What to expect from your first few weeks with Orchard...
This article explains what to expect from the Orchard platform during the first few weeks of use. This is based on the default configurations for app patching, macOS enforcement and security controls
Stage 1 - Initial setup and device enrollment…
The first stage with Orchard is to create an account and to get your first device enrolled. If you haven’t yet done this, please see the following KB articles explaining the process:
The initial setup will create policies with default settings for app patching, macOS update enforcement and security settings. To learn more about these default policies and how they are configured, see the following KB articles:
- Default app patching policy
- Default macOS update enforcement policies
- Default security policy
Once you have a device enrolled with Orchard, it will report it’s current state, measured against the default app patching, macOS and security policies.
It is quite common to find issues at this stage. Most devices enrolling into Orchard for the first time will have a number of patching and security issues that Orchard will start working on for you over the coming weeks.
Is there anything more for you to do?
For the most part, you will be able to leave Orchard to carry out its work. The only actions left for you to do are:
- Add settings to your MDM if required (please see Stage 3 below)
- Customise the default patching and security settings if needed by your organisation
Please note that we have set a default level of policies for all functions within Orchard, so further customisation is entirely optional.
Stage 2 - macOS and app patching
Once the Mac is enrolled in the Orchard platform, it reports each 3rd party installed app and the current macOS version. This is compared against the corresponding app patching and macOS policies and will display an alert on the device if:
- The macOS version is out of date
- There are 3rd party apps installed on the device that are out of date
On the Mac, Orchard will offer the corresponding updates to the user straight away, allowing them to defer if it isn’t a convenient time. Notifications for macOS updates and/or app updates will continue to show, based on the deferral timeframe selected on the device, up until the deadline where updates must be installed.
To understand more about the macOS and app patching deadline behaviours, please see the following KB articles:
- macOS update enforcement behaviour
- App patching deadline behaviour
Stage 3 - Security settings
Once the Mac is enrolled, the state of each security control, defined in the security policy is reported into then web portal. Within XXXX hours, the Orchard agent on the device will run the auto-remediation actions to correct any cases of non-compliance that it is able to fix. These happen silently in the background and will have no visible user interaction.
It is important to note Orchard is deliberately not an MDM system. This is to ensure it can work smoothly alongside any existing MDM, rather than acting as a replacement. In practice, that means that any security controls, such as FileVault enforcement, or Password Policy settings, that are configured via an MDM Configuration Profile, will be reported on by Orchard, but not auto-remediated.
To remediate cases of non-compliance for MDM managed security controls, add the corresponding controls to your organisations MDM service.
For a full list of MDM vs Orchard security controls, please see this KB article: Security control KB article
What happens next?
Over the following weeks, as the defined patch deadlines are reached, you will see the compliance state of Macs enrolled in Orchard climb rapidly.
While security settings can be applied more rapidly, users need sufficient warning before macOS updates and app patches are installed, which is why Orchard doesn't force update immediately upon enrollment.