Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Using "Configautomation" To Wipe Checkout iOS Devices and Deploy Standard Staff Config

Jamf
October 23, 2018

Using "Configautomation" To Wipe Checkout iOS Devices and Deploy Standard Staff Config

Presentation from JNUC 2018, the world's largest rally of Apple IT administrators.

Session:
Using "Configautomation" To Wipe Checkout iOS Devices and Deploy Standard Staff Config

Presented by:
Christopher Sweet, Iowa State University

View all session slides, recordings and more at https://www.jamf.com/events/jamf-nation-user-conference/2018/.

Jamf

October 23, 2018
Tweet

More Decks by Jamf

Other Decks in Technology

Transcript

  1. © JAMF Software, LLC Using Configautomation To Wipe Checkout iOS

    Devices and Deploy Standard Staff Config Presentation agenda: Obtain necessary software Create certificate and key Create workflow Demonstrate workflow
  2. © JAMF Software, LLC Problem • An easy way to

    check out iPads to patrons and wipe device when returned Solution • Resetting and managing the iPads via a Mac mini, workflows, commands, Apple Business Manager/Apple School Manager, VPP and Jamf Pro Server
  3. © JAMF Software, LLC Risks • Unwanted access to personal

    data if a patron fails to delete cookies, clear caches, sign out their Apple ID, remove Apps, Movies and Music
  4. © JAMF Software, LLC Process and success • Configautomation: Sal

    Soghoian http:// www.configautomation.com • Trial and error, started with 10 iPads a year ago, now checking out 40 iPads
  5. © JAMF Software, LLC How I ended up here on

    stage • This is my 6th JNUC • Not much being said about Configautomation • Figured I would evangelize the process • Process works great for checkout scenarios & initial setup for deployment!
  6. © JAMF Software, LLC Requirements • A machine running macOS

    and Apple Configurator 2 • USB hub if doing multiple devices at once • Zip files from http://www.configautomation.com • Jamf Pro Server • Apple Business Manager/Apple School Manager enrolled devices
  7. © JAMF Software, LLC Software downloads • Apple Configurator 2

    • “Attached” Workflow Installer (https:// configautomation.com/attach-actions- installer.zip) • Action to access Apple Business Manager/ Apple School Manager (https:// configautomation.com/DepSPCInstaller.zip)
  8. © JAMF Software, LLC Automation Tools Install the automation tools

    from Apple Configurator 2 located in the File menu
  9. © JAMF Software, LLC Create Certificate and Private Key •

    Apple Configurator 2 menu, Preferences • “+” then fill out fields • Gear, Export Supervision Identity Use Apple Configurator 2 (AC2)
  10. © JAMF Software, LLC Prepare Automated Enrollment Wi-Fi Profile •

    Apple Configurator 2, File, New Profile, Wi-Fi • Under Wi-Fi, Enter SSID
  11. © JAMF Software, LLC Workflow to Wipe Devices • Open

    file attachment-workflow.workflow (located?) • Remove steps between “Begin Attached Workflow” and “End Attached Workflow” • Add “Erase Devices” • Add “Prepare Devices using Automated Enrollment”
  12. © JAMF Software, LLC Configure Erase and Prepare actions •

    .crt is the Certificate • .der is the private key Preparing Erase Devices action Preparing the Prepare action • Select the already created Wi-Fi profile
  13. © JAMF Software, LLC auto-attachment command • attachment-workflow.workflow path should

    be set to ~/Library/Workflows/ attachment-workflow.workflow) Visually verify to double-check
  14. © JAMF Software, LLC Running the workflow • Launch Terminal.app

    • Go to the Script Menu, Select Activate Chosen Attachment Command • Go to “~/Library/Workflows” and select the auto-attachment.command Terminal
  15. © JAMF Software, LLC Synopsis • Get and install tools

    and files • Create files for actions • Edit workflow • Launch command • Plug in devices
  16. © JAMF Software, LLC Gotcha’s and Showstoppers • iTunes auto-sync

    • Computer Trust relationship • Sign-out of AppleID (MFA) • Skip setup steps checked in Jamf Pro Server Gotcha’s
  17. © JAMF Software, LLC Caveats • Will wipe whatever iOS

    device is plugged into the USB hub • Cycling power on hub • Plugging/relaunching script Indescriminate
  18. © JAMF Software, LLC Caveats • Don’t upgrade the iOS

    past version supported by your Jamf Pro Server • Can result in unskippable screens iOS Upgrades
  19. © JAMF Software, LLC Caveats • Major macOS upgrades can

    result in AC2 automation tools needing to be reinstalled • Test after upgrading macOS upgrades
  20. © JAMF Software, LLC Additional Use-case scenarios • Not only

    for checkout • Prep-work for staff deployment iOS devices • Launch command script, plug-in, disconnect, done!
  21. © JAMF Software, LLC One last thing Check out Sal

    Soghoian’s session about Automator • Wednesday, Oct. 24 at 11:15 AM - 12:00 PM • Greenway Ballroom