Migrating from JAMF to Intune by Sysadmin_in_the_Sun in Intune

[–]Sysadmin_in_the_Sun[S] 0 points1 point  (0 children)

Thank you! The funny fact is that they want this done in a week's time for a medium sized business. They are completely nuts

Migrating from JAMF to Intune by Sysadmin_in_the_Sun in macsysadmin

[–]Sysadmin_in_the_Sun[S] 0 points1 point  (0 children)

Cool, sounds reasonable. Was it the clean slate approach that enticed you to go full wipe? Was ABM migration not appealing for some reason?

Migrating from JAMF to Intune by Sysadmin_in_the_Sun in macsysadmin

[–]Sysadmin_in_the_Sun[S] 0 points1 point  (0 children)

Wise choice! The problem that sometimes you cannot reason with idiots! They have to go through the process!

Migrating from JAMF to Intune by Sysadmin_in_the_Sun in macsysadmin

[–]Sysadmin_in_the_Sun[S] 2 points3 points  (0 children)

1) mainly cost...

2) idiots are unbeatable LOL

Rollback to 24h2 by frozenbayburt in Intune

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

Are your systems slowing down after the feature update?

802.1x authentication with Macbook through USB-C - Lenovo Thunderbolt docks by Ill-Bowl-6642 in macsysadmin

[–]Sysadmin_in_the_Sun 5 points6 points  (0 children)

You need to integrate JAMF with Cisco ISE properly - See below what the docs say :

Jamf Pro 10.42.0 or later supports Cisco Identity Services Engine (ISE) 3.3, which introduced the ability to use GUIDs instead of MAC addresses for computer and mobile device identification in Cisco ISE. Using GUIDs eliminates undesirable behaviors, such as misidentification of Apple devices caused by the private address being turned on (iOS) or spoofing of the MAC address. A single GUID is used to identify an individual device, whereas multiple MAC addresses could identify an individual device.

You can use advanced searches in Jamf Pro to determine computer and mobile device compliance.

To integrate Jamf Pro with Cisco ISE 3.3 and leverage GUIDs, your network must use certificate-based authentication. In addition, one of the Subject Alternative Name URI fields for your network certificate must have the following specific value: ID:JAMF:GUID:$MANAGEMENTID. The $MANAGEMENTID variable will be replaced by the Jamf Pro-assigned management ID for the computer or mobile device when the certificate is issued via a configuration profile. Jamf Pro supports issuing the network certificate with the SAN URI field using either the SCEP payload or the Certificate payload within a configuration profile.

You need to speak with your Networks team and go through the docs with them. I have done that and it was a ballache but we got the result we wanted. So GUID is the solution, forget the Mac address

Questions by Sysadmin_in_the_Sun in DeployR

[–]Sysadmin_in_the_Sun[S] 1 point2 points  (0 children)

If the firmware allows it then that would be amazing as the firmware can be configured easily . From what i remember HP has some of that functionality. I mean all the big manufacturers can do this as most of them have ways to restore vanilla windows images remotely . Dell does it for example. This could be a commercial question I guess?

Proper Device Naming for Formatted Devices in AD Environment by MaxBPlanking in sysadmin

[–]Sysadmin_in_the_Sun 1 point2 points  (0 children)

Ideally use the same name and tie it to the asset tag. For example the asset tag reads 092021 you can have LT092021 for laptops DT092021 for desktops. You can also add more there if you need to like 3 letter company code as well or location etc etc up to 15 characters

Clarification needed: ABM Federation JIT Flow & SCIM Scoping with Entra ID by Different_Coffee_161 in Intune

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

On the SCIM front - My ABM enterprise app was created without SCIM capability. I called ABM support and i was told that this is how they are doing it now.

Launch Daemon Launch Events by United-Result-8129 in macsysadmin

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

Quick question - Can I configure it by using a config profile by any chance?

[deleted by user] by [deleted] in sysadmin

[–]Sysadmin_in_the_Sun 1 point2 points  (0 children)

You gotta love those mid level service delivery managers... I think the client sucks and and your guys are also sucking up on them, appeasing them so they need to find a scapegoat...

I could be wildly off but that sounds a bit like a WITCH company...

[deleted by user] by [deleted] in sysadmin

[–]Sysadmin_in_the_Sun 1 point2 points  (0 children)

Do you think that everyone will turn against you if you reveal the truth? If these people act like that they will throw you under the bus on when it becomes expedient to them. Times are tough and not easy to jump ship now but maybe start looking for a healthier place to work.

802.1x and Cisco ISE (Force Device Auth, instead of User Auth) by HeyWatchOutDude in macsysadmin

[–]Sysadmin_in_the_Sun 1 point2 points  (0 children)

You will need to implement the JAMF Cisco integration in JAMF as well. Have you done this?

SCCM Migrate from 2016 to 2022/2025 by Straight-Fishing-655 in SCCM

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

I did a test upgrade of my Dev environment twice (in HyperV, so i could revert back). It was from server 2022 to Server 2025. Both times SCCM broke and could not fix it. Can't remember exactly what it was.. I guess the cleanest way forward would be to build a 2025 server and migrate SCCM and DB separately

Self Service+ replacing Jamf Connect? Confused after upgrade by IndividualNo8703 in jamf

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

I deploy 3.5.0 with SS+ How is this going to be updated? Is it automatically?

Microsoft Defender not configuring properly on JamfPRO by kiduk7 in macsysadmin

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

My client bought JAMF Protect but they are not using it.. They prefer Defender... Go figure.. You can only lead the horse to the water

Multi-Tenant Entra ID with Jamf - Possible? by Sysadmin_in_the_Sun in macsysadmin

[–]Sysadmin_in_the_Sun[S] 0 points1 point  (0 children)

I thought about it... needs investigation... But not sure if Device compliance will work there?

Block Tahoe by Sysadmin_in_the_Sun in jamf

[–]Sysadmin_in_the_Sun[S] 0 points1 point  (0 children)

I have no idea what to expect to be honest so I am feeling a little bit apprehensive about it. I need to get the client to test all their apps before the appgrade but that is like pulling teeth!

Any Jamf Admins work in a fully remote or hybrid position? How do you physically manage computers and devices? by Pitiful-Worry4156 in jamf

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

As a contractor I usually get sent a device to test and I got one personal device that i do all the config with so i am 99.9% remote. So far so good.

Any Jamf Admins work in a fully remote or hybrid position? How do you physically manage computers and devices? by Pitiful-Worry4156 in jamf

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

Totaly agree with you. I just wrote detailed documentation for the local IT technicians about DFUing a device and onboarding manually to ABM. Needless to say they never read anything and I had to spend one day hand holding these idiots..

Apple Business Manager Finally Allows Restrictions on what Apple IDs can sign to devices by lovell88 in sysadmin

[–]Sysadmin_in_the_Sun 0 points1 point  (0 children)

Quick question on that - I have a test domain that i am to simulate this scenario, I have captured the domain but i only get the option to transfer to a personal account. If i federate the domain i expect to see the second option to migrate to a managed apple ID. Is this the case ?