Get Support
Recently active
Hello All, Hopefully this is the correct place to post this, but I need a helping hand. What are the management capabilities that are lost when using User-Initiated Enrollment as opposed to using Device Enrollment through Apple Configurator? I am implementing Jamf into our organization and we already have a number of Mac computers in circulation, and wiping these devices to enroll them may not be feasible. Any and all help is appreciated. Thanks! I have only been able to find one article covering this, but it does not list everything. https://learn.jamf.com/bundle/jamf-now-documentation/page/Supervision.html
I'm trying to create a Configuration Profile to change the screensaver from Flurry to Classic slide show. I have an option set in the Login Window to use the /System/Library/Screen Savers/Classic.saver for the Screen Saver module, but it doesn't seem to work and it stays at Flurry. Ideas or suggestions would be greatly appreciated. Thanks,Richard Eppert
I couldn't find record of the new bundle identifiers posted anywhere so I thought I'd share my findings for anyone who may need these for hiding some of the new built-in apps via the "Do Not Allow Some Apps" restriction or with the "Home Screen Layout" payload.Not all of the built-in apps currently auto-populate in Jamf Pro when typing the app name. All you need to do to use an item from this list is type the name of the app as you'd like to see it in "App Name," scroll down and choose "YOUR_APP_NAME +" in blue from the bottom of the search results, and paste the new bundle ID in.iOS & iPadOS 12-16App Name | Bundle ID Activity | com.apple.Fitness App Store | com.apple.AppStore Apple Store | com.apple.store.Jolly Apple Support | com.apple.supportapp Arcade | com.apple.Arcade Books | com.apple.iBooks Calculator | com.apple.calculator Calendar
I'm fairly sure this isnt possible but not able to find any documentation backing it up. Is it possible to block the phone app on iPhones? We have no cellular service and I have tried sending a "some apps not allowed" config blocking the phone. But the device remains able to call 911 services. Can the phone app be completely disabled and blocked?
Almost a year ago we implemented 802.1x wifi authentication NOT using Active Directory certs. The certificates all issue properly and work just fine with our WiFi authentication.After we deployed the profiles and issued certs, I made sure this was set:sudo defaults write /Library/Preferences/com.apple.mdmclient AutoRenewCertificatesEnabled -bool YESNow that we are approaching the 1 year expiration of some of the first Macs to test this, we are expecting their certs to automatically renew, but they are not. I have a Mac with a computer cert expiration of Feb 9 - well within the default 14 day window for renewing - but it isn't renewing. Keychain Access still indicates that it expires Feb 9. There are no duplicate certs that would indicate a renewal. The Profiles system preferences does not have a renew or update button for the 802.1x profile. Here is what happens when I try to renew it manually with the profiles command:profiles -verbose renew -type configuration -identifier CORRECT-PRO
Hi all! recently arrived to Apple management and I've got a task pending to fix: to setup two environment variables necessary for one GUI application.I can setup them over a plist file stored in /Library/LaunchAgents, but same plist file doesn't work loading it as a Configuration Profile from Jamf Pro. If I look for loaded profiles, it appears from Jamf as well as from terminal typing 'profiles list -all', but it doesn't work. Other plist files launched from Jamf are working properly but no for setting environment variables.Could someone to assist on this?Thanks a lot in advance
Hello all,I noticed today that I can no longer send MDM commands to a specific device. These commands are always only on the status "Pending". When I took a closer look, I found out that the MDM profile has already expired a few weeks ago. How can something like this happen? These actually renew themselves 180 days before expiration. Am I wrong? I built a search query for it and saw that this happened to a total of 10 devices. Do any of you have a tip on how I can recapture these devices? I tried a "sudo profiles renew -type enrollment" but this had no success unfortunately. An error 500 came back.
"We've detected a recent WebKit update which may impact Enterprise Single Sign On (SSO) for Microsoft 365 services" - MicrosoftI think we are running into an issue related to this and wondering if others are as well. We have iphones setup as shared devices using jamf setup and jamf reset. We do a soft reset between users since you still have to register the device between full resets (unless someone has a way to skip that requirement) When a user resets it is keeping the prior login active on Epic rover. Before it was clearing the token, but we are seeing sessions remaining I think on iOS 17 devices.
Hi all I created an override how make I Autopkgr to recognize it so it starts working Now the jssimporter is deprecated I can't get packages to upload to Jamf, for instance the AmazoncorettoAppleSiliconJDK21 Downloading works but how can I get it uploaded Any help is very much appreciated
I've read that Google Identity supports OIDC - but does anyone know for sure whether a business could use GI for free to utilize Jamf Connect?
Hi, I appreciate if anyone can share a script that can delete the computer from which the script is executed from the JamfPro (onprem server). It would be great if the script can delete the computer getting the computer ID or computer name and check with Jamf and delete if available and then remove all the profiles including the CA certificate, basically remove the framework. Thanks in advance.
Hi, We took our labs to Sequoia over the Christmas break and have seen an issue whereby the `audiomxd` process sits using 100% CPU on the computers preventing anyone from logging in and rendering the machines unusable. We've had mixed success with flattening the machines, it seemed to fix some and on others the problem has reoccured. The main room this has affected are iMac19,2 machines (2019 Intel iMacs, observed by me) but we have also seen this on a handful of M1 iMacs (I wasn't able to verify this myself so possible red herring). Has anyone else observed this? I'm at a bit of a loss as to what might be causing it, I think the process is part of Core Audio but we don't do anything weird in terms of audio setup really, there are no peripherals on the machines and nobody logged in. The only audio related software that gets installed is Audacity and Adobe Audition as part of CC. As this happens at the login window following a reboot there are no user processes running anyway. My t
Dear Jamf experts,I need your support to get my on-prem Jamf Pro infrastructure correctly setup.I have Two windows 2022 server installed with Tomcat web app for Jamf Pro as a child node ( cluster ) behind load balancer and one Server with Jamf Pro and Jamf database as a primary server (Tomcat & MySQL ) and one more windows server which has Jamf Pro Database ( mySQL). All three servers are in cluster with memcached installed on ubuntu. On load balancer we have placed child node behind that and I have used public trusted SSL on load balancer to offload encrypted traffic, I have used publicly resolvable DNS name on load balancer ( like mdm.public.com ) but I have used diffenrent Jamf Pro Url on Jamf Pro setting under global setting like (mdm.private.com). and used Jamf Pro CA signed SSL for Primary server with CN Name mdm.private.com My issues are two.1- I am not able to enroll any device no matter I am in public network or private network2- I am not able to login in Jamf Pro co
Hi All Is there a way that once you have provided the 'purchasing' details of hardware that it can stay linked or associated to that serial number of that device? I've noticed that when a laptop is formatted and assigned to a new user or even the old user that the purchasing information must be filled in again. We use this record to store and report on for when laptops are due an upgrade and or when the lease expires, but only recently discovered that the information doesn’t remain when its formatted. Ideas or Thoughts? I’ve attached a screenshot Jamf Pro: 11.15.2
Managing Labs devices in a university environment. Looking at ways to provide remote support and access devices when I am working offsite. Does Jamf Remote Assist work? I think I have everything configured correctly, but thus far haven't been able to establish a connection to any devices. Before I go to our cyber/infrastructure team to troubleshoot, does anyone use JRA, and is it stable enough to rely upon as the sole Remote Access system?
hey Nation, has any one seen a change with log predicates streaming to splunk since updating to macOS Sequioa? Our SIEM team is seeing all Data but nothing related to logd or log predicate events, even though it is configured. Any agent updates that anyone remember? we are on 9.3.4 Tia
Hey all, I recently deployed an app through JAMF (an App Store app) and want to prevent it from updating. The app is still available in Self-Service, but I've learned that it updates when users click the "Re-install" button in the Self-Service Store. I've double-checked the settings and confirmed that both the "Schedule Jamf Pro to automatically check the App Store for app updates" and "Automatically force app updates" options are disabled. Can you advise how I can prevent this app from updating if a user attempts to re-install it via the Self-Service Store?
Hey All,Starting a few days ago I was alerted to a communications error from our Jamf Infrastructure Manager instance. It's been working fine for quite a while (years), and is running JIM 2.4.0 (Windows 2019 server, Java 11.17.x)The JIM Log files clearly show the moment when things went awry April 1 @ 10:06:42, but no indicators as the nature of the issue. I haven't yet found anything relevant in the Windows server logs.2023-04-01 10:05:52,672 INFO c.j.i.l.LpsTransferThread [JSS->LDAP for [/54.208.14.206:8869](2803)] Transfer thread started2023-04-01 10:05:52,672 INFO c.j.i.l.LpsTransferThread [LDAP->JSS for [/54.208.14.206:8869](2803)] Transfer thread started2023-04-01 10:05:52,809 INFO c.j.i.l.LpsTransferThread [JSS->LDAP for [/54.208.14.206:8869](2803)] Input Socket (JSS), end-of-stream2023-04-01 10:05:52,809 INFO c.j.i.l.LpsProxyConnection [JSS->LDAP for [/54.208.14.206:8869](2803)] Closing Jamf Pro socket2023-04-01 10:05:52,809 INFO c.j.i.l.LpsProxyConnecti
Looking to see if anyone knows about JAMF Pro support for Windows Server 2025. If it doesn't currently support it then when will the expected date that JAMF will support Windows Server 2025.
Hello, Has anyone found a way to configure this using a config profile or script now that the airport command has been deprecated? I'm trying to configure this setting: Thanks! --Josh
We are trying to implement full disk access for Rapid7 on mac with Mac os 15.1 with help of a Jamf Configuration Profile.We followed the exact steps recommended by the software vendor (Rapid7) from the below link https://docs.rapid7.com/insight-agent/mac-installation/#use-an-mdm-for-configuration We have double checked with path of the ir_agent, which is as to be default /opt/rapid7/ir_agent/ir_agent Tried in couple of machines with mac os 15.1 and 14.5, but still we see from the GUI that the ir_agent FDA is not enabled using the toggle button. Can someone suggest how can we get this working or any way to understand why this doesn't work. Any help would be appreciated here. Let us know if you need additional information. Thank you!
A number of years ago Apple changed access to the system.log file (and others) so that only admin level users could read them. In the name of 'security' I'm assuming. We don't allow non-standard users on our devices however, and one of our developers needs to be able to read the affected logs and can't.I've tried editing the sudoers file and adding the user to access /System/Applications/Utilities/Console.app, and using a policy to try and open Console. But Console just complains and doesn't work. I could change the permissions on the effected log files, but that'll be reversed as soon as the OS rotates the logs...Is there a simpler method, or something I'm not thinking of?Allowing the user temporary admin access isn't a solution either unfortunately.
Does anybody know what could be wrong? I don't see Transfer to a work account for one Apple ID account, only Keep as a personal account. I had read https://support.apple.com/en-gb/102159 and checked every option. Once I saw Transfer to a work account, but I was told to update my Mac to the latest OS. After that, I had tried many times without success. It's giving only one option: Keep as a personal account. It wouldn't be a big issue, but the problem is that this Apple ID is used for an APN certificate.
We have profile witch push machine cert and wifi with tls. We need to push this profile very 6 months or year. How can i do it? i can store .mobileconfig on Mac i think but how can i install it via policy?
Experiencing issues with the JAMF Remote Assist feature! It was effective for a few months, but now, I'm unable to access any devices remotely. Even after trying the troubleshooting methods recommended by JAMF Support, the problem persists. I've learned there's an ongoing product issue. Is anyone else encountering similar challenges?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!