The Chaos of Unrestricted Enrollment
In a Google Workspace environment that utilizes managed Chromebooks, device enrollment is critical. When a Chromebook is enrolled into your domain, it immediately downloads all of your corporate security policies, Wi-Fi passwords, and forced application installations.
By default, Google Workspace allows any user in the organization to enroll a new Chrome OS device simply by logging into it for the first time. If a student brings their personal Chromebook from home and logs in with their school email, that device instantly becomes fully managed by the school district. When the student goes home, they will discover they can no longer access their personal Gmail or browse freely. This creates massive headaches for IT administrators who must then manually deprovision the device.
To prevent this, you must restrict the Chrome OS enrollment permission to a specific group of IT administrators.
Step 1: Create an IT Administrator Group (Optional)
If you don’t already have an Organizational Unit (OU) or a security group dedicated strictly to IT staff, you should create one first so you can apply the permission exclusively to them.
Step 2: Access the Chrome Device Settings
- Log into the Google Workspace Admin Console (admin.google.com).
- Navigate to Devices > Chrome > Settings > Users & browsers.
- In the left-hand Organizational Unit (OU) tree, select your top-level root organization. This ensures the restriction cascades down to all employees and students.
Step 3: Modify the Enrollment Permission
- Scroll down to the Enrollment controls section.
- Locate the setting named Device enrollment. By default, it is set to “Place Chrome device in user organization.”
- Click the dropdown menu and change it to: Do not allow users in this organization to enroll new devices.
- Click Save at the top right of the screen.
Step 4: Grant Permission to the IT Department
Now that nobody in the company can enroll a device, you must give the power back to your IT technicians so they can configure new inventory.
- In the left-hand OU tree, click on the specific OU containing your IT staff (e.g.,
Staff > Information Technology). - Scroll back down to the Enrollment controls section.
- Change the Device enrollment setting from “Inherited” to Place Chrome device in user organization (or “Place Chrome device in top-level organization” depending on your preferred structure).
- Click Save.
The Result
If a standard employee or student attempts to enroll a personal Chromebook, they will be met with a hard error stating they do not have permission. Your IT technicians, however, can unbox 50 new Chromebooks and enroll them seamlessly using their own credentials.