Jamf School: prepare direct URLs and OS 27
Jamf says that starting October 1, 2026, login.jamfschool.com will no longer provide access to Jamf School. Administrators must use their instance’s direct URL. The same release note lists payloads and keys deprecated following Apple changes in macOS, iOS, iPadOS and tvOS 27: two separate changes that institutions should address before their next critical operations.
1. A precise access deadline on October 1
Jamf instructs customers to use their institution’s direct address, in the form yourdomain.jamfcloud.com. Administrators who do not know it should contact their reseller or Jamf Support. This is not an announced instance outage: the generic entry point is being removed.
Preparation should nevertheless cover more than a browser bookmark. Runbooks, password vaults, IT portal links, on-call procedures and service-provider documentation may still contain the previous address. Every administrator should test the direct URL with their normal authentication flow before the deadline.
2. Restrictions deprecated with OS 27
Jamf marks the com.apple.applicationaccess.new safelist and blocklist payload as deprecated in macOS 27. The Camera, Microphone, Accessibility and SpeechRecognition keys in the Security & Privacy payload are also affected.
For iOS 27, iPadOS 27 and tvOS 27, Jamf names allowListedAppBundleIDs and blockedAppBundleIDs. The note says feature support is based on testing with the latest Apple beta releases. Deprecation does not, by itself, mean immediate removal: it calls for inventory, testing and a documented migration, not a rushed deletion of profiles.
3. What does this announcement change for a Belgian or French organization?
In a school, university or public-sector body, MDM access is part of service continuity: a lost or erased iPad, reassignment, exam session, start of term or security incident cannot wait for someone to find an instance URL. Small teams should at least record the direct address and an escalation contact. Multi-site organizations should verify that delegated teams, bookmarks and procedures point to the correct instance.
Security and compliance owners should map every deprecated key to its actual objective: privacy protection, application control or exam conditions. This register provides evidence of what remains enforced, what needs replacement and how the control will be tested on OS 27.
4. Underside view: test outcomes, not only profiles
Our view is that this note exposes two silent dependencies: human reliance on the generic portal and technical reliance on older keys. In both cases, seeing a configuration in the console proves neither effective access nor enforcement on the device.
A sound model links every item to an owner, deadline and evidence: successful sign-in through the direct URL, a pilot device for every relevant OS, observed MDM state and verified user behavior. This approach supports broader governance of Jamf MDM in Apple environments and app controls with OS 27.
5. Action plan before OS 27 deployments
- Identify and test the direct URL for every Jamf School instance.
- Replace
login.jamfschool.comin runbooks, bookmarks, vaults and internal portals before October 1. - Verify break-glass access and reseller or support contacts without sharing administrator accounts.
- Inventory the deprecated payloads and keys named by Jamf, including their scope and objective.
- Test profiles on a representative pilot group before broadly deploying OS 27.
- Retain results and anomalies to support the replacement decision for each control.
Objective: retain console access after October 1 and give every deprecated restriction an owner, a test and a replacement path.
Audit Apple management with JamfOfficial source: Jamf School Release Notes — 2026-09-01, published September 1, 2026 (accessed September 4, 2026).