Case Study · Apple & Mac

Mac setup cut from over two hours to under 30 minutes

How TexArxs rebuilt Jamf Pro for a US retailer's 100 executive Mac devices: sign in and ready for work in under 30 minutes, apps and security included.

  • < 30 min From first sign-in to ready, apps and security included
  • 1 Manual step left in onboarding
  • 6 weeks Delivered, against a 12-week plan
  • 100 Mac devices used by senior leadership

Before and After

What changed Before After
Setup Time per Mac Over 2 hours of IT work Under 30 minutes, automatic
Manual Onboarding Work IT hands-on for every device 1 step: three details
Single Sign-On Unreliable with Entra ID Working with Entra ID
Delivery 12-week plan Done in 6 weeks

Challenge

A major US retailer runs about 100 Mac devices for its CEO, CxOs and senior leadership: the people who can least afford IT friction. Their Jamf Pro environment had built up problems that those users felt directly. Setting up a new Mac still depended on IT, and installing the standard apps alone took more than two hours per device.

Our assessment found twelve issues. The most important were:

  • Unreliable provisioning. Zero-touch enrolment was not giving a dependable out-of-box experience, so every new Mac needed manual work from IT.
  • Sign-in problems. Jamf Connect single sign-on with Microsoft Entra ID was not working reliably.
  • Slow app installs. Installing the standard apps took over 120 minutes per device.
  • Encryption gaps. FileVault was not enforced consistently, and user accounts were created without the correct FileVault ownership.
  • Over-privileged enrolment. Devices enrolled with a full-admin account, against least-privilege principles.
  • A cluttered Jamf Pro. Inactive, duplicated and unscoped policies, old scripts, outdated packages and redundant configuration profiles.
  • No fleet visibility. No consistent patch management, compliance dashboard or regular reporting.

Environment

  • About 100 executive Mac devices managed in Jamf Pro
  • Jamf Connect and Self Service+ for sign-in, with Microsoft Entra ID as the identity provider
  • Standard apps: Google Chrome, Microsoft 365 (Office, Teams, OneDrive), Zoom and Slack

Approach

We took a structured, fix-first approach, delivered remotely in the client’s US Eastern business hours by a named Mac support engineer who knows the environment. The work ran in three phases:

  1. Understand and stabilise. Audit the environment, rebuild automated provisioning, fix single sign-on, harden the enrolment account and restructure app delivery.
  2. Fix and rebuild. Clean up unused objects, rebuild Smart Groups, remove local accounts and enforce encryption.
  3. Manage proactively. Set up patch management, build compliance dashboards and document everything.

Implementation

An Automated Provisioning Flow

  • Devices enrol automatically through Apple Business (formerly Apple Business Manager) and Automated Device Enrollment, and the user must sign in before setup continues.
  • Jamf Setup Manager starts on first boot and shows a clear progress screen.
  • A technician enters just three details: user ID, computer name and department. That is the only manual step.
  • Installomator installs every standard app at the same time, straight from each vendor’s own download source.
  • Jamf Connect creates the user account with the right encryption rights, so the user can unlock the encrypted disk.
  • FileVault switches on automatically, and recovery keys are stored securely.
  • The final touches run on their own: Dock setup, Self Service+, VPN registration and an inventory update.

Two Ways to Hand Over a New Mac

Both run on the same automated flow, so the client can choose per person:

  1. Straight to the employee (zero-touch). The Mac ships from the supplier to the employee’s home or desk, still sealed. They turn it on and sign in with their work account. Every app they need on day one installs on its own, together with the security tools (such as EDR and DLP), and FileVault switches on. In under 30 minutes it is ready for work, with no visit from IT.
  2. Prepared by IT, then handed over. The Mac arrives at the IT team. A technician turns it on, signs in, enters the three details and lets the apps and security tools install. They shut it down and hand it over. The user turns it on, signs in and is ready to work straight away.

Single Sign-On That Works

We resolved the sign-in issues and aligned Jamf Connect with the client’s Microsoft Entra ID setup, so leaders sign in to their Mac with their work account.

A Clean Jamf Pro

We took a full backup first, then removed inactive, unused, duplicated and unscoped objects with the Prune tool and reorganised what remained so it is easier to understand and maintain.

Encryption and Patching Under Control

  • FileVault encryption brought under consistent, managed control
  • macOS updates enforced through a configuration profile
  • Patch management titles configured for reporting
  • A compliance dashboard showing encryption status, macOS versions, patch compliance and device health
  • Monthly reporting

Documentation and Knowledge Transfer

Fixing the environment was only half the job. We also documented it so the client’s team can see how it works:

  • A knowledge base article on Jamf Connect password sync, covering the architecture, workflows, FileVault behaviour at start-up, troubleshooting and common questions.
  • An architecture diagram showing the main components and flows: sign-in through OAuth 2.0 and OpenID Connect, the MDM channel, how FileVault passwords are updated, and password sync without a VPN.

Outcome

  • Ready on first sign-in: a new Mac goes from sealed box to ready for work in under 30 minutes, with every work app and security tool installed automatically. Before, it took more than two hours of IT work per device.
  • One manual step in the whole onboarding process.
  • Working single sign-on through Jamf Connect and Microsoft Entra ID.
  • Encryption set up correctly at enrolment for new devices, and FileVault enforced across the fleet.
  • Least privilege: the enrolment account no longer has full admin rights.
  • A clean, documented platform with dashboards for fleet health, patch compliance and macOS versions, and a defined patching process.
  • Documentation that shows the client’s infrastructure and security team how identity and device management fit together.
  • Delivered in six weeks, half the twelve weeks originally planned.

What This Shows

  • Remote delivery for a US client. Support in US Eastern hours, from a named engineer who knows the environment.
  • Depth in Apple device management. Hands-on work across Jamf Pro, Jamf Connect, identity integration and encryption, not just general IT support.
  • Support that continues. The work did not end with the fixes. Support and improvement carry on beyond the first six weeks.

Facing something similar? Let’s talk.

Talk to TexArxs

Our work

All Case Studies