Skip to content

Release Notes

Karthikeyan Marappan edited this page Sep 27, 2026 · 7 revisions

Release Notes — AxM Jamf Sync


v3.0

September 2026

What's New

Command-Line Mode

  • New --silent flag runs a full sync with no window, no Dock icon, and no notifications — for launchd, cron-style scheduling, or scripting. It's the same signed app, using the same environments, credentials, cache, and settings you've already set up
  • Writes warranty/purchase data back to Jamf Pro, the same as Run Sync in the app — a full sync, not a preview
  • --env <name> syncs just one or more named environments; --help prints full usage
  • A ready-to-edit sample LaunchAgent for unattended scheduling ships in the repo under docs/launchd/
  • Every log line is now tagged [GUI] or [CLI] so you can tell which one wrote it, in both the shared sync.log and each environment's own log
  • If a scheduled command-line sync fails before it even starts (e.g. no environment configured yet), the app shows a one-time alert the next time you open it, instead of that failure only ever showing up in a log file nobody's watching

Update Checker

  • The app now checks GitHub for newer releases — once a day automatically, or on demand from AxM Jamf Sync → Check for Updates… or Settings → General
  • Shown as an Update Available item in the menu bar, or a dialog with release notes for an on-demand check, with View Release / Skip This Version / Later
  • Never downloads or installs anything on its own — it only tells you a newer version exists and opens its release page

Sidebar & Setup

  • An environment shows Syncing (command-line) in the sidebar while a --silent run is in progress for it, instead of looking idle
  • Renaming, deleting, or editing credentials for that environment is disabled until the command-line sync finishes, with an explanation instead of a silent no-op
  • Every environment's ID is available from a right-click (Copy Environment ID) or a hover tooltip — useful for --env and for matching a log file to its environment

Reliability

  • Fixed a crash that could fail an entire sync just because Jamf wasn't configured or authenticated. A background or scheduled sync with real AppleCare coverage data waiting to be written, but no working Jamf connection, used to fail outright with an unrelated-looking error. It now does exactly what it does when Jamf credentials are simply missing: leaves those devices pending and finishes normally.
  • Fixed reopening the app being able to silently kill an in-progress command-line sync. Under specific conditions — most likely to come up right after a Mac wakes and a scheduled sync starts automatically — opening the app while a --silent run was already going could terminate that run outright, with no error, no log entry, and no saved progress. Command-line syncs no longer share anything with the app that this could happen through.
  • Fixed saving new Jamf credentials silently starting a background sync. Changing the Jamf URL or client ID in Setup used to immediately queue a sync with no explicit action from you — indistinguishable from an unrelated automatic trigger. It still correctly marks the cached device mapping as needing revalidation; it just no longer starts that sync on its own. The next Run Sync (or scheduled/command-line run) does it, same as it always would have anyway.

Upgrade Notes

No action required. Existing credentials, cache, and preferences carry over unchanged. Command-line mode and the update checker are both new — neither changes anything about how the app already worked for you.


v2.5

September 2026

What's New

New AxM Device Data

  • Wi-Fi, Bluetooth, and Ethernet MAC addresses, IMEI, MEID, and EID are now structured, queryable fields — previously visible only in the device detail sheet's raw JSON. Available as CSV export columns (off by default; enable them under Export → Columns)
  • Apple's MDM migration fields — capability, status, and deadline — are now fully wired through and power the new dashboard cards below

Apple (AxM) Dashboard

  • New MDM Migration Status card — Not Requested / Requested / In Progress / Success / Failed, each its own stat tile rather than a donut slice, so a real-but-small count (e.g. 4 of 1,325 devices) never renders as an invisible sliver of the chart
  • A Deadline Approaching row (Next 30 / 31–60 / 61–90 Days) appears once any device has an in-progress migration with a live deadline
  • MDM Migration Capability now sits alongside MDM Assignment in the same row
  • Coverage Distribution's legend rows are tappable now (they drill into the Devices tab, same as every other card) and show a percentage next to each count
  • Last-sync status moved to the bottom of the dashboard, below Coverage Distribution

Jamf Pro Dashboard

  • New MDM Cert Expiring card (Next 30 / 31–60 / 61–90 Days) — the MDM enrollment certificate expiration date was already being fetched but had no dashboard presence until now
  • New Hardware card — Apple Silicon vs. Intel breakdown, plus a RAM (GB) breakdown
  • macOS and iOS/iPadOS version cards now show currency at a glance as Current (N) / N-1 / N-2, computed from whichever version is actually newest in your fleet — never a hardcoded target, so it can't go stale as Apple ships new versions
  • Layout reorganized for better grouping: Device Type + Check-in Freshness share a row, FileVault Encryption + MDM Cert Expiring share a row, Hardware sits below Device Type; last-sync status moved to the bottom

Default Dashboard

  • Coverage Distribution's legend rows are tappable now and show a percentage next to each count

Diagnostics

  • Help → Export Diagnostics… now masks every device serial number in the bundled log files, replacing each with a consistent <device N> placeholder — the same serial reads as the same placeholder everywhere in the bundle, so a diagnostics zip can be shared for troubleshooting without exposing your org's device inventory

Reliability

  • Fixed a Core Data migration bug ("Persistent store migration failed, missing mapping model") that could prevent the app from opening its device database on launch after certain updates. Your data was never at risk — the app safely refuses to open an incompatible store rather than touching it — but this is now fixed at the root: the Core Data model is properly versioned, so every future schema change carries a valid migration path regardless of which exact schema your environment's store is currently on.

Upgrade Notes

No action required. Existing credentials, cache, and preferences carry over unchanged; the Core Data schema updates transparently on first launch.


v2.4

September 2026

What's New

Dashboard Focus Modes

  • The Dashboard is now three views instead of one, chosen from a menu next to Run Sync:
    • Default — today's mixed ABM/ASM + Jamf reconciliation view, unchanged in substance
    • Apple — every card scoped to ABM/ASM-sourced fields only (status, product family, purchase source, MDM assignment, added-to-org history)
    • Jamf Pro — every card scoped to Jamf-sourced fields only (managed status, device type, macOS/mobile OS version, FileVault, check-in freshness)
  • Each focus mode has its own facet filter bar — filtering the Dashboard is a separate lens from the Devices tab's own filters and never touches them
  • Every number on every card drills into the Devices tab pre-filtered to exactly the population it counted, with any active Dashboard facet carried into the drill-down alongside the tapped dimension
  • New chart types built on Swift Charts: donut charts (product family, device type mix, FileVault encryption), horizontal bar charts (purchase source, macOS/mobile OS version — version-aware sorting so "26" doesn't sort before "9"), and a year-over-year bar chart (devices added to org)

Setup Tab

  • Credentials now save to Keychain automatically as you type (debounced ~0.6s) or the moment Test Auth succeeds — the Save to Keychain checkbox is gone
  • A status line under each credential panel shows Saved to Keychain · Verified <relative time>, or Not verified, or Not saved yet
  • The private key status pill now shows a masked Key ID (e.g. AUTHKEY_X…7L2K) next to "Loaded from Keychain"/"Loaded from file", so it's clear which key is active
  • Jamf Page Size is a segmented control (500 / 1000 / 1500 / 2000) instead of a slider

Sync Tab

  • The Last Run Summary tiles are now Apple Devices · Jamf Devices · Coverage Checked · Jamf Updated · Jamf Failed · Duration, each with a Mac/Mobile split shown as a subtitle where relevant — replaces the old tile set, one of which silently displayed whichever of three unrelated counters happened to be non-zero
  • The overall-run ETA ("~2h 15m total") is now actually shown, bottom-right of the progress bar
  • The summary and log panes sit in a resizable split view — drag the log pane taller during a long run
  • The log only auto-scrolls to new lines while you're already at the bottom; scroll up to read something and a Jump to Latest pill appears instead of yanking you back down
  • A Clear button on the log toolbar resets what's displayed (the on-disk log file is untouched)
  • The level filter gained a Warn+ option (warnings and errors together) alongside All / Info / Error
  • The Sync tab icon shows a small red dot when the last run didn't end in success and you haven't looked at it yet — clears the moment you open the tab
  • A failed-run notification is no longer marked "critical" (which bounces the Dock icon until you focus the app) — a sync failure never risks existing data, so this was overstating the urgency

Devices Tab

  • Search now also matches: username, Jamf ID, AppleCare agreement number, MDM server name, order number, and model identifier — not just serial/name/model
  • The device list supports multi-select (⌘-click, ⇧-click, or drag): selecting several devices shows a summary panel with Copy Serial Numbers and Export Selection…
  • Every device — via right-click on its row, or a button row in the detail panel — offers Copy Serial, Copy Jamf ID, and Open in Jamf Pro (deep-links straight to that device's Jamf inventory record)
  • MDM server assignment moved from a row badge into a subtitle line under the model name; row badges are now just Coverage + Source (+ a "WB Failed" badge when relevant)

Export Tab

  • Four new presets: Expiring in 30 Days, Expiring in 31–60 Days, Expiring in 61–90 Days, and Write-back Failed
  • Columns can be dragged to reorder, and both the column order and enabled/disabled state now actually persist across app restarts (previously this silently didn't save at all, regardless of version)
  • A Show in Finder button appears after a successful export
  • Exported filenames now include the environment name: AxM-Jamf-Sync_{environment}_{preset}_{date}.csv

Environments Sidebar

  • Environment rows are now a native, keyboard-navigable list (arrow keys, VoiceOver)
  • Each row's second line shows sync recency ("Synced 2h ago") instead of repeating the ABM/ASM scope label; a scope tag only appears at all when your environments actually mix ABM and ASM
  • Rename is inline now — double-click a name, or select a row and press Return; Esc cancels. The delete (trash) icon only appears on hover, no longer permanently visible next to the active environment

Diagnostics

  • New Help → Export Diagnostics… — builds a zip with app/environment metadata, a per-environment settings summary, and every live and archived log file, for attaching to a bug report. Never includes credentials, API keys, or your Jamf/Apple server hostnames.

Security & Data Integrity

These landed incrementally before this release but are documented here together for the first time:

  • Token identity scoping — every cached ABM/ASM and Jamf access token is now bound to a SHA-256 identity (origin + client ID). One environment can no longer load a token cached by another, and a token can't outlive a host or client-ID change within the same environment.
  • Jamf write-back mapping revalidation — if you change an environment's Jamf URL or client ID, every cached serial→Jamf-device mapping is held from write-back until re-confirmed against the new host on the next sync. Previously, a changed Jamf connection could patch warranty data onto the wrong physical machine using a mapping built against the old host.
  • Four-state sync outcomes — a run now reports Success, Partial, Failed, or Cancelled, instead of always presenting as success even when part of the run actually failed.
  • Safer environment deletion — deleting an environment now stops any in-flight sync and cleanly detaches its Core Data store and log file before removing anything from disk, closing a race that could corrupt a store mid-delete.
  • Crash-safe device fetch resume — each batch of Apple org devices is durably committed to the local database before the resume checkpoint advances, so an interrupted large fetch can't silently skip a page of devices when it resumes.
  • Safer v1→v2 migration — the one-time migration now verifies the copied credentials (byte-for-byte) and device count before deleting the v1 originals; a failed migration leaves the original data completely untouched and retries on next launch.

Bug Fixes

  • Fixed the "device database unavailable" alert re-appearing immediately after clicking "Continue Without Syncing"
  • Fixed the Devices search field matching a different, narrower set of model fields than the debounced background filter used for everything else
  • Fixed the scheduler polling every 30 seconds indefinitely regardless of how far off the next scheduled run actually was
  • Fixed the Sync tab's Last Run Summary occasionally showing a different environment's data (or zeros) immediately after switching environments or relaunching, in a multi-environment setup — it was reading an unnamespaced settings key while every write already used the correct per-environment one

Upgrade Notes

No migration required. Existing credentials, cache, and preferences all carry over unchanged. If you had the Setup tab's "Save to Keychain" checkbox unticked for any credential set, save it once after upgrading — it now saves automatically going forward.


v2.3

July 2026

What's New

Automatic Sync Scheduling

  • New Schedule tab in Settings (⌘,) — turn on Automatically Sync and the app runs syncs for you, unattended
  • A friendly schedule builder: Repeat Every Minute(s), Hour(s), Day(s), Week(s), or Month(s), each with plain controls — no cron knowledge required
  • Day(s) and Week(s) support multiple times a day (e.g. 8:00 AM, 2:00 PM, 8:00 PM) by selecting several hours that share one minute
  • An Advanced (Raw Cron Expression) field for anyone who wants to write a standard 5-field cron expression directly — the friendly controls and the raw field always stay in sync with each other
  • A live, green-highlighted summary line always shows the active schedule in plain English (e.g. "Mon, Wed, Fri at 9:00 AM")

Always-Visible Schedule Status

  • A Next Sync badge now sits in the main window's header bar — green with a live countdown when a schedule is active, a neutral gray "Schedule" pill when it isn't. Click it anytime to jump straight to Settings
  • The menu bar icon now shows AxM Jamf Sync's own icon rather than a generic symbol, and the dropdown shows both Next Sync and Last Sync alongside Sync All Now, Settings…, and Quit

Launch at Login & Menu Bar–Only Mode

  • Turning on Automatically Sync now offers to enable Launch at Login, so scheduled runs keep happening even after you quit the app
  • A new Show in Dock toggle (Settings → General) lets AxM Jamf Sync run menu bar–only, with no Dock icon or Cmd-Tab entry, if you'd rather keep it out of the way
  • Quitting (Cmd-Q or the Quit menu item — not just closing the window) while a schedule is active now shows a confirmation dialog first, since quitting pauses scheduled syncs until the app reopens

Scheduling Notifications

  • A Scheduled Sync Starting notification fires when a scheduled run begins, listing the environments queued
  • A Scheduled Sync Complete summary notification fires once every environment in that run has finished, on top of the existing per-environment completion notifications

Improvements

  • Settings window is now resizable — previously fixed-size with only internal scrolling, which cramped the Schedule tab's controls

Upgrade Notes

No migration required. Scheduling defaults to off. If you had experimented with an earlier development build's Interval or Specific Times options, those have been replaced by the unified cron-based model above — reconfigure your schedule once in Settings → Schedule.


v2.2

May 2026

What's New

Multi-Environment Sync Queue

  • New Sync All button in the sidebar header — opens a checklist to select environments and add them to the sync queue
  • All syncs (single and multi-environment) now run through a single serial queue — no parallel Apple API calls, no race conditions
  • The queue advances automatically after each environment finishes, saving progress along the way
  • While the queue is running, a progress banner appears in the header showing which environment is syncing and how many remain

Queue-Aware Run Sync Button

  • The Run Sync button now enqueues rather than triggering immediately — clicking it while another environment is syncing adds it to the queue rather than blocking or starting a parallel sync
  • While an environment is waiting in the queue, the button shows In Queue in a muted style
  • The button correctly shows Stop Sync when that environment's sync is active, even after switching away and back

Stop & Save from the Banner

  • Stop & Save in the queue progress banner stops the currently-running sync, saves all progress, and advances the queue to the next environment
  • Cancel All stops the current sync and clears the entire queue — both actions show a confirmation dialog

Bug Fixes

  • Fixed environment switching being blocked while a sync was running — you can now browse Dashboard, Devices, and Export freely on any environment while another is syncing
  • Fixed Run Sync button reverting to its idle state when switching away from an environment mid-sync and returning
  • Fixed Stop & Save in the banner having no effect when the user had switched to a different environment
  • Fixed sync log showing empty when switching away from an environment mid-sync and returning

Upgrade Notes

No migration required. The sync queue is in-memory and resets on app restart.


v2.1

April 2026

What's New

MDM Server Visibility

  • Device list now shows the assigned MDM server name as a badge on each device row
  • Devices registered in AxM but not enrolled in any MDM server are marked Unassigned
  • New MDM Server filter in the Devices tab — filter by server name or by Unassigned
  • Device detail panel includes a new MDM Assignment section with server name, type, and ID
  • Three new CSV export columns: MDM Assignment, MDM Server, MDM Server Type
  • Dashboard includes a new MDM Assignment card showing assigned/unassigned counts and a per-server device breakdown
  • Sync log and Sync tab summary card now include MDM server counts and assigned device totals after each run
  • MDM data only refreshes when v1/orgDevices runs a live fetch — respects Device Cache (days) and Force Refresh Devices

AppleCare Coverage Date Format

  • Start Date and Expired On in the coverage detail now respect System Settings → General → Language & Region date format

Bug Fixes

  • Force Refresh Coverage ignored Sync Device Types — selecting Mobile Only or Mac Only and enabling Force Refresh Coverage still fetched coverage for all devices. Fixed: Force Refresh Coverage now applies the same device type scope filter as a normal coverage run
  • Environment scope mismatch — fixed a bug where an environment created as ABM could store and display ASM credentials (or vice versa). v2.1 auto-corrects on launch using the Keychain scope key, clientId prefix, or cached sync scope as fallbacks — survives Keychain deletion
  • Scope-agnostic Keychain keys — ABM and ASM credentials within the same environment no longer share the same Keychain key, preventing one from overwriting the other
  • Scope change not persisted — tapping ABM/ASM in Setup now correctly updates the environment record so the change survives app restart
  • Credential data in error logs — Apple's token endpoint error responses could echo back the client_assertion JWT containing the API clientId. Response bodies are no longer logged on auth errors — status code only
  • ProgressView Auto Layout warnings — eliminated NSProgressIndicator constraint warnings in the console

Improvements

  • Account Type picker removed from the New Environment sheet — scope is set automatically from credentials
  • macOS HIG compliance pass: semantic colours, native toolbar materials, SF Symbol hierarchical rendering, compact header bar

Upgrade Notes

No manual migration required. Existing environments with a scope mismatch are corrected automatically on first launch.


v2.0

March 2026

What's New

  • Multi-Environment support — manage multiple ABM/ASM + Jamf Pro configurations from a single app, each fully isolated (credentials, device cache, logs)
  • Sidebar navigation — switch between environments instantly
  • Automatic v1 migration — existing data carries over on first launch, no re-sync needed
  • More Jamf fields — PO Number, PO Date, and Vendor (with Purchase Source ID) now written to Jamf purchasing records
  • External change detection — if someone edits warranty data in Jamf, the next sync detects and restores it automatically
  • Sync Device Types — choose Mac only, Mobile only, or both per environment

Still free, open source, signed & notarised for macOS 14+. Built for Mac admins. Runs entirely on your Mac — no cloud relay, no third-party servers.


v1.2

What's New

  • Sync Device Types — choose Mac + Mobile, Mac Only, or Mobile Only in Setup. Controls which devices are included in AppleCare coverage fetch and Jamf write-back. Apple org devices always fetched in full
  • More fields synced to Jamf — PO Number, PO Date, and Vendor ("purchaseSourceType (purchaseSourceId)") from ABM/ASM are written to Jamf purchasing fields
  • Re-sync on external changes — if warranty date, vendor, PO number or PO date are edited in Jamf after a successful sync, the app detects and re-queues those devices automatically

Bug Fixes

  • Fixed HTTP 401 mid-sync on Jamf servers with short token TTLs — token now refreshes per page and per write-back chunk
  • Fixed app launching as ABM despite ASM credentials being saved in Keychain
  • Account type selector now locked when credentials or cache exist — requires both to be cleared to switch
  • Write-back log now shows device type: Jamf Update Mac [659/840] SERIALNO: OK
  • External purchasing changes now logged as a single count rather than one line per device

CoreData schema migrates automatically — no cache wipe required.


v1.1

What's New

Large Organisation Support (20k+ devices) Fixes app freezing mid-fetch due to API connection limits. Progress is now saved every 10,000 devices and automatically resumes on next sync if interrupted. AppleCare coverage is skipped until all device pages are fetched.

Reliability

  • Fixed failed Jamf write-back devices being permanently stuck — now retried every sync
  • Fixed -999 connection errors on Jamf PATCH requests
  • Fixed Force Refresh Devices resetting already-synced devices
  • Fixed Force Coverage skipping already-fetched devices

Performance

  • AppleCare coverage fetch restored to v1.0 speed (~8 mins per 1,000 devices)

Security

  • Credentials migrated to macOS Data Protection Keychain automatically on first launch
  • Credential values no longer appear in debug logs

Other

  • Mac/mobile breakdown added to write-back summary
  • Detailed run summary added to log (start time, end time, total duration, counts)

Existing credentials migrate automatically — no re-entry required.


v1.0

First Public Release

AxM Jamf Sync is a macOS utility that syncs AppleCare warranty coverage from Apple Business Manager / Apple School Manager into Jamf Pro.

Highlights

  • Fetch devices from ABM / ASM
  • Pull device inventory from Jamf Pro
  • Match devices by serial number
  • Retrieve AppleCare coverage
  • Update warranty data back into Jamf Pro
  • Native SwiftUI macOS app
  • Secure credentials stored in macOS Keychain

⚠️ Please test carefully before using in production environments.

Thanks to the MacAdmins community for the inspiration and feedback.


Requirements: macOS 14.0 · Apple Business Manager or Apple School Manager API credentials · Jamf Pro OAuth2

Clone this wiki locally