Jamf Pro 11.30: reframe authentication, inventory and Apple logs
Jamf Pro 11.30.0 is not just an administration update. Jamf's official notes highlight changes that affect Apple enterprise fleet governance directly: Jamf ID passkeys, narrower Microsoft Entra ID permissions, embedded domain verification, Last Contact attributes in inventory, and changes to Apple log collection.
1. What Jamf announces in Pro 11.30
In the official Jamf Pro 11.30.0 release notes, Jamf says environments using OIDC-based authentication through Jamf Account can now use a passkey with Jamf ID, either as a sign-in method or as part of MFA. Jamf also states that organization administrators can view login history and whether Jamf IDs have passkeys enabled, without managing other users' passkeys.
The same version reduces the scope of new Microsoft Entra ID connections: Jamf uses GroupMember.Read.All and User.Read to retrieve group data instead of Directory.Read.All. Jamf also adds embedded domain verification for the Microsoft Entra ID SSO consent flow, plus Last Contact attributes for computer and mobile-device inventory reporting, smart groups and advanced searches.
2. Why this matters for Apple IT teams
For IT leadership, these changes connect four areas that are often handled separately: administrator access, cloud permissions, fleet visibility and advanced support. A Jamf console carries powerful rights over Macs, iPhones and iPads, so hardening console access and reducing Entra ID permissions is not a cosmetic security preference.
The Last Contact attribute also makes controls more operational. Teams can isolate devices that no longer report correctly through the Jamf binary, MDM or declarative device management, then trigger support or compliance action before the gap disappears into monthly reporting.
3. What does this announcement change for a Belgian or French business?
For a Belgian or French SMB, Jamf Pro 11.30 is a prompt to review administrator accounts, Jamf ID passkey adoption and smart groups based on contact freshness. For mid-market organizations, large enterprises and public bodies, the impact is broader: align Entra ID, Jamf Account, logging, privilege delegation, compliance and field support.
In organizations spread across Belgium, France and several European sites, the reduced Entra ID permission model also helps security and compliance discussions. It makes it easier to justify why the Jamf integration does not need broader directory access than necessary while keeping the group data required for automation.
4. Underside analysis: govern Jamf as a critical platform
Our read is that Jamf Pro should be treated as a critical Apple identity and operations platform, not only as an MDM console. The question is not whether to enable a new passkey option; it is who administers what, with which access evidence, which Entra ID permissions, which dynamic groups and which support-escalation path.
For Underside, an Apple enterprise Belgium or Apple enterprise France project needs to connect Apple Business Manager, Automated Device Enrollment, Jamf, MDM, SSO, inventory, log collection and helpdesk procedures. That coherence is what lets an Apple fleet operate without relying on fragile manual actions.
5. Recommended control points
- Identify high-privilege Jamf ID accounts and define passkey and MFA expectations.
- Compare existing Entra ID permissions with the new
GroupMember.Read.AllandUser.Readscope. - Test embedded domain verification in a non-critical environment before modifying existing SSO flows.
- Create smart groups based on Last Contact to identify silent Macs, iPhones and iPads.
- Document who can trigger or cancel Apple log collection, and under which conditions logs may be transmitted.
- Update French and English runbooks for support, security, compliance and Jamf escalation.
Goal: turn Jamf Pro 11.30 into an operational governance review. The value sits in administrator identity, least privilege, inventory quality and Apple support traceability.
Review your Jamf and Apple MDM governanceOfficial sources: Jamf Pro Release Notes 11.30.0, Improvements to Jamf Platform Authentication, Inventory Reporting and Improvements to Enhanced Log Collection.