Editer
Contents
This is the standard method of commissioning a BSG Windows Laptop onto the BSG domain. The laptop should be running Windows 10 Enterprise, and be BitLocker compatible.
Fresh out of the box Dell Computers will have Windows 10 Enterprise installed. If you need to install a fresh version of Windows 10 Enterprise, please follow the below steps.
Download the latest Windows 10 bundle from the University Microsoft Download Page. You will need to login with your SSO username and password.
Create a bootable Windows 10 USB drive. You will need this to install a fresh version of Windows 10.
Once you have booted into windows 10, you need to assign the computer the to BSG domain. Do this by following the below steps.
Login to the NAC and put the device on the 'User' VLan using its MAC address.
Uninstall 'MyOffice' if present, then download and install Microsoft Office 2016 from the University Microsoft Download site.
Navigate to Dell Support page and in install any missing drivers. Make sure to install any dock patches that may be needed.
FireFox
For Oracle Financials users, install the University Java package
For CoreHR users you must follow the setup instructions at the CoreHR Local IT webpage.
For Oracle Financial users, you must follow the setup instructions at the Oracle Financials Technical Support page.
This is automatically followed by the 'Planting' stage where essential configuration for security, binding, branding etc and installation of the munki software deployment tools including the Orchard Software Centre. Once Planting is complete the user is prompted to restart and Orchard Software Centre (munki) will deploy software.
For macOS 10.13 onwards the jamf binary is downloaded via MDM.
You have an account on the Orchard JSS with the privilege 'JSS Actions' --> 'Enrol Computers and Mobile Devices'.
If the Mac has an ethernet port, this needs to be put on the NAC under the 'User' Vlan.
Whether the Mac is fresh out of the box or a reinstallation, create an ladmin account as part of the Setup Assistant. You can use an easy password for this section of enrolment for ease. You will need to set a complex password and record this in 1Password later.
Login to the Mac using the ladmin account.
In System Preferences --> Sharing, check the Computer Name has the bsg- prefix eg. bsg-Macbook. This will be the name used to create the Computer Record in the Orchard JSS. It will also be used to bind the Mac to the BSG Active Directory.
On the Mac to be commissioned, browse to https://jss.orchard.ox.ac.uk/enrol to start the enrolment process.
Complete this process to add your Mac: Enter your JSS User Account credentials.
Assign to user: enter the end-user's SSO username (abcd1234), click the spyglass and wait for a tick or cross to appear.
Assign to user: Once the tick has appeared click 'Enrol'.
To continue with enrolment...: Click Continue to download and open the MDM profile.
Are you sure you want to install...: Click Continue to install the MDM profile.
INSTALL STEP 2
Are you sure you want to install...: Check the details of the profile then click Install.
INSTALL STEP 3
Profiles wants to make changes: Enter credentials for the ladmin account.
STEP 4
Profiles: Note the MDM profile is now Verified.
STEP 5
Profiles: The Privacy Preferences Policy profile should then install automatically.
STEP 6
To follow the results of the Planting policies, run tail -f /var/log/jamf.log in a Terminal window.
Computer record: While waiting for the Planting policies to complete, sign into the Orchard JSS at https://jss.orchard.ox.ac.uk and find the new computer.
Computer record: In General, edit the page and add an Asset Tag number based on the sticker you chose.
GENERAL ASSET TAG PICTURE
Computer record: In User & Location, check the user and correct it to the end-user's if necessary.
USER & LOCATION PICTURE
Computer record: In Purchasing, enter the PO Number and PO Date.
PURCHASING PICTURE
A restart is needed: Once the Planting policies are complete you will see this dialog. Click the 'Restart in 2 Minutes' button and wait for the Mac to automatically restart.
PLANTING RESTART PICTURE
Orchard Software Centre: After the Mac restarts, the login screen should appear but be locked immediately. Orchard Software Centre should then automatically install Apple Software Updates followed by software titles. This may require one or more automated restarts.
If you are commissioning a MacBook it will receive a Configuration Profile to enable FileVault at login. Encryption will only proceed if the ladmin account is used; it will not happen if any other account logs in.
Follow the encryption workflow for macOS 10.13 onwards on 'FileVault - Information for IT Support Staff', then return here to complete the remainder of the commissioning process.
On the Mac, confirm in System Preferences >>> Profiles that all the Configuration Profiles listed in the Mac's JSS Computer Record under Management have been installed.
To troubleshoot issues check the computer record in the JSS for failed policies (History --> Policy Logs), and check the Orchard Software Centre install log for failures at /var/log/munki/Install.log