Manually Preparing and Enrolling a Device Using Apple Configurator

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Requirements
To enroll a device in Jamf School using Apple Configurator, you need:
  • A Mac computer with the latest version of Apple Configurator installed
  • Mobile devices with iOS 16 or later, iPadOS 16.1 or later, or Apple TV devices with tvOS 16 or later

  • (Optional) A USB hub to enroll up to 30 devices at one time

  • A server token uploaded to Jamf School. For more information, see Apple School Manager Integration.

  • An Automated Device Enrollment profile for iOS devices created in Jamf School. For instructions, see Automated Device Enrollment.

Note:
Before enrolling a mobile device using Apple Configurator, Jamf recommends doing the following:
  • Erase the device and progress through Setup Assistant until the device is connected to the internet.

  • Download and import your organization and supervision identity from Jamf School. For more information, see Downloading a Supervision Identity for Use in Apple Configurator.

  • Ensure you have Apple School Manager login credentials. Jamf recommends creating an Apple School Manager account that only has the Device Enrollment Manager role configured. Configuring the Content Manager role may cause problems with the volume purchasing token in Jamf School. For more information on Apple School Manager roles, see Intro to roles and privileges in Apple School Manager in the Apple School Manager User Guide.

  • Ensure the device is not already added to Apple School Manager. You can verify this by navigating to Devices in the Apple School Manager sidebar and searching for the device. If the device displays, you can start the following workflow at step 14.

To require authentication during enrollment, you must configure authentication settings. For more information, see the following sections in this guide:
Note:

If a device was previously enrolled in another MDM, you must remove the MDM profile before using Apple Configurator enrollment. For more information, see Removing an MDM Profile Manually.

  1. Connect the device you want to enroll to a Mac computer with Apple Configurator installed by doing the following:
    • For iPadOS or iOS devices, use a Lightning-to-USB cable to connect to the Mac computer.

    • For Apple TV devices, use a USB-C cable to connect to the Mac computer. For additional connection options for Apple TV devices, see Connect devices to Apple Configurator for Mac in the Apple Configurator User Guide for Mac.

  2. If the Trust This Computer? pop-up dialog appears on the device, tap Trust.
  3. Open Apple Configurator and do the following:
    • Verify that the device is displayed and that it is not currently supervised.

    • Note the device's serial number (available from the Info view in Apple Configurator). You will need it later to assign the device to the MDM server synced with Jamf School.

  4. Select the device and click Prepare from the top bar.
  5. In the Prepare Devices dialog, do the following:
    1. From the Prepare with pop-up menu, choose "Manual Configuration".
    2. Select the Add to Apple School Manager or Apple Business Manager checkbox.
    3. Ensure the Activate and complete enrollment checkbox is deselected.
    4. Ensure the Supervise devices checkbox is selected.
    5. (Optional) Jamf recommends selecting the Allow devices to pair with other computers checkbox.
    6. Ensure the Enable Shared iPad checkbox is deselected.
    7. Click Next.
  6. In the Enroll in MDM Server dialog, do the following:
    • If this is your first time using Apple Configurator, choose "New Server..." from the Server pop-up menu and click Next.

    • If you have previously used Apple Configurator, choose your MDM server from the Server pop-up menu and click Next.

  7. If you are setting up a new server, do the following in the Define an MDM Server dialog:
    1. Enter a display name for your server in the Name field. For example: Jamf School MDM.
    2. Log in to Jamf School, and navigate to Devices > Enroll Device(s) in the sidebar.
    3. Copy the URL in the MDM Server URL field.
    4. In Apple Configurator, paste the URL in the Host name or URL field and click Next.
      Note:

      If an "Unable to verify the server's enrollment URL" message appears, click Next again.

    5. Click *.jamfcloud to add trust anchor certificates for the MDM server and click Next.
  8. In the Assign to Organization dialog, do the following:
    • If you are setting up a new organization, choose "New Organization..." from the Organization pop-up menu and click Next.

    • If you already have an organization set up, choose the existing organization from the Organization pop-up menu and click Next.

  9. If you are setting up a new organization, enter your login credentials to sign in to Apple School Manager in the Sign in to Apple School Manager or Apple Business Manager dialog.
  10. If you are setting up a new organization, generate or choose a supervision identity in the Create an Organization dialog. If this is your first time using Apple Configurator, select Generate a new supervision identity and click Next.
  11. In the Configure iOS Setup Assistant or Configure tvOS Setup Assistant dialog, depending on the device being prepared, choose "Don't show any of these steps" from the Setup Assistant pop-up menu and click Next. Steps displayed on the device during Setup Assistant will be configured in the Automated Device Enrollment profile instead.
  12. In the Choose Network Profile dialog, click Prepare.
    Note:

    Jamf recommends manually connecting the device to Wi-Fi during Setup Assistant.

  13. If your device is already set up, you will be prompted to erase the device. Click Erase.
    The device will reboot and be added to your account.
    Note:

    This process may take several minutes.

  14. Log in to Apple School Manager.
  15. Click Devices in the sidebar and enter the serial number of the device in the search field.
  16. Click Edit MDM Server.
  17. From the Assign to server pop-up menu, choose the Jamf School MDM server and click Continue.
  18. In Jamf School, navigate to Devices > Automated Device Enrollment in the sidebar.
  19. Confirm the device is listed and "Profile assigned" is displayed in the Status column.
    • If there is no profile assigned to the device, select the checkbox next to the device and click Assign profile in the upper right. Then, in the pop-up dialog, choose the Automated Device Enrollment profile from the Automated Device Enrollment profile pop-up menu and click Assign.

    • If the device is not displayed, click Dashboard in the sidebar and then click Synchronize Now to sync with Apple School Manager.

  20. On the device, complete the setup steps to complete enrollment.
The device is now enrolled in Jamf School via Automated Device Enrollment as a supervised device. The device will also appear under the Supervised tab in Apple Configurator.
Note:

In Jamf School, when you add a mobile device or Apple TV device using Apple Configurator, the device is provisionally managed. Provisional management means that the user has the ability to leave remote management for the first 30 days of management. During that period, the user will see a message notifying them of the updated management state and will be able to remove MDM management in the System Settings menu. After 30 days, the message disappears and the user can no longer opt out of MDM management.