Automated Jamf New Device Onboarding Checks
Every night, WebRun opens Jamf, lists the devices enrolled since yesterday, checks each one landed in the right smart groups, received its configuration profiles and policies, and escrowed its FileVault key, then posts the incomplete ones to Slack and sends the desk-ready summary to Microsoft Teams.
How do I check that a newly enrolled Mac finished its Jamf setup?
WebRun opens Jamf every night and lists the Macs enrolled that day, then checks each one landed in the right smart groups, received its configuration profiles and policies, and escrowed its FileVault key. It posts the incomplete devices to Slack and briefs the IT desk in Microsoft Teams before handover.
- Half configured laptops are caught before they reach a new hire's desk
- Missing FileVault escrow is flagged the same night enrollment happens
- Every enrollment gets the same four checks, every day
Built for Mac admins · IT operations · MDM administrators · endpoint security teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.jamf.comin a real browser with your saved login - no setup, no API keys. -
1
Jamf - check today's new enrollments
WebRun opens Jamf to check today's new enrollments. - Open Jamf and list every device enrolled since the previous run, with its serial, model, and assigned user
- For each device confirm it landed in the expected smart groups and that its configuration profiles installed
- Check the required policies ran and that the FileVault recovery key is escrowed, and record the last inventory update time
Done when Every device enrolled today has a pass or fail against groups, profiles, policies, and FileVault escrow.
-
2
Slack - flag half-finished devices
WebRun opens Slack to flag half-finished devices. - Post the devices that failed any check to your Mac admin channel
- Name the serial, the assigned user, and exactly which step is missing on each one
- Put devices with no FileVault escrow at the top, since those are the ones that cannot be recovered
Done when Every incomplete enrollment is posted in Slack with the missing step named.
-
3
Microsoft Teams - brief the IT desk
WebRun opens Microsoft Teams to brief the IT desk. - Post the IT desk a short summary: devices enrolled today, how many passed every check, and how many need a hand
- List the devices due to be handed to a new hire this week so a half configured laptop is caught first
- Keep the tone factual. WebRun does not run a policy, reissue a profile, or wipe a device
Done when The IT desk has tonight's enrollment summary and the devices needing attention before handover.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it run policies or change device settings?
No. WebRun only reads enrollment state and reports what is missing. Running a policy, reissuing a profile, or remediating a device stays with your Mac admins, and nothing is wiped or locked.
Does it read or store FileVault recovery keys?
No. It only checks whether a key is escrowed for the device and reports yes or no. The key itself is never read, copied, or included in any message.
What counts as a failed onboarding?
A device missing an expected smart group, a configuration profile that did not install, a required policy that never ran, or a FileVault key with no escrow record. Each failure is named per serial.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.