I’ve got an interesting dilemma with new employees.
Currently, we are a Gsuite shop, using all mac hardware. Jamf is configured to verify employees against Gsuite with an LDAP connection during the initial enrollment.
However… On an employee’s first day, when they are handed a laptop, they cannot enroll in Jamf, because they have not yet logged into Gsuite for the first time. Right now, this has us directing them to use a personally owned device to log into their email for the first time and change their password, before they set their laptop up. This is awkward and confusing for a lot of non-technical folks who don’t understand why they can’t just log into their laptop first.
How have others solved this? Is it adjusting the workflow? Or is there a better process?
