Get Support
Recently active
I'm working with my mate AI, to write a clever script, to keep my kids in line from using VPN in the school, which will present them with any annoying re-petative pop up on their screen, when ever they engage the use of a VPN. it runs for 14 minutes on loop, running a 2 minute intervals check on if the local ip of the client, is within one of our networks subnets, and then checks for the reported current public IP from amazon, and if it doesn't come from one of our own, if it flags as being within one of our subnets and not with our public IP, it will proceed to prompt the end user, to turn off VPN, repetitiously, checking in every 3 minutes to see if the vpn has been turned off.basically they are using VPN to by pass, and play games in class, the constant prompt will ongoingly interrupt their games.its run every 14 minutes, so that next policy run, it will start over again. my issue is, I want it to run separately to the remaining polices, I want it to run the script seperate to
Hello all. When I use the following API point: --url $JAMFServer/api/v1/managed-software-updates/update-statuses/ I get a long list of info. This indicates I have permissions to access this data. However if I use "--url $JAMFServer/api/v1/managed-software-updates/update-statuses/filter=status=="installing" " I get a 403 error. Which is "Forbidden". It doesn't matter what filter I use, no go. Anyone know what permission needs to be set to get access to this info? Thanks.
We’re excited to share that Jamf's Network Relay service - our Jamf solution for transforming the network connectivity experience on Apple devices, is now available as a Release Candidate (RC) for production use on Apple mobile platforms (iPhone, iPad, Apple TV, Vision Pro) and Mac devices.Built on Apple native technologies - including MASQUE and Managed Device Attestation, and powered by Jamf’s global private mesh network and conditional access engine, Jamf's Network Relay service is a next-generation remote access solution that delivers pervasive, policy-driven connectivity from the moment a device boots, all configured via MDM and completely invisible to the end user.Ready to Try It?We’re offering limited access during this Release Candidate phase to ensure a great customer experience as we continue scaling the service.👉 If you're interested in enabling Network Relay for your production Apple mobile and Mac fleet, please fill out this short survey outlining your use case and deploy
Hey ya'll, I am currently in the middle of developing the process for converting my users over from using the Kerberos Extension to using Platform SSO on our Macs. I've got the profiles ready and all the local apps and such prepped to deploy, but when I perform the process I run into a few errors during the PSSO registration process. In particular I run into an issue at the end of the PSSO registration where it states that the "Sign in is currently unavailable", which does not happen when I enroll a device and have it go direct to the PSSO process and excluded from any of our KE profiles/policies. I was wondering if there is anyone here that went through the migration process and if anyone had any tips/tricks as to what they did to ensure a smooth user experience. I have every other piece ready to go and working flawlessly, just need to get my users in there and as we all know, the easier the experience is, the more likely users will do it quickly. Thank you!
Hello Teamwhile we expect inventory checkin to run every 15 minutes when device is On, this is not happening consistently for a few devices.Anyone observed this issue?
We are finding that when we run "Return to Service" on an iPad the location services is not turned on when it re-enrolls. Because of this the date and the time is not set correctly. Is there a way to force this to be ON, or a way to turn it on remotely?
hello all, I took advantage of Der Flounders excellent script to backup SS icons and made some enhancements to it. This script is designed to extract all of the icons from all Self Service policies and store them on a local folder. Great for when Self Service starts to display generic icons...you can restore them with your backup. repo: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/BackupSSIcons Initial Welcome screen Progress dialog Der Flounder's original script idea: https://derflounder.wordpress.com/2022/01/12/backing-up-self-service-icon-graphic-files-from-jamf-pro/
OK..this has been a couple years in the making, but I think I finally have something ready to distribute. In our environment (probably like yours to), the users don't have admin rights (which means they cannot run Apple's Migration Assistant), so I had to come up with a method for an end user to backup/migrate their data to another computer if they want. Designed to be run from Self service.... Source Code: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/MigrationWizard We use Microsoft OneDrive for our environment, but it can be used on SMB (legacy) networks as well...I used the tar method of backup, but can easily be adapted for rsync if you want to use that... If you want to add/remove items from the migration list, it can very easily be done using the JSON blob construct (details on my website).
Hey Jamf Nation, We're excited to announce the release of Jamf Pro 11.18.0 Beta! With this version we're releasing return to service in the Jamf Pro interface, a new Enable authentication with Jamf ID setting and more. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you’ll receive an invitation to join the Beta Forum, click “Join this group Hub” to gain access. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks, Blueprints, and App Switcher. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Morning all, I've found an issue a BETA Jamf tenant where policies don't appear in Self Service if the execution frequency is set to once per user per computer Changing the same policy to one per computer makes the policy appear, and changing it back to once per user per computer means that is disappears again. When the policy isn't appearing, it works if I call it with the policy ID from the binary: sudo jamf policy -id n Anyone else seeing this? It means that once per user per computer policies aren't running in macOS Onboarding. Using SS Classic, if it matters, but it shouldn't as this is still supported until March 2026
Hi Everybody! Just throwing this one out there in hopes that someone has been in this situation before. This morning I had a report from a user that they couldn't connect to our secure Wi-Fi and upon investigating, I found that their Mac was no longer in the JSS/Jamf Pro Server (JPS?). Someone has deleted it!!! Do any of you know of any logs that may show when a Computer is deleted from the JSS/JPS and by whom? Obviously I can't check the Computer record as it is non-existent. I have of course asked the team if anyone deleted computer "X" and surprise surprise the response was "Nope, don't think so". Not looking to catch anyone out, just would like to know who to do some additional training with or in the unlikely event if there is no record of it being deleted, then maybe we have an issue with the JSS/JPS. Thanks in advance!
Hello all, We are working on leveraging the DDM managed-software-uodate API feature for pushing out enforceable updates to our endpoints. One of the issues we are seeing, however, is that some machines get stuck where the machine never updates but when I try to push and check a new plan, I get the error EXISTING_PLAN_FOR_DEVICE_IN_PROGRESS My question is, how do we go about canceling a plan that is already in progress? Thank you, Alex Weiner
This one grew out of necessity at my old job. The higher level VPs didn't want to go into each browser settings and clear their cache/cookies/history when asked to do so, so I tried to create a "one stop shop" to work on all installed browsers with a single click. The goal was to keep their bookmarks, extensions & tabs intact...and it works "for the most part". If anyone knows critical directories / files that should be kept during a cleanup, by all means, let me know and I can get it put into the code. Hopefully you find this app useful. Code is here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/blob/main/ClearBrowserCache.sh
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server: Security Issues Jamf provides the CVE-ID for security issues with high or critical severity when possible.[PI124081] Fixed: A known vulnerability in a third-party library. (CVE-2024-47554) Jamf Pro Server [PI135204] Fixed: After device re-enrollment, some configuration profiles may fail to install automatically even when properly scoped to the device. [PI135884] Fixed: Smart user groups that use excluding criteria (e.g., "is not", "not like", "does not match regex") to match roster data fail to match users with no associated Apple School Manager roster data due to a smart group calculation error. [PI135942] Fixed: An update to Log4j introduced a threading issue that could cause silent thread failures during server operations. [PI135944] Fixed: When "Last Reported IP Address" is selected as a display field for an advanced computer search, the disp
As a follow-up to a recent email all Jamf Pro customers should have received, some IP address have been added and removed from the Inbound/Outbound traffic from Jamf Cloud list. For a complete list, please see the “Permitting Inbound/Outbound Traffic with Jamf Cloud” document located here:Permitting Inbound/Outbound Traffic with Jamf Cloud - Technical Articles | Jamf For a list of only the updates, please see here:IP Address and Domain Changelog for Inbound/Outbound Traffic with Jamf CloudIn order to provide ample time to make these changes, we are requesting these updates be made by August 20, 2025.
Hi I'm trying to make a Smart User Group that takes all Managed Apple Account that ends on our primary domain. I'm using the following Criteria "Managed Apple ID - matches regex - .*aau\\.dk$", but for some reason it only takes 92 out of the 129 users we have with a Managed Apple Account. For example I have a user with the following information in the Roster tab that's not added to that Smart User Group: I have also tried just using "Managed Apple ID - Like - aau.dk" and that still does not add all the users. Any ideas? //Kenneth
Hey all,I am using the script below to install Maya 2024 and activate it using a network license. This is the script we used for the past 3 years. I've made the necessary changes to the script (product key, year, server), double checked things a few times and still can't figure this out: #!/bin/sh#Instructions for next time#Copy installer app to /tmp using Composer package#Modify values below as necessary (Usually: year pKey and serial)#Make sure to check pkgPath1-10 match latest installer#Set variablesyear="2024"pkgPath1="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Licensing/AdskLicensing-13.3.1.9694-mac-installer.pkg"pkgPath2="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Licensing/adskflexnetserverIPV6.pkg"pkgPath3="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Maya/Maya_AdLMconf2024.pkg"pkgPath4="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Maya/LookdevX.pkg"pkgPath5="/tmp/InstallMaya2024.app/Contents/Helper/Packages/Maya/MayaUSD.pkg"pkgPath6="/t
Join us for the first ever South Florida Mac Admins meetup including dinner, drinks, and bowling. This is a casual event for folks who manage and support Apple Devices in enterprise and education to network and get to know one another.https://www.eventbrite.com/e/mac-admins-south-florida-kick-off-tickets-597257101067
We're testing Platform SSO with Entra, we can get the Intune machine to login & create new accounts, but it seems to be removing admin rights on the accounts if they were previously enabled (like our local admin account). I recall jamf mentioned something about this being a potential issue - but I haven't found much on how to change the behavior. Does anybody have any recommendations?
Hello,I have been searching online and through forums but I cannot find any useful information on if anyone has gotten the desktop/folder automatic syncing to work for Mac devices via Jamf? The Plist configurations I am pushing is not working. All the previous posts concerning this topic have gone cold. Has anyone been able to successfully implement this configuration and if so, can you guide me on how to complete this process?
So with the below permission, if we disable it like the below photo will we still have access to Blueprints and Compliance benchmarks? If so what are the negatives in doing so? An Enable authentication with Jamf ID setting has been added to Settings > Single sign-on > OIDC IdP integration, and is enabled by default in environments integrated with OIDC-based SSO in Jamf Account. You can disable this option to force users to use their SSO credentials to log in to Jamf Pro.
Hi We are transitioning to enabling FileVault by Configuration Profile once Mac is enrolled via DEP. All is well, except we cannot add other authorized users to fileVault using the FileVault System Preferences --> Enable Users button. I just click the "Enable Users" button and it does nothing. Any ideas??? What is best practice for getting an end user and a local admin account enabled for FileVault. We are testing with Mojave 10.14.6
Hi, Since 18.4 on iPads at least they now automatically reboot after 3 days of being idle. This is annoying as it drops them from the Wi-Fi preventing them receiving any MDM commands until they are unlocked. Typically, in the holidays we clear the passcodes on our iPads that are kept in school and schedule the update to the latest iPadOS version however as they've been idle over the bank holiday weekend, they are now all disconnected and unable to receive commands. According to Apples MDM Commands page there is a 'Allow Idle Reboot' command, but I can't find any documentation about it at all. ChatGPT came up with a .mobileconfig file but I've no idea where it pulled it from as there's only one result on Google for "Allow Idle Reboot" and it's the above webpage! I've deployed the .mobileconfig file to a test iPad (it shows up as 'unknown payload' but I've got to leave it 3 days before I know if it worked so I was curious if anyone else has had these issues? Thanks
It seems that on or about 6 May 25, and for whatever reason, endpoints seem to have stopped communicating with our cloud instance. After pulling logs, and running analytics, I found references to "JWT Null Key error" pertaining to "MDMActionFactory," which seems to mean our cloud instance couldn't sign--well, anything. Didn't catch it sooner because, and "song as old as time, tale as old as rhyme," ours is very much a Windows-first enterprise--meaning we're forced to install a number of agents upon our managed Mac endpoints--because InfoSec says... So we thought it was that...Turns out it was both.This past Friday evening our push proxy cert was renewed, and we pulled the trigger on the 11.17 upgrade... Now, a scripted DDM sync against all managed endpoints runs to completion (it wasn't before these referenced changes), as does a scripted command to cancel all failed commands...Despite this all policies still indicated a "pending" status... There shouldn't be anything in the way any lo
Can anyone advise what would happen if a policy name was changed? For example, if I needed to rename "10-Install Chrome" to "210-Install Chrome", would it remove the package that was installed by the first policy and reinstall the same package under the 2nd policy? And am I correct in assuming that removing a policy does NOT remove the installed app? We're renaming them so that we can properly sequence the policies (e.g. anything with 0XX are pre-app installations, anything with 1XX are required app installations, anything with 2XX are for specific labs, etc).
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!