Uploading and Deploying a iOS and iPadOS Activation Profile using Citrix Endpoint Management - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Once you have pushed the Jamf Trust app to your iOS and iPadOS devices via Citrix Endpoint Management, you can create a UEM configuration profile to push a traffic vectoring profile to these devices.

Important: If you are using the on-premise version of Citrix Endpoint Management, replace the parameter mdm-id=${device.uniqueid} in this payload with mdm-id=${device.id}. This does not apply if you are running the solution in the Citrix cloud.
Requirements
  1. Log in to Citrix Endpoint Management.

  2. Navigate to Settings > Client Properties > Edit Client Property.

  3. Set the value for ALLOW_CLIENTSIDE_PROXY to "TRUE".

Jamf recommends that you do this before deploying a GHP profile.

  1. In Jamf Security Cloud, navigate to Devices > Activation Profiles.
  2. Select the required Activation Profile.
  3. In the Managed Deployment area, select Citrix Endpoint Management.
  4. Save the required UEM configuration file.
    Note:

    There are two configuration files for iOS and iPadOS devices: one for supervised devices, and one for unsupervised. Select the one that applies to your devices. If you have both supervised and unsupervised devices, run through this process twice to create configuration profiles for both types

  5. Log in to Citrix Endpoint Management.
  6. Navigate to Configure > Policies, and then click Add.
  7. Select iOS on the left-hand side of the page.
  8. Select Custom > Import IOS & macOS profile.
  9. Enter a Policy Name, such as "Jamf Trust Supervised" or "Jamf Trust Unsupervised".
  10. De-select macOS on the left-hand side of the page, then click Next.
  11. Upload the UEM configuration profile you downloaded previously.
  12. Under Deployment Rules, create a rule specifying whether the profile is for supervised or unsupervised devices. Either:
    • Supervised = True

    • Supervised = False

  13. Create other rules if required.
  14. Click Save.
  15. If you have a mixed fleet of supervised and unsupervised devices, repeat the above steps for the other profile type as needed.