Get Support
Recently active
Hey all, I've been stuck on this for quite a few weeks. Our JSS servers were moved from one location to another. Since then we've had to redo numerous things. The last being TomCat. The boxes used to be behind a load balancer, now they are not. Anytime we navigate to our jss site, it says it is not secure over https and another issue is any policies with packages trying to push, fail due to it not being secure and not being able to make the connection. If I go into TomCat and "Change the SSL certificate used for HTTPS" -> Next -> I've tried "Generate a certificate from the JSS's built-in CA. Restarted the box. No different " Same steps as above, only this time, "Upload an existing SSL Certificate" -> our network guy pulled the cert we use for other servers. Anytime I try to upload, the second part where it asks for the password, it does not go through. This password works on everything else. Tried redownloading it from the s
This script works fine as an EA on 80% of our Mac's but returns Blank on the rest. The APP is thereAnd it we run this manually on the Mac it returns a result, but as an EA we get a blank.If it didnt work on all our Mac's I'd understand I'd made a mistake, but its only a handful, any ideas ? #!/bin/bash ZScalerVersion=$(defaults read /Applications/Zscaler/Zscaler.app/Contents/Info.plist CFBundleShortVersionString) /bin/echo "<result>$ZScalerVersion</result>" Thanks
Hello Jamf Nation! Our Jamf Nation vendor will be putting Jamf Nation into read-only mode in the evening of Monday March 3rd through Tuesday 3/4. During this time individuals will not be able to sign into the platform or make new contributions to the site. Sorry for any confusion, and thanks for your support as we work to continuously improve Jamf Nation!
We were using Jamf Connect with Azure/Entra for about a year without issue, it's only used on a small number of clients and I'm unsure how often the computers are actually used, but at the moment none permit authentication. I've trimmed down the config to the barebones, and even recreated the app registration in Entra without any change. Any user attempting to sign in sees Invalid Response Code 401 from https://login.microsoftonline.com and it gets no further. The original working plist for jamf.connect.login included, the following, but has been well trimmed down to just app registration IDs and secrets without any change. <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>AllowNetworkSelection</key><true/><key>BackgroundImage</key><string>/usr/local/share/jc.jpg</string><key>CreateAdminUse
Hi, I am trying to get a config to block all chrome extensions and allow only approved ones as I keep finding.I found some examples online but I am not too familiar how to proceed, I know the way to setup is in Configuration Profile and Custom Settings, but I don't know the exact way to set that up. here is an example I found but can someone show me how to implement it. thanks <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>DeveloperToolsDisabled</key> <false/> <key>ExtensionInstallBlacklist</key> <array> <string>*</string> </array> <key>ExtensionInstallWhitelist</key> <array> <!--Docs--> <string>aohghmighlieiainnegkcijnfilokake</string> <!--sheets--> <string>felcaaldnbdncclmgdcncolpebgiejap</string> <!--slides--></arra
We have a scenario I wasn't expecting. So basically we are eliminating JAMF and going with InTune. Know not a new story. However as this was never expected, all BYO devices have "our" apps set to remove on unenroll and were installed thru VPP. This is going to cause a lot of issues as the individuals aren't leaving but being asked to unenroll and then enroll in a different MDM. If we set the apps to not uninstall when unenroll, what would happen? So the apps I guess stay behind but... 1. Will they keep working? 2. If they keep working will they stop eventually? 3. Will they be able to get app updates? 4. Will the apps magically get tied to their own iTunes account? 5. Depending on above, if a user goes into their Apple App Store and installs the app while already on the device what will happen? Thanks. JR
Hello, We need to have ways to troubleshoot SSO connections. It is activated on my beta instance since it's available. I log in though SSO, yet, Compliance Benchmarks or Blueprints tell me I need to log in through SSO... This is not only annoying, there is absolutely no way or log to understand why this happens. I can only imagine issues when this rolls out at scale. Who should I talk with to troubleshoot ?
I am trying to figure out a way i can use the profile command to remove a user profile that was installed by JAMF. The profile is used to add a AD generated user cert to connect systems to our . WiFi. For various reasons this cert breaks or gets removed. I was hoping to build something in self service user can use to remove the profile and re-add it forcing a new user cert to be generrated. But im having zero luck i get a profile not found error using sudo profiles -R -p "profiles ID" Error:profiles remove for identifier:'Profile ID' and user:'Username' returned -205 (Unable to locate configuration profile.)
Hi team, Let me ask question for webfilter on port 8080. I set localhost for wihte list on restrictions profile with Jamf administrator role like that, however, when I access http://localhost:8080/ I cannot browse the website, which returned error screen. White list for browser <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>URLAllowlist</key> <array> <string>chrome://*</string> <string>localhost</string> ← here! I checked process for port 8080 and there are some unknown webfilter processes besides java process which I would like to use. (Actually I tried to use Jenkis using localhost:8080 but couldn't....) # sudo lsof -P -i:8080webfilter 97579 root 74u IPv6 0x3f2d9709054bb09e 0t0 TCP localhost:58811->localhost:8080 (CLOS
Hi All,GreetingsI am looking to set custom screensaver (Only 1 static image) in around 20 Macbooks enrolled in JAMF, I tried all the steps but nothing works so far.We have machines with Sonoma, Monterey, Catalina, and BigSur.
Hey, since last week we can not remove the Restriction Software settings from Mac Clients. We run Jamf Pro Version 11.13, most Clients are on macOS 15.3.1 Removing Clients from the Scope does not remove the Restriction Setting from the Clients. New Clients enrolled to the Site formerly in Scope of the Restriction get the Restriction Setting ... Should I delete the Restriction Rule to remove it from the Clients? Thanks in advance!
HiI can't find any documentation on the new "Autonomous Single App Mode apps" restriction in the iOS Profiles. Can someone explain me what it does? Thanks in advance!
Basically the title, does pushing the same config profile with different settings applied cause conflicts? Here is a very specific example: Security and Privacy One profile has the firewall turned on and another has the firewall off (not checked). Basically, which wins? Do they fight? We had some weird behavior happen when pushing the same payload multiple times with different settings. Any advise or guidance is appreciated.
We are using Jamf Pro and need a way to restrict students from changing the Wifi settings on iOS devices such as iPads. I have looked through all configuration profile settings/restrictions and do not see any that would achieve this result. Does anyone have a script or know how to accomplish this? Any help would be appreciated.
I was prompted about being able to enable the Apps Inventory (Beta) this morning. I activated it. There's a seperate option to use the current or beta version after that. It seems to be similar to the current Inventory page. It promised that the new appearance woudl be faster. That aside it doesn't seem to have any functionality. When I select apps I can't take any action. Beta: Current: Am I missing something? I did try in Firefox and Google Chrome.
I have a 2019 iMac running Sequoia that keeps losing the Jamf Connect (2.44) window at login. We use the "authchanger -reset -jamfconnect" command to fix it and it works when we log out after fixing it. But when we reboot, it goes right back to this. I have photos of the output from "authchanger -print" if anyone can interpret them. Thanks!
Well, the idea of Jamf Remote was wonderful... it's not reliable in any manner. We have a number of small businesses we support. Teamviewer is for our enterprise clients but the cost is a bit much for many SMBs. What do you use for your SMB clients when you have to balance cost vs features? I know the options, just looking to see why you use what you do [Jamf shop for most clients. ] Zoho Assist? Tailscale with Screen Sharing? Anydesk? Splashtop? LogMeIn?
We're excited to announce a powerful new feature in Jamf Security Cloud that enhances your organization's security posture through advanced vulnerability management capabilities. This new functionality enables real-time visibility into Apple device vulnerabilities and streamlines your security operations.Key Features and Benefits Comprehensive CVE Monitoring: Track both system and application vulnerabilities across your Apple device fleet Real-time SIEM Integration: Stream vulnerability data directly to your preferred SIEM solution Enhanced Security Visibility: Gain deeper insights into your security landscape through consolidated vulnerability reporting Automated Response Capabilities: Enable faster threat detection and streamlined remediation workflows Supported PlatformsThe vulnerability data stream integrates seamlessly with leading SIEM platforms, including: Microsoft Sentinel Splunk Datadog Google Security Operations Easy SetupGetting started with vulnerability data streaming
We have been trying to manually enroll few Macs and since last week, we are getting the attached error message. These Mac were enrolled to a different JAMF server, and we remove the old profiles before starting our own enrollment process. We are not facing any issues while manually enrolling any other devices apart from those specific ones. I have confirmed that MDM certificate and all profiles are fine. Any idea what might be causing this? Thanks
I have a smart group with users that have not shutdown/restarted over 30+ days. (one user 467 days) What kind of policy can I do to force a reboot, I've noticed some things have changed in Jamf Pro. A reboot with a timer and message?
Hi All,Any else having issues with setting up manage login items for Xerox Workplace Cloud Client..I have added the TEAMID but still getting the prompt when installed on Ventura..Here is what i have...Rob
TLDR: If Jamf Connect's password countdown isn't updating or Kerberos tickets aren't being received, turn off iCloud+ Private Relay. We recently solved a puzzling issue affecting a small number of users. After password changes, their Jamf Connect Menu Bar wouldn't refresh the expiration countdown (even showing negative numbers) and they weren't receiving Kerberos tickets, despite the new passwords working correctly in Entra and AD. After hours of investigation - trying different Jamf Connect versions, reinstalls, profile changes, and terminal commands like klist and kinit - we discovered the culprit: iCloud Private Relay was rerouting traffic, preventing proper domain resolution needed for Kerberos tickets. The simple fix: turn off iCloud Private Relay and restart Jamf Connect. Both issues resolved instantly!
Can we enable an button for user to view the password when login ?
I am working on deploying Platform SSO using Microsoft Entra ID. I have followed the steps outlined here: https://learn.jamf.com/en-US/bundle/technical-articles/page/Platform_SSO_for_Microsoft_Entra_ID.html#concept-7900 This seems to be working really well. I created a guide for my users to educate them about the steps that are needed to get registered to use Platform SSO. My current SSO implementation uses Kerberos. The URLS for our current SSO are our internal AD servers that also sync with Entra ID. When it is time for users to reset their password (90 days), they are notified 2 weeks in advance and notified again later. When they are ready to change their password, they can do so using the menubar icon. We are also syncing the user's local Mac password with their AD account password. When the user changes their AD password, the local Mac password is also changed to match. It's a very simple process to follow. I have been trying to find out what the user experience is for
Is there a way to configure TvOS to update automatically? I looked in the configuration profiles and I'm not seeing it.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!