Jamf Pro Cloud: prepare for the end of legacy admin authentication
In the official Jamf Pro 11.30.0 release notes, Jamf announces an important deprecation for cloud-hosted Jamf Pro instances: legacy non-OIDC administrator authentication methods, including local Jamf Pro accounts, SAML, SAML failover login URLs, LDAP and directory services, should be replaced with OIDC authentication before their planned removal in the second half of 2027.
1. What Jamf officially announces
The Deprecations and Removals section of the Jamf Pro 11.30.0 release notes states that this deprecation applies to administrator sign-in for cloud-hosted Jamf Pro instances. Jamf says on-premise instances are not affected by this item and recommends migrating to a supported method such as Jamf ID or federation through an OIDC-compliant identity provider.
Jamf also connects the migration to platform security and readiness for declarative management capabilities. The operational message is clear: Jamf administrator access should no longer depend on local accounts or inherited identity mechanisms when the console controls MDM, Blueprints, updates and sensitive actions across the Apple fleet.
2. Why this is more than an SSO migration
A Jamf Pro console provides access to critical functions: MDM configuration, device wipe or lock, profiles, apps, scripts, certificates, inventory, logs and compliance policies. Changing administrator sign-in therefore affects service continuity, emergency procedures and privilege control.
The deprecation of SAML failover URLs deserves specific attention. Many teams treat them as a safeguard when identity is unavailable, but Jamf says it plans to introduce replacement options before they are removed. IT leaders should document now how Jamf will remain accessible if the IdP, MFA, a conditional rule or OIDC federation blocks administrators.
3. What does this announcement change for a Belgian or French company?
For an SMB, the practical change is moving away from a model where one or two historical local accounts are enough to administer the full Apple fleet. Teams need to identify privileged accounts, enable strong authentication, test access recovery and avoid a situation where one administrator or one provider controls Jamf continuity.
For a mid-market company, large enterprise or public body active in Belgium and France, the topic becomes an identity project: Entra ID or other IdP governance, admin groups, MFA, break-glass accounts, local delegation, logging, NIS2 or ISO 27001 expectations and bilingual support procedures. The goal is not only successful OIDC sign-in, but proof that Apple administration remains available and controlled.
4. Underside analysis: secure access before modernizing MDM
Our read is that this Jamf announcement should be handled before more visible MDM modernization projects. An organization may have Apple Business Manager, Automated Device Enrollment, Jamf, Platform SSO and declarative updates well framed; if Jamf administrator access still relies on poorly documented legacy mechanisms, the operational risk remains high.
For Underside, the right framework connects identity, least privilege, access continuity, audit evidence and Apple operations. This complements our analysis of Jamf Pro 11.30, Apple declarative patching and Platform SSO: administrator identity should be governed as tightly as user identity.
5. Recommended control points
- Inventory the Jamf Pro administrator sign-in methods used today: local, SAML, LDAP, directory service, Jamf ID or OIDC.
- Identify high-privilege accounts, shared accounts and provider access.
- Define an OIDC target with groups, MFA, conditional rules and logging compatible with support constraints.
- Test an IdP access-loss scenario without relying on a failover URL that is scheduled to disappear.
- Document Jamf roles, local delegations and English/French administrator recovery procedures.
- Align this migration with Apple Business Manager, MDM, Jamf, compliance and IT continuity plans.
Goal: treat Jamf administrator authentication as a critical Apple fleet control, with OIDC, MFA, access recovery and audit evidence ready before the announced deadline.
Audit your Jamf Pro governanceOfficial source: Jamf Pro Release Notes 11.30.0, Deprecations and Removals.