Goal
Integrate Automated Device Enrollment with Jamf Pro. Create a PreStage enrollment to automatically enroll devices.
Video
Apple Business Manager is now Apple Business. Part of this video contains instructions for navigating Apple Business that are no longer accurate. While we work on updating our content to correct these changes, check out these resources from Apple:
Apple Business User Guide
Key points
-
Automated Device Enrollment allows for quick and easy setup of new and newly wiped devices.
-
Automated Device Enrollment integrates Apple Business or Apple School Manager and Jamf Pro.
-
Once integrated, device information is synced from Apple School Manager or Apple Business to Jamf Pro.
-
-
A PreStage enrollment can be configured to prompt users, enforce settings, and customize Setup Assistant.
-
New or restored devices will automatically enroll during Setup Assistant.
-
To integrate Apple Business or Apple School Manager:
-
Download the Public Key from .
-
To download the service token from Apple Business, follow the steps in the Apple documentation Link to an external device management service in Apple Business, and then proceed to step 4.
-
To download the MDM server token from Apple School Manager:
-
Sign up for an account at https://school.apple.com.
-
From the Apple School Manager portal, navigate to your name on the bottom left, and then select .
-
Name the new MDM server.
-
Leaving Allow this MDM server to release devices selected will make it possible to "release" or completely remove a device from Apple School Manager.
-
Upload the Public Key file.
-
Save the MDM server.
-
Download the MDM server token.
-
-
Back in , click New.
-
Name the new connection.
-
Upload the MDM server token file.
-
Save the connection.
-
For a zero-touch workflow, set the MDM server as the default assignment for new devices. New devices will automatically populate in the server and won't need to be manually assigned.
-
Note: Devices must be purchased through a business or education channel. Devices purchased at an Apple Store with a credit card will not be automatically added to your deployment program.
-
-
-
The process for creating PreStage enrollments for computers and mobile devices is similar. To create a PreStage enrollment for a computer, click Computers. For mobile devices, click Devices.
-
Navigate to .
-
Name the PreStage enrollment.
-
Select an MDM server to connect to.
-
For a zero-touch workflow, select Automatically assign new devices.
-
Enter support information to let users know who is remotely managing the device.
-
Configure remaining settings to your needs.
-
Choose which, if any, Setup Assistant screens should be skipped.
-
Remember: a selected checkbox means the screen will be skipped.
-
-
Configure any additional payloads for the PreStage enrollment.
-
Add devices to scope.
-
If devices aren't appearing on the Scope page, they either aren't populated in your MDM server in Apple Business or Apple School Manager, or device sync may still be in progress.
-
-
Save the PreStage enrollment.
-
Wait 15 minutes or so for the PreStage settings to sync back to Apple's servers.
-
Devices in scope will enroll when they go through Setup Assistant.
-
Review
To view answers, click arrow next to each question.
Practice
-
Configure a device PreStage enrollment with the following settings:
-
Select your configured Automated Device Enrollment instance.
-
Supervise Devices with iOS 12.x or earlier: Selected
-
Make MDM Profile Mandatory for devices with iOS 12.x or earlier: Selected
-
Prevent Unenrollment: Selected
-
Apple ID and iCloud: Selected (Prevents displaying item in Setup Assistant)
-
Touch ID / Face ID: Selected (Prevents displaying item in Setup Assistant)
-
Screen Time: Selected (Prevents displaying item in Setup Assistant)
-
-
Assign a test device to the scope of this PreStage enrollment, save, then enroll the test device.
-
Configure a computer PreStage enrollment with the following settings:
-
Select your configured Automated Device Enrollment instance.
-
Make MDM Profile Mandatory: Selected
-
Allow MDM Profile Removal: Deselected
-
Apple ID: Selected (Prevents displaying item in Setup Assistant)
-
Touch ID / Face ID: Selected (Prevents displaying item in Setup Assistant)
-
Apple Pay: Selected (Prevents displaying item in Setup Assistant)
-
-
Assign a test computer to the scope of this PreStage enrollment, save, then enroll the test computer.
Resources
Jamf Pro Documentation
Apple Configurator 2 User Guide
Apple Business User Guide
Apple School Manager User Guide
-
Assign, reassign, or unassign devices in Apple School Manager
-
Link to an external device management service in Apple School Manager
Apple Platform Deployment
Apple