Integrating with Automated Device Enrollment by Exchanging the Public Key and Server Token

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The following workflow describes how to add the Jamf School server to Apple School Manager and set up Automated Device Enrollment in Jamf School.

Requirements

If you have not already done so, you must enroll your school in Apple School Manager. For more information, see Sign up for Apple School Manager in the Apple School Manager User Guide.

  1. In Jamf School, navigate to Organization > Settings in the sidebar.
  2. Click the Automated Device Enrollment payload, and then click + Apple School Manager.
  3. In the Apple School Manager pop-up dialog, click Download your Public Key to download the .pem file.
  4. Upload the public key to Apple School Manager by doing the following:
    1. Log in to Apple School Manager.
    2. Click your profile name in the lower-left corner, then choose "Preferences" from the pop-up menu.
    3. Click Your MDM Servers and then click +Add.
    4. In the MDM Server Name field, enter a unique name for the server.
    5. (Optional) If you want the MDM server to be able to release devices, select the Allow this MDM server to release devices checkbox.
      Note:

      Allowing the MDM server to release devices enables you to disassociate devices assigned to the server if you want to sell, donate, or recycle them. Releasing devices removes them from Apple School Manager and makes them ineligible for Automated Device Enrollment in the future. Before releasing devices, ensure the devices you are releasing are not currently in use.

    6. In the MDM Server Settings section, click Upload Certificate and locate the public key (.pem) certificate file you downloaded, click Upload, and then click Save.
    7. In the top bar, click Download Token and then click Download Token to confirm the server token (.p7m) download.
  5. In Jamf School, in the Apple School Manager pop-up dialog, drag and drop the server token you downloaded from Apple School Manager into the Upload Server Token field.
  6. Click Apply.

In Apple School Manager, you can set the default device assignment for different device types to the newly added MDM server by clicking MDM Server Assignment and configuring the settings in the Default MDM Server Assignment section. For more information, see Assign, reassign, or unassign devices in Apple School Manager in the Apple School Manager User Guide.

When the Automated Device Enrollment integration is complete, you can proceed with importing users from Apple School Manager, and importing school information to Apple School Manager. For more information, see Apple School Manager Integration.