Automated Device Enrollment from Apple Business Manager to a compliant, self-service Mac — and macOS folded into the same Conditional Access posture as Windows.
Windows had Intune. The Macs didn't have an equivalent. They were set up by hand, configured inconsistently, and — most importantly — sent no compliance signal to Entra ID, so they sat outside the Conditional Access posture every Windows device had to meet. As the Mac footprint grew, “managed by hand” stopped being viable.
The target was a Mac that unboxes into a fully configured, compliant, app-ready state with no admin involvement — the macOS mirror of Autopilot. I wired Apple Business Manager to Jamf Pro for Automated Device Enrollment, then built the enrollment as a single pipeline:
Scoping is driven by Smart Groups rather than manual assignment, so a device gets exactly the profiles and apps its state calls for. FileVault is enforced with recovery keys escrowed to Jamf, and app delivery runs through VPP and packages so licensed software installs without a person in the loop.
A new Mac now goes from sealed box to compliant, app-ready, and enrolled with no admin touch — the same zero-touch experience Windows already had. Configuration is consistent because it's policy, not memory. And because Jamf feeds compliance back to Entra, Macs are inside the same Conditional Access boundary as every other device, closing the gap that used to make them the exception.
I'm open to Principal Cloud / EUC Architect conversations, and to work at organizations building things that matter — infrastructure, security, or the mission itself.