Remediating a Jamf Protect System Extension Reinstall Loop

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Jamf has identified an issue that causes some computers to repeatedly download, install, and load the Jamf Protect system extension, which can leave Jamf Protect in a partially degraded state. This issue most often affects computers where an MDM profile renewal error occurred, or computers that were removed from the MDM solution (decommissioned) without Jamf Protect being uninstalled first.

In the macOS Security portal, computers affected by this issue will display an installation status warning indicating a problem with the Jamf Protect installation. You can remediate affected computers by verifying their enrollment status in your MDM solution, re-enrolling computers that are actively being used, confirming that the Jamf Protect system extension is deployed, and redeploying the Jamf Protect agent package.

  1. Identify computers with an installation status warning:
    1. In Jamf Protect, click Computers.
    2. From the Filter by pop-up menu, choose "installationStatus" and then choose "Check installation".
      Note:

      A computer's details page in Jamf Protect also displays installation status warnings. If a computer has an installation status warning, it displays in the following places:

      • On the Overview tab, under Protect Version in the Version Status card

      • On the Details tab, under Installation Type in the Computer Info card

  2. Verify whether the affected computers are enrolled in your MDM solution.

    In Jamf Pro, you can verify whether a computer is enrolled by clicking Computers in the sidebar and performing a simple or advanced computer search. For more information, see Simple Computer Searches or Advanced Computer Searches in the Jamf Pro Documentation.

  3. Based on each affected computer's enrollment status, do one of the following:
    • If the computer is not enrolled in your MDM solution, ignore the warning in Jamf Protect. You can also remove the computer from Jamf Protect, if desired. To delete a computer in Jamf Protect, click Delete Computer at the upper right of the computer's details page.

    • If the computer is enrolled in your MDM solution but not completing MDM commands, re-enroll the computer. For more information on enrolling computers in Jamf Pro, see Enrollment with Jamf Pro in the Jamf Pro Documentation.

  4. Confirm the Jamf Protect system extension is deployed to each affected computer. In Jamf Pro, you can do this by completing the following steps:
    1. In Jamf Pro, click Computers in the sidebar.
    2. Click Search inventory in the sidebar.
    3. In the Search field, enter the affected computer's name. For more information, see Simple Computer Searches in the Jamf Pro Documentation.
    4. Click the name of the affected computer.
    5. Under the Inventory tab, click the Profiles payload.
    6. Review the list of profiles and confirm whether the Jamf Protect system extension is installed on the computer. The Jamf Protect plan configuration profile contains the system extension by default, but the system extension can be deployed separately.
      Note:

      On computers with macOS 10.14 or later that have a User Approved MDM status, you can also deploy the Jamf Protect system extension by allowing Jamf Pro to automatically install the Privacy Preferences Policy Control profile and safelist Jamf Protect. If the Jamf Protect system extension is deployed using this method, Jamf Pro will install a payload to safelist Jamf Protect as a system extension on the computer.

      For more information, see Automatically Installing the Privacy Preferences Policy Control Profile in the Jamf Pro Documentation.

  5. Redeploy the Jamf Protect agent package to the affected computers. For more information, see Deploying Jamf Protect in the Jamf Protect Documentation.