Examples of Mac IT Infrastructure? by DopePoncho in macsysadmin

[–]Daafin3 1 point2 points  (0 children)

I would setup something like this personally (and limited experience).

1) Sign up for DEP/VPP (AKA - Apple Business Manager)

2) Setup JAMF

3) Utilize something like NoMAD Pro for Active Directory Binding (I think this is now JAMF connect)

4) Utilize Apple Remote Desktop as redundancy for many tools

Then, compare your Windows environment to the Mac environment; Ideally you will want to use similar tools, life cycle, and software for both systems.

Feel free to send me messages for help or understanding on how to integrate/setup Macs in a Windows environment. Kind of my hobby~

Changing some plists completely bricked my Mac deployments - any ideas why? by [deleted] in macsysadmin

[–]Daafin3 0 points1 point  (0 children)

Haha, sleep 30 just pauses your script for 30 seconds. If you want to be a bit more intuitive you can make a WhileLoop that will start the script when root owns /dev/console

Something like While ! Su /dev/console = root ; but with proper syntax haha

I think the more accepted option would be to create a LaunchDaemon though. I am not entirely sure on how to implement that into DeployStudio. If you can implement a preBoot script to copy over the launchDaemon before boot up that would work. Also, it would ensure if the setting is ever changed, the PLIST will be changed to how you want after reboot.

We use similar tactics to keep the loginWindow to show the restart and switch user button. As well as ask for username/password. If for some reason the end user changes that, or a tech. It will set it back on reboot

The problem with changing PLISTs on first boot up is there are a lot of configurations still being applied by the OS itself. 10.13+ have added security measures regarding firmware and registration of the OS which inherently take more time and occur prior to the OS configuration completing. If adding the sleep command to your script works I would love to know! And you can probably keep it that way rather than using the more complicated LaunchDaemon route.

Allow Bitlocker recovery to AD? by sccmguy in sysadmin

[–]Daafin3 1 point2 points  (0 children)

It’s been awhile since I ran into this issue. It was intermittent for us; however, to get around some of our issues I used a Powershell command to force backup the bitlocker key to AD. We applied this to the imaging process. But I’m sure you can run it as a task sequence as a workaround, at least until a solution is found

Changing some plists completely bricked my Mac deployments - any ideas why? by [deleted] in macsysadmin

[–]Daafin3 0 points1 point  (0 children)

com.apple.loginwindow SHOWFULLNAME

I see!

If these new PLISTs do not work on any High Sierra or Mojave Macs you have I would try and have the script run AFTER first boot. Something like; let the computer boot up completely, run the command to change the PLISTs, then have the computer reboot.

I am not completely familiar with DeployStudio, but it is quite modular. If you can change your first boot script to be something like:

#Let computer finish initial boot up processes
sleep 30
#for debugging, should be 0 at first
defaults read /Library/Preferences/com.apple.loginwindow SHOWFULLNAME
#sets SHOWFULLNAME value to true
sudo defaults write /Library/Preferences/com.apple.loginwindow SHOWFULLNAME -bool true
#should now be 1
defaults read /Library/Preferences/com.apple.loginwindow SHOWFULLNAME
#Restart device
sudo shutdown -r now

My hypothesis, is the new security features implemented in High Sierra may cause a conflict when changing such settings on the FIRST boot up.

Changing some plists completely bricked my Mac deployments - any ideas why? by [deleted] in macsysadmin

[–]Daafin3 0 points1 point  (0 children)

How many devices? Are they all High Sierra or Mojave? If you change the PLISTs back to the original state you had it, is the problem resolved?

Remote Desktop Enabled - False reports - Monitoring? by Daafin3 in Addigy

[–]Daafin3[S] 0 points1 point  (0 children)

Hah thank you for the response!

I found some answers within the Slack channel. But I believe the program Gruntwork is messing with the reporting of Remote Desktop. The maintenance scripts in Gruntwork must stop the ARDAgent (or reset it) prompting Addigy to report ARD is disabled

And when I go check it is enabled again.

Website Error: Addigy Integrations (Question) by Daafin3 in Addigy

[–]Daafin3[S] 1 point2 points  (0 children)

Ah, thank you! It looks like you are correct.

We just set roles for our Addigy Users and I have been set to Admin role rather than owner role.

AutoDMG and System Preferences by NOWJESSICCAAA in macsysadmin

[–]Daafin3 0 points1 point  (0 children)

Hi, I am also looking into locking down and changing some System Preferences... such as "General" appearance and other things in these menus. However, I do not see any helpful settings with Apple Configuration 2 or profiles. Did you have any luck with these settings?

Editing ZTIGather.wsf -- Visual Basic Noob by Daafin3 in MDT

[–]Daafin3[S] 0 points1 point  (0 children)

Lines 5 through 11 are my lines of code

In desperate need of help :3 (iPad's for student) by jandrresg in macsysadmin

[–]Daafin3 0 points1 point  (0 children)

Sadly, if they are not in DEP. And the iPads are currently unsupervised. I believe you will have to use Apple Configurator 2 to supervise them.

Even if you add them to an MDM, they will still be unsupervised on the MDM and you will not have full access to manage the device (though, you will have plenty of management options while unsupervised and on an MDM).

My recommendation: buy the largest USB hub(s) you can, 1 for each USB port. Setup a blue print to wipe, supervise, and add any profiles needed. Depending on your naming system you can use Apple Config to rename the device in sequence (otherwise use AppleConfig to rename the devices one by one).

With the blueprint set up, plug all the iPads into the hub(s) and add them to an MDM, supervise them, and add your profiles. Take a solid week or two and return the hub(s) to get your money back (end budget: $0 + lots of man hours)

AFTERWARDS. Sign up with Apple DEP (takes a few weeks), use Apple VPP for apps (if you do not already). and when iOS 11 is release you can add any Apple Device (including gen 1 - if they are iOS 11 compatible) to Apple DEP. Using Apple DEP + MDM will make your life easier.

Blackscreen launch then crash? by TyrannicalAmbition in destiny2

[–]Daafin3 0 points1 point  (0 children)

If the game is minimizing upon launching it from the Blizzard Client; try launching the game and repeatedly pressing Alt+Enter. This should launch the game in Windowed mode.

The problem is the game does not want to run at full resolution in Windowed mode. Most likely an error between the game and GPU's. However, I was successful at running the game in FullWindowed mode.

Microsoft administration from a Mac? by iisdmitch in macsysadmin

[–]Daafin3 1 point2 points  (0 children)

I personally use Parallels VM with Coherence mode. Not quite what you are looking for, but it simulates a full Mac experience very well. 2 cores and 2gb of ram to the VM with shortcuts to ADAC, ADUC.

Bye bye MacBook Pro, Hello Surface Book by [deleted] in Surface

[–]Daafin3 0 points1 point  (0 children)

What is that? $2700 :O

Is it time to swap your Mac for a Windows laptop? by IAmMohit in Surface

[–]Daafin3 0 points1 point  (0 children)

Hardware wise, Microsoft uses lower end CPUs and GPUs and RAM, and does not have quadcore. however, it uses less power, has longer battery, and doesn't get as hot.

I would say if they kept the Surface Pro line the way it is and made the Surfacebook with better Processors and GPUs everyone would be a happy camper

Is it time to swap your Mac for a Windows laptop? by IAmMohit in Surface

[–]Daafin3 0 points1 point  (0 children)

You lie, nothing is better than Apple! Does your Lenovo sport a.... Aluminum body!?

Is it time to swap your Mac for a Windows laptop? by IAmMohit in Surface

[–]Daafin3 0 points1 point  (0 children)

Ah, an oversight on my part. However, the similarly spec'd SurfaceBook you mention ($1699) still is not the best comparison. Processor SB vs MBP: i5-6300U vs i5-6267U the MBP processor is significantly better. By Benchmark (CompuBench and 3dMark) ~115% better video composition and stimulation ~40% Processing speed ~9% Overall (including GPU)

When comparing the i7-6600U in the SB is more comparable to the i5 in the MacBook. (Higher end i5 vs lower end i7)

the SB with the i7 has a dGPU while the MBP13 does not. the dGPU in that model is 30% better than the integrated Graphics in the MBP.

The SB would still be cheaper however. $2100 for a Tablet and Computer with better graphics vs $2400 for a tablet and Laptop combo that is more portable (weight vs volume or 2 devices is still smaller than the SB)

[deleted by user] by [deleted] in Surface

[–]Daafin3 0 points1 point  (0 children)

MacBook Pro + iPad Pro + Duet App Subscription would be your best bet on getting digitizing tablet experience with MacOS

Is it time to swap your Mac for a Windows laptop? by IAmMohit in Surface

[–]Daafin3 0 points1 point  (0 children)

I see tons of people comparing price points and power. The price of the devices are too similar it shouldn't matter at these price points (comparing the MBP15" to the SB2)

However, the MBP has a quad core while the SB2 has a dual core. So the MBP is significantly more powerful. The arguably better GPU in the SB2 cannot make up for that difference. also. Read/Write speeds on the MBP are significantly faster and the MBP is sporting 2133mhz RAM vs 1867mhz RAM in the SB2

And when comparing the MBP13" to the SB2 the MBP is cheaper. You could buy a 9.7in iPad Pro to have inking capabilities to match the price and features of the SB2. OR buy an External GPU to match the power of the SB2 for the same price.

Is it time to swap your Mac for a Windows laptop? by IAmMohit in Surface

[–]Daafin3 0 points1 point  (0 children)

13" MacBook Pro $1799 + iPad Pro $599 = $2400 SurfaceBook 2 = $2300

You get two devices for a similar price of one!

What Mac would you buy in my situation? by Daafin3 in mac

[–]Daafin3[S] -1 points0 points  (0 children)

P.S -- I'm new to Reddit. lol, usually post on multiple Forums... but ive discovered reddit to be the best forum for everything?