# Android Zero Touch Enrollment(ZTE) for Enterprises | ManageEngine Mobile Device Manager Plus This guide explains how to set up and manage Android Zero-Touch Enrollment in ManageEngine Mobile Device Manager Plus. It covers the prerequisites, portal setup, Android for Work integration, JSON configuration, device association, device activation, user assignment, troubleshooting, and related resources. Android Zero Touch Enrollment or Android Zero Touch Provisioning (ZTP) is a device enrollment method provided by Google that streamlines the enrollment and deployment of organization-owned Android devices in bulk. This method is also known as Google Zero Touch provisioning and lets devices enroll with MDM by downloading the ME MDM app during activation. ## Advantages of Android Zero Touch Enrollment - One-time setup - Aids large scale enterprise device roll out - Mandatory MDM management - Allows resellers to add devices to portal, easing enrollment process - Admins can set up the device with necessary apps and profiles and it gets applied automatically on device activation. ## Prerequisites for Zero Touch Enrollment - Android Zero Touch Enrollment is supported for devices running Android 9.0 or later, purchased from [specified reseller partners](https://androidenterprisepartners.withgoogle.com/resellers/index.html). - You need a Zero-touch portal account which can be obtained by contacting your reseller. ## Getting Your Zero Touch Portal ## Associating a Google Account If you already have a Google account associated with your corporate email, you can skip this section. You require a Google account (associated with your corporate e-mail), to setup the Android Zero Touch Portal. To associate, follow the steps below: - Go to [this link](https://accounts.google.com/signupwithoutgmail) and provide the requisite details. - Ensure you provide your corporate e-mail address for **e-mail address**. Do not click on **I would like a new Gmail address.** - Follow the on-screen instructions to complete the account creation. ## Zero-touch Portal Account After creating a Google account for your enterprise, contact your resellers to get your Zero-touch portal. Only the devices purchased from authorized resellers are eligible for getting the Zero-touch portal. Get your Zero-touch portal with your Enterprise Google account. [Read more about Zero-touch portal setup](https://support.google.com/work/android/answer/7514005) ## Steps for configuring Zero Touch Enrollment - [Configure Android for Work](#configure_android_for_work) - [Integrate Android for Work with Zero-touch](#integrate_android_for_work_with_zero-touch) - [About Zero-touch portal](#about_zero-touch_portal) - [Setting up Zero-touch portal using JSON configurations](#set_up_zero-touch_portal_using_json_configurations) - [Associate JSON configurations](#associate_json_configuration_to_devices_legacy_setup) **NOTE:** Since Google has updated the setup for Zero-Touch enrollment, the Zero-Touch portal needs to be linked with Android For Work. This will simplify the enrollment process. If you are prompted to configure Android for Work while setting up Zero-Touch, this indicates that you are using the updated version. Users who have not updated the product and still retaining the old version can directly go to [Setting up Zero-touch portal using JSON configurations](#set_up_zero-touch_portal_using_json_configurations). ## Configure Android for Work Configuring Android for Work is the first process in setting up Zero-touch. We recommend you temporarily enable third-party cookies while integrating Android for Work with Zero-touch. When disabled, the link for integration becomes unauthorized. **Case 1:** When Android For Work is not configured. On the MDM console, navigate to **Enrollment → Zero-Touch Enrollment**. Follow the on-screen instructions to set up Android For Work. To set up Android for Work, refer to the [Android for Work setup guide](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_afw_prerequisites.html). ![MDM console Zero Touch Enrollment page prompting Android for Work configuration — Case 1: Android for Work not yet configured](https://www.manageengine.com/mobile-device-management/help/images/ZT_Configure_AFW_case1.jpg) **Case 2:** When Android for Work is already configured. If you have already configured Android for Work while setting up app management for Android devices, you need to link Android for Work with Zero-touch. Navigate to **Enrollment → Zero-touch Enrollment → Launch Zero-touch Portal**. **Management Type:** Select the Management Type of the device: 1. **Full Device Management:** Admin has full control over the device. 2. **Workspace Management:** Admin can manage only the corporate apps and data by creating a separate work container on the device. ![Management type selection screen showing Full Device Management and Workspace Management options — Case 2: Android for Work already configured](https://www.manageengine.com/mobile-device-management/help/images/ZT_Configure_AFW_case2.jpg) ## Integrate Android for Work with Zero-touch Integrate your Android for Work with Zero-touch to continue the set up. ### Steps to Integrate Android for Work with Zero-touch 1. After setting up Android for Work, you will be automatically re-directed to integrate Zero-touch with Android for Work. ![Step 1: Redirect screen to begin Zero-touch and Android for Work integration](https://www.manageengine.com/mobile-device-management/help/images/ZT_Link_step1.jpg) 2. Click on the **Next** button. Sign in with your Zero-touch account credentials. ![Step 2: Sign-in page for entering Zero-touch account credentials](https://www.manageengine.com/mobile-device-management/help/images/ZT_Link_step2.png) 3. Choose the accounts which contain the devices to be managed. ![Step 3: Account selection screen to choose Zero-touch accounts containing devices to manage](https://www.manageengine.com/mobile-device-management/help/images/ZT_link_step3.jpg) 4. Click **Link** to display account details. ![Step 4: Account details confirmation screen after clicking the Link button](https://www.manageengine.com/mobile-device-management/help/images/ZT_link_step4.jpg) 5. Provide your company's support details for employees to reach you during setup. ![Step 5: Company support details entry page for Zero-touch enrollment contact information](https://www.manageengine.com/mobile-device-management/help/images/ZT_link_step5.jpg) 6. If successful, access the Zero-touch portal from **Enrollment → Zero-touch Enrollment → Settings → Launch Zero-touch Portal**. ![Step 6: Successful Zero-touch and Android for Work integration confirmation in MDM console](https://www.manageengine.com/mobile-device-management/help/images/ZT_Link_step6.png) The Zero-touch setup is now complete. ## About Zero-touch portal Zero-touch portal contains the details of the devices, resellers, MDM configurations and so on. | Parameter | Description | |---|---| | Configurations | If you have an updated setup, you are provided with Enterprise Default Configurations which cannot be modified. Else, you add, modify and delete the MDM configurations here. You can also assign MDM configurations by default to devices being added. | | Devices | View devices added to the account. Assign configurations or delete devices. | | Manage People | Add, modify and delete users who can manage and access the portal. | | Resellers | Add additional reseller details. | ![Zero-touch portal console showing Configurations, Devices, Manage People, and Resellers navigation sections](https://www.manageengine.com/mobile-device-management/help/images/ZT_console.jpg) ## Set Up Zero-touch Portal Using JSON Configurations If setting up using JSON configuration: ![Zero-touch portal JSON-based configuration setup flow diagram for legacy users](https://www.manageengine.com/mobile-device-management/help/images/Zt_old_steps.png) - [Log in to the Zero-touch portal](https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fenterprise.google.com%2Fandroid%2Fzero-touch%2Fcustomers&followup=https%3A%2F%2Fenterprise.google.com%2Fandroid%2Fzero-touch%2Fcustomers&ifkv=ASKV5MgX7Csqjlc38JVIxveQoJpqjl8fMSKevcjclThKhE5o8yrBAK9aqtpZSi-O8pv16ihFsO3qYw&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S1228149888%3A1747305157474025). - Click **Configurations** and then **+** to add a new configuration. ![Zero-touch portal Configurations panel with the Add (+) button to create a new MDM configuration](https://www.manageengine.com/mobile-device-management/help/images/ZT_console2.png) ### Zero-touch Configuration Parameters and Descriptions | Parameter | Description | |---|---| | Name | Name used to refer to the created MDM configuration. | | EMM DPC | Select **ManageEngine MDM app** from the list. | | DPC Extras | Copy from step 4 in the MDM console. | | Company Name | Organization name displayed during enrollment. | | Contact E-mail | IT admin e-mail displayed during enrollment. | | Contact Phone | IT contact number displayed during enrollment. | | Custom Message | Optional message displayed during enrollment. | ![Zero-touch portal new configuration form showing Name, EMM DPC, DPC Extras, Company Name, Contact Email, and Contact Phone fields](https://www.manageengine.com/mobile-device-management/help/images/ZT_console3.jpg) ## Associate JSON Configuration to Devices (Legacy Setup) - Log in to the Zero-touch portal. - Set the configuration as default under **Configurations** → **Default Configuration**. ![Zero-touch portal showing the Default Configuration setting under the Configurations section](https://www.manageengine.com/mobile-device-management/help/images/ZT_console4.png) ### Assigning Zero-touch Configurations to Devices Individually - Click **Devices** → ellipsis → **Upload batch configuration**. - Upload a CSV based on the specifications below. ![Zero-touch portal Devices panel with the Upload batch configuration option highlighted](https://www.manageengine.com/mobile-device-management/help/images/ZT_console5.jpg) ## Device configuration CSV file format | Column Header | Description | Example | |---|---|---| | modemtype | Always IMEI (uppercase). | IMEI | | modemid | IMEI number. | 150520043826120 | | manufacturer | Device manufacturer. | Google | | profiletype | Always ZERO_TOUCH (uppercase). | ZERO_TOUCH | | profileid | ID of the MDM configuration. | 036180 | ![Zero-touch portal showing device configuration CSV column headers: modemtype, modemid, manufacturer, profiletype, and profileid](https://www.manageengine.com/mobile-device-management/help/images/ZT_console6.jpg) ## Link Zero-touch with Android for Work (Updated Setup) If already set up using JSON, link it with Android for Work via **Enrollment → Zero-touch Enrollment → Settings → Launch Zero-touch portal**. ![Link Zero-touch with Android for Work option displayed in updated MDM console settings](https://www.manageengine.com/mobile-device-management/help/images/ZT_Link_AFW.jpg) ## Enrolling devices ### Device Activation Device activation can be performed by user or admin based on assignment. ![Device activation settings in MDM console showing Admin and User activation options for Zero Touch Enrollment](https://www.manageengine.com/mobile-device-management/help/images/ZT_Device_activation.jpg) When activated for the first time, devices enroll automatically and install the MDM app. - Welcome screen appears. ![Android device welcome screen displayed at the start of Zero Touch Enrollment activation](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile1.png) - Connect to Wi-Fi. ![Wi-Fi network connection screen during Zero Touch Enrollment device setup](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile2.png) - Activation stages: ![Stage 1 of Zero Touch Enrollment device activation process](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile3.png) ![Stage 2 of Zero Touch Enrollment device activation process](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile4.png) ![Stage 3 of Zero Touch Enrollment device activation process](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile5.png) ![Stage 4 of Zero Touch Enrollment device activation process](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile6.png) ![Stage 5 of Zero Touch Enrollment device activation process](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile7.png) ![Stage 6 of Zero Touch Enrollment device activation process](https://www.manageengine.com/mobile-device-management/help/images/ZT_workprofile8.png) - MDM app installs automatically. **By admins:** ![MDM enrollment in progress screen on Android device during Zero Touch Enrollment](https://www.manageengine.com/mobile-device-management/help/images/ZT_enrollment_in_progress.png) ![Device assigned by admin during Zero Touch Enrollment showing admin assignment confirmation](https://www.manageengine.com/mobile-device-management/help/images/ZT_by_admin.png) **By users:** ![MDM enrollment in progress screen on Android device during Zero Touch Enrollment](https://www.manageengine.com/mobile-device-management/help/images/ZT_enrollment_in_progress.png) ![User self-assignment screen during Zero Touch Enrollment requiring Active Directory credentials](https://www.manageengine.com/mobile-device-management/help/images/ZT_by_users.jpg) **NOTE:** Internet connection is mandatory during activation for enrollment to complete. ## User assignment Devices enrolled via Zero Touch must be assigned to users. Configure via **Enrollment → Zero-touch Enrollment → Settings → Device Activation**. ### Assign Users Manually - Go to **Enrollment** → **Zero Touch Enrollment**. - Click **Assign User** under **Action**. ![Zero Touch Enrollment device list in MDM console with the Assign User option under the Action column](https://www.manageengine.com/mobile-device-management/help/images/ZT_assign_user.png) - For bulk assignment, click **Assign Users** and upload a CSV. ![Bulk user assignment screen in MDM console showing the Assign Users button and CSV upload option](https://www.manageengine.com/mobile-device-management/help/images/ZT_assign_users.png) - Use serial numbers or IMEI numbers from reseller invoice to pre-assign users via CSV. ## Sample CSV Format ``` SERIAL_NUMBER,USER_NAME,DOMAIN_NAME,EMAIL_ADDRESS,GROUP_NAME C07Q853LG9RM,ANDREW,,andrew@zylker.com,zylker_drivers ,BEN,ZOHOCORP,ben@mobiledevicemanagerplus.com,Android,Corporate,Android_Group, ``` **NOTE:** 1. Serial Number, User Name, Email Address and Group Name are mandatory. 2. Default values: - Domain Name -- MDM - Owned By -- Corporate 3. Multiple groups must be separated with a slash (/). 4. First line is column header; order can vary. 5. Blank values must be comma separated. 6. If a value contains a comma, enclose it in quotes. ### Automate User Assignment - Select **User** for **Device to be activated by**. ![Device activation settings in MDM console with User option selected to enable automated user assignment](https://www.manageengine.com/mobile-device-management/help/images/ZT_users_assignment.jpg) Supported directory services: - Active Directory - Entra ID (formerly Azure AD) MDM Cloud uses Zoho Accounts by default. Optionally select a **Group** for automatic app and profile distribution. ## Dissociating Zero-touch portal - **Removing Android for Work —** Unlink via **Enrollment → Zero-touch Enrollment → Settings → Launch Zero-touch portal**. ![Unlinking enterprise account from Zero-touch portal in MDM console settings](https://www.manageengine.com/mobile-device-management/help/images/ZT_unlink_AFW.png) Click **Remove Android for Work** after unlinking. ![Remove Android for Work button in MDM console after unlinking the Zero-touch account](https://www.manageengine.com/mobile-device-management/help/images/ZT_remove_AFW.png) - **Deleting MDM configurations (legacy users) —** Delete the configuration to remove MDM association. ![Deleting an MDM configuration from the Zero-touch portal for legacy users](https://www.manageengine.com/mobile-device-management/help/images/ZT_remove_config.png) **NOTE:** Removing Android for Work disables silent app installation. [Click here to view the ports required for managing mobile devices.](https://www.manageengine.com/mobile-device-management/faq.html#g1) ## Troubleshooting Tips for Zero Touch Enrollment - Check the [Zero-touch Known Issues](https://developers.google.com/zero-touch/resources/known-issues) page. - **No accounts found message in iframe** ![No accounts found error message displayed in the iframe during Zero Touch Enrollment integration](https://www.manageengine.com/mobile-device-management/help/images/zte-tt.png) Ensure the account has portal access and prerequisites are met: https://www.manageengine.com/mobile-device-management/help/enrollment/android_zero_touch_enrollment.html#prerequisites - **Already linked error** ![Already linked error message shown when the Zero-touch account is already associated with another MDM solution](https://www.manageengine.com/mobile-device-management/help/images/zte-tt2.png) Disassociate the account from the previous MDM provider and retry integration. ## Frequently Asked Questions **How do I create a new Android Zero-Touch portal and what are the prerequisites for integrating it with ManageEngine MDM?** Contact the authorized reseller to initiate setup using your corporate Google account. Refer to the [official Zero-Touch documentation](https://support.google.com/work/android/answer/7514005). Prerequisites are available [here](https://www.manageengine.com/mobile-device-management/help/enrollment/android_zero_touch_enrollment.html#prerequisites). ## Related Articles - [Android for Work Prerequisites and Setup](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_afw_prerequisites.html) - [Android Enterprise Enrollment Overview](https://www.manageengine.com/mobile-device-management/help/enrollment/android_enterprise_enrollment.html) - [Android QR Code Enrollment](https://www.manageengine.com/mobile-device-management/help/enrollment/android_qr_enrollment.html) - [Android NFC Enrollment](https://www.manageengine.com/mobile-device-management/help/enrollment/android_nfc_enrollment.html)