JumpCloud policies can help you customize, manage, and secure devices in your organization. You can create a Mobile Device Management (MDM) enrollment policy to enroll existing Mac computers in MDM without using Apple’s Automated Device Enrollment (ADE).
This is a device level policy that applies system-wide to the device and all of its users. You can bind this policy to individual devices or device groups. For policies that apply to a specific user's profile across devices, see Get Started: Policies and Learn More section of this article.
You need to distribute and install your organization’s MDM enrollment policy and users will then approve the enrollment profile. See Add Company-Owned Apple Devices to MDM with Device Enrollment to learn more. Creating an MDM enrollment policy to do this saves you time and headaches.
If your Mac has been added to Apple Business Manager (ABM) or Apple School Manager (ASM) and the JumpCloud agent is installed, you can avoid wiping the device by following this procedure.
Prerequisites
- MDM is configured for your organization. See Set up Apple MDM.
- To assign a policy to a device, you need an active device running the JumpCloud agent on a supported OS. See Get Started: Devices.
- To assign a policy to a device group, you need a device group. See Get Started: Device Groups.
- Users must meet the following requirements before they can perform the MDM approval process:
- The user account must be associated with the device. See Bind Users to Devices.
- The user must have local administrator permissions. See Set Admin/Sudo Privileges.
Creating the Policy
To create a JumpCloud MDM Enrollment policy for Mac computers, do the following:
Selecting the Policy Template
- Log in to the JumpCloud Admin portal.
If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.
- Go to Device Management > Policy Management. The Policy Management page is displayed.
- On the Policy Management page, click +Add New.
- Select Device Policy to assign the policy to devices and device groups. On the New Device Policy page:
- Select the macOS tab.
- Search and select the required policy and click Configure. The Details tab of the policy is displayed.
- On the Details tab, configure the required policy configuration settings.
- (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
- (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.
Configuring the Policy
- (Optional) Under Settings, select Remove existing non-JumpCloud MDM enrollment profiles if you want to migrate devices previously enrolled in another MDM vendor. Selecting this removes existing non-JumpCloud MDM enrollment profiles before re-applying the JumpCloud MDM enrollment profile. However, it doesn’t remove existing enrollment profiles from other MDM vendors if the devices were enrolled through Apple’s Automated Device Enrollment. If you don’t have any devices that used another MDM vendor, the Remove existing non-JumpCloud MDM enrollment profiles setting isn’t visible.
- (Optional) Select the Device Groups tab, then select one or more device groups where you'll apply this policy.
Devices enrolled in ADE should not be added to an MDM Enrollment policy. Adding ADE devices to an MDM Enrollment policy may result in unexpected behavior during policy deployments.
Applying the Policy
- (Optional) Select the Policy Groups tab. Select one or more policy groups where you want to add this policy.
- Select the Device Groups tab. Select one or more device groups where you want to apply this policy. For device groups with multiple OS member types, the policy only applies when a user logs into a supported Mac computer that is enrolled in Apple MDM.
- Or, select the Devices tab. Select one or more devices whom you want to add this policy to.
- Click Create Policy. A success message is displayed indicating the completion of policy creation.
Viewing Policy Status
- Select the Status tab.
- To see the last Result Log for a device where this policy is applied, click view.
- If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.
After you create and apply a policy, the agent on an individual device continuously compares the local policy with the policy you created in JumpCloud. If a user modifies a device policy, JumpCloud automatically modifies the device policy to comply with the JumpCloud policy. This process ensures that JumpCloud policy and local devices are kept in sync.
Some policies take effect immediately while other policies may require an additional activation step, such as restarting the local system. After a policy takes effect, you can view the policy's status or review the log file to determine if the policy requires additional attention.
User Experience: Approving the MDM Enrollment Profile
After you apply the Mac MDM enrollment policy, users must manually approve the MDM profile via the JumpCloud Menu Bar App to enable user-approved MDM payloads.
- Requirements: Before proceeding, ensure your users meet the Prerequisites for MDM approval, including device binding and administrator permissions.
- End-User Instructions: For step-by-step instructions you can share with your users, see Users: Approve Your Mac MDM Profile.
