Hi everyone,
I’d like to raise a question and share some real-world challenges we’ve encountered regarding user switching on macOS devices enrolled via Jamf Pro and managed with Jamf Connect + Entra ID integration.
Scenario:
A Mac is enrolled in Jamf under one user (e.g., during setup), but then another user logs in and becomes the primary user of the device. This scenario is quite common in cases of device handoff, testing, or human error during deployment.
Observed Issues:
Incomplete Deployment of Policies and Apps:
After re-enrollment (even with full device removal from Jamf Pro and Entra ID), not all policies or apps are being deployed properly.
Device Registration & Compliance in Entra ID:
Devices sometimes fail to register properly in Entra ID.
Even if the device appears registered (sometimes duplicated 2–3 times), the "Compliance" status is either missing or errors out.
After several re-enroll attempts and manually removing the device from all platforms (Jamf, Entra ID, Intune), this can be resolved — but it’s inconsistent and time-consuming.
Jamf Connect Password Sync / Change Issues:
In one case, I couldn’t change the password via Jamf Connect after switching users.
It redirected to the “My Profile” page in the browser, but Entra ID claimed the device wasn’t registered — despite the device ID in the logs matching what’s in Entra ID.
Essentially, the user experience broke, and password sync became impossible.
Questions:
How bad is this practice technically — switching users after enrollment? Are we breaking expected workflows in Jamf Connect and Jamf Pro?
Has anyone else experienced issues with Entra ID device registration/compliance when a different user starts using the device?
What’s the best practice for handling user transitions on Jamf-managed macOS devices? Is full wipe and re-enrollment the only reliable method?
Are there logs or tools you recommend to better diagnose device-user mismatches or broken compliance registration?
Any advice, insights, or similar experiences are welcome. Thanks in advance!