Get Support
Recently active
Hey guys, Quick question here. I'm using Jamf Pro to help manage 3 computers labs. The boss has decided to add Staff to it too now. What is the best way to manage your Policies and Configuration Profiles for different environments? For example I have a CP for Login Window. There is a Banner that says welcome to the students. In Options I also have it set to Log out users after 30 mins. If I want another Login Window CP with different settings do you guys just specify in General in the Name of the CP? Just curious, thanks!
Anybody else getting double logins this past week in JS? My instance url takes me to a Jamf ID login but instead of SSO it takes me to the Jamf School login where I have to sign in again. Not a cookie issue as it happens in Chrome, Safari and other Macs and iPads. Just wanted to check my sanity before going to support.
I've seen this a couple of times now where a device claims that a Managed Software Update plan has "succeeded" but the device has not actually been updated. Most recent is a device set to go from 14.7.2 -> 14.7.3. It is still on 14.7.2 but the plan says it succeeded and there are no pending plans. Operating System History says: 14.7.3 Download, install, and restart Success 03/03/2025 at 2:11 AM Details: Install action:Download, install, and restart Update action:Specific version (14.7.3) Current state:PlanCompleted Error reasons: Deferrals:N/A Previous notifications sent:N/A Last event in the store: "type" : ".VerificationResultEvent", "managementUUID" : "fa6332eb-f266-46f9-b476-82478fac0f4c", "processManagerUUID" : "f3a47dd9-42d9-4117-bccf-83ec73181ed8", "id" : 248580, "deviceObjectId" : 1, "eventReceivedEpoch" : 1740985898532 Not sure how it verified as done if the OS has not in fact been updated.
Hi, Does Jamf School support this feature from Apple School manager please?
Anyone else seeing a problem where the Edit option isn't available for posts you've made? I've now seen it on multiple posts I've made in the past couple of days and I'm wondering if I have company.
Morning We have few Macs which have failed escrow there FileVault key back to Jamf. I have setup escrowbuddy and this seems to be working well bringing these keys back.I can see the policy has run to setup escrow buddy the policy also inculdes defaults write /Library/Preferences/com.netflix.Escrow-Buddy.plist GenerateNewKey -bool trueI can see users have had a fresh login.While machines now do seem to have a vaild FileVault key. I'm seeing two issues. FileVault 2 Enabled being switch from enabled to Not enabled. FileVault 2 Enabled set as Not enabled.This depsite the fact that the effected machines have a vaild Key, showing as encrypted and have a FileVault 2 enabled user.As anyone else seen this behaviour before?Thanks Thanks
When I deploy the CIS L1 baseline via JCE I'm having an issue with the following: 9.16. Configure Login Window to Show A Custom Message. When I change the default text from "Center for Internet Security Test Message" to anything else, I get a compliance failure. How do I change this message to something more relevant without it flagging up as a compliance fail?
Hello all I love how the MacApp updates so effortlessly assist in keeping our user's applications upgraded and I am very thankful for the assistance. It is a huge assistance in meeting our patching requirements. I am curious though how others are managing the false positive completions reported by MacApp though. Usually I pick these up through other policies but it is not unusual for JAMF's MacApp to provide patches that the manufacturer have not yet made available through other channels leaving us no other method to pick up the pieces. A couple examples I'm currently working with. As of March 4, MacApp is currently upgrading Adobe InCopy 2025 and Adobe InDesign 2025 to version 20.2.0.36 but both Adobe's Admin Console and Adobe Remote Update Manager only have patches through 20.1.0.71 so the 20.2.0.36 is only available through MacApp. At the same time, MacApps shows that it has successfully updated 30 of 33 Adobe InCopy 2025 and 29 of 35 Adobe InDesign 2025 users to the new version yet
I’ve noticed that when using JAMF LAPS, it correctly rotates local administrator passwords as expected. However, I’ve encountered an issue where the secure token becomes corrupt, typically when attempting to perform a software update. From what I can tell, this happens when JAMF LAPS rotates the password. Could you confirm whether the secure token is updated when the password is changed? Additionally, I used to find JAMF highly customisable with scopes and smart groups, but I’ve noticed that JAMF LAPS applies universally without an option to exclude specific devices. I wish there was a way to adjust this.
I've noticed recently that a number of our brand new deploy machines are getting their bootstrap token escrowed properly but when the user logs on for the first time, they're not getting a secure token -- meaning we have to then manually grant a secure token using a known account which has one. Any ideas why JAMF isn't issuing secure tokens to new users?
We run a clustered on premise environment. One JSS internal, one JSS in the DMZ behind a reverse proxy. I've never loved that even though you turn off the UI on the DMZ instance that www.myjss.com/api is still exposed as a UI. We do restrict what users have access to the API but I still don't like it being exposed so I tried blocking it in the reverse proxy. After doing this, I noticed that it broke the sync with VPP. I removed the /api block in the reverse proxy and the purchased apps immediately came down. I went and checked the reverse proxy logs thinking that I'd have an error logged every time the sync monitor ran. I found no such errors. The only thing i found in the logs related to /api was an errors with remote users and the self service branding icon not being passed down. Anybody else have any insight into why blocking /api breaks VPP sync and also why there would be no errors logged in the reverse proxy?
I saw a couple of articles online to install Cisco Secure Client via jamf. However it was mostly for VPN and umbrella and when taking dmg from xdr into composer it proved to be less then helpful. No matter what it did not like to be manipulated. I have created a deployment script using full installer dmg for anyone that runs into this who also is using Cisco XDR. I am open to suggestions on the script but this got the job done and cleanly. Make sure you setup a configuration profile for background processes. First thing is go in to Cisco XDR download both Full installers for AMD and ARM. Then upload the DMG files in to Jamf Next Create the Script using this bash script. It uses the jamf waitingroom cache applications. #!/bin/bash # Author: Ryan Tarson # Cisco Secure Client DMG Installer Script for Jamf (Flexible for Both Architectures) # # This script installs Cisco Secure Client for macOS using a pre-deploy DMG that # contains a single package: # com.cisco.secureclient.cloudmanage
How do I get passed the Activatiion Lock with a teacher has their Apple ID logged and Find My turned on. We run into this more than I would like to admit. We are trying to make sure they have it turned off before we take the device because they are no longer going to be with the school or it is broken and Find My needs to be turned off so it can be repaired.How do we get passed this without asking the person to come back in, remove the device from their iCould account, or ask them if they would be ok with giving us their password so we can get the device activated. I had to contact a person that had moved to Austrailia. Luckily they trusted me with their password and I was able to get the device activated. Any help would be great. Thanks for your time in advance.
Since the recent update to Version 11.14.1, I've noticed that policy logs are no longer visible. Is anyone else experiencing the same issue, or am I the only one facing this? Let me know.
To configure zoom for deployment with an MDM Zoom recommends putting us.zoom.config.plist into the /Library/Managed Preferences folder. i have been doing this with DepolyNotify using a policy with a package to put the file in the folder with no issues. I am now trying to replicate this with Setup manger. The policy runs during setup manager and says it installed (also Jamf logs shows this) but the file is not there. I also tried a policy with a script to create this file, it also said it succeeded but the file was not there.Does /Library/Managed Preferences refresh its self or something when a user first logs in?
Looking to see if anyone has created a Configuration Profile that will gray out the "Download iOS Updates" and Install iOS Updates" within the Automatic Update section. I do not want end-users to turn off the feature. As admins the plan is to have another configuration profile created to defer iOS updates for 14 days to confirm testing of a new update. We currently have that in place.
Hey everyone,I’ve set up Jamf Connect with Google IdP following the documentation and tested it; everything seems to run fine. However, I've run into issues during PreStage Enrollment deployment in Jamf Pro. I can’t seem to launch Jamf Connect properly for local account creation to show the Google login screen. Right after the Setup Assistant, it only shows a black login screen with empty fields for user and password. According to troubleshooting, it might be due to the permissions in the package, but since I’m using the official Jamf Connect 2.42.0 package and distributing it through Cloud Distribution Point (Jamf Cloud), I don’t think there should be an issue.Has anyone had a similar experience and found a solution? Here is my configuration excluding secrets: <key>AllowNetworkSelection</key> <true/> <key>CreateJamfConnectPassword</key> <true/> <key>CreateNewUserHide</key> <true/> <key>DenyLocal</key&g
Hi all,Having an issue with Filevault and our local admins getting secure token access. So I have a config profile set to enforce Filevault enablement. The user logs in, they enable filevault, all good to go. Problem is that the local admin we create does not have a secure token in this instance, and it's necessary the local admin has one.What I could do is login with the local admin first, enable filevault, but then I'd have to give the user local admin creds to login to the device prior to JamfConnect screen. That is undesirable.How can I ensure the local admin gets a secure token without actually logging in as the local admin? I know that the sysadminctl command can do it, but that would require someone with a secure token to authorize it (that's not feasible for obvious reasons).
Testing BeyondTrust deployment on Mac OS Sequoia. I also tested this on Sonoma, and ran into the same problem. I'm using the install script from BeyondTrust, and their recommended PPPC Configuration Profile. The installer appears to run successfully, but I am getting a pop-up asking for permission to copy the .app file to the Applications folder. Is there a change I can make or a security setting I can adjust to allow this app to copy to the applications folder without the user needing to click allow?
I'm surly missing something simple. I am trying to update the Adobe CC and Adobe Acrobat (with CC) packages in JAMF. They keep failing with the response being to contact the vendor, and the install log is saying there was an error with executing the packages scripts. Downloading the downloader for a managed package from the Adobe Admin CenterDoing all the random steps to download the package with the adobe package downloader app that comes in the .dmgUploading the install.pgk to JAMF (JAMF auto zips the file when uploading)Putting the install.pkg.zip in a policyTrigger the policy and fails every time.If I run the package locally on the device it works like a charm. Before I break down and put the installer pkg in a pkg and run it with a script, does anyone have any idea what I missed?
Any one notice if you install Self Service+, it re-triggers enrollment complete / first time login policies?
We are pushing a configuration profile to users. So far 1800 machines have completed but there are 450 that still show pending. In this list there are some machines that show pending but when I go to management history for a few of the pending machines it shows that the configuration profile completed but it does not show up in completed. Is there a way to fix this so that we can have a more accurate reading on machines that are actually pending/completed.
Hi, I have been asked to disable the telemetry on Rancher Desktop for deployment in our fleet, and was hoping someone might have done this, or had some insight as to what would be the right way to do it. you can pull the settings and i can see the flag i need to change, but my json skills are not my strongpoint... I know this needs to be changed to False "telemetry": { "enabled": true } https://docs.rancherdesktop.io/references/rdctl-command-reference/#rdctl-or-rdctl-help Any suggestions would be welcome
I've spent some time researching where these options are actually stored, and found them in all locked away in /private/var/root/Library/Preferences/com.apple.CoreBrightness.plist This file is editable by all users, as it simply stores the current display tone and brightness settings. The only trick is, this file is only read at startup, so editing it does require a restart afterwards. For our computers labs and classrooms, we simply run this script at every login. That does mean, however, that if someone changes the display settings, it takes two restarts to get them to go back to our desired default settings (if someone can figure out what service or process to restart to force the preferences to update, that would be great, but for now, this solution is working for us). Update: I have discovered that in order for this to work, you also need to have opened and closed System Settings. I will be working on finding a way around that. For the time being, we
I am using the Make Me an Admin : https://github.com/jamf/MakeMeAnAdmin I'm having 3 questions/concerns:• It is not reliably creating a log?• Is there a way to get the log to me or at least a notification that the policy was run?• Is there a way to block them from creating additional admin accounts while they are an admin? Thanks!
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!