Migrating to DEP Workflows from Imaging Workflows

matthew_johnson
New Contributor II

I have my Jamf Pro, Apple DEP, and Apple VPP all setup and working. I can find my newly ordered Macs in Jamf Pro (I am on 10.0.0). Our plans at first are going to manually setup the macs by our IT department before handing the machine to the user. Later we will work on getting zero touch with progress windows.

I have a couple of questions:

  1. Why do my configurations in Jamf Admin not show up in Jamf Pro?
  2. Do i use PreStage Enrollment or PreStage Imaging?
  3. How do I achieve "Install on boot drive after Imaging"?
  4. Do all my software packages get installed with policies with the trigger - "Enrollment Complete"?

Thanks for any help or links.

5 REPLIES 5

bmarks
Contributor II
  1. Jamf Admin configurations are for imaging via the Casper Imaging application (NetBoot, target disk imaging,) i.e. what DEP replaces.
  2. For DEP, you use PreStage Enrollment.
  3. This isn't relevant for DEP. With DEP, you are no longer "imaging" a Mac, you are leaving the OS on it and adding to (or subtracting from) it.
  4. That is one trigger that will work for running policies on a DEP device, but based on the situation it may not be the best option. This will depend on the policy.

robertliebsch
Contributor
  1. I can't tell you why, someone else could. But it is like they are two different beasts.
  2. Prestage Enrollments. Create one, select your DEP instance. Set your scope (assign DEP devices, or set All new, or select all)
  3. I think what you are asking is "what after prestage enrollment?" Create a SmartGroup with Criteria "Enrollment Method: Prestage enrollment is DEP". Then create a Policy scoped to your SmartGroup. Select all your packages, scripts, printers, dock items, whatever. You'll want your trigger to be enrollmentComplete (under Options/General)
  4. only what is assigned in the above policy is installed.

Occasionally. it does misfire. After which I have to reboot with CommandR, delete the drive, and reinstall. I don't think I've any machine fail twice.

jwojda
Valued Contributor II

take a look at splash buddy to help augment your DEP enrollments, lots of good work going on in there. and you can find them in the slack channel #splashbuddy

gachowski
Valued Contributor II

I think the bigger question is why are you doing a"manually setup" ... It sounds like you have most of it covered. I think it would be worth the extra time to get to zero touch...

Once you train the "IT department" how to image/enroll/configure/set up "manually" they are never going to stop and most likely will push back on most of the changes you make.

IMO. : )

C

  1. I would guess that the order of you installs and config makes a difference so most people install the easy software with Enrollment Complete and then run a scrip "after" to install the tricky/complex installs using a "At a custom event" trigger in that script.

matthew_johnson
New Contributor II

Good stuff here. Thanks for the responses.

I am going to try my hand at Splash Buddy and custom events.