Description
Self Service+ brings a modernized end user experience, but migrating from Self Service classic in a Jamf Connect environment requires careful attention to deployment order and configuration. Without it, end users are likely to encounter repeated Keychain access prompts and broken branding. This workflow outlines the recommended steps to address both.
Before You Begin
Self Service+ must install before Jamf Connect Login. Installing in the wrong order is the primary cause of repeated Keychain prompts.
Jamf Connect Login 3.6+ is required if your organization uses custom branding.
Existing Jamf Connect configuration profiles require no changes — preference domains remain compatible across 2.x and 3.x.
Migrating Self Service Classic to Self Service+
In Jamf Pro, go to Settings > Jamf Apps > Self Service+ and check Use Self Service+ as the default end user application. This deploys Self Service+ to all enrolled Macs on macOS 13+ at next check-in and removes Self Service classic.
Download the Self Service+ PKG from Jamf Account.
Upload it to Jamf Pro under Settings > Computer Management > Packages, and add it to your PreStage Enrollment under Computers > PreStage Enrollments > [Your PreStage] > Packages. Name it
0_selfservice+.pkgto ensure it installs before Jamf Connect Login.Note: When Self Service+ is included in PreStage and installs before Jamf Connect Login, the correct Keychain ACL entries are established during enrollment — preventing the repeated Keychain access prompts end users would otherwise see on every reboot.
Download the Jamf Connect Login 3.x PKG from Jamf Account, upload it to Jamf Pro, and add it to the same PreStage Enrollment. Name it
1_jamfconnectlogin.pkgso it installs after Self Service+.Add your Jamf Connect Configuration Profiles to the PreStage Enrollment. No changes to existing profiles are needed.
Scope Jamf App Installers — Jamf Connect Login 3.x to devices to handle ongoing updates post-enrollment.
Scope Jamf Connect Configuration Profiles to devices
Note: If a Jamf Connect LaunchAgent is currently deployed, remove it. Self Service+ includes its own LaunchAgent that handles the same functions — having both will prevent the Jamf Connect / Self Service+ Menu Bar from loading.
In Jamf Pro, go to Settings > Self Service > Branding. If a macOS Branding entry exists, open it and change the Application Header from
Self ServicetoSelf Service+.Note: If you need to push this immediately, run the following via a Jamf Pro Policy (Files and Processes > Execute Command):
selfservice branding brand --name "Self Service+"
