Methods to Achieve a User Approved MDM Status

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
There are a number of ways in which a computer can achieve a User Approved MDM status in Jamf Pro:
Enrollment TypeDescription
Enrollment via DEP

Enrollment via DEP using a PreStage enrollment is one of the methods which results in a User Approved MDM status.

For detailed information on computer PreStage enrollments, see Computer PreStage Enrollments in the Jamf Pro Documentation.

User-initiated enrollment with an MDM profile

User-initiated enrollment with an MDM profile is one of the methods which results in a User Approved MDM status.

During the user-initiated enrollment process, the user will be prompted to download and install a CA certificate (CA Certificate.mobileconfig) and then an MDM profile (enrollmentProfile.mobileconfig). Users must manually return to the enrollment portal webpage after CA certification installation to install the MDM profile and complete the enrollment process.

Note:

In environments with a trusted third-party signed SSL certificate in Jamf Pro, such as Jamf Cloud, administrators may choose to skip the installation of the CA certificate and only require the installation of the MDM profile. To allow the CA certificate installation to be skipped, navigate to Settings > Global > User-initiated enrollment and select the Skip certificate installation during enrollment checkbox.

For detailed information on Computer PreStage enrollments and the user-initiated enrollment experience, see User-Initiated Enrollment for Computers and User-Initiated Enrollment Experience for Computers in the Jamf Pro Documentation.

Enrollment in MDM prior to being upgraded to macOS 10.13.4

A computer with macOS that was enrolled in MDM prior to being upgraded to macOS 10.13.4 or later will retain the User Approved MDM status after the upgrade.

In addition, if a computer was enrolled without the User Approved MDM option, you can change the existing enrollment to a User Approved MDM status.

To approve an existing enrollment for an eligible computer, navigate to System Preferences > Profiles (macOS 12 or earlier) or System Settings > Privacy & Security > Profiles. Select the enrollment profile under Device Profiles, click the Approve button, and follow the prompts.