Loading...
centrexIT
Knowledge Center

Maia Biotechnology Windows Endpoint Provisioning

KB00003720
Shawn Lindell Work Instruction 1 min
PublishedShawn Lindellv2.0
Published Sep 30, 2025Expires Jan 9, 2027

Standard Make & Model: Lenovo (model N/A)

Alternate Make & Model: Dell (model N/A)

Default naming schema: MAIA-(SN)

Domain: Azure/Entra

Immy.bot Configuration: Configured, Ready to Deploy to skip Out-Of-Box-Experience+Software and localuser configuration. Ref: KB00038353

NOTE: If a user has an Exchange Online license, we will not be able to Azure join them on their new laptop. They will need a Business premium license that offers device management features.

  • Device join to MAIA’s Entra Tenant

  • The device has been renamed MAIA-SerialNumber

  • The user is signed in with user M365 Credentials

  • User’s Office apps, Outlook, Teams, and OneDrive are signed in

  • OneDrive Backup is enabled for Desktop, Documents, and Pictures

  • Umbrella module configured with OrgInfo.json

  • Default Apps Set: Mail: Outlook, Browser: Chrome:, PDF: Adobe Reader

  • Apps and Utilities loaded onto the device: per client WI

  • N-Able Windows Agent Take Control Tested

  • Device and drivers have been updated (Windows Update, Lenovo Vantage/System Update)

  • Perform Mic and Camera check with a Teams test call

  • Perform quality checks against the manager’s request and the provisioning Work instruction

  • Create “localuser” account with the credentials in 1Password.

  • Decline Windows 11 Upgrades

  • Add user to the system via Azure Active Directory

  • Windows Settings>Search “Work and School”> Sign into a work account

  • Click “Connect”

  • Select “Join this device to “Azure Active Directory”

 

  • Sign in with the user’s credentials.

Description

  • Agree to join the organization

Description

  • Navigate to the start menu and select Switch user

  • Sign in with the user Microsoft 365 e-mail and password

  • The user will likely be required to set up a pin, face ID, or fingerprint.

  • Users can forgo biometrics but must have a pin. usually 6 digits.

  • Setup the user profile

  • Sign in to Outlook, pin it to the taskbar

Description

  • When presented with this screen, uncheck the box that “Allows this organization to manage my device” as it tends to cause authentication issues with TPM.

Description

  • Set up Teams, perform a test call to ensure the camera and mic work and that no network authentication message pops up during the user’s first meeting.

Description

  • Setup OneDrive from taskbar shortcut

Description

  • OneDrive Backup is enabled for Desktop, Documents, and Pictures

  • Set App defaults within Settings

  • Uninstall bloatware

  • Clean up the taskbar and Start menu bloat

  • Remove Widgets, CoPilot, Shrink the Search menu

  • Pinned apps: File Explorer, Google Chrome, Outlook, Teams

  • Set system sleep times 15-30-30-1Hr.

  • Run All Lenovo Vantage updates

  • All Windows updates/patches

  • Ship the device using the MAIA FedEx account info included in the PC Provisioning request. Radu generally wants $1000 Insurance, FedEx Home Delivery, and a Direct Signature Required.

  • Radu will provide the shipping address for the user

  • Confirm tracking in the Provisioning ticket and with Radu directly in the public channel