This article describes how to enable HTTP Strict Transport Security (HSTS) for on-premise Jamf Pro installations. The HSTS response header directs web browsers to connect to your Jamf Pro server using only HTTPS.
HSTS is automatically enabled for new installations of Jamf Pro 10.44.0 or later.
You are upgrading to Jamf Pro 10.44.0 or later using the installer.
You are manually upgrading to Jamf Pro 10.44.0 or later.
You are not upgrading and are remaining on your installed version of Jamf Pro (10.4.0–10.43.x).
HSTS was not enabled on Jamf Pro 10.44.0 or later.
Enabling HSTS does not impact MDM communication. The URL found in will be installed on enrolled devices as the only way for devices to communicate with Jamf Pro via MDM.
You do not need to enable HSTS if your Jamf Pro instance is behind a load balancer. HSTS will be applied at the load balancer level.
*You can use the current version of the Jamf Pro installer. You do not need to wait to upgrade to the next version.