Get Support
Recently active
Managing Labs devices in a university environment. Looking at ways to provide remote support and access devices when I am working offsite. Does Jamf Remote Assist work? I think I have everything configured correctly, but thus far haven't been able to establish a connection to any devices. Before I go to our cyber/infrastructure team to troubleshoot, does anyone use JRA, and is it stable enough to rely upon as the sole Remote Access system?
hey Nation, has any one seen a change with log predicates streaming to splunk since updating to macOS Sequioa? Our SIEM team is seeing all Data but nothing related to logd or log predicate events, even though it is configured. Any agent updates that anyone remember? we are on 9.3.4 Tia
Hey all, I recently deployed an app through JAMF (an App Store app) and want to prevent it from updating. The app is still available in Self-Service, but I've learned that it updates when users click the "Re-install" button in the Self-Service Store. I've double-checked the settings and confirmed that both the "Schedule Jamf Pro to automatically check the App Store for app updates" and "Automatically force app updates" options are disabled. Can you advise how I can prevent this app from updating if a user attempts to re-install it via the Self-Service Store?
Hey All,Starting a few days ago I was alerted to a communications error from our Jamf Infrastructure Manager instance. It's been working fine for quite a while (years), and is running JIM 2.4.0 (Windows 2019 server, Java 11.17.x)The JIM Log files clearly show the moment when things went awry April 1 @ 10:06:42, but no indicators as the nature of the issue. I haven't yet found anything relevant in the Windows server logs.2023-04-01 10:05:52,672 INFO c.j.i.l.LpsTransferThread [JSS->LDAP for [/54.208.14.206:8869](2803)] Transfer thread started2023-04-01 10:05:52,672 INFO c.j.i.l.LpsTransferThread [LDAP->JSS for [/54.208.14.206:8869](2803)] Transfer thread started2023-04-01 10:05:52,809 INFO c.j.i.l.LpsTransferThread [JSS->LDAP for [/54.208.14.206:8869](2803)] Input Socket (JSS), end-of-stream2023-04-01 10:05:52,809 INFO c.j.i.l.LpsProxyConnection [JSS->LDAP for [/54.208.14.206:8869](2803)] Closing Jamf Pro socket2023-04-01 10:05:52,809 INFO c.j.i.l.LpsProxyConnecti
Looking to see if anyone knows about JAMF Pro support for Windows Server 2025. If it doesn't currently support it then when will the expected date that JAMF will support Windows Server 2025.
Hello, Has anyone found a way to configure this using a config profile or script now that the airport command has been deprecated? I'm trying to configure this setting: Thanks! --Josh
We are trying to implement full disk access for Rapid7 on mac with Mac os 15.1 with help of a Jamf Configuration Profile.We followed the exact steps recommended by the software vendor (Rapid7) from the below link https://docs.rapid7.com/insight-agent/mac-installation/#use-an-mdm-for-configuration We have double checked with path of the ir_agent, which is as to be default /opt/rapid7/ir_agent/ir_agent Tried in couple of machines with mac os 15.1 and 14.5, but still we see from the GUI that the ir_agent FDA is not enabled using the toggle button. Can someone suggest how can we get this working or any way to understand why this doesn't work. Any help would be appreciated here. Let us know if you need additional information. Thank you!
A number of years ago Apple changed access to the system.log file (and others) so that only admin level users could read them. In the name of 'security' I'm assuming. We don't allow non-standard users on our devices however, and one of our developers needs to be able to read the affected logs and can't.I've tried editing the sudoers file and adding the user to access /System/Applications/Utilities/Console.app, and using a policy to try and open Console. But Console just complains and doesn't work. I could change the permissions on the effected log files, but that'll be reversed as soon as the OS rotates the logs...Is there a simpler method, or something I'm not thinking of?Allowing the user temporary admin access isn't a solution either unfortunately.
Does anybody know what could be wrong? I don't see Transfer to a work account for one Apple ID account, only Keep as a personal account. I had read https://support.apple.com/en-gb/102159 and checked every option. Once I saw Transfer to a work account, but I was told to update my Mac to the latest OS. After that, I had tried many times without success. It's giving only one option: Keep as a personal account. It wouldn't be a big issue, but the problem is that this Apple ID is used for an APN certificate.
We have profile witch push machine cert and wifi with tls. We need to push this profile very 6 months or year. How can i do it? i can store .mobileconfig on Mac i think but how can i install it via policy?
Experiencing issues with the JAMF Remote Assist feature! It was effective for a few months, but now, I'm unable to access any devices remotely. Even after trying the troubleshooting methods recommended by JAMF Support, the problem persists. I've learned there's an ongoing product issue. Is anyone else encountering similar challenges?
Hi Jamf Nation Community, I’m reaching out to get some advice on using Jamf Pro to manage macOS devices for an upcoming event I’m organizing. I’m hosting a viewing party for the Masters Tournament 2025 (happening from April 10 to April 13 at Augusta National) for my team, and we’ll be streaming the event live on multiple MacBook Airs and iMacs in our office. I’m relatively new to Jamf Pro, and I want to ensure everything runs smoothly during the event. I’d really appreciate your insights on a few challenges I’m facing! Here’s the context: We have about 15 macOS devices (mostly running macOS Ventura and a few on macOS Sonoma) that we’ll be using to stream the Masters 2025 via FuboTV. I’ve already set up a guide for my team on how to stream the event, which I found helpful for planning (you can check it out here if you’re a golf fan: How to Watch the Masters Tournament 2025 Live on FuboTV on my blog at masterstournament2025.wordpress.com). However, I’m running into a few issues with Jamf
Hi, I see there is a configuration Profile that enables FileVault and a Policy that does the same. Can someone tell me what the difference between those two is? Do I need both? Do I only one? Do they have different use cases? Kind regards
Hello There, Can someone give me a suggestion for below configuration profiles and policies. 1- Lock screen wallpaper (screensaver after 5 minutes idle time) 2- MS teams background image 3- A custom PowerPoint templates 4- Custom Outlook Signature 5- Deploy a custom font and set as a default
My company sent me a MacBook to do some application testing on, but I initially couldn't login to it. I had to reset the device and let it re-enroll in our Jamf cloud before I could login to it.I can login as a standard user now. These are not domain joined and there is no local admin account right now.I am a Jamf administrator, but I've never used it. I went and created a new policy that targets only my computer that was supposed to create a new local account with administrator privileges, but it doesn't appear to have worked.Any suggestions?
After a recent patch we have had LIS files recently start requiring admin privilege's to open in TextEdit. Is there a way in Jamf Pro to allow for this without admin creds?
Hi All, Long time reader, first time poster! I was wondering whether anyone has successfully implemented Platform SSO with password auth whilst using Entra ID & Jamf Pro? We are currently working with this in testing. Initial UPN sign-ins are successful, but subsequent sign-ins with the user's UPN following a password change do not work. The user can however sign in successfully with their new password by either using their display name or UPN without the "@", suggesting it may be the user mapping that's at fault rather than the IdP connection. Has anyone experienced this? Any help would be greatly appreciated! Cheers!
Hi Folks,I'm putting this here to try to be a little helpful. We just moved from v5 to v6 for GlobalProtect, and basically, the setup that we had that, installed the stock pkg from paloalto and relied on a config profile to set our default portal stopped working. I also couldn't get the app to stop an endless "connecting" loop. So for anyone who is having the same issue, I hope this is helpful. Long story short, you need to package an XML file that installs the system extension with the app pkg and then run a script to install both.The GP release notes for 6.0.1 speak of a new Simplified and Seamless macOS GP app deployment Using Jamf MDM integration feature. The documentation is helpful but not comprehensive so I'll put it together here. Sources: https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/mobile-endpoint-management/manage-the-globalprotect-app-using-jamf/deploy-the-globalprotect-mobile-app-using-jamfhttps://docs.paloaltonetworks.com/globalp
I have a user on an M1 MacBook Air who has suddenly been getting the following message - credential verification failed because account is temporarily locked. We authenticate via 365 using JAMF Connect. I have checked on Azure (or whatever its new name is!) and the account isn't locked, I have sent a command via Unlock user account but no success -- any ideas ??thanks in advanceLenny
Trying to get an understanding of what some scripts do that were written by a previous Jamf admin. We have a device in our fleet that keeps racking up Pending management commands. The MacBook in question is up to date in terms of OS and software updates, but it never seems to process any management commands. I tried clearing them then sending a blank push, but that didn't do anything. A bit of online searching uncovered the recommendation to run the following command: sudo profiles renew -type enrollment I ran that on one of my test devices (actually ran it from Self Service because the script is a payload to a Policy) and am trying to understand what the script actually does, or how I can tell that it ran successfully. I can see in jamf.log where the script began to execute, but there's no other info in jamf.log or install.log. I checked the system logs by running the following Terminal command: log show --predicate 'process == "mdmclient"' --info That returned a ton of information, a
Hey Nation, Recently we deployed user initiated enrollment for all users in the company. But after that, a large group of developers are having issues with VPN connection. We are using OpenVPN. The VPN gets disconnected after every 2-3 hours and developers need to reconnect it. It is happening with GitLab, ChatGPT and some other webpages. It is affecting their daily workflow since they always need to push-pull repositories. Any idea what can be a reason behind this? Please note, we didn't put any networking restrictions on Jamf side. But WiFi profile was deployed from configuration profile. I am clueless here as a newbie. Thanks in advance.
I saw during one of the demo's at JNUC this year someone had added custom logo's to their JSS icons (not necessarily self service). Was that something they did manually or is there a way to brand my JSS that I'm unaware of?
Good morning, We recently upgraded our MacBook fleet to MacBook M1 Apple Silicon. Our old scripts that allowed us to force bluetooth back on does not work anymore do the restrictions of Apple Silicon. I was checking if any found a to turn bluetooth on using terminal? I found the /usr/sbin/bluetoolctl in terminal but it only shows if the power is on for bluetooth but nothing else.
Provide your users a “heads-up display” of critical computer compliance information via swiftDialog Background More than six years ago, William Smith (@talkingmoose) published "Build a Computer Information script for your Help Desk"; we implemented a customized version in the fall of that same year. Last week, during a conversation with one of our rock-star TSRs — whom I’ll refer to as “John” — we decided it was time for swiftDialog-ized reboot. Features The following compliance checks and information reporting are included in version 0.0.2. Compliance Checks Compliant OS Version Last Reboot Free Disk Space MDM Check-in MDM Inventory FileVault Encryption BeyondTrust Privilege Management Cisco Umbrella CrowdStrike Falcon Palo Alto GlobalProtect Network Quality Test Time Machine Information Reporting IT Support Telephone Email Website Knowledge Base Article User Information Full Name User Name User ID Kerberos Single Sign-on Extension Platform Single Sign-on Extension Computer
Hi https://learn.jamf.com/en-US/bundle/jamf-account-documentation/page/Jamf_SSO_with_Jamf_Account.htmlUse this guide to configure your Microsoft Entra IDI'm in the process of doing something and it says it's connected, but I can't see the IDP redirection page. Can you share any success stories?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!