Contents
This is the standard method of commissioning an Orchard Mac. The Mac needs an Orchard-supported version of macOS installed and is then enrolled via web browser to the Orchard JSS. A successful enrolment creates a computer record in the JSS and installs the 'jamf' management binary on the client.
This is automatically followed by the 'Planting' stage where essential configuration for security, binding, branding etc and installation of the munki software deployment tools including the Orchard Software Centre. Once Planting is complete the user is prompted to restart and Orchard Software Centre (munki) will deploy software.
For macOS 10.13 onwards the jamf binary is downloaded via MDM.
You have an account on the Orchard JSS with the privilege 'JSS Actions' --> 'Enrol Computers and Mobile Devices'.
If the Mac has an ethernet port, this needs to be put on the NAC under the 'User' Vlan.
Whether the Mac is fresh out of the box or a reinstallation, create an ladmin account as part of the Setup Assistant. You can use an easy password for this section of enrolment for ease. You will need to set a complex password and record this in 1Password later.
Login to the Mac using this ladmin account if you have not already done so.
In System Preferences --> Sharing, check the Computer Name has the bsg- prefix eg. bsg-Macbook. This will be the name used to create the Computer Record in the Orchard JSS. It will also be used to bind the Mac to the BSG Active Directory.
On the Mac to be commissioned, browse to https://jss.orchard.ox.ac.uk/enrol to start the enrolment process.
Complete this process to add your Mac: Enter your JSS User Account credentials. LOGIN PAGE PICTURE
Assign to user: enter the end-user's SSO username (abcd1234), click the spyglass and wait for a tick or cross to appear.
ASSIGN TO USER PICTURE
Assign to user: Once the tick has appeared click 'Enrol'.
To continue with enrolment...: Click Continue to download and open the MDM profile.
ENROL PICTURE DOWNLOAD
Are you sure you want to install...: Click Continue to install the MDM profile. INSTALL STEP 2
Are you sure you want to install...: Check the details of the profile then click Install.
INSTALL STEP 3
Profiles wants to make changes: Enter credentials for the ladmin account. STEP 4
Profiles: Note the MDM profile is now Verified. STEP 5
Profiles: The Privacy Preferences Policy profile should then install automatically. STEP 6
To follow the results of the Planting policies, run tail -f /var/log/jamf.log in a Terminal window.
Computer record: While waiting for the Planting policies to complete, sign into the Orchard JSS at https://jss.orchard.ox.ac.uk and find the new computer.
General In the General, edit the page and add an Asset Tag number based on the sticker you chose.
Computer record: In User & Location, check the user and correct it to the end-user's if necessary.
Computer record: In Purchasing, set the Billing Start Date to today's date. If you require an audit trail enter the support ticket/incident number in 'Commissioning: RT Reference'.
A restart is needed: Once the Planting policies are complete you will see this dialog. Click the 'Restart in 2 Minutes' button and wait for the Mac to automatically restart.
Orchard Software Centre: After the Mac restarts, the login screen should appear but be locked immediately. Orchard Software Centre should then automatically install Apple Software Updates followed by software titles. This may require one or more automated restarts.
If the Mac is already FileVault encrypted then Orchard Software Centre may not automatically launch. Login as normal then launch Orchard Software Centre or log out.
If you are commissioning a MacBook it will receive a Configuration Profile to enable FileVault at login. Encryption will only proceed if the same admin account used for the above is the one to log in; it will not happen if any other account logs in.
Follow the encryption workflow for macOS 10.13 onwards on 'FileVault - Information for IT Support Staff', then return here to complete the remainder of the commissioning process.
On the Mac, confirm in System Preferences >>> Profiles that all the Configuration Profiles listed in the Mac's JSS Computer Record under Management have been installed.
It is a requirement of the Orchard Fully Managed product that all end-user accounts be Standard not Admin. If the device is a desktop Mac, log in using 'orchard' credentials and delete any other administrator accounts in System Preferences --> Users & Groups. If the device is a laptop, create account ladmin/Local Administrator, then log in and ask the user to set a password, then remove any administrator accounts besides 'orchard' and 'ladmin'.
We recommend that Orchard For ITSS Macs also have only the minimum required Admin accounts.
To troubleshoot issues check the computer record in the JSS for failed policies (History --> Policy Logs), and check the Orchard Software Centre install log for failures at /var/log/munki/Install.log
Overview This is the standard method of commissioning an Orchard Mac. The Mac needs an Orchard-supported version of macOS installed and is then enrolled via web browser to the Orchard JSS. A successful enrollment creates a computer record in the JSS and installs the 'jamf' management binary on the client. This is automatically followed by the 'Planting' stage where essential configuration for security, binding, branding etc and installation of the munki software deployment tools including the Orchard Software Centre. Once Planting is complete the user is prompted to restart and Orchard Software Centre (munki) will deploy software. For macOS 10.13 onwards the jamf binary is downloaded via MDM. The workflow is different for macOS 10.12 and earlier, see this page instead. Prerequisites 1. You have an account on the Orchard JSS with the privilege 'JSS Actions' --> 'Enrol Computers and Mobile Devices'. 2. You have the credentials for an admin account on the Mac. If the Mac is already in use and the end user currently has admin rights on their personal account, this should be reduced to a Standard account and a Local Admin ('ladmin') or Site Admin ('sadmin') be used for the commissioning process. All Orchard laptops currently require a ladmin account as laptop support is still in beta. 3. The Mac has been registered for DNS with a valid hostname: o For Connect AD, review their latest Naming Scheme and request a hostname from the Desktop Services Team. o Units should use their own preference. o NSMS generically uses naming scheme unit-hostname.unit.ox.ac.uk e.g. obg-taxus.obg.ox.ac.uk. 4. The Mac has been registered for DHCP, preferably having a fixed IP address. 5. The Mac's storage has a single partition named 'Macintosh HD'. Process Prepare for enrolment 1. On the Mac to be commissioned, log in with an admin account named ladmin, sadmin or setupuser. If it's a fresh out of the box Mac then use one of these three names for the initial user created during Setup Assistant. 2. In System Preferences --> Sharing, check the Computer Name is set to the first part of the DNS hostname eg. admn-dap1234dev. This will be the name used to create the Computer Record in the Orchard JSS. If configured it will also be used to bind the Mac to an Active Directory. 3. Close all open documents and applications. Enrol and prepare for Planting 1. On the Mac to be commissioned, browse to https://jss.orchard.ox.ac.uk/enrol to start the enrollment process. 2. Complete this process to add your Mac: Enter your JSS User Account credentials. 3. Assign to user: enter the end-user's SSO username (abcd1234), click the spyglass and wait for a tick or cross to appear. o If a cross appears this means the user needs to be added to the JSS, which can be done later. Enter your own SSO instead and click the spylass again. o The user search relies on the Orchard JSS being bound to an Active Directory containing your users' data. If this has not been configured, leave the username field blank and set it in the Computer Record after enrolment.
4. Assign to user: If the Mac is on the Orchard Fully Managed product choose the required Site and click 'Enroll'. o Orchard for ITSS customers will not see the Site menu. 5. To continue with enrollment...: Click Continue to download and open the MDM profile. 6. Are you sure you want to install...: Click Continue to install the MDM profile. 7. Are you sure you want to install...: Check the details of the profile then click Install. 8. Profiles wants to make changes: Enter credentials for the admin account. 9. Profiles: Note the MDM profile is now Verified. 10. Profiles: The Privacy Preferences Policy profile should then install automatically. 11. Enrolment is now complete and Planting policies will start executing in the background. Planting and software deployment 1. The Planting policies are triggered automatically after enrolment and will take around five minutes to complete. These configure security, binding, branding etc and install 'Orchard Software Centre' (munki) for software deployment. o To follow the results of the Planting policies, run tail -f /var/log/jamf.log in a Terminal window. 2. Computer record: While waiting for the Planting policies to complete, sign into the Orchard JSS at https://jss.orchard.ox.ac.uk and find the new computer. o Orchard Fully Managed administrators should correct the Site here if needed.
3. Computer record: In User & Location, check the user and correct it to the end-user's if necessary. 4. Computer record: In Purchasing, set the Billing Start Date to today's date. If you require an audit trail enter the support ticket/incident number in 'Commissioning: RT Reference'. 5. A restart is needed: Once the Planting policies are complete you will see this dialog. Click the 'Restart in 2 Minutes' button and wait for the Mac to automatically restart. 6. Orchard Software Centre: After the Mac restarts, the login screen should appear but be locked immediately. Orchard Software Centre should then automatically install Apple Software Updates followed by software titles. This may require one or more automated restarts. o If the Mac is already FileVault encrypted then Orchard Software Centre may not automatically launch. Login as normal then launch Orchard Software Centre or log out.
7. Orchard Software Centre will close after all software is installed. MacBooks only: Initiate FileVault encryption If you are commissioning a MacBook it will receive a Configuration Profile to enable FileVault at login. Encryption will only proceed if the same admin account used for the above is the one to log in; it will not happen if any other account logs in. Follow the encryption workflow for macOS 10.13 onwards on 'FileVault - Information for IT Support Staff', then return here to complete the remainder of the commissioning process.