# IT Policies and Guidelines # Laptop, Licensing, and Support Guidelines #### **Grace Church of Greater Akron** #### **Laptop, Licensing, and Support Guidelines** The goal of these guidelines is to balance required functionality with cost. These are the defaults for each position type. The IT team will set new employees up per these guidelines unless notified by new hire’s supervisor of additional requirements that justify deviating from these guidelines. - **Position** – Impacts IT service requirements - **Laptop** – Windows Leased $30/mo, Mac Leased $50/mo), Older (more than 3 years $0/mo) - **Licensing** – Email, Office, SharePoint/OneDrive Online (MS E1 or E2) $0/mo, Full Microsoft Licensing (MS E3 & E5) $12.80/mo) - **Grace IT Helpdesk Support** – If helpdesk support is “Yes” then Grace IT team will provide support for all hardware and software. Otherwise will only support what is stated.
Position Laptop Guidelines Licensing Grace IT Helpdesk Support
Intern (Short-term) No laptop offered (use personal laptop) Email, Office, SharePoint/OneDrive Online (MS E1 or E2) Email, Office, SharePoint/OneDrive Only
Intern (Long-term) Offered laptop May use personal Full Microsoft Licensing (MS E3 & E5) Email, Office, SharePoint/OneDrive Online (MS E1 or E2) Yes Email, Office, SharePoint/OneDrive Only
Resident Leased Laptop Full Microsoft Licensing (MS E3 & E5) Yes
Pastor Leased Laptop (Choice Windows or Mac) Full Microsoft Licensing (MS E3 & E5) Yes
Staff (10hrs +) Leased Laptop Full Microsoft Licensing (MS E3 & E5) Yes
Staff (< 10 hrs) Offered older laptop May use personal Full Microsoft Licensing (MS E3 & E5) Email, Office, SharePoint/OneDrive Online (MS E1 or E2) Yes Email, Office, SharePoint/OneDrive Only
Custodial No laptop offered (use personal laptop) Email, Office, SharePoint/OneDrive Online (MS E1 or E2) Email, Office, SharePoint/OneDrive Only
Volunteer (Staff) Offered older laptop May use personal Full Microsoft Licensing (MS E3 & E5) Email, Office, SharePoint/OneDrive Online (MS E1 or E2) Yes Email, Office, SharePoint/OneDrive Only
Volunteer (Other) No laptop offered (use personal laptop) Email, Office, SharePoint/OneDrive Online (MS E1 or E2) Email, Office, SharePoint/OneDrive Only
#### **Stickers** AVOID putting stickers or other accessories on the computers in general, especially if yours is leased. The leasing companies strongly dislike these and will penalize us for returning equipment with these on. If you have stickers on yours, please make an effort to remove them from your computer. #### **Returning Laptops** Please see this article for what to do when you need to return your laptop. You will need to return your laptop, along with the accessories that came with it or the job position, when you offboard or the lease is due: [Returning your Laptop | Grace Church KB (gracechurches.org)](https://kb.gracechurches.org/books/it-policies-and-guidelines/page/returning-your-laptop). Coordinating with us in this way really helps us in redistributing the computer equipment. When your laptop lease is up, we will try to give you the heads up a month from the due date. # Multi Factor Authentication - MFA - 2FA [Figure 1:](https://kb.gracechurches.org/uploads/images/gallery/2022-05/msedge-ywmbg7j3cc.gif) GraceOhio Login 2FA Approval Process with phone app [![msedge_yWMBg7J3Cc.gif](https://kb.gracechurches.org/uploads/images/gallery/2022-05/msedge-ywmbg7j3cc.gif)](https://kb.gracechurches.org/uploads/images/gallery/2022-05/msedge-ywmbg7j3cc.gif)[![image-1653511204994.gif](https://kb.gracechurches.org/uploads/images/gallery/2022-05/image-1653511204994.gif)](https://kb.gracechurches.org/uploads/images/gallery/2022-05/image-1653511204994.gif) Grace IT is rolling out and enforcing this MFA policy to all Staff in order to improve the security of our organization and help reduce potential headaches. If you are enrolled in MFA, you will need to have your phone as an additional method of authenticating yourself (on top of your password) to log in to your Work Office365 account. The easiest way to do this is by using the *Microsoft Authenticator* App on your phone with push notifications; however, you can use a different method or authenticator if you prefer. The benefits of being enrolled in MFA is that you do not have to worry about resetting your Work Office365 *and* Work laptop password regularly, and you will not get any more password reset notifications/emails. MFA also makes it increasingly difficult for anyone else to access your account since they need your password *and* your approval from your phone in order to sign in, making this a critical technology in cybersecurity. #### **Standard 2FA Method: Microsoft Authenticator (App Push Notification)** **[![icon_microsoft-authenticator[1].png](https://kb.gracechurches.org/uploads/images/gallery/2021-05/scaled-1680-/icon-microsoft-authenticator1.png) ](https://docs.microsoft.com/en-us/azure/active-directory/user-help/user-help-auth-app-download-install)** **[(This is the Microsoft Authenticator App. For more app related information from Microsoft, click on the icon.)](https://docs.microsoft.com/en-us/azure/active-directory/user-help/user-help-auth-app-download-install)** The default (and most straightforward and quickest) method that Grace IT sets up everyone with is the push notification through the Microsoft Authenticator App. When a sign in attempt is made to your account, a push notification is sent to your phone asking to Approve or Deny the login attempt. This method can be changed to another one, if you desire, through your Microsoft Account page. Instructions for setting up MFA using this method are listed below. Click on the dropdown arrow to expand the corresponding guide:

A **passcode lock** on your phone is required by our organization in order to use the Microsoft Authenticator App and the Outlook app together. You will need to setup a 4 or 6 digit passcode on your phone in order to properly use the Authenticator app. **Please set this up** before proceeding through the below instructions.

#### **Setting up the method manually yourself** Expand this instruction list to get started! Use these instructions if you need to setup a new phone with the Authenticator app.
Instructions: Click on me! ##### 1) Install the latest version of the Microsoft Authenticator app, based on your phone: - **Google Android.** On your Android device, go to Google Play to [download and install the Microsoft Authenticator app](https://app.adjust.com/e3rxkc_7lfdtm?fallback=https%3A%2F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3Fid%3Dcom.azure.authenticator). - **Apple iOS.** On your Apple iOS device, go to the App Store to [download and install the Microsoft Authenticator app](https://app.adjust.com/e3rxkc_7lfdtm?fallback=https%3A%2F%2Fitunes.apple.com%2Fus%2Fapp%2Fmicrosoft-authenticator%2Fid983156458). - You won't need to open the app just yet. Proceed to the next step while the app is downloading in the background,. ##### 2) Configure 365 account in Authenticator App - With your work laptop, Sign into your Office365 at **[https://myaccount.microsoft.com/](https://myaccount.microsoft.com/)** - Select **Security info** in the left menu or by using the link in the **Security info** pane. If you have already registered or been registered by IT, you'll be prompted for two-factor verification. Then, select Add method in the Security info pane. - On the **Add a method** page, select **Authenticator app** from the drop-down list, and then click **Add**. - On the **Start by getting the app** page, click **Next**. - Remain on the **Set up your account** page while you set up the Microsoft Authenticator app on your mobile device. - Open the Microsoft Authenticator app on your phone, select to allow notifications (when prompted), select **Add account** from the **Customize and control** icon on the upper-right, and then select **Work or school account**. - Return to the **Set up your account** page on your computer, and then select **Next**. The **Scan the QR code** page appears. - Scan the provided code with the Microsoft Authenticator app QR code reader, which appeared on your mobile device after you added your work or school account. - The Authenticator app should successfully add your work or school account without requiring any additional information from you. However, if the QR code reader can't read the code, you can select the **Can't scan the QR code link** and then manually enter the code and URL into the Microsoft Authenticator app. For more information about manually adding a code, see [Manually add an account to the app](https://docs.microsoft.com/en-us/azure/active-directory/user-help/user-help-auth-app-add-account-manual). - Select **Next** on the **Scan the QR code** page on your computer. Pay attention to your phone afterwards. - A notification is sent to the Microsoft Authenticator app on your mobile device, in order to test that MFA works with your account. - You will need to open or tap on this notification to approve your sign in attempt. - Approve the notification request within the Microsoft Authenticator app, and then select **Next**. - Congratulations, you have successfully added MFA to your Work Office365 account! - As a BONUS, add a **Backup Method** to ensure you don't get locked out in the event you lose your phone. See **[Change or Add Methods](https://kb.gracechurches.org/books/it-policies-and-guidelines/page/multi-factor-authentication-mfa-2fa#bkmrk-change-or-add-method "Change or Add Methods")** to find where you can add your backup methods. -

If you are an iOS user, please read through the "Situational" section in this article.

#### **Setting up the method when required by your organization** Follow this instruction list if you see a "More information is required by your device" prompt when you try to use an Office 365 application. This means that we pushed the MFA policy onto your Office 365 account, which forces you to setup MFA in order to continue using your 365 applications. If you are a recent, new hire, you will see this.
Instructions: Click on me! ##### 1) Install the latest version of the Microsoft Authenticator app, based on your phone: - **Google Android.** On your Android device, go to Google Play to [download and install the Microsoft Authenticator app](https://app.adjust.com/e3rxkc_7lfdtm?fallback=https%3A%2F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3Fid%3Dcom.azure.authenticator). - **Apple iOS.** On your Apple iOS device, go to the App Store to [download and install the Microsoft Authenticator app](https://app.adjust.com/e3rxkc_7lfdtm?fallback=https%3A%2F%2Fitunes.apple.com%2Fus%2Fapp%2Fmicrosoft-authenticator%2Fid983156458). - You won't need to open the app just yet. Proceed to the next step while the app is downloading in the background,. ##### 2) Configure 365 account in Authenticator App - Proceed to the next page following "More information is required by your device". - On the **Start by getting the app** page, click **Next**. - Remain on the **Set up your account** page while you set up the Microsoft Authenticator app on your mobile device. - Open the Microsoft Authenticator app on your phone, select to allow notifications (when prompted), select **Add account** from the **Customize and control** icon on the upper-right, and then select **Work or school account**. - Return to the **Set up your account** page on your computer, and then select **Next**. The **Scan the QR code** page appears. - Scan the provided code with the Microsoft Authenticator app QR code reader, which appeared on your mobile device after you added your work or school account. - The Authenticator app should successfully add your work or school account without requiring any additional information from you. However, if the QR code reader can't read the code, you can select the **Can't scan the QR code link** and then manually enter the code and URL into the Microsoft Authenticator app. For more information about manually adding a code, see [Manually add an account to the app](https://docs.microsoft.com/en-us/azure/active-directory/user-help/user-help-auth-app-add-account-manual). - Select **Next** on the **Scan the QR code** page on your computer. Pay attention to your phone afterwards. - A notification is sent to the Microsoft Authenticator app on your mobile device, in order to test that MFA works with your account. - You will need to open or tap on this notification to approve your sign in attempt. - Approve the notification request within the Microsoft Authenticator app, and then select **Next**. - Congratulations, you have successfully added MFA to your Work Office365 account! - As a BONUS, add a **Backup Method** to ensure you don't get locked out in the event you lose your phone. See **[Change or Add Methods](https://kb.gracechurches.org/books/it-policies-and-guidelines/page/multi-factor-authentication-mfa-2fa#bkmrk-change-or-add-method "Change or Add Methods")** to find where you can add your backup methods. -

If you are an iOS user, please read through the "Situational" section in this article.

#### **Situational**: If you are an iOS user AND use the built in Mail or Calendar App for Work: [![iu[2].jpg](https://kb.gracechurches.org/uploads/images/gallery/2021-06/scaled-1680-/iu2.jpg)](https://kb.gracechurches.org/uploads/images/gallery/2021-06/iu2.jpg)[![ios-mail-icon-100669537-large[1].jpg](https://kb.gracechurches.org/uploads/images/gallery/2021-06/scaled-1680-/ios-mail-icon-100669537-large1.jpg)](https://kb.gracechurches.org/uploads/images/gallery/2021-06/ios-mail-icon-100669537-large1.jpg)
iOS Situation: Click on me! Unfortunately, as of right now Apple's built in [Mail ](https://apps.apple.com/us/app/mail/id1108187098)and [Calendar ](https://apps.apple.com/us/app/calendar/id1108185179)apps (if you use them for work) **will eventually stop working** when you setup MFA! This is because they are unable to bring up the prompt for 2FA when you are already signed in (very specific technical reason on Apple's end). You will have to remove your Office 365 account and re-add it in order to keep using these apps for work. Because of this,** Grace IT STRONGLY recommends you avoid using the built in iOS MAIL/CALENDAR apps and instead use the [Outlook App](https://apps.apple.com/us/app/microsoft-outlook/id951937596).** If you follow these steps, however, you will be able to get these back up and running for a little while longer (Until it stops working again. You also have the option of using the **[Outlook App](https://apps.apple.com/us/app/microsoft-outlook/id951937596)**, which does not have this reauthentication issue and supports both mail and calendar functionality.) - Open your settings app. - Scroll down and find either "Mail" or "Calendar". Tap one of them. If you use both for work, you may want to take note of your preferences that you may have setup for each. - Tap "Accounts" - Find and Tap on your Work account. It will have the graceohio/gracechurches email address. - Take note of the work content that you are syncing (Mail, Contacts, Calendars, Reminders, and Notes). Then click on Delete Account. - When it finishes removing your account from your phone, you should be taken back to the accounts screen. Tap on "Add Account" - You will see a list of email services you can select. Be sure to choose Microsoft Exchange, as Office365 accounts will only work with this and not the Outlook.com option. [![image-1624807663886.png](https://kb.gracechurches.org/uploads/images/gallery/2021-06/scaled-1680-/image-1624807663886.png)](https://kb.gracechurches.org/uploads/images/gallery/2021-06/image-1624807663886.png) - In the new screen that pops up, enter your work email here. Also put in a name for this account that you will recognize (For example: Grace Church - Work). - Tap Next. This will probably trigger 2FA, so you will need to approve the sign in attempt if it does ask. - The screen that lets you choose to sync specific content appears. Refer back to your note for what content you sync and enable those respectively. Hit next - Your mail/calendar/content will start syncing. This may take a minute, or if you have tons of calendar appointments/events it could take a couple hours to finish. We recommend leaving your device charging if it is taking more than a few minutes. You should be all set for the time being.

UPDATE: You may see a prompt like this picture below on your phone when roughly 60 or 90 days pass. Apple forces you to reauthenticate after that period of time but vaguely prompts you to do it with this message. **PLEASE** keep this in mind if you really want to use the iOS Mail app, as when the period time passes by you will stop receiving mail and calendar updates again *until* you reauthenticate your account again. There is not much that Grace IT can do to remedy this as this is primarily an Apple technology issue. The **[Outlook App](https://apps.apple.com/us/app/microsoft-outlook/id951937596)** does not have this issue, so Grace IT again recommends you to use that as your Mail and Calendar App solution for Work.

If you see this picture below, your iOS Mail/Calendar app wants you to reauthenticate your work account. As you can tell from reading the prompt: it vaguely tells you this—but you will need to address this prompt in order to continue receiving email and calendar updates when using the iOS mail and calendar apps for this purpose. [![image-1639268011495.png](https://kb.gracechurches.org/uploads/images/gallery/2021-12/scaled-1680-/image-1639268011495.png)](https://kb.gracechurches.org/uploads/images/gallery/2021-12/image-1639268011495.png) - - You can tap Edit Settings to re-enter your password for your Office365 account. You can also re-enter your password by going to the Settings app, then to Mail or Calendar. Tap on accounts and and tap on your work account..
#### **Logging into GraceOhio/Microsoft Office365 Account - How it works** Once you are setup with a MFA method using one of the guides above, you can reference the same two GIF's at the top of this page and down here as well to get a general idea of the process of using the Authenticator app to login to your GraceOhio account (Reload this page if the demonstration GIF's go out of sync, synchronizing two GIF's together is really difficult). The general login process goes as follows in these bullet point steps:
a. Computer View (www.office.com for example)b. iPhone View (Using Authenticator App to approve MFA)
[![msedge_yWMBg7J3Cc.gif](https://kb.gracechurches.org/uploads/images/gallery/2022-05/msedge-ywmbg7j3cc.gif)](https://kb.gracechurches.org/uploads/images/gallery/2022-05/msedge-ywmbg7j3cc.gif)[![image-1653511204994.gif](https://kb.gracechurches.org/uploads/images/gallery/2022-05/image-1653511204994.gif)](https://kb.gracechurches.org/uploads/images/gallery/2022-05/image-1653511204994.gif) - Goto/Open Microsoft Office365 service you are licensed for. In this case, we are logging into [www.office.com](http://www.office.com) in the Microsoft Edge web browser. - On the Login Screen, Enter your Email Address, and then Password. - Upon successful credentials entry, you **may** need to provide MFA. In the case where you do, you will either automatically receive a push notification, or you can send it yourself, OR send a different MFA request if you set one up (ex SMS code or email code). Note that a MFA request is *not required for every* *session*. The only time you will be requested MFA are these scenarios: 1. If you are authenticating in for the first time on the application or computer in question, OR 2. If you logging in after 30/60/90/365 days (This number depends on the application, or what option you choose for the "Don't ask again" prompt) - If you receive the Push Notification, just make sure you have your phone on you. Tap on the push notification to bring up the Authenticator app, and tap approve if it is you who is trying to sign in. You will only have about 60 seconds to accept this before you need to request another MFA request. - All done! You can get started now! #### **Tips and Cautions to be aware of** ##### **Tips** - Ensure that you keep the Microsoft Authenticator App up to date. This can help ensure that any issues or known security vulnerabilities have been patched. \[For iOS users, visit [How to Update iPhone apps manually and automatically](https://support.apple.com/en-us/HT202180). For Android users, visit [How to update Android apps](https://support.google.com/googleplay/answer/113412?hl=en).\] - On the step where you are entering your credentials, You *may* also have the option to sign in using the app rather than using your password via the ***Use an App instead*** method shown above. This is called a *passwordless* login method. You can enable it by following [Microsoft's steps](https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-phone#user-registration-and-management-of-microsoft-authenticator): - Browse to [https://aka.ms/mysecurityinfo](https://aka.ms/mysecurityinfo) . Sign in, then click Add method > Authenticator app > Add to add the Authenticator app. Follow the instructions to install and configure the Microsoft Authenticator app on your device. Select Done to complete Authenticator configuration. In Microsoft Authenticator, choose Enable phone sign-in from the drop-down menu for the account registered. Follow the instructions in the app to finish registering the account for passwordless phone sign-in. - Once you have the Authenticator App setup on your phone, you can follow the this guide: [Sign in to your accounts using the Microsoft Authenticator app](https://support.microsoft.com/account-billing/sign-in-to-your-accounts-using-the-microsoft-authenticator-app-582bdc07-4566-4c97-a7aa-56058122714c) - On the step where you need to provide MFA, it will also ask if you don't want to be asked again for a certain amount of time. You can check this off if you want! - Using the Microsoft Authenticator App method, instead of using a push notification you can provide a *one-time password code* provided by the app to enter in order to authenticate yourself. The code is generated every 30 seconds, and you can grab the code anytime by tapping on the GraceOhio entry in your Microsoft Authenticator app: [![image-1653783630962.PNG](https://kb.gracechurches.org/uploads/images/gallery/2022-05/scaled-1680-/image-1653783630962.PNG)](https://kb.gracechurches.org/uploads/images/gallery/2022-05/image-1653783630962.PNG) ##### **Cautions to take account**

Please read and keep these tidbits of information in mind to help protect yourself and our church from harm.

- Even with how strong MFA is, it is not infallible. You still need to have strong passwords. - MFA is only as strong as to how well you keep your phone/phone number (or email account) secured. Make sure that you keep your phone/phone account protected by strong passcodes and passwords, and make sure that your phone number is not compromised. - **Never** share a MFA token (or a session token) with anyone under any circumstance. The MFA token is a form of authentication that should only be used by the authorized user. - Do not accept Authentication Requests when you are not trying to login yourself. - **Never** accept authentication requests when you are not attempting to log in yourself. Even if Grace IT is trying to log in to your GraceOhio account to assist (Grace IT can bypass the MFA step or reset your account credentials), do not accept any sign-in request that you did not initiate. - If you receive a MFA request when you weren't attempting to log in through a login prompt yourself, your password may have been compromised. Change your password immediately, especially if you use the same password for other internet accounts. - Each Microsoft Authenticator app notification is supposed to be received almost instantaneously (within a couple of seconds), and each request sent will only last for approximately 60 seconds. If you do not accept the request in time, you will need to make a new request since the verification timed out. - If you miss the time window for authenticating through MFA, do not accept any requests that come later than 60 seconds after you initially made the request, as they will not be coming from you (check out **Figure 2**). This is particularly important since hackers may send fake requests to trick you into accepting them. Again, change your password when you don't initiate a MFA request yourself. - Check out this article that explains how people have fallen victim to cyber attacks, even when they have MFA enabled. It mentionins "MFA Fatigue" and Social Engineering attacks on Phone Providers: [MFA Bypass: The Next Frontline for Security Pros - Infosecurity Magazine (infosecurity-magazine.com)](https://www.infosecurity-magazine.com/news-features/mfa-bypass-frontline-security-pros) ##### **Figure 2: Approximately 1 Minute to accept MFA requests** [![image-1653512304152.gif](https://kb.gracechurches.org/uploads/images/gallery/2022-05/image-1653512304152.gif)](https://kb.gracechurches.org/uploads/images/gallery/2022-05/image-1653512304152.gif) #### **Change or Add 2FA method** [![image-1664897434078.png](https://kb.gracechurches.org/uploads/images/gallery/2022-10/scaled-1680-/image-1664897434078.png)](https://kb.gracechurches.org/uploads/images/gallery/2022-10/image-1664897434078.png) You can access your Microsoft Account page **[here](https://mysignins.microsoft.com/security-info)**. The link takes you to the security info section. Here you can remove and add methods (Phone text or call, Email, or another Authenticator App), as well as take a look at your default and current methods. You also don't have to strictly use the Microsoft Authenticator app if you prefer to use something else, but it is a solution that Grace IT recommends since it integrates well with our work environment. Once you click on *Add sign-in method*, choose your method and follow the onscreen instructions. You can also follow the manual step-by-step setup guide listed earlier in this KB article for adding the Microsoft Authenticator App for MFA quickly: **[Setting up the method manually yourself](https://kb.gracechurches.org/books/it-policies-and-guidelines/page/multi-factor-authentication-mfa-2fa#bkmrk-setting-up-the-metho "Setting up the method manually yourself")**

This resource will be useful if you ever go through the process of changing or upgrading your phone, as your Multi Factor configuration is *not* carried over to your new device automatically. If you see yourself upgrading your phone soon or often enough then we strongly recommend you add another method, like your phone number or personal email, using the above link so that you do not experience downtime from being locked out of your account.

If you ever get stuck, and get locked out of your account for any reason, don't panic—Grace IT will be able to reset your credentials or MFA methods for you. Reach out to Grace IT at the helpdesk: [https://kb.gracechurches.org/books/it-helpdesk/page/requesting-it-help-grace-church-and-ce-national](https://kb.gracechurches.org/books/it-helpdesk/page/requesting-it-help-grace-church-and-ce-national)

# Preparing for Leased Laptop Replacement #### Our leasing flow Most of our leased computer equipment are leased for 3 years. Currently, our Dell laptops are the exception at 4 years. #### When your lease is up When they come due, Grace IT will send a notice to you letting you know that the lease on your laptop is coming up and we will need to give you a replacement. We will typically give the heads up around a month before we need to return them, and then reminders later on if necessary. #### Prepare for your Swap To help prepare for this, here are some steps you can take: 1. Please make sure you have everything you need backed up to your Business OneDrive folder, see picture below for an example of what one's Buisness OneDrive folder may look like (Notice that Onedrive, if you are using a Windows PC, *automatically* backs up your Documents, Pictures, and Desktop folders, but *only* these folders out of all your Library folders. So, for example, if you have files in your Downloads, Videos, or Music folders that you still need—please move them into one of your OneDrive folders if you wish to hang onto them): [![image-1665433056165.png](https://kb.gracechurches.org/uploads/images/gallery/2022-10/scaled-1680-/image-1665433056165.png)](https://kb.gracechurches.org/uploads/images/gallery/2022-10/image-1665433056165.png) We will be using OneDrive to carry over your files to your new computer. Make sure your OneDrive application is running with no issues/errors reported to ensure that your files are being backed up and synced to the cloud! [![image-1676997436287.png](https://kb.gracechurches.org/uploads/images/gallery/2023-02/scaled-1680-/image-1676997436287.png)](https://kb.gracechurches.org/uploads/images/gallery/2023-02/image-1676997436287.png) If it is not running, please search and open OneDrive from the Start menu on Windows, or from Launchpad on MacOS. If it doesn't load up, please raise a support ticket with Grace IT to help you get that fixed. \- Notice on Macs that OneDrive **ONLY** backups your Onedrive Folder (see photo). All the library folders you see highlighted in yellow are not inside the OneDrive folder and thus aren't backed up by it by default on a Mac System. Keep this in mind when you are backing up your files. [![image-1680033044837.png](https://kb.gracechurches.org/uploads/images/gallery/2023-03/scaled-1680-/image-1680033044837.png)](https://kb.gracechurches.org/uploads/images/gallery/2023-03/image-1680033044837.png) 2. Once you are signed into your new laptop it will setup your desktop environment automatically for you, including OneDrive. 3. If you are on a windows laptop, it should also try to reinstall some of your programs you had on your old laptop. If you have certain software configurations or bookmarks you want copied over, you will need to do that yourself. For Google Chrome you can either [Make a Google account ](https://support.google.com/accounts/answer/27441?hl=en)to [Sync Bookmarks and Other Browser Settings Automatically](https://support.google.com/chrome/answer/165139?hl=en&co=GENIE.Platform%3DDesktop&oco=0), or export them to a file you can use to later import them onto your new laptop, preferably to OneDrive so that it is there ([Import bookmarks & settings - Google Chrome Help](https://support.google.com/chrome/answer/96816?hl=en)). If you are signed into the Edge Browser with your GraceOhio account, then any of your Edge settings and history will transfer over. 4. To add back your SharePoint folders you were syncing to your old laptop, please refer to this KB guide: [How to Sync and Favori... | Grace Church KB (gracechurches.org](https://kb.gracechurches.org/books/sharepoint/page/how-to-sync-and-favorite-any-of-the-campuses-files-sharepoint-folders) 5. Please let Grace IT know a good time to get you swapped out. We do need to get you signed in to your new laptop to get you setup with it and to initialize your laptop, so please be prepared to either enter in your credentials a couple of times, or to provide your desired password and/or (Windows) PIN code. Once you are signed into the laptop, it will start to receive policies, scripts, programs, and printers in the background. 6. If you were using a Mac, please disconnect your Apple ID completely from it *if you signed into it using that*. Turn off "Find my Device", or Activation Lock, if this is enabled. We will be charged a casualty fee if the device is still locked under your Apple ID since it cannot be remarketed. We will handle the data wiping your old computer for you before shipping the computer back to the leasers, so you do not need to worry about that. Though if you were using a Mac, please make sure you followed the procedures of disassociating your device from your Apple ID. ***This Mac check is EXTREMELY important.*** If you have questions about this, please let us know. --- #### Deactivating Activation Lock on MacBook - From MacBook You can disable Mac Activation lock directly on your Mac. Below details how to do this in 5 steps: [Deactivating Activatio... | Grace Church KB (gracechurches.org)](https://kb.gracechurches.org/books/laptop-operating-systems/page/deactivating-activation-lock-on-mac) --- #### House Keeping Items Since Grace IT has multiple laptops that we need to swap out from multiple people, it is important that we get you swapped out swiftly. To help make the swap transition smooth for everyone, please follow these other points for swapping: [Returning your Laptop | Grace Church KB (gracechurches.org)](https://kb.gracechurches.org/books/it-policies-and-guidelines/page/returning-your-laptop) # Purchasing Web Domains If you are interested in paying for a web domain dedicated to a church event, ministry, or other related subject {Examples of this would be like jrcamp.org, allinallout.org, gameday.org, lovebarberton.org/lovebarberton.com} *please do not purchase the domain yourself*, especially if it is a website. Please ask Grace IT to help you purchase it. Grace IT is in charge of managing and financing these internet domains owned by the church and cannot manage them if we didn't purchase them.

In addition, in order to transfer a domain to our Grace IT domain management account, we will have to coordinate with you some steps about the process and ensure that certain conditions are met to successfully make a transfer, [including paying a transfer fee and making sure 60 days have passed since the domain was bought](https://support.google.com/domains/answer/3251236?authuser=0&hl=en&ref_topic=9003137).

[![image-1674954244673.png](https://kb.gracechurches.org/uploads/images/gallery/2023-01/scaled-1680-/image-1674954244673.png)](https://support.google.com/domains/answer/3251236?authuser=0&hl=en&ref_topic=9003137) # Apple Genius Bar Appointments | Service Requests You or GraceIT can take your MacBook to get it serviced at the Apple Genius Bar if it is experiencing an issue. You can make an appointment, free of charge. All the MacBooks we purchase and lease come with AppleCare which backs it with a multiyear warranty. If you need to have your MacBook serviced, please make sure that you can deactivate your device from your Apple ID (look at [Turn off Find My on your iPhone or other devices - Apple Support](https://support.apple.com/en-us/HT211149)). If Grace IT needs to take it for you, please turn off ***Find My Device*** and ***sign out of your Apple ID*** in case your computer needs to be wiped while it is serviced. Otherwise, Apple won't be able to make repairs: - [Activation Lock - Support (apple.com)](https://al-support.apple.com/#/getsupport) - [Remove a device from Find Devices on iCloud.com - Apple Support](https://support.apple.com/guide/icloud/remove-a-device-mmfc0eeddd/icloud)

If there is physical damage or water damage related to the technical issue going on with the laptop, Apple will charge you to make repairs even if it has Apple Care+. If this is the case for your computer, please do not take it to the Apple Store (if you know there is a strong chance of water damage) or pay out of pocket to make the service repairs. Please let Grace IT know about it and we will take care of it all for you.

# Traveling Internationally - Account Access IT Policy Grace IT will by default prohibit logins coming from outside of North America. This is because a lot of scammers and online bots will often try to brute force through our online accounts from Internet IP's outside of the North Americas. Because of this, you won't be able to access your Grace Church Office365 work account (GraceOhio.org, GraceChurches.org, GraceGeorgia.org, etc) when you travel internationally. We can put you in an exemption group for times when you need access to your email or other services overseas. We ask that you help give us the heads up when you plan on traveling abroad by filling out this form, (you can also fill it out on behalf of someone): [https://forms.office.com/Pages/ResponsePage.aspx?id=tmkE-IFaT0am8UrY5KxEih\_2uv0Um4BOp9YIP8-5CSFUM0dTQU5VTEszQ08wNUU5SElTTlc2WFBTNS4u](https://forms.office.com/Pages/ResponsePage.aspx?id=tmkE-IFaT0am8UrY5KxEih_2uv0Um4BOp9YIP8-5CSFUM0dTQU5VTEszQ08wNUU5SElTTlc2WFBTNS4u) Just simply login with your Grace Church Office365 account to fill it out. Grace IT will be notified about the request. Thanks, and travel safe! [![image.png](https://kb.gracechurches.org/uploads/images/gallery/2024-07/scaled-1680-/image.png)](https://kb.gracechurches.org/uploads/images/gallery/2024-07/image.png) # Returning your Laptop If you offboard, or if your laptop lease is coming due, we need to take your laptop along with the accessories. These points will help us keep in the loop: 1. Let us know when to expect to receive your laptop and accessories that came with it. If you need to wrap up things before you officially leave staff, that is probably fine but there is the chance that we may have to ask you to swap to a loaner laptop so that we can manage our laptop inventory for future hires. 2. If you are getting a swap, verify that your files are backed up (i.e. in OneDrive: [Sharepoint / OneDrive | Grace Church KB (gracechurches.org](https://kb.gracechurches.org/books/sharepoint-onedrive)) and you recorded any miscellaneous software configurations/settings you want to keep. 3. Let us know if there are any important files/folders on your system that you want us to specifically backup to be used by someone on staff. We normally only archive your OneDrive files otherwise. 4. AVOID putting stickers or other accessories on the leased computers in general. The leasing companies strongly dislike these and will penalize us for returning equipment with these on. If you have stickers on yours, please make an effort to remove them from your computer. Sticker residue can sometimes be difficult to remove. 5. Make sure that you return your computer with **all the accessories** that came with it. People often forget to drop these off with their computer. Typically, this will include - The laptop itself - The charger adaptor - Any detachable cable that comes with the laptop / charger - If applicable, any other Monitor, Docking, or USB equipment separately purchased for your position. (*Obviously, if you are staying in your current position, you can continue to use these*). - If you lose your charger, cable, or anything else that goes with the laptop, *please* inform Grace IT before returning your computer so that we can act accordingly. These are required and expected to be returned along with the computer. 6. If you have been using a Mac that is due, and you use your Apple ID ***AND*** you turned on "Find my Device", you are responsible for **[turning off Activation Lock](https://al-support.apple.com/#/getsupport). (Also, for more information and to turn off activation lock when you don't have your computer on hand, look at [Remove a device from Find Devices on iCloud.com - Apple Support](https://support.apple.com/guide/icloud/remove-a-device-mmfc0eeddd/icloud)).** You can also look at [Deactivating Activatio... | Grace Church KB (gracechurches.org)](https://kb.gracechurches.org/books/laptop-operating-systems/page/deactivating-activation-lock-on-mac) for disabling directly on your Mac.