Computer PreStage Enrollment Payload Reference

Jamf Pro Documentation 11.30.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.30.0
ft:locale
en-US
vrm_version
11.30.0

When you create a PreStage enrollment, you can use a payload-based interface to configure settings to apply to computers during enrollment. The following table provides descriptions of each payload and links to related content.

PayloadDescriptionNotesRelated Content
General

This required payload allows you to configure basic settings for the PreStage enrollment, specify authentication and management requirements, add an enrollment customization configuration, and customize the Setup Assistant experience.

The following General payload settings are commonly recommended, but may not apply in all environments:
  • Automatically assign new devices

  • Make MDM profile mandatory

  • Prevent users from removing MDM profile

  • Prevent users from enabling activation lock

Account Settings

You can use the Account Settings payload to create a managed local administrator account during Setup Assistant and define the account properties and privilege levels for users created during the setup process.

macOS requires the creation of a managed local administrator account when Setup Assistant is configured to skip user account creation or make the first account a standard user.
Configuration profiles

You can use the Configuration profiles payload to add essential configuration profiles to distribute to computers during enrollment. This allows profiles that affect user account creation, including those used with Jamf Connect or Platform SSO workflows, to be installed before Setup Assistant continues after enrollment.

  • You must create configuration profiles for enrollment prior to configuring a PreStage enrollment. The scope of the configuration profile must also include computers in the scope of the PreStage enrollment.

  • Add only configuration profiles that are essential to the enrollment experience to a PreStage enrollment. Installing too many configuration profiles early in the Setup Assistant process may cause unexpected enrollment issues.

  • Configuration profiles that contain payload variables are not replaced with their respective values when distributed via a PreStage enrollment. Distribute profiles with variables after the computer is enrolled with Jamf Pro.

Computer Configuration Profiles
User and Location

You can use the User and Location payload to specify user and location information to store in Jamf Pro for each computer enrolled using a PreStage enrollment. This is most useful when computers in scope of the PreStage are associated with a static, known location.

Using Inventory Preload or authentication during enrollment can automatically populate user and location information for computers.

Purchasing

You can use the Purchasing payload to specify purchasing information for computers.

This information is stored in Jamf Pro for each computer enrolled using a PreStage enrollment.

If a GSX connection is configured in Jamf, purchasing information can be looked up and populated automatically from Apple's Global Service Exchange, reducing the need to enter this manually.GSX Connection
Attachments

You can use the Attachments payload to upload attachments to store for computers.

This information is stored in Jamf Pro for each computer enrolled using a PreStage enrollment.

Certificates

You can use the Certificates payload to establish trust during enrollment if your Jamf Pro instance is hosted on-premise and uses an SSL certificate that is not natively trusted by Apple products. The computer attempts a secure connection with Jamf Pro using only this certificate to enroll.

If your Jamf Pro instance is a

Jamf Cloud-hosted instance, do not configure this payload. Jamf manages the SSL certificate.

Enrollment packages

You can use the Enrollment packages payload to choose packages to deploy to computers during enrollment. Installation commands for the selected packages are deployed to computers before Setup Assistant completes.

  • Packages must be built as flat, distribution style .pkg files and signed by a certificate that is trusted by managed computers.

  • Packages are installed in the order listed. If a package has dependencies, ensure they are ordered correctly. Large packages can significantly increase enrollment time.

Installing Packages During Automated Device Enrollment Enrollment