Mobile Device Management Capabilities
Mobile Device PreStage Enrollment Enhancement
Configuration profiles can now be installed on supervised mobile devices in the scope of a PreStage enrollment before a user is presented with the Setup Assistant screens. This option is available when configuring a PreStage enrollment in Jamf Pro.
Activation Lock Enhancement
You can now enable Activation Lock directly on a device that is currently enrolled with Jamf Pro without requiring end user interaction. In addition, you can disable and prevent Activation Lock directly on a device. Disabling and preventing Activation Lock allows Activation Lock to be disabled on a device without wiping the device and prevents an end user from re-enabling Activation Lock. These features are available as a remote command or as a mass action.
Inventory Preload for Mobile Devices
You can use the Inventory Preload setting to upload a CSV file containing mobile device inventory data before mobile devices are enrolled. When mobile device inventory is collected, Jamf Pro checks the preloaded data for matching serial numbers. Mobile device inventory details are then updated with the preloaded data for the devices with matching serial numbers.
The preloaded data is used on an ongoing basis to update mobile device inventory details each time inventory is collected. For example, if you upload a CSV file with one set of inventory details, then upload a subsequent CSV file with different inventory details, the changed inventory details will be applied in Jamf Pro the next time inventory is collected.
You can use Inventory Preload to update mobile device usernames, buildings, departments, device purchasing information, extension attributes, and more. You can also create or update mobile device users.
To access this feature in Jamf Pro, navigate to Settings > Global Management > Inventory Preload.
For more information, see the Inventory Preload section in the Jamf Pro Administrator's Guide.
Reports Enhancements for Advanced Mobile Device Searches
You can now email inventory reports for saved advanced mobile device searches. Reports can be emailed immediately or according to a schedule. You can configure multiple email reports to be sent to different people on different schedules.
To access this feature in Jamf Pro, navigate to Devices > Search Inventory for an advanced mobile device search. Select a saved advanced mobile device search, and then click the Reports tab.
Note: This reports enhancement replaces the export method for downloading saved advanced mobile device search reports.
For more information, see the Mobile Device Reports section in the Jamf Pro Administrator's Guide.
Mass Update tvOS
You can now mass send an "Update tvOS Version to the latest version" remote command for tvOS 12 or later.
Computer Management Capabilities
Computer Configuration Profile Enhancements
You can now configure an Identity Preference in the Certificate and SCEP payloads of a computer configuration profile.
Added Criteria for Smart Computer Groups and Advanced Searches
You can now create a smart computer group and an advanced computer search with the following criteria:
Disable Automatic Login
Minimum Number of Complex Characters
You can use the Disable Automatic Login criteria to determine the state of the Disable Automatic Login setting. To view the status of this setting for a computer, navigate to the Security category of a computer's inventory information.
You can use the Minimum Number of Complex Characters criteria to determine which computers either meet or do not meet complexity compliance. To view the status of this setting for a computer, navigate to the Local User Account category of a computer’s inventory information.
FileVault Recovery Key Update
You can now enable FileVault individual recovery keys for macOS 10.14 using an existing valid recovery key or the management account, provided the management account has a secure token. Once again, you can use the recovery key to perform an authenticated restart. To perform an authenticated restart in Jamf Pro, navigate to Computers > Policies > Restart Options.
Additional Computer Policy Restart Option
You can now start the restart timer without requiring the user to acknowledge the restart message. To access this feature in Jamf Pro, navigate to Computers > Policies > Restart Options.
Apple Classroom Support for Mac Computers
When you create a class for use with Apple's Classroom app, Jamf Pro automatically creates an associated EDU profile that is installed on teacher Mac computers in addition to teacher iPads. This now allows teachers to use Mac computers to communicate with student iPads.
macOS Intune Integration Enhancement
When the macOS Intune Integration is enabled, you can now trigger a manual update of inventory attributes to be sent from Jamf Pro to Microsoft Intune. This ensures that Intune has up-to-date information for Mac computers that have Conditional Access policies applied to them. The update is independent of the standard communication schedule.
To trigger the update, navigate to Settings > Global Management > Conditional Access > macOS Intune Integration, and click Send Update.
jamf binary Return Code Descriptions
Starting with Jamf Pro 10.8.0, administrators can view return code descriptions for the policy and enroll verbs. Executing jamf help <verb> in Terminal will display the return code descriptions for that specific verb.
New Methods for Downloading the Jamf Pro Server Tools Command-Line Interface
You can now download the latest version of the Jamf Pro Server Tools Command-Line Interface using a package manager or browser. For instructions on each method, see the Using the Jamf Pro Server Tools Command-Line Interface Knowledge Base article.
Jamf Self Service for macOS
The name entered in the Application Name field now displays in the title bar and app menu. Previously, the name entered in the Branding Name field displayed in these locations.
Jamf Self Service for iOS
Jamf Self Service 10.8.0 includes several bug fixes and is the latest version of the Self Service app. It will be available in the App Store once it is approved by Apple.
Jamf Pro API Changes and Enhancements
The Jamf Pro API beta is open for user testing. The base URL for the Jamf Pro API is /uapi. To access the Jamf Pro API documentation, append "/uapi/doc" to your Jamf Pro URL. For example: https://jss.mycompany.com:8443/uapi/doc
Note: As the Jamf Pro API continues to be developed, changes will be made in future releases that may impact or break functionality. We strongly encourage that you test existing workflows using the Jamf Pro API before upgrading your production environment.
The Authorization header now uses the “Authorization: Bearer <token>” format to conform to the JWT standard. The “Authorization: jamf-token <token>” format has been deprecated and will be removed in a future release.
Tags in the Jamf Pro API have been reorganized to allow for easier navigation.
The Jamf Pro API Swagger documentation now includes default values in several endpoints to allow for easier use with client code generation and integrations.
The /settings/obj/enrollment/filteredLanguageCodes endpoint has been moved to settings/obj/enrollment/filtered-languages.
The following endpoints have been added under the /device-enrollment tag:
The following endpoints have been added under the /self-service tag:
The following endpoints have been added under the /inventory-preload tag:
Note: The inventory-preload endpoints currently apply to mobile devices only.
Other Changes and Enhancements
Jamf Pro now includes support for "Principal Name" for the SAN type when integrating with Active Directory Certificate Services (AD CS).
You can now display a message on a computer with macOS 10.14 or later when sending the Lock Computer remote command.
Added support for a future change to the unique device identifier (UDID) formatting.
Feature requests implemented in this release can be viewed at:
Privileges associated with new features in Jamf Pro are disabled by default.
It is recommended that you clear your browser's cache after upgrading Jamf Pro to ensure that the Jamf Pro interface displays correctly.