-
Notifications
You must be signed in to change notification settings - Fork 3
Jamf Extension Attributes
Gil Burns edited this page Sep 3, 2026
·
1 revision
Third Party Patcher ships a set of ready-to-use Jamf Pro Extension Attribute
(EA) scripts that surface patch status in device inventory, smart groups, and
dashboards. They live in the repo under
MDM Examples/Jamf Extension Attributes/.
Each script shells out to patcherreport (mostly its get
subcommand) and echoes a single <result> value. They use only tools present on
a stock macOS install — no jq, python3, or other add-ons.
| Script | Display name | Data type | Reports |
|---|---|---|---|
tpp-last-scan.sh |
TPP - Last Scan | Date | Last full Installomator scan (UTC) |
tpp-last-apply.sh |
TPP - Last Apply | Date | Last apply / install pass (UTC) |
tpp-apps-requiring-update.sh |
TPP - Apps Requiring Update | Integer | Managed apps found out of date |
tpp-pending-updates.sh |
TPP - Pending Updates | Integer | Updates staged and awaiting apply |
tpp-oldest-pending-days.sh |
TPP - Oldest Pending Update (Days) | Integer | Age of the oldest staged update |
tpp-days-until-hard-deadline.sh |
TPP - Days Until Hard Deadline | Integer | Days before deferrals are cut off |
tpp-broken-labels.sh |
TPP - Broken Labels | Integer | Scan-broken + stage-broken labels |
tpp-deferrals-30-days.sh |
TPP - Deferrals (Last 30 Days) | Integer | Dialog deferrals in the last 30 days |
tpp-deadlines-forced.sh |
TPP - Deadlines Forced (Lifetime) | Integer | Times a hard deadline forced an install |
tpp-patching-mode.sh |
TPP - Patching Mode | String |
monthly or deadline
|
tpp-pending-update-labels.sh |
TPP - Pending Update Labels | String | Comma-separated staged label list |
tpp-patch-compliance-status.sh |
TPP - Patch Compliance Status | String | Rollup verdict |
TPP - Patch Compliance Status returns one of, in priority order:
| Value | Meaning |
|---|---|
Not Installed |
patcherreport is not present on the device |
Overdue |
A hard deadline has been reached |
Deadline Approaching |
Updates pending, hard deadline within 3 days |
Pending |
Updates staged, deadline not yet close |
Updates Detected |
Updates found but nothing staged yet |
Compliant |
Nothing outstanding |
- Settings ▸ Computer Management ▸ Extension Attributes ▸ New
-
Display Name — use the name from the table (the
TPP -prefix keeps them grouped). - Data Type — match the table (Integer / String / Date).
- Input Type — Script, then paste the script contents.
- Save. Values populate on each device's next inventory submission (
jamf recon).
| Smart group | Criteria |
|---|---|
| Patching overdue |
TPP - Patch Compliance Status is Overdue
|
| Deadline approaching |
TPP - Days Until Hard Deadline less than 3
|
| Chronic deferrers |
TPP - Deferrals (Last 30 Days) greater than 10
|
| Stale scan |
TPP - Last Scan before (today − 7 days)
|
| Broken labels present |
TPP - Broken Labels greater than 0
|
| Never patched |
TPP - Last Apply is (blank)
|
-
Binary path. Scripts call
/usr/local/bin/tpp/patcherreport. For the dev build (/usr/local/bin/tpp_dev/), edit thepatcherreport=line. -
Dates are UTC. Jamf stores EA dates as
YYYY-MM-DD hh:mm:ssin UTC; the date scripts convertpatcherreport's ISO-8601 output accordingly. - Freshness. Values are only as current as the last inventory submission.
-
Roll your own.
patcherreport get <dotted.key> [--from <report>]prints any scalar from the JSON payloads — see Reporting ▸ get.
Getting Started
Reference
- Command-Line Reference
- Preference Keys
- Installomator Integration
- Installomator Metadata
- Managed Labels
Patching Behavior
- Deferral and Deadlines
- Patching Walkthrough: Deadline-Based
- Patching Walkthrough: Monthly Cadence
- User Prompts
- Branding and Customization
User-Facing Tools
Reporting
Support