Get Support
Recently active
Hi , Im able to read members of a AD group with command dscl "/Active Directory/domainname/All Domains" -read /Groups/ADgroupName | grep -Eo 'CN=[^,]+' | sed 's/CN=//' | sort -V . How can I add a computer to same group ?
So I am trying to figure out if its possible to use the Jamf Splunk Add-On to see if our team can use it view logs for one of our policies, where certain groups can gain temp-admin priv.From reading the documentation, you can use Splunk to spew out data from an Advanced Computer Searches, which can't cover that need. Or doing a Custom API call referencing from Jamf's classic API documentationHowever, haven't been able to find something that will fit the request. Was wondering if anyone knows way to use Splunk to spew out a certain policy log.
Hi guys, We have quite a few users who seem to download applications and run them from their desktop, Spotify and Chrome being the biggest culprits. I'm looking for a way to remove the application from users desktop folders. We have a couple of users (read: myself and a few other IT people) that have these installed on their machines in their Applications folder, and we don't want to touch those. Our users have local homes on our iMacs, and we run an AD environment. What's the best/tidiest way that people have used to remove apps from multiple users desktop folders?
Hey Jamf Nation!Since we announced Self Service+ at JNUC 2024, it has continued to evolve with features focused on content discovery, branding, and usability. Today, we’re excited to introduce the next major milestone: identity management in Self Service+. We're moving Jamf Connect's desktop app capabilities into Self Service+, which brings key functionality: synchronizing macOS accounts with cloud-based credentials, and privilege elevation for just-in-time admin rights on Mac. Jamf Connect's login window plugin remains separate application and is not included in this preview of Self Service+, ensuring continuity for account provisioning and local multi-factor authentication.How to join the beta:Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you'll receive an invitation to join the Beta Forum in your email, click "Join this group Hub" to gain access.Email beta@jamf.com with questions. The beta program is covered by the Jamf no
Hello all, I've had an issue since upgrading to Jamf Pro v10. On some client Macs, the Self Service app constantly crashes. In some cases it crashes as soon as it tries to launch. In other cases it crashes as soon as you click anywhere in the app window. In a few other cases, the app will be working fine, but as soon as you click on the 'History' or 'Updates' button at the top, the app crashes and continues to do so each time your open it. It has mostly happened on 10.11.6 clients, but we have one Mac running 10.12.6 that is now having the same issue. I had logged support call with Jamf about it. They said it was a bug with 10.0 and to update to 10.1. Did that, confirmed that the clients had the newest version of the app, but no change. Removing the frameworks from the client and re-enrolling it worked once on one client, but as soon as I clicked something in the app window, boom, crashed. Jamf did a remote session into my server, made sure everything look
Jamf Nation,We have big news for you today. I’m thrilled to share that we have announced our intent to join forces with Identity Automation, a company known for its innovative solutions, with capabilities that span identity lifecycle management, access management, and governance to help organizations secure their environments without hindering the user experience. This joining of forces is a natural fit, allowing us to enhance the way we support schools and other organizations that rely on desk-less workflows. We have a history of partnership with Identity Automation and RapidIdentity - sharing many customers who have benefitted from our shared technology and integrations. By further integrating Identity Automation’s technology with our own, we’ll be able to provide even more powerful solutions to help organizations enhance security, improve standard workflows and provide flexibility for shared devices. Our priority remains delivering the best possible experience for you, o
Content backfill required
Hi all,We are trying to determine if we can use Jamf to audit which users are actively using Apple Intelligence.Our hunch is that Apple doesn't log gen AI actions but I was wondering if anyone here might have some specific advice that could help.Thanks in advance!
Hi folks - working with a new jamf cloud and I've run into a problem trying to have a user follow the steps to make their device Entra compliant. When they log into the Company Portal app (after starting the registration from Self-Service) the login screen for Entra pops up, accepts their username and password, then goes to a blank window. We know authentication is happening because the MFA for the user kicks off but the login window is blank and does not show the numbers. Has anyone seen this before? I was able to do this on a different machine two days ago. The OS on this machine is 15.0
Today we are releasing a maintenance version of Jamf Pro; this release addresses the following product issues: Jamf Pro Server [PI126319] Jamf Pro now pushes a new single sign-on extension (SSOe) profile to devices that have been either re-enrolled without being marked as unmanaged in Jamf Pro or scoped for device compliance for shared devices and had the SSOe profile removed. [PI131971] Performance is improved in environments where a large number of computers belonging to a site update their inventory simultaneously. [PI134534] A 404 error no longer occurs when navigating between a smart group that is scoped to a blueprint and the blueprints interface. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. To access new versions of Jamf Pro, log into Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Pro. Cloud Upgrade Schedule Your Jamf Pro server, inc
Hi all - has anyone found a way to make Zoom the default for all events on new Outlook? Tried a few different policies with no success. Can add manually as a Zoom meeting, but this is pain for all users. Many thanks in advance!
I've filled out the survey, also going to post separately. I think it would be really beneficial to include the CIS control reference numbers in the UI so we can easily see if we're compliant on a specific control For organisations where there's a demarcation between client administration, and Information Security, the CIS control reference numbers become critical to ensure we're talking about the same thing, and are often used in other vulnerabliity management/scanning tools.
Hi, we ran into an issue during the Jamf Pro Patch Management. I ran a Patch Management Policy for Microsoft Teams 2.x with the Option to patch "Unknown Versions", too. The issue on some Mac Clients, all an macOS 15.3.2, that they were randomly quitting the Teams App. It turned out that their Inventory in Jamf Pro did not include the installed Microsoft Teams Version in the Patch Management section. In the Inventory view, the installed Microsoft Teams Version was recorded. A Jamf Recon didnt fix the issue, no MDM or DDM commands have failed on those Clients ... Did someone else run into a similar issue?
Anyone know if the ablity to set a screensaver at login windows is still broken in Sequoia. I belive its still the case in Sonoma.Im currently using this at works fine if a user is logged in locks the screen screensaver starts. The research I have done so far seems to indicate loginidealtime should trigger it at login screen, just doesnt seem to do anything. Have been playing around with a lower number that doesnt seem to help either.It something we always struggled to set in our labs, we adjusted our power policy last time so the macs would sleep. <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>askForPassword</key> <true/> <key>askForPasswordDelay</key> <integer>0</integer> <key>idleTime</key> <integer>900</integer> <key>loginWindowIdleTime</key
How can I find if any connected to VPN? Is it dependent on app to find it, like as for Cisco AnyConnect and Pulse it will be different. Or any generic way is there in macOS?
we have a few older Intel iMacs that are applying policies as normal, but configuration profiles changes and deletions seem to be stuck in pending. They're all checking in, and policies work without issue. This lab is all Intel iMacs running MacOS 14.7.1, but 75% works without any issues. They all report as being successfully enrolled in Jamf, and they where all automatically enrolled via ASM. I'm not sure what to do to troubleshoot, as these profiles work fine with most of the Intel iMacs, and our newer fleet of Apple Silicon computers.
We are seeing an issue with On-Prem installation of Jamf Pro 11.15.0.The Jamf-Pro.exe Server Tools are getting picked up by CrowdStrike for a malicious hash.Even grabbing the 3.1.5 Server Tool exe and manually installing it to the path results in Quarantine.We're having our InfoSec team investigate, but looks like this may affect others. Anyone else with On-Prem infrastructure seeing this issue?
Hi, I am looking for an Uninstaller for the Nextcloud App that also would remove the local cached Nextcloud Files. Because the location of those cached Files can vary, do I have to check the Nextcloud preference file of each User to find out the right location? Thanks for any help!
Our standardized testing program uses a locked-down browser, and will kick out a tester, if anything tries to do something in the background. We think that a number of students were kicked out of their tests because they set up Mail.app and got a notification. Rather than try to play cat and mouse with alert settings, is there a way to completely disable the Notification Center? I tried putting Notification* as a Restricted app, that gets killed, but that seems to have had no effect. We are currently running 10.12.6, but are going to move to Mojave this summer, so I need a solution for each OS. Under Mavericks, you could disable the LaunchAgent: launchctl unload -w /System/Library/LaunchAgents/com.apple.notificationcenterui.plist but that doesn't work under Sierra, so I bet it doesn't work in Mojave either. Should I just nuke the agent with: sudo rm -rf /System/Library/LaunchAgents/com.apple.notificationcenterui.plist Will I be able to do that in Mojave? Ideally, I'd like a
Is anyone encounter JAMF Teacher issue with after class end, restriction is not automatic restore to default. Case by when teacher start a class with apps restriction (example Google Chrome), after class end the restricted apps (Google Chrome) will not automatic restore/reappear? Is it normal? Teacher requires to manually clear all restriction when class ended to get the apps restore/reappear on student devices. Thank you.
Hello, We're working to put together new device personas (engineering, creative, etc), and all have been going well, except for our "lab" devices. Basically, they want a clean macOS device to use for testing, but it should still be enrolled in Jamf for asset tracking purchases. All the other devices, I've just added a trigger after enrollment for special_installs, and scoped/limited them by appropriate AD group. But for the clean devices, I need them to stop the normal enrollment process entirely. No config profiles (outside of the jamf required ones) and no software installed. I'd normally add them to an exclusion group, but I can't think of a way to do that automagically prior to enrollment...
Hi everyone, I've been facing an issue with internet connections just after updating to macOS Sequoia. Two devices running Sequoia cannot establish a connection with each other in Docker. Error response from daemon: Get "https://europe-docker.pkg.dev/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers) This issue started right after I installed the update, and I've heard about DNS/connection issues related to it. The first thing I wanted to test was turning off the firewall, but I wasn't able to make any changes. I have a policy that was supposed to turn off the firewall with the following command: defaults write /Library/Preferences/com.apple.alf globalstate -int 0 However, it didn't work on Sequoia, although I tested it on Sonoma and it worked well there. I've tried searching online but haven't found anything that works so far. My question is: Does anyone have any ideas on how to disable the firewal
With Jamf Pro 11.16.0 Beta we’re continuing our Compliance Benchmarks feedback. We’re also releasing the ability to configure the App Installers deployment process, along with new Prestage enrollment and inventory reporting options. How to join the beta: Enroll in the Beta Program under Product Feedback at account.jamf.com. Once you enroll you’ll receive an invitation to join the Beta Forum, click “Join this group Hub” to gain access. Please also check out this recent blog on Configuring SSO in Jamf Account prior to testing Compliance Benchmarks. Email beta@jamf.com with questions.The beta program is covered by the Jamf non-disclosure agreement; please do not share any information regarding your testing on any public forum, including the non-beta areas of Jamf Nation. Use the Jamf Nation Beta Forum or contact Jamf via beta@jamf.com with any questions. Thank you to all who participate in this program!
Hi, I want to disable OneDrive from the background service, but I don’t know how to do it. Currently, it is enabled, and I want to disable it. On Microsoft’s website, they explain how to enable it, but not the opposite. https://learn.microsoft.com/en-us/sharepoint/deploy-and-configure-on-macos#background-services Would you know how to do it?
We're using Adobe CC (Creative Cloud (all applications) for schools – shared licenses. Adobe documentation only offers deploying their packages via Jamf Pro. I'd tried to use Jamf School application installers. They work great but this likely fails 'cause the installers are obviously configured as user based licenses. The configured packages by Adobe admin console could not be installed even when packed with composer. This pkg-files are denied with error "Could not parse XML-file in package". Is there anybody who's next to this setup? Do you think this could be solved with a managed configuration via XML file?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!