Add Company-Owned Apple Devices to MDM with Device Enrollment

If your company-owned macOS device was not added to your ABM or ASM account, you cannot use Apple’s Automated Device Enrollment to enroll the device. Instead, you can use Device Enrollment to download, distribute, and install your organization’s JumpCloud MDM enrollment profile. Enrollment profiles aren't device-specific, and you can download the profile from the MDM tab in the Admin Portal. The disadvantage of enrolling devices with this method is that the process can be time-intensive and might require physical access to the machine.

Prerequisites:

  • Device Enrollment is only appropriate for devices running macOS 11.0 (Big Sur) or newer that are not enrolled via Automated Device Enrollment.
  • MDM must be configured for your organization. See Set Up Apple MDM.
  • End-user network connectivity must be available for device provisioning. 

Considerations:

  • Apple’s Stolen Device Protection, when activated, prevents new MDM enrollments of any kind as a preventative measure. Deactivate the feature temporarily to allow users to enroll in MDM. You can turn Stolen Device Protection back on after the device has been enrolled.

Adding MacOS Devices to MDM

Follow this process to use Device Enrollment to enroll a company-owned macOS device in MDM:

  1. (IT Admin) Download your organization’s MDM enrollment profile: This gives you an enrollment profile that you will use to enroll devices. 
  2. (IT Admin) Distribute the enrollment profile: This delivers the profile to your end users.
  3. (End User) Install the enrollment profile: This installs the JumpCloud agent and service account on the device.
  4. (IT Admin) Bind the device to the user in the JumpCloud Admin Portal: This allows the user that is bound to the device to be managed in JumpCloud.

Downloading your org’s MDM enrollment profile

  1. Log in to the JumpCloud Admin Portal: https://console.jumpcloud.com.
  2. Go to DEVICE MANAGEMENT > MDM.
  3. On the Home Page under MDM Configuration, click download profile.
    • You can download the enrollment profile directly to each device or download the file and distribute it to multiple devices (via email or Slack).
  4. If prompted, click Keep. The MDM enrollment profile does not expire.
  5. After you download the enrollment profile, you’ll distribute and install it on the devices you want to manage.
    • Installing the enrollment profile also installs the JumpCloud agent. 

Distributing the enrollment profile

  1. Distribute (either through email, Slack, or a physical transfer) the enrollment profile file to each user. The enrollment profile is the same for all users.
    1. If you email the enrollment profile file to users, note that JumpCloud enforces settings that are applied to a device and not a specific user.
    2. When transferring files physically, USB ports could be disabled by a policy, so check your policies in the JumpCloud Admin Portal if you are using this method.

Installing the enrollment profile on macOS Ventura

Note:

In macOS 13 Ventura, System Preferences was renamed to System Settings and the steps differ slightly from previous versions.

  1. Double-click on the profile that your admin delivered to you. 
  2. Navigate to System Settings > Privacy and Security > Profiles to view the MDM Enrollment profile. 
  1. Double-click on the profile and click Enroll.
  2. You will be prompted for your device’s account password.
    1. Allow two to three minutes for MDM Configuration Profiles and the JumpCloud agent to install.
    2. Upon completion, a list of profiles will populate in the sidebar.
  3. The JumpCloud Service Account Utility will automatically open and prompt you to choose your username and enter your device’s account password.
  1. Select your user account from the dropdown menu, enter your password, then click Create Account.
    • If your username is not listed in the dropdown, contact your IT Admin for assistance.
  2. The Mac is now enrolled in the JumpCloud Admin Portal.
    1. Notify your IT admin that the installation is complete on your end.
    2. When your IT Admin has finished the binding process, they will prompt you to log out of your Mac user account and log back in. Confirm your previous password and your new JumpCloud password when prompted.

Installing the enrollment profile on macOS Monterey and earlier

  1. Double-click on the profile that your admin delivered to you. 
  2. Navigate to System Preferences > Profiles to view the MDM Enrollment profile. 
  1. Click Install….
  2. You will be prompted for your device’s account password.
    1. Allow two to three minutes for MDM Configuration Profiles and the JumpCloud agent to install.
    2. Upon completion, a list of profiles will populate in the sidebar.
  3. The JumpCloud Service Account Utility will automatically open and prompt you to choose your username and enter your device’s account password.
  1. Select your user account from the dropdown menu, enter your password, then click Create Account.
    • If your username is not listed in the dropdown, contact your IT Admin for assistance.
  2. The Mac is now enrolled in the JumpCloud Admin Portal.
    1. Notify your IT admin that the installation is complete on your end.
    2. When your IT Admin has finished the binding process, they will prompt you to log out of your Mac user account and log back in. Confirm your previous password and your new JumpCloud password when prompted.

Binding the macOS device to the user in JumpCloud

Note:

The local username on the device must exactly match the JumpCloud username. See Take Over an Existing User Account with JumpCloud.

  1. Verify that the service account was created for the macOS device. See Install and Use the Service Account for MacOS.
  2. Log in to the JumpCloud Admin Portal: https://console.jumpcloud.com.
  3. Go to USER MANAGEMENT > Users.
  4. Select a user.
  5. Select Devices and select the device that you want to bind to this user.
  6. To bind the user to a device, click save user.

Adding iOS Devices to MDM 

Note:
  • This section uses the term “iOS devices” to include iPhones, iPads, and Apple TVs. 
  • The JumpCloud agent is not installed on iOS devices.

Prerequisites:

There are two ways to enroll a company-owned iOS device in MDM. The method depends on whether you have the device in hand (QR code) or not (enrollment profile):

  1. QR code: Scan the QR code in the Admin Portal and set up the device before handing it to the employee.
    • If you do not have access to the company-owned device, you can also email the Direct Link to the QR code to the user to scan.
  2. Enrollment profile: Download and distribute your organization’s JumpCloud MDM enrollment profile, and have the user install the profile on the device.

Enrolling via QR code

Have the iOS device handy because you’ll scan a QR code and set the device up before handing it over to the employee.

  1. Log in to the JumpCloud Admin Portal: https://console.jumpcloud.com.
  2. Go to DEVICE MANAGEMENT > MDM.
  3. Under Admin iOS Configuration, click View QR Code.

Tip:

You can also perform these actions by going to DEVICE MANAGEMENT > Devices, selecting Devices, selecting ( + ) to add a new device, and selecting iOS.

  1. Follow the steps to scan the QR code, download the MDM enrollment profile, and install it on the device.
    • If for some reason the QR code does not scan, click Direct Link to enroll the device.

Tip:

You can only install one profile at a time. For example, if you download a profile and don't install it, and then download a second profile, only the second profile is valid. 

If you do not have access to the company-owned iOS device, you can also email the Direct Link for the QR code to the user to scan and install.

  1. View the enrolled device by going to DEVICE MANAGEMENT > Devices
  2. Select the device you just enrolled and select Details to view more information, such as OS version, serial number, MDM Device ID, and storage usage.
  3. (Optional) If you want to enforce lock timers and PIN codes, you can create and apply a policy. See Configure Settings for iOS and iPadOS Policies.
  4. Deliver the enrolled device to the user.

Enrolling via enrollment profile

If a company-owned iOS device was not added to your ABM or ASM account, you can’t use Apple’s Automated Device Enrollment. You can instead download and distribute your organization’s JumpCloud MDM enrollment profile, and have users install it. 

  1. Download your organization’s enrollment profile.
  2. Log in to the JumpCloud Admin Portal: https://console.jumpcloud.com.
  3. Go to DEVICE MANAGEMENT > MDM.
  4. On the Home Page under Admin iOS Configuration, click View QR Code, then click Direct Link below the QR code to download the iOS MDM enrollment profile.
  5. If prompted, click Keep. The MDM enrollment profile does not expire.
  6. Distribute the enrollment profile file to each user. If you email the enrollment profile file to users, note that JumpCloud enforces settings that are applied to a device and not a specific user. 
  7. Verify that the user is on the device you want to manage when the user installs and approves the enrollment profile. 
  8. Instruct the user to install the enrollment profile on their devices and approve the profile:
    1. Tap Allow to download the profile.
    2. Tap Close to go to the profile in Settings.
    3. Tap Profile Downloaded, then tap Install to install the MDM enrollment profile.
    4. Tap Trust to enroll this device in MDM.
    5. After the profile is installed, tap Done.
ios-remote-mgmt.png
  1. Assign the device to the user.
    1. Log in to the JumpCloud Admin Portal: https://console.jumpcloud.com.
    2. Go to USER MANAGEMENT > Users.
    3. Select a user.
    4. Select Devices and select the iOS device that you want to assign to this user.
    5. Click save user

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case