You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

📢 Newsroom Update

Apple expands tools to help businesses connect with customers. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Can I use JAMF and InTune to manage different devices?

I am currently using JAMF to manage my iPads. There is talk about migrating from JAMF to InTune. I have set up everything in InTune, and have created another MDM server in Apple School Manager and added the device. I am testing a single device. I see the device in my InTune enrollment token, and it says ready to enroll. However, it appears to not want to enroll, or I don't know how to enroll it. This makes me wonder if it is even possible to use both MDM's to manage different devices through apple school manager. Assistance is appreciated.

iPad (10th generation)

Posted on Jul 22, 2024 2:16 PM

Reply
5 replies

Jul 23, 2024 2:40 PM in response to FFAMike

Yes. You can have many MDM servers. And you can assign device categories to auto-associate to the specific MDM. For example, Macs can auto-assign to Jamf and iPads to Intune. Or you can manually reassign as needed.


Ah, but you need to do a few things. It sounds like you have already created a second MDM server. Did you import the token into Intune and create a prestage enrollment policy? Next, you will need to create a new Location in ABM/ASM. This will allow you to create a second VPP token. If you try to use one token and you import the token into Intune, then you will revoke the apps on the Jamf managed devices. That will be bad. Instead, create the second location and then license or reassign apps to the Intune side. DON'T reassign all of the apps because then you will have no licenses available for the units still in Jamf. This is easy with the free apps because 10 copies x $0 = 500 copies x $0. Paid for apps may need some creativity - move the license as you move the device.


Once you have your second location, export the VPP token and import it into Intune.


Next, make sure you are using a unique push certificate in each of the MDMs. You can use the same ID but don't get the certs confused and don't let them expire. Never replace, always renew using the same ID.


Now, moving your devices may be a challenge. You will need to erase the devices after reassigning to your Intune MDM in ABM/ASM. That will allow automated enrollment to occur. But data will be lost so be careful.


Hope this is helpful

Jul 24, 2024 10:01 AM in response to FFAMike

A couple of follow ups.


If you imported the DEP token you now need to attach a policy to the token. In Intune, go to Devices > Device onboarding :: Enrollment > select the Apple tab > click Enrollment program tokens > click on your token > click on Profiles > Create a new profile for iOS/iPadOS. This is the equivalent of a Jamf Pre-Stage policy. Once the policy has been created, you must click it again and then choose Assign Devices to link your hardware assets to the prestage (enrollment profile). Intune is slower than Jamf in just about every way. Wait at least 15 minutes before resetting the iPad to make sure that everything applied properly. If you will only have one enrollment policy, make sure you set it as the default so that all newly assigned devices in ASM will automatically associate to your Intune enrollment policy.


The VPP token is the volume purchases plan. This is how you get Apps onto the devices. You use ASM to license/purchase apps. Then assign them to a location. When you have one MDM, you have one default location. If you have two MDMs, you need two locations. This allows each location to have a unique set of apps. In Intune, go to Tenant Administration > Connectors and Tokens > Apple VPP Token to upload your Intune VPP token from your second location. As noted before, if you simply export your existing VPP token and assign it to Intune, you will revoke all apps assigned by Jamf. Don't do that. Create a second location and then reassign existing licenses or acquire additional.


As a side note, and take this with a grain of salt as I am likely partial due to vendor association, Intune is much slower, frustrating, cumbersome, and mind boggling than Jamf. I managed devices in Jamf, Jamf School, Jamf Now, Mosyle (regular and Fuse), Hexnode (yep, I never heard of it before either), Intune, and Apple Business Essentials (avoid at all cost). Jamf is by far the best of the products (even with their recent rudderless direction). Again, this is my opinion and everyone's milage will vary. Intune changes every 4 months and what you thought you knew you need to relearn/rediscover. Then stuff that works, stops working. Stuff that wasn't working, starts working. You can enroll 5 devices at the same time and experience 5 different outcomes. Support is terrible (especially if you are trying to manage Macs). Oh, and did I mention it is slow? 24 hours for devices to post? Really. Hours for a profile to deliver. Yikes. (yes, I know, manually force - but why should I even need to be in the MDM if all I am doing is enrolling new devices based on already established policies and profiles?). And random order delivery remains a pain point for Macs. There are times when you need to deliver things in order and Intune cannot provide that.


Anyway, good luck. Hope this gets you on the right path.


Jul 24, 2024 7:35 AM in response to Strontium90

THANK YOU for all this goodness


I did create a new MDM in my ABA


"Did you import the token into Intune and create a prestage enrollment policy?" - I followed the steps intune and exported the cert from the MDM i created in ABA and imported it into intune and created a program token called InTune iPad, I assigned a default enrollment token for it, but Im not sure what a prestage enrollment policy is or where that is located.


so I need to make another location? I can do that. I currently dont have any VPP tokens set or activated in our environment. Is that necessary? if so I can create one.


Hey, thanks so much for taking the time to reply


Next, make sure you are using a unique push certificate in each of the MDMs. You can use the same ID but don't get the certs confused and don't let them expire. Never replace, always renew using the same ID. - Copy that, I did that at the start


Now, moving your devices may be a challenge. You will need to erase the devices after reassigning to your Intune MDM in ABM/ASM. That will allow automated enrollment to occur. But data will be lost so be careful.

  • I did that part. lol, uninrolled them from jamf, threw them in the trash, then wiped the device. It came back up and intune sees it, but wont enroll it.

Jul 25, 2024 6:51 AM in response to Strontium90

Thank you so much for the information, I have most of that set up, I might need to look at my configs. I'm also going to set up a separate location (we have 4) and create a VPP Ptoken.


I agree with you, I love JAMF, I use JAMF basic at this district, and JAMF pro at another, never have any issues. Unfortunately, cutbacks are having me look into my InTune environment as an alternative. Hence the use of both.


Can I use JAMF and InTune to manage different devices?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.