Morning,
I am after some help if possible. Further to my previous post (https://www.jamf.com/jamf-nation/discussions/31889/mojave-deployment-and-configuration-using-jamf-and-depnotify) we're a little further forward on how my organisation will be deploying Mojave. The workflow we have in mind requires some streamlining and, as a newbie to all this, I am wondering if anyone might be able to advise or assist with our process please.
Our Workflow is along the lines of:
> Utilising Twocanoes MDS we've decided upon repartitioning/formatting our drives, utilisting APFS and installing a clean Mojave - v10.14.5. This is kind of worked out now. This process is roughly: script to partition the drive, kick off the install script - this prompted to name the device, installs macOS and apply some basic customisations (location related, power settings, create local admin account)
> Where I am now is how to enrol the devices to JAMF. We have a mixture of DEP and non DEP devices, so I am wondering if we might be able to utilise a mixed approach of DEP enrollment and User initiated enrollment? However I am stumped how to do this.
For the manual/User initiated option - I understand that there is the jamf url, in that a user needs to logon to the computer, go to the url and the MDM downloaded/ran - it is this I an unsure about. Do I need to create a number of policies with JAMF, that are set to run on enrollment? If this is the case, as part of this process I need to bind AD - I have a number of Directory Bindings and policies created for these, but again do these just need to have the Trigger set 'Enrollment Complete' and if so, will they work themselves out, or might I need to create an addtional script/policy that systematically works through identifying the name of the device and picking it from maybe a list of the policies/possible OU's?
For the DEP devices - Is there a policy or something that I can create/run that will identify our DEP registered devices and in turn enrol them automatically? Again I am unsure about this side of things.
> Once the device is enrolled in JAMF and bound to AD I then need JAMF to apply various software installs. This needs to happen through a two pronged approach, in that there'll be a higher level, all devices smart group(?), where customisations needs to be made/applied to every device, regardless of location - along with things like AV, Printers. I then envisage a script or policy that will transfer the device, based on name, to a specfic smart group that will install all the relevant software packages for the specific location that it is in.
As above, any advice or input around the above would be most welcome.
Thank you.
