Get Support
Recently active
I am relatively new and not very knowledgeable when it comes to certificates. About a year ago I successfully created our company's push certificate for JAMF Pro (cloud version), and it is about to expire in a couple weeks. In attempting to renew our push certificate for another year I get the following message after I upload the new .pem file I downloaded from Apple. "WarningExisting devices that are enrolled with Jamf Pro will no longer respond to push notifications." What does this mean? What will happen if I complete the process as-is? Will I need to re-enroll my devices? Will they stop responding to JAMF? Should I wait until the actual expiration date to create a new push certificate? I believe I am using the same Apple ID, but is there a way to check or verify this? Any help would be appreciated. Mark BishopCommunity Action, Inc. of Central Texas
Hello, in our company, we automatically synchronize some SharePoint/Teams folders on certain Windows devices. Is there a similar solution for Jamf? Or does anyone have any ideas on how I could implement it best? Thank you in advance!
Hello everyone we have a major performance issue with Jamf Teacher (Jamf over jamfcloud.com). In a class of 20 students, it sometimes takes over 10 minutes for the last iPad to receive the profile. Since there are also such problems with other online services, but the speed of the Internet connection is about the same everywhere in the building (measured), I think it could be due to the configuration of our network. Has anyone here perhaps had similar experiences and found a solution?
Hello,I'm trying to find out if Jamf Pro has a audit log of users that log into Jamf Pro for administration and the actions they preformed? Looking for a audit log to trigger alerts in Splunk for when a new "Standard User" is created or etc...
Hello Hoping someone can point in the right direction.Im in the process of updating our secuirty base lines we settled on using Level 2 CIS.Things are going well so far with no major issues.I noticed our updated firewall config as cut of the ablity to screenshare using vnc I think I just need add allow com.apple.ScreenSharing under this section. Does anyone have the bundle ID for com.apple.ScreenSharing or now how to find it.I would normal run something simliar to this https://www.hexnode.com/mobile-device-management/help/how-to-find-the-bundle-id-of-an-application-on-mac/ but only seem to work for apps. I dont think it would work as its not an app. Thanks
Hi, Calling all jamf script superheroes... I am a newbie to scripting, I want to make a script to enroll computers to JamfPro and then add the computer to a specific static group. Could any one please share/help if you have a working script handy? I managed to make one but I am stuck with downloading the CA and enrollment profile config files. If I managed to download those two config files, I have to install it manually by clicking them and then the script continues and moves the computer to a specific static group, then a binding profile is pushed and the computer get binded to local AD. @greatkemo Is this a piece of cake for you? Thanks
Does anyone have a configuration file for macOS and iOS for locking Teams down so that only a specified user domain can login? Attempting to prevent our students from logging in with personal accounts.
We are testing enrolling Macs in to Microsoft Partner Compliance to enforce Conditional Access policy. For the most part, the process is smooth to enroll and we have not seen too many issues. However the one issue, that will be a user concern, is when a user goes to a Microsoft site (like Outlook on the web), they are prompted by macOS to allow Google Chrome to use the Microsoft Workplace Join Key from the Keychain. Edge and Safari use this key automatically, which makes sense being Apple & Microsoft. I tried adding com.google. to my SSO extension, like i have for Apple, Microsoft, and Jamf, but that doesn't seem to work. (See Below) Is there anyway that I can automatically allow Chrome to use this WJK? <?xml version="1.0" encoding="UTF-8"?> <plist version="1.0"> <dict> <key>AppPrefixAllowList</key> <string>com.microsoft.,com.apple.,com.jamf.,com.jamfsoftware.,com.google.</string> <key>browser_s
Hey,What is the recommended way of handling compliance with the upcoming Sequioa release? I have used the Jamf Compliance Editor to create config profiles for Sonoma, which was very convenient, since the JCE let's you upload perfectly name config profiles for Sonoma and its predecessors.If I am not mistaken, the JCE does not currently support Sequoia, yet. For now, I have set major OS updates to be deferred by 90 days, so I can sort this out.How do you guys handle this?When is the JCE likely to be updated? Thank you for your help.Toby
Want to earn Jamf Rewards Points and a shiny new badge? Get an article published in the Tech Thoughts blog, and (if enrolled) you'll be rewarded with bytes and this sweet badge 👇 If you have information that you'd like to contribute to the community, we want to hear from you! Tech Thoughts blog posts should be 400-600 words covering relevant Apple Admin topics. There's no pressure to write something epic or profound– articles are meant to read like a long-form Jamf Nation post. Interested? Please reach out to me on Slack @Joanna buchmeyer with your submissions or questions. Happy writing!
Hi Everyone, There are Aruba Access Points in my environment. We connect to the WIFI broadcast of these APs via Aruba Clearpass. Authentication is done through this. Then certificates and a Profile are downloaded to the MacOS device. After doing these, we can connect to the company WIFI network. This is a long and tiring process for the user and the technical support teams. We want to do this process automatically, without user participation as much as possible. For this, we decided to use the policies on Jamf Pro. However, we have not been successful so far. The configuration policies we have prepared remain in the "pending" state. We first made the SCEP configuration within the configuration policies and tried it. However, this does not work as it should. We configured this profile by using various documents. Of course, we first installed a Windows SCEP Server and configured it as it should. We activated the NDES service. We saw that we could reach the links we wanted via IIS for the
Following this weekend's update, I decided to start testing out the "Available in Self Service" option for App Installers. This works great for machines that do not have the application installed already. The problem is that App Installers that are set to Available in Self Service do not adopt previous installations of those applications unless the user goes to Self Service and re-installs the application using the App Installer route.Has anyone found a good method to get apps previously deployed by policies transferred to App Installers (Available) without forcing the end users to go into Self Service and re-install the program?
Hey everyone, I wanted to share a Bash script that allows standard users to temporarily gain admin rights for 15 minutes via Self Service in Jamf Pro. This script ensures users can perform admin-required tasks while maintaining security, compliance, and auditability. What This Script Does 1.Checks if the user is already an admin and notifies them if they don’t need elevation. 2. Prompts the user for a valid ServiceNow Request Number before granting admin access. 3.Logs the ServiceNow Request Number along with the username for auditing purposes. 4.Grants admin privileges to the user and creates a flag file for tracking. 5.Deploys a LaunchDaemon that ensures admin access is revoked after 15 minutes, regardless of reboots or logouts. 6.Starts logging all user activity for the duration of admin access, capturing executed commands for review. 7. At the end of 15 minutes, the script automatically revokes admin rights, stops logging, and collects logs for audit purposes. Key Features • E
Hello everyone,Now when we have left our old eDirectory and are up en running with our Entra en AD I put together some Apple Scripts for mounting network volumes - home and shared. The scripts work okej but I think it would work even better if you made them as bash script instead. But I'm not good att bash at all. Maybe someone's willing to help me out? One of the scripts I've done look like follows: set userName to short user name of (system info) set Share_Path to "smb://" & userName & "@our_server_address/home$/" & userName tell application "Finder" mount volume Share_Path open userName end tell Thanks in advance,Jonas
We're having issues trying to install Unreal Engine in our lab of 25 Macs. I've been searching for a solution but have come up empty handed. I found an unanswered question from someone with the same problem in the Epic Games Launcher community, and I've borrowed his description of the problem, as he explained it better than I could: We've installed Epic Games Launcher and Unreal Engine 5.2.1 on all of the Macs. When any other user logs in to use Epic Games Launcher and Unreal Engine, in the Unreal Engine section it asks to install Unreal Engine again, not recognizing that there is already a version installed. When you click Install it tries to install it to the exact same place and throws a ‘Directory must be empty’ error. (Obviously the directory isn’t empty because it already contains Unreal Engine)Unreal Engine is installed to the default /Users/Shared location, and permissions on the /Users/Shared/Epic Games and /Users/Shared/Unreal Engine folders (and their contents) ar
Has anyone been able to script/package beA Client Security? This is a requirement for our German offices, and would like to be able to streamline this if possible.
Hopefully someone can help. i am wondering if the below scenario is possible. We are wanting to push a users calendar, lets call them Person A to another users mobile device, lets call them Person B but im getting errors when we try to do this. I have tried setting this up in JAMF config profile, with Exchange Active Sync. however when Person B authenticates with their details, instead of loading Person A's calendar it loads Person B. JAMF support advised that this is 'Normal Behaviour' and we should share it through O365. while that is possible, we want a the phone to be setup prior to them receiving it and have this setup in the native calendar app, but also want Person B to not be able to view Person A emails. We need this greyed out which the config profile you can do as you can select to only show Calendar. Hope this makes sense, i can attach screen shots if needed.
Hi, we have some trouble with the latest Microsoft Teams Version which came via MAU. Starting with Version 25007.207.3396.1311 the Apps quits randomly after 20 - 30 minutes of use. We are back to Version 25007.203.3361.6689 which works fine. As a temporary workaround I distributed a CP which stops MAU ... All Apple Mac Silicon Clients run on the latest macOS 15.x, we use Tools like Sentinel One and Rapid7. Any ideas? Thanks
Hi, Is it possible to block access to the Apple Shortcuts Widget? I have added the App to the Blocklisted applcations but it can still be viewed via Widgets. Strangely, I also blocklisted the Apple Podcasts & TV apps and it removed them from being viewed in Widgets. Any help gratefully appreciated. Phill
Hey all! Back with another script that I wrote for necessity sake. Since JAMF v10.36 we can issue a "Self heal" command for whenever we get the dreaded "Device Signature error?" at the JAMF command in terminal. This script was built on the concepts by @snelson and Emily Kausalik, but I just wanted to put a nice end user interface to it. As long as the system does check into JAMF, you can issue the command to self heal. If it is not checking into JAMF, a desk side visit is probably in order... Source here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/tree/main/JAMFBinaryRedeploy Screenshots for the script Information collection screen Confirmation dialog Process finished
Hello All I am trying to Uninstall Zscaler i have script but for Uninstallation it is asking me password as below:Anyone have workaround for this?Note: It is not accepting user account password
If I have multiple configuration profiles made by different techs and as an example: profile 1 - allows iMessage and profile 2 does NOT allow iMessage, which profile wins? Is iMessage allowed or not?
Today we released Jamf Connect 2.45.0; this release includes minor bug fixes and improvements. To access new versions of Jamf Connect, log in to Jamf Account with your Jamf ID. The latest version is located in the Solutions section under Jamf Connect. Product Documentation For additional information on what's included in this release, review the release notes via the Jamf Learning Hub.
It looks like the Apple large clock is suddenly appearing on the login screen, blocking the local login and shutdown buttons. I’ve already tried disabling the large clock setting in System Preferences, but it’s still showing. Additionally, there doesn’t seem to be an option to hide it using the plist.
We noticed that the recent MacOS Sequoia update really messed with our users ability to print. To cover what has been happening with us, when a user adds a printer from Self Service, the very first print job never brings up the window for them to enter their credentials. Instead just sitting on "Hold for Authentication". Hitting that little refresh button doesn't do anything, and most of the old fixes I found online don't seem to help. Once the user cancels that job, then sends it again, the pop-up happens and everything is good to go from that point on. So, as a temporary workaround until we can find the actual issue we came up with this little script to send a 'dummy' print job, wait a few seconds to hit the authentication, then cancel the job. So far this has been working great so I wanted to post that script here just in case someone else can make use of it. Note: Is it just me or is there no Shell/Bash option when pasting code here? #!/bin/bash # Get pr
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!