Get Support
Recently active
So we might be learning this lesson the hard way, but we have an Air that a student has locked via his iCloud account and does not know the code. We've been fighting with Apple support and GSX to get it unlocked but in the interim we've begun discussing how to prevent this in the future. Only way I really see would be to disable the iCloud preference pane (configuration profile I assume?), correct? If that is the case, then you are debating the cost benefit of them being able to utilize the iCloud features against locking and wiping a device as well. If we go the route of disabling the iCloud pref pane, a user could still enable this during an OS upgrade to right? Finally, wondering if there is an extension attribute or another way to query all my devices to see who has iCloud enabled on their laptops?
Hi All, We have an issue with employees who are offboarded. When they return their Mac's, sometimes we find their Apple id's block us from wiping the computer and giving it to the next user. When this happens, we need to find the original invoice, send it to apple with a request and then they can unlock the Mac. I am wondering what companies do to circumvent this issue. We use Jamf but we do not provide company Apple id's. We dont mind if users connect their private Apple id's to the computer as it helps with the Apple ecosystem. Any suggestions would be greatly appreciated
Afternoon All Im trying to pull back a license for an app deployed via VPP I have removed the device from scope and update the inventory but it still not showing as been avilable to deploy again. Does ASM need to sync with jamf as well? Thanks Tom
Hi all - really annoying that the option for pointer size is greyed out and our developers need the option to adjust available. Has anyone seen this and found a workaround via Jamf through a script or profile? All my efforts have failed, many thanks :)
Hi All, We have company managed Macs with Jamf. We do have sensitive company data on the computers which we do not allow to be transferred out of the company environment. We block the use of external storages. If we allow users to connect their Apple id's and iCloud, will they be able to transfer company data from the computer to their iCloud? Is there anything we can do to prevent this? Maybe block their iCloud somehow? Any suggestions? Thanks in advance
We enrolled a device and, during the assistance migration, used a Time Machine backup from a non-enrolled machine. Using the Jamf login configuration profile, we allowed the merge of the network account with the local account. After merging, the local account name appears in the "Users and Groups" section and in the terminal, but the password of the network account is required. What steps can we take to ensure that after the merge, the local account adopts the network account name? In our standard routine, we use a synced network account and local account.
Hi, We are transitioning 250 or so users out of Jamf Pro / Jamf Connect. We have an upcoming license expiration, so trying to get all users out before expiration. Renewing the license wasn't an option as we'd only be doing so for a small number of users and the minimum possible duration of renewal is 6 months. Can anyone provide details on what happens when the license expires? I've seen mention of a 2 week grace period and a 30 day period. Will device be unmanaged or left in the state they were in at the time of license expiration? Just want to ensure we fully manage expectations. With all due respect to licensing, we aren't looking to short Jamf of licensing $. It's simply that we are moving into another product at the decision of our leadership on a short timeframe.
I have the following in a script on Jamf Pro. When I deploy the script and it runs this I can see on the test Mac it has "Attempt 1 to bootout com.Daemon" in the log file. However, it fails to continue with the rest of the script. I tried adding || echo "bootout error" after the bootout command but that didn't help either. When I run the launchctl list | grep "com.Daemon" command I can also see it has successfully booted out the Daemon. Why won't it continue to then trigger the jamf policy? I've tried /usr/local/bin/jamf policy -event 'Trigger'I've tried with sudo and without. I've also tried to have it trigger the jamf policy first which works but if I put a delay in the policy so I wait until bootout is complete it doesn't progress to attempt bootout (it waits on policy completing). I tried adding & to then end (/usr/local/bin/jamf policy -event 'Trigger' &) and that resulted in bootout command running but jamf policy did not. When I run the s
Hello,I'm testing the Temp user promotion setting:I have set a com.jamf.connect config profile with the below plistIt's showing correctly on the jamf connect menu bar but when I click and select the reason nothing happens and the timer doesn't show in the bar nor the user gets elevated.Hope anyone encoutered the same issueThanks <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>TemporaryUserPermissions</key> <dict> <key>TemporaryUserPromotion</key> <true/> <key>URLCommandLineElevation</key> <false/> <key>UserPromotionDuration</key> <integer>60</integer> <key>UserPromotionReason</key> <false/> <key>UserPromotionTimer</key> <true/> <key>VerifyUserPromotion</key> <false/> </d
This is in regards to the MiniEvent Outing at shooters during the JNUC. I'd be willing to help with Gas and other $$$ if they want to go to this. Regards,TJ
I just removed the mdm management from an ipad, FROM THE IPAD (not through jamf, but on the ipad). It is an ipad that I was going to remove from Jamf, but I kept seeing the remove management when looking at it on the ipad and wondered what it did. Now I know. Back in JAMF I have no ability to manage that ipad anymore even though it shows it in JAMF. Which means the user can remove the mdm management from the ipad and we have no control of that ipad? I just sent in a support question and they sent me nothing that is relatable to my concern. Why is the user able to remove the mdm management from the device?I have no idea how these ipads were enrolled, they were done before the job was handed to me. The past year they have been added to Apple Business Manager, then into JAMF. This was not one of those, but a previous enrollment. Not self enrolled but through apple configurator.
Today we are releasing Jamf Pro 11.14; highlights include: AD CS Certificate Deployment Using SCEPYou can now use the SCEP payload to deploy certificates from an Active Directory Certificate Services (AD CS) integration. Previously, only the Certificate (API) payload was available to issue AD CS certificates. The SCEP deployment method supports automatic certificate revocation based on scope change. You can also redistribute certificates that are approaching their expiration date by redistributing the configuration profile. App Installers Support for External URL DownloadsJamf App Installers supports software title installation packages that are downloaded via versioned URLs from a vendor's website. An alert is displayed on the Configuration settings tab for any software title that is downloaded via an external URL.Note: At this time, only newly added software titles that have a versioned URL available will be downloaded via external URLs. For additional information on what's
We have the Internet Accounts system preference pane disabled, but our users are still able to add accounts to Internet Accounts. I think this is being done via Safari because IIRC, it will ask you if you want to add a supported account when you sign in to that account through the browser. Does anyone know via the command line how to remove these accounts? Or do we just have to temporarily allow access to the Internet Accounts preference pane in order to remove these?
I have been working on a policy that will create a temporary admin account. A launch daemon gets installed and launched to handle the account deletion. Once the alotted time has elapsed, I see the account and its home folder get deleted. I see that the launchd process is no longer running. Everything works exactly as intended, but the launch daemon does not get deleted. I can manually run a command such as "sudo rm /Library/LaunchDaemons/com.my.launchdaemon.plist" and that works perfectly. The launch daemon triggers another Jamf Pro policy to run that deploys a script that runs the account deletion, deletes the home folder, unloads the launch daemon and then is supposed to delete the launch daemon. A moment ago, I commented out all the steps except the launchdaemon unload and deletion, and watched as the script deleted the launch daemon! Below are all the steps that the script runs. #!/bin/zsh # Delete the Rescue Admin account and its home folder echo "Removing Rescue Admin account" d
Previously the script below from another message made it possible to have custom screensaver files (Photos) that would rotate. This no longer works in macOS Sonoma. Does anyone know a new method to have the screensaver call photos from a particular folder in somona via a script or another way.#!/bin/sh## get current useruser=`ls -l /dev/console | cut -d " " -f 4`## get macOS version(s)osMajor=$(/usr/bin/sw_vers -productVersion | /usr/bin/awk -F"." '{print $2}')osMinor=$(/usr/bin/sw_vers -productVersion | /usr/bin/awk -F"." '{print $3}')## set key items for screensaver/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver CleanExit -string "YES"/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver PrefsVersion -int 100/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver showClock -string "NO"/usr/bin/sudo -u $user /usr/bin/defaults -currentHost write com.apple.screensaver idleTime -int 60## c
I watched the presentation given by @chadlawson and uploaded to the Rocketman Tech channel on YouTube (https://youtu.be/6xVmJqpbEHI) over the weekend. I decided to dive in and change a script that puts a machine into a static group (credit to @sdagley ) but whilst I can see that I'm getting a token, the computer is not going into the Static Group. The reason for changing from Basic Auth to Bearer Token Auth is because Basic Auth is deprecated so I'm trying to get this figured out before there's a panic.Just wondering if anyone can see where I'm going wrong or suggest a better way to do this? The first script below is my working script using Basic Auth and the second longer one is the one using Bearer Token Auth. The second script is mostly using code from Rich Trouton's blog on Bearer Tokens and I do get the Bearer Token but whilst I seem to have no errors, the machine is not added to the static group.#!/bin/sh # AddComputerToStaticGroup.sh # Adds the computer to a stat
The message keeps popping up for a user. He said this has been going on for like a month but there are no performance issues or any issues on the mac itself. His Mac is updated to the latest OS. Any ideas on this one?
Hello All, We have a few devices that were recycled that are popping up in Pakistan as they were not removed from pre-stage they are checking back in. I am looking for the best solution as to what to do about this. My thought process is to keep the record and try to send lock/wipe commands while removing the device from pre-stage. If the device ever checks back in then it should be locked/wiped and removing it from pre-stage should stop it from checking back in.
Hello guys, I have an IBM ACS software which I need to package and show in Self service. This app doesn't have a regular dmg or an installer. It installs via a script: Once the script runs, it puts the app in the Applications folder: This is what the script does: #!/bin/bash # Description: # This script will install IBM i Access Client Solutions in the Applications folder on Mac OS X # # Usage: ./install_acs # args=$@ args_length=$# arg1=$1 prefix_arg1=${arg1:0:9} suffix_arg1=${arg1:9} printhelp="no" default_noparms="no" reset_start_over="no" quiet_mode="no" exclude_functions="no" install_type_shared="no" install_type_preset="no" declare source declare target declare old_target declare source_AcsConfig declare target_AcsConfig declare old_target_AcsConfig function copyProductFiles { echo "Copying product files" >> $HOME/IBM/install_acs_log.txt #Remove the old app so we don't leave cruft laying around. rm -rf "/Applications/IBM i Access C
First time using Nudge here and i was trying to update all my Macbooks to 15.3.1 using Nudge to let our users know that they need to update their Mac.I've understood how to push the notification to all Macbooks that have less then a specific OS but I'd like them to update not to the latest but to the one before.Thank you
Hey, We're trying to set up a simple Jamf Connect Notify workflow where we just want to perform a few small checks before letting the user access the desktop. To achieve this, we followed the Jamf Connect Notify Documentation: https://learn.jamf.com/en-US/bundle/jamf-connect-documentation-current/page/Notify_Screen.html. We created a separate payload with the AuthChanger profile to set it to Jamf Connect Notify and added the key and value for the script path in the Jamf Connect Login Configuration Profile. Additionally, we created a separate package containing the script (root:wheel 700) at the path specified in the Jamf Connect Login Profile, along with two icons to brand the Notify screen. The directory used is the default one: /var/tmp/. We signed the package with the Jamf Pro Built-in CA signing certificate but also tried using a Developer Certificate and even signing the script separately before including it in the package. Unfortunately, we keep encountering the same issue. Jamf
I have a couple of smart groups which detect for the presence of certain Chrome Extensions or VPNs and then if a computer is added to that group it runs a policy script to remove those extensions or applications. The only issue I have is that apart from knowing a computer has joined or been removed from a group, there is no information. This may be a long shot, but does anyone know if there is a way to change the email report so it includes the reason a computer was added to a group? What I mean to clarify is that my VPN one, for example, looks for anything called "*VPN*" but it would be useful to know which application or extension triggered the group membership so I can get more information. I could of course remove the script from automatically running to remove the offending software and manually add devices to another group which does run the script after I've seen the inventory....but just seeing if it is possible to get that info in a more streamlined way?
Hi, Since none of the users on our computer have no admin rights, but we have created a possibility that the user can uninstall App. However, the script only deletes the application from the folder. That is sufficient in most cases. However, in some cases it is necessary to delete the created data. Maybe someone has an idea how to find these and delete them. #!/bin/bash ########################################################################## # Shellscript : Uninstall Script # Autor : Andreas Vogel, ########################################################################## # Script asks for the file to be deleted. # # Only for test - comment out in production! # set -x ###### please only edit here ###### list files to protect here app_protect=" NoMAD McAfee Self Service Preproxy Identity Agent jamf" ##### End ################ # Variabeln sys=$(while read p; do echo "$p" | grep "/Applications" ; done </System/Library/San
Is there a way to do a search for the Managed Apple ID that shows in an iPad's SHARED IPAD USER list?I have gone through all the Advanced Criteria but none of the "USER" related fields find even the one iPad with the user that we know has created an account on it. (Their name is listed in the iPad's inventory.)Thank you.
Hello Jamf Nation,I’m experiencing an issue where new users signing into Jamf Connect using Okta authentication encounter a blank white box with a “Done” button instead of being guided through the MFA enrollment process.Issue Details:• This only happens for new Okta accounts that have not yet configured MFA.• Existing users with MFA already set up can log in successfully without any issues.• The Jamf Connect login window recognizes the new user but doesn’t properly handle the Okta MFA enrollment flow.• The expected behavior would be for the user to be redirected to set up MFA, but instead, they get stuck with a blank screen.Current Jamf Connect Setup:• OIDC Authentication with Okta• OIDCAllowMFA is enabled• DenyLocal = True (Enforcing cloud login when online)• LocalFallback = True (Allowing cached logins when offline)• OIDCEmbeddedWebView = TrueTroubleshooting Steps Taken:• Confirmed that Okta policies require MFA enrollment for new users.• Checked Jamf Connect logs (log stream --predi
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!