You can use Jamf School to enable Activation Lock for a device that is in Apple School Manager during enrollment. This does not require end user interaction.
Requirements
To enable Activation Lock on computers, you need:
- Computers with macOS 10.15 or later
- Computers with Apple silicon or the Apple T2 security chip
- Two-factor authentication for Apple Account
- (Apple silicon only) The security policy must be set to Full Security, the default setting.
- (Apple T2 security chip only) Startup security must be set to Secure Boot and "Disallow booting from external media", the default settings.
- Computers in Apple School Manager
To enable Activation Lock on mobile devices, you need:
- iOS 7 or later
- Supervised devices
- Mobile devices in Apple School Manager
- (For mobile devices only) To enable Activation Lock for devices enrolled using Automated Device Enrollment, do the following:
- In Jamf School, navigate to in the sidebar.
- Click the name of the profile you want to enable Activation Lock for.
- Click the iOS Settings tab.
- From the Activation Lock pop-up menu, choose .
- Select the Use lock bypass code checkbox.
- Click Save.
- To enable Activation Lock for devices enrolled using on-device enrollment or User Enrollment, do the following:
- In Jamf School, navigate to in the sidebar.
- Click Enrollment.
- Select the Automatically enable Activation Lock on devices that are not enrolled using Automated Device Enrollment checkbox.
- Click Save.
When the device is enrolled with Jamf School, Activation Lock is automatically enabled after enrollment.