Back to blog

Jamf Pro 11.31: secure mass actions across Apple fleets

Article created on 18 August 2026 · Source reviewed on 18 August 2026 · Official source: Jamf · Topic: Jamf Pro, Apple MDM, security and governance

In the Jamf Pro 11.31 release notes, Jamf announces eight upcoming privileges dedicated to mass actions across Mac, iPhone and iPad. The measure reduces the blast radius of a compromised account or operational mistake, but requires organizations to identify now which administrators and API clients lock, wipe, unmanage or delete devices at scale.

1. What Jamf officially announced

Jamf plans separate privileges for sending mass lock, wipe and unmanage commands, as well as deleting inventory records in bulk. Each of these four capabilities will be split between computers and mobile devices, resulting in eight privileges.

Until now, the matching single-device privilege was sufficient to perform the same action in bulk. Jamf states that the new rights will not be granted automatically to any existing account and will not be included in the Administrator privilege set. They are scheduled for an upcoming release; Jamf Pro 11.31 is therefore an advance notice, not the effective change yet.

2. Why this goes beyond an interface option

A single-device action and an action affecting hundreds of devices do not carry the same risk. A mass lock can interrupt work; a wipe destroys local data; unmanaging removes MDM control; deleting inventory damages traceability. Separating the rights applies least privilege to scale, not only to the action type.

The change also affects integrations. An API client for device redeployment, an incident-response tool or an employee offboarding workflow may currently hold the single-device right and use it against a selection. Unless its custom privilege set is adapted, that automation may fail when Jamf enables the new controls.

3. Audit human and machine identities

The inventory should cover local administrator accounts, Jamf Account authentication, federated groups, API clients and secrets used by orchestrators. For every identity, document the mass action that is genuinely required, the Mac or mobile scope, owner, business justification and revocation mechanism.

Teams should separate daily administration, support, security, lifecycle management and automation. A technician allowed to wipe one lost iPhone should not automatically receive mass-wipe rights. An API client that removes stale inventory records does not need permission to unmanage devices.

4. What does this announcement change for a Belgian or French organization?

For an SME, the priority is to prevent one general-purpose administrator account from concentrating every irreversible operation. For a mid-market company, large enterprise or public body in Belgium or France, the split supports a more defensible access matrix during an ISO 27001, NIS2 or internal audit, without constituting compliance evidence by itself.

IT and security leaders should also connect Jamf to identity processes: administrator departures, periodic access reviews, API-secret rotation, logging and dual approval. Apple Business Manager and Automated Device Enrollment can re-enroll some devices, but they cannot reverse data loss or downtime caused by an incorrect mass command.

5. Underside analysis: isolate the right, control the workflow

Our view is that the eight privileges should remain exceptional and be attached to dedicated roles. Permanently granting them to every administrator would recreate the risk Jamf is trying to reduce. For APIs, one client per workflow limits blast radius and makes audit logs easier to interpret.

Control should not end with RBAC: every mass action should require a verifiable target set, an alert threshold, approval where impact is high and evidence after execution. This preparation complements the move to Jamf Account and OIDC authentication: strong identity protects access, while dedicated privileges restrict what that identity can trigger.

6. Recommended preparation plan

Objective: preserve useful automation while preventing an ordinary account or API client from turning a single-device mistake into a fleet-wide incident.

Audit your Jamf privileges

Official source: Jamf Pro 11.31 Release Notes — Upcoming New Privileges for Mass Actions.