Get Support
Recently active
Morning AllGearing up to role out Adobe 2025. Does have anyone have an EA which would show if a machine has no Adobe installed.I have done this using smart groups before, but gets a bit complicated given the amout of Adobe packages we push out.I already have script to remove Adobe, I was thinking I could then use the EA to build a smart group of machines with no Adobe installed.Thanks
Hello, We are experiencing an issue with creating a pkg using Composer from a Sequoia machine. We don't have this behavior when generating a pkg from a Sonoma machine. When we create a pkg containing a .app, for example, without anything else, no scripts, once the package is created, we can no longer open it with Composer because it gets stuck at 30% during the "converting xxx.pkg to source" phase. We have verified that Composer has full disk access in the macOS system settings. We tried deleting the /Library/Application Support/JAMF/Composer folder, but the same problem persists. We are using the Flat Package option and "automatically detect executable types" in Composer. There are no problems with dmg files. Have you encountered this type of problem before? Thank you for your help.
I am looking for a way to remove a firmware password via JSS policy. I work for a school district and we try to lockdown the computers so that the student don't have access to the recovery panel amongst other things. The problem is that there seems to be an issue with at least one of the computers not recognizing our firmware password, so we have no access either. Is there a way to do this using the built in policy (under accounts), or am I going to want to write a script based on the firm passwords article? Possibly helpful information:MacBook Airs (Mid-2011)Lion 10.7.4 and some 10.7.5current JSS 8.61
Hi All One question. We have some iPads with the yellow message in the Jamf at iPad details "Inactive.....". And the iPads don't get any changes over the Jamf, some new profile, App update and so. Happens it, if the iPad are to long offline and don't can be called up the infos with the Jamf School Server? Problem are, the Teacher can works further but does not realise, that they iPad don't communicate with the Jamf School Server. Is it possible to allow trustworthiness, if we download the "Supervision Identity" file over Jamf School and load it over an Apple Configurator to the iPad? Thanks Peter
Hello !I made a smartgroup for macOS greater or equal to 15 Sequoia. It should be simple:Criteria: Operating SystemOperator: matches regexValue: ^1[5-9]I have NO computer running Sequoia, but I have 3 results. 3 Intel computers with macOS version 10.14.6 (2 of them) and 10.15.7 for the last one.I searched all around and can't find where is the problem. I'm not really used with regex, but this one should be simple.Any help is welcome
Hi all, I am trying to push Software Updates to a smartgroup, but this doesn't seem to go through; I tried many options (Download only, Download and install, Download and schedule to install ecc.) but nothing seems to work. This is happening on Apple Silicon device. Having a check on the device > History > Operating System History, I see the Software Update failed and the error message: "AppleSiliconNoEscrowKey". Running sudo profiles status -type bootstraptoken I see the token is supported and is escrowed, and while running sudo profiles validate -type bootstraptoken I see the token has been obtained from the server and is validated. I am sure I am missing some basic checks, but can't find what. Has anyone had the same issue?
Noticed this morning we have a machine that logs say MDM Renewal was completed, but since then the machine is no longer MDM Capable. Any easy solutions?
We're using Jamf Now for an acquisition business (already use Jamf Pro). We've just enable Volume Purchasing in Jamf Now and started to populate with Apps purchased through ABM. However when launching Self Service on a test iPhone enrolled into Jamf Now we get the message:"Welcome to Self ServiceSelf Service is a component of Jamf Pro, developed by Jamf. This app must be associated with a Jamf ProServer.Contact your IT administrator for more information" Specifically referencing Jamf Pro. Now, we've seen this error before in Jamf Pro (think it started on V 11.1) and we use an App Configuration to fix this, but there is no option to create an App Configuration in Jamf Now, as well as there being no URL to place into the string for the App Configuration. Anyone know what the fix is here?
Hi! Please! I'll need to know what SQL syntax I need to run in the Mysql database to get the scope (and also exclusions) of profiles and policies. Thank you very much
Hello! I use my own Connectwise Control agent as my main source of remote support for clients. As you all know, since the Catalina update, Screen Recording and Accessibility permissions have been denied by default for most remote control applications, requiring someone with administrative credentials to sign in and permit the use of both categories to the application. I was hoping to find some way via a shell script (or otherwise) to force-allow these permissions to all computers in a policy. Just a little disclaimer: I do not use Jamf as my MDM platform for computers. If there are any solutions from within the Jamf platform please feel free to share them so I may attempt to replicate them on the platform I use though. I've seen a few articles posted on various platforms but they all relate to prompting users to allow permission. Any help, pointers, or references to other helpful articles would be much appreciated. Thanks!
Hi everyone, I was hoping anyone could help me out. We keep having the same issue where teachers enable restrictions on their classes, and when they select to end it at the end, a couple of students stay restricted... We need to go to the jamf school instance and disable the restrictions manually from there. We are all using same model devices, same network and bluetooth enabled. This clearly is a disruption for our students since they either need to stop at the IT office to have their device unrestricted or wait for the restriction time limit to expire.
Hi all!I have been tasked with installing Kaseya VAS through Jamf Pro at my agency. I want to avoid the why question, cause I know you will feel the same way I do!When I try to create the package in Composer with a snapshot, it will create the pkg, but with my personal machines settings, which means it will show up as my MacOS devices in the Kaseya back-end for every machine that I run this pkg on. Meaning that a user named Mike will still show on the back-end as being on my personal machine.When I download the Kaseya agent from my VSA site, I get a file with the agent application, and the items needed for installation (plist, cmd, exe). Now, I imagine that the agent installation application is just some script or wineskin to run the exe for install.I have been dealing with this for a month now, with no movement from Kaseya support, and it is driving me nuts!!! Any ideas? Thanks a bunch for taking a look!
When we open a policie and look at the logs which computers are completed or failed the button under actions called details is not working anymore. The button next to it called flush i functioning just fine. Does anybody noticed the same problem ?? we are using jamf pro cloud and i got some mails that there was a update so not sure if it has anything to do with that.
Hi all, Wondering if anyone else has ran into a similar issue. I've only noticed this with new devices running sequoia so far. I have a policy running a script to enable remote management and remote login for a local managed admin. I see that the service is running, but when going to remote management, there is no user displayed on 'Allow Access for' If I try to kickstart the process manually, it shows that these settings are already enabled and my specified users still doesn't show on the list of users to allow. I tried a fresh pre-enrolled device without running the policy in question, but the issue remains. My managed local admin is not on the list of users. Anyone experience similar issues and have a fix?
I'm cleaning up my Jamf environment mobile devices, iPads more or less, and I'm trying to use the "User and Location" fields such as "Name", "Username", "Email" fields, but every time I enter a name or email or anything and select save, no information is retained in these fields. Is this a feature only available to Macbook enrolled devices and not iOS? All iPads are having this issue and every one I've tried is enrolled and managed. Any help is appreciated!
I set up a push certificate with the intention of being able to send non invasive messages to IOS devices through the APN and Self Service app as opposed to locking the screen on a user. Notifications are typically temporary so in order to verify they are seen by the user, I would like to change the notification to persistent so it doesn't go away until the user views the message. I see in the IOS settings menu for the Self Service app, I can manually change the notifications to persistent but I don't want to touch each device. Is there some XML I can add the Self Service app in Jamf that would be associated with the app level notification settings? Or is there another way to do what I want?Thanks,Rob
we execute a script that prompts them to enter their current Mac login password along with the 6-digit PIN they wish to use as their password moving forward. Upon setting the Mac login password to a 6-digit PIN using the script "sudo dscl. -passwd /Users/"$LoggedInUser" "$currentPassword" "$newpin, successful password conversion occurs. However, post-restart, users who are logged into iCloud receive a prompt stating "This Mac can't connect to iCloud because of a Problem" and are asked to log in to iCloud again. Additionally, the Touch ID configuration removes previously added fingerprints, necessitating the need to reconfigure Touch ID and log in to iCloud after setting the password as a PIN and rebooting. Has anyone seen this or any hints about this
I want to trigger a script to run after the app is installed from Self Service. Currently the app is installed manually via Self Service. Its not a package, its from the Mac Apps/Jamf App Catalog. I want a custom event trigger that will run the script when the app is installed. What do I put here that will make that happen: Any other settings I need to configure in this script policy to make it run proper?Basically I want to run a simple script that will make Chrome Default but only after its been installed. I do not want to use a package (policy) to install Chrome, I want to keep installing it from Mac Apps/Jamf App Catalog which allows me to keep it up to date.
Hi All, In light of Microsoft security updates KB5014754: Certificate-based authentication changes on Windows domain controllers and the 2/12/2025 KB5051979 which toggled Full Enforcement Mode as promised for February 2025 (which you can temporarily delay until September 2025): What is Jamf's best practice guidance for implementation of Jamf SCEP Proxy? SCEP requests issued using the proxy supply RFC822 name in SCEP request and utilize a certificate template that allows that - but the resulting certificate does not have the necessary SID to work with the new Microsoft security posture outlined in the the security updates. Any thoughts or guidance from anyone? Thanks!
What is the best way to stop the macOS Sequoia install app from downloading automatically? The problem that this creates is when non-admin users try to upgrade to macOS Sequoia, the install app launches. The install app requires an admin user to run the install. If the upgrade is done entirely through Software Update, a non-admin user can run the upgrade. The install app doesn't launch since it wasn't downloaded. This was an issue last year when I opened up upgrades to macOS Sonoma. I had to create a policy that would temporarily elevate users to admin. They would be demoted back to a standard user at the first check-in after the upgrade. This worked well, but I prefer not to have to do this again.
Hey All! I've created a script that is supposed to mount our district's Private Network Folder and create Desktop and Dock shortcuts for the share for the currently logged in user. I've been able to get my script to work locally, but whenever I try to pass the script through Jamf, it asks to give Terminal "Finder" access: I believe this is what I need to give terminal access to: I set up a PPPC profile as follows but it doesn't seem to have helped: Any Guidance on what PPPC settings I need to pass to our computers so that end users don't get that prompt? I also tried uploading rtroutons config profile found here to no avail. Bonus points if anyone wants/can help me figure out the best way to pass this script? I know I could send it in a Policy that runs at every login, but that seems like bad practice? Maybe a LaunchAgent? Disregard my sloppy code, it's cobbled together from what I kind of understood from the 400 and what ChatGPT helped me write... &nbs
My Google-fu is failing me today. Does anyone have a link to the Apple KB (I think?) that talks about how joining Macs to AD should be discontinued?
Hi everyone, can someone help me sending the jamf pro summary? i always recieve an error : Failed to upload Jamf Pro Summary; 500 Internal Server Error: "{"message":"An unexpected rest client error has occurred","fields":null,"classification":"UNEXPECTED_ERROR"}"
Hello, I am testing adding a printer to iPads via a configuration profile. Anyone have any experience with that? What information do I need. I create a new configuration profile and go the AirPrint option. I see that I have to input the printer IP address, port and resource path. Lets say I only know the ip address and leave the port and resource box empy, will that still work? Thanks
I believe Scheduled updates should work, but I probably did something wrong.So, I created a smart computer group where I added my machine. Then, I opened software updates and tried to force macOS updates for this group (I have used different flags to force the update). My machine is Apple Silicon (m1). I don't see a proper way to check scheduled updates on my machine, so I use API (v1/managed-software-updates/plans) for it.In answer, I see already 14 plans, and most of them failed with the error "EXISTING_PLAN_FOR_DEVICE_IN_PROGRESS" .That means at least the plan should be executed, but nothing happened.What did I do wrong?{ "totalCount" : 14, "results" : [ { "planUuid" : "09487431-7d17-4c4f-baa2-5b5d03f7c076", "device" : { "deviceId" : "579", "objectType" : "COMPUTER", "href" : "/v1/computers-inventory/579" }, "updateAction" : "DOWNLOAD_INSTALL_SCHEDULE", "versionType" : "LATEST_MAJOR", "specificVersion" : null, "maxDeferrals" : 0
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!