Skip to main content
Question

Re-enroll Mac in JSS

  • August 8, 2016
  • 27 replies
  • 359 views

Show first post

27 replies

ega
Forum|alt.badge.img+17
  • Valued Contributor
  • July 24, 2019

If the device still has the jamf binary and framework I have had good success using jamf reenroll -prompt
Will prompt for JSS login and ssh login but works with JSS credentials for both, at least on my cloud deployment.


Forum|alt.badge.img+31
  • Honored Contributor
  • July 25, 2019

@jameson

The main difference is how the full chain of trust is established. OTA enrollment, you download a cert (root CA) that is signed by your jamf pro instance (self signed) and you must install it first to establish trust. Once that is established, you then get the MDM profile, which uses that chain of trust to enroll the device. This is designed to do user approved MDM

If you are doing DEP to the cloud, jamf has public certs, which are pre-trusted by Amazon. DEP enrollments are automatically user approved MDM

they are technically different methods. If I am wrong, someone please correct me.