Jamf and Entra ID: remove two scopes before they break compliance
Jamf has retracted its guidance on enforcing Microsoft baseline scopes for device compliance. Organizations that followed it must remove microsoftCAScopes from Macs and MSAL_SCOPES from Self Service on managed devices, or compliance registration may fail.
1. What Jamf officially retracted
In the Jamf Pro 11.31 notes updated on August 13, 2026, Jamf says it removed an important notice and its related technical article because of unintended results with net-new integrations. The retracted guidance addressed Microsoft's baseline scope enforcement for device compliance.
Jamf gives two explicit instructions to customers who applied it: unscope every Mac from the profile that configures microsoftCAScopes in the com.jamf.management.jamfAAD preference domain, and remove the MSAL_SCOPES key from the Self Service managed app configuration. Jamf recommends contacting Support for assistance.
2. Why scope matters as much as deletion
A centrally deployed change may affect several populations: compliant Macs, devices still enrolling, mobile users and new Entra ID integrations. Removing a value from one profile without checking its effective scope leaves a risk that another profile, dynamic group or duplicated configuration applies it again.
Control should start at the Jamf source of authority, inventory every object containing either key, and follow removal through to devices. Teams need evidence of the previous value, the approved change, targeted devices and successful compliance registration afterward.
3. What does this change for a Belgian or French organization?
For an SMB, the priority is to establish whether the retracted guidance was actually deployed before changing anything. For a midmarket company, large enterprise or public administration in Belgium or France, Jamf, Entra ID, Conditional Access and security owners also need to coordinate so an MDM remediation is not mistaken for weaker control.
A device that no longer registers properly may receive an access decision different from the intended one. Teams should monitor registration failures, compliance status changes and tickets involving protected resources, without assuming that removing one setting will solve every Entra ID incident.
4. Underside analysis: treat retracted guidance as a controlled change
Our view is that these settings should neither remain in place nor be removed blindly fleet-wide. Confirm their presence, freeze new deployment, test removal with a pilot group, validate Jamf–Entra ID registration, then expand with a documented rollback path.
This remediation complements our Jamf Pro and Entra ID governance analysis and Jamf Pro 11.31 Mac enrollment validation. More broadly, vendor documentation changes: every compliance exception needs an owner, a review date and a recorded rationale.
5. Recommended remediation plan
- Find profiles that write
microsoftCAScopestocom.jamf.management.jamfAAD. - Find
MSAL_SCOPESin the Self Service managed app configuration. - Freeze new assignments and export the current scope before making changes.
- Remove the settings from a representative pilot group, then sync and inspect devices.
- Validate compliance registration, Conditional Access, and Jamf and Entra ID logs.
- Expand removal gradually and contact Jamf Support if the guidance had been applied.
Goal: remove an officially retracted configuration without creating a blind spot between MDM, identity and access control.
Audit your Jamf and Entra ID integrationOfficial source: Jamf Pro 11.31 Release Notes — Important Notices (updated August 13, 2026).