Hi Jamf Community,
I’m looking for guidance on implementing Recovery Lock password rotation for existing Apple Silicon Macs already enrolled in Jamf Pro.
Current Setup
For newly enrolled Macs, we have enabled Recovery Lock through PreStage Enrollment.
This works as expected:
- Recovery Lock password is automatically generated.
- The password can be viewed from the device inventory in Jamf Pro.
- After the password is viewed, Jamf automatically rotates it after approximately 1 hour.
Challenge with Existing Macs
We also have a number of Apple Silicon Macs that were enrolled before Recovery Lock was enabled in our PreStage configuration.
For these existing Macs, I created a script that uses the Jamf Pro API with Client ID and Client Secret authentication.
The script successfully:
- Authenticates to Jamf Pro.
- Retrieves the Mac’s Management ID.
- Generates a random Recovery Lock password.
- Sends the
SET_RECOVERY_LOCKMDM command. - Successfully enables/updates Recovery Lock on the Mac.
This part is working as expected.
Problem
The issue is that Recovery Lock passwords set through the API do not appear to inherit the same automatic password rotation behavior as Recovery Lock configured through PreStage Enrollment.
For example:
PreStage-enrolled Mac:
Password viewed → Wait 1 hour → Jamf automatically rotates password
Existing Mac with Recovery Lock set through API:
Password viewed → No automatic rotation
What I’m Trying to Achieve
I would like to reproduce the PreStage behavior for our already-enrolled Macs:
Admin views Recovery Lock password in Jamf → Detect viewing event → Wait 1 hour → Generate new password → Send SET_RECOVERY_LOCK → Password rotated
Is there a supported way in Jamf Pro to detect when a Recovery Lock password has been viewed?
I’m particularly interested in whether this can be achieved using:
- Jamf Pro API / API audit history
- Jamf webhooks
- Jamf Routines
- Smart Groups
- Extension Attributes
- Jamf automation/workflows
- Another supported method
Ideally, I would like to detect the password-view event and then trigger another SET_RECOVERY_LOCK command one hour later.
Has anyone successfully implemented automatic Recovery Lock password rotation after viewing for existing enrolled Macs?
If there is an API endpoint, audit event, script, or workflow that can detect when the Recovery Lock password was viewed, I would really appreciate an example or some guidance.
Thanks in advance!
