Fore-warning, the answer below is from Jamf’s AI assistant… But my read through feels like it’s pretty accurate to my understanding of BYOD enrollment and Jamf School syncing with ASM.
FWIW, we are 100% school owned devices, SIS uploaded to ASM for Managed Apple Accounts syncing one-way to Jamf School and using on-device enrollment.
****************************
How User Enrollment Works for BYOD iPads
User Enrollment uses a student’s Managed Apple Account (from ASM) as the authentication mechanism. When a student enrolls their own iPad, they sign in with their Managed Apple Account — and Jamf School automatically links the device to that user record.
The enrollment process from the student’s perspective is straightforward:
- Open Safari on their iPad and navigate to your school's enrolment URL
- Enter the Network ID and Location Code (provided by school)
- They enter their Managed Apple Account
- Tap Enroll and follow the prompts to install the profile
- They sign in with their Managed Apple Account password to complete enrollment
At the end of this process, the device is enrolled in Jamf School and automatically associated with that pupil's user account — no manual linking required.
Important Considerations for Jamf Student
User Enrollment — What to Expect
Automatic user association via Managed Apple Account
Device is linked to the student's ASM user record at enrollment
Jamf Student app can be used
Student user accounts with login credentials are required
Device remains unsupervised
Limits some restrictions and payloads compared to supervised devices
MDM profile can be removable by the student
Students can unenroll their own device from Settings
Personal data is protected
Only school/institutional data is managed; personal data is untouched on unenrlolment
Jamf Student Requirement
For Jamf Student to work fully, students need student user accounts with login credentials assigned to a student User group in Jamf School.
What You'll Need to Set Up
- Provide pupils with the enrolment URL, Network ID, and Location Code — found in Jamf School under Devices > Enrol Device(s) > On-device enrolment (iOS & macOS)
- Ensure pupils know their Managed Apple Account credentials — these come from ASM, so if you use federated authentication (e.g., with Microsoft or Google), they may already use these daily
- Assign pupils to user groups and classes in Jamf School so that Jamf Student can reflect the correct class structure
- Configure Jamf Student settings under Organisation > Settings > Jamf School Student
Tip: Consider creating a simple one-page guide for pupils to follow when they arrive in August. The enrolment steps are short, but having clear instructions will save a lot of time on the day.
The main trade-off to be aware of is that because these are personally owned, unsupervised devices, some of the more restrictive management capabilities won't be available — but for the purpose of running Jamf Student in a classroom, User Enrollment provides everything you need.
****************************
Here’s a list of the sources that the AI gleaned the above from:
Jamf Product Documentation
Jamf Knowledge Base Articles