There are two ways to migrate macOS devices from other Mobile Device Management (MDM) vendors to JumpCloud’s MDM. The method you use depends on the device’s enrollment status in Apple’s Automated Device Enrollment (ADE) or Apple Business Manager (ABM):
- The device is enrolled in Apple’s Automated Device Enrollment or ABM - If a device is shipped with an MDM enrollment profile already installed, use your current MDM provider to unenroll the device. You can then migrate the device to JumpCloud MDM. See To migrate an Automated Device Enrollment-enrolled device to JumpCloud MDM below.
For ADE devices enrolled with another MDM vendor, you must perform the following steps before they can be enrolled in JumpCloud MDM:
- Unenroll these devices directly from the other MDM vendor.
- Remove the old enrollment profile from these devices.
- The device is not enrolled in Apple’s Automated Device Enrollment or ABM - If a device hasn’t been enrolled through Automated Device Enrollment or ABM, you can migrate the device from another MDM vendor to JumpCloud MDM. See To migrate a non-Automated Device Enrollment device to JumpCloud MDM below.
To migrate an Automated Device Enrollment-enrolled device to JumpCloud MDM:
You’ll need to log into your ABM or Apple School Manager (ASM) account to reassign the device, and then re-enroll it using Apple’s Automated Device Enrollment.
- Access your current MDM provider and unenroll the device from that provider. If the current MDM provider cannot send the unenroll command and the enrollment profile is non-removable, you will need to erase the device before re-enrolling it with JumpCloud.
- If the device was enrolled using Automated Device Enrollment with ABM or ASM, reassign the device from your ABM or ASM account:
- Log into your ABM or ASM account.
- Select Devices in the sidebar and select your device. You might need to search by serial number.
- Click Edit MDM Server.
- Select one of these options:
- Assign to the following MDM - Choose a JumpCloud MDM server for automated enrollment or zero-touch enrollment. For more instructions, see Configure Automated Device Enrollment and Add Company-Owned Apple Devices to MDM with Device Enrollment.
- Unassign from the current MDM - Choose Unassign for device enrollment (formerly called manual or user-approved enrollment).
- Click Continue, then click Continue again to confirm the change. For more details on assigning and reassigning devices, see Apple's documentation on assigning, reassigning, and unassigning devices in ABM.
- Re-enroll the device. As root, use this command to enroll the device with Automated Device Enrollment:
# profiles renew -type enrollment
This command also creates a profile that the user cannot remove from the device, so that your company can continue to manage the device.
To migrate a non-Automated Device Enrollment device to JumpCloud MDM:
If your devices have not been enrolled through Apple’s Automated Device Enrollment or ABM, you can migrate those devices from another MDM vendor to JumpCloud’s MDM. If you don’t have the JumpCloud agent installed, installing the enrollment profile also auto-installs the agent. See Add Company-Owned Apple Devices to MDM with Device Enrollment.
JumpCloud's MDM Enrollment policy includes the ability to remove existing non-JumpCloud MDM enrollment profiles so that you can migrate devices from another MDM vendor to JumpCloud. See Create a MacOS MDM Enrollment Policy to learn how to remove existing non-JumpCloud MDM enrollment profiles before re-applying the JumpCloud MDM enrollment policy.
- Unenroll device from your current vendor.
- Enroll the device with JumpCloud. See Choosing an MDM Enrollment Method.