Goal
Configure user-initiated enrollment for computers and devices. Enroll a computer and device with user-initiated enrollment.
Video
As of macOS 11, all enrolled computers are considered supervised, regardless of their enrollment method. Management may still be removed from computers if they are enrolled with user-initiated enrollment.
Key points
-
User-initiated enrollment allows users to enroll institutionally owned and personally owned devices themselves.
-
User-initiated enrollment takes place after Setup Assistant.
-
Supervision is not enabled during user-initiated enrollment on iOS and iPadOS.
-
Supervision is enabled during user-initiated enrollment on macOS 11 and later.
-
Users may remove management from devices enrolled with user-initiated enrollment at any time.
-
There are several methods for user-initiated enrollment.
-
For institutionally owned computers:
-
Profile-driven Device Enrollment can be triggered by navigating to the enrollment URL.
-
Account-driven Device Enrollment can be triggered by navigating to and signing in with a Managed Apple ID.
-
-
For institutionally owned mobile devices:
-
Profile-driven Device Enrollment and profile-driven User Enrollment can both be triggered by navigating to the enrollment URL.
-
Account-driven Device Enrollment can be triggered by navigating to and signing in with a Managed Apple ID.
-
-
For personally owned mobile devices:
-
Account-driven User Enrollment can be triggered by navigating to and signing in with a Managed Apple ID.
-
-
-
To set up user-initiated enrollment:
- In Jamf Pro, navigate to .
-
Configure the General tab.
-
These settings may be left to their defaults unless your organization has special circumstances.
-
-
Configure the Messaging tab.
-
All messaging for the English language is configured by default and may be edited to customize the user's enrollment experience.
-
Additional languages may be added.
-
-
Configure the macOS tab.
-
The Enable user-initiated enrollment for computers checkbox must be selected in order for a PreStage enrollment to be created for Automated Device Enrollment.
-
The managed local administrator account may be created to use for LAPS workflows.
-
A management account is not required for user-initiated enrollment.
-
-
Enable account-driven Device Enrollment for computers if the required JSON file is hosted on a web server. See resources for instructions.
-
-
Configure the iOS tab.
-
Select checkboxes to enable any of the four methods of user-initiated enrollment for iOS/iPadOS.
-
-
Configure the Access tab.
-
If LDAP, SSO, or a cloud directory are configured in Jamf Pro, specify any directory groups here that should have access to enroll devices.
-
Devices enrolled using directory accounts will be automatically assigned to the account used to enroll.
-
-
To test profile-driven enrollment, navigate to your organization's enrollment URL and follow the prompts to enroll.
- If Jamf Pro is hosted in Jamf Cloud, the enrollment URL is your Jamf Pro server URL followed by "/enroll".
-
If Jamf Pro is hosted on-premise, the enrollment URL is your Jamf Pro server URL followed by ":8443/enroll".
-
To test account-driven enrollment on a mobile device, navigate to and sign in with a Managed Apple ID from your organization's Apple Business Manager or Apple School Manager.
Review
To view answers, click arrow next to each question.
Practice
-
Configure user-initiated enrollment for macOS with the following options:
-
Enable user-initiated enrollment for computers: Selected
-
Management Account: IT_Manage
-
Create management account: Unselected
-
Allow SSH for management account access only: Unselected
-
Ensure SSH is enabled: Unselected
-
Launch Self Service when done: Selected
-
Sign QuickAdd Package: Unselected
-
-
Configure user-initiated enrollment for iOS.
-
Under Profile-Driven Enrollment via URL, select the Enable for institutionally owned devices and Enable for personally owned devices checkboxes.
-
-
Navigate to the enrollment URL on a test computer and complete enrollment.
-
Enroll a test mobile device.
Resources
Jamf Pro Documentation
Jamf Technical Articles
Apple Platform Deployment