Workstation Encryption Support Roles and Responsibilities - IT Services / Divisional IT Partners
JAMF
Divisional IT Partners
- Provide Central IT Services a list of AD users to make JAMF Pro Users who will be able to run view recovery keys
- Provide Central IT Services a list of AD users to make JAMF Pro Users who will be able to run compliance reports
Options
- Retrieve recovery keys for their Divisional IT computers from department site within JAMF
- Run compliance reports from JAMF Console
- Audit details surrounding the past retrievals of a recovery keys for a computer
Onboard every computer in their division
- Configure computer with FileVault prerequisites.
- Install the JAMF client, given by Central IT Services, on each computer
Central IT Services Desktop Engineering
- Provide Divisional IT documentation and JAMF client to install
- Create the list of users from Divisional IT in JAMF as JAMF Pro Users, that will be able to run compliance reports and view recovery keys.
Options
- Retrieve recovery keys for any Divisional IT computers from the JAMF console
- Run compliance reports for Divisional IT from JAMF Console
- Audit details surrounding the past retrieval of a recovery keys for a computer
MBAM
Divisional IT Partners
- Link a MBAM GPO to an OU containing their computers that are wanting to be encrypted
- Provide Central IT Services a list of AD users that will be able to run MBAM compliance reports from Internet Explorer
- Provide Central IT Services a list of AD users that will be able to recover BitLocker keys from the Administration and Monitoring Website https://campusmbam.uchicago.edu/helpdesk/
- Provide Central IT Services a list of AD users that will be in charge of manually maintaining approved listings of Divisional IT computers from their assigned Divisional IT security group in AD.
Options
- Retrieve BitLocker keys for their Divisional IT computers from Campus MBAM website
- Run compliance reports from Campus MBAM website
- Audit details surrounding the past retrievals of a BitLocker key for a computer
Onboard every computer in their division
- Configure computer with BitLocker prerequisites.
- Install the MBAM client, given by Central IT Services, on each computer
- Maintain approved listing of every computer as a member into assigned Divisional IT security group in AD.