Can you setup DEP prestage enrollment groups in different sites?

tcandela
Valued Contributor II

 We have multiple sites so for my site I set up a separate prestage enrollment DEP group and I assigned one test computer to this group.  When would the computer I assign to this group be visible in the group because I do not see it in there Until after the computer Gets enrolled.

  When I do Internet recovery on the test computer install a fresh Monterey it does not hit this computer with DEP it's just basically bypass it and does nothing. It just enrolls it into the site and nothing else.

  I have the DEP install package all set up in the DEP prestage enrollment group. I have the DEP notify script set to run on enrollment.

 Nothing happens, just basically ignores everything.  Does anyone know what might be happening here?

6 REPLIES 6

jtrant
Valued Contributor

Is the Mac assigned to the correct ADE instance in Apple Business Manager? Is the correct ADE instance associated with the new PreStage? Did you wipe the drive and re-install the OS to trigger a DEP enrollment, or at least delete /var/db/.AppleSetupDone and reboot?

What does the following Terminal command return:

 

 

sudo profiles show --type enrollment

 

 

 

 

tcandela
Valued Contributor II

I created my own separate prestige en rollement group and assigned the test computer from the main DEP prestige enrollment group to my enrollment group. I wipe it and do all that stuff from Internet recovery,it just doesn't do anything but enroll in my site.

  I assign this test computer to my prestige enrollment group so shouldn't it Be ready?

 What's this ADE stuff you're talking about?

Hugonaut
Valued Contributor II

ADE is what use to be DEP. Terms are pretty interchangeable, its like referring to Jamf as Casper, it will take a while for us to stop saying DEP lol.

https://support.apple.com/en-us/HT204142

________________
Looking for a Jamf Managed Service Provider? Look no further than Rocketman
________________


Virtual MacAdmins Monthly Meetup - First Friday, Every Month

tcandela
Valued Contributor II

@jtrant I did that sudo show enrollment command, now what?  I see it's tied to my organization but I don't see anything regarding my DEP prestage enrollment group

tcandela
Valued Contributor II

@jtrant @Hugonaut so it's not just that easy to just create a new DEP prestage enrollment group and assign the computer to it by checking its check box and then save it ?

I did all that @jtrant said but these 2 --> Is the Mac assigned to the correct ADE instance in Apple Business Manager? Is the correct ADE instance associated with the new PreStage?

 

tcandela
Valued Contributor II

We have a main DEP prestage enrollment group #1 and I'm setting up a separate DEP prestage enrollment group that is aimed at a specific site #2.

Does anyone have something similar setup?

The enrollment packages (dep notify 1.1.5) assigned to my #2 group does not run. I have enrollment policies setup for #2 and those don't run. #2 is setup to enroll in my site.

What I'm seeing is that when the DEP process runs the test computer gets enrolled into the main  inventory instead of my site, causing the test computer to not get the enrollment policies. After all this is complete the computer ends up in my site #2.

So basically the computer ends up in my site but no policies have been applied.

Anyone have a similar setup that works? If so what's your setup?