Andrew Yeoman / Case studies / Jamf deployment
Case study · macOS platform

Zero-touch macOS with Jamf Pro

Automated Device Enrollment from Apple Business Manager to a compliant, self-service Mac — and macOS folded into the same Conditional Access posture as Windows.

Role
Lead engineer
Platform
macOS via Jamf Pro
Approach
ABM zero-touch
Result
Compliant on first boot
The situation

Macs were the unmanaged corner of the estate.

Windows had Intune. The Macs didn't have an equivalent. They were set up by hand, configured inconsistently, and — most importantly — sent no compliance signal to Entra ID, so they sat outside the Conditional Access posture every Windows device had to meet. As the Mac footprint grew, “managed by hand” stopped being viable.

The approach

Zero-touch from purchase to compliant, one pipeline.

The target was a Mac that unboxes into a fully configured, compliant, app-ready state with no admin involvement — the macOS mirror of Autopilot. I wired Apple Business Manager to Jamf Pro for Automated Device Enrollment, then built the enrollment as a single pipeline:

01
Apple Business Manager
Devices land in ABM at purchase and assign to Jamf automatically.
02
PreStage enrollment
Setup Assistant runs the PreStage: account, config, supervision — hands-off.
03
Config profiles
Smart Groups scope Wi-Fi, security, restrictions and FileVault by device state.
04
Self Service
A branded portal lets users install approved apps on demand, no admin rights.
05
Entra compliance
Jamf sends the compliance signal to Entra; Conditional Access gates access.

Scoping is driven by Smart Groups rather than manual assignment, so a device gets exactly the profiles and apps its state calls for. FileVault is enforced with recovery keys escrowed to Jamf, and app delivery runs through VPP and packages so licensed software installs without a person in the loop.

What shipped

A Mac that manages itself — and answers to the same posture as Windows.

  • ABM ↔ Jamf Automated Device Enrollment with PreStage — new Macs enroll and supervise on first boot.
  • A baseline set of configuration profiles (Wi-Fi, security, restrictions) scoped by Smart Groups.
  • FileVault enforced with recovery keys escrowed to Jamf.
  • A Self Service catalog for on-demand, no-admin app installs.
  • App deployment via VPP and packages, license-assigned through ABM.
  • macOS compliance surfaced to Entra ID so Conditional Access covers Macs the same as Windows.
Jamf ProApple Business ManagerPreStage / ADEConfig ProfilesSmart GroupsFileVault escrowVPPEntra ID complianceConditional Access
The outcome

macOS joined the platform instead of living beside it.

A new Mac now goes from sealed box to compliant, app-ready, and enrolled with no admin touch — the same zero-touch experience Windows already had. Configuration is consistent because it's policy, not memory. And because Jamf feeds compliance back to Entra, Macs are inside the same Conditional Access boundary as every other device, closing the gap that used to make them the exception.

Get in touch

Let's talk.

I'm open to Principal Cloud / EUC Architect conversations, and to work at organizations building things that matter — infrastructure, security, or the mission itself.