Automatic Device Enrollment (ADE) lets Apple devices be automatically enrolled into your JumpCloud-managed MDM environment when they are powered on and connected to the internet, as long as the device has been assigned in Apple Business Manager (ABM). This guide walks you through the configuration steps in JumpCloud to support ADE, including uploading certificates, configuring profiles, and validating enrollment.
before you begin, make sure the following are in place:
An active JumpCloud account with Administrator permissions to configure ADE.
Apple Business Manager account with Administrator permissions.
A valid Apple Push Notification service (APNs) certificate (or the ability to obtain one via CSR).
Log in to the JumpCloud Admin Portal: https://console.jumpcloud.com.
Go to DEVICE MANAGEMENT > MDM.
On the MDM home page, click get started under Automated Device Enrollment Configuration.
On the Set Up Apple’s Automated Device Enrollment page, download the token.
login to business.apple.com
Select your profile name, then select Preferences.
Select +add button on Device Management Services section .
Enter a name for your company’s MDM server and leave Allow this MDM Server to release devices selected.
Click Choose File.
then upload the token file that you previously downloaded from Jumpcloud.
Click Save.
Download the token by selecting the server and clicking Download Token, then clicking Download Server Token.
On the Set Up Apple’s Automated Device Enrollment page, upload a token file that you previously downloaded from ABM.
Click Complete Setup.
Select your profile name, then click Preferences.
Navigate to the Management Assignment section.
Click Edit under Default Assignment.
In the Mac section, select the MDM server you configured previously.
This step enables automatic assignment of new Mac devices to the JumpCloud MDM server.