MacBook Install Guide for Vogelwarte Devices
This setup works for macOS Tahoe
Manual Setup (until we have a MDM)
Prerequisites:
You need to be in Sempach at a staging docking station to have access to the internal network
Step 1: Out-Of-The-Box Setup Guide
Follow the setup guide and create a user Scientific IT (UNIX username "scientific.it") with the password from Bitwarden ("Mac Laptop Admin Login"). Disable Location Services, disable Siri, disable analytics, skip Touch ID, skip Apple Account.
Step 2: Install Updates or update to macOS Tahoe
Go to system settings and check for updates. So far, M4 devices were still shipped with macOS Sequoia 15. Thus an update to macOS Tahoe is necessary. Proceed with said update.
Step 3: Install Sophos and FortiVPN
Conect to smb://vogelwarte.ch/dfs and navigate to Teamwork > IT and copy the FortiVPN online installer & SophosInstall folder to the machine. Install Sophos. During the installation you will be prompted to enter the password multiple times to enable extensions. Additionally you need Full Disk Access for multiple Sophos services. In Sophos Endpoint Self Help under Prerequisits, you find an icon to drag & drop to the Full Disk Access Setting in macOS which makes this setup easier.
Next, install FortiVPN. The configuration of FortiVPN is done in a later step.
Step 4: Install M365 Apps
Download Office Apps from microsoft.com. You can temporary login with your Vogelwarte account. Install pending updates with the Microsoft AutoUpdate app. Do not open the apps yet.
Step 4: Install Printers
Step 4: Connect to AD
Unlock and double click on Active Directory in the service list. Enter the following