RYI New User Creation Steps:
Section titled “RYI New User Creation Steps:”- Login to M365 and verify there is a Microsoft 365 Premium License
- If there is no license please reach out to Dylan Quiros.
- If Dylan Quiros is not available to add licenses, please reach out to the Service Desk Leads.
- Once there is a free license move on to user account setup
- Launch the SP admin center: https://ryanyoung-admin.sharepoint.com/_
- Select sites and export all sites:
- Send Sandra the CSV and request she highlight every site/team that the user will be a part of.
User Account setup
Section titled “User Account setup”- Login to RYI-DC2
- Launch Active Directory
- Expand Ryan Young OU
- Right click Users, and create new user
- Input all the required information in to AD (Found in the User Spec form)
- When selecting a user name. Please use the user’s first name.
- Click next, and enter the users password.
- Be sure to check “User must change password at next logon”
- Click Next and Finished
- Fill out the address field with the information in the user spec form
- Under the user account tab please select “Password Never Expires”
- Under the General Tab Fill out the following: (If given on the form)
- Office
- Telephone Number
- Website (If applicable)
- Under the Organization Tab fill out the following (If given on the form)
- Job Title
- Department
- Company
- Manager
- Launch PowerShell “As Administrator”
- Run the command below to force a delta sync to Azure:
- Import-Module ADSync
- Start-ADSyncSyncCycle -PolicyType Delta
- Verify the account has been sync’d, and is now showing with in M365
- Once the account is in showing with in M365 licenses the account
- Setup Distribution groups as requested in the user spec form.
- Once Sandra has sent over the excel file with the requested sites/teams the user needs to be a part of, open the user and select “manage groups”
- Begin adding user to each security group/site (the site/team name will have the same name as the security group)
- In an Encrypted email, please email the POC the username and password for the new account
- Reach out Sandra to schedule time to remote provision the End-Point
End-Point Provisioning (See KB00002320 for further details)
Section titled “End-Point Provisioning (See KB00002320 for further details)”- Login to the laptop using local admin account
- If account is not “Localuser” Sandra will be able to Provide Creds
- When provisioning the End-Point for the new employee verify the following Standard applications have been installed
- Add PC into Intune and confirm it is compliant with all policies
- Any connection VPN (vpn.ryan-young.com)
- OneDrive
- Zoom Meeting launcher
- Google Chrome (set as Default)
- Add the computer to the domain
- Remove Add-on Applications (Bloatware)
- Clean up task bar, and pin only office applications
- Clean up start menu and have production application (Work Apps)
- Remove Cortona Task Button
- Add user as local admin
- Once setup of the End-Point has been completed. Add the new employee to the following group in Azure AD
- MFA-VPN
Other Setup Requirements:
Section titled “Other Setup Requirements:”- Setup scan to OneDrive:
- Login into the “Kyocera OneDrive Scan Account” (creds in pwstate - DO NOT MFA)
- Launch OneDrive and navigate to the scans folder
- Open Company Scans and create a folder with the user’s full name.
- Share the folder to the newly created user.