{"id":49592,"date":"2021-03-18T11:00:00","date_gmt":"2021-03-18T15:00:00","guid":{"rendered":"https:\/\/live-jc-marketing-site.pantheonsite.io\/?p=49592"},"modified":"2022-11-22T12:42:16","modified_gmt":"2022-11-22T17:42:16","slug":"the-directory-driven-magic-behind-jumpclouds-zero-touch-enrollment","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/the-directory-driven-magic-behind-jumpclouds-zero-touch-enrollment","title":{"rendered":"The Directory-Driven Magic Behind JumpCloud\u2019s Zero-Touch Enrollment"},"content":{"rendered":"\n
This article was also contributed by Jared Cantwell, Chief Architect at JumpCloud<\/em><\/p>\n\n\n\n IT administrators know that procuring and deploying new devices for remote workforces takes additional time and resources, delaying onboarding of new employees and updating existing staff hardware. <\/p>\n\n\n\n In addition, security vulnerabilities and configuration needs for organizations limit how much self-service set up and installation is allowed and feasible for end users.<\/p>\n\n\n\n By integrating with Apple Business Manager<\/a> (formerly known as Apple DEP) in JumpCloud\u2019s Directory Platform, IT admins gain streamlined Zero-Touch Enrollment for Macs<\/a> alongside powerful tools for enabling the configuration of the device, management of the user, and securing a new computer without ever having to touch the hardware themselves.<\/p>\n\n\n\n In this article we\u2019ll dive deeper into the specifics of setting up your zero-touch enrollment processes, and give you a feel for what\u2019s happening behind the scenes.<\/p>\n\n\n\n IT admins can automate MDM enrollment and device deployment by leveraging Apple Business Manager with JumpCloud MDM<\/a> for Mac computers and workstations. <\/p>\n\n\n\n Using this process, Macs can be set up and configured automatically upon first bootup \u2014 eliminating the need for IT admins to handle each device individually prior to sending it to the employee who will eventually use it.<\/p>\n\n\n\n IT admins are no longer required to image a computer, bind it to the directory, and then allow users to login. When an employee receives a new laptop, all of the provisioning that needs to happen for them occurs at the first system login. <\/p>\n\n\n\n Simply put: zero-touch is a hands-off, scalable model that streamlines device and user onboarding for organizations.<\/strong><\/p>\n\n\n\n Using JumpCloud MDM with Apple Business Manager allows IT admins to selectively enable Zero-Touch Enrollment for an organization. The following steps detail the configuration process:<\/p>\n\n\n\n After completing a device purchase with Apple Business Manager, IT admins only need to complete the following steps to ensure enrollment success:<\/p>\n\n\n\n Though not required, it is recommended that admins activate \u201cForce Password Change\u201d on user login for increased security. This requires employees to select their own password directly in the device setup process and eliminates concerns about new employees missing that step.<\/p>\n\n\n\n When the user receives the new device, the process of setup and configuration is simple and straightforward. The steps include:<\/p>\n\n\n\n A new user just needs to follow the (likely familiar) steps to configure the device based on the options selected in the Setup Assistant Settings<\/em> of the Zero-Touch configuration above. The only prerequisite for the end user is an internet connection; this must be enabled and connected in order for the device to complete the Zero-Touch Enrollment.<\/p>\n\n\n\n The following steps describe what the user will step through during the process:<\/p>\n\n\n\n Once the device is synced into JumpCloud MDM, the device opens a web browser on first boot during the Aut<\/a>omated Device Enrollment<\/a>. This web browser will connect to JumpCloud\u2019s servers to fetch a Welcome Screen that is customizable by the administrator.<\/p>\n\n\n\n Once the user clicks \u2018continue,\u2019 the browser redirects to JumpCloud\u2019s authentication page. The Zero-Touch Enrollment flow only supports password authentication, but combined with forced password changes<\/em> the admin can ensure that a temporary password is changed before the device is even fully configured. <\/p>\n\n\n\n All of this leverages the existing JumpCloud user authentication process so the experience will look familiar to end users.<\/p>\n\n\n\n After successful authentication, the browser securely transfers the user\u2019s identity to JumpCloud\u2019s MDM servers to complete the enrollment process. A success screen is displayed letting the user know that authentication was successful and what to expect next.<\/p>\n\n\n\n Next, Apple\u2019s MDM enrollment process takes over. JumpCloud returns an Enrollment Profile with the user\u2019s identity securely embedded, so that when the device contacts our MDM servers we can associate this MDM device with the user that authenticated.<\/p>\n\n\n\n During Zero-Touch Enrollment, JumpCloud leverages DEP Profile configurations<\/a> that allow us to pause the enrollment and securely configure the device before the enrollment completes:<\/p>\n\n\n\n Once the agent has been installed, it checks in with the JumpCloud servers and retrieves the list of users and policies that it should apply to the device. After completing this work, the agent signals<\/a> that the enrollment can continue now that the user is properly configured and the device is being monitored by the JumpCloud agent.<\/p>\n\n\n\n Next, the user sees a login screen where they can use their JumpCloud credentials to login.<\/p>\n\n\n\n At this point, with no administrator intervention, the device is enrolled and securely configured, the user\u2019s password is secure, the JumpCloud agent is managing the user on that device, and the JumpCloud Mac App is installed for secure password management.<\/p>\n\n\n\n Zero-Touch Enrollment in the JumpCloud Directory Platform will help you remotely onboard and manage Mac devices<\/a> and give the device user access to authorized resources without you ever physically touching the machine first.<\/p>\n\n\n\n Unlike other solutions, JumpCloud gives you one place to control Apple MDM<\/a>, identity management, and any Windows or Linux devices in your fleet so you can reduce your vendor footprint. The choice is yours.<\/p>\n\n\n\nWhat is Zero-Touch Enrollment?<\/h2>\n\n\n\n
Configuring of Zero-Touch with JumpCloud<\/h2>\n\n\n\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
Zero-Touch Enrollment From IT\u2019s Perspective<\/h2>\n\n\n\n
Zero-Touch Enrollment From the End User\u2019s Perspective<\/h2>\n\n\n\n
Welcome Screen<\/h3>\n\n\n\n
<\/figure>\n\n\n\n
Authentication<\/h3>\n\n\n\n
<\/figure>\n\n\n\n
Enrollment and Device Setup<\/h3>\n\n\n\n
Login<\/h3>\n\n\n\n
<\/figure>\n\n\n\n
Try Zero-Touch Enrollment for Free <\/h2>\n\n\n\n