Creating an Enrollment Customization Configuration for Mobile Devices

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

Creating an enrollment customization configuration for mobile devices with Jamf Pro enhances the Trusted Access framework by tailoring the enrollment experience to meet specific organizational needs. Enrollment customization allows you to guide end users through the setup process, simplifying the overall enrollment experience.

You can add branding elements, informational videos, and ensure authentication, all before the user ever uses their device. By customizing enrollment configurations, you streamline device setup, enforce security policies, and maintain compliance standards from the moment a device is activated. This approach not only simplifies the user experience but also fortifies the security posture of your organization's IT infrastructure, ensuring that sensitive data always remains protected.

Requirements
  • Mobile devices with iOS 13 or later or iPadOS 13 or later

  • To add a Single Sign-On Authentication PreStage Pane, you must have Single Sign-on enabled in Jamf Pro. For more information, see Single Sign-On (SSO) in the Jamf Pro Documentation.

  • To add a Directory Service Authentication PreStage Pane, you must have Directory Service server set up in Jamf Pro. For more information, see LDAP Directory Service Integration in the Jamf Pro Documentation

  1. In Jamf Pro, click Settings in the sidebar.
  2. In the Global section, click Enrollment customization .
  3. Click New.
  4. Enter a display name and description for the enrollment customization configuration.
  5. Choose a site to add the enrollment customization configuration to from the Site pop-up menu.

    This allows you to add the configuration to a PreStage enrollment in that same site.

    Note:

    If you have site access only, the profile is assigned to the applicable site automatically and the Site pop-up menu is not displayed.

  6. Add PreStage Panes to display screens to the end user:
    1. Click Add Pane.
    2. In the Add Pane dialog, enter a display name for the pane that will identify it in the list of PreStage Panes.
    3. Choose the type of PreStage Pane you want to add from the Pane Type pop-up menu.
    4. Configure the settings for the PreStage Pane.
      Note:

      If you are configuring a Text PreStage Pane as the first screen presented to the user in the configuration, the button for navigating back in the enrollment process is not displayed. If the pane is the last screen in the configuration, the button to navigate forward initiates the enrollment process.

    5. Click Apply.
  7. (Optional) Add additional PreStage Panes to the enrollment customization configuration as needed.

    You can drag and drop PreStage Panes to change the PreStage pane order. If you added a Single Sign-On Authentication PreStage Pane and a Text PreStage Pane, the transition between each type of pane occurs when the user authenticates in the IdP login screen or uses the navigational buttons.

  8. Click the Branding and Preview tab to customize the enrollment experience and configure the settings on the page.

    Once a change is made, it automatically displays in the preview field.

  9. Click Save .

You can add the configuration to a PreStage enrollment to deploy during Automated Device Enrollment.

Note:

You cannot delete an enrollment customization configuration if the configuration is included in a PreStage enrollment. To delete the configuration, you must first remove it from the PreStage.