Deprecations and Removals

Jamf Pro Release Notes 11.13.0

Solution
Application
Content Type
Technical Documentation
Release Notes
Utilities & Services
version
11.13.0
ft:locale
en-US
vrm_version
11.13.0

Deprecations Added in This Release

Self Service Classic for macOS Support
Self Service+ will eventually replace Self Service classic and support for Self Service classic for macOS is projected to end in 2026. To receive the most current updates, Jamf recommends migrating to Self Service+ as early as possible.

Deprecations Added in a Previous Release

DeprecationNotes
Declarative device management status reporting for on-premise environments

Jamf will remove on-premise support for declarative device management status updates via the status channel (estimated removal date: early 2025). After support is removed, computers and devices in on-premise environments that previously reported declarative device management as "Enabled" will report as "Not Enabled" in inventory records.

Computers and mobile devices in on-premise environments will no longer report the following state changes to the MDM server via the status channel:
  • Computers
    • Battery health

    • FileVault2 enabled

  • Mobile devices:
    • Battery health

Computers and mobile devices in on-premise environments will continue to report the following state changes through MDM inventory updates:
  • Computers:
    • Operating System Version

    • Operating System Build

    • Operating System Supplemental Build Version

    • Operating System Rapid Security Response

  • Mobile devices:
    • OS Version

    • OS Rapid Security Response

    • OS Build

    • OS Supplemental Build Version

    • Passcode Compliance

Conditional Access on-premise supportJamf will replace Conditional Access support due to the migration away from Microsoft's Partner Device Management legacy API. Jamf plans to end support for the Partner Device Management legacy API on 31 January 2025. Jamf offers an alternative solution called macOS device compliance using Microsoft's new Partner Compliance Management API. A migration path from the legacy Partner Device Management API to the new Partner Compliance Management API is now available. The legacy Partner Device Management API will remain active until 31 January 2025, allowing organizations leveraging the legacy API time to migrate to the new API.
Note:

As of 15 August 2024, Conditional Access support will end on a new estimated removal date of 31 January 2025. Previous release notes and documentation stated that support for Conditional Access would end on 01 September 2024.

Software identification (SWID) tagsThe functionality to use software identification (SWID) tags for licensed software records will be removed.
Maintenance pages
Computer inventory collection for fonts
Computer inventory collection for plug-ins
Functionality to make policies available offlineThis option, currently available only for policies set to the "Ongoing" frequency, will be removed from the Jamf Pro interface, and all policies will require a connection to the Jamf Pro server to check for triggers before running.
SCCM plug-inJamf plans to stop distributing the SCCM plug-in. Existing installations will be supported until annual maintenance licenses for the SCCM plug-in expire.
Sign QuickAdd Package functionality for user-initiated enrollment settingsThis functionality is only used in legacy enrollment workflows involving QuickAdd packages and does not affect the user-initiated enrollment workflow.
Azure AD Graph for Conditional AccessAzure AD Graph is deprecated. If you previously modified the conditionalAccessDomains.json file, Jamf recommends editing the file to add the "msGraphResourceUrl": "https://graph.microsoft.com/" property into GLOBAL settings and "msGraphResourceUrl": "https://graph.microsoft.us/" into US_GOVERNMENT settings. For more information on this deprecation, see the following documentation from Microsoft:

Migrate your apps from Azure AD Graph to Microsoft Graph

Cache name settingThis setting will be removed from the Single Sign-On Extensions payload in computer and mobile device configuration profiles because Apple deprecated them.
Password expiration and Replication time settingsThese settings will be removed from the Single Sign-On Extensions payload in computer configuration profiles because Apple deprecated them.
Skip Display Tone and Skip Home button sensitivity settingsThese settings will be removed from the Skip Setup Items payload for mobile device configuration profiles.
Home Button Sensitivity and True Tone Display settingsThese settings will be removed from the General payload for computer and mobile device PreStage enrollments.
Functionality to issue the Tomcat SSL/TLS certificate from Jamf Pro's built-in certificate authorityJamf Pro's functionality to issue the Tomcat SSL/TLS certificate from the JSS built-in certificate authority (CA) will be discontinued. The release version for this change has not been determined. Before this change occurs, it is recommended that all on-premise Jamf Pro instances leveraging this functionality switch to a publicly trusted third-party CA to issue the Tomcat SSL/TLS certificate. This will prevent the potential loss of MDM communication from Jamf Pro to enrolled devices. If needed, a Tomcat SSL/TLS server certificate for Jamf Pro may be issued from an internal certificate authority. The JSS built-in CA will maintain its current ability to manually issue server certificates to other servers.
The "DIGEST-MD5" authentication type option"DIGEST-MD5" will be removed from the authentication type options. This authentication type option displays when configuring an LDAP server to use Jamf Infrastructure Manager as a proxy server.
Computer Access Only and Mobile Device Access Only Limited Access settings

Jamf Pro web app instances with one of these settings configured will automatically be updated to the Computer and Mobile Device Access setting. Administrators will only be able to assign Full Access or Computer and Mobile Device Access privileges after the deprecation.

Personal device profilesPersonal device profiles will be removed from Jamf Pro in conjunction with User Enrollment.
Webhook responses for ComputerPolicyFinished and ComputerCheckIn

These webhook responses will be modified to include additional information. These changes may break integrations that currently utilize these event types.

Supervise Devices and Make MDM Profile Mandatory settings in a mobile device PreStage enrollmentThe ability to supervise devices and require the user to install the MDM Profile during enrollment with a PreStage enrollment will be required and will be built-in functionality. As a result, these settings will be removed from the Jamf Pro user interface.
User-generated content in Siri settingThe User-generated content in Siri setting will be removed from the Restrictions payload for mobile device configuration profiles.
forceClassroomManagedClassroomScreenObservation key

This key will be removed from the Restrictions payload for mobile device configuration profiles. It will be replaced with the forceClassroomUnpromptedScreenObservation key.

IfLostReturnToMessage key

The grayscale key will be removed from the Accessibility payload for computer configuration profiles.

Support for non-certificate based client communication with the Jamf Pro serverThe Enable certificate-based authentication checkbox will be removed from Settings > Computer Management > Security.

Removals

Removed in version...Item Removed or DiscontinuedNotes
11.12.0Jamf Infrastructure Manager 1.x.x

Beginning in 11.12.0, Jamf Pro will no longer support Jamf Infrastructure Manager 1.x.x. To prepare for this change, Jamf recommends updating to the latest version of Jamf Infrastructure Manager. For more information, see the Jamf Infrastructure Manager for LDAP Proxy Installation Guide and the Healthcare Listener Installation and Configuration Guide.

11.11.0Amazon Aurora (MySQL 5.7 compatible)
11.10.0Profile-driven User Enrollment for iOS 18 and iPadOS 18

Apple announced the removal of support for profile-driven User Enrollment in iOS 18, iPadOS 18, and macOS 15. This means users can no longer enroll personally owned (BYOD) mobile devices using this method, also known as "user-initiated enrollment via URL". Devices that were previously enrolled via profile-driven User Enrollment will continue to be managed when they are upgraded to iOS 18 and iPadOS 18. If your organization manages personally owned iOS and iPadOS devices, you can enable account-driven User Enrollment as an alternative by navigating to Settings > Global > User-initiated enrollment > Devices.

For more information about account-driven User Enrollment, see the Prepare for Account-Driven User Enrollment with Managed Apple Accounts and Service Discovery article and the Building a BYOD Program with User Enrollment and Jamf Pro technical paper.

11.9.0Option to never validate package checksumsTo improve the security of package deployments, the option to never validate package checksums (Settings > Computer management > Security > Package Validation) has been removed from Jamf Pro. The new default value for this setting after upgrading to Jamf Pro 11.9.0 or later is "When checksum is present". If your environment relies on workflows that involve altering package checksums, package deployments may fail. Workflows that involve package deployment where checksums are unaltered or not used are unaffected.
11.9.0Java 11Java 11 has been replaced by Java 21. For more information, see the Migrating to Java 21 on Jamf Pro Servers article.
11.9.0Unsigned SAML responses with encrypted assertionsJamf Pro single sign-on no longer supports unsigned SAML responses with encrypted assertions. To prevent single sign-on errors Jamf Pro, configure your identity provider (IdP) to use signed SAML responses.

If your IdP is configured to use unsigned SAML responses with encrypted assertions, Jamf Pro will inform you in Notifications.

11.9.0Tomcat 9Tomcat 9 has been replaced by Tomcat 10.