MacBook Initial Startup steps:
When you get the MacBook from ITAM they should already been ADM and intune with MDM enrollment completed
- Open the lid – MacBook will come ON automatically
- Follow the screen instructions very carefully
- You will be prompted to how you need to connect to the network via Wifi or local ethernet
- You will be prompted to enter the user’s account – have user put in their county login credentials – this step is required
- For the computer account you MUST create one this will be the local admin account otherwise you will not be able to go on to the next step
- When the initial startup enrollment is completed you now on the desktop
- Click on Settings
- General
- Software Updates
- Click on Updates for any new updates
- When all updates are installed now you can follow the steps below to join the device to the domain
Join MacBook to the domain OS version “Ventura or Sonoma”
To join a company MacBook to the domain, follow the steps below:
- Go to System Settings > Users & Groups.
- Click Edit on Network Account Server
- Click on Open Directory Utility
- Click the lock icon bottom left corner to unlock and enter the local Mac’s administrator password.
- Double Click on Active Directory and ether the local administrator password
- Click Options.
- Under User Experience:
- √ check local home directory on startup disk
- √ check Use UNC path from Active Directory to derive network home location
- Network protocol to be used: smb;
- √ check Default user shell: /bin/bash
- Under Mapping: leave all unchecked
- Under Administrative: √ check Allow administration by and click on the + symbol and enter the following one at a time.
- domain admins
- enterprise admins
- isdgglocaladmins
- scclocaladmin
- √ Check Allow authentication from any domain in the forest
- Click OK
- Active Directory Domain: Sccgov.org
- Computer ID: enter your device name
- Click “Bind“
- Unsername: your field account (must have privilege to join mac devices if getting error see Shawn)
- Password: your FS account password
- Computer OU: OU=ISD,OU=SCCComputers,DC=sccgov,DC=org
- Make sure both boxes are check and Click OK
- If successful you will see the domain name in Green
- Restart
- At the logon screen you will see the Local Mac Account as the default please wait 10-15 seconds to allow the Mac to sync with the active directory to allow domain user to login.
- After 15 seconds or more you now hover the mouse on the picture and you will see another user click on that to login with your county personal login.
- Please note you WILL NOT see your desktop like the normal PC, but your network drives should be available for access
- Click on Finder on the taskbar to get to the network folders
- Also please note that HHS field support technicians are not trained to work on Macbook, but you can try calling your organization’s help desk.
Ping the device host name now it should be online and getting the IP address. RDP into the device now.
Installing Apps required by county CISO
- Zscaler
- Qualys
- CrowdStrike
- Microsoft 365
- Microsoft Edge