If you are upgrading to Jamf Pro 10.49.0 or later, you should consider the following:
| Consideration | Guidance |
|---|---|
| You can no longer specify a known password for the managed local administrator account in user-initiated enrollment settings. The account will now only be created with a randomized password. | You can access the randomized password using the Jamf Pro API. If you want to deploy a local administrator account using a known, static password, you can use a policy with the Local Accounts payload. A local administrator account created using a policy does not leverage LAPS functionality. Warning: If you create an account using a policy and it is the first account created on the computer (i.e., the account is created before Setup Assistant user creation), it may receive the first secure token cryptographic privileges, and no bootstrap token will be automatically escrowed. If your deployment workflow relies on a known, static password for a common local administrator account, you should consider creating that account by using other methods, such as via a policy using the Local Accounts payload. To prevent a local administrator account created this way from receiving the first secure token, Jamf recommends choosing a trigger of Login so the policy runs after the primary computer user signs in. |
| The Management Account payload in a Jamf policy now has only one option to randomize the password in place of the previous options that were available. | The previous Management Account payload options are converted as follows:
|
The ability to specify or modify computer management account credentials was removed from Jamf Pro. This includes the following methods:
| |
| The ability to enable and disable the management account for FileVault via a policy was removed. | |
The -sshUsername, -sshPassword, and -sshPasshash options for the recon command of the jamf binary on managed computers was removed. |