Requirements
To create an Automated Device Enrollment profile, you must automatically or manually assign devices in Apple School Manager to the Jamf School server. To automatically add devices you purchase to Jamf School, see Link to a third-party MDM server in Apple School Manager in the Apple School Manager User Guide. To manually assign devices to Jamf School after purchasing them, see Assign, reassign, or unassign devices in Apple School Manager in the Apple School Manager User Guide.
To require enrollment authentication with Microsoft Entra ID (formerly Azure AD) or Google Sign-In when enrolling devices via Automated Device Enrollment, you must integrate Jamf School with Microsoft Entra ID or Google Sign-In. For more information, see Microsoft Entra ID Integration and Google Sign-In Setup.
To deploy Jamf Connect via Automated Device Enrollment, you must license and download Jamf Connect. You can then configure packages and profiles in an Automated Device Enrollment profile. For more information, see Jamf Connect Deployment with Jamf School.
- In Jamf School, navigate to in the sidebar.
- Select the type of profile you want to create by clicking +iOS, +tvOS, or +macOS.
- Use the pop-up dialog to configure basic settings, including a profile name.
- Enter a support phone number and department name that users can reach out to if they need assistance during Automated Device Enrollment.
- To automatically configure device names during Automated Device Enrollment, enter a device name schema using variables in the Set Device Name field. For more information on the variables you can use, see Payload Variables.
- To allow the devices enrolled with this Automated Device Enrollment profile to connect to other computers, select the Allow pairing with other computers checkbox.
- To allow users to remove the MDM profile, select the Allow removal of the MDM profile checkbox.
Important:If a user removes the MDM profile, you cannot manage the device.
- To enable Shared iPad on devices enrolled with this Automated Device Enrollment profile, select the Enable Shared iPad checkbox.
- (For iOS 26 or later only) To preserve managed apps on a mobile device when returning the device to service using Return to Service, select the Preserve managed apps after erasure checkbox. Enabling app preservation eliminates the need to reinstall managed apps during device reset.
Note:If a device is set up with Return to Service app preservation enabled, the device becomes ineligible for MDM solution migrations that are initiated from Apple School Manager. The device becomes eligible again if it is erased and re-enrolled with an Automated Device Enrollment profile that has the app preservation feature disabled.
If a device is set up with Return to Service app preservation enabled, the device will not be able to install software updates. Managed software updates can be used to update the device on an ongoing basis if it is erased and re-enrolled using an Automated Device Enrollment profile that has the app preservation feature disabled. For more information, see Manage software and app updates with Return to Service in Apple Platform Deployment.
- To wait for profiles and packages to be deployed and installed before proceeding through Setup Assistant, select the Wait for the configuration to be applied before continuing the Setup Assistant checkbox.
For computers, you can enable FileVault during Setup Assistant by selecting the Force enabling FileVault during the Setup Assistant checkbox. Doing so will cause all other keys in the FileVault payload to be ignored. You can also select the Enable Personal Recovery Key Escrow checkbox to enable the computer to generate its own unique key to be escrowed by Jamf School. For more information, see Administering FileVault on Computers.
Note:In order to configure the profile's Administrator and Profiles and packages settings, you must select the Wait for the configuration to be applied before continuing the Setup Assistant checkbox.
- To activate eSIM automatically during Automated Device Enrollment, select the Configure eSIM checkbox and enter the carrier's URL in the Carrier URL field.
- To skip all Setup Assistant steps and choose the most restrictive option for each step automatically on Apple TV devices with tvOS 11.3 or later or computers with macOS 11 or later, select the Enable Zero-Touch Setup checkbox. This option allows you to choose the initial language and location on devices.
Important:If you select the Enable Zero-Touch Setup checkbox, Apple TV devices or computers must be connected to the internet via Ethernet during Automated Device Enrollment.
- To customize the user experience of Setup Assistant, select which steps you want to skip.
Note:If you choose to skip steps, the user can enable these settings after the device is configured unless otherwise restricted.
If you skip setting up an Apple Account during Setup Assistant, it will not affect the devices ability to deploy managed apps from Jamf School if your organization distributes apps via volume purchasing through Apple School Manager. If allowed, a user may sign into a personal Apple Account to download personally acquired apps from the App Store after device setup is complete.
If you choose to skip the Location Services step, the device will not automatically set the time and date and will not be able to use the Find My app.
- To require authentication during Automated Device Enrollment, select the Require authentication for enrollment checkbox. Additionally, you can make the authenticated user the device owner by selecting the Make authenticated user the device owner checkbox.
Note:If you want users to authenticate with Microsoft Entra ID after enrollment using a web clip, do not enable the the Make authenticated user the device owner checkbox. Only iOS and iPadOS devices can authenticate after enrollment using the Microsoft Entra ID web clip.
- To prompt users to create a local user account on the computer during Setup Assistant, do the following:
- Select the Prompt user to create an account of type: checkbox.
- Choose either Standard or Administrator as the account type. Administrators are users who can install apps, modify settings, and add and manage other users. Standard users can install apps and modify their own settings, but they cannot add and manage other users.
Note:(macOS 14–14.4 only) To enable FileVault Personal Recovery Key escrow during Automated Device Enrollment, the user must create an administrator account while proceeding through Setup Assistant.
- To configure the account full name and account name, select the Pre-fill primary account Full Name and Account Name checkbox and then fill in the Full Name and Account Name fields.
Note:The account full name is typically the user's first and last name (for example, Samantha Johnson). The account name, also called the short name, is set as the name of the user's home folder (for example, samanthajohnson) and can be set as the user's login name.
- To allow users to change the pre-filled account full name and account name during Setup Assistant, select the Allow user to modify primary account Full Name and Account Name checkbox.
- To set the account full name and account name based on the computer's inventory information at the time of enrollment, select the Use device owner's details checkbox.
Warning:Account creation can fail if accounts on the same computer have the same name.
- To create a managed local administrator account on the computer, do the following:
- Select the Create a managed macOS Administrator account checkbox.
- Enter the account full name, account name, and password.
- To show the managed local administrator account in the Users & Groups pane in System Settings (macOS 13 or later) or in System Preferences (macOS 12 or earlier), select the Show Managed Administrator account in Users checkbox.
- To make the managed local administrator account MDM-enabled and allow it to deploy user-configuration profiles, select the Make the local administrator account MDM-enabled checkbox.
Warning:Making the managed local administrator account MDM-enabled prevents the subsequent local user account from being MDM-enabled. If the primary local account is not MDM-enabled, user-level configuration profiles cannot be installed for the user.
- To automatically install Rosetta 2 on computers to use apps built for a Mac with an Intel processor, select the Automatically install Rosetta 2 on Mac computers with Apple silicon checkbox.
- To deploy and install profiles on computers during setup, click +Add next to Profiles and choose up to five profiles you want to deploy from the pop-up menu.
- To deploy and install packages on computers during setup, click +Add next to In-house macOS packages and choose up to five packages you want to install from the pop-up menu.
- Click Save. It can take up to five minutes before the profile is pushed to new devices.
Note:A device enrollment-created administrator account is eligible to receive a secure token when it logs in to a computer with macOS 10.15 or later if a bootstrap token has been escrowed to Jamf School. For more information about bootstrap token, see Use secure token, boostrap token, and volume ownership in deployments in Apple Platform Deployment.