Get Support
Recently active
We’re using JAMF Connect to manage our logins for our school iMac lab, and we’re having a bit of an issue with students changing passwords. I understand that if their network login is changed, they are prompted to enter their most recent local password to sync them up. The trouble is, students typically only have their network password changed if they forget it, meaning they effectively become locked out of that particular iMac.I was thinking that if I can detect which accounts have mismatched passwords, I could write a script to remove the local profile entirely, and allow the student to log in with their network password again. Does anyone know of a way to detect whether or not an account has a mismatched password via a script? My initial plan was to read PasswordCurrent from the local account’s com.jamf.connect.state plist, but that variable only updates while JAMF Connect is running while the user is logged in.
I was asked last week to think of some practices as a Jamf Admin that I’ve adopted into my environments that have really helped me out. One of the first things that came to mind was organization practices. Organization is key to keeping a clean environment and can help you quickly identify what is being configured and where. I’ve made some notes on how I like to keep my environments organized with naming conventions and will share them below. Naming conventions will help to keep objects organized, reduce confusion, and help optimize our Jamf Pro platform. As additional policies, configuration profiles, packages, groups, etc. get added to the platform, a consistent naming scheme will provide clarity. The name of any object in Jamf Pro should quickly describe what it does or what it’s for. Each object within Jamf Pro should also be tied to an appropriate category. Keep it simple. Static/Smart Computer Groups &
As part of a broader security baseline effort, my org wanted to know how frequently Edge users were signing into multiple user profiles (spoiler: not often). It was then pointed out that being signed into a "work" account may have implications for Edge's ticket broker service and PSSO in general; browser hardening often includes statements to limit or prevent multiple user profiles. Sharing this EA in case its helpful to anyone else. jq was only included by default beginning with macOS Sonoma (14.0), older versions of the OS will need either a third-party jq (or one of you awk-fu experts to fork this and parse the email). #!/bin/bash # This version now iterates through all Edge profiles and reports the profile and # the email address signed in. If Edge has never been used, this will return nothing. # Since jq is now included by default on macOS we can use that more effectively # then trying to parse the JSON with awk. # Setting IFS Env to only use new lines as fie
All of the installers that are published in App installers have always gone through a validation and testing process before a new version is published to the service however this process has now been strengthened further with our recent integration with the Jamf Threat Labs Malware Threat Database. This recent integration provides even further validation of a particular version of a software by scanning it for signs of known malware using the same mechanisms as our threat researchers, before it can be published to App Installers. Another change that we are about to start rolling out is beginning to replace the mechanism that controls how App Installers actually performs the installation on an end user Mac. The current process is that a team at Jamf sources the media for a software title from a vendor, often having to repackage it so that it can be deployed via App Installers and then it is bundled up with a LaunchDaemon and a notification binary in one package, digitally sign
Hi all, I've discovered that this profile we push to lab machine to disable the requirement for a password when the computer display is turned off is no longer working in Sonoma:<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"><plist version="1.0"><dict><key>askForPassword</key><integer>0</integer></dict></plist>This profile now causes the setting in System Settings>Lock Screen>Require Password After Screen saver begins or display is turned off to be set to IMMEDIATELY.Anyone see this or have alternate solution for environments where we don't want the screen to lock when the display turns off (other than setting it manually?)?
Seems a critical piece in my Apple management arsenal has become severely hindered. Here is a description of what I and others are dealing with:https://www.reddit.com/r/macsysadmin/comments/17n0xw3/sonoma_osascript_via_apple_remote_desktop_not/I have worked with settings within the new “Remote Application Scripting,” but that doesn’t seem to help.This worked previously on machines, 13.6.1, before I upgraded them to Sonoma.Your help in resolving this issue is greatly appreciated.
I'm looking to be able to rename a computer in Jamf Pro (in the web interface) and have it apply on the computer. I've seen others post more complex questions and use a script to rename multiple computers based on other info in the inventory, but we have external asset tags, so we're just gonna go in and manually name the computers using those tags (the tags are plain alphanumeric strings that come from our inventory asset system which get printed onto a barcode sticker that is placed on the computer, but we don't have a way to get that into Jamf). It sounds like it should work to rename a computer using the instructions here: https://learn.jamf.com/en-US/bundle/jamf-pro-documentation-current/page/Renaming_a_Computer.html But I've tried several times, and after saving the name in Jamf Pro and waiting a day, the computer name on the macbook hasn't changed, and the name in Jamf Pro has reverted to the original computer name. Does anyone know if this is expected to work? Are there minimum
I'm gonna show you guys a way that like what I said in the title.First you need to access the Profile Configuration > Ristriction , set Only Allowed some apps , input the com.apple.webapp and click save, then add the Chrome on next line.Then you can add your WebClips as your wish, don't forget use the "googlechromes://" instead of "https://" if you want to use the chrome but no safari like me.Finally, when the configuration profiles affected, the other apps were hidden and only the WebClips were remained.PS: Choose the Fullscreen app in the WebClips, and you can touch the WebClips and directly open in chrome , if you didn't , when you touch the WebCllips , it will open in the safari first and then redirect to the chrome.
On Saturday, March 22, 2025 (previously March 15, 2025), Jamf Cloud Infrastructure will be patched. During this time, you will be logged out of your Jamf Pro instance. The purpose of patching is to ensure that Jamf Cloud infrastructure and the database service are up-to-date, stable, and safe from security threats. Please see the times for our regions below. Hosted Data Region Date Start Time End Time ap-southeast-2 March 21 1300 UTC 1700 UTC ap-northeast-1 March 21 1500 UTC 1900 UTC eu-central-1 March 21 2300 UTC 0300 UTC eu-west-2 March 22 0000 UTC 0400 UTC us-east-1/2 March 22 0500 UTC 0900 UTC us-west-2 March 22 0700 UTC 1200 UTC Jamf Cloud Hosted Data Region Information
Since the initial release of this integration, Jamf and Microsoft have both made improvements to related features and capabilities, which includes additional data complexity and updates to Sentinel to better support it. The updated integration includes support for the latest telemetry data types and includes: A new Jamf Protect integration, available on the Microsoft Azure marketplace. A new section for configuring data forwarding to Microsoft Sentinel, available in the macOS Security portal. For more information, see Setting Up Data Forwarding to Microsoft Sentinel. If you already have Sentinel configured, migrate to the new integration.
Hello, We are enrolling our current iPads into Jamf via ABM and most are working well. I have one staff member that has an iPad that is part of a family plan with their kids. When I wiped the iPad and then restore it using their personal Apple account and restore their backup it never prompts for our MDM profile to be installed and it just reboots continues to restore the backup. The iPad is in prestage enrollment in JamF and I have enrolled it successfully without using the personal Apple family account. Can an iPad that is part of a family plan use an MDM from Jamf and be managed by Jamf? Thank you.
Hello People, While troubleshooting a failed policy deployment I came across this error messageError: Bootstrap token must be escrowed to the Jamf Pro server in order for computers with Apple Silicon (i.e., M1 chip) to use RestartDevice MDM command.I tried manually with “sudo profiles install -type bootstraptoken” but I got this errorBootstrap Token functionality is not supported on the server. My user is an admin and has securetoken enabled according to “sysadminctl -secureTokenStatus”“sudo fdesetup list -extended” also lists my user admin as Volume owner and I have filevault enabled.I can also carry out update on the computer without issues.The laptop operates like a test computer and I have had to enrol and unenrol it multiple times. could that be the cause of the Bootstrap Token functionality is not supported on the server. error?Some information about my setupComputer operates more or less like a test laptop and gets unenrolled and enrolled to jamf multiple times.JAMF Cloud V
Hi, is there a way to push a PDF to a group of iPads in my fleet? So they can access it locally on their device?
After the upgrade to MacOS 12.3, the Jamf login screen went away, i found that running this command would fix the issue : /usr/local/bin/authchanger -reset -jamfconnectAlthough after creating a policy and trying this through execute command i get the following error:LLVM Profile Error: Failed to write file "default.profraw": Read-only file system I tried the command in terminal manually with sudo permissions and it did work. How can i fix it ?
Hi! I have many computers that currently do not have assigned users. Some of our policies rely on the "department" field. Our cloud identity provider is Google, and all of our data is downloaded from it. However, right now, I need to manually go through hundreds of computers to assign users to each one. Is there a way to automate this process?
Hi all,I just migrated from JamfNow to JamfPro and Im very new here. Im addressing computer's name by a Smart Group with a policy to execute this Script, which is not working for me.Basically I want to use the prefix MBP or MBA, depending on the model, following the SN of the laptop. Any advice or help will be highly value. #!/bin/sh# Get laptop modelmodel=$(system_profiler SPHardwareDataType | awk '/Model Identifier/ {print $3}')# Get Serial Numberserial=$(system_profiler SPHardwareDataType | grep Serial | awk '{ print $4 }')# Assign a prefixif echo "$model" | grep -q "MacBookPro"; then prefix="MBP"elif echo "$model" | grep -q "MacBookAir"; then prefix="MBA"else prefix="APPLE"fi # Generate computernamecomputerName="$prefix-$serial"echo "$computerName" # Rename computerscutil --set ComputerName "$computerName"sleep 5scutil --set HostName "$computerName"sleep 5scutil --set LocalHostName "$computerName"s
In MacOS Sequioa, we're seeing that accounts are not showing under Users & Groups, except for the current user. In previous OSs as an admin, once unlocked you typically saw the other users... doesn't seem to have an unlock here. Only way we've been able to see other users is to see if they have a home folder created. We're using JAMF Pro to create some, but not all users accounts. Locally created users also do not appear in the System Settings.Has anyone seen this similar behavior and have suggestions/know how to make all users visible to admins?
Today I have ran into a problem I have not seen in the past. We have been using Jamf Teacher to restrict iPads for awhile now and have not changed anything today with our settings. We are getting a red exclamation point icon next to users names when trying to apply device restrictions now. It is happening when using the app on many different devices, and while attempting to restrict many different devices. Any insight into this?
When going in to a iPhone and utilizing the lock device button in the management tab, device lock seems to be bypassed if the user has a pin or FaceID setup. Does anyone know of a way to get around this so a phone can truely be locked and could only be unlocked by a admin or is this some sort of limitation by Jamf/Apple? Any thoughts on this would be greatly appreciated. I was not able to come up with anything when searching the boards or documentation but could have missed it somewhere
I found this website with what appears to be really good info on how to disable Time Machine. It's dated March 2021, so I tried the first one anyway (Prong 1), and neither the sudo command, nor the MDM Profile work. The sudo command sudo defaults write /Library/Preferences/com.apple.TimeMachine DoNotOfferNewDisksForBackup -bool TRUE returns "Could not write domain /Library/Preferences/com.apple.TimeMachine".The configuration profile got installed on the machine, but after connecting an external drive, I got the prompt anyway. I figure this is old information at this point, but does anyone have knowledge on how to do effectively disable Time Machine in its entirety? I can restrict the app, but what can be done about the popup when external drives are inserted?
I would like to add applications to a users Login Items. But I do not want to add them using Configuration Profiles, as this means the user is unable to remove these applications from Login Items.I want to add them just so that they start up when the user boots the mac or logs in. But if the user doesn't want this, they should be free to remove them again.This used to be possible via Apple Script: App_Path="$4" App_Name="$5" Hidden="$6" /usr/bin/osascript <<EOF tell application "System Events" to make login item at end with properties {Path:"$App_Path", name:"$App_Name", hidden:$Hidden} EOF but it seems this doesn't work anymore.Does anyone have a way to do this?
Howdy... I’ve detected an issue where the Jamf binary stops checking in, this can be for hours, days, weeks or even months. This is evident when Macs have run their Inventory Update for "x days". It would appear that the Jamf binary begins its check-in process but never completes, this stops any further check-in attempts as the process is still running and wont attempt to check-in until the original process has completed. If you attempt to manually check-in you will get a similar error to:This policy trigger is already being run: root 88591 0.0 0.0 34245156 1048 ?? Ss 21Jul22 0:03.85 /usr/local/jamf/bin/jamf policy -stopConsoleLogs -randomDelaySeconds 300I suspect this issue is caused by a network interuption when a policy is running or a script within a policy that cannot complete (the softwareupdated process has been hanging on some versions of macOS Big Sur). There does not appear to be a time-out for the Jamf binary.CasperCheck or the new Jamf-Management-Framework-Redeploy API func
EDIT.. wrong sub group 🙄 should be in JAMF Pro.... where is delete in this thing.. ? 🤔 🤔 Any user can right click on jamf management notifications and 'turn off'.They will not turn back on until reboot.This is.. bad. Have a ticket in with jamf support, but in the meantime.. any thoughts.. iI've had poke around trying to see where this value is stored.. and so far not located.. of course the config profile for this is default from jamf and is locked out to the user.
At it again with some more goodies! Got a revamped GUI version of @robjschroeder excellent bootstrap script. Changed it to be more inline with all of my other scripts that I have written: Code is here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/blob/main/EscrowBootStrap.sh And some screenshots: (1st one is the prompt users will get if they cannot escrow their account) 2nd one is to ask the user to escrow their account Result if it escrows OK... Please be sure to test before you put this into production!
Howdy folks! While people are digging into the shiny new Self Service+ app I thought I'd share a quick way to manage notifications for that app with a simple configuration profile. Why do we need this? The Self Service (Classic) app has the Notifications payload covered in the Security settings for computer management, which deploys Notifications preferences for the bundle ID com.jamfsoftware.selfservice.mac. However, the bundle IDs for Self Service+ are com.jamf.selfserviceplus and com.jamf.selfserviceplus.agent. As of the time of this writing built-in settings for Self Service (Classic) Notifications will not apply to Self Service+. Building a new configuration for Self Service+. One way to create a Notifications payload for Self Service+ is to use the built-in payload type in a Jamf Pro configuration profiles within the Jamf Pro web app. Navigate to Computers > Configuration Profiles and make a New profile. Select the Notifications option and add two payloads,
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!