Skip to main content
Cisco Meraki

Chrome OS Enrollment

Chrome OS enrollment allows Meraki Systems Manager to install apps, configuration profiles, and more to Chrome OS users & devices. The instructions in this guide cover the setup and enrollment of Chrome OS users & devices with your existing Meraki Systems Manager network and Google Admin console.

This article explains configuring the newest Chrome MDM framework with SM, which requires a licensed G Suite with Enterprise licensing. Google currently does not make this available to non-Enterprise account types. Here is an example of valid "G Suite Basic" licensing from the Google Admin Console: 

G Suite Basic

There is an older set of Google APIs which support both Google education and business customers with less functionality. Instructions for those configurations are covered in this article. Additional information for this type of Chrome Enterprise management can be found here

Dashboard Preparation

1.  Bind your Google Admin account to Dashboard for Chrome OS Device Management using the Sign up using Google button which can be found in the dashboard by navigating to Organization > MDM

Screen Shot 2018-02-13 at 12.19.00 PM.png

Screen_Shot_2018-02-13_at_12.20.26_PM.png

 

2. Once bound to a Google Admin Account in Org > MDM, navigate to Systems Manager > Manage > Add devices. Note the ID and URLs listed here. We will need to add these into the Google Admin Console.  

URIs and Client ID

3.  Use the link provided to log in to your GSuite Admin Console, and from there navigate to Security > API controls > Domain wide delegation > Manage domain wide delegation

Google Admin ConsoleScreen Shot 2020-10-26 at 3.28.45 PM.png

4.  Click Add new. Copy your ID into the Client Name field and the API scopes as a comma-separated string into the One or More API Scopes field, then click on Authorize to add these to your account. 

authorize

     If successful, your page should look similar to the one below:

Successfully added

5. Navigate to Devices > Device Settings > Chrome Management

Screen Shot 2020-10-27 at 3.50.05 PM.png

 

6. On the Device Settings and User & Browser Settings pages, enable Chrome Management - Partner Access 

Screen Shot 2020-10-27 at 3.52.18 PM.png
Screen Shot 2020-10-27 at 3.54.27 PM.png

7. Optional: under Android application settings enable Enable Android applications to be managed through the Admin Console 

Screen Shot 2018-02-13 at 12.26.23 PM.png

For first-time enrollment, you MUST click the Android for Work box to view and acknowledge the terms of service before this check box is selectable

8. In Systems Manager Dashboard, fill in the requested information under Enrollment info and click Bind domain


Screen_Shot_2018-02-13_at_12.33.06_PM.png

9. When you are finished, you should be able to perform Android device and user syncs from Meraki Systems Manager Dashboard/ 

Client Device Enrollment

Chrome OS client devices can be enrolled on a device level by switching the device's initial login mode (by pressing Ctrl + Alt + E) to switch from the standard user account sign-in screen to enterprise enrollment sign in. This must be performed during the device's initial setup. From the enterprise enrollment login screen: log in to an account on the specified Google domain with permissions (enabled by default) to enroll devices. This will add the device to the existing Google admin console and allow Systems Manager to install apps & profiles on a device level. Additional instructions on how to enroll Chrome OS devices with the enterprise enrollment steps can be found here

These client device enterprise enrollment steps are required to install apps & profiles on a device level basis. If devices are not enrolled with this enterprise enrollment option then Systems Manager can still install profiles & apps directly to the end user's Google account.

 

  • Was this article helpful?