purplegreen MDM

purplegreen MDM is being prepared for its first pilot. These pages describe the development release.

Enrolling a tablet

Before you start

  • The tenant is connected to Google (settings page) and the site has a profile (its own, or the tenant default).
  • Create an enrollment token on the Enrollment page: pick the site, how long the token is valid (1 hour, 1 day, 30 days, 1 year or no expiry), whether it may be used once only, and which Wi-Fi network the QR code carries:
  • a workshop network, when you set up tablets at your own desk and ship them;
  • one of the site's networks, when you set up the tablet on site;
  • none, when someone connects the tablet to Wi-Fi by hand during setup.
  • Print the provisioning sheet for the site, or open the QR code on screen.

Steps

  1. Factory reset the tablet (Settings > General management > Reset, or the recovery menu) so it starts at the welcome screen.
  2. On the welcome screen, tap the same empty spot six times quickly to open the QR code reader.
  3. Scan the QR code on the sheet. If the code does not contain the Wi-Fi network, connect to Wi-Fi when the tablet asks.
  4. Wait for the "Install work apps" screen and let the setup finish. The tablet installs the kiosk app and locks into kiosk mode by itself.
  5. Check that the tablet appears under this site in the device list.

Known gotchas

  • A wrong Wi-Fi password makes the tablet loop between "Saved" and "Authenticating", and the setup wizard cannot forget a saved network: factory reset the tablet and scan again with the right password.
  • Adding a network with the same SSID as a saved one overwrites the saved network, including its password.
  • A QR code with an embedded Wi-Fi network contains the Wi-Fi password: do not email it or leave it printed after use. Every time someone opens the QR or a sheet, it is recorded in the audit log.
  • An expired or revoked token cannot enroll tablets; create a new token and print a new sheet.
  • If the setup asks for a work email address, the token is wrong; stop and contact support.

Moving tablets from another EMM

There is no way to move a tablet between EMMs without a factory reset. Import the serial numbers on the site page first, print the migration sheet, and for each tablet:

  1. Check the serial number against the list (Settings > About tablet, or the label on the back).
  2. Remove the tablet from the old EMM if it allows that.
  3. Follow the steps above.
  4. The tablet is marked migrated automatically when it enrolls with a pre-registered serial number.