To avoid disrupting device connectivity when updating the password on an existing Wi-Fi network, Jamf recommends creating and deploying a secondary Wi-Fi profile that devices in Jamf School can connect to during the transition to the new password. After you complete the following steps, devices will transition to the new Wi-Fi network password without losing connectivity.
Complete steps 1–6 before changing the Wi-Fi password.
- Create a secondary Wi-Fi network that devices can temporarily connect to while the primary network's password is updated. You can also use an existing, available secondary network, such as a guest network.
- Create a secondary mobile device Wi-Fi profile for the secondary Wi-Fi network, and then deploy it to all mobile devices.
- Create a secondary computer Wi-Fi profile for the secondary Wi-Fi network, and then deploy it to all computers.
- Create smart groups to identify devices that do not yet have the corresponding secondary Wi-Fi profile installed:
- For mobile devices, create a smart group with the following rules:
Criteria Operator Value Managed Profile (Installed) not equals Secondary mobile device Wi-Fi profile Device Type one of the following All mobile device types in your fleet - For computers, create a smart group with the following rules:
Criteria Operator Value Managed Profile (Installed) not equals Secondary computer Wi-Fi profile Device Type one of the following All Mac models in your fleet
For more information on creating smart groups, see Creating a Smart Device Group.
- For mobile devices, create a smart group with the following rules:
- Change the scope of each original Wi-Fi profile to include only the corresponding smart group created in step 4. This ensures that devices will keep the original Wi-Fi profile only if they do not yet have the secondary Wi-Fi profile installed.Note:
Devices that have the secondary Wi-Fi profile will be automatically removed from the scope of the original Wi-Fi profile.
- In Jamf School, navigate to Profiles > Overview in the sidebar.
- Click the name of the original mobile device or computer Wi-Fi profile.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
- Remove all device groups from the scope by clicking the Delete
icon for each group.
- Add the corresponding smart group created in step 4 to the scope.
- Click Save.
- Repeat steps a–f for the remaining original Wi-Fi profile.
- Wait for all devices to transition to the secondary Wi-Fi profiles. You can monitor the progress by navigating to Devices > Device Groups in the sidebar and keeping track of the device count for each smart group created in step 4. After all devices have transitioned to the secondary Wi-Fi profiles, each smart group's device count will be zero.Note:
If there are devices that do not transition to the secondary Wi-Fi profiles, you may need to manually configure the devices after the primary Wi-Fi network's password is changed.
- Change the primary Wi-Fi network's password.
- Update the original mobile device Wi-Fi profile with the new password, and then revert its scope to include its initial device groups:
- In Jamf School, navigate to Profiles > Overview in the sidebar.
- Click the name of the original mobile device Wi-Fi profile.
- In the list of payloads on the left side of the pane, locate the General payload category and click the Wi-Fi payload.
- Update the password, as well as any other settings that may have changed.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
- Remove the smart group created in step 4a from the scope by clicking the Delete
icon for the group.
- Re-add the initial device groups to the scope.
- Click Save.
- Update the original computer Wi-Fi profile with the new password, and then revert its scope to include its initial device groups:
- In Jamf School, navigate to Profiles > Overview in the sidebar.
- Click the name of the original computer Wi-Fi profile.
- In the list of payloads on the left side of the pane, locate the General payload category and click the Networks payload.
- Update the password, as well as any other settings that may have changed.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
- Remove the smart group created in step 4b from the scope by clicking the Delete
icon for the group.
- Re-add the initial device groups to the scope.
- Click Save.
- Update the smart groups created in step 4 to target devices that still require the updated original Wi-Fi profile:
- In Jamf School, navigate to Devices > Device Groups in the sidebar.
- Click the name of the smart group created in step 4a.
- In the list of categories on the left side of the pane, click Members.
- In the Scope pane, update the rules to find mobile devices that do not yet have the original mobile device Wi-Fi profile:
Criteria Operator Value Managed Profile (Installed) not equals Original mobile device Wi-Fi profile Device Type one of the following All mobile device types in your fleet - Click Save Scope.
- Navigate to Devices > Device Groups in the sidebar.
- Click the name of the smart group created in step 4b.
- In the list of categories on the left side of the pane, click Members.
- In the Scope pane, update the rules to find computers that do not yet have the original computer Wi-Fi profile:
Criteria Operator Value Managed Profile (Installed) not equals Original computer Wi-Fi profile Device Type one of the following All Mac models in your fleet - Click Save Scope.
- Change the scope of each secondary Wi-Fi profile to include only the corresponding smart group updated in step 10. This ensures that devices retain the secondary Wi-Fi network until they receive the updated original Wi-Fi profile that has the new Wi-Fi network password.
- In Jamf School, navigate to Profiles > Overview in the sidebar.
- Click the name of the secondary mobile device or computer Wi-Fi profile.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
- Remove all device groups from the scope by clicking the Delete
icon for each group.
- Add the corresponding smart group updated in step 10 to the scope.
- Click Save.
- Repeat steps a–f for the remaining secondary Wi-Fi profile.
As each device receives the updated original Wi-Fi profile, it will automatically disconnect from the secondary Wi-Fi network and revert to using the primary Wi-Fi network with the new password.