Skip to main content

Migrating to AUTH/MECM

Overview

A checklist and guide for migrating devices into auth.tamu.edu. All steps here will be performed by the ISO team.


These documents are essential to operating within the MECM environment and should be provided to the UNIT team for review.

[MECM Procedural documentation in development


Prerequisites

  • The discovery process has been completed
  • The Unit OU name
  • The OU description
  • A list of of admin user accounts

MECM Onboarding Checklist

Step 1: AUTH Domain Delegation

  • Create Workstation Management OU
    • Path: AUTH.TAMU.EDU\Workstation Management\[Unit OU Name]
  • Create OU Security Group
    • Name: OUSG-[SCOPE]
    • Membership: Initial admin NetIDs
  • Delegate OU Permissions (to OUSG-[SCOPE] group)
    • Generate resultant set of policies (logging)
    • Generate resultant set of policies (planning)
    • Create/Delete Computer Objects
    • Create/Delete Group Objects
    • Create/Delete Printer Objects
    • Read/Write gPOptions (allows blocking inheritance)
    • Full control of Descendant msFVE-RecoveryInformation Objects (BitLocker access)
    • Full Control of Descendant Computer Objects
    • Read/Write gPLink (link group policies)
    • LAPS password access

Step 2: MECM Delegation

  • MECM Delegation Process
    • Create MECM Security Scope
      • Name: [SCOPE]
      • Description: [Description]
    • Organize Devices
      • Folder: Devices\[SCOPE]
    • Create Primary Device Collection
      • Name: _Scope-[SCOPE]-Workstation
      • Set Dynamic membership rules:
        • Rule #1: Devices in the AUTH workstation management OU
        • Rule #2: Devices tagged in Intune with [SCOPE]
    • Delegate RBAC
      • Assign MECM RBAC with:
        • Security Scope: [SCOPE]
        • Collection: _Scope-[SCOPE]-Workstation
        • Role: Customized or least-privilege admin role
    • Configure Optional Services
      • OS Deployment Task Sequence (PXE / USB)
      • Monthly Update Cycle Opt-In
        • Set weekly maintenance window
        • Confirm monthly patch release cadence