[Music] in this video we'll explain how to use zero touch enrollment for chrome os devices which is an alternative to manual enrollment of devices with zero touch enrollment an approved pre-provisioning partner such as select device manufacturers distributors or resellers sends instructions to google to automatically enroll a compatible chrome os device into a customer's domain after that device is turned on and connected to the internet zerotouch enrollment requires three things a zerotouch enrollment capable device a pre-provisioning token from the google admin console and a pre-provisioning partner who offers zero touch enrollment service let's begin by creating
a pre-provisioning token from the google admin console click on devices then select the chrome devices tile now choose the ou that you want to pre-provision devices into you can create a pre-provisioning token for each one of your organizational units which lets you choose where devices get enrolled once they go through zero touch enrollment for example if you want some devices to be enrolled into the enrollment organizational unit you can create separate pre-provisioning tokens for each of these units note that a pre-provisioning token can be used on multiple devices and orders until the token is revoked
to create the token select the organizational unit you want to create a token for click on the yellow pre-provisioning token button in the bottom corner you'll see that a pre-provisioning token has not been generated for this ou select generate token a 30 character token has now been created now that you have created your pre-provisioning token you have three options first you can copy the pre-provisioning token to the clipboard this is useful if you need to email it to a reseller account manager or a deployment partner second if you just want to stop using this token
for example when you change partners and you no longer want some partners to have access to this token to be able to enroll devices you can revoke it and regenerate it third you can revoke your token if you no longer need a pre-provisioning token for this organizational unit simply revoke it the generate token button only appears the first time when a pre-provisioning token is not present for an organizational unit once that pre-provisioning token and domain name are sent to the pre-provisioning partner they will send that information along with the device information to google through an
api once received devices in your admin console will now show a new status called pre-provisioned previously we offered devices in provisioned de-provisioned disabled or suspended statuses matching all the different actions that you can take on your domain now all the devices that a partner has pre-provisioned for your domain will show in these organizational units as pre-provisioned status to learn more visit the google chrome help center