Get Support
Recently active
Hi, Is anyone getting this error with the Jamf Connect Login window? We are Using OKTA and JAMF Cloud. I have logged a ticket with Support and we tried recreating the profiles(login, license, Jamf Connect), scoping and unscoping to specific machines etc. Each time I log off/restart the machine loses the license. Checked /Library/Managed Preferences/ and I can see the Jamf Connect plist(s) with the license keys. Can see my profiles in System Prefs. I know the license file is valid as it will sometimes license at random then 'disappears' after log off.
I was recently working on performing some testing to find out why we are having problems with policies that install apps using an install package. We noticed that the packages would fail to download successfully. I created a policy that runs a packet capture while an application install policy that contains a package payload is running. The packet capture along with the Jamf log, and some other data all get zipped up and uploaded to each computer's inventory as an attachment. This enabled me to get the data I needed without having to ask the user to provide the data to me. I got the logs and other data that I needed to get help finding out what is causing the failed package downloads. This process created another problem. Over 100 Mac inventory records had multiple attachments from the multiple tests I ran. Jamf Pro does not provide an easy and automated way to delete the attachments. The API does provide a delete function. To run this function, we need to know the computer's Jamf ID a
Greetings all, We have recently migrated our Jamf Pro instance from on-prem to the cloud product. We are now looking for best practices information and suggestions from others who have made this move and changed the way that they had implemented things locally. We made a fair sized jump (from late v10 to current v11, for various reasons) and some things definitely changed in that gap. For instance, the way that LAPS handles the password rotation and loses the cryptographic linked capabilities. One of the things we are particularly interested in is how to keep a secure environment (e.g. no "one account and password to rule them all" situation) but still have the token information needed for doing things like OS updates. But, frankly, any suggestions are welcome. We have a bit of a grace period for organizational changes here during the migration project, and we want to take full advantage of it. We are working with consultants (Rocketman Tech) through
Hi everyone, Since the update of JAMF Connect to V2.43.0 we've had a couple of devices getting an error messages saying that "JAMF Connect is Damaged and can't be opened." On investing this further we have found that "JAMF Connect was blocked from use as it is not from an identified developer." I'm curious why this would be.
Hi Jamf community, Recently, a user reported a pop up that appeared talking about Jamf depreciation. Is this something anyone else has encountered? Is this going to be an issue?
We are excited about recent updates that make Chrome on macOS easier to deploy and manage. Our work with the Google Chrome for Enterprise Team is ongoing, and this first release benefits not only Jamf Pro admins, but everyone who manages Mac at scale. Look for more information in the form of a blog, but here are the highlights: Updates to the installer - Chrome is now available as a PKG in addition to the standard DMG. This is the preferred installer format for mass distribution, and is available from the Chrome Browser Enterprise Installers website. Initial Support for Application & Custom Settings - Chrome Browser Cloud Management (CBCM) is a a single location to set Chrome policies on multiple platforms. Google simplified the process of deploying the enrollment token by leveraging Jamf's new Application & Custom Settings payload. This work comes from user feedback and @alexbauer from the Chrome for Enterprise Team is joining this thread to hear your thoughts! Chrom
Hi all,I'm running in an issue concerning the installation of the OpenVPN app.Basically I've deployed the after converting the .app into a .pkg via Composer, and the app works just fine untill our users need to connect via profile. If the user tries to connect to the VPN they are greeted with an error. My issue is that, if I try to download the application using the original .dmg file (but that needs an admin login, that our users don't have) and run OpenVPN afterwards no error occurs and both the profile and the app work just fine 100% of the time.I think this leaves me with 2 options: either let our users download and install OpenVPN via .dmg but without any need for an admin password or I need to push to our users every file that the .dmg install on the computer and not just the .app.I'd really like to go for the first option since it could be useful in plenty other situations but sadly I don't know how to do neither of them.Thank you for the help!
Hey everyone. I was recently asked to upgrade our GlobalProtect to 6.0.7. After some extensive searching on JAMF Nation I was able to piece a good script together that will add your portal connection(s) to the install. Create your package and the following script...#!/bin/shsudo rm -f /Library/Preferences/com.paloaltonetworks.GlobalProtect.settings.plist## Set the portal address for GlobalProtect#portalAddress="YOURCONNECTION"## Modify PLIST to reflect the correct portal address.#echo '<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>Palo Alto Networks</key><dict><key>GlobalProtect</key><dict><key>PanSetup</key><dict><key>Portal</key><string>'$portalAddress'</string><key>Prelogon</key><integer>0</integer></dict></dict></dict&g
Hi all - We got PSSO working with our Okta preview environment and thought the setup for our production environment would be easy using the article by Sean from Jamf. However, we are hitting the same issues during registration when after the user input their password, the registration is not available (see screenshot). Also, I've noticed all articles references the okta preview environment. Has anyone gotten PSSO to work in their prod environment with a custom domain (e.g., companyname.com, login.companyname.com, etc.) vs. the standard company name.okta.com? I have reached out to Okta who suggested we add desktop password sync in addition to their PSSO article and we are still having the same issue.
We're in the process of configuring another Jamf instance for a separate group. One issue I'm running in to is with a specific package we created using Composer. After a tech enrolls the device, they run a self-service Audit Check and it checks to make sure the 6 security tools are running. When it runs, it copies a script to the /Shared folder and then runs the script. We use the same package in our Prod and QA site, but for the new site, when you run it, it always errors out. I've even tried creating the pkg again.Error Downloading https://xxx.jamfcloud.com/jcds/downloads/Audit_Script.pkg... Verifying package integrity... Installing Audit_Script.pkg... Installation failed. The installer reported: installer: Error - the package path specified was invalid: '/Library/Application Support/JAMF/Downloads/Audit_Script.pkg'.
Hi,We have a computer lab, fully ethernet and we've always turned off wifi (using a simple JAMF policy running on startup) to avoid confusion. We recently upgraded to Sonoma and have had reports of users complaining as the wifi is popping up asking for credentials persistently. On further investigation we've noticed that if you turn wifi off, but then sign in with a new user, wifi is automatically turned back on.We can fix this by changing our policy to run on 'login' as well as 'startup' but just wondered if others had observed this behaviour, and if it can be attributed to Sonoma or some other update?Thanks,Lawrence
Does anyone possibly have a bash script to uninstall Cirrato? I have tried many things without success.I know that Cirrato isn’t a very common software, but I give it a try here anyway.
I'm currently trying to setup a group of iPads to function as kiosks that are locked to a browser window that the user can't get out of. Previously for this we used a combination of an app called Managed View and Guided Access, however since we now have Jamf, we want to be able to configure this through Jamf Pro so that we don't need to manually setup iPads to function this way. I've followed all the documentation I could find relating to Single App Mode, however whenever I try to push out the config profile for enabling it I simply get a "failed" message in the Jamf Pro logs. This app definitely supports SAM and ASAM, so I'm confused why it is proving so hard to setup. I can get the app deployed and working just fine, however the config profile to limit users to just the app is proving to be very difficult. Any advice? I'm considering having a go at a different Kiosk app but the one I'm working with has better documentation than most.
Hi.,In my organization, several Mac laptops are experiencing an issue where users enter the correct password, but receive a message stating, "Your account is locked. Try again in 3 minutes." We attempted to send an unlock command via Jamf Pro, but it did not respond or resolve the issue.As an alternative, we tried resetting the password using the recovery key, and it successfully resolved the issue.I'm not sure if the recent patches are causing this issue, but I wanted to give a heads-up. If anyone has any insights or suggestions, please share.All the devices are running macOS Sequoia 15.3.2.
Hey all, I have been using the tools at https://office-reset.com/macadmins/ for assisting with O365 and other office related issue. However, I was wondering if anyone has made a Microsoft Teams (Work or School) removal script? Office reset has a full office removal script, however it does not include he new Teams as part of the removal... Main reason for wanting it is to get the mac back to a clean slate from the O365 perspective to troubleshoot some other issues.
Has anyone experinced this? Guest Accounts Stop Working After Update and cannot be Enabled via System Preferences or Terminal Command. I am trying to contact Jamf to see if they can help. If anyone has experienced this and have a solution please let me know:)
Hi, we are trying to find a solution to prevent the device name from changing after an iOS device is reset. With the PreStage Enrollment method "List of Names", each enrolled device receives a name from the predefined list (e.g., Device0001, Device0002...). However, when we reset and re-enroll the device, it gets a new name from the list instead of keeping the original one. We plan to label the devices with stickers showing their assigned names, so the current behavior is not ideal for us. Is there a way for Jamf to assign the device name as it does now, but without changing it after a new enrollment? Thanks in advance! Currently we have this workaround: We show the hostname on the lockscreen.
After upgrading to iOS 18, students are seeing trusted certificates being removed from their iPads. In our case, they are root certificates that get pushed via Jamf Pro during enrolment - one for wifi access, one is the JSS built in certificate. (click on settings, about, certificate trust settings to see the certificates that get pushed)Is anyone else seeing this please? We are seeing this sitewide, as the OS update rolls out.No fix at the moment other than wipe the device and enrol all over again to get the certificates back - not feasible when you have over 1000 iPads!
Hey Gang, I have gotten 1 computer out of 300 that refuses to finish a jamf recon (either at login or on demand). I am pretty sure that my EAs are OK as the collection works perfectly fine on all of the other Macs. I did try "jamf recon -verbose" and it did provide me a detailed listing, but that didn't tell me much info on where to start troubleshooting... Could it be a particular app or corruption that could be causing this? I am looking for some ideas on what to try next...
Hello everyone, I want to force the Microsoft login windows when the user enrolls a device. I already archviced:Settings -> System -> Cloud identity providers -> Entra ID (Mappings test works) Settings -> System -> Single sign-on with SAML Settings -> System -> User accounts and groups -> Jamf Pro User Groups - > I got two Directory Service Groups for Jamf Pro Administrator access and Enrollment The only thing that's left is the Error HTTPStatus:500 when I want to register a Mac. I don't want the whole bunch of extras of Jamf Connect with local/mobile account creation on the Mac etc.. Just the extra step as login to verify the user is an active member of the company. Thanks a lot.
Does anyone know of a way to modify the built-in extension attribute for a Patch Management title? The issue I'm seeing is that the one for Jamf Protect is pointing to /Library/Application Support but the application is installed in /Applications, meaning the extension attribute is turning up as blank for all the machines. If there's no way to modify, is there at least a way to point the Patch Management version collection to a different place? Any help is appreciated!
I've been asked to deploy some apps as managed on all our iPads - but some people seem to have the app with their own apple ID. Does the 'convert unmanaged to managed' option fix that? Or is my only option to ask them to remove the one they installed?
I've been looking for a way to silently uninstall the zoom outlook plugin but everything I see is just running the uninstall.app. Is that the only viable option (remote connect and uninstall) or is there a better way to do it?
How are you updating your users to the latest version of Safari (17)? Mac Apps does not have Safari available and you can't add Safari to VPP, so I tried creating a package using composer and adding it to a Patch Management policy and pushing it that way, but that is not working. I also tried just creating a regular Jamf policy and adding the package there and pushing it out, but no dice even though the logs show it was installed successfully, but when the machine runs recon it still shows the old version of Safari, not Safari 17. I have Software Updates (System Settings>General>Software Updates) disabled because Restricted Software was not restricting users from going to macOS Sonoma, so this may have something to do with why I'm not able to update these devices to the latest version of Safari, but at this point It's just a guess. Any help is greatly appreciated!
When I was asked to write my thoughts down for a blog to celebrate International Women’s Day, my first reaction was, What the heck?! Advice, from me? More specifically, advice on professional development. Ha! I don’t even RTFM! Then, I had a flashback to 2019 when Jamf asked me to be on their first Women in Tech panel at JNUC. I’ll admit—I needed some encouragement from other admins, my leadership, and my team. I may or may not have gone into hiding when first asked to be on a panel. In the end, I wound up co-presenting with a fellow woman Mac admin on leadership, and it turned out to be a positive experience. After this quick montage in my head, I cast my doubts aside and realized, Okay, maybe I do have something to share. I can talk about a few key things in my career that I think could be helpful to other women out there. The 2025 UN International Women’s Day (IWD) theme is “For ALL Women and Girls: Rights. Equality. Empowerment.” This theme focuses on empowering the next gener
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!