Get Support
Recently active
Apologies if this is a basic question — I'm new to MDM administration. During the initial rollout at a new school location, the iPads get stuck after connecting to Wi-Fi and attempt to load the profile. The error message appears to be something like: "Timeout while reaching for profile" (translated from a different language). Troubleshooting so far: I spoke with the Wi-Fi administrator to ensure that the necessary ports are open, and the firewall shouldn't be blocking anything. I also tested with a different Wi-Fi network, but that didn't resolve the issue. I un- and reassigned the ADE profiles. The profiles are relatively small compared to those at other locations, so size shouldn't be the issue. Any suggestions for potential solutions or next steps would be greatly appreciated.
We allow our users from management level up to download apps as they need and we do not worry about controlling their backgrounds or layouts on their devices. If you restore from backup on a phone that was never in JAMF it will not show up in JAMF. If you restore from backup on a phone that was in JAMF after a restore it no longer actively communicates. Is there a way for these users to restore from backup and keep their new phones similar to the old?
With the new changes in the US, we would like to know how the EU manages third-party app stores within Jamf, as they have had the feature for a little while. Specifically, is there a way to automatically install an app from one of the third-party app stores?
Hey everyone,Having an issue with jamf app catalog installations. Some machines just seem to randomly not want to install the app. These machines are very similar, it's a computer lab, but one machine will install successfully and its neighbor will fail.My question is how do I investigate this further plus all I see in the console is that it failed with no real information and also has anyone else experienced this and was able to fix it.
I’ve set up Jamf Connect, but the current login process feels too complicated for users. Right now, they need to: Then authenticate with their Entra ID password, And finally enter a local admin password to sync the network and local accounts. I don't understand what I configured wrong and why this is happening. As far as I understood from the forums and documentation, this should happen at the beginning when you need to synchronize the password, or when the password has not been synchronized.So it's most likely that the password is not synchronized? How can I troubleshoot it?
Hi everyone! I’m a few months into using Jamf Pro and loving it — but my list of configuration profiles is growing faster than my caffeine intake on patch Tuesdays. Categories definitely help a bit, but honestly... my Config Profiles page is starting to look like a teenager's bedroom: stuff everywhere, no clear idea what belongs where, and a growing sense of fear every time I open the list. I’m curious — what’s your "best practice" for keeping things clean, understandable, and future-you-friendly? Do you: Create broader profiles (e.g., one config for all things Microsoft Edge),OR Break it down into smaller, highly specific profiles (e.g., one profile just for Edge homepage settings, another for extensions, another for updates)? Would love to hear how you actually organise it day-to-day. Bonus points if your method also stops your future self from screaming into the void six months from now. 😅 Thanks legends!
I have an employee who reset his passcode on his laptop and then immediately forgot it. I don't have the option to reset his passcode (in the management section where you would typically lock it). It's managed by jamfusermanagement and we generated that 1 hour passcode to log in and that didn't work. FileVault says it's off one place and on in another. But it's managed by jamf. I can see that. Shouldn't I be able to help him??
Greetings! We use FileVault through Jamf Pro and we also have a mixed bag of Intel and Apple Silicon laptops. As far as our Jamf Protect Complaince report, ALL of the Apple Silicon machines show as "Pass" and ALL of the Intel machines show as "Fail". I've been poking around online trying to figure that one out, but can't seem to find anything. Has anyone else experienced this phenomenon and found a fix? Thank you
Here is another goodie! As everyone knows (or maybe it is just me), that the Adobe apps are a real pain to deal with, and I have come up with a script that will facilitate the removal of any Adobe apps that are discovered on a user's system. The script will go thru and import a directory listing all of the adobe apps that it can find and determine the highest "year" that is installed, and when the user is presented with the removal options, it will NOT allow them to remove the the highest year versions, but will allow them to remove previous versions. I will also remove any CS6 and older files, outdated Adobe reader apps, outdated Acrobat apps & Safari flash plugin You can also pass the year when a new version becomes available and it will (optionally) present the user with a message stating that there is a newer version available if they don't already have it installed. There are two critical functions for this process noted here: extract_version_code(): (This h
I've been tasked wtih trying to rightsize our Mac fleet's SSD that we purchase for the devices. I've been tried doing an EA script that is generating some info and I tried creating an advanced computer search looking at "Boot Volume % full". The Comp search one seems to give inconsistent data when I click into a machine record it vary's wildly from the column the report spits out. I was thinking that once I get consistent data out, I could use smart groups to dump the machines that are 25% full go into one group, 26-50% to another, and so on. But I'm also open to other suggestions. thank you!
Hi Friends! Today is the FINAL day to apply to be a Jamf Hero! A few things to note: Heroes is for ANY Jamf customer. (It doesn't matter if you're new to Apple management or have loads of experience!) Even if you were in the program before, you still need to apply. Applications won't open again until next spring. THIS is your chance to get in amazing community! Learn more from this previous post. Or apply directly HERE! Reach out to jamfnation@jamf.com with any questions.
I have been trying to scope a policy to an Azure directory group however im not having any luck. In the settings JAMF thinks the user is a member of the directory group so that part all seems ok. In the policy i scoped it to all managed devices with a limitation of the directory group but it doesnt seems to run at all. I have tried both a Self-Service policy and a policy that runs on check-in but neither seems to work. When i remove the group limitation the policy works fine. Is there anything else i need to do to get the group limitation working?
Hi, I'm looking for a script or uninstaller for removing all Jamf components. My company made a decision to move to Intune, and we took the non-best practice route of manually moving devices (best practice is to completely reimage). Because of this the devices have Jamf residuals on them. We're simply looking to clean up after and remove any unlicensed elements as part of good due diligence. I did find one post suggesting use of a third-party uninstaller. Perhaps this is best over trying to come up with a script?
So I was having a hard time removing TV.app from the dock. Now before we start I know I could've used dockutil (which I've used in the past before) to make my life easier. However I didn't want to push any more 3rd apps unless I really needed to. I decided to use the built-in tools JAMF has to keep our deployment lean. I read a lot of post and found nothing relating to the TV.app itself.Some Applications are found in /Applications (Music, Numbers) while other like TV.app is found in /System/Applications (Launchpad, Photos). So I kept on trying /System/Applications/TV.app and nothing happen, it didn't remove itself. I tried every thing I can think of and nada, it was putting up a hell of a fight. So I decide to dig into the app itself. I finally came across something interesting. If you open up this file: /System/Applications/TV.app/Contents/version.plistYou will find:<string>TVDesktop</string>. Now I haven't seen any mention of this any where before. I was like hmmmmmm
Using Configuration Profiles option in JAMF i had setup HTTP/HTTPS Proxies.Distribution method was "Install Automatically". In Scope had added the target machine to which these Proxies should be applied In Proxies option enabled "Enable Web Proxy (HTTP)" and " provided Hostname or IP address and port number for web proxy.In Proxies option enabled "Enable Secure Web Proxy (HTTPS)" and providedHostname or IP address and port number for secure web proxy.After this saved the Proxies.Checked and verified in logs and found that the Proxies was pushed automatically. As per JAMF logs Proxies values were pushed successfully and automatically to target machine.In target machine went to Network--->Advanced--->Proxies to check if the values were pushed or not.Values were not being reflected there. Can some please provide some thoughts and inputs on this.The Proxies section under Network--->Advanced should show the updated values which have been pushed.Nothing was sho
In any organisation some of the applications are licensed and which need to be scoped to individual machine or through static group collection.But when we check the JAMF App Catalog which are limited to scope “Smart Computer Groups” only.Could you please enhance this JAMF App catalog scope feature to the individual machines or static group.Thanks.
My team has been tasked with changing some settings for Safari and Chrome. We have to have the homepage set and then a second tab that's blank. We are able to successfully push these changes with a config profile, but of course this locks down the settings. Has anyone had any experience with pushing settings like this and the user still being able to change the settings back if they want? I tried scripting the changes and pushing to me device, but neither browser seems to care about the changes. Any advice would be much appreciated. Thank you
Hey Mac Admins, I wanted to share a custom Jamf Extension Attribute I wrote to help detect the current IPv6 configuration state for whichever network interface is actively routing traffic — including when a VPN tunnel is in use. This script: Detects the active interface via route get default Handles VPN tunnel interfaces (utunX) by falling back to the actual enX interface from netstat -rn Reports the hardware type (AirPort for Wi-Fi, Ethernet otherwise) Categorizes the IPv6 mode as Automatic, Link-Local Only, or OffExample Result: <result>Ethernet - Automatic</result> Category Group Name Network IPv6 Automatic – Ethernet Devices Network IPv6 Automatic – Wi-Fi Devices Network IPv6 Link-Local – Ethernet Devices Network IPv6 Link-Local – Wi-Fi Devices Network IPv6 Disabled – Ethernet Devices Network IPv6 Disabled – Wi-Fi Devices Network IPv6 Status Unknown – Needs Review Extension Attribute Script: #!/bin/bash #######################
I have been able to determine if the application is enabled and running, just have not been able to create a script or guidance to help the user turn it back on without generating support tickets. I have seen this type of guidance demonstrated with a Jamf lead learning presentation.So what I want to do is create an alert that will guide a user to a self service help script that will either direct a user to or allow them to click a button to enable Jamf Private Access when it gets disabled. Anyone have any Ideas? I have not been fruitful in my search of information as of yet to be able to run JamfPrivateAccess using CLI or create the assistive guidance necessary.
Hi,This is a bit of a strange issue; so I thought I'd see if it was one anyone else has seen, and had a resolution for.We have a configuration profile to apply our wi-fi settings. The wi-fi has a hidden SSID and is using WPA2 Enterprise, certificate based security. The profile works fine. It applies, and computers can join the wi-fi; however, every now and again the mac will stop joining the wi-fi. The profile is still applied. When I check the advanced wi-fi settings I can see that it still has all the settings present. It just will not join the wi-fi.The only thing I can find that makes it join the wi-fi again is to remove the configuration profile, and then re-add it; however that is awkward as the devices are rarely connected to ethernet in order to re-apply the profile.Hopefully someone has seen this behaviour before, and knows what the fix is?Thanks,
Just as an FYI - Slickdeals has Macworld today only for $7 / yr (up to 2 years). http://slickdeals.net/permadeal/95416/discountmags-macworld-magazine
Hello, We're looking to import Cyber Threat Intelligence a feed into Jamf Protect. Something like STIX2.1 or a GraphQL API similar to here .The idea is to enrich Jamf Protect endpoint protection and integrate IoC's from external feeds.Is there already a solution? Is this on the roadmap?
Has anyone noticed that the latest version of Jamf Connect, version 2.45, now shows up at the very bottom of the screen as opposed to centered on the screen? Is this the norm now?
My employer has a yearly daycare program where parents pay to drop there kids off at one of our campuses and then the kids can take various fun classes. This year one of the classes features the plane flight slim. I was looking at that and the installer for it is a custom .app, that asks whether you want the demo, or full version with a license key, and then it downloads about 80GBs. For some reason it won't let you install the app in /Applications/ saying it will cause 'problems', it defaults to ~. However you can change it to /Users/Shared, which is what i will do. By default xplane stores its activation in ~/X-Plane 12/Output/preferences/, i don't know if that could be moved to the equal computer level locale. Does anyone have any experience with deploying this app via jamf pro and SSO via Jamf Connect? Contact the vendor for multi seat advice? Build a massive composer package and pray? thanks for the advice
Hi, I work in an education space (with Mac labs and the like) - we have 800+ Macs. Our current process for keeping macOS up-to-date is to copy an entire mac installer to each mac, then use a policy to trigger this installer. I find this a little exessive for applying minor updates. I'm wondering how else people keep their Mac fleets up-to-date. I've looked at Jamf Managed Software Updates but it seems quite manual, and also hit-and-miss.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!