PCI - Mac Imaging and Deployment

Overview of deploying Apple macOS devices in PCI
  • Assign device to PCI MDM in ASM
  • Boot device and enroll in WS1
  • Log in with "localadmin"
  • Connect to adminvpn
  • Run BigFix baseline
  • Run certificate enrollment
    • In a non-Safari browser sign in using AD credentials:  https://pci-one-ca-01.pci.wisc.edu/certsrv
      • Request a certificate, advanced certificate request
      • Open Keychain, select Keychain Access in the top menu, select Certificate Assistant, and then Request a Certificate From a Certificate Authority
      • In the menu enter the following
      • Email:  pci-wiscit@doit.wisc.edu
    • Common Name:  WPT-SERIAL aka the computer name
    • Save to disk
    • Open the CSR in a text editor and copy/paste into the Saved Request box in your web browser
    • From the dropdown select DS - Mac Computer
    • Submit
  • Select DER encoded and Download certificate chain
  • Add the full cert chain to Keychain by double-clicking on it but make sure to select the System Keychain
  • Very Important!  When you first try to connect to remotepcs.pci.wisc.edu you will get a permissions popup that GP is trying to access the cert; make sure you select "Always Allow"


Keywords:
pci imaging mac imaging setup new computer new user 
Doc ID:
162578
Owned by:
Collin L. in DoIT DS Critical Infrastructure
Created:
2026-07-13
Updated:
2026-07-30
Sites:
DoIT DS Critical Infrastructure