Creating a PreStage Enrollment to Deploy the Automated Device Enrollment Experience to Mobile Devices

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

Creating a PreStage enrollment with Jamf Pro acts as a template for deploying customized and secure configurations using Automated Device Enrollment, ensuring a seamless deployment and Trusted Access experience. This process automates the application of pre-configured mobile device customizations and adjustments directly to devices, reducing the time and interaction needed to prepare new devices for use.

By using PreStage enrollments, you ensure that these critical settings are applied uniformly from the moment a device is activated. This method simplifies the user setup process, enhances security compliance, and maintains the integrity of your organization's IT infrastructure from the start.

Note:Devices with iOS 13 or later are automatically supervised and require users to install the MDM profile when enrolled via Automated Device Enrollment. For more information about supervision, see About Apple device supervision in Apple Platform Deployment.
Requirements

Before you can use a PreStage enrollment, you must do the following:

  1. In Jamf Pro, click Devices in the sidebar.
  2. On the PreStage Enrollments page, click New to create a PreStage enrollment.
  3. Click Save .
  4. Do the following to configure remote management and supervision settings during Automated Device Enrollment:
    1. Select the Require Credentials for Enrollment checkbox to require users to enter an LDAP username or password.

      LDAP authentication during enrollment also automatically populates user and location information in the device's inventory information.

      Note:If you add an enrollment customization configuration to the PreStage enrollment, this setting is ignored for devices with iOS 13 or later, and iPadOS 13 or later.
    2. Select any of the following settings for supervised devices:
      • Pairing

        Allow a mobile device to connect to Mac computers via USB

      • Prevent unenrollmentDisallow users from removing the MDM profile
      • Install configuration profiles before Setup AssistantBegin installing configuration profiles that include the device in its scope after the user completes enrollment and connects to WiFi but before the Setup Assistant displays.
    3. Make sure the Prevent user from enabling Activation Lock checkbox is selected.

      This ensures users cannot enable Activation Lock. For more information, see the Leveraging Apple's Activation Lock Feature with Jamf Pro article.

  5. In the General pane, do the following to skip Setup Assistant during Automated Device Enrollment:
    1. (tvOS only) Locate the Setup Assistant settings and select the Automatically advance through Setup Assistant (tvOS only) checkbox.
    2. Go to the Setup Assistant Options settings and select the screens that you want to skip during enrollment.
      Best Practice:

      Click All to skip all the Setup Assistant screens and decrease the total enrollment time for users.

  6. To add an existing enrollment customization configuration during Automated Device Enrollment, choose a configuration from the Enrollment Customization Configuration pop-up menu in the General pane.
  7. (Optional) To configure how enrolled devices are named, do the following:
    1. Click the Mobile device names payload and then click Configure.
    2. Choose and configure one of the following from the Naming Method pop-up menu:
      • Default Names

        Depending on the enrollment status of the device, the following can happen when this option is chosen

        • If the device is re-enrolled with Jamf Pro, the value of the Mobile Device Name attribute field in the device's inventory information in Jamf Pro is assigned to the device at enrollment.

        • If the device is enrolled for the first time with Jamf Pro, the current name of the device persists after enrollment.

      • Serial Numbers

        The serial number of the device becomes the device's name during enrollment. You can add a suffix or a prefix to the serial number.

        Best Practice:

        Jamf recommends this naming method, which ensures enrolled devices are easy to identify and do not create a large number of devices with the default display name such as "iPhone" and "iPad".

      • List of Names

        Enter names separated by a comma to assign to the devices during enrollment.

      • Single Names

        Enter a single name that is assigned to all devices during enrollment.

  8. Configure the Purchasing, Attachments, or Certificates PreStage enrollment payloads to add the configured information to the inventory information of each device in scope during Automated Device Enrollment.
  9. Click the Scope tab.
  10. Do one of the following:
    • Select each device that you want to enroll via Automated Device Enrollment using settings in the PreStage enrollment.

    • Click Select All to add all devices associated with the Automated Device Enrollment instance, regardless of any results that have been filtered using the Filter Results, to the PreStage enrollment.

  11. Click Save .

When you save your PreStage enrollment, the settings sync with Apple. Jamf Pro automatically syncs with Apple every two minutes and displays device information updates in the PreStage enrollment. If you continuously edit and save a PreStage enrollment, syncing delays may occur.