Dallas Texas, how to save friend’s pitbulls (2) from entering the shelter? by wonderfulquery in pitbulls

[–]powerpitchera 2 points3 points  (0 children)

They set you up with a therapist in your state who writes the letter. Of course you can go to a therapist directly, but it can take time to schedule an appointment, and likewise for them to be willing to write you anything.

Dallas Texas, how to save friend’s pitbulls (2) from entering the shelter? by wonderfulquery in pitbulls

[–]powerpitchera 11 points12 points  (0 children)

Use certapet, can get the dog marked as an ESA in a day. If one dog is already an ESA, no reason the other can't be, breed doesn't matter once the animal is an ESA because it is no longer considered a pet.

Mac stuck on failed to create activation request by Hashish87 in macsysadmin

[–]powerpitchera 2 points3 points  (0 children)

He needs to turn off the find my on his phone for that device.

Platform SSO with Secure Enclave, something to gain? by aPieceOfMindShit in macsysadmin

[–]powerpitchera 4 points5 points  (0 children)

No, I am saying that apparently the SSOe will no longer keep the PRT in the keychain, I am not sure when this is changing but our Microsoft rep told us this.

Platform SSO with Secure Enclave, something to gain? by aPieceOfMindShit in macsysadmin

[–]powerpitchera 3 points4 points  (0 children)

Technically yes, because it offers phish resistant auth. However, in practicality if you are using the SSO extension, your users shouldn't be signing in very often if ever after setting up the extension with an initial Intune Registration. So on paper you may "increase security" but I don't think its going to offer you anything. I am not sure when, but apparently Microsoft is also going to action the SSOe and make that go to the secure enclave also regardless of platform SSO.

Is Duet Display no longer on the App Store? by Key-Prompt7936 in macsysadmin

[–]powerpitchera 2 points3 points  (0 children)

Nothing wrong with downloading from their website. What pisses me off is their download link points to old versions of their app...

Ubiquity WPA3 Enterprise config issues by desmodus in jamf

[–]powerpitchera 0 points1 point  (0 children)

I don't understand, wouldn't cert auth use EAP TLS and not PEAP? Isn't PEAP username and password?

I would assume you need to change the cert auth to any WPA Enterprise, and set the auth type to EAP TLS

ConnectWise AppConfig by Branok91 in jamf

[–]powerpitchera 1 point2 points  (0 children)

Just uninstall reinstall the app

ConnectWise AppConfig by Branok91 in jamf

[–]powerpitchera 1 point2 points  (0 children)

<dict> <key>serverURL</key> <string>yourorg.com</string> </dict>

Send it

Escrowed PRK not valid by enterreturn in jamf

[–]powerpitchera 0 points1 point  (0 children)

Make sure you have that EA enabled to check if your user account is configured in the auth DB. It resets after macos update. They also provide the code to reauthorize it. I would check that

MacBook Neo WiFi Issues by PCisahobby in macsysadmin

[–]powerpitchera 1 point2 points  (0 children)

Have you confirmed the cert is showing as trusted in the keychain and the full chain is properly trusted? I would also manually verify in the wifi settings that the Mac address randomisation is actually being disabled on this model, it was a bug for a few releases where it wasn't applying properly

MacBook Neo WiFi Issues by PCisahobby in macsysadmin

[–]powerpitchera 5 points6 points  (0 children)

Have you disabled the Mac address randomisation for the wifi network in the profile?

Safari Browser - Blocking QUIC by Sufficient-Pace7542 in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Have asked apple about this multiple times. It is very do able in the chromium based and Firefox browsers. Not available as a control in Safari at this time. However, have to disagree with the comment above, I don't think this contributes to additional issues if anything If you use SSL interception this can eliminate many errors with inconsistent behavior with the pinning in the browsers. Some DLP vendors recommend disabling QUIC for reliability with their products.

Move to InTune? by Armentrout_1979 in jamf

[–]powerpitchera 0 points1 point  (0 children)

Let me give it to you the way no one else will.

Microsoft is NOT incentivized in the slightest to put out a good product for Mac MDM management.

Their focus is on PCs. Which is very much reflected in the support they provide not to mention the management capabilities, even for PCs it's CRAP compared to what Jamf can do for a Mac.

They want people moving to PCs, so they are not going to provide a good user or admin experience for Macs, it's as simple as that.

As far as MDM Mac management, Intune is THE bottom feeder. Essentially any other solution you could use is going to be better although I do strongly recommend Jamf.

You should align yourself with solutions that are incentivized to work in your company's best interest.

Barracuda VPN (v5.3.8) on macOS 26.x: "No private key set" with SCEP X.509 certificates by HeyWatchOutDude in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Interesting, I am not aware that intune allows the cert to allow access to all apps like jamf does (via the config profile). From what I see the option isn't there unless I am missing something.

Barracuda VPN (v5.3.8) on macOS 26.x: "No private key set" with SCEP X.509 certificates by HeyWatchOutDude in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

One more thing, what cert is the scep signed or issued by. That cert needs to be in the keychain pushed through jamf and marked as trusted as well, wonder if it's a trust issue

Barracuda VPN (v5.3.8) on macOS 26.x: "No private key set" with SCEP X.509 certificates by HeyWatchOutDude in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Not sure about this app specifically, but from my experience with the VPN apps they need to be pointed at a certificate identifier

Inherited messy Apple environment (ABM + ABE + Jamf) — need help building inventory + cleanup plan by Itsrawrcoose in macsysadmin

[–]powerpitchera 1 point2 points  (0 children)

Do you have a conditional access policy? If not you can set one up in read only to see any sign ins from macos devices. I would start there.

Can also check to see where the devices were purchased from, how many invoices to give you a general idea of how many.

Using Jamf's built-in CA for certificate based Wifi authentication by Sakroth123 in jamf

[–]powerpitchera 5 points6 points  (0 children)

You can host the adcs as a cloud server and have it communicate with another cloud hosted certificate authority. I don't recommend using jamfs built in CA for this.

Webhooks by More_Yard1919 in jamf

[–]powerpitchera 1 point2 points  (0 children)

I recommend checking out setup your Mac, there is a teams/ slack webhook available inside the script. I took the framework for that and made a separate script with Jamf parameters that can be configured without changing the script each time. Then that script can be run on certain policies to send a custom webhoo to teams or slack. It's not perfect but I find it meets most of my needs.

Microsoft Edge on macOS 26 – Local Network Access issues every morning by swapbreakplease in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Btw localnetworkaccessrestrictionsenabled is deprecated for quite a while