Creating an Enrollment Customization Configuration for Computers

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

Creating an enrollment customization configuration for computers with Jamf Pro enhances the Trusted Access framework by tailoring the enrollment experience to meet specific organizational needs. Enrollment customization allows you to guide end users through the setup process, simplifying the overall enrollment experience.

You can add branding elements, informational videos, and ensure authentication, all before the user ever reaches their computer. By customizing enrollment configurations, you streamline computer setup, enforce security policies, and maintain compliance standards from the moment the computer is activated. This approach not only simplifies the user experience, but also fortifies the security posture of your organization's IT infrastructure, ensuring that sensitive data always remains protected.

Requirements
  • Computers with macOS 12.x or later

  • To add a Single Sign-On Authentication PreStage Pane, you must have Single Sign-on enabled in Jamf Pro. For more information, see Single Sign-On (SSO) in the Jamf Pro Documentation.

  • Enabling Jamf Pro to pass user information to Jamf Connect requires Jamf Connect 1.12.0 or later. In addition, you must ensure Jamf Connect is configured and integrated with your identity provider (IdP). For more information, see Jamf Connect Identity Provider Integrations in the Jamf Connect Documentation.

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the Global section, click Enrollment customization .
  3. Click New.
  4. Enter a display name and description for the enrollment customization configuration.
  5. Choose a site to add the enrollment customization configuration to from the Site pop-up menu.

    This allows you to add the configuration to a PreStage enrollment in that same site.

    Note:

    If you have site access only, the profile is assigned to the applicable site automatically and the Site pop-up menu is not displayed.

  6. Add PreStage Panes to display screens to the end user:
    1. Click Add Pane.
    2. In the Add Pane dialog, enter a display name for the pane that will identify it in the list of PreStage Panes.
    3. Choose the type of PreStage Pane you want to add from the Pane Type pop-up menu.
    4. Configure the settings for the PreStage Pane.
      Note:
      • If you are configuring a Text PreStage Pane as the first screen presented to the user in the configuration, the button for navigating back in the enrollment process is not displayed. If the pane is the last screen in the configuration, the button to navigate forward initiates the enrollment process.

      • If you enable Jamf Pro to pass user information to Jamf Connect, you can map the attributes from your Identity Provider to an Account Name and Account Full Name. For example, if your IdP uses "Short Name" for the Account Name, you can type "Short Name" in the Account Name field so when the user enters their username (Account Name) during enrollment, Jamf Connect maps the Account Name to the "Short Name" in the IdP. When configured, these values are automatically sent to computers via a configuration profile during Automated Device Enrollment.

        Values entered in the Account Name and Full Account Name fields must be entered exactly as they appear in your IdP.

    5. Click Apply.
  7. (Optional) Add additional PreStage Panes to the enrollment customization configuration as needed.

    You can drag and drop PreStage Panes to change the PreStage pane order. If you added a Single Sign-On Authentication PreStage Pane and a Text PreStage Pane, the transition between each type of pane occurs when the user authenticates in the IdP login screen or uses the navigational buttons.

  8. Click the Branding and Preview tab to customize the enrollment experience and configure the settings on the page.

    Once a change is made, it automatically displays in the preview field.

  9. Click Save .

You can add the configuration to a PreStage enrollment to deploy during Automated Device Enrollment.

Note:

You cannot delete an enrollment customization configuration if the configuration is included in a PreStage enrollment. To delete the configuration, you must first remove it from the PreStage.