Back to blog

Jamf Pro 11.32: secure ADE accounts before upgrading

Article created September 19, 2026 · Source reviewed September 19, 2026 · Official source: Jamf Pro 11.32 release notes · Topic: Jamf, Automated Device Enrollment and Apple Business Manager

Jamf Pro 11.32 fixes an issue that could delete Automated Device Enrollment account details when upgrading to Jamf Pro 11.27.0 through 11.31.x if multiple instances shared one MDM server in Apple Business Manager or Apple School Manager. For IT leaders, the fix is a reason to treat the ADE connection as a critical, verifiable dependency of zero-touch deployment.

1. What Jamf officially fixed

In the resolved issues for Jamf Pro 11.32, Jamf identifies defect PI200840. Its wording is precise: upgrading to a version from 11.27.0 through 11.31.x could delete Automated Device Enrollment account details for instances that shared an MDM server in Apple Business Manager or Apple School Manager.

Jamf does not say that every environment was affected or that device assignments in Apple Business Manager were deleted. The finding should not be broadened: the documented risk concerns ADE account details held in Jamf Pro within this particular topology.

2. Why the ADE connection is a production dependency

Automated Device Enrollment connects ownership recorded in Apple Business Manager to the device management service and the profile shown during Setup Assistant. If Jamf Pro can no longer use the account configuration, new Mac, iPhone and iPad devices may not follow the intended enrollment, supervision and initial configuration path.

The impact is therefore not confined to an administration screen. It can affect employee onboarding, urgent replacements, device return-to-service and bulk operations. Our guide to qualifying Jamf Pro 11.32 covers compatibility and inventory; this control focuses on continuity between Apple Business Manager and MDM.

3. What does this fix change for a Belgian or French organization?

For an SMB using one instance, the documented topology may not apply, but checking the ADE account is still a simple pre-upgrade control. For a mid-market company, large enterprise, public body or group operating across Belgium and France, several instances may coexist to separate subsidiaries, environments or operational responsibilities.

These organizations should explicitly identify instances sharing the same Apple-side MDM server, assign ownership of the connection and preserve evidence before and after the upgrade. A responsive console and current inventory do not prove that a new device will complete zero-touch enrollment correctly.

4. Underside analysis: verify the chain, not only the version

Our view is that an MDM upgrade should never be approved solely from server health. The trust chain includes Apple Business Manager, the ADE token or account, assignment to the MDM server, the enrollment profile, device activation and the configurations applied after Setup Assistant.

Jamf Pro 11.32 fixes the reported defect, but it does not replace backups, a pilot or functional evidence. Underside recommends documenting each connection, limiting shared accounts, testing a representative device and maintaining a restoration procedure aligned with Jamf documentation and internal controls.

5. Pre- and post-upgrade control plan

Objective: turn the Jamf Pro 11.32 upgrade into evidence of Apple deployment continuity, from Apple Business Manager assignment to MDM policy delivery.

Secure your ADE and Jamf chain

Official source: Jamf Pro 11.32 — Resolved Issues, defect PI200840, accessed and reviewed September 19, 2026.