Configure Profiles in JAMF Pro

To create configuration profiles in JAMF Pro, complete the following steps:

  1. Log in to the JAMF Pro dashboard.

  2. In the left navigation pane, click DevicesConfiguration Profiles > New.

    The New Mobile Device Configuration Profile page is displayed.

  3. In the General page, configure the following parameters:

    • Name—Enter a name for the profile.

    • Description—Add a description for the profile.

    • Level—Select Device Level.

    • Distribution Method—Select Install Automatically.

  4. Under Options select Certificate.

  5. In the Configure Certificate pop-up, click Configure to add certificates to the configuration profile.

    The Certificate page is displayed.

  6. In the Certificate page, configure the following parameters:

    • Certificate Name—Enter a name for the certificate.

    • Select Certificate Option—Select Upload.

  7. In the pop-up, click Upload Certificate and click Choose File to select the downloaded JAMF Pro certificate. For more information, see Configure Profiles in JAMF Pro.

    The certificate is uploaded and is listed in the Certificate page.

  8. Under Options select SCEP and click Configure.

  9. In the SCEP configuration page, configure the following parameters:

    • SCEP Authority Type—Select Manual configuration.

    • SCEP URL—Paste the SCEP URL copied from the UEM instance.

    • Name—Enter a name for the SCEP configuration.

    • Redistribute Profile—Select Never.

    • Subject—Enter the subject as required by your CA/UEM.

    • Subject Alternative Name Type—Select Uniform Resource Identifier.

    • Subject Alternative Name Value—Enter the URI value.

    • NT Principal Name—Enter username.

    • Challenge Type—Select Dynamic.

    • Use as Signature and Use for Key Encipherment—Enable these two options.

  10. Click Upload Certificate and upload the same JAMF Pro certificate file similar to step 7.

  11. Click Save.

    The SCEP payload is configured and saved.

  12. Under Options select Wi-Fi and click Configure to configure the Wi-Fi Network Profile.

  13. In the Wi-Fi configuration page, configure the following parameters:

    • Service Set Identifier—Enter the Wi-Fi network name and enable Auto-Join.

    • Security Type—Select WPA2 Enterprise.

    • Accepted EAP Types—Select TLS.

    • Identity Certificate—Select the SCEP server certificate.

    • Switch to the Trust tab and select the trusted certificate.

  14. Click Save.

    The Wi-Fi network profile is configured.

  15. To set up a wired network, in the left navigation pane, click the Computers icon.

  16. Under Content Management > Configuration Profiles > New.

    The New macOS Configuration Profile page is displayed.

  17. Under Options navigate to the Network tab and click Configure in the Configure Network section.

    The Network configuration page is displayed.

  18. In the Network Interface drop-down, select First active ethernet.

  19. Under Network Security Settings, configure the following parameters:

    Protocols

    • Accepted EAP Types—Select TLS.

    • Identity Certificate—Select the certificate for connecting to the network.

    • Accepted EAP Types—Select TLS.

    • Identity Certificate—Select the SCEP server certificate. In the

    • Switch to the Trust tab and

    In the Trust tab, select the trusted certificate under Identity Certificate.

  20. Click Save.

    The wired network profile is configured.

  21. Navigate to the Scope tab of the profile.

  22. Under Targets, choose Specific Mobile Devices and Specific Users.

  23. Click Add, select specific devices and/or users you want to include, then click Add to confirm.

  24. Click Save to create and deploy the profile.

    The configuration profile is created and deployed and the device will connect to the network.