User Enrollment for personally owned mobile devices is enabled via Jamf Pro's user-initiated enrollment settings.
Jamf recommends using account-driven User Enrollment because it provides a better end user experience and prevents end users from accessing a potentially untrusted enrollment endpoint.
Profile-driven User Enrollment is also available for iOS and iPadOS 13.1 or later (visionOS is not supported). However, this guide assumes the use of account-driven User Enrollment. Profile-driven User Enrollment can be useful for testing purposes if your organization has not yet hosted a service discovery configuration.
Jamf also recommends using Managed Apple Accounts that are federated with an identity provider (IdP) for the best enrollment experience for end users. When federated, end users can easily use the same credentials to authenticate to Jamf Pro and to iCloud to complete enrollment, and no new accounts and passwords are required to be generated to enroll. For more information, see Intro to federated authentication with Apple Business Manager in the Apple Business Manager User Guide.
Managed Apple Accounts and a service discovery configuration
For more information, see the Prepare for Account-Driven Enrollment with Managed Apple Accounts and Service Discovery article.
(LDAP login only) An LDAP server set up in Jamf Pro
For more information, see LDAP Directory Service Integration in the Jamf Pro Documentation.
(SSO login only) Single sign-on authentication enabled in Jamf Pro with the Enable Single Sign-On for User Authentication during Enrollment checkbox selected
For more information, see Single Sign-On (SSO) in the Jamf Pro Documentation.
Jamf Pro 10.33.0 or later
Personally owned devices must have the following:
Enough storage space for corporate data
iOS or iPadOS 15 or later
- visionOS 1.1 or laterNote:
Enrollment of Apple Vision Pro devices requires Jamf Pro 11.3.1 or Jamf Pro 11.4.0 or later.
- In Jamf Pro, click Settings in the sidebar.
- In the Global section, click User-initiated enrollment .
- Click Edit .
- Click the Devices tab.
- Select the checkboxes to enable account-driven User Enrollment for the personally owned devices you want to enroll.
- Click Save .
Account-driven User Enrollment is now enabled for enrolling personally owned devices with Jamf Pro. End users can navigate to and enter the email address for their Managed Apple Account to begin enrollment.
If Okta is your federated IdP for both Jamf Pro and Apple Business Manager, you can optionally configure an enrollment flow to use the Okta Verify app as an Enrollment SSO app. For more information, see Enrollment Single Sign-on (SSO) in the Jamf Pro Documentation.