Using UT Provisioning for Jamf Connect

Using UT Provisioning for Jamf Connect

Using UT Provisioning for Jamf Connect, you can streamline setting up a new Mac (or reimaging one), and let users log into their Macs with their EID. Your Macs will be more secure, consistent, and easier to manage. And, no Stache entries are needed.
 

 

The setup process will configure everything needed for compliance with UT policies and install a base set of applications (which can be edited by changing some parameters on a few policies in your site).

 

Using Jamf Connect on a Mac:

 

  • Users log in with their EID (IID or email address the first time)

  • Admins use 'jamf-admin' with the LAPS password from Jamf, or TAP (Temporary Admin Password)

  • Users needing admin access can either be given the jamf-admin password, or use TAP

  • Unauthorized admin accounts cannot log in (only unlock) and will be demoted to standard accounts (e.g If a user abuses their admin privileges and creates a local admin account)

  • Optional auto-registration for utexas-iot and connecting to utexas-iot at the Microsoft login window

 

 

To provision a new Mac

  • Get the serial number and assign it to your site in Apple School Manager

  • Wait for the Mac's status in your "SITE - Jamf Connect" PreStage to be "Assigned" (not "Assigned - Pending Sync")

  • RECOMMENDED: connect the Mac to ethernet (you can use 'utexas' wifi but you will need to sign in multiple times)

  • Power on the Mac - Activate it, answer the prompts with the defaults, then choose "Set up as New"

  • Click Continue at the prompt to enroll in Remote Management and the Mac will enroll in Jamf

 

Once enrolled in Jamf

  • Log in as "engr-setup" with password "<REDACTED>"

  • Wait for the Registration window to open

  • Fill in Asset Tag, User's EID (not yours), Department Code

  • Leave "Install Standard Applications" on Yes unless you don't want them installed

  • Click "Register this Mac"

 

After registration finishes

  • You may need to enable some Privacy & Security settings (e.g for BeyondTrust, Zoom, etc)

  • Check that everything installed properly

  • When ready to deploy to the user, log out or shut down the Mac.

    • DO NOT LOG IN AGAIN until the user logs in (it's not a disaster but makes things more difficult)

 

Deploying to the user

  • The first time a user logs in the Mac must be at the Microsoft Login screen, not the Filevault login screen: 

  • They should enter their email address or IID (EID@eid.utexas.edu)

  • Then sign in at the UT Login screen: 

  • And complete Duo authentication: 

  • The Mac will create their account on the Mac (it will just be their EID)

  • After the first login, the Mac will be encrypted, the engr-setup account will be disabled, and your unit's IT admin account will be created

  • If a new user needs to log in, an existing user must log in, then LOG OUT (not restart), to bring up the Microsoft login screen. Unlocking via the Recovery Key is also an option

  • For later logins to the Mac, the user will generally not see the Microsoft Login screen. However if they do see it, they can click the "Local Login" button to use their EID to log in

 

  

What needs to be in place in your Jamf site

 

You need a PreStage Enrollment for Jamf Connect, and all of the following Smart Groups, Policies, and Config Profiles.

It may seem like a lot, but ITG has a tool which can clone everything needed into your site, contact us if you want to take advantage of that.

 

PRESTAGE

SITE - Jamf Connect

  • General

    • Automatically Assign new devices

    • Prevent user from enabling Activation Lock

    • Make MDM Profile Mandatory

    • Setup Assistant - Automatically advance through Setup Assistant

      • Setup Assistant Options - check all

  • Account Settings

    • Create a managed local administrator account (this account will be disabled later)

      • Username: engr-setup

      • Password: engr-IT-initial-SETUP

    • Make the managed local administrator MDM enabled

  • Local User Account Type

    • Skip Account Creation

 

SMART GROUPS

SITE - UT Provisioning - PreStage New Mac - registration and software - Jamf Connect

SITE - UT Provisioning - Name starts with department

SITE - UT Provisioning - PreStage New Mac - setup complete

SITE - UT Provisioning - PreStage New Mac - setup complete, not encrypted

SITE - Jamf Connect Installed

SITE - TAP Allowed

 

POLICIES

This runs first:

SITE - UT Provisioning - New Mac - registration and software - Jamf Connect


It runs these policies:

SITE - UT Provisioning - Required Configuration

This runs:

SITE - Nessus Manage - Schedule to run Daily

GLOBAL - UTexas Shared Packet Firewall install - on-demand

SITE - Install Outset

SITE - Outset script - block-user-admin

SITE - Outset - Install SS+ Menu exit script

SITE - Enable remote login - on-demand

SITE - BeyondTrust Jump Client install (Engineering group)

 

SITE - UT Provisioning - Install Base Software

This runs:

GLOBAL - Adobe Acrobat Reader DC-2200120112

GLOBAL - Google Chrome

GLOBAL - Firefox

SITE - Office 365

SITE - Teams

GLOBAL - Zoom

* NOTE: You can daisy chain to another policy if you want more - UT Backup, Cisco VPN, etc

 

SITE - UT Provisioning - Prepare for EID Login - Jamf Connect

This runs:

SITE - UT Provisioning - Jamf Connect Background

SITE - UT Provisioning - Install UT-macOS-Icons

SITE - UT Provisioning - Install JAMF Connect Login

 

These run after first login:

SITE - UT Provisioning - Encrypt at Login - Jamf Connect

SITE - UT Provisioning - Create IT Admin Account after Encryption

 

Optional utexas-iot registration (you must have your own XMP api key):

SITE - UT Provisioning - Prepare for EID Login - Jamf Connect - utexas-iot

SITE - Outset script - check-network at login

 

This runs daily and at every login:

SITE - Demote Unauthorized Admin Users

 

This is available from Self Service, if the user is allowed and logged into Self Service:

SITE - TAP - Temporary Admin Password

  

CONFIG PROFILES

Define settings for UT-branded Jamf Connect:

SITE - Jamf Connect App - UT

SITE - Jamf Connect Login - UT

 

Configure the Block-User-Admin Outset script

SITE - Outset - Block User Admin - Settings

 

Configure the Demote-Unauthorized-Admin script

SITE - Allowed Admin Users

 

Configure the Outset Check Network script (for use with utexas-iot):

SITE - Outset - Check Network - Settings