Get Support
Recently active
Hello, We are having issues enrolling BYOD devices in Jamf Pro using Account-driven BYOD Enrollment. We are following the instructions on Jamf documentation but we are receiving an error for any Managed AppleID that tries to sign in:"Your Apple ID does not support the expected services on this device. Contact your administrator to sign in"All of our Apple IDs are managed and the domain is setup in Apple Business Manager. We have a ticket open with Jamf Support but wondering if anyone else has had this issue. Current configuration: This has worked before. We had these settings turned off for a while while we investigated (about 1.5 months).iPhone 13 Pro Max running iOS 16.4.1.
Hey guys, So in the midst of setting up our jamf i have a second user profile set up for our Dept to login to every laptop, Is there a way to set a standard profile pic using jamf pro ? Any advise would be great. Thanks
We're not a fan of Jamf requiring a Jamf Account SSO setup to access new features such as Blueprints or Compliance Benchmarks. What about new features down the pipeline? I was looking forward to Blueprints, and we use the JCE now for Compliance Benchmarks (CIS Level 2). So, the new features had us excited since it was presented at JNUC 2024. However, the Jamf Account SSO setup may be a deal breaker for organizations. Consider reading and voting for this Jamf Nation Idea:https://ideas.jamf.com/ideas/JPRO-I-1182
I have a strange issue. First couple of wave deployments worked well, but now has stopped working. Every device that I scope Nudge and the jamf profile to, give the message No minimum required macOS version found within the Nudge Deferral Status Extension Attribute. This Mostly Mac blog states that means the requiredMinimunOSVersion key is not found. This sounds like Nudge or Jamf are not reading the config profile located in /Library/Managed Preferences/com.github.macadmins.Nudge.plist. I am using the default Nudge Suite (latest) with Jamf Pro Schema. Any ideas are greatly appreciated
We have a Smart Group to set the Lock Screen and wallpaper on our iPads that has been working fine for over a year. Today I was setting up a couple of iPad Air M3 systems (iOS 18.3) and it didn't work on both of them. I checked the group's Automated Management tab in the Smart Device Group and it is showing "Error" in the status field for those devices. The desktop image file is a 1080x1080 PNG file. Any ideas?
Hi there, What would be the best/easiest way to enable SSH on a specific users' machine remotely, from Jamf? thank you!
A Read-only Friday post by William Smith You have no control over when you’ll get an idea.Yes, I do get my best ideas in the shower. Ready to go on a scavenger hunt? Getting through and beyond your own anxieties about presenting at a technical conference or meetup is the hardest part about presenting at a technical conference or meetup. Taking that first step to commit yourself to an uncomfortable (but worthwhile!) challenge begins your journey of a thousand miles. But I promise the rest will only feel like 500. 🫠 Now begins the execution: we need to first find ideas for a topic. What do I know that I can present? You may ask yourself, “What do I know that makes me an authority on anything?” Simply put, it’s your own experiences that your audience wants to hear. Notice the title of this post starts with “Finding”. Right now, it’s time to find your story. Don’t try to make something out of thin air. In the next blog post, I’ll talk about starting and developing your story. Every presen
Hello all, Newbie here. I've been tasked with installing a mobile config profile and then have to install an extension from https://droxi-extension.s3.amazonaws.com/droxi-ext.html I can upload and scope the mobile config with no problem, but I don't know how to deploy this extension. I know how to deploy an extension from the Chrome web store, but I'm having trouble figuring this one out. I have to deploy this to many Macs across 8 different locations. If all else fails, I'll have to do it by hand one by one and that'll take a longggg time. Thanks in advance!!!
Hi ! Can someone suggest me how to set up a custom analytic to get an alarm if a user (yes, they need to have adminrights sadly) removes the MDM profile? I had some cases in the last weeks where all profiles went missing and i do not want to suspect someone falsely. Thanks !
So we might be learning this lesson the hard way, but we have an Air that a student has locked via his iCloud account and does not know the code. We've been fighting with Apple support and GSX to get it unlocked but in the interim we've begun discussing how to prevent this in the future. Only way I really see would be to disable the iCloud preference pane (configuration profile I assume?), correct? If that is the case, then you are debating the cost benefit of them being able to utilize the iCloud features against locking and wiping a device as well. If we go the route of disabling the iCloud pref pane, a user could still enable this during an OS upgrade to right? Finally, wondering if there is an extension attribute or another way to query all my devices to see who has iCloud enabled on their laptops?
Hi All, We have an issue with employees who are offboarded. When they return their Mac's, sometimes we find their Apple id's block us from wiping the computer and giving it to the next user. When this happens, we need to find the original invoice, send it to apple with a request and then they can unlock the Mac. I am wondering what companies do to circumvent this issue. We use Jamf but we do not provide company Apple id's. We dont mind if users connect their private Apple id's to the computer as it helps with the Apple ecosystem. Any suggestions would be greatly appreciated
Afternoon All Im trying to pull back a license for an app deployed via VPP I have removed the device from scope and update the inventory but it still not showing as been avilable to deploy again. Does ASM need to sync with jamf as well? Thanks Tom
Hi all - really annoying that the option for pointer size is greyed out and our developers need the option to adjust available. Has anyone seen this and found a workaround via Jamf through a script or profile? All my efforts have failed, many thanks :)
Hi All, We have company managed Macs with Jamf. We do have sensitive company data on the computers which we do not allow to be transferred out of the company environment. We block the use of external storages. If we allow users to connect their Apple id's and iCloud, will they be able to transfer company data from the computer to their iCloud? Is there anything we can do to prevent this? Maybe block their iCloud somehow? Any suggestions? Thanks in advance
We enrolled a device and, during the assistance migration, used a Time Machine backup from a non-enrolled machine. Using the Jamf login configuration profile, we allowed the merge of the network account with the local account. After merging, the local account name appears in the "Users and Groups" section and in the terminal, but the password of the network account is required. What steps can we take to ensure that after the merge, the local account adopts the network account name? In our standard routine, we use a synced network account and local account.
Hi, We are transitioning 250 or so users out of Jamf Pro / Jamf Connect. We have an upcoming license expiration, so trying to get all users out before expiration. Renewing the license wasn't an option as we'd only be doing so for a small number of users and the minimum possible duration of renewal is 6 months. Can anyone provide details on what happens when the license expires? I've seen mention of a 2 week grace period and a 30 day period. Will device be unmanaged or left in the state they were in at the time of license expiration? Just want to ensure we fully manage expectations. With all due respect to licensing, we aren't looking to short Jamf of licensing $. It's simply that we are moving into another product at the decision of our leadership on a short timeframe.
I have the following in a script on Jamf Pro. When I deploy the script and it runs this I can see on the test Mac it has "Attempt 1 to bootout com.Daemon" in the log file. However, it fails to continue with the rest of the script. I tried adding || echo "bootout error" after the bootout command but that didn't help either. When I run the launchctl list | grep "com.Daemon" command I can also see it has successfully booted out the Daemon. Why won't it continue to then trigger the jamf policy? I've tried /usr/local/bin/jamf policy -event 'Trigger'I've tried with sudo and without. I've also tried to have it trigger the jamf policy first which works but if I put a delay in the policy so I wait until bootout is complete it doesn't progress to attempt bootout (it waits on policy completing). I tried adding & to then end (/usr/local/bin/jamf policy -event 'Trigger' &) and that resulted in bootout command running but jamf policy did not. When I run the s
Hello,I'm testing the Temp user promotion setting:I have set a com.jamf.connect config profile with the below plistIt's showing correctly on the jamf connect menu bar but when I click and select the reason nothing happens and the timer doesn't show in the bar nor the user gets elevated.Hope anyone encoutered the same issueThanks <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>TemporaryUserPermissions</key> <dict> <key>TemporaryUserPromotion</key> <true/> <key>URLCommandLineElevation</key> <false/> <key>UserPromotionDuration</key> <integer>60</integer> <key>UserPromotionReason</key> <false/> <key>UserPromotionTimer</key> <true/> <key>VerifyUserPromotion</key> <false/> </d
This is in regards to the MiniEvent Outing at shooters during the JNUC. I'd be willing to help with Gas and other $$$ if they want to go to this. Regards,TJ
I just removed the mdm management from an ipad, FROM THE IPAD (not through jamf, but on the ipad). It is an ipad that I was going to remove from Jamf, but I kept seeing the remove management when looking at it on the ipad and wondered what it did. Now I know. Back in JAMF I have no ability to manage that ipad anymore even though it shows it in JAMF. Which means the user can remove the mdm management from the ipad and we have no control of that ipad? I just sent in a support question and they sent me nothing that is relatable to my concern. Why is the user able to remove the mdm management from the device?I have no idea how these ipads were enrolled, they were done before the job was handed to me. The past year they have been added to Apple Business Manager, then into JAMF. This was not one of those, but a previous enrollment. Not self enrolled but through apple configurator.
Today we are releasing Jamf Pro 11.14; highlights include: AD CS Certificate Deployment Using SCEPYou can now use the SCEP payload to deploy certificates from an Active Directory Certificate Services (AD CS) integration. Previously, only the Certificate (API) payload was available to issue AD CS certificates. The SCEP deployment method supports automatic certificate revocation based on scope change. You can also redistribute certificates that are approaching their expiration date by redistributing the configuration profile. App Installers Support for External URL DownloadsJamf App Installers supports software title installation packages that are downloaded via versioned URLs from a vendor's website. An alert is displayed on the Configuration settings tab for any software title that is downloaded via an external URL.Note: At this time, only newly added software titles that have a versioned URL available will be downloaded via external URLs. For additional information on what's
We have the Internet Accounts system preference pane disabled, but our users are still able to add accounts to Internet Accounts. I think this is being done via Safari because IIRC, it will ask you if you want to add a supported account when you sign in to that account through the browser. Does anyone know via the command line how to remove these accounts? Or do we just have to temporarily allow access to the Internet Accounts preference pane in order to remove these?
I have been working on a policy that will create a temporary admin account. A launch daemon gets installed and launched to handle the account deletion. Once the alotted time has elapsed, I see the account and its home folder get deleted. I see that the launchd process is no longer running. Everything works exactly as intended, but the launch daemon does not get deleted. I can manually run a command such as "sudo rm /Library/LaunchDaemons/com.my.launchdaemon.plist" and that works perfectly. The launch daemon triggers another Jamf Pro policy to run that deploys a script that runs the account deletion, deletes the home folder, unloads the launch daemon and then is supposed to delete the launch daemon. A moment ago, I commented out all the steps except the launchdaemon unload and deletion, and watched as the script deleted the launch daemon! Below are all the steps that the script runs. #!/bin/zsh # Delete the Rescue Admin account and its home folder echo "Removing Rescue Admin account" d
Previously the script below from another message made it possible to have custom screensaver files (Photos) that would rotate. This no longer works in macOS Sonoma. Does anyone know a new method to have the screensaver call photos from a particular folder in somona via a script or another way.#!/bin/sh## get current useruser=`ls -l /dev/console | cut -d " " -f 4`## get macOS version(s)osMajor=$(/usr/bin/sw_vers -productVersion | /usr/bin/awk -F"." '{print $2}')osMinor=$(/usr/bin/sw_vers -productVersion | /usr/bin/awk -F"." '{print $3}')## set key items for screensaver/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver CleanExit -string "YES"/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver PrefsVersion -int 100/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver showClock -string "NO"/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver idleTime -int 60## c
I watched the presentation given by @chadlawson and uploaded to the Rocketman Tech channel on YouTube (https://youtu.be/6xVmJqpbEHI) over the weekend. I decided to dive in and change a script that puts a machine into a static group (credit to @sdagley ) but whilst I can see that I'm getting a token, the computer is not going into the Static Group. The reason for changing from Basic Auth to Bearer Token Auth is because Basic Auth is deprecated so I'm trying to get this figured out before there's a panic.Just wondering if anyone can see where I'm going wrong or suggest a better way to do this? The first script below is my working script using Basic Auth and the second longer one is the one using Bearer Token Auth. The second script is mostly using code from Rich Trouton's blog on Bearer Tokens and I do get the Bearer Token but whilst I seem to have no errors, the machine is not added to the static group.#!/bin/sh # AddComputerToStaticGroup.sh # Adds the computer to a stat
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!