Deploy 1,000+ Devices with Jamf Pro Zero-Touch
Zero-touch provisioning changes what a device rollout costs you. Instead of a technician unboxing, imaging, and hand-configuring every machine, a device ships straight to the person who’ll use it and finishes setting itself up on first boot — supervised, secured, and compliant before they’ve signed in. This is exactly how I deployed 1,000+ Macs with Jamf Pro and Apple Business Manager, cutting manual setup time by roughly 40% across a fleet spanning hybrid corporate offices and manufacturing floors.
Key takeaways
Zero-touch works when Apple Business Manager, PreStage enrollment, and the standard build are treated as one system, not three separate projects. Get ABM device assignment right, supervise every device through PreStage, and encode the “standard build” as policy rather than a wiki page — done right, it cuts manual setup time by roughly 40% and turns a replacement into a shipping-time problem instead of a technician-hours problem.
What you need before starting
An active Jamf Pro instance, an Apple Business Manager account, and administrator access to both. Devices need to come from an Apple Authorized Reseller or Apple directly with your Apple Customer Number attached — that’s what makes them appear in ABM automatically. Anything bought outside that channel has to be added to Automated Device Enrollment manually through Apple Configurator, which works but adds a step you want to avoid at volume.
Step 1: Link Apple Business Manager to Jamf Pro
In ABM, create an MDM server entry and download its token. In Jamf Pro, upload that token under Global Management → PreStage Enrollments, and set Jamf as the default MDM server so every new device lands there without manual claiming. Two dates go on a calendar the moment this is live: the MDM server token expires yearly, and the Apple Push Notification certificate (a separate portal, separate expiry) is also annual. Let either lapse and enrollment stops working for every Apple device in the fleet — this is the single most common cause of a zero-touch pipeline quietly breaking.
Step 2: Build the PreStage Enrollment
The PreStage is what makes a device configure itself. Set it to supervised and non-removable MDM so the enrollment can’t be undone by the end user, and use enrollment customization to skip the Setup Assistant panes that generate support tickets — Apple ID sign-in, Siri, Screen Time, the privacy walls of text. Assign a management account, and if you want a branded first-boot screen, this is where it’s configured. A device that reaches PreStage but never appears in Jamf almost always traces back to an ABM assignment problem, not a PreStage misconfiguration — check the source before debugging the destination.
Step 3: Build the configuration profiles and Smart Groups
This is where the “standard build” stops being a wiki page and becomes something enforced. Security baseline profiles for FileVault (with escrow — a device that encrypts without a recoverable key isn’t actually secured), password policy, and screen lock; software deployment policies for the core app set; and Smart Groups that scope all of it dynamically by department, location, or compliance state rather than by manually maintained lists. Smart Group membership updates with every inventory check-in, so once this is built correctly, new devices fall into the right scope automatically — you stop maintaining assignment lists by hand.
Step 4: Pilot before you trust it
Five to ten devices, not your whole fleet. Confirm enrollment completes cleanly, every profile applies without a conflict, every app installs and actually launches, and the device passes your compliance check the moment it’s usable. If you’re feeding Jamf compliance into Conditional Access, this is also where you confirm a freshly enrolled device reaches compliant status fast enough that a new hire isn’t locked out of email on day one — a gap between “enrolled” and “compliant” is the most common pilot surprise.
Step 5: Deploy at scale
With the pilot clean, the rollout is mostly a procurement conversation: every future purchase goes through the linked reseller so devices auto-populate PreStage with zero manual work. For devices already in the field that need to join the pipeline, a wipe-and-re-enroll through the Jamf enrollment URL brings them in under the same PreStage. Roll out in rings — IT first, a friendly department next, then everyone — so a problem shows up on ten devices before it shows up on a thousand.
Results
Across 1,000+ devices: roughly a 40% reduction in manual setup time per machine, configuration drift that used to come from manual setup essentially disappeared because the build is now enforced policy, and device replacement or RMA turnaround dropped to the shipping time plus a first boot — no imaging bench involved. The support team’s device-refresh workload dropped correspondingly, because there’s nothing to refresh by hand.
Bottom line
The MDM configuration is the easy part of zero-touch. What actually determines whether it works is the layer underneath — ABM assignment, the two annual tokens you can’t let expire, and the discipline of moving every “we always configure this by hand” step into a Smart Group or policy. Get that right once, and every device after it configures itself.