Lesson 13: User-Initiated Enrollment

Jamf 100 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Configure user-initiated enrollment for computers and devices. Enroll a computer and device with user-initiated enrollment.

Video

Note:

As of macOS 11, all enrolled computers are considered supervised, regardless of their enrollment method. Management may still be removed from computers if they are enrolled with user-initiated enrollment.

Key points

  • User-initiated enrollment allows users to enroll institutionally owned and personally owned devices themselves.

  • User-initiated enrollment takes place after Setup Assistant.

  • Supervision is not enabled during user-initiated enrollment on iOS and iPadOS.

  • Supervision is enabled during user-initiated enrollment on macOS 11 and later.

  • Users may remove management from devices enrolled with user-initiated enrollment at any time.

  • There are several methods for user-initiated enrollment.

    • For institutionally owned computers:

      • Profile-driven Device Enrollment can be triggered by navigating to the enrollment URL.

      • Account-driven Device Enrollment can be triggered by navigating to System Settings > Privacy & Security > Profiles and signing in with a Managed Apple ID.

    • For institutionally owned mobile devices:

      • Profile-driven Device Enrollment and profile-driven User Enrollment can both be triggered by navigating to the enrollment URL.

      • Account-driven Device Enrollment can be triggered by navigating to Settings > General > VPN & Device Management and signing in with a Managed Apple ID.

    • For personally owned mobile devices:

      • Account-driven User Enrollment can be triggered by navigating to Settings > General > VPN & Device Management and signing in with a Managed Apple ID.

  • To set up user-initiated enrollment:

    1. In Jamf Pro, navigate to Settings > Global > User-initiated enrollment.
    2. Configure the General tab.

      • These settings may be left to their defaults unless your organization has special circumstances.

    3. Configure the Messaging tab.

      • All messaging for the English language is configured by default and may be edited to customize the user's enrollment experience.

      • Additional languages may be added.

    4. Configure the macOS tab.

      • The Enable user-initiated enrollment for computers checkbox must be selected in order for a PreStage enrollment to be created for Automated Device Enrollment.

      • The managed local administrator account may be created to use for LAPS workflows.

        • A management account is not required for user-initiated enrollment.

      • Enable account-driven Device Enrollment for computers if the required JSON file is hosted on a web server. See resources for instructions.

    5. Configure the iOS tab.

      • Select checkboxes to enable any of the four methods of user-initiated enrollment for iOS/iPadOS.

    6. Configure the Access tab.

      • If LDAP, SSO, or a cloud directory are configured in Jamf Pro, specify any directory groups here that should have access to enroll devices.

      • Devices enrolled using directory accounts will be automatically assigned to the account used to enroll.

  • To test profile-driven enrollment, navigate to your organization's enrollment URL and follow the prompts to enroll.

    • If Jamf Pro is hosted in Jamf Cloud, the enrollment URL is your Jamf Pro server URL followed by "/enroll".
    • If Jamf Pro is hosted on-premise, the enrollment URL is your Jamf Pro server URL followed by ":8443/enroll".

  • To test account-driven enrollment on a mobile device, navigate to Settings > General > VPN & Device Management and sign in with a Managed Apple ID from your organization's Apple Business Manager or Apple School Manager.

Review

To view answers, click arrow next to each question.

  1. User Enrollment refers to enrolling personal devices, whereas Device Enrollment refers to enrolling institutional devices.
  2. Profile-driven enrollment requires the user to navigate to an enrollment URL and then download and install the MDM profile onto their device. Account-driven enrollment allows a user to log in to VPN & Device Management on their device with a Managed Apple ID to initiate enrollment.
  3. A Managed Apple ID provided through your organization's Apple Business Manager or Apple School Manager is required for account-driven enrollment.

Practice

  1. Configure user-initiated enrollment for macOS with the following options:

    1. Enable user-initiated enrollment for computers: Selected

    2. Management Account: IT_Manage

    3. Create management account: Unselected

    4. Allow SSH for management account access only: Unselected

    5. Ensure SSH is enabled: Unselected

    6. Launch Self Service when done: Selected

    7. Sign QuickAdd Package: Unselected

  2. Configure user-initiated enrollment for iOS.

    1. Under Profile-Driven Enrollment via URL, select the Enable for institutionally owned devices and Enable for personally owned devices checkboxes.

  3. Navigate to the enrollment URL on a test computer and complete enrollment.

  4. Enroll a test mobile device.

Resources

Jamf Pro Documentation

Jamf Technical Articles

Apple Platform Deployment