Creating an Activation Profile for Trusted Access

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

Activation profiles are used to enroll devices with the Jamf Security Cloud.

For Jamf Trusted Access, create an activation profile that enables all necessary security capabilities when deployed to devices. This activation profile will be referenced and utilized throughout your Trusted Access implementation.

Best Practice:

Considerations for Activation Profile Management

  • Use descriptive names and a consistent naming convention for all activation profiles in your environment.

  • Most activation profile settings cannot be edited after creation. To update security capabilities and settings on devices, unenroll devices by uninstalling the Jamf Trust app and deleting the device record from Jamf Security Cloud.

  • Security capabilities available during activation profile creation depend on whether your organization subscribes to Jamf Protect, Jamf Connect, or both.

Requirements
  • Familiarity with Activation Profile Settings.

  • You must link an identity provider to your portal.

    For more information, see Linking Identity Providers.

  • If you want to apply a Jamf-branded block page, you must enable the customized block page under Settings > Notifications > Browser Templates.

    The customized block page is only shown on proxied Apple devices that are deployed via your UEM solution. On other devices, the static block page will be shown.

  1. In Jamf Security Cloud, navigate to Devices > Activation profiles.
  2. Click Create profile.
  3. On the Capabilities and routing page, select all the security capabilities necessary for Trusted Access:
    Network access
    Provides secure access to your organization's resources using Jamf Connect's Zero Trust Network Access
    Content controls
    Manages network activity using Jamf Protect's internet content filtering and usage controls
    Network security
    Protects your network connections from cyber threats
  4. (Optional) Choose a traffic vectoring option and then click Next.
  5. On the User identification page, configure whether users must sign-in to the Jamf Trust via your organization's identity provider to enroll devices, and then click Next.

    Authenticated by identity provider is required to enable Jamf Connect Zero Trust Network Access or use identity-based provisioning.

  6. On the Advanced settings page, specify additional settings for the profile, such as the profile's expiration date.

    Available settings depend on which service capabilities you selected for the activation profile.

  7. On the Naming and grouping page, enter general information about the profile:
    1. Enter a descriptive name for the activation profile.
      Best Practice:

      Use descriptive names and a consistent naming convention for all activation profiles in your environment.

    2. Choose a device group to associate with the profile.
      Devices that use the activation profile to enroll are automatically added to this group in the Jamf Security Cloud portal.
      Note:If UEM Connect is configured, this group is overwritten during the next UEM Connect sync.
  8. On the Review page, confirm the details of the activation profile and then click Save and create.
You can now use the activation profile to enroll devices with the Jamf Security Cloud portal throughout your Trusted Access implementation.

To view your activation profiles in the Jamf Security Cloud portal, navigate to Devices > Activation Profiles.

To distribute the activation profile and Jamf Trust app to devices you want to enroll, see Distribute the Jamf Trust App with Jamf Pro.