Body
Objective
For macOS devices deployed via Jamf, a default PreStage enrollment has been configured to provide a consistent, automated workflow for all NU endpoints. This zero-touch, user-driven deployment process supports standard single-user macOS devices without requiring assignment to a specific Apple School Manager (ASM) location or individual Jamf PreStage.
This article will provide instructions for navigating through the PreStage Enrollment process as part of initial setup for the device.
Users
- Workstation Support Technicians
- Staff
- Students given a university managed macOS device
Before You Begin
- The device should be unopened in front of you.
- Your Workstation Support Technician should have verified the device is in the correct enrollment profile before handing it over to you. If you think your technician has not verified this, please reach out to your Help Desk for assistance.
Key Features
- OS Updates During Setup Assistant
- The PreStage uses the “Minimum required macOS version” setting to enforce the latest compatible macOS version during setup.
- Device Naming Site Assignment
- During setup, you will assign a name to the device. Based on the naming prefix, JAMF Pro automatically assigns the device to the correct support group/site.
- Risk Classification Assignment
- You will select a risk classification (Low, Medium, or High) during setup. This immediately enables the appropriate compliance controls upon login.
- Baseline Application Deployment
- Productivity and security applications are installed during macOS Setup Manager, allowing for faster compliance and readiness upon first login.
- Local User Account Creation and JAMF Connect
- You will create a local macOS account during Setup Assistant, becoming the Secure Token holder. JAMF Connect is automatically installed, allowing you to sync your local password with TrueYou credentials.
- Automatic Encryption
- FileVault is enabled immediately after your local user account is created, ensuring encryption from the start.
Steps
Once your technician has handed over your device, you may open it and power the device on. Follow these steps to set up your device. The screenshots given below will depict an example device being enrolled into UNL Athletics - Computing Services.
- Connect the device to a power source and a reliable network.
- A wired connection is recommended but not required.
- Proceed through the Remote Management screen.
- This begins enrollment using Automated Device Enrollment

- Accept the University of Nebraska Privacy and Security Notice and Sign In.
- You will sign in with your TrueYou credentials.
- NUID and TrueYou password
- This information is linked to your record in Jamf and used later during account creation.

- Set the device name.
- This determines the Jamf site assignment based on naming prefix.
- Your prefix is tied to your department.
- Select your campus (Lincoln)
- Select your organization (Athletics)
- Select your department (Computing Services)
- This will create your prefix, which makes up the first five characters of your device name.
- The second half of your device name is part of your serial number
- Your device should say that it has been placed in ATH-UNL if you have named it correctly

- This configuration helps your technician identify which department the machine belongs to, and what exact machine it is.
- Select a risk classification
- Shared Machines or Student Machines are LOW
- Most staff are MEDIUM
- Devices that require access to special servers or devices that store sensitive information should be set to HIGH.

- Wait for baseline applications to install.
- This occurs automatically during Jamf Setup Manager
- This will automatically go through setting up device security and installing required applications.

- Create your local user account.
- Your account will be the Secure Token holder and FileVault-enabled administrator.
