When creating and distributing mobile device configuration profiles directly in Jamf Pro, keep the following in mind:
In the summary view, only the included or configured settings are displayed in the Jamf Pro interface.
Some enforced settings that do not change default values will not be visible on the device. For more information on the default settings, see Profile-Specific Payload Keys from the Apple Developer website.
You cannot apply profiles that require supervision to devices enrolled using User Enrollment. For more information on the payloads that can be configured for devices enrolled using User Enrollment, see User Enrollment MDM information in Apple Platform Deployment.
Requirements
Before creating a configuration profile, you should have basic knowledge of configuration profile payloads and settings. For more information, see Plan your configuration profiles for Apple devices in Apple Platform Deployment.
Note:
Some configuration profile payloads and settings available in Jamf Pro may differ from their implementation in Apple's tools.
In Jamf Pro, click Devices in the sidebar.
Click Configuration Profiles in the sidebar.
Click New.
Use the General payload to configure basic settings for the profile, including the level at which to apply the profile and the distribution method. If you chose to make the profile available in Jamf Self Service, choose a Security setting.
Only payloads and settings that apply to the selected level are displayed for the profile.
Use the rest of the payloads to configure the settings.
Note:
Some payloads and restrictions are only configurable for supervised devices. For more information, see the MDM restrictions for supervised Apple devices in Apple Platform Deployment.
Click the Scope tab and specify the devices and users to which the profile should be applied.
To distribute user-level profiles, ensure you add iPads to the scope that have Shared iPad enabled. This allows the profile to be installed on the device for each potential user of that device. When each user logs in, the profile is then installed on the device.
Note:
If a user is logged in to an iPad prior to a profile being saved in Jamf Pro, the user must log out and log back in to the iPad for the profile to be installed on the device.
For limitations or exclusions to be based on LDAP users or LDAP user groups, the Username field must be populated in the mobile device's inventory.
(Optional) If you chose to make the profile available in Self Service, click the Self Service tab to configure Self Service settings for the profile.
Click Save .
The profile is distributed to deployment targets in the scope the next time they contact Jamf Pro.