Update the macOS Forwarder

Push the update from the console, or deploy it out of band through JAMF, Kandji, or by hand. All three routes need a maintenance token except the first.

Four routes, and the first one is the right answer unless something prevents it.

Push it from the console. No token, no uninstall, no reboot. Stairwell tells the forwarder to update itself.

The other three exist for machines the console cannot reach or fleets managed entirely through an MDM, and they share a shape: put the forwarder into maintenance mode with a token, remove the old version, install the new one. That extra work is all because the forwarder is anti-tamper protected and will otherwise resist being replaced.

Push the update from the console

  1. Sign in to app.stairwell.com/assets.
  2. Select your environment from the dropdown at the top right.
  3. Select the assets to update.
  4. Right-click, or use the ... menu at the top right.
  5. Choose Update.
  6. Pick the forwarder version.
  7. Select Next, then Update.

The forwarder downloads and applies the update itself. Confirm the new version appears in the asset list afterwards; that is the only confirmation that matters, since a machine that was offline at the time simply will not have moved.

For a whole group rather than a selection, see Update the Forwarders in a Group.

Update by hand

For machines without console access, or air-gapped environments.

  1. Download the latest macOS package. See Forwarder Downloads.
  2. Generate a Forwarder Maintenance Token. See Asset Identifiers.
  3. Put the forwarder into maintenance mode using the token.
  4. Uninstall the current version. See Uninstall the macOS Forwarder.
  5. Reboot.
  6. Install the new version.
  7. Confirm the machine is reporting and the version is correct in Stairwell.

Maintenance mode has to come before the uninstall. It is what disables anti-tamper protection so the forwarder can be removed cleanly. Skipping it is how a machine ends up with a half-removed forwarder that neither reports nor uninstalls.

Update through JAMF

  1. Download the latest macOS package.
  2. Upload it to JAMF Pro as a new package.
  3. Generate a maintenance token in Stairwell.
  4. Create a policy that puts the forwarder into maintenance mode with the token, uninstalls the current version, then installs the new package.
  5. Scope the policy to the target machines and deploy it.
  6. Confirm the new version in Stairwell afterwards.

Update through Kandji

  1. Download the latest macOS package.
  2. Upload it to Kandji as a custom app.
  3. Generate a maintenance token in Stairwell.
  4. Configure the custom app to enter maintenance mode with the token, remove the current forwarder, then install the new package.
  5. Assign it to the right device blueprint and deploy.
  6. Confirm the new version in Stairwell afterwards.

Plan around the token's 14 day life on both MDM routes. A policy carrying an expired token fails on every machine it reaches, and the failure looks like a packaging problem rather than an expiry. If a staged rollout runs longer than two weeks, expect to regenerate and update the policy partway through.

What should I read next?


Did this page help you?