{"id":115479,"date":"2024-10-30T16:31:50","date_gmt":"2024-10-30T20:31:50","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=115479"},"modified":"2025-02-07T10:00:20","modified_gmt":"2025-02-07T15:00:20","slug":"configure-account-driven-enrollment","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/configure-account-driven-enrollment","title":{"rendered":"Configure Account-Driven Enrollment"},"content":{"rendered":"\n
This article explains how to enable and configure account-driven user enrollment within the 探花大神 Admin Portal. You must configure enrollment before users are able to enroll their iOS and iPadOS devices to be managed by your organization.<\/p>\n\n\n\n
Account-driven enrollment is the preferred method for enrolling Apple iOS\/iPadOS devices into 探花大神 MDM. With this method, end users can enroll their devices directly by using a Managed Apple Account provided by your organization instead of downloading a profile from an external link or scanning of a QR code in the 探花大神 User Portal.<\/p>\n\n\n\n
<\/p><\/div>
This process must be used for all devices running iOS\/iPadOS 18 or later. Profile-based user enrollment, where the user downloads a configuration profile onto their device, will fail for personal device enrollments on devices running iOS\/iPadOS 18 or later.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Considerations<\/strong>:<\/p>\n\n\n\n Prerequisites<\/strong>:<\/p>\n\n\n\n First, create Managed Apple Accounts either through federated authentication between Apple and your identity provider (Google Workspace, Microsoft Entra ID, or other)*, or manually in Apple Business Manager or Apple School Manager.<\/p>\n\n\n\n *Federation between Apple and 探花大神 is in active development.<\/p>\n\n\n\n Reference the following Apple documentation on creating Managed Apple Accounts:<\/p>\n\n\n\n After the Managed Apple Accounts are created, they need to be associated with 探花大神 user accounts. See Run the MAID Import Script<\/a> for instructions.<\/p>\n\n\n\n Next, set up a well-known URL on your domain. Depending on the method you choose, you will host an enrollment file at this URL directly or you will place a redirect from this URL to the 探花大神 service discovery URL.<\/p>\n\n\n\n Prerequisites<\/strong>:<\/p>\n\n\n\n On your web server, implement the following well-known URL for MDM service discovery, replacing Next, configure the redirect from this URL or host a file at this URL.<\/p>\n\n\n\n To configure account-driven user enrollment using a redirect:<\/strong><\/p>\n\n\n\n The steps to configure the redirect will look different depending on your solution. Below are resources for placing a redirect with popular web servers:<\/p>\n\n\n\n See Cloudflare’s Create rule in the dashboard<\/a> for more information on this process.<\/p>\n\n\n\n To set up a redirect using Cloudflare Rules<\/strong>:<\/p>\n\n\n\n Once the redirect rule is active, any requests to the specified path will be redirected to the specified URL. It may take some time for the rule to take effect due to Cloudflare’s caching.<\/p>\n\n\n\n See Shopify’s Creating and managing URL redirects<\/a> for more information on this process.<\/p>\n\n\n\n To set up a URL redirect in Shopify<\/strong>:<\/p>\n\n\n\n See Squarespace’s URL mappings documentation<\/a> for more information on this process.<\/p>\n\n\n\n To set up a URL redirect in Squarespace<\/strong>:<\/p>\n\n\n\n Although a self-hosted file is less flexible than a Redirect, it may be useful if you do not have access to your web server configuration. <\/p>\n\n\n\n For more information about the service discovery process, see Apple\u2019s Discover Authentication Servers<\/a> from the Apple Developer website.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n To configure account-driven user enrollment using a self-hosted file:<\/strong><\/p>\n\n\n\n To host the 探花大神 enrollment information on a web server, you must define the path to your web server. If the verified domain you use for Managed Apple Accounts is already configured to host files, you can host the enrollment information at the same hosting location. If your environment is not configured to do so, you must set up a web server to host the information.<\/p>\n\n\n\n 探花大神 recommends consulting your internal web services and hosting team to help you complete this task.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Prerequisites<\/strong>:<\/p>\n\n\n\n The resulting URL for the file must be similar to the following, where Configure the server to return the appropriate Content-Type<\/strong> header with the file, as follows: Your server software may refer to Content-Type as “MIME type.”<\/p>\n\n\n\n For more information about how to modify the MIME type, see the following documentation:<\/p>\n\n\n\n To test your configuration<\/strong>:<\/p>\n\n\n\n After ADUE has been configured in the Admin Portal, users can follow the steps to enroll their devices (iOS 15+). See Users: Enroll Your Personal iOS Device<\/a>.<\/p>\n\n\n\n In order for users to enroll their devices, you must select the option to Allow users to enroll personal mobile devices and access Enroll Your iOS Device in the User Portal<\/strong>.<\/p>\n\n\n\n This article explains how to enable and configure account-driven user enrollment within the 探花大神 Admin Portal. You must configure enrollment […]<\/p>\n","protected":false},"author":206,"featured_media":0,"template":"","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"support_category":[2925,2852,2995],"support_tag":[],"coauthors":[2842],"acf":[],"yoast_head":"\n\n
\n
\n
Creating Managed Apple Accounts<\/h2>\n\n\n\n
<\/p><\/div>
\n
Setting Up a Well-Known URL<\/h2>\n\n\n\n
\n
yourdomain.com<\/code> with your org’s domain:<\/p>\n\n\n\n
https:\/\/
yourdomain.com\/.well-known\/com.apple.remotemanagement<\/code><\/code><\/p>\n\n\n\n
Configuring a Redirect<\/h2>\n\n\n\n
\n
<\/li>\n\n\n\n
\n
https:\/\/yourdomain.com\/.well-known\/com.apple.remotemanagement<\/code><\/li>\n\n\n\n
https:\/\/apple.mdm.jumpcloud.com\/account-driven-service-discovery?organization_id=XXXXXXXXXXXXXXX<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
\n
Configuring a Redirect in Cloudflare<\/h3>\n\n\n\n
\n
https:\/\/example-domain.com\/.well-known\/com.apple.remotemanagement*<\/code> where
example-domain.com<\/code> is your root domain. Remember to include the asterisk after com.apple.remotemanagement.<\/li>\n\n\n\n
https:\/\/apple.mdm.jumpcloud.com\/account-driven-service-discovery?organization_id=XXXXXXXXXXXXXXXXXXXXX<\/code> where XXXXXXXXXXXXXXXXXXXXX is replaced with your 探花大神 Organization ID.<\/li>\n\n\n\n
Configuring a Redirect in Shopify<\/h3>\n\n\n\n
\n
\/.well-known\/com.apple.remotemanagement<\/code><\/li>\n\n\n\n
https:\/\/apple.mdm.jumpcloud.com\/account-driven-service-discovery?organization_id=XXXXXXXXXXXXXXXXXXXXX <\/code>where
XXXXXXXXXXXXXXXXXXXXX<\/code> is replaced with your 探花大神 Organization ID.<\/li>\n\n\n\n
Configuring a Redirect in Squarespace<\/h3>\n\n\n\n
\n
XXXXXXXXXXXXXXXXXXXXX<\/code> is replaced with your 探花大神 Organization ID.:<\/li>\n<\/ol>\n\n\n\n
\/.well-known\/com.apple.remotemanagement -> https:\/\/apple.mdm.jumpcloud.com\/account-driven-service-discovery?organization_id=XXXXXXXXXXXXXXXXXXXXX 301<\/code><\/p>\n<\/div><\/div>\n\n\n\n
\n
Configuring a Self-Hosted File<\/h2>\n\n\n\n
<\/p><\/div>
\n
<\/li>\n\n\n\n
Setting up a Web Server to Host the File<\/h3>\n\n\n\n
<\/p><\/div>
\n
example_domain.com<\/code> is the same format and domain as the Managed Apple Accounts’ email address:
https:\/\/example_domain.com\/.well-known\/com.apple.remotemanagement<\/code><\/p>\n\n\n\n
Content-Type is ‘application\/json’<\/code><\/p>\n\n\n\n
<\/p><\/div>
\n
Testing the Enrollment Configuration<\/h2>\n\n\n\n
\n
Troubleshooting Error Messages<\/h3>\n\n\n\n
\n
<\/p><\/div>
<\/p>\n <\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"