Playbook: Device Refresh / Back to School

Step into the 'Device Refresh' Playbook, your go-to resource for handling large-scale device re-enrollments. Suitable for any organization, this playbook simplifies the process from device auditing to post-enrollment support. Discover how to utilize FileWave's powerful features for automation, security, and effective communication. With this playbook, achieving efficient device management has never been easier.

Back to School / Device Refresh Introduction

Introduction

computers.jpgAs we head into the fall, many organizations find it's a prime time to refresh, replace, and (re)Enroll devices. Whether you're an academic institution preparing for a new school year or a business updating your technology for the next fiscal year, the task of managing, replacing, and (re)Enrolling devices is a significant one.

With FileWave, our comprehensive toolsets allow you to streamline these projects and ensure a smooth transition. Our system is designed to be efficient, effective, and user-friendly, regardless of your organization's industry. Here are some best practices we recommend for device (re)Enrollment/replacement that will help make your project a success:

Considering the above practices and how they can/should apply to your organization will ensure a smooth and efficient device refresh and (re)Enrollment process for your organization. And FileWave's features will help you here as well, but keep in mind...you don't have to go it alone!  Our Professional Services team has years and years of experience, and we'd be happy to help you with your project at quite reasonable rates.  You can reach our team at professional.services@filewave.com.

Preparing for (re)Enrollment

Lincoln axe.jpg

Preparation is the difference between a smooth device refresh and a long week of avoidable surprises. Before the project starts, confirm what needs to be collected, what needs to be deployed, and how each device should be assigned when it comes back online.

Use the questions below as a planning checklist, and look for places where FileWave can remove manual work from the process.

Device reclamation

Step one of a refresh is often retrieving devices that are already in the field. If that applies to your project, decide whether you need to know who returned each device, where it came from, or which devices must be handled differently.

Example: Brian is retrieving and reassigning all iPads in his district. Two-thirds of the devices will be wiped, updated, and re-enrolled for new users. The remaining third are at the end of a two-year lease and must be returned to the leasing company.

Brian plans an on-site student return at three locations, with a technician receiving devices at each site. His team could record each serial number or asset tag and compare it against the lease spreadsheet, but that would be slow and easy to get wrong.

Because the return serial numbers are known, Brian can create a FileWave custom field called Return? before collection starts and populate it from the spreadsheet. He can then assign custom wallpapers ahead of return, such as a yellow lock screen background, so technicians can see immediately which pile each device belongs in.

Another example: Emily is replacing all Windows devices in the Finance department. Because Department is already tracked as a custom field in FileWave, she uses that list as her starting point and adds a true/false custom field to track device return. As each device is returned, technicians can look it up quickly in FileWave Anywhere by asset tag and update the field from False to True.

Every retrieval project is different, but the same principle applies: use the data FileWave already has, or add a simple custom field before the project starts, so the collection process is faster and easier to report on.

Content

If devices are entering or re-entering the environment, they will need software, configurations, restrictions, and utilities. In FileWave terms, that means filesets and assignments. Before enrollment day, confirm the content is ready.

Pre-assigning content

You can pre-assign content for FileWave managed devices before those devices are enrolled. Devices can match on identifiers such as serial number, MAC address, or device name. That means you can prepare groups, custom fields, and assignments with a CSV import before the first device is unpacked.

Practically, this can remove a lot of hands-on staging. If the data is ready and the assignments are in place, users can unbox devices and FileWave can apply the planned content as the devices enroll.

Documentation and process

Write down the plan and share it with the people helping you. Anything that is not documented becomes a question during the rollout.

This is not complicated work, but it punishes vague planning. The more you can decide before the refresh starts, the less you will have to improvise when the room is full of devices.

During (re)Enrollment

The actual (re)Enrollment phase is where the rubber meets the road regarding your planning effectiveness.  No planning is ever perfect, but the more prepared you are, the more successful you are going to be.

During the enrollment and (re)Enrollment phase, the process becomes more hands-on as devices are reset, reconfigured, unboxed, assigned, and redistributed.  That is a lot of steps, but this doesn't mean that the task has to be overwhelming or complicated. With FileWave, you can utilize a range of tools and features to make the (re)Enrollment process smooth and efficient, and we have a list of best practices for you to follow too.

Start Small

Your process was written as 1) Unbox, 2) Assign Asset Tag, 3) Affix Tag, 4) Put device in case.  But you find out with your first batch of devices that the user needs to read the asset tag in a later step, but they can't see it because of the case being in the way.  Now, do you want to find that out with a 500 students in the room, or 5?  It is by far best to approach the day in small batches, and scale up as the system is proven effective.

Employ Efficient (re)Enrollment

Once your system is proven, batching or grouping (re)Enrollment is an effective way to manage the process without becoming overwhelmed. FileWave provides capabilities to organize devices into logical groups based on your organization's needs, such as by department, device type, or user role. This allows for batch operations, enabling a more organized and efficient (re)Enrollment process.

Don't Bite of More than You Can Chew

I have 5000 devices, surely I can enroll them all at once, no?  No.  There are many considerations to the enrollment process.  Some are physical...for instance, how many boxes can actually be opened by 3 people in 10 minutes?  But others are more subtle.  For instance, enrolling Apple Devices concurrently means a lot of requests going to Apple at the same time, and there could be processing bottlenecks both on your local server and in the cloud.  And the thing everyone forgets about is the actual network itself...can it handle all of that traffic at the same time? 

nick-abrams-FTKfX3xZIcc-unsplash.jpgIn most environments, there is a natural "upper limit" to enrollment concurrency that you don't want to go beyond.  So, start small, get bigger until you run into an issue, and then back off a bit to a comfortable pace.  Slow and steady wins the race!

Device Preparation

Taking a cue from our previous section on 'Preparing for Enrollment', remember to reset devices to factory settings before initiating (re)Enrollment. This will ensure that any residual data or settings from previous users do not interfere with the new user experience.  For new devices, make sure to consider the physical steps of unboxing, dealing with recycling, affixing asset tags, and even the ability to plug the device in. (And of course, you can use FileWave to send "wipe" commands to devices in preparation)

Automate Where Possible

FileWave's automation capabilities can significantly reduce the time and effort spent on (re)Enrollment tasks. Here are some areas where automation can be beneficial:

Monitor Progress

FileWave's device monitoring features allow you to keep track of the (re)Enrollment progress. Use custom fields to mark devices as "(re)Enrolled" or use FileWave's dashboard to monitor device status in real time. This can help identify any issues early on and allow for quick resolution.

Remember, the goal is to make the (re)Enrollment process as seamless as possible for both your IT team and the end-users. With careful planning, efficient batch processing, and the extensive use of automation, FileWave can help you achieve this.

Manufacturer Specific Considerations

Manufacturer Specific Considerations

Apple Specific Considerations

FileWave loves Apple, and so do our customers.  If you happen to be one of the organizations that have chosen to incorporate Apple devices into their infrastructure, from iPads to MacBooks, here are some crucial considerations for a successful refresh and (re)Enrollment:

The Apple Program Considerations

You no doubt already know about the various Apple Programs, such as ABM/ASM/VPP/DEP/MDM and even APN.  Each of these programs, explained below, provide critical roles during device enrollment.  As with everything else (re)enrollment, pre-work is good work, and each program has it's own pre-requisites (and sometimes lead-time).  You'll want to review the specifics of each below:

Apple Push Notification (APN)

Apple Push Notifications are the method by which FileWave initiates communication with your devices through the Apple MDM framework.  Every FileWave server must have a valid APN token assigned, and it must be refreshed annually.  Before any major project, you should make sure your APN has plenty of life left (and you can renew early).

Apple School Manager/Apple Business Manager Integration (ASM/ABM)

Apple School Manager (for educational institutions) and Apple Business Manager (for businesses) are central to the administration of Apple devices. When integrated with FileWave, these platforms provide granular control and enhanced capabilities. They allow you to:

But, you can't use these programs if they aren't established and integrated with FileWave.  So, in particular if you are setting up a new environment, you'll want to give yourself plenty of time before your project to enroll.

Volume Purchase Program (VPP) and Device Enrollment Program (DEP)

The VPP ( Volume Purchase Program ) and DEP ( Working with Apple’s Device Enrollment Program ) play a critical role in managing applications and automating device enrollments. Their integration with FileWave allows for:

VPP and DEP also require initial setup, and shouldn't be left to the last minute.  DEP profiles control device configuration at setup time, and you'll want to make sure you procure all licenses through VPP well ahead of time to avoid last-minute congestion on Apple systems.  (Remember you aren't the only organization enrolling 5,000 devices today).

Using FileWave's DEP profile assignment wizard is a great way to pre-configure your devices automatically, even before they leave the box.

Apple MDM Framework (and known issues)

Apple were very innovative with the creation of the MDM framework, and it allows for controlled management of endpoints through known, controlled mechanisms.  It is very structured, and means that MDM vendors provide support in very common and defined manners.  Knowing for instance that an MDM command to InstallApplication X won't be able to run until the push notification is able to be sent to the device plays into your capacity planning for (re)enrollment.  So, it is structured, but it (like any other system) isn't perfect and there are some additional recommendations we'd make to ensure success:

Non-VPP Apps

Everyone has  some apps that aren't in VPP that they need to push out.  If filesets, fileset magic, .APP installs and custom filesets aren't quite enough options for you :), take a look at Installomator - The one installer script to rule them all (macOS Script) to easily push out over 450 different applications. Completely opensource, and completely super!

Use the Kiosk

With all platforms, but particularly iOS/iPadOS, using the Kiosk ( Kiosk ) to allow your customers to easily and effectively install pre-approved applications and profiles will help you both:

Manufacturer Specific Considerations

Microsoft Specific Considerations

FileWave may love Apple, but we also love Microsoft Windows.  (In the same way that you don't have a favorite child)

Microsoft's Windows platform is widely used in various organizations due to its versatility and familiarity. For a successful device refresh or (re)Enrollment of Microsoft devices, these factors should be considered:

Windows Autopilot and MDM

Windows MDM ( Microsoft Windows MDM ) offers an advanced set of capabilities that allow IT teams to pre-configure Windows devices for immediate deployment. With FileWave and Autopilot working in unison, you can:

Imaging Systems when you can't get to MDM-only

Depending on your situation you may not be able to simply enroll devices in Windows MDM and let Filesets install and configure everything. If that's where you are at then take a look at:

Client Deployment

If dealing with enrollment of an existing fleet of devices, but one not yet under FileWave's care, remember that you can create a custom FileWave Client installer at custom.filewave.com.  This client installer is a standard MSI installer and can be distributed manually, through a GPO, or even through a legacy management system.  It is very flexible, and when combined with the use of placeholders and custom fields, you can pre-assign all device content to deploy automatically on enrollment.

Active Directory Integration

It isn't isolated to only MSFT of course, but Active Directory (AD) or AzureAD are usually an integral part of user management in the Microsoft ecosystem. By integrating AD with FileWave, you can enhance user and device management, including:

Updates and Patch Management

Microsoft consistently releases updates for Windows OS and their suite of office applications. An effective patch management strategy is crucial to maintain security and productivity. FileWave can:

By considering these manufacturer-specific aspects and leveraging FileWave's integrations and capabilities, you can ensure a smooth and efficient device refresh or (re)Enrollment process.

Utilize solutions like Microsoft winget to patch 3rd party applications. 

Manufacturer Specific Considerations

Google Specific Considerations

FileWave supports two distinct Google device platforms, Chromebooks and Android devices. Each platform has its own setup and management considerations.

Chromebook Integration

FileWave support for Chromebooks is primarily focused on device visibility and organizational unit (OU) management. That makes it useful for finding devices quickly, checking where they belong, and moving them between OUs so the correct settings and extensions are applied.

Chromebooks still need to be enrolled before FileWave can manage them. The Google integration is configured once at the organization level, so after that setup is complete, FileWave can work with the Chromebooks in your environment without touching each device individually.

Chrome Education Upgrade / Chrome Enterprise Upgrade and Android Enterprise

These services extend device management for education and enterprise environments. When they are integrated with FileWave, they can provide:

Android and Google Play management

Google Play's large app catalog can be difficult to manage manually. FileWave can help you:

Google as an identity provider

FileWave admins can also authenticate through Google's identity provider services.

Keeping these Google-specific considerations in mind can make device refresh and re-enrollment projects go more smoothly.

Post (re)Enrollment

After the (re)enrollment process is complete, the work doesn't stop. The post (re)enrollment phase (also known as the day-to-day phase) is equally critical to ensure a smooth transition for end users and to maintain the security and performance of your organization's devices. Here's what this phase might look like with FileWave:

Ensure Software Updates

The first step after (re)Enrollment is ensuring that all devices are running the latest software versions and security patches. Regular updates are crucial for the performance and security of your devices, and can also introduce new features or improvements. FileWave's device management tools can schedule and automate these updates, ensuring all devices stay up-to-date without requiring individual attention.  Additionally, you can report on status as well to identify any outliers.

Proactive Maintenance

A good IT is an invisible IT, and there is no better way to be invisible than to predict and correct problems BEFORE they occur.  How is this possible?  Make sure everything is updated, as listed above, but also use FileWave's amazing inventory and custom fields to report on issues before the customer even notices.  You don't need to wait for Jen to call the support desk reporting that she can't install her needed application, when we were already aware that she was running dangerously low on free disk space.

Empower Your Customers

One of the things FileWave excels at is the ability to allow your customers to install content without being admins on their machines.  This means secure workstations and empowered customers.  Pavel doesn't need to call the service desk to install Photoshop if it is sitting in his Kiosk App just waiting for him to click "install".

Provide User Training

While FileWave helps streamline device management, the end users – your staff or students – also play a vital role in the effective use of their devices. Utilize FileWave's resources to conduct training sessions that cover important topics such as device usage, application features, security protocols, and best practices. Training can be tailored based on the user's role and the device they are using, ensuring that everyone gets the most out of their technology.

Set Up a Support System

Despite the best preparation and training, it's inevitable that users will encounter technical issues or have questions after the (re)enrollment process. To address these issues, implement a support system that utilizes FileWave's reporting, remote control and help desk features. This system can provide real-time device status reports, integrate with support ticket systems, and enable IT staff to quickly troubleshoot and resolve technical issues. It also provides users with an easy and efficient way to get help when they need it.

Feedback and Review

Finally, post (re)enrollment is a great time to gather feedback and review the process. Engage with your customers to learn about their experiences, and use FileWave's reporting capabilities to analyze device status, success rate, and common support issues. This information can be invaluable for refining your future device refresh and (re)enrollment strategies.

Remember, the goal of the post (re)Enrollment phase is not just to ensure everything is running smoothly, but to set the stage for continued success. By keeping software updated, providing comprehensive user training, setting up a robust support system, and learning from the process, you'll be well-positioned for future device management tasks.

Communication

What

Satellite dish representing communication planningCommunication is one of the controls that keeps a device refresh from turning into a ticket storm. Users need to know what is happening, when it is happening, what they need to do, and where to go when something does not work. That communication should start before (re)Enrollment and continue after devices are back in service.

Before (re)Enrollment

Set expectations early. Share the refresh schedule, the device return or distribution process, backup expectations, training requirements, and any user actions that must happen before the appointment or cutover window.

Good refresh communication should answer these questions plainly:

During (re)Enrollment

Keep updates short, consistent, and easy to find. Email, team chat, a help desk portal, classroom notices, or a status page can all work; the important part is that users know which channel is authoritative.

Use this phase to confirm what is complete, what is still in progress, and what users should avoid doing until IT gives the all-clear. If users need to sign in, reconnect to Wi-Fi, wait for FileWave Kiosk content, or report a missing app, say that directly instead of assuming they will know.

Two-way communication

Leave room for feedback. Users will surface edge cases that the project plan missed: missing apps, local data questions, shared-device confusion, training gaps, or timing conflicts. A clear support path lets the IT team fix those issues quickly instead of discovering them after frustration has already spread.

After (re)Enrollment

Communication should not stop when the device is handed back. Follow up with practical tips, known-issue notes, app or security changes, and reminders about maintenance windows or update behavior. The goal is to help users understand the new managed state, not just survive the refresh event.

FileWave can manage the device workflow, but communication manages the user experience. Treat it as part of the refresh plan, not a final announcement after the technical work is already done.

Security

 

In our increasingly interconnected world, security is not just a luxury, it's a necessity. As your organization undertakes the device refresh and (re)Enrollment process, it's essential to prioritize device security at every stage. FileWave provides a variety of tools that can help you enforce security protocols and provide a secure operational environment for your users. Here's what you can do:

Prioritize Device Security

fly-d-mT7lXZPjk7U-unsplash.jpgFrom the onset, it's crucial to enforce security protocols on all devices. This includes installing security updates, setting secure device settings, and ensuring the proper configuration of all software. FileWave's device management tools allow you to automate these tasks, ensuring that all devices adhere to your organization's security standards.

Train Users on Security Protocols

User behavior is a critical factor in device security. Conduct training sessions to inform users about your organization's security protocols, the importance of regular software updates, safe internet practices, and how to identify and report potential security threats. FileWave's tools can assist in disseminating this information, making users active participants in maintaining device security. You can easily script notifications via PowerShell on Windows or use tools like swiftDialog Deployment (macOS PKG) on macOS. 

Monitor Device Status

Regular monitoring of device status can help detect any security issues early on. Use FileWave's reporting and analytics tools to perform routine checks, track device performance, and detect any irregularities that may indicate a security threat. This proactive approach can prevent minor issues from escalating into major security breaches.

Respond to Security Incidents

Despite your best efforts, security incidents can still occur. When they do, it's important to have a response plan in place. FileWave can assist in identifying affected devices, isolating them to prevent the spread of security threats, and restoring them to a secure state. 

Review and Improve Security Measures

Security is an ongoing process. Post (re)Enrollment, review your security practices and use the insights gained to improve them. FileWave's reporting tools can provide valuable data to assist in this review, helping you continually enhance device security.

By taking a comprehensive and proactive approach to security during the device refresh and (re)Enrollment process, you can provide a secure operational environment for your users and protect your organization's valuable data and resources.

Conclusions

Undertaking a large-scale device refresh or (re)Enrollment is a significant task. However, with careful planning, thorough preparation, and efficient execution, your organization can transition smoothly and successfully. FileWave's comprehensive toolsets, combined with our recommended best practices, can help you streamline these projects and ensure a seamless transition.

As we have explored throughout this playbook, FileWave empowers you to:

Remember, your organization is unique, and your device refresh and (re)Enrollment strategy should reflect that. Each step along the way offers opportunities to customize and optimize according to your specific needs. Always keep your end goals in mind and make decisions that align with those objectives.

Lastly, you don't have to go it alone! Our Professional Services team has years of experience, and we're ready to assist you with your project at reasonable rates. You can reach our Professional Services team at professional.services@filewave.com. Whether you have questions, need advice, or require hands-on assistance, we're here to support you.

In this constantly evolving technological landscape, staying up-to-date is key to maintaining a robust, secure, and efficient environment. With proper planning, sound strategies, and the right tools, your large-scale device refresh or (re)Enrollment can be a major success. We're here to help make that a reality.

Good luck with your upcoming device refresh or (re)Enrollmentt project!