Skip to main content

Apple Changes & Release Notes

Latest change requests, release notes, and updates for Apple UEM.

Jamf Pro - Upgrading Jamf Pro from 11.16 to 11.18.1

· One min read
Noah Bruce
Apple Device Management Professional

Change Request 279779 Jamf Pro - Upgrading Jamf Pro from 11.16 to 11.18.1.

Description: Details of maintenance: The Jamf Pro server in both test and production servers will be upgraded from 11.6 to 11.18.1

Benefit of change: Upgraded Jamf Support ticketing system, Jamf Pro no longer returns a "Version entered is unknown" error when attempting to execute an advanced search or save a smart computer group that uses 'unknown version' as a value for existing patch reporting criteria, and fixes a security issue with the Jamf Pro Server. https://learn.jamf.com/en-US/bundle/jamf-pro-release-notes-11.18.1/page/New_Features_and_Enhancements.html

Impact to customers: Jamf Pro console access and device enrollment capabilities for IT support teams may not be available during the upgrade.

Intune/SCCM Co-Management settings no longer assigned

· One min read
Jon Griffey
IT Director for Endpoint Management

Change Request 265098 Intune/SCCM Co-Management settings no longer assigned.

Description: Change Description: An emergency change was implemented to reassign the Intune Enrollment Co-management settings after it was discovered that they were no longer assigned to any device group. This reassignment was necessary to resolve an issue reported by Jon, where SCCM agents were failing to install on OAL Self-Driven Autopilot enrolled devices.

Root Cause and Initial Fix

Root Cause: The Intune Co-management settings had lost their assignments, which prevented proper SCCM agent deployment during Autopilot.

Initial Emergency Action: The Co-management settings were assigned to the device scope group for all Autopilot enrolled devices.

Immediate Outcome: This resolved the issue for OAL Self-Driven devices, as confirmed by Jon.

Jamf Pro - Executive Support Site Creation

· 3 min read
Bernardo Garcia-Moreno
IT Professional I

Change Request 230394 Jamf Pro - Executive Support Site Creation.

Description: ## Details of Maintenance We will be creating a new Prestage, automated device enrollment, and site for Executive support. Step 1 - Creating the Prestage (MDM Server) In Apple School Manager, navigate to preferences and add an MDM server. You will have to upload a "Public Key" which can be downloaded from Jamf in the Automated Device Enrollment section This will generate an MDM Server Token which will be used later in Step 3 Step 2 - Creating a New Site In Jamf Pro, Create a new Site by navigating to the Site Tab This site will be named "Executive Support" This will be important in the next step Step 3 - Creating Automated Device Enrollment In Jamf Pro, create a new Automated Device Enrollment and upload the MDM Server Token which was downloaded in step 1 Configure the page, it will be named "TAMU - Executive Support - New Devices" Point the site to "Executive Support" which was created in Step 2 Step 4 - Creating Prestage Navigate to the prestages and create a new prestage Name the prestage "TAMU - Executive Support - New Devices" Select "TAMU - Executive Support - New Devices" under the Automated Device Enrollment Instance selection. Check the option to automatically assign new devices Enrollment site should be set to "Executive Support" Configure the rest of the settings as needed Add the following configuration profiles to the prestage: Global - Device Encryption - PreStage and Log In Jamf Connect - License Jamf Connect - Login Jamf Connect - Login (2.38.0 Branding Settings) Jamf Connect - Login (2.38.0 Entra Settings) Jamf Connect - Menu_Bar Jamf Connect - Notifications Jamf Connect - Run Script Mechanism Jamf ConnectLoginWindow WiFi (exp.04-18-26) Jamf ConnectLoginWindow WiFi (exp.04-26-25) FileVault - Escrow Personal Recovery Key to Jamf Pro Managed Login Item - Suppress Notifications Global - SupportApp - Managed Login Global - SupportApp - Notifications Global - SupportApp - PPPC Global - SupportApp - Prod - 2.6 Add the following Enrollment Packages Jamf Connect Launch Agent 2.44 Package JamfConnect 2.44 Package JamfConnectFiles.pkg Source_Images.pkg dialog-2.5.5-4802.pkg setupYourMacStarter.pkg Save


Benefit of Change​

Creating this site will allow Executive support who mostly deals with VIP customers to be segmented into their own group. This will allow deployments to be easier, exclusion to be easier, and less manual support for both teams in the long run in terms of deployments.


Impact to Customers​

None


Impact to Other Services/Websites​

None

Jamf Pro - Executive Support Site Creation

· 3 min read
Bernardo Garcia-Moreno
IT Professional I

Change Request 228441 Jamf Pro - Executive Support Site Creation.

Description: ## Details of Maintenance We will be creating a new Prestage, automated device enrollment, and site for Executive support. Step 1 - Creating the Prestage (MDM Server) In Apple School Manager, navigate to preferences and add an MDM server. You will have to upload a "Public Key" which can be downloaded from Jamf in the Automated Device Enrollment section This will generate an MDM Server Token which will be used later in Step 3 Step 2 - Creating a New Site In Jamf Pro, Create a new Site by navigating to the Site Tab This site will be named "Executive Support" This will be important in the next step Step 3 - Creating Automated Device Enrollment In Jamf Pro, create a new Automated Device Enrollment and upload the MDM Server Token which was downloaded in step 1 Configure the page, it will be named "TAMU - Executive Support - New Devices" Point the site to "Executive Support" which was created in Step 2 Step 4 - Creating Prestage Navigate to the prestages and create a new prestage Name the prestage "TAMU - Executive Support - New Devices" Select "TAMU - Executive Support - New Devices" under the Automated Device Enrollment Instance selection. Check the option to automatically assign new devices Enrollment site should be set to "Executive Support" Configure the rest of the settings as needed Add the following configuration profiles to the prestage: Global - Device Encryption - PreStage and Log In Jamf Connect - License Jamf Connect - Login Jamf Connect - Login (2.38.0 Branding Settings) Jamf Connect - Login (2.38.0 Entra Settings) Jamf Connect - Menu_Bar Jamf Connect - Notifications Jamf Connect - Run Script Mechanism Jamf ConnectLoginWindow WiFi (exp.04-18-26) Jamf ConnectLoginWindow WiFi (exp.04-26-25) FileVault - Escrow Personal Recovery Key to Jamf Pro Managed Login Item - Suppress Notifications Global - SupportApp - Managed Login Global - SupportApp - Notifications Global - SupportApp - PPPC Global - SupportApp - Prod - 2.6 Add the following Enrollment Packages Jamf Connect Launch Agent 2.44 Package JamfConnect 2.44 Package JamfConnectFiles.pkg Source_Images.pkg dialog-2.5.5-4802.pkg setupYourMacStarter.pkg Save


Benefit of Change​

Creating this site will allow Executive support who mostly deals with VIP customers to be segmented into their own group. This will allow deployments to be easier, exclusion to be easier, and less manual support for both teams in the long run in terms of deployments.


Impact to Customers​

None


Impact to Other Services/Websites​

None

Jamf Pro - Executive Support Site Creation

· 3 min read
Bernardo Garcia-Moreno
IT Professional I

Change Request 228558 Jamf Pro - Executive Support Site Creation.

Description: ## Details of Maintenance We will be creating a new Prestage, automated device enrollment, and site for Executive support. Step 1 - Creating the Prestage (MDM Server) In Apple School Manager, navigate to preferences and add an MDM server. You will have to upload a "Public Key" which can be downloaded from Jamf in the Automated Device Enrollment section This will generate an MDM Server Token which will be used later in Step 3 Step 2 - Creating a New Site In Jamf Pro, Create a new Site by navigating to the Site Tab This site will be named "Executive Support" This will be important in the next step Step 3 - Creating Automated Device Enrollment In Jamf Pro, create a new Automated Device Enrollment and upload the MDM Server Token which was downloaded in step 1 Configure the page, it will be named "TAMU - Executive Support - New Devices" Point the site to "Executive Support" which was created in Step 2 Step 4 - Creating Prestage Navigate to the prestages and create a new prestage Name the prestage "TAMU - Executive Support - New Devices" Select "TAMU - Executive Support - New Devices" under the Automated Device Enrollment Instance selection. Check the option to automatically assign new devices Enrollment site should be set to "Executive Support" Configure the rest of the settings as needed Add the following configuration profiles to the prestage: Global - Device Encryption - PreStage and Log In Jamf Connect - License Jamf Connect - Login Jamf Connect - Login (2.38.0 Branding Settings) Jamf Connect - Login (2.38.0 Entra Settings) Jamf Connect - Menu_Bar Jamf Connect - Notifications Jamf Connect - Run Script Mechanism Jamf ConnectLoginWindow WiFi (exp.04-18-26) Jamf ConnectLoginWindow WiFi (exp.04-26-25) FileVault - Escrow Personal Recovery Key to Jamf Pro Managed Login Item - Suppress Notifications Global - SupportApp - Managed Login Global - SupportApp - Notifications Global - SupportApp - PPPC Global - SupportApp - Prod - 2.6 Add the following Enrollment Packages Jamf Connect Launch Agent 2.44 Package JamfConnect 2.44 Package JamfConnectFiles.pkg Source_Images.pkg dialog-2.5.5-4802.pkg setupYourMacStarter.pkg Save


Benefit of Change​

Creating this site will allow Executive support who mostly deals with VIP customers to be segmented into their own group. This will allow deployments to be easier, exclusion to be easier, and less manual support for both teams in the long run in terms of deployments.


Impact to Customers​

None


Impact to Other Services/Websites​

None

Jamf Pro - Remove Unnecessary Configuration Profiles

· One min read
Stephen Johnson
IT Manager for Unified Apple Device Management

Change Request 201733 Jamf Pro - Remove Unnecessary Configuration Profiles.

Description: Details of Maintenance: We will remove profiles from devices that no longer need to have a profile and delete some configuration profiles that are not needed.

Benefit of Change: This is an initial cleanup of the Jamf Pro servers. We will be removing some configuration profiles that are no longer needed in order to help reduce server load.

Impact to Customers: During testing no notifications happen for this set of changes being made.

Impact to other services/websites: None

Jamf Connect Upgrade to 2.44

· 2 min read
Bernardo Garcia-Moreno
IT Professional I

Change Request 198413 Jamf Connect Upgrade to 2.44.

Description: Details of Maintenance

The Unified Endpoint Management (UEM) - Apple Team will deploy updated configuration profiles and the latest version of the Jamf Connect application (v2.44) to all managed Apple macOS devices. The deployment will proceed as follows:

Application Deployment

The updated Jamf Connect v2.44 application will be deployed using the Jamf policy titled "Jamf Connect 2.44 Deployment", scoped to all managed macOS devices, excluding the following groups:

Academic Support - Disability Resources Testing Macs

AS - Disability Resources Testing Macs

The current prestages will be updated to include the new version of Jamf Connect in their package configuration.

Monitoring

UEM team members will actively monitor the deployment in real-time via Jamf to ensure there are no disruptions to service.

The deployment will be validated on both the Production and Test Jamf servers prior to full rollout.

Benefit of Change

This update ensures that Jamf Connect profiles and the application are current, more secure, and compliant with the latest standards.

Configuration options for Jamf Unlock are now removed from the Jamf Connect Configuration app. A future release of Jamf Connect will remove Jamf Unlock settings from other Jamf applications, including Jamf Pro.

[CON-5497] Jamf Connect configurations using Entra ID and Active Directory Federation Services no longer experience a login loop during OIDC authentication.

View the full change log

Impact to Customers

End users should experience no disruption during the deployment of Jamf Connect v2.44.

The application will update silently in the background; no user interaction is required.

Impact to Other Services/Websites

None.

Jamf Pro - Upgrading Jamf Pro from 11.15 to 11.16

· One min read
Stephen Johnson
IT Manager for Unified Apple Device Management

Change Request 193405 Jamf Pro - Upgrading Jamf Pro from 11.15 to 11.16.

Description: Details of Maintenance: The Jamf Pro test and prod servers will be upgraded to the latest version.

Benefit of Change: There are new features available in the latest version.

The main new feature of interest is called Compliance Benchmarks and can help us get compliance metrics and reporting based on CIS benchmarks.

There are more features but none of major impact to our day to day and you can see more in depth in the following link: https://learn.jamf.com/en-US/bundle/jamf-pro-release-notes-current/page/New_Features_and_Enhancements.html?_gl=1*1i3b3gm*_ga*ODY0ODY5NTc0LjE3NDEwMTk3OTA.*_ga_X3RD84REYK*MTc0NjIwMDQ0MC4yMy4wLjE3NDYyMDA0NDAuNjAuMC4w

Link to list of resolved issues: https://learn.jamf.com/en-US/bundle/jamf-pro-release-notes-current/page/Resolved_Issues.html

Impact to Customers: None

Impact to other services/websites: None

Jamf Pro - Updating Elastic Deployment Script

· 2 min read
Andrew Barnett
Senior IT Professional II

Change Request 188952 Jamf Pro - Updating Elastic Deployment Script.

Description: Details of maintenance: Update the script used to deploy and update Elastic in our Jamf servers. After tamper prevention got enabled the previous script stopped working and some agents started breaking. This new script deals with the issues cause by the use of tamper prevention for Elastic and fixes agents if they are broken. It also helps keep Elastic updated. Additionally change the scope of the elastic configuration profile to All Computers.

Updates to new Elastic Script:

Uninstall Status Check:

The checkUninstallStatus function now includes a pause for backoffSeconds before checking the status.

Added a check for the Elastic Security application in addition to the Elastic Agent folder and application.

Directory Removal:

A new function checkAndRemoveDir has been added to check if a directory exists, is empty, and remove it if necessary.

Script Exit Logic:

The quitScript function now includes additional conditions for running Jamf Recon and exiting with different status codes based on the value of exitCode.

Elastic Agent Information Check:

The elasticInfoCheck function has been added to check for the presence of the Elastic Agent folder and installed versions.

Get Elastic Agent Version:

The getElasticAgentVersion function has been updated to include additional checks for the Elastic Agent app using both direct path and Spotlight search.

Set Default Values:

A new function checkAndSetDefaults has been added to set default values for forceInstall and forceUninstall.

Check Elastic Version:

The checkElasticVersion function has been updated to include additional logic for handling force install and force uninstall scenarios.

Uninstall Agent:

The uninstallAgent function has been updated to include additional logic for handling uninstall attempts, including fallback methods and directory removal.

Install and Verify Agent:

The installAndVerifyAgent function has been updated to include additional logic for handling retry attempts, elapsed time checks, and exit codes.

Benefit of change: This change updates the deployment script for Elastic to deal with agents breaking after tamper prevention got enabled and the previous script stopped working. The change to the configuration profile will ensure that all devices in the server get the configuration profile regardless of what group they are in, even if they do not fall into a smart group initially.

Impact to customers: None. Happens in the background.