Get Support
Recently active
Hi, We use Jamf to auto update Microsoft apps like Word, Excel and Powerpoint. Recently all our users are now seeing this message when Jamf updates the apps. Has this happened to anyone else and is there a fix for it?
<3 to all the people at Jamf working to fix things. In them time, shout out to #jamfnation
Our original Jamf Pro URL is mdm.dpmhome.com, but now it's failed to use. BTW, I have to use dpmhome.jamfcloud.com for access after your cloud service going back recovered, please let us know how can I use back mdm.dpmhome.com, thank you
It's strange that I've been dealing with this for the last 10 hours, and it's been completely unprofessional
Curious as to what happens to paid app licenses when you wipe a device. Seems to me that we are losing licenses if we wipe an iPad. Some of these apps are expensive. I wiped an iPad this morning and 2 paid app licenses were not available to scope, even though they were on the device before. It appears that the device is no longer scoped, but the license is no longer available. Any thoughts on this?
Hi all, I am currently trying to enable LAPS for our computers and after reading through documentation and watching videos on the topic, I disabled the creation of the local MDM admin account in PreStage and only enabled the UIE admin account. New problem that arose with that: The account created by the user during setup is now an admin. But I don't want that. Does anyone have an easy solution for that?
Hi, new Jamf admin and not very knowledgeable about the inner workings of SSO. I have configured SSO to our Entra ID domain and the web log into Jamf Pro and Account and no issues with log in with my account or a test account. I have been able to have devices enrolled successfully when the device (iOS only) is in ABM and have moved on to set up User Self Enrollment. When the test user account, goes to register, at: domain.jamfcloud.com/enroll, the user is directed to the Microsoft log in. After the credential are entered the process fails with the error : "Sorry, but we're having trouble signing you in" message with the AADSTS650056 error. I've found a few suggestions here on JamfNation, but they haven't resolved the issue. SSO Azure AD - Misconfigured application Cloud Identity providers has been set up and tested successfully redid the MS Application set up ensured: Jamf Pro > Settings > System > Single Sign On > Enable Singl
IS there an ETA on the USA hosted outage. I’m unable to apply settings or enroll a single device.
This one is for all of those wanting to issue the .p12 certificate to computers via Jamf Pro for Google LDAP Authentication with Jamf Connect. I've recently performed an integration for a customer with Jamf Connect and their G-Suite tenant following the article provided here: https://learn.jamf.com/bundle/jamf-connect-documentation-current/page/Integrating_with_Google_Identity.html and found that when attempting to issue the certificate via a configuration profile, I would get the error "the certificate could not be verified (authentication error)" I ended up going down a long rabbit hole of troubleshooting that ended with having me attempt to install the certificate manually, which lead me to find that the password I created wasn't being accepted within keychain access.This lead me to the following article going over an open issue with OpenSSL 3.x and it's deciphering issues:https://stackoverflow.com/questions/70431528/mac-verification-failed-during-pkcs12-import-w
Hi All, Does anybody know how to default the edge browser and also add bookmarks within Jamf Pro? Thanks in advance
Hi All, Does anyone know how to remove the configuration profile for the passcode policy deployed during prestage enrollment? In Prestage Enrollment settings, we have set the Passcode requirement, and now we want to deploy a new requirement, but I can't see the option to remove the existing profile. Thank you all in advance.
I noticed that there are 2 Managed Local Administrator Accounts listed in the Inventory > General page of our computers. All our computers and devices are all under Apple School Manager and are automatically enrolled via PreStage Enrollment (so I am thinking that User-Initiated Enrollment never happens for us). My questions are: 1. Under Settings > Global > User-initiated enrollment > Computers, do we need to check the box for "Enable user-initiated enrollment for computers"? And if yes, do we need to check the box for "Create managed local administrator account" (everything else is unchecked) given that each PreStage Enrollment also creates a managed local administrator account? 2. Under Settings > Global > User-initiated enrollment > Devices, do we need to check the box for "Enable for institutionally owned devices" (everything else is unchecked)? 3. If we disable User-Initiated Enrollment, will the currently enrolled devices be affected?
How do I toggle this feature off or prevent it from being toggled on? I went to reset the users password via Recovery Setup Options, user had logged into personal Apple ID when MacBook was issued but didn't remember the password. FileVault is enabled an we escrow those PRK's, but it wasn't until after the user reset their Apple ID password and logged in with it on the recovery side before the system would even allow me to put in the escrow'd PRK. We don't manage Apple IDs, I really don't see the point in them if they can't purchase anything through them. Yes I've had a VPP setup for yrs, but there are those few who like to connect their watches and such. Any advice would be welcomed.VickiH
We want to block Apple Intelligence while not signed in to ChatGPT, but allow it to be linked to ChatGPT with a specific workspace ID. This is because we recognize that Apple Intelligence while not linked to ChatGPT is a learning target. Do you know anything about this control?I know that sign-in can be managed by specifying a workspace id.
Hi everyone, I'm starting to deploy some Mac Mini for a school, although they don't have any LDAP or Federation, they want to deploy Mac mini with Jamf School for a Lab. No problem for that, I've made the DEP profile, started every mac, and create several standard account in them. The problem is when I want to add some restriction to this mac, I would like to know if there are any possibilities that the restrictions only apply to the Standard account, not the Admin account. Because Standard accounts are the student's account, and we don't want them to have access to some functionality of the mac. Thanks for your help and sorry if this question seems to be too Noob style. Ben
Does anyone have an EA that will bring into inventory those applications that have been authorized in Location Services?
Hi, I am looking for a Universal Version of aria2c that I can deploy as PKG to the Mac Clients. On Brew I found Version 1.37 which seems to be the latest Universal Build? We do not want to have Brew on every Client. Is there a way to create a PKG of the local installed aria2 from Brew and to distribute it to other Mac Clients who do not of Brew installed? Thanks!
This time, looking for a job was a bit different. In the past when you looked, there always seemed to be a few options out there you could choose from. At the very least, a list you could rank and go after a few based on priority. These days it seems you may still see what appear to be quite a few options out there, but unfortunately the times they are a changing as the saying goes. I don't want to sound dire, but between new factors that have chipped away at what you see and what you actually get. It's quite a bit more difficult out there right now. Because of that, I wanted to jot a few things down to see if I could help about my recent experience. So whether you're in the midst of your job search or about to embark on that journey, here are some observations that I think could help. Things aren’t totally what they appear to be. Between AI being tier zero to any job applicant, and the fact that companies are posting ghost jobs just to compile data, my first takeaway from that
When making a script available in the Self Service app and the user runs the script.Where is it stored and how long will it be stored there? I see packages in the /Library/Application Support/JAMF/Receipts folder, but no scripts are there are stored there
Hi, I am trying to find all installed Apps from the Mac App Store which have not been purchased through the VPP/Self Service. This is what I got with the help of an older Script from Craig Lindsey #!/bin/bash # JAMF Extension Attribute that finds any MAS apps # that were NOT purchased through VPP # Based on Script from: Craig Lindsey for Starz 2017-2-10 checkMD=$(mdfind -onlyin /Applications/ 'kMDItemAppStoreReceiptIsVPPLicensed == "0"') #echo "### checkMD - $checkMD" if [ "$checkMD" = "" ] then echo "<result>Not Found</result>" exit 0 fi result="" mdfind -onlyin /Applications/ 'kMDItemAppStoreReceiptIsVPPLicensed == "0"' | while read VPPApp do AppName=$( echo "$VPPApp" | awk -F'/' '{print $NF}' | sed -e 's/^"//' -e 's/"$//') result+="$AppName" echo "### Result - $result" done echo -e "### Result-TEST - $result" #echo -e "<result>$result</result>" exit 0 And this is the Result I get ### Result - Push Diagnostics.app ### Result - Push
Hello, I am currently having an issue with installing Symantec on any MAC device (does not matter the OS). When running the policy, I get an error message: Installing SEPRemote v.14.3.5055.3000.pkg... Installation failed. The installer reported: installer: Package name is SEPRemote v.14.3.5055.3000installer: Installing at base path / installer: The install failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurred while running scripts from the package “SEPRemote v.14.3.5055.3000.pkg”.) I assume this has something to do with the package but this just happened out of no where so I am confused on what the issue on/ where to get a new package. Any ideas?
Have issue for client when they have been auto logout after Apple set default 3 minutes. Please note that I am saying User Logout but in fact the setting is "Start Screen Saver after". Option to change that is greyed out, there is no policy set for that specific setting (at the start of the issue). There are set settings in Computers - Configuration Profiles - Login items - Logon Banner where two options are available: "Log out user after" and "Start Screen Saver after". When setting specific time for first option - it doesn't change anything - users still are being logout after 3 minutes. If value is set to 0 or disabled - the same result - 3min. defaults is still active. If setting for "Start screen saver" is set up to specific time - that will change logout time to that specific time. But it will change back to 3 min. at random restarts. So you can restart once, it will stay 35 min., restart one more time - it will suddenly go back to 3 min.
Hello, I have a question and a couple of request: 1. If I run a script with API credentials on students' machines, is there a way students can find or check the credentials? 2. I want a working script which will prompt to select a static group and after selecting it, the computer should be automatically added to that particular static group. I have tried many scripts and for some reason its not working. I gave up and decided to get help from this awesome place. I am pretty sure many would have done this and will have a working script. Thanks.
Hey Everyone, I’m still getting used to Jamf Pro and wanted to ask—what’s the most efficient way to handle app updates across multiple Macs? Is there a built-in method for automating third-party app updates, or are most admins using third-party tools or scripts for that? Also, how do you handle update notifications for users? Just trying to streamline our update process without too much manual effort. Thanks For Any Suggestions!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!