community” from something abstract to something tangible and real. I love supporting people who may have once felt alone —shouting into the void — find connection, clarity and camaraderie through programs like User Groups. User Groups are a fantastic way to regularly connect with fellow admins, solve problems, talk shop and maybe even make some new friends along the way. While forums and Slack are great for quick questions and short conversations, nothing quite compares to the impact of meeting your pee
iPads that sit on lock screen for a few hours, go to partial sleep mode which disconnects from WiFi. The only way to connect them to WiFi is to wake it up and go to home screen. If an iPad is locked with passcode and not connected to WiFi, how will it complete the "Clear passcode" command through Jamf? There is literally no way to connect back to the internet using the same WiFi, Ethernet or Internet Sharing. In the past, people claimed that Ethernet to lightning adapters worked, but since iOS 11.4.1, USB restricted mode disabled the use of dongles at the lock screen. We have a lot of iPads for staff that are simply added to Jamf without any configuration policies applied to them. I know there is an option to enable/disable USB restricted mode under configuration policies, but the problem is that we are not applying any policies to these iPads. So by default, USB restricted mode is Enabled which prevents use of dongles while at the lock screen. The only way to solve this matter is
We’ve been running into a persistent issue with Jamf Connect (v2.45.1) on devices running macOS 14 Sequoia, where login via Okta intermittently fails after a few reboots. The error we consistently see on the login window is:An error occurred. Contact your IT administrator. The operation couldn’t be completed. (JamfConnectLogin.JCAuthProviderFactory.FactoryError error 0)This happens after the machine has been rebooted 2–3 times, even if it initially works fine after provisioning. Some users can click the network icon and select their username to log in using local credentials, but others get stuck at the login screen completely. We’ve verified the machine is connected to the internet when this occurs.Additionally, the macOS native Microsoft Entra ID login option (added in Sequoia) sometimes appears despite us not using Entra ID at all, which we believe is causing interference or confusion with Jamf Connect.⸻Environment:• Jamf Connect: 2.45.1• macOS: 14.0 (Sequoia) on Apple Silicon Macs•
Good Morning. I am a new Jamf Administrator. We have managed to get everything up and running for the most part. The only thing I am seeing is that when Jamf Protect is installed it does not appear to have been granted full disk access in the Privacy and Security menu. The policy is self configured from Jamf Protect and signed so that it cannot be edited. But it appears to be correct.
We recently tested a scenario with Jamf Connect and Active Directory where we enabled the "Change password at next login" flag on the AD user account. Here's what happened: I was logout of Jamf Connect and on the Self Service+ UI, I noticed the status said: “Password out of sync” and “Sign in to your Identity Provider”. On the next login attempt via Jamf Connect, I expected a prompt to change the password. Instead, Jamf Connect displayed an error saying that the password is expired, with no option to change it directly from the login window. This raises a few questions: Shouldn't Jamf Connect handle the password change flow directly when AD requires it? What are the recommended access limitations when a user is not signed into Jamf Connect? Currently, I can still request admin access via Jamf Connect even if I'm not signed in. However, if I log out and log back in, the system prompts me for the current password as expected. How do you structure access policies arou
We're rolling out a couple of iPads in Single App Mode with a kiosk app and that's working well. However, we need to manage OS updates as well. Does anyone have a workflow that allows for automatic OS updates for devices in Single App Mode? I would also be fine with a process that be scheduled for an overnight maintenance window.
I recently installed Jamf Safe Internet on my device, I seem to be facing an issue that I'm hoping someone could help me with. I've been having trouble accessing certain websites. It's not all websites, but there's a handful that just won't load anymore. I've double-checked my internet connection, cleared my browser cache, and even restarted my device a couple of times, but the problem persists. Has anyone else experienced a similar issue after installing Jamf Safe Internet?
Is it possible to enroll macOS, but to not install SelfService app? For example, I want for some devices install only Jamf Protect app without any configuration profiles and apps. Additionally, I see there is SelfService+ App, it is the same that default installed?
I've been following the directions as per https://school.jamfcloud.com/api/docs/#api-Devices-Assign_owner and PUT to https://{yourDomain}.jamfcloud.com/api/devices/:udid/owner with all the relevant information but no matter how I send the request with the user parameter, it returns a code of 400 with the message "UserRequired".I've spent a whole day trying every variation of submission and multiple programs and methods and the result is the same. Has anyone got any pointers?
I have a computer that we created the user account with Jamf Connect. Once in the user account, we can't open self service. I removed self service and reinstalled it with Jamf policy command. It still won't open. To clarify what I mean but not opening, I click to open it from the applications folder in finder. It shows in the dock then goes away. I get the report option. So it is crashing at launch. I deleted the user account and created it through system settings and still have the same issue with self service. I can open self service in the admin account. I'm not sure what else to try.
We have noticed that on some of our Macs the computer's name is getting added to /etc/hosts. This isn't having any negative effect on the operation of the Mac, but it does cause an issue with Tanium which queries the computer name as part of its data gathering tasks. These Macs display in Tanium as "localhost", not the name that is actually set for the Mac. We use the Mac's serial number for computer names. During initial setup, a policy runs "jamf setComputerName -useSerialNumber" I created an extension attribute that reads the contents of the hosts file and reports if the computer name is present. There have only been about 30 out of 1500. I created a script to remove the computer name, but on some of the Macs, the computer name has reappeared in the hosts file. Since this doesn't happen on all Macs, I'm not sure what could be doing this. Does anyone have ideas on what might be doing this?
I like Jamf Self Service+. It's a clean interface. Currently I don't see a way to rename it like the current version of Self Service. We rename Self Service to Software Center to make it familiar to those that go between Windows and MacOS. Also, while Self Service+ is nice, it doesn't seem to offer any current major advantages over Self Service at this time so we haven't been deploying it. I don't really want to have two versions of Self Service to confuse our users. Is there any plans to make Self Service+ as an automated install like the current version of Self Service? And will we be able to change the name of the app like we can do with Self Service? I'm also failing to understand what makes Self Service+ any better than Self Service other than the UI overhaul. A recent email I received said it has identity management capabilities but you can also log into Self Service. I understand Self Service will be sunset at some point so would I be co
Hello We recently updated our Mac estate to MacsOS 15.I have noticed issues with taking screenshotsWe deploy two base profiles one for staff devices one for shared lab devices.Both have Allow screenshots and screen recording (macOS 10.14.4 or later) set under Functionality.The shortcut key just does't seem to do anything but works fine on staff devices using the same setting.I dont belive Im blocking it elsewhere.Any idea Thanks Capture a portion of the screen Press Shift-Command-4, then move the crosshair pointer to where you want to start the screenshot. Press the mouse or trackpad button, drag over the area you want to capture, then release the mouse or trackpad button.
Is this blog still accurate for version 16.3? Any changes or modifications needed for the newer version?Deploying Xcode on managed devicesConfigure Xcode post installation script with SDK download for Xcode 14 and 15 · GitHub
How can I enable two-factor authentication (such as SMS or email verification) after entering username and password on the Jamf Pro login screen?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!