Configuring the Windows Bulk Provisioning Tool configuration wizard to create a bulk provisioning tool executable

Configure the Windows Bulk Provisioning Tool executable with a client management tool (CMT).

About this task

Notes:
  • Ensure that the Windows device that is used to create the OS image or the SelfExtractingOA.exe executable file with the Windows Bulk Provisioning Tool is not MDM-enrolled.
  • Administrators must avoid enrolling the same device that was used to create the SelfExtractingOA.exe executable file with the Windows Bulk Provisioning Tool.
The Bulk Provisioning Tool Configuration wizard is automatically started by the Windows Bulk Provisioning Tool.

Procedure

  1. Read the instructions and click Continue.
  2. Enter the Administrator Username and Password to authenticate with IBM® MaaS360® and click Next.
  3. Configure the following deployment steps and click Next.
    • Choose configuration type
      The configuration method that you want to use to configure the Bulk Provisioning Tool. Choose the Export bulk enrollment executable method.
    • Device Addition Mode
      By default the device is onboarded as an MDM-managed device. Clear the MDM checkbox to manage device without MDM.
      Note: This setting is available if the Mixed Mode service is enabled. Contact customer support to enable the Mixed Mode service.
    • Enable end user authentication
      Applies to Windows devices that are bulk enrolled with unified user authentication. By default, this setting is enabled. During onboarding users are authenticated against one of the following user authentication types: MaaS360, AD/LDAP, Azure, or an identity provider (Okta, PingIdentity, Azure, other third-party providers). If the user closes the prompt, the user is prompted again in an hour to authenticate. Authenticated user's profile is only added to device.
    • Enter end user email address for enrollment
      The email address that is used for association when the image is deployed to managed devices.
      Attention: All devices are onboarded to MaaS360 with this email address.
    • Choose end user computer account
      The user account type (account used to log in to the machine) for enrolling the managed device.
      • New Local User
        Use this option if you are deploying the executable file to a new local machine. The device is enrolled when the new local user is created and the user logs in to the device for the first time. If the user does not have administrative access rights on the machine, the enrollment is not completed.
      • New Domain User
        Use this option if you are deploying the executable file to a machine that is connected to the Azure Cloud or to an on-premises Active Directory domain. The device is enrolled when the new domain user is created and the user logs in to the device for the first time. If the user does not have administrative access rights on the machine, the enrollment is not completed.
      • Existing User
        Use this option to install the executable on the device that the user is logged in to. If the user does not have administrative access rights on the machine, the enrollment is not completed.
    • Choose number of devices for onboarding
      Select the number of devices that you want to enroll into the IBM MaaS360 Portal.
      Number of devices Estimated enrollment times
      Fewer than 10 devices Device enrollment is immediate.
      11 - 100 devices Device enrollment occurs over a period of 10 minutes.
      101 - 500 devices Device enrollment occurs over a period of 30 minutes.
      501 - 1000 devices Device enrollment occurs over a period of an hour.
      More than 1000 devices Device enrollment occurs over a period of 2 hours.
  4. Accept the End User License Agreement for all users that you want to automatically enroll when the image is deployed to devices and click Next.
  5. Click Finish.

Results

A self-extractable executable is added on the desktop of the Windows machine.

The Windows Bulk Provisioning Tool configuration wizard setup is complete and the user is notified that device enrollment will occur over the period of time that was selected in step 3. You can now copy the executable file to the Windows devices that you want to bulk enroll.

Important: It is recommended to assign the enrolled devices that are configured under Enter end user email address for enrollment field to the user account or relevant user accounts as per your requirement in the IBM MaaS360 Portal. For more information, see Associating users with bulk enrolled Windows devices.