Employee - Existing - Mac
Contents
- 1 Existing Faculty or Staff Mac Cascade
- 2 Imaging and/or Cascading Quick Links
- 2.1 Cascade Checklist
- 2.2 Register the Mac
- 2.3 Step One: Check Crashplan for Backup Status/Run Sync
- 2.4 Step Two: Bootstrap the New Mac
- 2.5 Step Three: Apply Configuration and Updates
- 2.6 Step Four: Data Restoration and User Account Creation
- 2.7 User Creation/Restoring Data Using Migration Assistant
- 2.8 Step Five: Verify Data Restore
- 2.9 Step Six: Install Printers & Update/Install Other Software
- 2.10 Step Seven: Set up CrashPlan
- 2.11 Step Eight: Install iProjection
- 2.12 Step Nine: Mac Cascade Letter
- 2.13 Step Ten: Delivery
- 2.14 Step Eleven: Store Old Equipment
- 2.15 Troubleshooting
Existing Faculty or Staff Mac Cascade
Imaging and/or Cascading Quick Links
- What is Imaging? - Imaging
- Macintosh Imaging/Cascading Directions - Mac Imaging
- Windows Imaging/Cascading Directions - Windows Imaging
- Cascade Letters - Universal Cascade Letter
- Computer Drop Off and Pick Up Procedure - Computer Drop Off Procedure
Cascade Checklist
Checklist created to help with the cascade process.
Register the Mac
Before you unbox the Mac, register the Mac in GReg and update FileMaker. If they are receiving a USB-C Mac, please register the HooToo USB-C adapter. To find the MAC address of the HooToo, please either use Network Preferences/Network Utility.
Step One: Check Crashplan for Backup Status/Run Sync
- Log into crashplan.gac.edu
- Enter the computer name of the device in the search field.
- Verify the backup is at least 99% complete.
- When logged in as the user, run Run CrashPlan Sync.
Step Two: Bootstrap the New Mac
Bootstrapping is similar to imaging but we're only installing a base operating system and Managed Software Center. This makes bootstrapping really fast and allows us to update software and computer setup more easily.
- Connect a bootstrap drive to the Mac.
- Boot the Mac to Recovery Mode by powering on the Mac and holding down command+r
- Select Utilities --> Terminal
- Type the command /Volumes/macOS/run in the Terminal window.
- Terminal will ask which drive you'd like to bootstrap. Select the drive labeled Macintosh HD. If you don't see a drive labeled Macintosh HD you will need to partition the drive with Disk Utility first.
- After you've selected the drive, Terminal will ask you if you want to erase the target volume before install. Type y and press return.
Step Three: Apply Configuration and Updates
Once the Mac has been bootstrapped, it will reboot and you will be presented with the macOS initial setup window. Follow the onscreen prompts.
Important: Make sure you see a screen that says "Remote Management" and "鶹Ƶ can automatically configure your computer". If you don't see this screen the Mac will need to be moved to the correct MDM server. Any dutyperson should be able to move it for you if you provide them with the serial number of the Mac.
Once you've progressed through the macOS Setup windows, Managed Software Center will automatically begin downloading any applicable updates.
Step Four: Data Restoration and User Account Creation
鶹Ƶ uses Migration Assistant, an app built into macOS, to move data and users to a new Mac laptop. Migration Assistant can use a variety of sources to move data including DeployStudio backups, Time Machine Backups, and Macs booted to target disk mode.
This guide will start with how to connect to the various data source types.
Sync Domain Password with Filevault Password (Summer 2020 note: this step should already be done for you-you will find the reset domain password in the ticket)
Find out what kind of account the user is. To view this information, please visit System Preferences, Users and Groups. Does the user account say Managed/Mobile, or does it say Admin?
If the user account says Admin, Managed, Mobile, you will need to follow the directions below.
- Ask the user to log in to their mac
- Reset domain password
- Write down domain password for the user on the purple sheet and for GTS on the blue sheet
- While the computer is logged in, click the Apple Menu and click Log out.
- Log in with their username and the reset domain password.
- If this doesn't work, you will need to run AD Fix. If it does work please skip to letter n
- To run ad fix, please have them log in with their username and password.
- Click Go, Connect to Server, and log into macsoft.gac.edu as your username and password.
- Go to the Tools folder, and drag ADFix to the desktop.
- Double click AD Fix, and type in the admin credentials to run.
- On an employee's computer, click rebind employee
- you will receive a progress report and it will closed when it is done running.
- Once AD fix is done running, please log out again and try again with their username and password.
- If this works, restart the computer and try the reset domain password at the FileVault login.
- If it doesn't work, have the user log in again with their computer password, and try restarting again and log in with the username and temporary domain password.
- The reset domain password has been successfully synced with their FileVault password.
If the user account says Admin, you will need to sync the reset domain password via Enterprise Connect.
- Reset the user's domain password
- Open Enterprise Connect
- Log into Enterprise Connect with the username and reset domain password. Make sure the button that says "sync active directory password with computer password box is checked."
- Restart the computer and log into the computer with the reset domain password.
Target Disk Mode (Preferred Method)
Target Disk Mode allows the Mac to act as a really big (really expensive) external hard drive. To boot to Target Disk Mode follow these steps:
- Power off the Mac you'd like to transfer data from.
- Power on the Mac and hold down the T key. You will see a bouncing Thunderbolt symbol indicating that the Mac as booted to Target Disk Mode.
- Connect the Target Disk Mode Mac to the new Mac using the appropriate cable and adapter (a Thunderbolt cable with a Thunderbolt to USB-C adapter in most cases).
TimeMachine Backup
Time Machine Backups can be used on any Mac. Simply connect the TimeMachine drive to the new Mac.
Crashplan
Crashplan can be used in emergency circumstances where no other data source is available. To use Crashplan as a data source, create a user account for the user while signed into the admin account. Then log in as the user and follow the MacOS crashplan restore guide on the wiki.
DeployStudio Backup
Older Macs (that don't use APFS as their filesystem usually version 10.12.x or older) are able to backup to DeployStudio. The backup can then be used to move the account to the new user. To connect to a DeployStudio backup follow these steps.
- Login to the machine you'd like to transfer data to using the admin account.
- Click on "Go" in the Menu Bar and click on Connect to Server. Or use the keyboard shortcut: command + k.
- Type in afp://ispace.gac.edu and press return.
- Authenticate with your 鶹Ƶ credentials.
- Double click on the corresponding backup as listed in the Apple_Backups folder.
- You are now ready to restore data from a DeployStudio backup.
User Creation/Restoring Data Using Migration Assistant
Migration Assistant can transfer data from a Mac booted to Target Disk Mode, a DeployStudio backup, or a TimeMachine Backup. If these methods do not work, ask a dutyperson for help restoring using Crashplan.
Follow these steps to restore data using Migration Assistant.
- Log in as admin on the Mac you'd like to transfer data to.
- Mount or connect the datasource as detailed above. Type in the computer password (old computer) to unlock the drive.
- Click Don't Use when presented with the time machine prompt.
- Open Migration Assistant located in the /Applications/Utilities folder or by using Spotlight search.
- Click continue and follow the on screen prompts from Migration Assistant.
- Ignore any FileVault requests by clicking cancel.
- Select the default option, "From a Mac, Time Machine backup, or startup disk" and click Continue.
- Migration Assistant will scan for data sources. Select Macintosh HD and click continue.
- Migration Assistant will then begin scanning the drive to look for user accounts and data to transfer.
- Deselect everything except the user account you'd like to transfer and click continue.
- Set a temporary password for the user account; "changeme" is standard and click continue.
- You'll then be prompted to authorize the transfer using the admin account. Click on "Authorize..." and enter the admin password. Then click continue.
- Migration Assistant will begin transferring data. Depending on how much data is being transferred, Migration Assistant could take anywhere from a few minutes to a few hours.
Step Five: Verify Data Restore
Check to make sure that data restoration method you used has completed successfully. Check bookmarks, Documents, Desktop to verify their data is in place.
Step Six: Install Printers & Update/Install Other Software
- Use Managed Software Center to install the printers.
- Use Managed Software Center to install software that the user wants installed. Refer to ticket for specialized software requests.
- Click Updates to make sure all installed software is up to date.
Step Seven: Set up CrashPlan
- Open the CrashPlan app under their user.
- Click Set up Device
- Click Replace Existing
- Click the old computer name.
- Skip File Transfer
- Open System Preferences and choose Security and Privacy.
- Navigate to the Privacy tab, and choose Full Disk Access from the left side panel. Check the box next to CrashPlan and falconhd.
Step Eight: Install iProjection
iProjection is replacing EasyMP, and is currently not on Managed Software Center. Please visit and download the installer for Mac.
- After installation, open iProjection.
- Choose Advanced Connection Mode.
- Check the box to set the selected Connection Mode as default.
- Press OK.
- Connect to the Olin 133 or Olin 124 projector. When prompted to allow Screen Recording in System Settings, select yes. If Privacy Settings do not automatically open, navigate to System Preferences > Security & Privacy > Privacy tab. On the lefthand side panel, click Screen Recording.
- Check the box next to iProjection.
Step Nine: Mac Cascade Letter
Customize (replace the items in bold italic that are placeholders) and print a Mac Existing Employee Letter for each user.
Step Ten: Delivery
Deliver the prepared Mac to the user and assist them with signing into Enterprise Connect.
- Sync their password using the 鶹Ƶ user setting page. If the the domain password will not sync with the computer password. Please try the following instructions:
- Copy the ConvertMobileToLocal.sh script from Macsoft/Tools to the desktop of the user you’d like to convert.
- Open Terminal and run the following command: cd /Users/<theusername>/Desktop where <theusername> is the 鶹Ƶ username of the Mac you’re working on.
- Then, run the following command sudo ./ConvertMobileToLocal.sh Don’t forget the period before the slash.
- Follow the instructions within Terminal. This will be the users current login password.
- Exit the interactive script after it’s completed.
- Click Allow access for contacts, calenders, etc.
- Run the following Terminal Command: pwpolicy -setpolicy canModifyPasswordforSelf=1
- Restart and try the syncing process.
- Make sure Filevault is turned
- Make sure you click store recovery key with MDM.
- Open Enterprise Connect and have them sign in with their 鶹Ƶ username and password.
- When prompted, enter their login password changeme. Enterprise Connect should report the passwords are in sync.
- Answer any additional questions they may have.
Step Eleven: Store Old Equipment
Please give Mike the old laptop once delivery has been completed.
Troubleshooting
Q: Crashplan won't let me log in as the user?
A: Restart the Mac and re-open Crashplan