3 weeks ago
Hello everyone, I hope you are well and can answer my questions.
We are currently on-boarding a new client and they are using MaaS360 at the moment with another MSP. I have everything just about finished up in JAMF, except Auto-Enrollment which requires connecting to the Apple Business Manager Server. Once I do, that is usually what bring in the devices (If I remember correctly). If the devices are currently already setup with a MDM profile on them with another MDM service provider, would that be interfered with if I would setup the connection between ABM and JAMF?
I am wanting to make this transition seamless and have zero down time as the customer works 24/7 and needs access to these devices.
I have only done setup of new users to JAMF and not migrated from another MDM Provider. Any insight would be helpful.
My Plan was to have the users setup and tie that to Groups and profiles so that when he sees the users account it downloads the appropriate profile and adds MDM automatically. Trying to keep this Zero touch on our end.
Solved! Go to Solution.
3 weeks ago
Moving computers and devices in Apple Business Manager from one MDM to another won't affect currently enrolled computers and devices. The change to the new MDM only happens during Automated Device Enrollment.
You might consider reaching out to Jamf to ask about their service for migrating computers and devices. They'll provide you the tools you need, they have experience with many vendors, and they know a lot of the issues you may encounter during the migration.
3 weeks ago
Moving computers and devices in Apple Business Manager from one MDM to another won't affect currently enrolled computers and devices. The change to the new MDM only happens during Automated Device Enrollment.
You might consider reaching out to Jamf to ask about their service for migrating computers and devices. They'll provide you the tools you need, they have experience with many vendors, and they know a lot of the issues you may encounter during the migration.
3 weeks ago
I will reach out to JAMF and see what they can offer. I have built a plan already, but if there are tools that can make this even smoother I will absolutely utilize it. Thank you for your quick response.
3 weeks ago - last edited 3 weeks ago
There is no such thing a truly 0-touch MDM enrollment, it is unfortunately just a sales pitch unless you are moving from Jamf Pro instance to another Jamf Pro instance. Someone is having heavy touch on the device, either it's your IT department or the user.
The 0-touch migration service Jamf advertises is from a Jamf Pro server to another Jamf Pro server. Basically what happens is Jamf will get a copy of your database, then Jamf imports that database in to the new Jamf instance. This effectively makes the new Jamf instance a copy of the old Jamf instance. Then you need to add a C-Name redirect which tells devices to talk to the new Jamf server, and effectively tricks devices in to thinking this is the old server so they talk to it normally. Since you are using Maas365, migrating the database is not possible, so you will need to release and re-enroll devices. Ideally the enrollment happens with Automated Device Enrollment which will be mostly hands off for IT but is a OS reinstall. The other option of Device Enrollment (note the lack of automated) which would require someone to manually enroll every single device. Apple makes migrating MDMs very difficult.
https://it-training.apple.com/tutorials/apt-deployment/#understanding-device-and-user-enrollment