Re-enrolling a Computer Using Automated Device Enrollment

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Typically, devices are enrolled in Jamf School via Automated Device Enrollment during Setup Assistant. If a computer was not enrolled during setup, you can retroactively update the enrollment using the following workflow.

Requirements
  • A computer with macOS 13 or later
    Note:

    If the computer was signed in to iCloud with Find My enabled prior to enrollment in Jamf School, Activation Lock settings cannot be managed by Jamf School until the user manually disables Find My, or an IT administrator disables Activation Lock for the computer using Apple School Manager.

  • A computer that is logged in to the local account you plan to manage
    Note:

    If the computer has macOS 14 or earlier, the account must have administrative privileges. You can downgrade the account to standard after enrollment. For more information, see Change Users & Groups settings on Mac from the Apple Support website.

  • A computer that does not already have a Jamf School MDM profile installed.

    To check if there is an MDM profile installed on the computer, navigate to Devices > Inventory in Jamf School and click the computer you want to re-enroll. If "Automated Device Enrollment" displays next to Enrollment Method, the device has already been enrolled via Automated Device Enrollment and does not require re-enrollment, unless you are re-enrolling the device in order to make the local user MDM-enabled.

    If any other enrollment method displays, remove the profile by navigating to System Settings > General > Device Management on the computer. Then select MDM Profile and click the Remove icon (). When prompted to confirm the removal, click Remove.
    Note:

    Removing a profile requires an administrator account.

  • A computer enrolled in Apple School Manager and assigned to your Jamf School MDM server.

    To verify a computer is enrolled in Apple School Manager and assigned to your Jamf School MDM server, navigate to Devices > Automated Device Enrollment and locate the computer you want to re-enroll. If Jamf School recognizes the device as enrolled in Apple School Manager, a serial number displays for the device.

    Note:

    When a device is re-enrolled, you will still assign an Automated Device Enrollment profile to the device. Some settings configured in an Automated Device Enrollment profile can only be applied when the device proceeds through Setup Assistant during enrollment after it is erased.

  1. On the computer, open Terminal and execute the following command:
    • For macOS 15 or later:
      profiles renew -type enrollment
    • For macOS 14 or earlier:
      sudo profiles renew -type enrollment
  2. Enter the password for the local account and press Return.
  3. For macOS 14 or later, do the following:
    1. Click Enroll on the Remote Management screen.
    2. Enter the password for the local account and click Enroll.

      An Enrollment Complete status displays on the Remote Management screen.

    3. Click Quit.
  4. For macOS 13 or earlier, do the following:
    1. Click Details on the Device Enrollment notification that displays in the upper-right corner of the screen.
      Note:

      If the notification does not immediately display, click the date in the upper-right corner. Recent notifications will display, including the Device Enrollment notification.

    2. Follow the prompts to install the necessary profiles.

After the enrollment process is complete, the device will be enrolled in Jamf School via Automated Device Enrollment. If the Allow removal of the MDM profile checkbox is deselected in the Automated Device Enrollment profile, the profile cannot be removed by the user.

Note:

If you added the device to Apple School Manager using Apple Configurator, the device is provisionally managed and the user has the ability to leave remote management for the first 30 days of management. During that period, the user will see a message notifying them of the updated management state and will be able to remove MDM management in the System Settings menu. After 30 days, the message disappears and the user can no longer opt out of MDM management.

You can enable Find My or sign in to iCloud on the computer after enrollment to share its Activation Lock bypass code with Jamf School.

Note:

If Find My was enabled prior to enrollment, disable Find My on the computer, and then re-enable it. The Activation Lock bypass code in Jamf School will be updated in the device record the next time the device checks in to Jamf School.

If you enabled FileVault prior to enrollment and want to store FileVault keys in Jamf School, you must escrow a new FileVault recovery key. For more information, see Administering FileVault on Computers.