Skip to main content
Question

Jamf Connect created users (without enrollment customization), MDM capable users, and macOS 27

  • September 11, 2026
  • 3 replies
  • 218 views

bwoods
Forum|alt.badge.img+14

Do we need to re-enroll all of our computers to make users MDM capable?
 

3 replies

bartzach86
Forum|alt.badge.img
  • New Contributor
  • September 14, 2026

That seems to be the best option for now. You can save yourself from erasing the Mac though: https://philipross.github.io/posts/Retroactively-activating-user-channel/. Tried that few hours ago and it worked ok (except enrollmentComplete trigger on policies and conf. profiles being reapplied).


bwoods
Forum|alt.badge.img+14
  • Author
  • Honored Contributor
  • September 14, 2026

Same idea as ​@bartzach86’s article above to get ADE devices re-enrolled. I also use it for expired MDM profiles: https://ordonez.tv/2025/12/20/fixing-mdm-communications-with-apple-business-manager-migration/

I would also suggest enabling enrollment customization ( With Jamf Connect) or switching to PSSO (password method) for new devices.


bwoods
Forum|alt.badge.img+14
  • Author
  • Honored Contributor
  • September 14, 2026

For more context:

With the release of macOS 27, it appears that we will no longer be able to deploy system-level Accessibility TCC/PPPC configuration profiles. Instead, we will need to use user-level App Configuration declarations. The challenge is that when Jamf Connect creates a local account, that account is not MDM-capable. As a result, Jamf Pro cannot apply the required user-level configurations to the account, creating a potential management issue for environments that currently rely on Jamf Connect.