Creating a PreStage enrollment with Jamf Pro acts as a template for deploying customized and secure configurations using Automated Device Enrollment, ensuring a seamless deployment and Trusted Access experience. This process automates the application of pre-configured mobile device customizations and adjustments directly to devices, reducing the time and interaction needed to prepare new devices for use.
By using PreStage enrollments, you ensure that these critical settings are applied uniformly from the moment a device is activated. This method simplifies the user setup process, enhances security compliance, and maintains the integrity of your organization's IT infrastructure from the start.
Note:Devices with iOS 13 or later are automatically supervised and require users to install the MDM profile when enrolled via Automated Device Enrollment. For more information about supervision, see About Apple device supervision in Apple Platform Deployment.
Requirements
Before you can use a PreStage enrollment, you must do the following:
To require LDAP authentication to complete enrollment, integration with LDAP is required. For more information, see LDAP Directory Service Integration in the Jamf Pro Documentation.
In Jamf Pro, click Devices in the sidebar.
On the PreStage Enrollments page, click New to create a PreStage enrollment.
Click Save .
Do the following to configure remote management and supervision settings during Automated Device Enrollment:
Select the Require Credentials for Enrollment checkbox to require users to enter an LDAP username or password.
LDAP authentication during enrollment also automatically populates user and location information in the device's inventory information.
Note:If you add an enrollment customization configuration to the PreStage enrollment, this setting is ignored for devices with iOS 13 or later, and iPadOS 13 or later.
Select any of the following settings for supervised devices:
Pairing —
Allow a mobile device to connect to Mac computers via USB
Prevent unenrollment —Disallow users from removing the MDM profile
Install configuration profiles before Setup Assistant —Begin installing configuration profiles that include the device in its scope after the user completes enrollment and connects to WiFi but before the Setup Assistant displays.
Make sure the Prevent user from enabling Activation Lock checkbox is selected.
In the General pane, do the following to skip Setup Assistant during Automated Device Enrollment:
(tvOS only) Locate the Setup Assistant settings and select the Automatically advance through Setup Assistant (tvOS only) checkbox.
Go to the Setup Assistant Options settings and select the screens that you want to skip during enrollment.
Best Practice:
Click All to skip all the Setup Assistant screens and decrease the total enrollment time for users.
To add an existing enrollment customization configuration during Automated Device Enrollment, choose a configuration from the Enrollment Customization Configuration pop-up menu in the General pane.
(Optional) To configure how enrolled devices are named, do the following:
Click the Mobile device names payload and then click Configure.
Choose and configure one of the following from the Naming Method pop-up menu:
Default Names —
Depending on the enrollment status of the device, the following can happen when this option is chosen
If the device is re-enrolled with Jamf Pro, the value of the Mobile Device Name attribute field in the device's inventory information in Jamf Pro is assigned to the device at enrollment.
If the device is enrolled for the first time with Jamf Pro, the current name of the device persists after enrollment.
Serial Numbers —
The serial number of the device becomes the device's name during enrollment. You can add a suffix or a prefix to the serial number.
Best Practice:
Jamf recommends this naming method, which ensures enrolled devices are easy to identify and do not create a large number of devices with the default display name such as "iPhone" and "iPad".
List of Names —
Enter names separated by a comma to assign to the devices during enrollment.
Single Names —
Enter a single name that is assigned to all devices during enrollment.
Configure the Purchasing, Attachments, or Certificates PreStage enrollment payloads to add the configured information to the inventory information of each device in scope during Automated Device Enrollment.
Click the Scope tab.
Do one of the following:
Select each device that you want to enroll via Automated Device Enrollment using settings in the PreStage enrollment.
Click Select All to add all devices associated with the Automated Device Enrollment instance, regardless of any results that have been filtered using the Filter Results, to the PreStage enrollment.
Click Save .
When you save your PreStage enrollment, the settings sync with Apple. Jamf Pro automatically syncs with Apple every two minutes and displays device information updates in the PreStage enrollment. If you continuously edit and save a PreStage enrollment, syncing delays may occur.