- Видео 68
- Просмотров 101 430
Rocketman Tech
США
Добавлен 13 авг 2021
Need help with Jamf? Our consultative process can take over from the first meeting and bring your organization through a comprehensive scoping process to ensure we help you get where you need to go
Rocketman Command Center - Beta Release
🚀 Big News for the LaunchPad Community! 🚀
We are officially opening up a private beta for a product we've been working on several years. But spots are limited! If you're interested in trying out what we're cooking up, sign up for the beta today: www.rocketman.tech/command-center
CHAPTERS
---------------------------------------------------
00:00 Introduction
00:16 Limitations of Shell Scripts
00:58 Challenges Updating Shell Scripts
01:36 Lack of Industry Knowledge
02:07 Rocketman Command Center
02:49 Private Beta
We are officially opening up a private beta for a product we've been working on several years. But spots are limited! If you're interested in trying out what we're cooking up, sign up for the beta today: www.rocketman.tech/command-center
CHAPTERS
---------------------------------------------------
00:00 Introduction
00:16 Limitations of Shell Scripts
00:58 Challenges Updating Shell Scripts
01:36 Lack of Industry Knowledge
02:07 Rocketman Command Center
02:49 Private Beta
Просмотров: 52
Видео
A Deep Dive into Jamf Security Cloud
Просмотров 557 часов назад
Wayne Treadwell, Jamf Sr. Security Systems Engineer is this month's guest LaunchPad presenter discussing Jamf Security Cloud. Remote work and cloud computing are redefining the modern workplace, presenting evolving IT and security challenges, particularly for mobile devices. With the rise of mobile threats and the increasing frequency of phishing attacks, it is essential for organizations to se...
Mass Update Tool (MUT) Tutorial: Streamline Bulk Updates for Jamf Admins
Просмотров 24921 час назад
Streamline device updates like a pro with the Mass Update Tool (MUT)! In this tutorial, we show you how to use MUT to efficiently manage large-scale updates, save time, and keep devices compliant. Essential for Jamf admins and IT professionals looking to maximize their update workflows-watch and get up to speed! For more information about Rocketman Tech, or to schedule a meeting with one of our...
Introduction to Jamf Concepts Video Series
Просмотров 56День назад
For more information about Rocketman Tech, or to schedule a meeting with one of our Jamf Experts, visit our website: www.rocketman.tech CHAPTERS 00:00 Introduction
Setting Up Account-Driven Enrollment in Jamf Pro | Jamf Admin Tutorial
Просмотров 524Месяц назад
In this video, we’ll guide you through the process of setting up account-driven enrollment for your Jamf Pro Server. This step-by-step tutorial will help you streamline device enrollment and enhance your Jamf management capabilities. Perfect for both beginners and experienced admins, this video covers essential tips and techniques to make the setup process smooth and effective. For more informa...
Jamf App Installers & Software Update: Reclaim your Time and Sanity
Просмотров 184Месяц назад
Jamf App Installers have grown up, now supporting plenty of new features. Additionally, it has a new sibling; Software Update! Hear first hand from power user, David Goldberg, how he saves precious time and sanity with App Installers. Adam Derrick from Jamf will also discuss new features and enhancements, along with the future of App Installers. For more information about Rocketman Tech, or to ...
JNUC 2024 Recap: Sequoia, CIS, Blueprints, and Platform SSO
Просмотров 3872 месяца назад
Join us for the JNUC 2024 Recap as the Rocketman Team walks you through the latest updates on macOS Sequoia, CIS Compliance, Blueprints, and Platform SSO with Jamf Pro, sharing our insights and opinions. For more information about Rocketman Tech, or to schedule a meeting with one of our Jamf Experts, visit our website: www.rocketman.tech CHAPTERS 00:00:10 Welcome 00:00:58 Keynote Intro 00:01:33...
We're giving away our Apple Vision Pro!
Просмотров 1122 месяца назад
If you're coming to the Jamf Nation User Conference (JNUC) this year, make sure to make it for the LaunchPad Game Night on the opening night of JNUC! Free food, free tokens, free drinks, and a chance to win our Apple Vision Pro. Sign up today for a chance to win: www.rocketman.tech/2024-launchpad-game-night
Restricting macOS Sequoia
Просмотров 2,1 тыс.2 месяца назад
Are you scrambling to restrict macOS Sequoia today? Watch this quick video as we walk through all the things you'll need to do to catch up! If you're coming to the Jamf Nation User Conference (JNUC) this year, make sure to make it for the LaunchPad Game Night on the opening night of JNUC! Free food, free tokens, free drinks, and a chance to win our Apple Vision Pro. Sign up today for a chance t...
Inside the Mac Admins Foundation: What's ahead for 2024
Просмотров 1663 месяца назад
Tom Bridge and Collin Elliot of the Mac Admins Foundations join us to discuss their 2024 initiatives, including Mac Admin Mentorship, Penn State MacAdmins Sponsorships, Mac Admins Open Source, and much, much more. Sign up for next months LaunchPad: www.rocketman.tech/launchpad Register to win an Apple Vision Pro at the LaunchPad Party at JNUC: www.rocketman.tech/2024-launchpad-game-night Fo...
LaunchPad - Gold Medal Tips from Jamf Experts
Просмотров 2034 месяца назад
This month Rocketman Tech’s Chad Lawson and Chris Schasse will demonstrate their secret strategies for managing Jamf Pro servers by each giving tips and tricks to help you manage Jamf better. Sign up to get notified for future LaunchPad Meetups here: www.rocketman.tech/launchpad For more information about Rocketman Tech, or to schedule a meeting with one of our Jamf Experts, visit our website: ...
LaunchPad - WWDC24 Review for Mac Admins
Просмотров 1844 месяца назад
This month on LaunchPad, Rocketman Tech's Christopher Schasse and Robert Hammen, an Apple Platform Architect in the Aerospace industry give a recap of WWDC specifically for Mac Admins on what to expect over the next year with Apple and Jamf. We delve deep into the WWDC sessions, saving you the hassle! The annual Worldwide Developers Conference (WWDC) hosted by Apple is an essential hub of infor...
Jamf vs Intune - Rocketman Tech's In Depth Review
Просмотров 4,2 тыс.5 месяцев назад
Intune has been investing in updating its macOS Management capabilities, but is it good enough for your organization? In this in-depth review we dive deep into Intune's capabilities, especially when compared to Jamf Pro. A lot of research went into this video. Check out two interviews we did with industry experts: Interview with Simon Binder: ruclips.net/video/fG4N_fJTNh8/видео.htmlsi=paLKrji5E...
Simple Searches with Jamf Pro
Просмотров 3345 месяцев назад
One of the most underrated features within Jamf Pro is simple searches which, despite their name, are not really all that simple, and certainly not intuitive. Learning how this works will greatly empower you to navigate Jamf Pro much quicker! If you want to see how to use Simple Searches plus some Excel magic to do mass updates in your Jamf Pro server, check out this video: ruclips.net/video/az...
Diving deeper into Jamf & Intune with Simon Binder
Просмотров 4925 месяцев назад
Diving deeper into Jamf & Intune with Simon Binder
WWDC 2024 Updates for Jamf and Apple Administrators
Просмотров 5386 месяцев назад
WWDC 2024 Updates for Jamf and Apple Administrators
Why and how to use Erase Install to upgrade your Mac Fleet
Просмотров 1,1 тыс.6 месяцев назад
Why and how to use Erase Install to upgrade your Mac Fleet
Microsoft Intune: Expert Interview with Alexis Johnson
Просмотров 1656 месяцев назад
Microsoft Intune: Expert Interview with Alexis Johnson
Setting Up Intune - Part 5: Intune Review Outline
Просмотров 926 месяцев назад
Setting Up Intune - Part 5: Intune Review Outline
Setting Up Intune - Part 4: (attempting) to Setup Zero Touch Provisioning
Просмотров 1916 месяцев назад
Setting Up Intune - Part 4: (attempting) to Setup Zero Touch Provisioning
Setting up Intune - Part 3: Adding Apps and Configs
Просмотров 1356 месяцев назад
Setting up Intune - Part 3: Adding Apps and Configs
Setting up Intune - Part 2: Enrolling a MacBook
Просмотров 2016 месяцев назад
Setting up Intune - Part 2: Enrolling a MacBook
Setting up Intune - Part 1: Initial Setup
Просмотров 3146 месяцев назад
Setting up Intune - Part 1: Initial Setup
Don't make yourself a cog in your own machine. unless...
Просмотров 1087 месяцев назад
Don't make yourself a cog in your own machine. unless...
Need S.U.P.E.R.M.A.N. to Save Your Jamf Server?
Просмотров 8027 месяцев назад
Need S.U.P.E.R.M.A.N. to Save Your Jamf Server?
Unsure About Jamf's New Onboarding Experience? Check this out!
Просмотров 1,8 тыс.7 месяцев назад
Unsure About Jamf's New Onboarding Experience? Check this out!
Another great video! Definitely going to share this one out. Hope your clothes came out dry!
Thank you for doing this investigation; it would be interesting to have a periodic follow up in which the feature gaps between Jamf Pro and Intune are re-evaluated as both products improve. I was considering performing an investigation like this - but between my limited time and not needing to reinvent the wheel by doing what you've already done, I can focus on winning the argument to keep an Apple specific device management platform in my organization.
Yeah this took a long time to put together, I might make another one in a year or so. In the meantime I'm thinking of doing some interviews with different industry experts to talk about the two platforms.
Thank you Graham for creating this script! I stumbled onto it a few years back and it has been invaluable when managing my small fleet.
Thanks for this tutorial, allot of it makes sense, i found this because we have global users who sometimes have to procure their own devices, can you tell me if by doing this process, this will add the device in this case a macbook to ABM so in the future it will be able to utilize ADE?
No, unfortunately the only way to add the user to ABM is to wipe the device and use Apple Configurator on your iPhone to set it up. Without wiping the device, and without having physical access to the device (or granting your users Device Manager access to your ABM portal) this is not possible.
However, we may want to clarify our acronyms, because although enrolling a user through Account Driven Enrollment will not allow them to use Automated Device Enrollment, this is confusing because they could both be abbreviated ADE
Looking for the talk about the SCEP and ADCS certification audit and reissues to the mac device like expired and reissue and how to audit and fix the missing certificate ecttt
Sounds good - we'll put that on our list! Certainly something we've dealt with quite a bit with our clients.
Account-Driven Enrollment for prez 2028!!!
That was a well put together video, well done. I was wondering if you'd be able to help me out before I create a case with Jamf? I posted on the Jamf Nation community that I had to re-imaged my computer labs from Monterey to Sonoma. I tried to login to one of my laptops this week and found it wasn't accepting my local account admin password. I tried on another laptop and no dice. I did some research and came across LAPS and a guy from Jamf Nation believes this is the case. I noticed that you need Ventura and up for it to work so by upgrading it is now in effect. Here is the kicker, I never turned it on. I checked my jamfinstance/api an under PUT /v2, local-admin-password/settings. autoDeployEnabled is set to false and autoRotateEnabled: false. I also checked Settings:Computer Management: Security and Enable LAPS for PreStage accounts is NOT selected. Yet when I go to a computer Inventory: Local Users Accounts I see View under Password. My account was created in PreStage I noticed yours was with Jamf Binary. The guy on Jamf Nation suggested I erase and re-install. Like you said, yea that's not going to happen. But even if I did, I think LAPS would still affect them. My question is, where else would it be enabled? I want to turn it off. Thanks!
Too bad its available only for cloud members. For others, Installomator is taking care of the job
Make a video zero touch deployment on windows environement
We only work in the mac administration sphere and specifically with Jamf Software.
@RocketmanTech thnx for your reply...
What is better for MacBook and Iphone management. WorkSpaceOne or Jamf ?
Definitely Jamf Pro, I'm hoping to make a video on that soon.
Good info to see it all together. Title is a little misleading in that Jamf also can manage mobile devices, Apple TV, Vision Pro (which is addressed in the video intro). I know the video would be longer, but in the spirit of completeness... it may be also good to compare mobile device management between the two; I don't think Intune can handle AppleTV and Vision Pro yet, even though AppleTV has been out there for a while.
Yeah I agree... I was going to make another video on mobile device management as well but just haven't had time.
Thank you guys missed JNUC but i love you videos. Want to join the meetups in the future . Is there a way to do it?
Yes! You can sign up for our newsletter here, where we will send updates each month about our meetup: www.rocketman.tech/launchpad You can also sign up for our next meetup here: rocketman-tech.zoom.us/meeting/register/tZIkdu6oqjkpGNFgS5ShYPRIGM6Rcfrrtoql#/registration
Great job Chris, thankyou
Hey Chris. Thanks for sharing this. Just one question if i want to re enable users to install sequoia then how do i do that?
Would love to "up" my certification
Just tested this, did not work as it is showing in Software Update with only major updates selected. Will have to make sure to add restriction in the sidebar setting to stop the installer app
Nice old school JAMF shirt....I think I still have one
Use Safe Practices! Supply chain attacks have happened to even the most security-conscious organizations. Caution should be exercised when using this app just as with any content sourced from the internet. Be aware that this application incorporates content from a number of Jamf and non-Jamf sources. Initial implementation of a new process in a test environment improves the chances you’ll catch problems before they can effect something important. Always do a careful inspection of any content uploaded to Jamf Pro before scoping it to user devices to make sure you fully understand what it’s doing. Deploy and test new content gradually, initially scoping it to a small number of non-production test devices, then expanding the scope over time to increasingly larger groups of user devices.
Yes - this is good advice and best practices for all of us.
Awesome giveaway!
Thanks! Are you going to be at JNUC this year?
@@RocketmanTech My company decided not to send me this year but I'm trying to swing it personally, looks like it's going to be a good one!
if you already had a profile that does this, I think you have to remove it first, and then reapply. the timer is one time use (according to jamf) so you have to reset the clock by removing it. Its not perpetual.
In case anyone slips in, Ive already observed Sequoia breaks wifi / radius auth via eap-ms-chap
I had stopped using the Restricted Software record for the past few years because is seemed to stop working. Thankfully, I'm seeing reports on Reddit that it's working for some environments now, so I've added it back. Strangely, we had switched to using a Config Profile with "major updates" deferred for 90 days, but already have about 20 computers that slipped through the cracks. Very frustrating.
We have both the configuration profile and restricted software block in place. For the config profile, our previous engineer set the Defer Updates field to "All software, applications and non-OS updates" for 7 days, with the "Include major software updates" checked with a delay of 90 days. We are less concerned about point updates or other software than we are with macOS upgrades. The only difference I can see between selecting "All software, applications and non-OS updates" vs "Software updates" in the drop-down menu is that the latter lacks the "Set different delay for minor software updates" checkbox. We also include the Software Update payload in the same config profile, enabling everything except macOS beta installs and administrator user only installs. Overall, both the config profile and the restriction block seem to work just fine as-is for us. Even after 90 days, presumably the Restricted Software block should continue to block the Sequoia installer, even though the System Settings app will show the upgrade badge and show the Sequoia entry in Software Update.
Just adding the majorOS block did work for us and as a back up we added the restriction payload as well.
Perfect! Glad it worked!
Thanks Chris!
Glad you found it helpful!
thanks, great guide
Glad you liked it!
Graham thank you for keeping this open source!
When I run the scripts, I end up with 30 failing tests for CIS Level 1. Are they not supposed to fix all of those?
It takes some tinkering, it's not a guaranteed one size fits all solution for all macs
Guess I have not heard anyone choose Intune because it is a good product - they choose intune because it is "free" and part of their MS license already. Price is of course an important indicator - but in larger Mac enviroments, Intune would is really a struggle. If you have few mac´s then Intune could work I guess
Intune enrollment with Mac is a nightmare. many prompts and also different behavior depending on default browser used on client. Often devices suddenly are "kicked" off intune as there is no connection - so conditional access fail, as device no longer are registered - and then need to delete intune entry - and do new registration.
Yeah I didn't have a great experience either with what I was able to setup for a test instance. I constantly struggled with whether or not I was setting it up incorrectly, if it was just waiting to send the command, or if it just wasn't working at all.
How is Conditional Access a "Legacy feature"?....😖
Sorry, "legacy" was probably the wrong word, I was referring to the Conditional Access Integration with Jamf Pro, which has been deprecated and replaced with the Device Compliance Integration.
How did you create an apple business manager / school account? also how did you verify your business, please guide
Highly biased, natural for a Jamf integrator. :D Intune dont have beatiful screens or ready-to-use settings such Jamf.
Is JAMF more Mac-centric, sure. But a few of the noted "can't dos" just aren't true. You CAN: manage the dock. Disable activation lock. If it is enabled, you have recovery passwords auto-generated for each device record. Haven't had a problem with FileVault, but we might just be lucky. We use mostly Intune for the very reasons you list, but are managing several hundred Macs with them. Long before MDM, we used Munki and it definitely takes a lot of Intune's shortcomings away. I doubt we could manage Macs with Intune alone without it.
Yeah I think something like Munki really helps with some of those shortcomings, I should have mentioned that in the video!
Hugely biased comparison of not much use sadly
It's biased in exactly the way they intended: those who have considerable investment in a Jamf infrastructure who are considering making a change (for whatever reason) to Intune. If that's not the perspective that you're coming from, the video is still of use in that you can see certain places where Jamf might have an advantage.
I found @RocketmanTech's presentation to be fairly balanced, especially in how Chris broke down the pros and cons of both platforms. From my experience working on projects where Apple devices were integrated with Intune, I understand the appeal of 'free' Microsoft solutions for IT management, there are trade-offs in terms of functionality, compliance, and community support. For larger deployments, I agree with Chris-Jamf is the industry standard, and I've been fortunate enough to work with some of the most talented people in MDM. The support from Jamf Nation and the open-source community has been invaluable (in my view), and it's an important factor that I feel often gets overlooked in comparisons. While Intune has its advantages, particularly for smaller setups, I’ve found that the community and support ecosystem around Jamf is significantly stronger. Additionally, as a paying Jamf client, the level of ongoing support (including direct Apple support in collaboration with Jamf) and continuous updates is another level compared to Microsoft.
Great info and huge thanks for compiling all this and presenting to the community, well done 🎉🎉
Thanks! I'm glad you enjoyed it
Any way to get this presentation, may be only as "read only". Thank you.
Are you referring to the keynote I used?
When it comes to Jamf Connect you should have taken a look into Microsoft Platform SSO that is already available. As you've mentioned User Affinity can't be compared to Jamf Connect. Regarding Zero Touch Provisioning: I recommend taking a look into Baseline in combination with Installomator. That's working well for me enrolling devices via Intune.
Love the channel and info, but do not underestimate the need for quality audio. Don't think AirPods Pro are gonna cut it. A professional mic definitely when making these videos.
I totally agree... but my podcasting mic is in storage, and I was on the road in a hotel room. In a month, I'll have my studio setup back. I did the best with the tools I had on hand, with my crazy travel schedule 😂
We appreciate your time and efforts to show how Intune is still far behind from Jamf
Man if you are coming from Jamf(like me) Intune totally sucks
At 00:28:54 I talk about the Device Check-in Frequency. Since I created this video, I've gotten several people claiming different things about Intune's check-in frequency. Some people say 8 hours, others say 24 hours, and still others say 5 minutes. An Intune SME who worked for Microsoft told me if they made a change to a profile, their standard procedure was to have them check the computer the next day. In my experience, the wait time for a change to happen was often longer than I was willing to wait, so I would plug the computer in and wait a day for the change to apply, or restart the computer which would sometimes work (but not all the time).
CheckIn with Intune is worse, I agree. I always reboot the Mac when I made adjustments to my macOS Scripts, because restarting the MDM agent on the system locally just does not speed things up.
This true I've had the same experiencing with intune, which is quite inconsistent, and frustrating if you're working with a client.
I've rarely ever seen a restart AND then a login by the user fail. That combo works for us. Then again, we've been in production with Intune for several years now and our configuration profiles aren't updated very often anymore.
Very informative 👍
Really hope that macOS SU will be adressed. Running Macs without being to enforce software updates is a real pain and shame.
Or without having to use a combination of Super/erase-install/nudge/SOFA/custom tools we built
@@RocketmanTech I use a tool I made myself based with Smart groups but that's soooo painful
Love the excel tip, but the real pro tip is the comma separated searching... I'd tried doing space separated searches (ala Apple Business Manager) to no avail and assumed this wasn't possible. Never tried commas! Great tip!
Same! I remember the day I learned about comma-separated searches in ASM. I am absolutely elated to know that it is also in Jamf!