Self-setup up your new Apple device (MacBook/iMac):

Summary

Step by step instructions for users to self set-up a new Apple device using JAMF connect.

Body

Objective

For macOS devices deployed via Jamf, a default PreStage enrollment has been configured to provide a consistent, automated workflow for all NU endpoints. This zero-touch, user-driven deployment process supports standard single-user macOS devices without requiring assignment to a specific Apple School Manager (ASM) location or individual Jamf PreStage.

This article will provide instructions for navigating through the PreStage Enrollment process as part of initial setup for the device.

Users

  • Workstation Support Technicians
  • Staff
  • Students given a university managed macOS device

Before You Begin

  • The device should be unopened in front of you.
  • Your Workstation Support Technician should have verified the device is in the correct enrollment profile before handing it over to you.  If you think your technician has not verified this, please reach out to your Help Desk for assistance.

Key Features

  • OS Updates During Setup Assistant
    • The PreStage uses the “Minimum required macOS version” setting to enforce the latest compatible macOS version during setup.
  • Device Naming Site Assignment
    • ​​​​​​​During setup, you will assign a name to the device. Based on the naming prefix, JAMF Pro automatically assigns the device to the correct support group/site.
  • Risk Classification Assignment
    • ​​​​​​​You will select a risk classification (Low, Medium, or High) during setup. This immediately enables the appropriate compliance controls upon login.
  • Baseline Application Deployment
    • ​​​​​​​Productivity and security applications are installed during macOS Setup Manager, allowing for faster compliance and readiness upon first login.
  • Local User Account Creation and JAMF Connect
    • ​​​​​​​You will create a local macOS account during Setup Assistant, becoming the Secure Token holder. JAMF Connect is automatically installed, allowing you to sync your local password with TrueYou credentials.
  • Automatic Encryption
    • ​​​​​​​FileVault is enabled immediately after your local user account is created, ensuring encryption from the start.

Steps

Once your technician has handed over your device, you may open it and power the device on. Follow these steps to set up your device. The screenshots given below will depict an example device being enrolled into UNL Athletics - Computing Services.

  1. Connect the device to a power source and a reliable network.
    • A wired connection is recommended but not required.
  2. Proceed through the Remote Management screen.
    • This begins enrollment using Automated Device EnrollmentJamf splash screen noting that remote management for the device is required and will set up applications, accounts, and apply settings.
  3. Accept the University of Nebraska Privacy and Security Notice and Sign In.
    • You will sign in with your TrueYou credentials.
      • NUID and TrueYou password
    • This information is linked to your record in Jamf and used later during account creation.Screenshot of University of Nebraska's TrueYou logon screen
  4. Set the device name.
    • This determines the Jamf site assignment based on naming prefix.
    • Your prefix is tied to your department.
      • Select your campus (Lincoln)
      • Select your organization (Athletics)
      • Select your department (Computing Services)
    • This will create your prefix, which makes up the first five characters of your device name.
    • The second half of your device name is part of your serial number
    • Your device should say that it has been placed in ATH-UNL if you have named it correctlyA Jamf dialog box to select the campus where the device will be located to apply a specific prefix to the computer name.
    • This configuration helps your technician identify which department the machine belongs to, and what exact machine it is.
  5. Select a risk classification
    • ​​​​​​​Shared Machines or Student Machines are LOW
    • Most staff are MEDIUM
    • Devices that require access to special servers or devices that store sensitive information should be set to HIGH.A Jamf dialog box with a dropdown to select the computer's expected data risk classification.
  1. Wait for baseline applications to install.
    • This occurs automatically during Jamf Setup Manager
    • This will automatically go through setting up device security and installing required applications.A Jamf dialog box allowing the end user to view which baseline software is added to the device.
  2. Create your local user account.
    • ​​​​​​​​​​​​​​​​​​​​​Your account will be the Secure Token holder and FileVault-enabled administrator.A Jamf dialog box prompting the user to set up a computer account that will be used to access the device.

Details

Details

Article ID: 697
Created
Fri 8/21/26 1:15 PM
Modified
Wed 8/26/26 9:02 AM