Get Support
Recently active
Morning, just installed the self service+ as per Jamf instructions so, downloaded .pkg, created a policy and deployed it on my admin machine as a test. In terminal i ran the command sudo jamf policy and it did install however, i got the following error shell-init: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory job-working-directory: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory shell-init: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory job-working-directory: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory shell-init: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory job-working-directory: error retrieving current directory: getcwd: cannot access parent directories: No such file or directory shell-init: error
With Jamf Pro 11.14, utilize new additions to the Jamf Pro API in scripts for automation and use the SCEP payload of a computer configuration profile to deploy certificates with the Active Directory Certificate Services (AD CS) Connector! Be sure to check out the Jamf Pro release notes for all of the exciting new features and enhancements. Thank you for your continued support and feedback! Learn more here!
Anyone here using the new Jamf Remote Assist? I’ve gotten it to work a few times but it always fails now saying the cmoputer is not registered. Then when I click the "Reregstier App button", the installation of the Jamf Remote Assist PPPC Profile always fails. I realize the feature is in its infancy, but would still like to leverage it.
Hello everyone, still a beginner with the 14 days trial. I know what I want but I don't know how to archive that. I would like to give out a device and the user logs in with his MSO365 account. (name@comapny.com) So the device gets entrolled to "his name". - Cloud Services connection is on. - Cloud identity provider is configured with our Entra ID. The test shows I can search for users and groups and see if they are part of a group How do I need to proceed to get the users in Jamf Pro? Thanks a lot in advance.
Hello - we have iCloud accounts disabled for our staff. However, many of them would like to use Apple Music as a quality of life issue, and some have a longstanding workflow of purchasing music from iTunes for work functions. In my restrictions profile I have "allow Apple Music" checked, however, in my testing I still cannot log in to either Apple Music with a subscription account, or even the iTunes section of the app. Is there a way to enable Apple Music and iTunes for users without enabling iCloud accounts? Thank you!
I've originally written this post to my Github. Overview This document examines critical implementation challenges with Jamf Pro Computer Configuration Profiles, specifically focusing on the Restrictions Payload deployment mechanism. Three key issues have been identified, along with potential solutions and important operational considerations for organizations to implement while awaiting platform updates. Key Issues 1. Legacy Configuration Format The Jamf Pro Restrictions Payload for macOS devices continues to use an outdated deployment format, diverging from the modern "include/don't include" approach implemented in other payloads. This legacy system requires explicit value assignment for all available keys, forcing organizations to make decisions on settings they may prefer to leave unmanaged. When viewing the Security and Privacy Payload, we can see Jamf implemented the modern approach of "Include/Don't Include" In this example, Password Change is included and re
Trying to find a simple solution to give me the IP address of an ethernet connection to a mac, if its through a USB-C adapter or a docking station. Most of the macs stay connected to our wifi, and the service order usually puts that first so the built in jamf reporting is always giving us the wifi IP. I would like to create an EA to give me ethernet... (even if there isnt one and the computer is only on wifi thats fine, it can report "none" or nothing.)
Back again with some more goodies. Modified the script from https://mostlymac.blog/2021/06/09/using-a-self-service-policy-to-grant-end-users-a-secure-token/ to put a nice Swift UI interface on it and some GUI feedback on the process. Code is here: https://github.com/ScottEKendall/JAMF-Pro-Scripts/blob/main/GrantSecureToken.sh and here are some screenshots: and if successful: and if any failures occur:
We upgraded our on prem Jamf Server from 11.1.5 to 11.13.1 and after that when open Self Service is says "Self Service Cannot reach a JAMF MDM server".When I download a new Self Service from JAMF I just got version 11.1.3?
Hi, I want to enable set time zone automatically using your current location radio button on system settings for all my org Mac on bulk. How do we get it, I want all the Mac date and time settings to be like it is on this image.
Hello all, I was having trouble setting the date and time automaticaly for jamf pro, i cant seem to find an option for in the config profile is there something im missing?
We have a lot of users who aren't updating Chrome. How are you enforcing updates and relaunches to apply the updates?
Morning AllGearing up to role out Adobe 2025. Does have anyone have an EA which would show if a machine has no Adobe installed.I have done this using smart groups before, but gets a bit complicated given the amout of Adobe packages we push out.I already have script to remove Adobe, I was thinking I could then use the EA to build a smart group of machines with no Adobe installed.Thanks
Hello, We are experiencing an issue with creating a pkg using Composer from a Sequoia machine. We don't have this behavior when generating a pkg from a Sonoma machine. When we create a pkg containing a .app, for example, without anything else, no scripts, once the package is created, we can no longer open it with Composer because it gets stuck at 30% during the "converting xxx.pkg to source" phase. We have verified that Composer has full disk access in the macOS system settings. We tried deleting the /Library/Application Support/JAMF/Composer folder, but the same problem persists. We are using the Flat Package option and "automatically detect executable types" in Composer. There are no problems with dmg files. Have you encountered this type of problem before? Thank you for your help.
I am looking for a way to remove a firmware password via JSS policy. I work for a school district and we try to lockdown the computers so that the student don't have access to the recovery panel amongst other things. The problem is that there seems to be an issue with at least one of the computers not recognizing our firmware password, so we have no access either. Is there a way to do this using the built in policy (under accounts), or am I going to want to write a script based on the firm passwords article? Possibly helpful information:MacBook Airs (Mid-2011)Lion 10.7.4 and some 10.7.5current JSS 8.61
Hi All One question. We have some iPads with the yellow message in the Jamf at iPad details "Inactive.....". And the iPads don't get any changes over the Jamf, some new profile, App update and so. Happens it, if the iPad are to long offline and don't can be called up the infos with the Jamf School Server? Problem are, the Teacher can works further but does not realise, that they iPad don't communicate with the Jamf School Server. Is it possible to allow trustworthiness, if we download the "Supervision Identity" file over Jamf School and load it over an Apple Configurator to the iPad? Thanks Peter
Hello !I made a smartgroup for macOS greater or equal to 15 Sequoia. It should be simple:Criteria: Operating SystemOperator: matches regexValue: ^1[5-9]I have NO computer running Sequoia, but I have 3 results. 3 Intel computers with macOS version 10.14.6 (2 of them) and 10.15.7 for the last one.I searched all around and can't find where is the problem. I'm not really used with regex, but this one should be simple.Any help is welcome
Hi all, I am trying to push Software Updates to a smartgroup, but this doesn't seem to go through; I tried many options (Download only, Download and install, Download and schedule to install ecc.) but nothing seems to work. This is happening on Apple Silicon device. Having a check on the device > History > Operating System History, I see the Software Update failed and the error message: "AppleSiliconNoEscrowKey". Running sudo profiles status -type bootstraptoken I see the token is supported and is escrowed, and while running sudo profiles validate -type bootstraptoken I see the token has been obtained from the server and is validated. I am sure I am missing some basic checks, but can't find what. Has anyone had the same issue?
Noticed this morning we have a machine that logs say MDM Renewal was completed, but since then the machine is no longer MDM Capable. Any easy solutions?
We're using Jamf Now for an acquisition business (already use Jamf Pro). We've just enable Volume Purchasing in Jamf Now and started to populate with Apps purchased through ABM. However when launching Self Service on a test iPhone enrolled into Jamf Now we get the message:"Welcome to Self ServiceSelf Service is a component of Jamf Pro, developed by Jamf. This app must be associated with a Jamf ProServer.Contact your IT administrator for more information" Specifically referencing Jamf Pro. Now, we've seen this error before in Jamf Pro (think it started on V 11.1) and we use an App Configuration to fix this, but there is no option to create an App Configuration in Jamf Now, as well as there being no URL to place into the string for the App Configuration. Anyone know what the fix is here?
Hi! Please! I'll need to know what SQL syntax I need to run in the Mysql database to get the scope (and also exclusions) of profiles and policies. Thank you very much
Hello! I use my own Connectwise Control agent as my main source of remote support for clients. As you all know, since the Catalina update, Screen Recording and Accessibility permissions have been denied by default for most remote control applications, requiring someone with administrative credentials to sign in and permit the use of both categories to the application. I was hoping to find some way via a shell script (or otherwise) to force-allow these permissions to all computers in a policy. Just a little disclaimer: I do not use Jamf as my MDM platform for computers. If there are any solutions from within the Jamf platform please feel free to share them so I may attempt to replicate them on the platform I use though. I've seen a few articles posted on various platforms but they all relate to prompting users to allow permission. Any help, pointers, or references to other helpful articles would be much appreciated. Thanks!
Hi everyone, I was hoping anyone could help me out. We keep having the same issue where teachers enable restrictions on their classes, and when they select to end it at the end, a couple of students stay restricted... We need to go to the jamf school instance and disable the restrictions manually from there. We are all using same model devices, same network and bluetooth enabled. This clearly is a disruption for our students since they either need to stop at the IT office to have their device unrestricted or wait for the restriction time limit to expire.
Hi all!I have been tasked with installing Kaseya VAS through Jamf Pro at my agency. I want to avoid the why question, cause I know you will feel the same way I do!When I try to create the package in Composer with a snapshot, it will create the pkg, but with my personal machines settings, which means it will show up as my MacOS devices in the Kaseya back-end for every machine that I run this pkg on. Meaning that a user named Mike will still show on the back-end as being on my personal machine.When I download the Kaseya agent from my VSA site, I get a file with the agent application, and the items needed for installation (plist, cmd, exe). Now, I imagine that the agent installation application is just some script or wineskin to run the exe for install.I have been dealing with this for a month now, with no movement from Kaseya support, and it is driving me nuts!!! Any ideas? Thanks a bunch for taking a look!
When we open a policie and look at the logs which computers are completed or failed the button under actions called details is not working anymore. The button next to it called flush i functioning just fine. Does anybody noticed the same problem ?? we are using jamf pro cloud and i got some mails that there was a update so not sure if it has anything to do with that.
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!