Academy
Technical · Course T2

Lesson 4 of 5

Zero Touch enrollment

8 min read
In this lesson you'll learn to
  • Set up a Zero Touch configuration pointing at WeGuard
  • Explain the reseller's role in device registration
  • Set a default configuration so new devices auto-assign
  • Walk the first-boot enrollment flow and its requirements

Zero Touch is what "enrollment at scale" should feel like: the customer's people unbox a device, power it on, and walk away — it lands managed. The setup work happens once, in two portals.

The moving parts

Three parties, one handshake:

  • You / the customer create a configuration in Google's Zero Touch portal that says "devices on this account belong to WeGuard."
  • The reseller registers purchased devices to the customer's Zero Touch account. This is the step nobody else can do — devices are only added by authorized resellers/carriers.
  • Google's servers check each device's identity on first boot and hand it to WeGuard.

Requirement to remember: Android 8.0+. Older Samsung hardware has its own program — that's the next lesson.

Set up the configuration

WeGuard embeds the Zero Touch portal at Settings → Android (your Enterprise ID shows at the top of the page — if it's missing, finish lesson 1 first). Use the embed or open the portal in its own tab.

  1. In Configurations, add a new configuration:
    • EMM DPC: select WeGuard from the dropdown
    • Company name / support email / phone: what users see during provisioning
    • DPC extras: leave blank unless WeGuard support says otherwise
  2. Save it.
  3. Then — the step that saves future work — open the configuration's menu and Set as default. Every device the reseller registers from now on auto-assigns to WeGuard.

Without a default, each new batch needs manual assignment in the Devices tab (checkbox the devices → Assign Configuration → WeGuard).

Verify devices are registered

The portal's Devices tab should list what the reseller registered — IMEI/serial, model, and the assigned configuration. Empty list? The customer sends their Zero Touch customer ID to their reseller; there is no self-serve add.

Prepare the WeGuard side

In WeGuard, make sure the right policy exists — Work Managed (Corporate) is the usual choice for zero-touch fleets, Kiosk for dedicated devices. Zero-touch enrolled devices pick up the default policy configured under Settings → Device Provisioning.

First boot

Unbox, power on, connect (Wi-Fi or SIM). The device checks in with Google, skips the consumer setup wizard, installs the WeGuard agent, applies the policy, and lands on the managed home screen. Devices show Active in the WeGuard Devices list.

The property that makes this corporate-proof: a factory reset doesn't free the device. Its assignment lives in Google's servers, so the next boot re-enrolls it — which is exactly what you want for company-owned hardware.

When it fails

  • Device boots to the normal consumer wizard — it isn't registered (check the portal's Devices tab) or no configuration is assigned.
  • Registered but not connecting to WeGuard — open the configuration and confirm the EMM points at WeGuard, and that the device had connectivity on first boot.
Knowledge check
1. The customer's Zero Touch portal shows zero devices. Who fixes that?
2. What does setting a default configuration in the Zero Touch portal do?
3. What is the minimum Android version for Zero Touch enrollment?