Get Support
Recently active
Hopefully someone can help. i am wondering if the below scenario is possible. We are wanting to push a users calendar, lets call them Person A to another users mobile device, lets call them Person B but im getting errors when we try to do this. I have tried setting this up in JAMF config profile, with Exchange Active Sync. however when Person B authenticates with their details, instead of loading Person A's calendar it loads Person B. JAMF support advised that this is 'Normal Behaviour' and we should share it through O365. while that is possible, we want a the phone to be setup prior to them receiving it and have this setup in the native calendar app, but also want Person B to not be able to view Person A emails. We need this greyed out which the config profile you can do as you can select to only show Calendar. Hope this makes sense, i can attach screen shots if needed.
Hi, we have some trouble with the latest Microsoft Teams Version which came via MAU. Starting with Version 25007.207.3396.1311 the Apps quits randomly after 20 - 30 minutes of use. We are back to Version 25007.203.3361.6689 which works fine. As a temporary workaround I distributed a CP which stops MAU ... All Apple Mac Silicon Clients run on the latest macOS 15.x, we use Tools like Sentinel One and Rapid7. Any ideas? Thanks
Hi, Is it possible to block access to the Apple Shortcuts Widget? I have added the App to the Blocklisted applcations but it can still be viewed via Widgets. Strangely, I also blocklisted the Apple Podcasts & TV apps and it removed them from being viewed in Widgets. Any help gratefully appreciated. Phill
Hey all! Back with another script that I wrote for necessity sake. Since JAMF v10.36 we can issue a "Self heal" command for whenever we get the dreaded "Device Signature error?" at the JAMF command in terminal. This script was built on the concepts by @snelson and Emily Kausalik, but I just wanted to put a nice end user interface to it. As long as the system does check into JAMF, you can issue the command to self heal. If it is not checking into JAMF, a desk side visit is probably in order... Source here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/JAMFBinaryRedeploy Screenshots for the script Information collection screen Confirmation dialog Process finished
Hello All I am trying to Uninstall Zscaler i have script but for Uninstallation it is asking me password as below:Anyone have workaround for this?Note: It is not accepting user account password
If I have multiple configuration profiles made by different techs and as an example: profile 1 - allows iMessage and profile 2 does NOT allow iMessage, which profile wins? Is iMessage allowed or not?
Today we released Jamf Connect 2.45.0; this release includes minor bug fixes and improvements. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
It looks like the Apple large clock is suddenly appearing on the login screen, blocking the local login and shutdown buttons. I’ve already tried disabling the large clock setting in System Preferences, but it’s still showing. Additionally, there doesn’t seem to be an option to hide it using the plist.
We noticed that the recent MacOS Sequoia update really messed with our users ability to print. To cover what has been happening with us, when a user adds a printer from Self Service, the very first print job never brings up the window for them to enter their credentials. Instead just sitting on "Hold for Authentication". Hitting that little refresh button doesn't do anything, and most of the old fixes I found online don't seem to help. Once the user cancels that job, then sends it again, the pop-up happens and everything is good to go from that point on. So, as a temporary workaround until we can find the actual issue we came up with this little script to send a 'dummy' print job, wait a few seconds to hit the authentication, then cancel the job. So far this has been working great so I wanted to post that script here just in case someone else can make use of it. Note: Is it just me or is there no Shell/Bash option when pasting code here? #!/bin/bash # Get pr
Hey guys, Quick question here. I'm using Jamf Pro to help manage 3 computers labs. The boss has decided to add Staff to it too now. What is the best way to manage your Policies and Configuration Profiles for different environments? For example I have a CP for Login Window. There is a Banner that says welcome to the students. In Options I also have it set to Log out users after 30 mins. If I want another Login Window CP with different settings do you guys just specify in General in the Name of the CP? Just curious, thanks!
Anybody else getting double logins this past week in JS? My instance url takes me to a Jamf ID login but instead of SSO it takes me to the Jamf School login where I have to sign in again. Not a cookie issue as it happens in Chrome, Safari and other Macs and iPads. Just wanted to check my sanity before going to support.
I've seen this a couple of times now where a device claims that a Managed Software Update plan has "succeeded" but the device has not actually been updated. Most recent is a device set to go from 14.7.2 -> 14.7.3. It is still on 14.7.2 but the plan says it succeeded and there are no pending plans. Operating System History says: 14.7.3 Download, install, and restart Success 03/03/2025 at 2:11 AM Details: Install action:Download, install, and restart Update action:Specific version (14.7.3) Current state:PlanCompleted Error reasons: Deferrals:N/A Previous notifications sent:N/A Last event in the store: "type" : ".VerificationResultEvent", "managementUUID" : "fa6332eb-f266-46f9-b476-82478fac0f4c", "processManagerUUID" : "f3a47dd9-42d9-4117-bccf-83ec73181ed8", "id" : 248580, "deviceObjectId" : 1, "eventReceivedEpoch" : 1740985898532 Not sure how it verified as done if the OS has not in fact been updated.
Hi, Does Jamf School support this feature from Apple School manager please?
Anyone else seeing a problem where the Edit option isn't available for posts you've made? I've now seen it on multiple posts I've made in the past couple of days and I'm wondering if I have company.
Morning We have few Macs which have failed escrow there FileVault key back to Jamf. I have setup escrowbuddy and this seems to be working well bringing these keys back.I can see the policy has run to setup escrow buddy the policy also inculdes defaults write /Library/Preferences/com.netflix.Escrow-Buddy.plist GenerateNewKey -bool trueI can see users have had a fresh login.While machines now do seem to have a vaild FileVault key. I'm seeing two issues. FileVault 2 Enabled being switch from enabled to Not enabled. FileVault 2 Enabled set as Not enabled.This depsite the fact that the effected machines have a vaild Key, showing as encrypted and have a FileVault 2 enabled user.As anyone else seen this behaviour before?Thanks Thanks
When I deploy the CIS L1 baseline via JCE I'm having an issue with the following: 9.16. Configure Login Window to Show A Custom Message. When I change the default text from "Center for Internet Security Test Message" to anything else, I get a compliance failure. How do I change this message to something more relevant without it flagging up as a compliance fail?
Hello all I love how the MacApp updates so effortlessly assist in keeping our user's applications upgraded and I am very thankful for the assistance. It is a huge assistance in meeting our patching requirements. I am curious though how others are managing the false positive completions reported by MacApp though. Usually I pick these up through other policies but it is not unusual for JAMF's MacApp to provide patches that the manufacturer have not yet made available through other channels leaving us no other method to pick up the pieces. A couple examples I'm currently working with. As of March 4, MacApp is currently upgrading Adobe InCopy 2025 and Adobe InDesign 2025 to version 20.2.0.36 but both Adobe's Admin Console and Adobe Remote Update Manager only have patches through 20.1.0.71 so the 20.2.0.36 is only available through MacApp. At the same time, MacApps shows that it has successfully updated 30 of 33 Adobe InCopy 2025 and 29 of 35 Adobe InDesign 2025 users to the new version yet
I’ve noticed that when using JAMF LAPS, it correctly rotates local administrator passwords as expected. However, I’ve encountered an issue where the secure token becomes corrupt, typically when attempting to perform a software update. From what I can tell, this happens when JAMF LAPS rotates the password. Could you confirm whether the secure token is updated when the password is changed? Additionally, I used to find JAMF highly customisable with scopes and smart groups, but I’ve noticed that JAMF LAPS applies universally without an option to exclude specific devices. I wish there was a way to adjust this.
I've noticed recently that a number of our brand new deploy machines are getting their bootstrap token escrowed properly but when the user logs on for the first time, they're not getting a secure token -- meaning we have to then manually grant a secure token using a known account which has one. Any ideas why JAMF isn't issuing secure tokens to new users?
We run a clustered on premise environment. One JSS internal, one JSS in the DMZ behind a reverse proxy. I've never loved that even though you turn off the UI on the DMZ instance that www.myjss.com/api is still exposed as a UI. We do restrict what users have access to the API but I still don't like it being exposed so I tried blocking it in the reverse proxy. After doing this, I noticed that it broke the sync with VPP. I removed the /api block in the reverse proxy and the purchased apps immediately came down. I went and checked the reverse proxy logs thinking that I'd have an error logged every time the sync monitor ran. I found no such errors. The only thing i found in the logs related to /api was an errors with remote users and the self service branding icon not being passed down. Anybody else have any insight into why blocking /api breaks VPP sync and also why there would be no errors logged in the reverse proxy?
I saw a couple of articles online to install Cisco Secure Client via jamf. However it was mostly for VPN and umbrella and when taking dmg from xdr into composer it proved to be less then helpful. No matter what it did not like to be manipulated. I have created a deployment script using full installer dmg for anyone that runs into this who also is using Cisco XDR. I am open to suggestions on the script but this got the job done and cleanly. Make sure you setup a configuration profile for background processes. First thing is go in to Cisco XDR download both Full installers for AMD and ARM. Then upload the DMG files in to Jamf Next Create the Script using this bash script. It uses the jamf waitingroom cache applications. #!/bin/bash # Author: Ryan Tarson # Cisco Secure Client DMG Installer Script for Jamf (Flexible for Both Architectures) # # This script installs Cisco Secure Client for macOS using a pre-deploy DMG that # contains a single package: # com.cisco.secureclient.cloudmanage
How do I get passed the Activatiion Lock with a teacher has their Apple ID logged and Find My turned on. We run into this more than I would like to admit. We are trying to make sure they have it turned off before we take the device because they are no longer going to be with the school or it is broken and Find My needs to be turned off so it can be repaired.How do we get passed this without asking the person to come back in, remove the device from their iCould account, or ask them if they would be ok with giving us their password so we can get the device activated. I had to contact a person that had moved to Austrailia. Luckily they trusted me with their password and I was able to get the device activated. Any help would be great. Thanks for your time in advance.
Since the recent update to Version 11.14.1, I've noticed that policy logs are no longer visible. Is anyone else experiencing the same issue, or am I the only one facing this? Let me know.
To configure zoom for deployment with an MDM Zoom recommends putting us.zoom.config.plist into the /Library/Managed Preferences folder. i have been doing this with DepolyNotify using a policy with a package to put the file in the folder with no issues. I am now trying to replicate this with Setup manger. The policy runs during setup manager and says it installed (also Jamf logs shows this) but the file is not there. I also tried a policy with a script to create this file, it also said it succeeded but the file was not there.Does /Library/Managed Preferences refresh its self or something when a user first logs in?
Looking to see if anyone has created a Configuration Profile that will gray out the "Download iOS Updates" and Install iOS Updates" within the Automatic Update section. I do not want end-users to turn off the feature. As admins the plan is to have another configuration profile created to defer iOS updates for 14 days to confirm testing of a new update. We currently have that in place.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!