Skip to main content
Question

Jamf Connect Login not presenting OAuth window on some machines

  • August 20, 2026
  • 4 replies
  • 136 views

NickTeo
Forum|alt.badge.img+1

After wiping and re-enrolling lab machines, approximately 23 out of 29 are showing the native macOS username/password login window instead of the Jamf Connect Login OAuth window. The remaining 6 machines show the correct College branded Jamf Connect login screen.

 

What I've confirmed on the broken machines:

  • JamfConnectLogin.bundle is present in /Library/Security/SecurityAgentPlugins/
  • Jamf Connect Login is fully registered in the authorization database (security authorizationdb read system.login.console shows all JamfConnectLogin entries)
  • Jamf Connect Login v3.10 and Jamf Connect v3.10 configuration profiles are both installed
  • A StagedPlugins folder appears in /Library/Security/SecurityAgentPlugins/ after every restart but is always empty
  • No autologin configured
  • A conflicting LAB: Login Window Settings profile (com.apple.loginwindow payload) was previously scoped to these machines and has since been removed but this did not resolve the issue

Has anyone experienced Jamf Connect Login silently falling back to the native login window on macOS 26 (Tahoe) specifically?
Is there a known PPPC or Security & Privacy permission required for Jamf Connect Login 3.10 to activate on macOS 26?
Is the StagedPlugins folder appearing empty after a wipe a known issue?

4 replies

talkingmoose
Forum|alt.badge.img+36
  • Community Manager
  • August 21, 2026

This sounds like the Jamf Connect window may have never activated.

Be sure you’re controlling the order of operations when installing the configuration profiles and Jamf Connect login package.

The configuration profiles must be installed on the computer before you install the package. A post-install script in the package references the configuration profile for the identity provider you’ve configured. Depending on your identity provider, it’ll run the authchanger command to set the correct login window.

If the profiles aren’t present for the package to reference, this is the behavior you’ll see.

For those computers that have failed, add the authchanger command to a policy and scope to them to see if you can switch to the correct login window:

New Jamf Pro policy > Files and Processes payload > Execute Command:

/usr/local/bin/authchanger -JamfConnect

If you’re not using Jamf Pro, send the command to your computers using your existing management system.


GovindSharma
Forum|alt.badge.img+1
  • New Contributor
  • August 25, 2026

This sounds like the Jamf Connect window may have never activated.

Be sure you’re controlling the order of operations when installing the configuration profiles and Jamf Connect login package.

The configuration profiles must be installed on the computer before you install the package. A post-install script in the package references the configuration profile for the identity provider you’ve configured. Depending on your identity provider, it’ll run the authchanger command to set the correct login window.

If the profiles aren’t present for the package to reference, this is the behavior you’ll see.

For those computers that have failed, add the authchanger command to a policy and scope to them to see if you can switch to the correct login window:

New Jamf Pro policy > Files and Processes payload > Execute Command:

/usr/local/bin/authchanger -JamfConnect

If you’re not using Jamf Pro, send the command to your computers using your existing management system.

Tried the same command but no luck. ​@NickTeo did you find anything for the fix or root cause ?


talkingmoose
Forum|alt.badge.img+36
  • Community Manager
  • August 25, 2026

What response are you getting from the authchanger command?

If it’s not found, that indicates the Jamf Connect login software may never have installed in the first place. The command is part of the installer package.

Otherwise, more information about the result would help.


NickTeo
Forum|alt.badge.img+1
  • Author
  • New Contributor
  • August 26, 2026

This sounds like the Jamf Connect window may have never activated.

Be sure you’re controlling the order of operations when installing the configuration profiles and Jamf Connect login package.

The configuration profiles must be installed on the computer before you install the package. A post-install script in the package references the configuration profile for the identity provider you’ve configured. Depending on your identity provider, it’ll run the authchanger command to set the correct login window.

If the profiles aren’t present for the package to reference, this is the behavior you’ll see.

For those computers that have failed, add the authchanger command to a policy and scope to them to see if you can switch to the correct login window:

New Jamf Pro policy > Files and Processes payload > Execute Command:

/usr/local/bin/authchanger -JamfConnect

If you’re not using Jamf Pro, send the command to your computers using your existing management system.

Tried the same command but no luck. ​@NickTeo did you find anything for the fix or root cause ?

I did, it was a total overlook on my end, FileVault was enabled on the Lab devices and JAMF was prompting for local admin creds over a jamf connect login for saftey of the drive. If need be I can show you the config profile and policy I created to ensure that FileVault is off and remains off for the shared devices.