New Computer Setup¶
Source: _imported/New Computer Setup Updated 2024.txt · Applies to: all club workstations · Last reviewed: 2026-07
Purpose¶
Full SOP for deploying a new workstation at a client site — from initial OOBE through domain join, Jonas/JAM, security agents, applications, user-profile setup, Windows hardening, and folder ACLs.
Prerequisites¶
- Windows 10 Pro (required for domain join)
- Domain
CSupportaccount credentials - Physical or network access to the club's server (PDC)
- Access to the club's Jonas drive (J:)
Pre-checks (for rebuild/replacement)¶
Always check the client's folder first in case there are any differences or specifics not covered by this guide.
- [ ] Confirm network drives currently mapped
- [ ] Document programs in use (e.g., Creative Cloud, Zoom, Zac)
- [ ] Check root of C:\ for saved documents
- [ ] Record Jonas terminal ID
- [ ] Confirm VPN configuration
- [ ] Check for local
.pstarchive files (archived emails/mailboxes) - [ ] Verify Chrome account exists for bookmark and password sync; if none, request user create one
- [ ] Note installed printers
Computer naming convention¶
| Purchased by | Format | Example |
|---|---|---|
| Club | First initial + last name + Windows version | JDoe10P (John Doe, Windows 10 Pro) |
| Club Support | <CLUB>-<FirstInitial><3LastNameLetters>-<MMYY> |
<CLUB>-GZen-0721 |
| POS | <CLUB>-POS<JonasID>-<MMYY> |
<CLUB>-POSG1-0721 |
Rule: Use the same naming scheme as before. The old computer object must be deleted from AD before joining a replacement with the same name.
Domain depends on club/location.
Steps¶
Initial Setup¶
- Boot to OOBE; set Region & Keyboard to US.
- Create local
CSupportaccount. - Decline all trackers and optional features (e.g., Cortana).
- Set UAC to Never notify.
- Uninstall all bloatware (e.g., trial AV, pre-installed Office).
Domain Join¶
- Go to System → Rename this PC (advanced).
- On the Computer Name tab, select Change…
- Enter the computer name per the naming convention above.
- Set the domain to the club's domain.
- Restart the computer.
- Log in as domain
CSupport. - Verify the Jonas drive is present and accessible (confirms successful domain join).
Installing Jonas¶
- Log into the PC as domain
CSupport. - Run
Jonas (J:)\GJCwin\tools\setup.exe. - If an error occurs, exit and run
Jonas (J:)\GJCwin\tools\Jonas Mapped Drive Connector.exefirst, then retry. - If the system asks for Admin permissions even though logged in as domain
CSupport:- Copy the installer to the desktop, then to the C: drive.
- Log in as local
CSupportand run it from there.
- When prompted for a terminal ID, enter TX if the real ID is not yet known.
- After installation finishes, a window will pop up with a Jonas icon.
- Copy the shortcut to the C: drive.
- Shortcut location:
C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Jonas Business Systems - Restart the computer.
- Log back in as
CSupport. - Run Jonas as Administrator the first time.
- Open properties of
C:\GJCWIN→ Security tab → Edit → AddEveryone→ grant Full control.
Changing the Jonas terminal ID (if set to "TX" above)¶
- Log into Jonas as
CSupport. - Navigate to Workstation Setup.
- Click the magnifying glass beside Terminal ID and find the correct ID for the station.
- Open
C:\GJCWIN\DATAand open the JONAS file with Notepad. - Change
Fid0:to the desired terminal ID.
Disabling NIC offload properties¶
- Open Network and Sharing Center.
- Go to the network adapter properties → Advanced tab.
-
Disable the following:
-
[ ] Flow Control
- [ ] Interrupt Moderation
- [ ] IPv4 Checksum Offload
- [ ] Large Send Offload V2 (IPv4)
- [ ] Large Send Offload V2 (IPv6)
- [ ] TCP Checksum Offload (IPv4)
- [ ] TCP Checksum Offload (IPv6)
- [ ] UDP Checksum Offload (IPv4)
- [ ] UDP Checksum Offload (IPv6)
Installing JAM¶
- Log into the server as
CSupport. - Run
Jonas (J:)\GJCwin\tools\Jonas.NET\INSTALL\setup.exe. - Run the JAM shortcut on the desktop as Administrator for the initial setup.
- Windows will pop up to fix the connection — select Direct Connection.
- Fill in the direct-connection template:
| Field | Value |
|---|---|
| SQL Server | <server-name>\SQLexpress |
| Database Name | JonasNET |
| SQL User | Jonas01 |
| SQL Password | Jonas01 |
Note: The SQL Server name can differ depending on how the club had it set up previously. Check any computer that already has JAM or PDC installed, or consult the client's folder in "BC Clients."
- Log into
CSupportlocally. - Open REGEDIT.
- Navigate to
HKLM\SOFTWARE\WOW6432Node\JonasNET. - Right-click JonasNET → Permissions → grant Everyone Full control.
Antivirus¶
Sentinel One is the current AV/EDR standard (Trend Micro is retired). The S1 agent is deployed from the SentinelOne Management Console (installer + site token) via the club's standard push method (GPO/Atera/Intune). Confirm the console URL and token with your supervisor. Every client must have the S1 agent.
Installing Atera¶
- Log into the server as
CSupport. - Check the server for the Atera install package.
- If not present, log into Atera in a browser and download Install agent.
- Install Atera.
- Open
services.msc— confirm AteraAgent is running. - Check the Atera console to confirm the system appears.
Misc Applications¶
- Remove OEM pre-installed Microsoft 365. Sign into the user's account and download the installer from the portal instead.
- Install Adobe Acrobat Reader.
- Install Google Chrome.
- Install TeamViewer Host:
- Go to clubsupport.ca → Support → download TeamViewer Host.
- Do not create a TeamViewer account.
- Check with the user to see if any other applications are needed.
Setting Up New User Profile¶
- Log into the user's account.
- In File Explorer, access the server via domain (e.g.,
\\<PDC-name>) or DNS IP (e.g.,\\<server-IP>). - If replacing an old PC — ensure the user has access to the same network drives, printers, and files as on the old PC.
- Check for any documents / PDFs / spreadsheets on the C: drive — if found, copy them to the user's My Documents.
- Install any required printer(s) by browsing to
\\<PDC-name>from File Explorer. - Add Computer and User's Files icons to the desktop:
- Right-click desktop → Personalize → Themes → Desktop icon settings.
- Check Computer and User's Files → OK.
Windows Hardening¶
Notifications¶
- Settings → System → Notifications & actions — turn off and uncheck all boxes.
Privacy¶
- Settings → Privacy:
- General — turn off all options
- Inking & typing personalization — turn off all options
- Diagnostics & feedback — turn off all options
- General — turn off all options
- Activity history — turn off all options
Gaming¶
- Settings → Gaming:
- Xbox Game Bar — turn off all options
- Captures — turn off all options
- Game Mode — turn off all options
Power Settings¶
- Press Win + R → run
powercfg.cpl. - Select Change plan settings.
- Desktops: change all options to Never.
- Laptops: change Plugged in options to Never.
Windows Updates¶
- [ ] Run and install all mandatory Windows Updates.
Redirected Folder ACLs¶
On the server, verify permissions on the user's redirected folders:
- By default, Users and Administrators have Full control — this is incorrect.
- Disable inheritance and set permissions explicitly:
| Account | Permission |
|---|---|
| Administrator | Full Control |
| SYSTEM | Full Control |
| CSupport | Full Control |
<new-user> |
Full Control |
All other groups/accounts should be removed.
VPN & RDP¶
See the VPN and RDP document for the applicable procedure.
Notes / Gotchas¶
- Always check the client's folder first before following this guide — every club may have differences or specifics not captured here.
- AV/EDR: Sentinel One is the current standard (Trend Micro retired) — install the S1 agent from the SentinelOne console.
- The JAM SQL Server name varies by club. If
<server-name>\SQLexpressdoes not work, check an existing JAM/PDC machine or the client's folder in "BC Clients." - When Jonas setup.exe prompts for Admin credentials while logged in as domain
CSupport, copy the installer to C: and run it as localCSupport. - For replacements, the old computer object must be deleted from AD before reusing the name.
- Default SQL credentials for JAM direct connection: user
Jonas01, passwordJonas01.