Skip to main content

Issues with password sync on Jamf Connect Login 3.5 / Tahoe 26.1

  • November 21, 2025
  • 2 replies
  • 154 views

Forum|alt.badge.img

We recently upgraded from Jamf Connect Login 3.3 to 3.5 to fix a keychain popup bug from earlier this month:

This had the unintended consequence of breaking the “password sync” feature of self service +:

Clicking the link to “Sync password” leads to a greyed out credential screen. This screen contains the correct email address and presumably correct password.

The “change password” feature of self service plus seems to work, the local password and idp password will match afterwards, but self service plus doesn’t recognize them as being synced.

Initially we assumed it was because we did not update configuration profiles to match when deploying 3.5, however after some testing even valid new config profiles seem to result in the same behaviour, despite OIDC and ROPG tests working in the configuration app.

Has anyone else seen the same issues in the past week or two?

IDP: Microsoft Entra

****************************

macOS: Tahoe 26.1

****************************

JamfConnect:Menubar
Version: 2.13.0
Build: 2.13.9251104.1
****************************
JamfConnect:Login
Version: 3.5.0
Build: 6785
****************************
JamfConnect:Configuration
Version: 3.5.0
Build: 3577
****************************
JamfConnect:Daemon
Version: 3.5.0
Build: 621
****************************
JamfConnect:SSPDaemon
Version: 3.11.0
Build: 619
****************************

2 replies

Chubs
Forum|alt.badge.img+21
  • Jamf Heroes
  • November 21, 2025

Check your keychain. We noticed this previously and part of the sync flow was breaking due to the inability to receive the response from Entra. 
 

are you using a DNS filter at all like cloudflare?


Forum|alt.badge.img
  • Author
  • New Contributor
  • November 25, 2025

We seem to have fixed this by adding “Client ID (Password Verification)” to preference domain com.jamf.connect.

We have always had that key in com.jamf.connect.login, but our theory is that it became required in com.jamf.connect when upgrading to Self Service Plus or Jamf Connect 3.5.