Posted on 03-25-2025 06:29 AM
Hello,
We're working to put together new device personas (engineering, creative, etc), and all have been going well, except for our "lab" devices. Basically, they want a clean macOS device to use for testing, but it should still be enrolled in Jamf for asset tracking purchases.
All the other devices, I've just added a trigger after enrollment for special_installs, and scoped/limited them by appropriate AD group. But for the clean devices, I need them to stop the normal enrollment process entirely. No config profiles (outside of the jamf required ones) and no software installed.
I'd normally add them to an exclusion group, but I can't think of a way to do that automagically prior to enrollment...
Posted on 03-25-2025 07:57 AM
Perhaps by simply making a second Service for the lab computers which will allow them to be reset at will or by using SetupManager and setting configurations based on user entry.
Posted on 03-25-2025 07:58 AM
Second Prestage, sorry.
Posted on 03-26-2025 02:33 AM
Conceptually having an unmanaged device, in device management doesn't work... I think there is a danger in not defining a reasonable usecase. Why does the device need to be "clean", for the most part, minimal base config/application install will not interact with application development, especially as the application should have sandboxing.
Posted on 03-26-2025 06:41 AM
It's not for development, it's for virus lab testing.
also base application install uses M$oft licenses that we otherwise wouldn't need.
Posted on 03-26-2025 02:43 AM
Make a smart group, use the Serial number as the criteria. Use that group as your exclusion group.
Serial numbers for me are listed on the paperwork when we purchase, in Apple School Manager, as well as on the box. And for existing devices it will be on a plate somewhere under the Mac.