Jamf Pro 11.32: secure ADE accounts before upgrading
Jamf Pro 11.32 fixes an issue that could delete Automated Device Enrollment account details when upgrading to Jamf Pro 11.27.0 through 11.31.x if multiple instances shared one MDM server in Apple Business Manager or Apple School Manager. For IT leaders, the fix is a reason to treat the ADE connection as a critical, verifiable dependency of zero-touch deployment.
1. What Jamf officially fixed
In the resolved issues for Jamf Pro 11.32, Jamf identifies defect PI200840. Its wording is precise: upgrading to a version from 11.27.0 through 11.31.x could delete Automated Device Enrollment account details for instances that shared an MDM server in Apple Business Manager or Apple School Manager.
Jamf does not say that every environment was affected or that device assignments in Apple Business Manager were deleted. The finding should not be broadened: the documented risk concerns ADE account details held in Jamf Pro within this particular topology.
2. Why the ADE connection is a production dependency
Automated Device Enrollment connects ownership recorded in Apple Business Manager to the device management service and the profile shown during Setup Assistant. If Jamf Pro can no longer use the account configuration, new Mac, iPhone and iPad devices may not follow the intended enrollment, supervision and initial configuration path.
The impact is therefore not confined to an administration screen. It can affect employee onboarding, urgent replacements, device return-to-service and bulk operations. Our guide to qualifying Jamf Pro 11.32 covers compatibility and inventory; this control focuses on continuity between Apple Business Manager and MDM.
3. What does this fix change for a Belgian or French organization?
For an SMB using one instance, the documented topology may not apply, but checking the ADE account is still a simple pre-upgrade control. For a mid-market company, large enterprise, public body or group operating across Belgium and France, several instances may coexist to separate subsidiaries, environments or operational responsibilities.
These organizations should explicitly identify instances sharing the same Apple-side MDM server, assign ownership of the connection and preserve evidence before and after the upgrade. A responsive console and current inventory do not prove that a new device will complete zero-touch enrollment correctly.
4. Underside analysis: verify the chain, not only the version
Our view is that an MDM upgrade should never be approved solely from server health. The trust chain includes Apple Business Manager, the ADE token or account, assignment to the MDM server, the enrollment profile, device activation and the configurations applied after Setup Assistant.
Jamf Pro 11.32 fixes the reported defect, but it does not replace backups, a pilot or functional evidence. Underside recommends documenting each connection, limiting shared accounts, testing a representative device and maintaining a restoration procedure aligned with Jamf documentation and internal controls.
5. Pre- and post-upgrade control plan
- Inventory Jamf Pro versions and the instances connected to each MDM server in Apple Business Manager.
- Identify instances sharing an MDM server and confirm their ADE accounts, profiles and operational owners.
- Perform the backups and preflight checks required by the organization’s Jamf procedure.
- Deploy Jamf Pro 11.32 first in a test environment or controlled pilot window.
- After the upgrade, verify ADE account status, device synchronization and profile assignments.
- Erase or use an authorized pilot device to validate the full Automated Device Enrollment path through policy application.
- Keep screenshots, logs, test times and rollback criteria in the change record.
Objective: turn the Jamf Pro 11.32 upgrade into evidence of Apple deployment continuity, from Apple Business Manager assignment to MDM policy delivery.
Secure your ADE and Jamf chainOfficial source: Jamf Pro 11.32 — Resolved Issues, defect PI200840, accessed and reviewed September 19, 2026.