Preparing Devices Using Apple Configurator for Mac

Jamf Now Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Requirements
  • Ensure that you are registered in Apple Business or Apple School Manager, and that this account is linked with Jamf Now. For more information, see Setting Up Automated Device Enrollment with Apple Business.
  • Back up the device with iCloud, and then wipe the device to restore it to factory defaults. You can restore the device using Apple Configurator.
  • Turn off Find My from the Settings app to disable Activation Lock.
  • Confirm that the device to be enrolled has a valid network connection.
  • Ensure you have the latest version of Apple Configurator.

  • Ensure you are not signed in to Apple Configurator's Accounts menu with your Apple Business or Apple School Manager account credentials. If you are signed in to those accounts, Jamf Now's ability to enroll new devices and install managed apps will be disrupted.

  • If enrolling an iPad or iPhone, the device must have iOS 11 or later.

  1. Connect your device to a computer with a Lightning-to-USB cable for iPad or iPhone.
  2. If the Trust This Computer? pop-up window occurs, tap Trust.
  3. Open Apple Configurator and do the following:
    • Verify that the device is displayed and that it is not currently supervised.

    • Note the device's serial number (available from the Info view in Apple Configurator). You will need it later to assign the device to the MDM server synced with Jamf Now.

  4. Select the device and click Prepare.
  5. In the Prepare Devices dialog box:
    1. Select the Prepare with Manual Configuration and Add to Apple School Manager or Apple Business checkboxes.
    2. Do not select the Activate and Complete Enrollment or Enable Shared iPad checkboxes.
    3. Supervise Device will automatically be selected. Leave it selected.
    4. (Optional) Jamf recommends you also select Allow devices to pair with other computers.
    5. Click Next.
  6. In the Enroll in MDM Server dialog box:
    • If this is your first time using Apple Configurator, select New Server.

    • If you have previously used Apple Configurator, select your MDM server from the list.

  7. Click Next.
  8. In the "Define an MDM Server" dialog box:
    1. Enter a display name for your server (for example, "Acme MDM").
    2. Log in to Jamf Now, and click Auto-Enrollment.
    3. Copy the URL in the Enrollment URL field in Jamf Now.
    4. In Apple Configurator, paste the URL in the Host name or URL field.
    5. Click Next.
      Note:

      An error message may appear stating that the URL could not be verified. Click Next.

  9. You will be prompted to add trust anchor certificates for the MDM server. To do so, follow these steps:
    1. Confirm that you see the following: *.jamfcloud.com.
    2. Select it, and then click Next.
    3. Sign in to your Apple deployment account. Be sure to use the same Apple Account that you used to enroll in Apple Business or Apple School Manager. You may be prompted to verify your identity with two-factor authentication.
  10. Generate or choose a supervision identity. If this is your first time using Apple Configurator, select Generate a new supervision identity.
  11. Select which setup steps you want to show on the device. Jamf recommends testing this workflow with a few users to ensure your current configuration is correct.
  12. Connect the device to a non-restricted network in one of the following ways:
    • Use cellular connectivity.

      Devices with a valid cellular connection should not need to connect to Wi-Fi.

    • Create and upload a Wi-Fi profile in the "Choose Network Profile" step. Use Apple Configurator to create this profile by navigating to File > New Profile.

      This is the recommended option when preparing multiple devices because it bypasses the need to manually enter the Wi-Fi password for each individual device.

    • Manually connect the device to Wi-Fi during the initial Setup Assistant.

    Important:

    The device must have a valid network connection before completing step 14, or enrollment in to Apple Business or Apple School Manager will fail, and you will need to redo the following process.

  13. Click Prepare.

    If your device is already set up, you will be prompted to erase the device. You may be prompted to enter your Apple Account password for the Apple deployment account. The device will reboot and be added to your account. This may take several minutes. Once the "Hello" screen is displayed, leave until step 17.

  14. Unplug the device from the computer after Apple Configurator has completed preparing the device.

    Do not finish setting up the device.

  15. Log in to Apple Business or Apple School Manager, and assign the device to the MDM server synced with Jamf Now by performing one of the following workflows:
    • In Apple Business, click Devices, click on the device you want to assign, click Assign Device Management, select your Jamf Now MDM server, and then click Save.

    • In Apple School Manager, click Devices, search for a device by serial number and click on the device, click on the Action pop-up menu (•••) and choose Assign Device Management, select your Jamf Now MDM server from the Assign Device Management pop-up menu, and click Continue.

  16. Confirm that the device appears under the Auto-Enrollment > Devices tab in Jamf Now. If the device does not appear under Auto-Enrollment immediately, click Sync Devices to sync with Apple Business or Apple School Manager.
  17. On the device, go through the setup steps. When you see Remote Management displayed, that means enrollment is working.

Your devices are now enrolled in Jamf Now as supervised devices enrolled with Automated Device Enrollment.

Note:

When you add a device using Apple Configurator, the device is provisionally managed. Provisional management means that the device will give the user the ability to leave remote management for the first 30 days of management. During that period, a user will see a banner notifying them of the updated management state and will be able to remove MDM management in the Settings menu. After 30 days, the banner will disappear, and the user will no longer be able to opt out of MDM management.