Updating a Wi-Fi Network Password

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

To avoid disrupting device connectivity when updating the password on an existing Wi-Fi network, Jamf recommends creating and deploying a secondary Wi-Fi profile that devices in Jamf School can connect to during the transition to the new password. After you complete the following steps, devices will transition to the new Wi-Fi network password without losing connectivity.

Note:

Complete steps 1–6 before changing the Wi-Fi password.

  1. Create a secondary Wi-Fi network that devices can temporarily connect to while the primary network's password is updated. You can also use an existing, available secondary network, such as a guest network.
  2. Create a secondary mobile device Wi-Fi profile for the secondary Wi-Fi network, and then deploy it to all mobile devices.
  3. Create a secondary computer Wi-Fi profile for the secondary Wi-Fi network, and then deploy it to all computers.
  4. Create smart groups to identify devices that do not yet have the corresponding secondary Wi-Fi profile installed:
    1. For mobile devices, create a smart group with the following rules:
      CriteriaOperatorValue
      Managed Profile (Installed)not equalsSecondary mobile device Wi-Fi profile
      Device Typeone of the followingAll mobile device types in your fleet
    2. For computers, create a smart group with the following rules:
      CriteriaOperatorValue
      Managed Profile (Installed)not equalsSecondary computer Wi-Fi profile
      Device Typeone of the followingAll Mac models in your fleet

    For more information on creating smart groups, see Creating a Smart Device Group.

  5. Change the scope of each original Wi-Fi profile to include only the corresponding smart group created in step 4. This ensures that devices will keep the original Wi-Fi profile only if they do not yet have the secondary Wi-Fi profile installed.
    Note:

    Devices that have the secondary Wi-Fi profile will be automatically removed from the scope of the original Wi-Fi profile.

    1. In Jamf School, navigate to Profiles > Overview in the sidebar.
    2. Click the name of the original mobile device or computer Wi-Fi profile.
    3. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
    4. Remove all device groups from the scope by clicking the Delete icon for each group.
    5. Add the corresponding smart group created in step 4 to the scope.
    6. Click Save.
    7. Repeat steps a–f for the remaining original Wi-Fi profile.
  6. Wait for all devices to transition to the secondary Wi-Fi profiles. You can monitor the progress by navigating to Devices > Device Groups in the sidebar and keeping track of the device count for each smart group created in step 4. After all devices have transitioned to the secondary Wi-Fi profiles, each smart group's device count will be zero.
    Note:

    If there are devices that do not transition to the secondary Wi-Fi profiles, you may need to manually configure the devices after the primary Wi-Fi network's password is changed.

  7. Change the primary Wi-Fi network's password.
  8. Update the original mobile device Wi-Fi profile with the new password, and then revert its scope to include its initial device groups:
    1. In Jamf School, navigate to Profiles > Overview in the sidebar.
    2. Click the name of the original mobile device Wi-Fi profile.
    3. In the list of payloads on the left side of the pane, locate the General payload category and click the Wi-Fi payload.
    4. Update the password, as well as any other settings that may have changed.
    5. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
    6. Remove the smart group created in step 4a from the scope by clicking the Delete icon for the group.
    7. Re-add the initial device groups to the scope.
    8. Click Save.
  9. Update the original computer Wi-Fi profile with the new password, and then revert its scope to include its initial device groups:
    1. In Jamf School, navigate to Profiles > Overview in the sidebar.
    2. Click the name of the original computer Wi-Fi profile.
    3. In the list of payloads on the left side of the pane, locate the General payload category and click the Networks payload.
    4. Update the password, as well as any other settings that may have changed.
    5. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
    6. Remove the smart group created in step 4b from the scope by clicking the Delete icon for the group.
    7. Re-add the initial device groups to the scope.
    8. Click Save.
  10. Update the smart groups created in step 4 to target devices that still require the updated original Wi-Fi profile:
    1. In Jamf School, navigate to Devices > Device Groups in the sidebar.
    2. Click the name of the smart group created in step 4a.
    3. In the list of categories on the left side of the pane, click Members.
    4. In the Scope pane, update the rules to find mobile devices that do not yet have the original mobile device Wi-Fi profile:
      CriteriaOperatorValue
      Managed Profile (Installed)not equalsOriginal mobile device Wi-Fi profile
      Device Typeone of the followingAll mobile device types in your fleet
    5. Click Save Scope.
    6. Navigate to Devices > Device Groups in the sidebar.
    7. Click the name of the smart group created in step 4b.
    8. In the list of categories on the left side of the pane, click Members.
    9. In the Scope pane, update the rules to find computers that do not yet have the original computer Wi-Fi profile:
      CriteriaOperatorValue
      Managed Profile (Installed)not equalsOriginal computer Wi-Fi profile
      Device Typeone of the followingAll Mac models in your fleet
    10. Click Save Scope.
  11. Change the scope of each secondary Wi-Fi profile to include only the corresponding smart group updated in step 10. This ensures that devices retain the secondary Wi-Fi network until they receive the updated original Wi-Fi profile that has the new Wi-Fi network password.
    1. In Jamf School, navigate to Profiles > Overview in the sidebar.
    2. Click the name of the secondary mobile device or computer Wi-Fi profile.
    3. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
    4. Remove all device groups from the scope by clicking the Delete icon for each group.
    5. Add the corresponding smart group updated in step 10 to the scope.
    6. Click Save.
    7. Repeat steps a–f for the remaining secondary Wi-Fi profile.

As each device receives the updated original Wi-Fi profile, it will automatically disconnect from the secondary Wi-Fi network and revert to using the primary Wi-Fi network with the new password.