{"id":46753,"date":"2020-06-26T17:46:01","date_gmt":"2020-06-26T23:46:01","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=46753"},"modified":"2022-10-07T13:09:19","modified_gmt":"2022-10-07T17:09:19","slug":"remote-macos-mdm-enrollment-policy","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy","title":{"rendered":"Enroll Remote macOS Systems with the MDM Enrollment Policy"},"content":{"rendered":"\n

Reading the tea leaves from Apple\u00ae<\/sup>\u2019s WWDC2020, it\u2019s evident that their mobile device management<\/a> (MDM) framework is the future for macOS\u00ae<\/sup> lifecycle management.\u00a0<\/p>\n\n\n\n

To that end, JumpCloud\u00ae<\/sup> is excited to offer admins a seamless way to remotely enroll macOS systems<\/a> into MDM via policy in the Directory-as-a-Service\u00ae<\/sup> platform.<\/p>\n\n\n\n

Admins can implement the JumpCloud MDM Enrollment policy in just a few clicks \u2014 enrolling their entire fleet of macOS systems into MDM without any end user input, interaction, or disruption.<\/p>\n\n\n\n

One of the most exciting aspects of this policy is its ability to be used to migrate from another MDM vendor to JumpCloud. JumpCloud provides robust system management capabilities across Mac\u00ae<\/sup>, Windows\u00ae<\/sup>, and Linux\u00ae<\/sup> systems, leading many admins to Directory-as-a-Service as a way to consolidate device management<\/a> into a single platform. <\/p>\n\n\n\n

How it Works<\/h2>\n\n\n\n

The MDM Enrollment Policy leverages the macOS system agent to apply the JumpCloud MDM enrollment profile.  <\/p>\n\n\n\n

JumpCloud policies execute on a device’s agent check-in. This means that targeted offline systems will receive the policy\u2019s payload the next time they come online.  <\/p>\n\n\n\n

With one click of the checkbox shown below, the policy will also migrate the bound system from another MDM vendor to JumpCloud MDM.<\/p>\n\n\n\n

When selected, the JumpCloud system agent removes any existing non-JumpCloud MDM enrollment profiles before installing the JumpCloud MDM profile on the macOS device. Like the Highlander, there can only be one MDM enrollment profile, so admins using another MDM provider must use this policy to remove existing profiles before deploying the JumpCloud MDM enrollment profile. <\/p>\n\n\n\n

Note: <\/strong>If a device has been enrolled into MDM via automated device enrollment (DEP) and the profile is set to be non-removable, the JumpCloud agent will not be able to remove this profile and migrate the system to JumpCloud MDM.<\/em><\/p>\n\n\n\n

For admins looking to migrate systems in this state, the device must be reassigned to the JumpCloud MDM server through Apple Business or School Manager, and then re-registered to the profile via new device activation.<\/em><\/p>\n\n\n\n

Why It Matters<\/h2>\n\n\n\n

For admins working in the new remote \u201cwork from home\u201d world, macOS system management capabilities available via Apple MDM are more important than ever \u2014 and admins might find that Apple Business Manager<\/a> isn’t the solution they’re looking for.<\/p>\n\n\n\n

Often, the trickiest part of managing remote systems is deploying management software to them securely. The JumpCloud MDM Enrollment policy allows JumpCloud admins to roll out JumpCloud MDM to existing systems in their org with just a few clicks.<\/p>\n\n\n\n

For admins that may have no remote system management currently in place, this policy can be paired with a new feature that allows end users to enroll their own machines<\/a> into JumpCloud via a self-service workflow in the JumpCloud User Portal, creating a clear path to implement MDM.  <\/p>\n\n\n\n

What\u2019s Next<\/h2>\n\n\n\n

The JumpCloud Apple MDM<\/a> development team is hard at work developing features that will capitalize on the investment Apple has made in the Apple MDM protocols revealed during its world wide developer conference. Stay tuned for releases that blend the power of the JumpCloud directory with the payloads only available via Apple MDM.
<\/p>\n","protected":false},"excerpt":{"rendered":"

With the new macOS MDM enrollment policy, admins can remotely apply the JumpCloud MDM profile to manage WFH users through Directory-as-a-Service.<\/p>\n","protected":false},"author":72,"featured_media":43060,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"categories":[23],"tags":[],"collection":[2778,2779],"platform":[],"funnel_stage":[3016],"coauthors":[2594],"acf":[],"yoast_head":"\nEnroll Remote macOS Systems with the MDM Enrollment Policy - JumpCloud<\/title>\n<meta name=\"description\" content=\"With the new macOS MDM enrollment policy, admins can remotely apply the JumpCloud MDM profile to manage WFH users through Directory-as-a-Service.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Enroll Remote macOS Systems with the MDM Enrollment Policy\" \/>\n<meta property=\"og:description\" content=\"With the new macOS MDM enrollment policy, admins can remotely apply the JumpCloud MDM profile to manage WFH users through Directory-as-a-Service.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy\" \/>\n<meta property=\"og:site_name\" content=\"JumpCloud\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-26T23:46:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-10-07T17:09:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"564\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Scott Reed\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Scott Reed\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#article\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy\"},\"author\":{\"name\":\"Scott Reed\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/2e86bfef11c0b527d4da30d38cbb3678\"},\"headline\":\"Enroll Remote macOS Systems with the MDM Enrollment Policy\",\"datePublished\":\"2020-06-26T23:46:01+00:00\",\"dateModified\":\"2022-10-07T17:09:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy\"},\"wordCount\":533,\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg\",\"articleSection\":[\"Best Practices\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy\",\"url\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy\",\"name\":\"Enroll Remote macOS Systems with the MDM Enrollment Policy - JumpCloud\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg\",\"datePublished\":\"2020-06-26T23:46:01+00:00\",\"dateModified\":\"2022-10-07T17:09:19+00:00\",\"description\":\"With the new macOS MDM enrollment policy, admins can remotely apply the JumpCloud MDM profile to manage WFH users through Directory-as-a-Service.\",\"breadcrumb\":{\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg\",\"width\":1024,\"height\":564,\"caption\":\"GPO-Like Policy\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jumpcloud.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Enroll Remote macOS Systems with the MDM Enrollment Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jumpcloud.com\/#website\",\"url\":\"https:\/\/jumpcloud.com\/\",\"name\":\"JumpCloud\",\"description\":\"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.\",\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jumpcloud.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jumpcloud.com\/#organization\",\"name\":\"JumpCloud\",\"url\":\"https:\/\/jumpcloud.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"width\":598,\"height\":101,\"caption\":\"JumpCloud\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/2e86bfef11c0b527d4da30d38cbb3678\",\"name\":\"Scott Reed\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/6564d0066ff197d0725566149a13c563\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5da305aaf57ba9fbef01d614278392ff?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5da305aaf57ba9fbef01d614278392ff?s=96&d=mm&r=g\",\"caption\":\"Scott Reed\"},\"description\":\"Scott Reed is a Product Manager on the Devices team at JumpCloud. Prior to joining the Product team, he led the Solution Architecture team at JumpCloud. In fact, Scott is the original author of the JumpCloud PowerShell module. Scott\u2019s background is in Corporate IT. Outside of work Scott loves to seek out fresh air and adventure with his wife, two young sons, and their black lab Lucy.\",\"sameAs\":[\"https:\/\/github.com\/scottd3v\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Enroll Remote macOS Systems with the MDM Enrollment Policy - JumpCloud","description":"With the new macOS MDM enrollment policy, admins can remotely apply the JumpCloud MDM profile to manage WFH users through Directory-as-a-Service.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy","og_locale":"en_US","og_type":"article","og_title":"Enroll Remote macOS Systems with the MDM Enrollment Policy","og_description":"With the new macOS MDM enrollment policy, admins can remotely apply the JumpCloud MDM profile to manage WFH users through Directory-as-a-Service.","og_url":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy","og_site_name":"JumpCloud","article_published_time":"2020-06-26T23:46:01+00:00","article_modified_time":"2022-10-07T17:09:19+00:00","og_image":[{"width":1024,"height":564,"url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg","type":"image\/jpeg"}],"author":"Scott Reed","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Scott Reed","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#article","isPartOf":{"@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy"},"author":{"name":"Scott Reed","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/2e86bfef11c0b527d4da30d38cbb3678"},"headline":"Enroll Remote macOS Systems with the MDM Enrollment Policy","datePublished":"2020-06-26T23:46:01+00:00","dateModified":"2022-10-07T17:09:19+00:00","mainEntityOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy"},"wordCount":533,"publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg","articleSection":["Best Practices"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy","url":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy","name":"Enroll Remote macOS Systems with the MDM Enrollment Policy - JumpCloud","isPartOf":{"@id":"https:\/\/jumpcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg","datePublished":"2020-06-26T23:46:01+00:00","dateModified":"2022-10-07T17:09:19+00:00","description":"With the new macOS MDM enrollment policy, admins can remotely apply the JumpCloud MDM profile to manage WFH users through Directory-as-a-Service.","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#primaryimage","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2019\/11\/JumpCloud-Policies-Template.jpg","width":1024,"height":564,"caption":"GPO-Like Policy"},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/blog\/remote-macos-mdm-enrollment-policy#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jumpcloud.com\/"},{"@type":"ListItem","position":2,"name":"Enroll Remote macOS Systems with the MDM Enrollment Policy"}]},{"@type":"WebSite","@id":"https:\/\/jumpcloud.com\/#website","url":"https:\/\/jumpcloud.com\/","name":"JumpCloud","description":"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.","publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jumpcloud.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/jumpcloud.com\/#organization","name":"JumpCloud","url":"https:\/\/jumpcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","width":598,"height":101,"caption":"JumpCloud"},"image":{"@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/2e86bfef11c0b527d4da30d38cbb3678","name":"Scott Reed","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/person\/image\/6564d0066ff197d0725566149a13c563","url":"https:\/\/secure.gravatar.com\/avatar\/5da305aaf57ba9fbef01d614278392ff?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5da305aaf57ba9fbef01d614278392ff?s=96&d=mm&r=g","caption":"Scott Reed"},"description":"Scott Reed is a Product Manager on the Devices team at JumpCloud. Prior to joining the Product team, he led the Solution Architecture team at JumpCloud. In fact, Scott is the original author of the JumpCloud PowerShell module. Scott\u2019s background is in Corporate IT. Outside of work Scott loves to seek out fresh air and adventure with his wife, two young sons, and their black lab Lucy.","sameAs":["https:\/\/github.com\/scottd3v"]}]}},"_links":{"self":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/46753"}],"collection":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/users\/72"}],"replies":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/comments?post=46753"}],"version-history":[{"count":3,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/46753\/revisions"}],"predecessor-version":[{"id":70078,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/posts\/46753\/revisions\/70078"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media\/43060"}],"wp:attachment":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media?parent=46753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/categories?post=46753"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/tags?post=46753"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/collection?post=46753"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/platform?post=46753"},{"taxonomy":"funnel_stage","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/funnel_stage?post=46753"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/coauthors?post=46753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}