Get Support
Recently active
Hello, we have a lot of iPads for a special use case. Therefore the devices are very restricted. We are using a configuration profile with a home screen layout and restrictions for Apps.We restricted many apps and especially we are using the function "App usage" with "Only some apps allowed". Since iOS 18 it's no longer possible to send a document via Airdrop to this device. The sound of reception is heard but no notification appears to allow the document. The status on the other device which send the document is "waiting".It works again, if I remove the function "app usage" from configuration profile. Is there any option to add AirDrop or the notification to "allowed apps"? Or is there any other workaround to use this function with AirDrop? Best regardsFabian
Hello, We are going to use Jamf Security Cloud (Radar) on our macOS devices.We will not be using the ZTNA part.I still haven't understood if the Jamf Trust application is really necessary if we are not using ZTNA and, if it is necessary, what does it bring? Thank you for your help.
In the release notes from December 10, 2024, I noticed the following update: Changes and Improvements You can now download audit logs in CSV file format by clicking Export on the Organization > Audit log page or by using the GET <domain>/audit-logs/v1 endpoint. The endpoint mentioned here (GET <domain>/audit-logs/v1) seems to follow a different structure compared to the existing APIs: • API v1 uses: https://{yourDomain}.jamfcloud.com/endpoint • API v2 uses: {yourDomain}:443/apiv2/v1/endpoint I couldn’t find any reference to this new endpoint in the API documentation, except for the release notes and a brief mention in the Audit Log documentation about the new Export button. My questions are: 1.Which API version does this new endpoint belong to? 2.How should this endpoint be addressed (full URL structure)? 3.Are there any additional details or headers required to access it? Some changes in the Access Right Role? Any clarification would
Is there a fix for Webclips and shared ipads. Currently it is only possible for single user only.
Greetings all, We are migrating from our on-prem Jamf Pro to the cloud product. We are working with Rocketman Tech as consultants, and with Jamf Support of course. I just wanted to hear from anyone who has gone through this transition as to things to watch out for, possible problem points, things you would do differently and so forth. Our "lift and shift" date is January 21, 2025, so we are definitely approaching the critical point in the process. Any thoughts or comments would be greatly appreciated.
We are currently seeing minor updates being deferred even though there are no restrictions on them. There is a major OS Deferral set for 90 days and enforced and no other settings. I thought maybe it may have been the Jamf configuration profile, so I configured just the settings manually but same issue appears. If I disable the configuration profile completely, all updates show Deferred: NoThere going to be no major release until the end of the year so its safe to disable the policy for now but would be great to get an understanding on why this is occuring.
My organization is looking to rely less on local admin accounts. We mainly use admin accounts that exist in our IdP (Okta) to preform any tasks that needs hands on elevated permissions. We do have a managed admin account set up with LAPs to rotate a password, but prefer to avoid that if possible. The issue we run into if one of our admin accounts does not already exist on the machine we can not simply enter credentials if it needs elevated permissions. Is there a way, or has anyone made a script to prompt the Jamf Connect log in window if a user is already signed in? Something where this would create a user similar to a Windows experience with a UAC prompt.
I never configured a separate patch policy for Jamf connect I just went into Settings--Jamf Apps---Jamf Connect and have the Automatically Deploy and Update Jamf Connect configured. Currently it shows the latest version and Minor\\Maintenace is selected. I notice that for some reason I only have a handful of devices that are on the current release and the others are on various older versions. What triggers Jamf Connect to upgrade? Where would I see why it is failing
We're looking at our options for patch management/app updates. Many of our apps are available in either the Mac Store or Jamf store so we could just use automatic updates. Is there a best practice? Is it better to use automatic updates or use patch management?
My district uses Jamf School to manage iPads. We set wallpapers for each school and prevent students from changing the wallpaper. Students found a couple of loopholes in iPadOS 17 that allowed them to change the wallpaper (via Focus and by setting a picture from the Photos app as background). These loopholes are resolved, but some of the iPads still have the wallpaper students set. The wallpaper hasn't reset to the assigned wallpaper after checking in or after reinstalling the profile that sets the wallpaper. For some iPads we've tested, we can only get the wallpaper to reset after erasing the device. We can continue to erase iPads as needed to correct this (most could probably benefit from this anyway), but is there another solution we could try to force the wallpaper back to the assigned wallpaper?
I don't know if this is possible, but does anyone have a way to create a smart group where the operating system has done a major version upgrade in the past 24 hours? I'm prepping for a Sequoia rollout and want to have some idea of which machines upgrade each day. I use an erase-install Self Service process for the upgrades but the policy never technically finishes as it gets killed when the Sequoia installer restarts, so I can't rely on policy logs.
Did anyone had luck getting Accessibility to "allow" for Microsoft Teams application?Tried using PPPC and allowed Accessibility for Teams but its not working. As a standard user, I'm not able to allow it.can anyone help to fix this.
Today we are releasing Jamf Pro 11.13; highlights include: Admin SSOAdministrators can use Admin SSO as a single sign-on (SSO) method to log in to Jamf Pro. Admin SSO, configured in Jamf Account, allows you to use a centralized configuration for each Jamf product instead of separate single sign-on integrations. Admin SSO allows you to log into Jamf Account using either a cloud-based identity provider (IdP) or your Jamf ID. Self Service+Self Service+ is an enhancement to the Self Service end user application for macOS that allows users to access content and updates that have been preconfigured in Jamf Pro. Using Self Service+, end users can now view security status via the home screen's Security dashboard if Jamf Protect is installed on the device. For additional information on what's included in this release, review the release notes via the Jamf Learning Hub. See the latest release notes video for a brief overview of new features and enhancements. To access new versio
We hare looking at setup manager to replace our Depnotify config as its not supported any more. We have setup an HTTPS distribution point on an IIS server with anonymous share access added the signed setup manager pkg, uploaded the manifest file to jamf and setup the prestage enrollment package to deploy setup manager. Setup manager launches and starts configuring and trying to deployment packages When trying to deploy packages (from another HTTPS distribution point with authentication required) the deployments fail. Is this the case that all packages you want to deploy with setup manager need to be setup on an anonymous share accessible to all? meaning licensed software can be downloaded by anyone that knows the URL (on campus at least) Maybe I am missing something but this seems like a bad idea? When I do enable anonymous share access and set authentication type to none on the distribution share the packages deploy.
Hi Everyone,After upgrading the operating system to Sonoma, I noticed that I could not see the Profiles section. I see the message in the screenshot below. Has anyone encountered this situation? Does anyone know the solution?
Afternoon All So Im going through a process of removing a reduant local admin account from our fleet.It most cases I have been able to pass the secure token from one admin account to another admin account which I know the password for. This has worked in most cases.I assume there isnt a way to remove the secure token from that admin account only which then would alllow me to remove the admin account.I confused by most of these machines have another secure token user however they are not admin. Just trying to get my head around why I cant remove the admin account if another account also has a secure token. Machine in some cases have Filevault turn on and we do us jamf connect.Thanks
Hey, Macos 15 (and IOS 18) add support for controlling Safari extensions enablement using DDM - https://developer.apple.com/documentation/devicemanagement/safariextensionsettingsIs it supported on jamf already? didn't see anything about it in the recent release notes. If not, any plan to add jamf support for this configuration anytime soon?
We deploy our updates monthly and use autopkgr or installomator to install the updates. It seems we always have issues with Adobe Products updating. There is always a handful of devices that it fails to install on. I was using a script to check it was open and then close it and that seemed to help a little. These devices are getting other 3rd party updates just fine. When I go to the policy log, it shows the below. Executing Policy Update Adobe Acrobat Downloading Adobe Acrobat DC-24.005.20320.pkg... Downloading https://xxx.jamfcloud.com/jcds/downloads/Adobe%20Acrobat%20DC-24.005.20320.pkg... Verifying package integrity... Installing Adobe Acrobat DC-24.005.20320.pkg... Installation failed. The installer reported: installer: Package name is Adobe Acrobat (24.005.20320) installer: Upgrading at base path / installer: The upgrade failed. (The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. An error occurr
Our infrastructure is team is doing a bunch of upgrades to our PKI infrastructure. They are setting it up to have redundancy with different hosting sites. They are exploring putting Multiple the NDES severs behind a VIP but we are not sure if we will run into any issues. My thought is as long as the various NDES servers provide valid certs it should be accepted by our NAC ClearPass. Has anyone tried this or have experience with it?
When I try and remove Cisco AMP version 1.14.0 or newer the way I would with pre 1.14.0 version by running the uninstaller package in /Applications/Cisco AMP (now moved to /Applications/Cisco AMP for Endpoints) the user gets prompted for admin credentials. I've even tried running as root on the command line like I did before: /usr/sbin/installer -verbose -pkg /Applications/Cisco AMP for Endpoints/Uninstall AMP for Endpoints Connector.pkg -target / but it still prompts. I've also looked at the steps listed here https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/216232-manual-uninstall-procedure-for-amp-for-e.html to manually uninstall but again there are some steps which produce the prompts: /Applications/Cisco AMP for Endpoints/AMP for Endpoints Service.app/Contents/MacOS/AMP for Endpoints Service deactivate endpoint_security Enter password when prompted. For macOS versions 10.15.5 and newer: /Applications/Cisco AMP for Endpoints/AMP for Endpoints S
We have a requirement where users need to enable/disable the Automatic Proxy Configuration without requiring admin credentials. From the developer documentation, I found the "object NetworkProxyConfiguration.Proxies," but I am unable to modify it via a script. Could you please guide me on any alternative methods, such as using a configuration profile, to achieve this?
We have created Sites in our Jamf instance and are now planning to delete all of them. Before proceeding, I would like to ensure that none of the sites are currently being used by any policies, groups, or configuration profiles. Could you suggest the best way to gather detailed information on their associations?
Is anyone having issues packaging the additional content for Logic Pro X 11?I've tried twice, and my normal method isn't playing ball.In short, 'Composer' a whole installation, Also move related receipts to /Library/Receipts and add that to Composer. Build the PKG, PKGchunk up the 60-80GB file, upload and test deploy.If I remember correctly, the Logic Pro X 10 receipts used to appear in the users library and had to be moved. Now they're arriving in /Library/Apple/System/Library/Receipts - this seems to be a protected location. Any sudo ditto commands to that location result in 'Operation not permitted'.Anyone had any success getting Logic to register all the installed content?
Hi,I'm wondering if iBeacons are still a thing as they don't appear to have any effect on devices, no matter what policy is set.Documentation refers to Location Services and the Self Service app but the Jamf Self Service app doesn't appear to have any hooks in to Location Services and permissions can't be set for it.Were iBeacons something that Apple created but are now deprecated? Is anyone actually using them in 2024? If so, how did you manage that?!
Hello friends,I have recently deployed Forticlient version 7 through a package and then a policy, however, it is installed on the computers but appears blank. Does anyone have a solution?
Earn a cool badge and Jamf Nation Reward Bytes for your published articles. We’re looking forward to your submissions!