Enabling Activation Lock for a Device in Apple School Manager During Enrollment with Jamf School

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can use Jamf School to enable Activation Lock for a device that is in Apple School Manager during enrollment. This does not require end user interaction.

Requirements
To enable Activation Lock on computers, you need:
  • Computers with macOS 10.15 or later
  • Computers with Apple silicon or the Apple T2 security chip
  • Two-factor authentication for Apple Account
  • (Apple silicon only) The security policy must be set to Full Security, the default setting.
  • (Apple T2 security chip only) Startup security must be set to Secure Boot and "Disallow booting from external media", the default settings.
  • Computers in Apple School Manager
To enable Activation Lock on mobile devices, you need:
  • iOS 7 or later
  • Supervised devices
  • Mobile devices in Apple School Manager
  1. (For mobile devices only) To enable Activation Lock for devices enrolled using Automated Device Enrollment, do the following:
    1. In Jamf School, navigate to Profiles > Automated Device Enrollment Profiles in the sidebar.
    2. Click the name of the profile you want to enable Activation Lock for.
    3. Click the iOS Settings tab.
    4. From the Activation Lock pop-up menu, choose "Activate upon enrollment".
    5. Select the Use lock bypass code checkbox.
    6. Click Save.
  2. To enable Activation Lock for devices enrolled using on-device enrollment or User Enrollment, do the following:
    1. In Jamf School, navigate to Organization > Settings in the sidebar.
    2. Click Enrollment.
    3. Select the Automatically enable Activation Lock on devices that are not enrolled using Automated Device Enrollment checkbox.
    4. Click Save.

When the device is enrolled with Jamf School, Activation Lock is automatically enabled after enrollment.