Migrating to AUTH/MECM
Overview
A checklist and guide for migrating devices into auth.tamu.edu. All steps here will be performed by the ISO team.
Related Documents
These documents are essential to operating within the MECM environment and should be provided to the UNIT team for review.
[MECM Procedural documentation in development
Prerequisites
- The discovery process has been completed
- The Unit OU name
- The OU description
- A list of of admin user accounts
MECM Onboarding Checklist
Step 1: AUTH Domain Delegation
- Create Workstation Management OU
- Path:
AUTH.TAMU.EDU\Workstation Management\[Unit OU Name]
- Path:
- Create OU Security Group
- Name:
OUSG-[SCOPE] - Membership: Initial admin NetIDs
- Name:
- Delegate OU Permissions (to
OUSG-[SCOPE]group)- Generate resultant set of policies (logging)
- Generate resultant set of policies (planning)
- Create/Delete Computer Objects
- Create/Delete Group Objects
- Create/Delete Printer Objects
- Read/Write
gPOptions(allows blocking inheritance) - Full control of Descendant
msFVE-RecoveryInformationObjects (BitLocker access) - Full Control of Descendant Computer Objects
- Read/Write
gPLink(link group policies) - LAPS password access
Step 2: MECM Delegation
- MECM Delegation Process
- Create MECM Security Scope
- Name:
[SCOPE] - Description:
[Description]
- Name:
- Organize Devices
- Folder:
Devices\[SCOPE]
- Folder:
- Create Primary Device Collection
- Name:
_Scope-[SCOPE]-Workstation - Set Dynamic membership rules:
- Rule #1: Devices in the AUTH workstation management OU
- Rule #2: Devices tagged in Intune with
[SCOPE]
- Name:
- Delegate RBAC
- Assign MECM RBAC with:
- Security Scope:
[SCOPE] - Collection:
_Scope-[SCOPE]-Workstation - Role: Customized or least-privilege admin role
- Security Scope:
- Assign MECM RBAC with:
- Configure Optional Services
- OS Deployment Task Sequence (PXE / USB)
- Monthly Update Cycle Opt-In
- Set weekly maintenance window
- Confirm monthly patch release cadence
- Create MECM Security Scope