ChromeOS Zero-Touch Enrollment (ZTE)

Zero-Touch Enrollment (ZTE) is a cloud-based deployment feature for ChromeOS devices that allows IT departments to drop-ship devices directly to end users. The device automatically registers with your organization’s domain and pulls down policies upon the first internet connection, bypassing manual enrollment screens.

Prerequisites

Before initiating ZTE, ensure the following requirements are met:

  • Hardware: A ChromeOS device that natively supports zero-touch enrollment.
    Note: ChromeOS Flex is not compatible.
  • Licensing & Infrastructure:

    • A valid Google Workspace (Chrome Enterprise, Education, or Non-Profit) subscription.

    • BigFix Mobile: A configured BigFix Mobile environment with WebUI access and ChromeOS MDM services installed.

  • Access: Administrator privileges in both the Google Admin Console and the BigFix MCM WebUI.

  • Partnership: The devices must be purchased through an authorized pre-provisioning partner (reseller, distributor, or manufacturer).

How to enable ZTE for ChromeOS

1. Configure BigFix Mobile

To integrate ChromeOS management into BigFix, perform the following in the BigFix WebUI:

  1. Navigate to Settings > Android Enterprise / Google Enterprise.

  2. Register your organization with Google by uploading the necessary service account JSON file.

  3. Bind your Google Workspace domain.

  4. Enable ChromeOS device management.

  5. Sync Google devices to ensure the BigFix console can communicate with your organization's Google Admin Console.

2. Prepare Google Admin Console
  1. Generate a Pre-Provisioning Token:

    1. Log in to theGoogle Admin Console.

    2. Navigate to Devices > Chrome > Devices.

    3. Select the target Organizational Unit (OU) (or the top-level organization).

    4. Click Enroll > Generate new token.

  2. Required Information: Provide this token and your organization's Customer ID to your authorized pre-provisioning partner.

3. Partner Registration

Your pre-provisioning partner uses the token and customer ID to register the devices with Google.

  • Once registered, devices will appear in your Google Admin Console with a "Pre-provisioned" status.

  • The devices can now be shipped directly to end users.

4. Enrollment & Policy Deployment

Once the end user receives the device:

  1. Power On: The user turns on the device and connects to the internet.

  2. Automatic Registration: The device automatically pulls down policies, registers with the domain, and prompts for the corporate login.

  3. Status Update: The device status in the Google Admin Console transitions from "Pre-provisioned" to "Provisioned".

  4. Policy Enforcement: BigFix applies the default policies defined in the BigFix WebUI (e.g., Wi-Fi, VPN, restrictions, and OS updates) based on the assigned Organizational Unit (OU).

5. Remote Device Actions

Administrators can perform the following actions on enrolled devices directly from the BigFix WebUI:

  • Restart: Remotely reboot the device (useful for updates/troubleshooting).

  • Wipe all users off: Removes only the user profile data while maintaining the device management state.

  • Remote Powerwash: Performs a factory reset, removing all local data and accounts; the device remains enrolled.

  • Unenroll: Removes the device from BigFix and Google Workspace management entirely.