Jamf Self Service+ 2.30: make Platform SSO reliable after a password change
Jamf Self Service+ 2.30.0 fixes a false out-of-sync password alert after a Mac using Platform SSO restarts following a Microsoft Entra ID password change. For IT teams, this removes support noise, but more importantly it should trigger an end-to-end identity test, from the directory change through to the local session.
1. What Jamf actually fixed
In release notes published on September 15, 2026, Jamf states that the issue affected Self Service+ 2.24 and later when Platform SSO was enabled. After changing an Entra ID password and restarting, the user could incorrectly receive a notification that the passwords were out of sync.
Version 2.30 also fixes missing Jamf Protect information in the Security dashboard, a skipped sign-in prompt when running a user-scoped policy through the Self Service command-line action, and several accessibility and post-re-enrollment branding defects.
2. Why a false identity alert matters in production
An incorrect alert can prompt users to repeat a password change, contact support, or question access to their Mac. It also obscures diagnosis: the directory, Platform SSO, the local password, and the FileVault token do not always describe the same state at the same moment.
The fix does not prove that every Entra ID configuration works. It removes a known Self Service+ defect. The organization's Platform SSO extensions, MDM profiles, Conditional Access rules, network conditions, and recovery procedures still require qualification.
3. What does this announcement change for a Belgian or French organization?
SMBs can reduce avoidable tickets by updating a small group of Macs and confirming the password-change journey. Mid-market organizations, large enterprises, and public bodies should add this scenario to their identity acceptance testing, especially when teams operate in French and English or support is distributed across sites.
For security leaders, the Security dashboard correction also matters: missing status in Self Service+ should no longer be too quickly interpreted as missing protection. The Jamf Protect console and central telemetry remain the control sources to reconcile with the user-facing display.
4. Underside view: test a journey, not a notification
Our view is that this fix exposes an often fragile operational boundary between cloud and local identity. A meaningful validation starts with the Entra ID password change, observes Platform SSO updating, restarts the Mac, verifies login, and confirms access to business resources.
This test complements the framework for Platform SSO on macOS and the preparation of Mac enrollment with Jamf Pro. Apple Business Manager and Automated Device Enrollment bind the Mac to the organization; Jamf and the IdP must then sustain a coherent identity experience throughout its lifecycle.
5. Recommended validation plan
- Identify Macs using Platform SSO, Self Service+ 2.24 or later, and Microsoft Entra ID.
- Deploy Self Service+ 2.30 to a representative pilot group before broad rollout.
- Change the Entra ID password, allow the expected synchronization, restart, and verify the local session.
- Separately check FileVault, recovery keys, Wi-Fi, VPN, and critical business applications.
- Compare the Self Service+ Security dashboard with the actual state in Jamf Protect.
- Update French and English support procedures and retain versions, profiles, and results as acceptance evidence.
Goal: make password changes predictable and observable without confusing a user notification, Platform SSO state, and compliance evidence.
Make Mac identity reliableOfficial source: Jamf — Self Service+ 2.30.0 Release Notes, published September 15 and reviewed September 16, 2026.