Using UT Provisioning for Jamf Connect
Using UT Provisioning for Jamf Connect, you can streamline setting up a new Mac (or reimaging one), and let users log into their Macs with their EID. Your Macs will be more secure, consistent, and easier to manage. And, no Stache entries are needed.
The setup process will configure everything needed for compliance with UT policies and install a base set of applications (which can be edited by changing some parameters on a few policies in your site).
Using Jamf Connect on a Mac:
Users log in with their EID (IID or email address the first time)
Admins use 'jamf-admin' with the LAPS password from Jamf, or TAP (Temporary Admin Password)
Users needing admin access can either be given the jamf-admin password, or use TAP
Unauthorized admin accounts cannot log in (only unlock) and will be demoted to standard accounts (e.g If a user abuses their admin privileges and creates a local admin account)
Optional auto-registration for utexas-iot and connecting to utexas-iot at the Microsoft login window
To provision a new Mac
Get the serial number and assign it to your site in Apple School Manager
Wait for the Mac's status in your "SITE - Jamf Connect" PreStage to be "Assigned" (not "Assigned - Pending Sync")
RECOMMENDED: connect the Mac to ethernet (you can use 'utexas' wifi but you will need to sign in multiple times)
Power on the Mac - Activate it, answer the prompts with the defaults, then choose "Set up as New"
Click Continue at the prompt to enroll in Remote Management and the Mac will enroll in Jamf
Once enrolled in Jamf
Log in as "engr-setup" with password "<REDACTED>"
Wait for the Registration window to open
Fill in Asset Tag, User's EID (not yours), Department Code
Leave "Install Standard Applications" on Yes unless you don't want them installed
Click "Register this Mac"
After registration finishes
You may need to enable some Privacy & Security settings (e.g for BeyondTrust, Zoom, etc)
Check that everything installed properly
When ready to deploy to the user, log out or shut down the Mac.
DO NOT LOG IN AGAIN until the user logs in (it's not a disaster but makes things more difficult)
Deploying to the user
The first time a user logs in the Mac must be at the Microsoft Login screen, not the Filevault login screen:
They should enter their email address or IID (EID@eid.utexas.edu)
Then sign in at the UT Login screen:
And complete Duo authentication:
The Mac will create their account on the Mac (it will just be their EID)
After the first login, the Mac will be encrypted, the engr-setup account will be disabled, and your unit's IT admin account will be created
If a new user needs to log in, an existing user must log in, then LOG OUT (not restart), to bring up the Microsoft login screen. Unlocking via the Recovery Key is also an option
For later logins to the Mac, the user will generally not see the Microsoft Login screen. However if they do see it, they can click the "Local Login" button to use their EID to log in
What needs to be in place in your Jamf site
You need a PreStage Enrollment for Jamf Connect, and all of the following Smart Groups, Policies, and Config Profiles.
It may seem like a lot, but ITG has a tool which can clone everything needed into your site, contact us if you want to take advantage of that.
PRESTAGE
SITE - Jamf Connect
General
Automatically Assign new devices
Prevent user from enabling Activation Lock
Make MDM Profile Mandatory
Setup Assistant - Automatically advance through Setup Assistant
Setup Assistant Options - check all
Account Settings
Create a managed local administrator account (this account will be disabled later)
Username: engr-setup
Password: engr-IT-initial-SETUP
Make the managed local administrator MDM enabled
Local User Account Type
Skip Account Creation
SMART GROUPS
SITE - UT Provisioning - PreStage New Mac - registration and software - Jamf Connect
SITE - UT Provisioning - Name starts with department
SITE - UT Provisioning - PreStage New Mac - setup complete
SITE - UT Provisioning - PreStage New Mac - setup complete, not encrypted
SITE - Jamf Connect Installed
SITE - TAP Allowed
POLICIES
This runs first:
SITE - UT Provisioning - New Mac - registration and software - Jamf Connect
It runs these policies:
SITE - UT Provisioning - Required Configuration
This runs:
SITE - Nessus Manage - Schedule to run Daily
GLOBAL - UTexas Shared Packet Firewall install - on-demand
SITE - Install Outset
SITE - Outset script - block-user-admin
SITE - Outset - Install SS+ Menu exit script
SITE - Enable remote login - on-demand
SITE - BeyondTrust Jump Client install (Engineering group)
SITE - UT Provisioning - Install Base Software
This runs:
GLOBAL - Adobe Acrobat Reader DC-2200120112
GLOBAL - Google Chrome
GLOBAL - Firefox
SITE - Office 365
SITE - Teams
GLOBAL - Zoom
* NOTE: You can daisy chain to another policy if you want more - UT Backup, Cisco VPN, etc
SITE - UT Provisioning - Prepare for EID Login - Jamf Connect
This runs:
SITE - UT Provisioning - Jamf Connect Background
SITE - UT Provisioning - Install UT-macOS-Icons
SITE - UT Provisioning - Install JAMF Connect Login
These run after first login:
SITE - UT Provisioning - Encrypt at Login - Jamf Connect
SITE - UT Provisioning - Create IT Admin Account after Encryption
Optional utexas-iot registration (you must have your own XMP api key):
SITE - UT Provisioning - Prepare for EID Login - Jamf Connect - utexas-iot
SITE - Outset script - check-network at login
This runs daily and at every login:
SITE - Demote Unauthorized Admin Users
This is available from Self Service, if the user is allowed and logged into Self Service:
SITE - TAP - Temporary Admin Password
CONFIG PROFILES
Define settings for UT-branded Jamf Connect:
SITE - Jamf Connect App - UT
SITE - Jamf Connect Login - UT
Configure the Block-User-Admin Outset script
SITE - Outset - Block User Admin - Settings
Configure the Demote-Unauthorized-Admin script
SITE - Allowed Admin Users
Configure the Outset Check Network script (for use with utexas-iot):
SITE - Outset - Check Network - Settings