I have an attribute for "In Storage" that I have configured in all of our policies to not use. I was thinking it could be helpful for this to be set automatically to "Yes" during enrollment so nothing runs on the device in Jamf. We have several different static groups that get different configurations so ideally nothing would happen to a device until we assign it a group. There are some things that ALMOST everything gets that isn't scoped to specific groups but we would prefer these get paused until after we set which group it should be in. If there is a better way to accomplish what we are trying to do please let me know!
Extended Attribute at Enrollment
Best answer by sdagley
@rhowell The manual adding of a device to an "Is Deployed" static group which is required to enable your "almost everything" polices would definitely work. And not to throw another option out late in the conversation, but another approach if all the devices you're talking about are Macs you could have a "fingerprint" file created somewhere in a persistent area the file system at the end of your enrollment script, a corresponding Extension Attribute which checks for the presence of that file, and a Smart Group whose criteria is the file does not exist. Then use that Smart Group as an exclusion for your "almost everything" policies.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
