802.1x WiFi and LAN profiles disappearing

infrase2020
New Contributor III

Hi all,

We have a strange issue that i am hoping you can help with. 

We have had around 10-15 instances where 802.1x WiFi and LAN profiles disappear from a users device. 

To give some context, its a single profile with LAN and Wifi 802.1x networks with a single SCEP profile, the issue happens on all kinds of devices on different versions of Sonoma and Sequoia. 

 

The profile shows as installed on Jamf and the device however the SSID is missing from known networks. 

The fix is to exclude the device from the profile and then remove the exclusion and the profile reinstalls and all is good.

We've logged a ticket with support and they have ruled out Jamf and said its an Apple issue and to log it with them.

Has anyone else come across this and been able to resolve it? 

 

Its so frustrating as its so sporadic and we cannot reproduce the issue on demand so its proving difficult to resolve.

Thanks in advance. 

 

3 REPLIES 3

howie_isaacks
Valued Contributor II

That is really odd. What do you see for each affected Mac when you look at the log for the profile? Since the profile installs after excluding and removing the exclusion, the Macs are obviously in scope initially. Is the profile scoped to "All Computers" or to a smart group? If it's a smart group, something could be causing these systems to leave the smart group.

Hi @howie_isaacks - thanks for the reply.

The profiles show as installed on the device (In system settings) but when you go onto the wifi networks they have been removed from the known network. 

I don't think its a smart group issue as this group is used on other profiles without any issues and the device shows in the list. We also ruled the group out as if we exclude the device and then remove it the profile gets redeployed! 

 

It seems like a bug but we are unable to prove it and hoping someone else has had the same issue and been able to resolve it. 

 

I know that in macOS 15, if 'Private IP Address' is set to 'fixed' (default setting) instead of 'Off' a ClearPass authentication server (if you use those) will reject the authentication connection and your Wi-Fi network will disappear from known networks.  The configuration profile will still be installed and the wi-fi network configuration will still be listed under the ADVANCED button at the bottom of Wi-Fi settings in System Settings.  To re-join the network you have to set Private IP Address to Off and then click OTHER at the bottom of the list of found Wi-Fi networks.  Enter the name of the Wi-Fi network, enther the network authentication type ie. WPA2-Enterprise etc, Enter the EAP-TLS, there is no username or password.  Click connect, and the Wi-Fi network should reappear in the list.   It is a macOS bug and I have only seen it on macOS 15 because of the issues caused by the new Private IP Address setting.  It's caused by a failed connection attempt to an 802.1x Wi-Fi network (in our case ClearPass).