UPDATE: JC agent (version 2.153.5) has been released:
- macOS 26.6 (and later): The JumpCloud agent fixes the keychain issue when changing the password on-device (both from Login Window and Tray App)
- macOS versions prior to 26.6: Will continue to use the same behavior and work as expected
JumpCloud has identified an issue affecting devices running macOS Tahoe 26.6. The issue impacts JumpCloud’s ability to sync the user’s Keychain with their previous and new password following off-device (User Portal changes, Admin Portal resets, etc.) password changes.
Observed Behaviors
- Unchanged Passwords: Users may be prompted to enter their previous password during login. Direct users to leave the Previous Password field blank. Their password and Keychain will remain intact and will continue to be accessible.
- Recently Changed/Reset Passwords: Password synchronizations on the device may fail even with the correct previous password. This results in loss of Keychain access.
- Expired Passwords at Login: Users attempting to change an expired password directly from the macOS login window will be blocked from setting a new password. Login access will remain blocked until an administrator resets the password.
Recommendations
- Defer Upgrades: Defer updating to macOS 26.6 until JumpCloud has released an Agent update with a fix.
- Advise Users to Hold Password Changes: Instruct users on macOS 26.6 to avoid changing passwords unless strictly necessary.
- Workaround for Necessary Password Changes: Instruct users to perform password updates only via the JumpCloud App in the macOS menu bar. After changing the password, have the user run the following command in Terminal to manually align the Keychain with their new credentials:
security set-keychain-password ~/Library/Keychains/login.keychain-db
If you encounter any issues, please contact your IT support team for assistance. We are working with Apple to resolve this issue and will provide an update as soon as a fix is available.
FAQs
What is the root cause of this issue?
This is actively under investigation. The issue is isolated to macOS Tahoe 26.6.
If a user did not change their password, but they see a password sync prompt (to enter their old password), what should they do?
If the password was not changed, they can safely leave the Previous Password field blank. Their Keychain will not be impacted.
If a user changes or resets their password, is there a way to recover the previous Keychain?
In some cases, yes. If the password change occurred through the tray application or while the user was logged in, they can run the following command to manually recover and sync their Keychain:
security set-keychain-password ~/Library/Keychains/login.keychain-db
If a user forgets their previous password, can they recover their Keychain?
No, the issue in macOS 26.6 prevents JumpCloud from automatically recovering the user's Keychain.
How will I know when this is resolved?
Check this article for updates.