Lesson 12: Automated Device Enrollment

Jamf 100 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Integrate Automated Device Enrollment with Jamf Pro. Create a PreStage enrollment to automatically enroll devices.

Video

Important:

Apple Business Manager is now Apple Business. Part of this video contains instructions for navigating Apple Business that are no longer accurate. While we work on updating our content to correct these changes, check out these resources from Apple:

Apple Business User Guide

Key points

  • Automated Device Enrollment allows for quick and easy setup of new and newly wiped devices.

    • Automated Device Enrollment integrates Apple Business or Apple School Manager and Jamf Pro.

    • Once integrated, device information is synced from Apple School Manager or Apple Business to Jamf Pro.

  • A PreStage enrollment can be configured to prompt users, enforce settings, and customize Setup Assistant.

  • New or restored devices will automatically enroll during Setup Assistant.

  • To integrate Apple Business or Apple School Manager:

    1. Download the Public Key from Jamf Pro > Settings > Global > Automated Device Enrollment.

    2. To download the service token from Apple Business, follow the steps in the Apple documentation Link to an external device management service in Apple Business, and then proceed to step 4.

    3. To download the MDM server token from Apple School Manager:

      1. Sign up for an account at https://school.apple.com.

      2. From the Apple School Manager portal, navigate to your name on the bottom left, and then select Preferences > Your MDM Servers > Add.

      3. Name the new MDM server.

      4. Leaving Allow this MDM server to release devices selected will make it possible to "release" or completely remove a device from Apple School Manager.

      5. Upload the Public Key file.

      6. Save the MDM server.

      7. Download the MDM server token.

    4. Back in Jamf Pro > Settings > Global > Automated Device Enrollment, click New.

    5. Name the new connection.

    6. Upload the MDM server token file.

    7. Save the connection.

    8. For a zero-touch workflow, set the MDM server as the default assignment for new devices. New devices will automatically populate in the server and won't need to be manually assigned.

      1. Note: Devices must be purchased through a business or education channel. Devices purchased at an Apple Store with a credit card will not be automatically added to your deployment program.

  • The process for creating PreStage enrollments for computers and mobile devices is similar. To create a PreStage enrollment for a computer, click Computers. For mobile devices, click Devices.

    1. Navigate to PreStage Enrollments > New.

    2. Name the PreStage enrollment.

    3. Select an MDM server to connect to.

    4. For a zero-touch workflow, select Automatically assign new devices.

    5. Enter support information to let users know who is remotely managing the device.

    6. Configure remaining settings to your needs.

    7. Choose which, if any, Setup Assistant screens should be skipped.

      • Remember: a selected checkbox means the screen will be skipped.

    8. Configure any additional payloads for the PreStage enrollment.

    9. Add devices to scope.

      • If devices aren't appearing on the Scope page, they either aren't populated in your MDM server in Apple Business or Apple School Manager, or device sync may still be in progress.

    10. Save the PreStage enrollment.

    11. Wait 15 minutes or so for the PreStage settings to sync back to Apple's servers.

    12. Devices in scope will enroll when they go through Setup Assistant.

Review

To view answers, click arrow next to each question.

  1. Yes. Devices need to be populated in Apple Business or Apple School Manager and synced to Jamf Pro via an MDM server.
  2. On the General payload of the PreStage enrollment, select the checkbox for any Setup Assistant screen item you want to skip.
    1. In Apple Business or Apple School Manager, configure your MDM server to be the default for the types of devices your organization will be using.

    2. In the associated PreStage enrollment in Jamf Pro, select the checkbox to Automatically assign new devices.

Practice

  1. Configure a device PreStage enrollment with the following settings:

    1. Select your configured Automated Device Enrollment instance.

    2. Supervise Devices with iOS 12.x or earlier: Selected

    3. Make MDM Profile Mandatory for devices with iOS 12.x or earlier: Selected

    4. Prevent Unenrollment: Selected

    5. Apple ID and iCloud: Selected (Prevents displaying item in Setup Assistant)

    6. Touch ID / Face ID: Selected (Prevents displaying item in Setup Assistant)

    7. Screen Time: Selected (Prevents displaying item in Setup Assistant)

  2. Assign a test device to the scope of this PreStage enrollment, save, then enroll the test device.

  3. Configure a computer PreStage enrollment with the following settings:

    1. Select your configured Automated Device Enrollment instance.

    2. Make MDM Profile Mandatory: Selected

    3. Allow MDM Profile Removal: Deselected

    4. Apple ID: Selected (Prevents displaying item in Setup Assistant)

    5. Touch ID / Face ID: Selected (Prevents displaying item in Setup Assistant)

    6. Apple Pay: Selected (Prevents displaying item in Setup Assistant)

  4. Assign a test computer to the scope of this PreStage enrollment, save, then enroll the test computer.

Resources

Jamf Pro Documentation

Apple Configurator 2 User Guide

Apple Business User Guide

Apple School Manager User Guide

Apple Platform Deployment

Apple