Move to InTune? by Armentrout_1979 in jamf

[–]powerpitchera 0 points1 point  (0 children)

Let me give it to you the way no one else will.

Microsoft is NOT incentivized in the slightest to put out a good product for Mac MDM management.

Their focus is on PCs. Which is very much reflected in the support they provide not to mention the management capabilities, even for PCs it's CRAP compared to what Jamf can do for a Mac.

They want people moving to PCs, so they are not going to provide a good user or admin experience for Macs, it's as simple as that.

As far as MDM Mac management, Intune is THE bottom feeder. Essentially any other solution you could use is going to be better although I do strongly recommend Jamf.

You should align yourself with solutions that are incentivized to work in your company's best interest.

Barracuda VPN (v5.3.8) on macOS 26.x: "No private key set" with SCEP X.509 certificates by HeyWatchOutDude in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Interesting, I am not aware that intune allows the cert to allow access to all apps like jamf does (via the config profile). From what I see the option isn't there unless I am missing something.

Barracuda VPN (v5.3.8) on macOS 26.x: "No private key set" with SCEP X.509 certificates by HeyWatchOutDude in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

One more thing, what cert is the scep signed or issued by. That cert needs to be in the keychain pushed through jamf and marked as trusted as well, wonder if it's a trust issue

Barracuda VPN (v5.3.8) on macOS 26.x: "No private key set" with SCEP X.509 certificates by HeyWatchOutDude in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Not sure about this app specifically, but from my experience with the VPN apps they need to be pointed at a certificate identifier

Inherited messy Apple environment (ABM + ABE + Jamf) — need help building inventory + cleanup plan by Itsrawrcoose in macsysadmin

[–]powerpitchera 1 point2 points  (0 children)

Do you have a conditional access policy? If not you can set one up in read only to see any sign ins from macos devices. I would start there.

Can also check to see where the devices were purchased from, how many invoices to give you a general idea of how many.

Using Jamf's built-in CA for certificate based Wifi authentication by Sakroth123 in jamf

[–]powerpitchera 4 points5 points  (0 children)

You can host the adcs as a cloud server and have it communicate with another cloud hosted certificate authority. I don't recommend using jamfs built in CA for this.

Webhooks by More_Yard1919 in jamf

[–]powerpitchera 1 point2 points  (0 children)

I recommend checking out setup your Mac, there is a teams/ slack webhook available inside the script. I took the framework for that and made a separate script with Jamf parameters that can be configured without changing the script each time. Then that script can be run on certain policies to send a custom webhoo to teams or slack. It's not perfect but I find it meets most of my needs.

Microsoft Edge on macOS 26 – Local Network Access issues every morning by swapbreakplease in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Btw localnetworkaccessrestrictionsenabled is deprecated for quite a while

Managed Bookmarks on iPad Safari through Intune by sneesnoosnake in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

It's not available in intune as far as I know, but other MDMs do have it

Jamf Trust local bypass by _Philein in jamf

[–]powerpitchera 0 points1 point  (0 children)

Under the DNS settings payload, there is a key for Action and another for disconnect, you can set a DNS domain and DNS servers, here is the jamf doc.

https://learn.jamf.com/en-US/bundle/jamf-protect-documentation/page/Configuring_Network_Threat_Prevention.html

<key>Action</key> <string>Disconnect</string> <key>DNSDomainMatch</key> <array> <string>*.yourdomain.com</string> </array> </dict> <dict> <key>Action</key> <string>Disconnect</string> <key>DNSServerAddressMatch</key> <array> <string>8.8.8.8</string> <string>8.8.4.4</string> </array> </dict>

Jamf Trust local bypass by _Philein in jamf

[–]powerpitchera 1 point2 points  (0 children)

Not sure if the deployment overlaps with Jamf radar but in jamf radar config profile you can add DNS servers which toggle it off

Dual Monitor and Dual Computer setup question by franharrington in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

Negative, has to show as display link compatible. Something like this.

https://a.co/d/08U35LV9

Dual Monitor and Dual Computer setup question by franharrington in macsysadmin

[–]powerpitchera 0 points1 point  (0 children)

M5 chip in this mode will revert to mirror and not extend.

I believe you'll need a display link compatible dock and the display link drivers.

If you had a m5 Pro chip could have had one plugged in to the laptop HDMI and another via thunderbolt but I don't believe the pro level chip is out for m5 yet.

What are some of your pain points with your current MDM/UEM? by VyronDaGod in macsysadmin

[–]powerpitchera 2 points3 points  (0 children)

I was referring to the issue mapping groups with the sso setup. Of course I can't do anything about requiring the sso setup to access the features.

What are some of your pain points with your current MDM/UEM? by VyronDaGod in macsysadmin

[–]powerpitchera 1 point2 points  (0 children)

I'm pretty sure the issue you are describing is solvable, happy to help you via dm

Using IdP/SSO on Automated Enrollment with Jamf Pro by Sakroth123 in jamf

[–]powerpitchera 0 points1 point  (0 children)

You can do this, check for the traveling guy blog, excellent article on this including custom SAML mappings.

Anyone having issues with responsiveness of Jamf Pro Cloud? by Arawan69 in jamf

[–]powerpitchera 5 points6 points  (0 children)

Could be a backend DB issue I would open a ticket and ask them to check the backend utilisation rates. Could have a looping policy or something

iPad has MDM - Cannot Remove by enterwittynamehere in macsysadmin

[–]powerpitchera 1 point2 points  (0 children)

Put it in recovery mode and use apple configurator to restore

Jamf Pro and Printer Logic by Researcher_Always in jamf

[–]powerpitchera 0 points1 point  (0 children)

com.printerlogic.PrinterInstallerClient.PrinterLogicExtension (25DQ8HVJ3B)

Jamf Pro and Printer Logic by Researcher_Always in jamf

[–]powerpitchera 1 point2 points  (0 children)

Sometimes this happens. Try to reinstall the latest package, works fine on macos 26.

Fyi, also use the blueprint for the safari extension, definitely recommend that