Restricted Software - Computers moved out of smart group is still in scope?

Ferrard
New Contributor II

Hey Guys,

I'm unsure if this is a defect.

We have a restricted software setup in our JSS where the installation of OSX 10.11 is blocked for computers that falls under two different smart groups. We see no issues with this.

But when a computer was part of these smart group previously and now moved out of the group, the Restricted software should no longer be applicable for the machine. But when the user tries to install OSX 10.11.3 is still says its blocked. Even if I manually exclude the machine from this restricted Software and run a recon it still says its blocked. Any idea what is going on here?

Please let me know.

Thanks,

Ravi

2 ACCEPTED SOLUTIONS

dgreening
Valued Contributor II

Try running a "jamf manage" on the machine.

View solution in original post

mm2270
Legendary Contributor III

Run a sudo jamf manage on the Mac, not a recon. Restricted Software gets updated on a system when the management framework is refreshed. See if that helps.

View solution in original post

7 REPLIES 7

dgreening
Valued Contributor II

Try running a "jamf manage" on the machine.

mm2270
Legendary Contributor III

Run a sudo jamf manage on the Mac, not a recon. Restricted Software gets updated on a system when the management framework is refreshed. See if that helps.

thoule
Valued Contributor II

That block list is /Library/Application Support/JAMF/.blacklist.xml I find it gets refreshed about every 15 mins in my environment and jamf mange or recon had no effect on that.

mm2270
Legendary Contributor III

@thoule I'm not sure what would be up with that, but I can assure you doing a sudo jamf manage refreshes the Restricted Software items on the Mac. I just did a quick test on this. We block the BootCamp Assistant application since we don't want people using it to install an unmanaged Windows OS on their Macs. I ran the app, Restricted Software blocked it right away. I then went into our JSS and to that Restricted Software item, added my Mac into the Exclusions tab, hit Save and within about 2 seconds ran a sudo jamf manage command on my Mac, and then launched the app again right after. The entire amount of time between me saving my Mac into the Exclusions tab and running the app again couldn't have been longer than about 10-15 seconds, and I was able to then keep BootCamp Assistant running - no Restricted Software block.
I then did the same process in reverse, removing my Mac from Exclusions, and as soon as I ran the jamf manage command the open BootCamp Assistant application was shut down and I received our block message.

Ferrard
New Contributor II

Thanks all! Waiting for the user to come back from Lunch to test this :)

Do you know how often management framework gets updated automatically on the managed computers?

Ferrard
New Contributor II

btw, just tested sudo jamf manage and that did the trick. Appreciate the responses here.

TechSpecialist
Contributor

This should not be. If I scope a smartgroup to Restricted software, then I expect the restriction to be lifted automatically when that mac is no longer part of that smartgroup.