Creating a PreStage enrollment with Jamf Pro acts as a template for deploying customized and secure configurations using Automated Device Enrollment, ensuring a seamless deployment and Trusted Access experience. This process automates the application of pre-configured customizations and adjustments to the macOS Setup Assistant directly to computers, reducing the time and interaction needed to prepare new computers for use. By using PreStage enrollments, you ensure that these critical settings are applied uniformly from the moment a computer is activated. This method simplifies the user setup process, enhances security compliance, and maintains the integrity of your organization's IT infrastructure from the start.
Requirements
Before you can use a PreStage enrollment, you must do the following:
Integrate Jamf Pro with Automated Device Enrollment
On the PreStage Enrollments page, click New to create a new PreStage enrollment.
Click Save .
Do the following to configure remote management and security settings during Automated Device Enrollment:
Select the Require Authentication checkbox to require users to enter a username or password to enroll and set up the computer.
LDAP authentication during enrollment also automatically populates user and location information in the device's inventory information.
Note:If you add an enrollment customization configuration and have computers assigned to the PreStage enrollment that are capable of running a macOS version earlier than 10.15, Jamf recommends selecting the Require Authentication setting as a fail-safe to ensure those computers are not inadvertently enrolled without authentication. For computers with macOS 10.15 or later, the enrollment customization settings will transparently overwrite this setting.
Select the Make MDM Profile Mandatory checkbox.
(macOS 10.15 or later only) Select the Prevent user from enabling Activation Lock checkbox.
(Apple silicon with macOS 11.5 or later only) Select the Set Recovery Lock Password checkbox, and then choose an option from the Set Password Method pop-up menu.
This ensures users cannot access recoveryOS on computers without a password. recoveryOS password methods include the following:
"Manually enter password (applies to all computers)" —Enter a recoveryOS password that applies to all computers in the scope of the PreStage enrollment.
(Recommended) "Automatically generate random password for each computer" —Generate a unique password for each computer in the scope of the PreStage enrollment. This password is stored in each computer's inventory information in Jamf Pro. If you also select Rotate Recovery Lock password, the password is changed each time it's viewed in Jamf Pro.
In the General pane, do the following to skip Setup Assistant during Automated Device Enrollment:
Go to the Setup Assistant Options settings and select the screens that you want to skip during enrollment.
Select the Automatically advance through Setup Assistant (macOS 11 or later only) checkbox to skip all Setup Assistant screens. This option allows you to choose the initial language and location of the computer for users.
To distribute configuration profiles during Automated Device Enrollment, select one or more configuration profiles in the Configuration Profiles pane (for example, Jamf Connect configuration profiles).
Important:
Configuration profiles that contain payload variables are not replaced with their respective values when distributed via a PreStage enrollment. Jamf recommends distributing profiles with variables after the computer is enrolled with Jamf Pro.
To distribute and install packages that support the enrollment process during Automated Device Enrollment, click Add next to one more PKGs in the Enrollment Packages pane (for example, Jamf Connect packages).
To add an existing enrollment customization configuration during Automated Device Enrollment, choose a configuration from the Enrollment Customization Configuration pop-up menu in the General pane.
(Optional) In the Account Settings pane, do the following to create a managed local administrator account during Automated Device Enrollment:
Select the Create a managed local administrator account before Setup Assistant checkbox.
Complete the Username and Password fields, and then verify the password.
Select the Hide managed administrator from Users & Groups.
This prevents users from seeing or interacting with the managed administrator account in System Settings (macOS 13 or later) or System Preferences (macOS 12 or earlier).
Ensure the Make the local administrator account MDM-enabled checkbox is not selected.
This makes the managed administrator account MDM-enabled.
Warning:
Making the managed administrator MDM-enabled prevents the subsequent local user account from being MDM-enabled. If the primary local account is not MDM-enabled, user-level configuration profiles cannot be installed for the user. For more information, see MDM-Enabled Local User Accounts.
Select Skip Account Creation for the local account type.
By selecting this option, the user will not create the local user account because Jamf Connect is configured to create primary user local accounts during Automated Device Enrollment.
Configure the Purchasing, Attachments, or Certificates PreStage enrollment payloads to add the configured information to the inventory information of each device in scope during Automated Device Enrollment.
Click the Scope tab.
Do one of the following:
Select each device that you want to enroll via Automated Device Enrollment using settings in the PreStage enrollment.
Click Select All to add all devices associated with the Automated Device Enrollment instance, regardless of any results that have been filtered using the Filter Results, to the PreStage enrollment.
Click Save .
When you save your PreStage enrollment, the settings sync with Apple. Jamf Pro automatically syncs with Apple every two minutes and displays device information updates in the PreStage enrollment. If you continuously edit and save a PreStage enrollment, syncing delays may occur.