Skip to main content
Question

Bootstrap Token not supported on server Error


Forum|alt.badge.img+3

Hello People, While troubleshooting a failed policy deployment I came across this error message
Error: Bootstrap token must be escrowed to the Jamf Pro server in order for computers with Apple Silicon (i.e., M1 chip) to use RestartDevice MDM command.

I tried manually with “sudo profiles install -type bootstraptoken” but I got this error
Bootstrap Token functionality is not supported on the server.

 

My user is an admin and has securetoken enabled according to “sysadminctl -secureTokenStatus

sudo fdesetup list -extended” also lists my user admin as Volume owner and I have filevault enabled.

I can also carry out update on the computer without issues.

The laptop operates like a test computer and I have had to enrol and unenrol it multiple times. could that be the cause of the Bootstrap Token functionality is not supported on the server. error?

Some information about my setup

Computer operates more or less like a test laptop and gets unenrolled and enrolled to jamf multiple times.
JAMF Cloud Version is 11.1.1-t1701704198
Enrollment is via user initiated

I noticed a couple of computers in our JAMF inventory seem to have been affected by this issue but not all of them.I got scant results from my search about this particular Bootstrap Token functionality is not supported on the server error and got very scant result, both on google and on hereI would really appreciate any insight on this

7 replies

Forum|alt.badge.img+15
  • Esteemed Contributor
  • 719 replies
  • January 11, 2024

We've had a few Macs in our environment lately where bootstrap token is reported as Not Supported. So far, the only fix I've found is to remove the MDM profile for that Mac, delete the computer record from Jamf and then re-enroll it. Re-enrolling without deleting the computer record in Jamf will result in the same bootstrap token Not Supported problem.


Forum|alt.badge.img+1
  • New Contributor
  • 5 replies
  • October 3, 2024
cbrewer wrote:

We've had a few Macs in our environment lately where bootstrap token is reported as Not Supported. So far, the only fix I've found is to remove the MDM profile for that Mac, delete the computer record from Jamf and then re-enroll it. Re-enrolling without deleting the computer record in Jamf will result in the same bootstrap token Not Supported problem.


@cbrewer I re-enrolled a device after removing all profiles from the Mac by using the commands:

cd /var/db/ConfigurationProfiles

sudo rm -rf *

sudo mkdir Settings

sudo touch Settings/.profilesAreInstalled

To remove the profiles from the device and used the following command to enrol the Mac:

sudo profiles renew -type enrollment

However after doing this I got the same error same error 

Bootstrap Token functionality is not supported on the server.

Are there any other commands or solutions I can try to resolve this error?

Kind regards,

Owen Burton


Forum|alt.badge.img+15
  • Esteemed Contributor
  • 719 replies
  • October 3, 2024
owen_burtonrg wrote:

@cbrewer I re-enrolled a device after removing all profiles from the Mac by using the commands:

cd /var/db/ConfigurationProfiles

sudo rm -rf *

sudo mkdir Settings

sudo touch Settings/.profilesAreInstalled

To remove the profiles from the device and used the following command to enrol the Mac:

sudo profiles renew -type enrollment

However after doing this I got the same error same error 

Bootstrap Token functionality is not supported on the server.

Are there any other commands or solutions I can try to resolve this error?

Kind regards,

Owen Burton


Did you delete the computer record from Jamf Pro before re-enrolling?


Forum|alt.badge.img+1
  • New Contributor
  • 5 replies
  • October 3, 2024
owen_burtonrg wrote:

@cbrewer I re-enrolled a device after removing all profiles from the Mac by using the commands:

cd /var/db/ConfigurationProfiles

sudo rm -rf *

sudo mkdir Settings

sudo touch Settings/.profilesAreInstalled

To remove the profiles from the device and used the following command to enrol the Mac:

sudo profiles renew -type enrollment

However after doing this I got the same error same error 

Bootstrap Token functionality is not supported on the server.

Are there any other commands or solutions I can try to resolve this error?

Kind regards,

Owen Burton


I have solved this by re-issuing the FileVault key after re-enrolling the Mac.


Forum|alt.badge.img+1
  • New Contributor
  • 5 replies
  • October 3, 2024
cbrewer wrote:

Did you delete the computer record from Jamf Pro before re-enrolling?


I did remove the Mac from Jamf before re-enrolling.


Forum|alt.badge.img+1
  • New Contributor
  • 5 replies
  • October 4, 2024
cbrewer wrote:

We've had a few Macs in our environment lately where bootstrap token is reported as Not Supported. So far, the only fix I've found is to remove the MDM profile for that Mac, delete the computer record from Jamf and then re-enroll it. Re-enrolling without deleting the computer record in Jamf will result in the same bootstrap token Not Supported problem.


@cbrewer Is there a way to run the following commands without disabling System Integrity Protection?

cd /var/db/ConfigurationProfiles

sudo rm -rf *

sudo mkdir Settings

sudo touch Settings/.profilesAreInstalled

We don't to have users to go into recovery mode and disable SIP to resolve this issue. And if possible would prefer to have a script which and re-enrol a Mac into Jamf after removing the record. Thanks for your help in advance.


Forum|alt.badge.img+9
  • Valued Contributor
  • 59 replies
  • February 20, 2025
owen_burtonrg wrote:

I have solved this by re-issuing the FileVault key after re-enrolling the Mac.


I know that this is an old thread, but I am running into the exact same thing...how did you reissue a FV key?


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings