How To Distribute Shield Network Profiles to Your Devices via Jamf Pro
Overview - How to Distribute Network Profiles to Your Jamf Pro Managed Devices
Jamf Pro is a Mobile Device Management (MDM) platform that allows you to configure and manage your organization’s macOS and iOS devices.
To get your Jamf Pro managed devices connected to your network, you will need to push a Network Profile, which includes the necessary network settings, authentication methods, and certificates required for the devices to connect and authenticate with your network. The process is pretty similar across different device platforms, but there are some platform-specific steps and considerations that you need to be aware of.
How Does Distributing Network Profiles via Jamf Pro Work?
Pushing a network profile to a managed device in Jamf Pro requires a few different pieces to properly configure trust, encryption, and authentication. This typically involves:
- Trusted Certificate: For a device to trust your Shield identities, server endpoints, and network infrastructure, it must have your Shield’s Root CA certificate pushed to its trusted certificate store. Without this certificate, the device will not be able to establish a secure connection to Shield for network access or authentication.
- ACME Certificate: Every Jamf Pro managed device needs its own identity and certificate, which is delivered via the Automated Certificate Management Environment (ACME) protocol. Shield communicates with your device and with Jamf Pro via the ACME device attestation protocol to ensure that each device has a unique and trusted identity for network authentication.
- Wi-Fi Profile: A Wi-Fi profile contains the necessary network settings, such as the SSID, security type, and authentication method, required for the device to connect to your network. This profile ensures that the device can automatically connect to the network using the appropriate credentials and certificates provisioned through Jamf Pro.