My organization is looking for ways to make our deployment workflow completely zero-touch as a response to the COVID-19 crisis.
A little background: All of our Macs are bound to a domain. It is a large educational organization with multiple child domains, including a public-facing domain for our public-facing computing resources.
Currently, the final step for setting up a Mac for staff is to have the end-user authenticate to the domain with their staff Active Directory credentials.
Since our devices are deployed onsite during typical business operation, we always have the ability to authenticate. COVID-19 introduces a flaw in this process as we attempt to onboard new staff and provision computers to current staff as temporary loaners during the crisis.
Does anyone have insight on how we can enable VPN authentication prior to login or some other workflow for preconfiguring mobile accounts? Anything you have, forum discussions, links to existing documentation, etc. is welcome.
Thanks, Jamf Nation!