Get Support
Recently active
Trying to setup a test student account and have it automatically accept the VPP Invitation which was introduced in the last JSS updated. I'm currently getting this error: Managed Apple ID does not match account The managed apple ID is populated in the student account and I'm logged into the App store with this managed apple ID on the iPad. Not quite sure what this error message means. Any ideas?
Hello folks,how do you deal with Mozilla Firefox and the Auto Updater if the users are not local admins and cannot install the helper tool? is there a way like with google chrome?Cheers
Hey folks! Just wanted to drop by with another bit of info that may be helpful when using the new Self Service+ application on your managed computers. The app leverages macOS unified logging, so to grab logs you'll want to parse the log stream to get app activity. One way to grab these files programmatically (as of version 1.2.0 of the app) is to use the Collect Troubleshooting Info option in the Help menu (or use the hotkeys ⇧ ⌘ L /Shift + Command + L) and the app will generate a zip file and save it wherever you specify. For folks familiar with parsing the unified log on macOS, you can use Terminal to filter the log and look for Self Service+ events. To see events from the last hour would look something like this: log show --info --predicate 'subsystem BEGINSWITH "com.jamf.selfserviceplus"' --last 1h --style compact To stream activity from the app as it's running in real time you'd want to use an elevated log stream command, something like this: sudo lo
Hey, Let me know if this is the wrong area to post in. Essentially we are attempting to disable Siri and its "Listen For" option. Unfortunately it seems we can only disable siri but if "Listen For" was enabled prior to disabling siri it still allows for the pop-ups saying "you dont have permission". We have been able to supress/kill the pop-ups as a temp fix for the time being though we notice the Siri icon in the top right of the menu bar is still there. While you can manually get rid of that icon in the Control Center, We have yet to find much if any information or option to control the control center options and remove that icon through Jamf Pro's Config profiles as of yet. My question is, Is there any way to remove a menu bar icon even if its with like a script or anything or even a way to manage the Control center through jamf just yet?
hi All,Pretty new to JAMF and i would like to know if anyone has a doc I can read on how to add a line to the visudo settings.Right now its a manual process every time i provision a laptop but i would like to script this.I have search and there are so many answers and none officially supported by JAMF. I now just do sudo visudoedit the filewrite/quit and save the file. Any help is appreciated
If you're wanting to create a self service policy object that users can run to execute sudo jamf policy and sudo jamf recon, these are the steps you'll want to take. I haven't seen a clear and concise post on this so I wanted to create one.When creating the Policy, in the General payload, you'll leave all triggers off because you want it to be triggered by Self Service. For the execution frequency, set it to be Ongoing. Then add the Maintenance Payload and hit Configure. This will automatically have the Update Inventory selected. The update inventory essentially does what a “sudo jamf recon” would. Then to also have it force a check-in, go to the Files and Processes payload and under Execute Command you can put in “jamf policy” without the quotes. Lastly, make the policy available in Self Service. This will then ensure a check-in and update inventory will occur when a user selects that button.
Recently I've been trying to extract infos of which extensions our users have on their browsers.I have a script running for our major browsers and it's working great but now I'd like to get more infos that are sealed inside a .json file.Is there a way to extract specific lines from a .json file such as the "manifest.json" you can find in every Chrome extension's folder?Specifically I need only the rows talking about which permission does the extension have as seen below.
I'm not really concerned but I had this popup appear on a few people's screen after a MacOS Update. This is not our normal Jamf Connect login screen and kinda made me question how this came up out of nowhere. Not sure if anyone has seen this type of screen or would know why it would pop up.
Does anyone have any best practice for this? I suspect we'll need to package both the STATA/MC and STATA/IC versions. Thanks for any guidance.
Sorry if a little off topic but I need to change my email address assoicated with this Jamf Nation Community.I have looked everywhere but can't see the option.
Hello All! Looking for some advise from anyone who has had experience with Microsoft Intune for macOS MDM. I feel every organization gets the question, "Why are we paying for Jamf when we could use Intune?" Well that conversation has finally come around at my organization. Everything I am reading and heard from others screams don't drop Jamf Pro for Intune, but looking to get some specific reasons why. Anything that could be shared regarding this would be awesome!
As a system administrator, I am happy to use Jamf Safe Internet with Jamf Pro to manage 1:1 iOS devices in an educational environment. However, we are experiencing a problem with a Jamf Safe Internet policy rule that includes a scheduled content filter. The expected behaviour was that the content should only be blocked during the specified scheduled times.Unfortunately, the content is being blocked as soon as the rule is submitted and continues to be blocked outside the scheduled times. I know that scheduled content filtering is a new feature in the Jamf Safe Internet product. Has anyone else tried this feature and had a similar issue?Any advice or guidance would be greatly appreciated.
We’re using JAMF Connect to manage our logins for our school iMac lab, and we’re having a bit of an issue with students changing passwords. I understand that if their network login is changed, they are prompted to enter their most recent local password to sync them up. The trouble is, students typically only have their network password changed if they forget it, meaning they effectively become locked out of that particular iMac.I was thinking that if I can detect which accounts have mismatched passwords, I could write a script to remove the local profile entirely, and allow the student to log in with their network password again. Does anyone know of a way to detect whether or not an account has a mismatched password via a script? My initial plan was to read PasswordCurrent from the local account’s com.jamf.connect.state plist, but that variable only updates while JAMF Connect is running while the user is logged in.
I was asked last week to think of some practices as a Jamf Admin that I’ve adopted into my environments that have really helped me out. One of the first things that came to mind was organization practices. Organization is key to keeping a clean environment and can help you quickly identify what is being configured and where. I’ve made some notes on how I like to keep my environments organized with naming conventions and will share them below. Naming conventions will help to keep objects organized, reduce confusion, and help optimize our Jamf Pro platform. As additional policies, configuration profiles, packages, groups, etc. get added to the platform, a consistent naming scheme will provide clarity. The name of any object in Jamf Pro should quickly describe what it does or what it’s for. Each object within Jamf Pro should also be tied to an appropriate category. Keep it simple. Static/Smart Computer Groups &
As part of a broader security baseline effort, my org wanted to know how frequently Edge users were signing into multiple user profiles (spoiler: not often). It was then pointed out that being signed into a "work" account may have implications for Edge's ticket broker service and PSSO in general; browser hardening often includes statements to limit or prevent multiple user profiles. Sharing this EA in case its helpful to anyone else. jq was only included by default beginning with macOS Sonoma (14.0), older versions of the OS will need either a third-party jq (or one of you awk-fu experts to fork this and parse the email). #!/bin/bash # This version now iterates through all Edge profiles and reports the profile and # the email address signed in. If Edge has never been used, this will return nothing. # Since jq is now included by default on macOS we can use that more effectively # then trying to parse the JSON with awk. # Setting IFS Env to only use new lines as fie
Hello all,First-time poster on Jamf Nation, so please criticize formatting, grammar, etc.We use Bomgar Remote Support on our Macs, but when deploying to a test machine running Sequoia, I get the message "Allow Remote Support Customer Client to find devices on local networks?" It looks like a PPPC popup with options to "Don't Allow" or "Allow", but I can't find a corresponding PPPC setting. We already have Accessibility, SystemPolicyAllFiles, and ScreenCapture set up according to this deployment guide, and I don't see another PPPC option that looks related to this error message. I'm not even sure why this is a permission that needs to be allowed. It feels like the Windows message to "allow this device to be discoverable on local networks," but it's going the opposite way. Why would I need permission to go out on the network and connect to the Bomgar server from my endpoint? Has anyone else seen this popup before or something similar?
All of the installers that are published in App installers have always gone through a validation and testing process before a new version is published to the service however this process has now been strengthened further with our recent integration with the Jamf Threat Labs Malware Threat Database. This recent integration provides even further validation of a particular version of a software by scanning it for signs of known malware using the same mechanisms as our threat researchers, before it can be published to App Installers. Another change that we are about to start rolling out is beginning to replace the mechanism that controls how App Installers actually performs the installation on an end user Mac. The current process is that a team at Jamf sources the media for a software title from a vendor, often having to repackage it so that it can be deployed via App Installers and then it is bundled up with a LaunchDaemon and a notification binary in one package, digitally sign
Hi all, I've discovered that this profile we push to lab machine to disable the requirement for a password when the computer display is turned off is no longer working in Sonoma:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>askForPassword</key><integer>0</integer></dict></plist>This profile now causes the setting in System Settings>Lock Screen>Require Password After Screen saver begins or display is turned off to be set to IMMEDIATELY.Anyone see this or have alternate solution for environments where we don't want the screen to lock when the display turns off (other than setting it manually?)?
Seems a critical piece in my Apple management arsenal has become severely hindered. Here is a description of what I and others are dealing with:https://www.reddit.com/r/macsysadmin/comments/17n0xw3/sonoma_osascript_via_apple_remote_desktop_not/I have worked with settings within the new “Remote Application Scripting,” but that doesn’t seem to help.This worked previously on machines, 13.6.1, before I upgraded them to Sonoma.Your help in resolving this issue is greatly appreciated.
I'm looking to be able to rename a computer in Jamf Pro (in the web interface) and have it apply on the computer. I've seen others post more complex questions and use a script to rename multiple computers based on other info in the inventory, but we have external asset tags, so we're just gonna go in and manually name the computers using those tags (the tags are plain alphanumeric strings that come from our inventory asset system which get printed onto a barcode sticker that is placed on the computer, but we don't have a way to get that into Jamf). It sounds like it should work to rename a computer using the instructions here: https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/Renaming_a_Computer.html But I've tried several times, and after saving the name in Jamf Pro and waiting a day, the computer name on the macbook hasn't changed, and the name in Jamf Pro has reverted to the original computer name. Does anyone know if this is expected to work? Are there minimum
I'm gonna show you guys a way that like what I said in the title.First you need to access the Profile Configuration > Ristriction , set Only Allowed some apps , input the com.apple.webapp and click save, then add the Chrome on next line.Then you can add your WebClips as your wish, don't forget use the "googlechromes://" instead of "https://" if you want to use the chrome but no safari like me.Finally, when the configuration profiles affected, the other apps were hidden and only the WebClips were remained.PS: Choose the Fullscreen app in the WebClips, and you can touch the WebClips and directly open in chrome , if you didn't , when you touch the WebCllips , it will open in the safari first and then redirect to the chrome.
On Saturday, March 22, 2025 (previously March 15, 2025), Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time ap-southeast-2 March 21 1300 UTC 1700 UTC ap-northeast-1 March 21 1500 UTC 1900 UTC eu-central-1 March 21 2300 UTC 0300 UTC eu-west-2 March 22 0000 UTC 0400 UTC us-east-1/2 March 22 0500 UTC 0900 UTC us-west-2 March 22 0700 UTC 1200 UTC Jamf Cloud Hosted Data Region Information
Since the initial release of this integration, Jamf and Microsoft have both made improvements to related features and capabilities, which includes additional data complexity and updates to Sentinel to better support it. The updated integration includes support for the latest telemetry data types and includes: A new Jamf Protect integration, available on the Microsoft Azure marketplace. A new section for configuring data forwarding to Microsoft Sentinel, available in the macOS Security portal. For more information, see Setting Up Data Forwarding to Microsoft Sentinel. If you already have Sentinel configured, migrate to the new integration.
Hello, We are enrolling our current iPads into Jamf via ABM and most are working well. I have one staff member that has an iPad that is part of a family plan with their kids. When I wiped the iPad and then restore it using their personal Apple account and restore their backup it never prompts for our MDM profile to be installed and it just reboots continues to restore the backup. The iPad is in prestage enrollment in JamF and I have enrolled it successfully without using the personal Apple family account. Can an iPad that is part of a family plan use an MDM from Jamf and be managed by Jamf? Thank you.
Hello People, While troubleshooting a failed policy deployment I came across this error messageError: Bootstrap token must be escrowed to the Jamf Pro server in order for computers with Apple Silicon (i.e., M1 chip) to use RestartDevice MDM command.I tried manually with “sudo profiles install -type bootstraptoken” but I got this errorBootstrap Token functionality is not supported on the server. My user is an admin and has securetoken enabled according to “sysadminctl -secureTokenStatus”“sudo fdesetup list -extended” also lists my user admin as Volume owner and I have filevault enabled.I can also carry out update on the computer without issues.The laptop operates like a test computer and I have had to enrol and unenrol it multiple times. could that be the cause of the Bootstrap Token functionality is not supported on the server. error?Some information about my setupComputer operates more or less like a test laptop and gets unenrolled and enrolled to jamf multiple times.JAMF Cloud V
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!