How can the requirement for installing a self-signed certificate before enrollment be removed?

A.
Encrypt the device before enrollment.
B.
Register the certificate with a third parte certificate manager.
C.
Replace the self-signed certificate with a certified certificate signed by a trusted party.
D. Create an IBM Endpoint Manager policy that automatically installs the self-signed certificate.