Notice History by Release

Jamf Pro Release Notes 11.13.0

Solution
Application
Content Type
Technical Documentation
Release Notes
Utilities & Services
version
11.13.0
ft:locale
en-US
vrm_version
11.13.0
Starting with version...Change or ConsiderationDescription
11.12.0Legacy Binary Protocol for Push Certificates No Longer Supported

As of 13 December 2024, Jamf Pro no longer supports the legacy binary protocol option for Apple Push Notification service (APNs) communication. Jamf requires the HTTP/2 protocol for your push notification certificate. If you have not transitioned to the HTTP/2 protocol by 13 December 2024, remote management commands, configuration profiles, applications, and push certificates will no longer work. For more information, see the Supporting Apple Push Notification Service (APNs) Over HTTP/2 article. For assistance, contact Jamf Support.

11.10.0Microsoft Graph API no longer requires the Group.Read.All permission

Microsoft has recently reviewed and lowered the permissions required for the Graph API endpoints that Jamf Pro uses for the Entra ID integration. Jamf Pro no longer requires the Group.Read.All permission to enable the Entra ID integration.

You can continue using the Entra ID integration with the original permissions granted, or you can remove the Group.Read.All permission. To remove the Group.Read.All permission, navigate to Settings > System > Cloud identity providers and click your Entra ID identity provider from the list to open the integration page. On the integration page, click Refresh Consent.

11.9.0Preventing SSO Errors Caused by Spaces in Entity ID Field

Due to PI120315, if spaces are present in the Entity ID field of single sign-on (SSO) settings, Jamf Pro logs will show an error and logins will fail. To prevent errors, delete all spaces from the Entity ID field.

11.9.0Java 21 Now Required

Java 21 is required for Jamf Pro 11.9.0 or later. Java 11 is no longer supported. For more information, see the Migrating to Java 21 on Jamf Pro Servers article.

11.9.0Tomcat 10 Now Required
Tomcat 10 is required for Jamf Pro 11.9.0 or later. Tomcat 10 is included in the Jamf Pro installers.
Important:

Red Hat Enterprise Linux does not support Tomcat 10 and Red Hat will not provide technical support for manual installations of Tomcat 10. However, Tomcat 10 is installed automatically by the Jamf Pro installers and has been tested by Jamf.

11.9.0Support Ending for the APNs Legacy Binary Protocol

The legacy binary protocol option for Apple Push Notification service (APNs) communication will be removed from Jamf Pro in an upcoming release later in 2024. If you use the legacy binary protocol, Jamf recommends transitioning your push notification certificate to the HTTP/2 protocol as soon as possible to avoid any interruption with the connection between Jamf Pro and APNs. For more information, see the Supporting Apple Push Notification Service (APNs) Over HTTP/2 article. For assistance, contact Jamf Support.

11.9.0New Connector Requirement for AD CS Integrations

Integrations with Active Directory Certificate Services (AD CS) now require Jamf AD CS Connector 1.1.0.

Note:

Jamf AD CS Connector 1.1.0 requires .NET Framework 4.8 or later.

To determine which version of Jamf AD CS Connector you have installed, run the following command in PowerShell:
Select-String -Path "C:\inetpub\wwwroot\adcsproxy\api-swagger.json" -Pattern "Revoke"

If you have version 1.1.0 installed, the JSON file will return results related to "Revoke". If you have version 1.0.0 installed, the JSON file will not return any results related to "Revoke".

For upgrading instructions, see Upgrading the Jamf AD CS Connector in the Integrating with Active Directory Certificate Services (AD CS) Using Jamf Pro technical paper.

11.9.0Conditional Access End-of-Support Date Change

As of 15 August 2024, Conditional Access support will end on a new estimated removal date of 31 January 2025. Previous release notes and documentation stated that support for Conditional Access would end on 01 September 2024. If you have computers enrolled under the legacy Conditional Access integration, you must migrate the computers to the device compliance integration before the new end-of-support date. For more information, see Migrating from macOS Conditional Access to macOS Device Compliance in the Device Compliance with Microsoft Entra and Jamf Pro technical paper.