Description
This article provides steps to take if a computer is not checking in with Jamf Protect.
Troubleshooting Steps
If the computer has never checked in with Jamf Protect:
Ensure the Jamf Protect agent (pkg) and plan configuration profile have been installed on the computer. For more information, see Jamf Protect Deployment on the Jamf Learning Hub.
If the computer has previously checked in but is now failing (e.g. showing "Unable to contact server"):
Run
sudo protectctl info -vandsudo protectctl checkinin Terminal and review the output. If you see an "Unable to contact server" error, proceed with the steps below.
Resolving "Unable to contact server" Errors
If the computer has previously checked in but now shows a server connection error, the most reliable resolution is to fully remove and reinstall the Jamf Protect agent to clear any corrupted keychain credentials.
Run the Jamf Protect uninstaller package on the client machine. For instructions, see Uninstalling Jamf Protect on the Jamf Learning Hub.
Remove any Jamf Protect configuration profiles from the computer by adding it as an exclusion for the profile in Jamf Pro.
Open Keychain Access and confirm the uninstaller removed all Jamf Protect-specific items from the Login and System Keychains (look for the WSS authorizer key and any Jamf Protect public/private keys).
Remove the computer from the exclusions list in Jamf Pro so the Jamf Protect configuration profile is reapplied.
Push the latest Jamf Protect installer to the computer.
Confirm the configuration profile was received:
sudo /usr/local/bin/protectctl checkin --insightsVerify the computer checks in successfully:
sudo /usr/local/bin/protectctl checkin
