Get Support
Recently active
The message keeps popping up for a user. He said this has been going on for like a month but there are no performance issues or any issues on the mac itself. His Mac is updated to the latest OS. Any ideas on this one?
Hello All, We have a few devices that were recycled that are popping up in Pakistan as they were not removed from pre-stage they are checking back in. I am looking for the best solution as to what to do about this. My thought process is to keep the record and try to send lock/wipe commands while removing the device from pre-stage. If the device ever checks back in then it should be locked/wiped and removing it from pre-stage should stop it from checking back in.
Hello guys, I have an IBM ACS software which I need to package and show in Self service. This app doesn't have a regular dmg or an installer. It installs via a script: Once the script runs, it puts the app in the Applications folder: This is what the script does: #!/bin/bash # Description: # This script will install IBM i Access Client Solutions in the Applications folder on Mac OS X # # Usage: ./install_acs # args=$@ args_length=$# arg1=$1 prefix_arg1=${arg1:0:9} suffix_arg1=${arg1:9} printhelp="no" default_noparms="no" reset_start_over="no" quiet_mode="no" exclude_functions="no" install_type_shared="no" install_type_preset="no" declare source declare target declare old_target declare source_AcsConfig declare target_AcsConfig declare old_target_AcsConfig function copyProductFiles { echo "Copying product files" >> $HOME/IBM/install_acs_log.txt #Remove the old app so we don't leave cruft laying around. rm -rf "/Applications/IBM i Access C
First time using Nudge here and i was trying to update all my Macbooks to 15.3.1 using Nudge to let our users know that they need to update their Mac.I've understood how to push the notification to all Macbooks that have less then a specific OS but I'd like them to update not to the latest but to the one before.Thank you
Hey, We're trying to set up a simple Jamf Connect Notify workflow where we just want to perform a few small checks before letting the user access the desktop. To achieve this, we followed the Jamf Connect Notify Documentation: https://learn.jamf.com/en-US/bundle/jamf-connect-documentation-current/page/Notify_Screen.html. We created a separate payload with the AuthChanger profile to set it to Jamf Connect Notify and added the key and value for the script path in the Jamf Connect Login Configuration Profile. Additionally, we created a separate package containing the script (root:wheel 700) at the path specified in the Jamf Connect Login Profile, along with two icons to brand the Notify screen. The directory used is the default one: /var/tmp/. We signed the package with the Jamf Pro Built-in CA signing certificate but also tried using a Developer Certificate and even signing the script separately before including it in the package. Unfortunately, we keep encountering the same issue. Jamf
I have a couple of smart groups which detect for the presence of certain Chrome Extensions or VPNs and then if a computer is added to that group it runs a policy script to remove those extensions or applications. The only issue I have is that apart from knowing a computer has joined or been removed from a group, there is no information. This may be a long shot, but does anyone know if there is a way to change the email report so it includes the reason a computer was added to a group? What I mean to clarify is that my VPN one, for example, looks for anything called "*VPN*" but it would be useful to know which application or extension triggered the group membership so I can get more information. I could of course remove the script from automatically running to remove the offending software and manually add devices to another group which does run the script after I've seen the inventory....but just seeing if it is possible to get that info in a more streamlined way?
Hi, Since none of the users on our computer have no admin rights, but we have created a possibility that the user can uninstall App. However, the script only deletes the application from the folder. That is sufficient in most cases. However, in some cases it is necessary to delete the created data. Maybe someone has an idea how to find these and delete them. #!/bin/bash ########################################################################## # Shellscript : Uninstall Script # Autor : Andreas Vogel, ########################################################################## # Script asks for the file to be deleted. # # Only for test - comment out in production! # set -x ###### please only edit here ###### list files to protect here app_protect=" NoMAD McAfee Self Service Preproxy Identity Agent jamf" ##### End ################ # Variabeln sys=$(while read p; do echo "$p" | grep "/Applications" ; done </System/Library/San
Is there a way to do a search for the Managed Apple ID that shows in an iPad's SHARED IPAD USER list?I have gone through all the Advanced Criteria but none of the "USER" related fields find even the one iPad with the user that we know has created an account on it. (Their name is listed in the iPad's inventory.)Thank you.
Hello Jamf Nation,I’m experiencing an issue where new users signing into Jamf Connect using Okta authentication encounter a blank white box with a “Done” button instead of being guided through the MFA enrollment process.Issue Details:• This only happens for new Okta accounts that have not yet configured MFA.• Existing users with MFA already set up can log in successfully without any issues.• The Jamf Connect login window recognizes the new user but doesn’t properly handle the Okta MFA enrollment flow.• The expected behavior would be for the user to be redirected to set up MFA, but instead, they get stuck with a blank screen.Current Jamf Connect Setup:• OIDC Authentication with Okta• OIDCAllowMFA is enabled• DenyLocal = True (Enforcing cloud login when online)• LocalFallback = True (Allowing cached logins when offline)• OIDCEmbeddedWebView = TrueTroubleshooting Steps Taken:• Confirmed that Okta policies require MFA enrollment for new users.• Checked Jamf Connect logs (log stream --predi
Has anyone had any success getting Parallels to use PXE boot so we can use an SCCM image?
Hello all,I created this script to get around the not-so-great Safelist and Blocklist profile payload for macOS in Jamf School. This still isn't a great solution, which is why we plan to lock devices down more next school year, but may be found useful for anyone wanting to remove apps remotely. If I had a github account, I probably would have posted it there, but for now I'll walk through it here. I welcome any feedback and advice on how I can improve the script.Credit to grahampugh for the process killing function from his Remove Application.sh that I tweaked for this.Please note: Jamf School is not required to use this script. The implementation will be different, but the script itself can easily be used elsewhere on macOS devices.ScriptWhat the script does is look for the app matching the provided bundle ID. If there is a match, it quits/kills any running processes and deletes the app. Apps outside of the Application folder will still be detected. While doing all of this, it reports
Hello All, I just want to know if anyone uses this integration currently and what are the benefits to integrating data dog with Jamf Pro.
Today we are releasing a maintenance version of Jamf Connect. Jamf Connect 2.45.1 addresses the following product issue: [PI134272] Jamf Connect login window configurations with Okta Classic Engine as the identity provider no longer display the authentication web view as a blank window, preventing new user accounts from logging into their computers. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
Hello,I like to request a feature. We use a specific network profile. On a device the Wi-Fi is always on and can't be turned off. At our school a time based restriction profile is installed with a whitelist of apps which are acessable during time in school. After school this profile isn't active anymore so a user can use the iPad for private purposes. We use private apple IDs because the iPad is owned by the pupil not by the school.The problem is that some smart pupils turn off auto-join of our via profile installed network. So they arent visible on classroom and also do not receive the restrictio profile.A solution could be a setting in jamf for the network, that auto-join can't be turned off.Thanks
We continuously strive to enhance our products and features, and your insights are invaluable to this process. We're conducting a survey to better understand how reporting in Jamf Protect's Compliance Baseline feature serves your organization's needs. Your feedback is essential in ensuring we effectively meet your compliance auditing needs. And who better to provide feedback than the geniuses who use it? If you use the Jamf Protect Compliance Baseline feature, no matter how frequently, we would greatly appreciate your input on how we can improve. This brief survey (approximately 3–5 minutes) will play a crucial role in shaping our next steps. Complete the quick survey HERE! Thank you for your time and support!
Has anyone gotten a script or custom pkg to deploy Carbonite Pro?
I would like to see if there is a way to require a IT Staff user to sign in before DEP will proceed. I was thinking of using the Enrollment Customization to do this, but this will assign the user to the device. I would rather not have all our devices assigned to me. Anyone else tried something similar? Any ideas?
Our Jamf Pro instance features an astounding 69 Catagories in Settings/Global. Personally I'd like to reduce this down to a maximum of 10. I'm wondering how others approach organisation of their Jamf Pro and Self Service... in particular, those who work in an education space.
I have been testing the Jamf app catalog.I have a prestage that seems to be working for the initial deploy.What I need is the ability to delete an app and have it redeploy on next check in.Outlook constantly becomes corrupt and needs to be removed and re-installed.Previously I used a script that allowed the EU to remove and re-install the app through Self Service.Is it possible to re-trigger the Jamf app catalog deployment beyond the initial install?
Is there any way is there to make a cert set as Always Trust in system keychain through JAMF? I have few devices where Zscaler cert is not set as Always Trust when the device got the certificate from Zscaler.
We have a sprinkling of this problem across our fleet. If a user taps "no" to the notifications dialog box on first open of Self Service they then get the error."Error loading content. For more informations,contact your administrator." If we turn on notifications in Settings for Self Service then we see the Self Service populate normally with apps Any suggestions for how to avoid this? More data points that may be irrelevant - this example iPad was enrolled using Return to Service, it's running iOS 17.6
Hey guys, I have no idea how to get out of this one. Any help is greatly appreciated. I support a High School and a University. The High School started using Jamf a few years ago. This year the University decided to finally get a MDM. They decided to use the High School Instance so I created Sites. This busted my Configuration Profiles. We use a Enterprise WIFI similar to eduroam. When I moved the lab computers to the site it lost the WIFI. I can't connect a Ethernet to USB-C connector because they are running Sonoma and you need to Allow to use Accessories. I can't login, more on that... In addition when I did a erase/install with the laptops last summer Jamf broke my Lab Admin account. It was working at first but then stopped. I created a case with them but they were unable to give me any answers. I thought it was LAPS but I never turned it on and confirmed it is not on. The recommended solution they gave me would be to wipe and re-enroll the computer (and delete the inventory record
I am about to deploy Jamf Connect to my org, with Okta as our IdP. We are replacing JumpCloud as our previous LDAP and IdP. With Jumpcloud when users reset their password using the Jumpcloud desktop app, Users would set their new password in the desktop app, and that new password was automatically and instantly working as their local password. The user was NOT prompted to sync their cloud/network password to their local password a an extra step. With Jamf Connect however, after changing their Okta password using the Jamf Connect desktop app/menu bar, users are prompted to log back into the Jamf Connect menu bar app, then have another pop-up saying that their local password (old network password) and network password (new network password just set) are out of sync, and are asked to provide their local password (old network password) to sync them. Is there any way for Jamf Connect to automatically sync network and local password when the new network passw
Hello everyone, We are currently facing an issue with Jamf Connect where some users keep receiving the notification: "Registration required - Register with your Microsoft Entra password on your Mac." Our Setup: Jamf Connect installed manually on affected devices Devices manually registered in Company Portal MacOS 15.3.1 Latest version of Jamf Connect & Company Portal Devices appear as compliant in MS Entra Devices in Jamf Managed &Supervised uniqueIdentifier" : "97BD-IUHGLD-LIUGHW7G-.....ETC." FileVault 2 Partition Encryption State:Encrypted Troubleshooting Steps Taken: Verified compliance status in MS Entra Deleted the device from MS Entra and re-registered Cleared keychain entry: /Users/testuser/Library/Keychains/65649DB6-A89B14CE16E0E Ran a script to reset Entra registration, which: Quits Company Portal Deletes related preference files and saved states Removes keychain entries and identity preferences Deletes the MS-ORGANIZATION-ACCESS certificate Reinstalls
Hello All, I am very new to Jamf Pro and Im trying to teach my self how to build packages and deploy them in our test environment. I am having a problem with an app downloading to my Macbook using Jamf Pro I have built the package and it shows up in Self Service. But when I download it, it said Installed but it does not show installed on the MacBook. I checked the policy logs and it show it starts to install the app but then it closes the packages. I have included the steps from the log [STEP 1 of 4] Executing Policy Steam [STEP 2 of 4] Downloading https://diamond.jamfcloud.com/jcds/downloads/steam.dmg... Verifying DMG... Verifying package integrity... Installing Steam... Closing package...
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!