We have just started with DEP in our enterprise.
A user-initiated enrollment has been configured :
We have set an prestage enrollment with a few options (directory, account settings…).
When we run the setup assistance DEP on scoped computer, this computer does not enroll. But we can see it in inventory with the name « DEP - Serial Number ». I probably forget something…
We have tested in 10.10.5 and it's works, but not in 10.12.5.
Our JSS is in 9.97.
Have you met same issue ?
Many thanks for your support,
Solved! Go to Solution.
@yduche I would try another Prestage without setting up anything I've circled red. Prestage with account payloads has been an issue. It's really a hit or miss. I would create an Enrollment Complete policy which lays down everything else. If that works and the machine enrolls, the binary is installed and everything is working. I would then reach out to your TAM to see if they could get the Prestage to work 100% of the time with you account Payload.
We had this issue at my place as well, and it turned out to be a cert issue. I use Require Authentication for all DEP enrollments, no issue. Our JAMF buddy asked to drop the 3rd party cert and use build in JAMF certs. The issue was resolved at that point. I'd check to make sure your certs are good for all systems related to JAMF and Apple DEP.
We had a few issues with our migration to DEP over netboot imaging. Specifically, when I set up a PreStage Enrollment and added anything (a tech admin account to be more specific) under the "Account Settings" the enrollment would only work sporadically. If the computer was not deleted from the JSS, then it would update with a new name (Ex. "DEP-XXXXXXXX") Once I removed the items from "Account Settings", my prestage worked perfectly.
They way i confirmed was to set up a DEP Prestage with only setting put in the "General Tab". As i moved down the list, i found that adding an account...or using the "Account settings" section to demote users to a standard account was the issue.