Managing Chrome Hardware Lifecycles
When an enterprise organization utilizes ChromeOS devices (Chromebooks or Chromeboxes), these devices are typically enrolled into Google Workspace. This enrollment enforces strict corporate policies, forces specific apps to install, and prevents unauthorized users from logging in. It also permanently ties the physical hardware to your corporate domain.
If a Chromebook reaches its end-of-life (EOL), is scheduled to be sold to a surplus vendor, or is being given to a graduating student, you cannot simply perform a factory reset (Powerwash). If a managed device is wiped, it will immediately phone home to Google during the next setup process and lock itself back to your domain, rendering it useless to the new owner.
Before releasing the hardware, a system administrator must explicitly Deprovision the device in the Admin Console.
Step 1: Locate the Device
- Log into the Google Workspace Admin Console (admin.google.com).
- Navigate to Devices > Chrome > Devices.
- You will see a master list of every piece of Chrome hardware registered to your company.
- Use the search bar at the top to locate the specific device. It is highly recommended to search by Serial Number (e.g.,
5CD923A4X1) rather than relying on user assignments or recent IP addresses. - Click on the Serial Number to open the detailed device profile.
Step 2: Execute the Deprovision Command
Once you are looking at the specific device profile, you can sever its connection to your domain.
- At the top of the device profile page, click the Deprovision button.
- A critical warning prompt will appear. Google requires you to provide a reason for the deprovisioning.
- Select a reason from the dropdown menu (e.g., “Retiring device,” “Selling or donating,” or “Replacing hardware”).
- Crucial Step: If you are completely getting rid of the device, you must check the box acknowledging that you understand you will lose the Chrome Enterprise upgrade license associated with this machine (unless you are replacing it with a same-model RMA replacement).
- Click Deprovision to confirm.
Step 3: Verify the State
The device state in the Admin Console will immediately change from Provisioned to Deprovisioned.
The next time the physical Chromebook connects to the internet, it will receive the deprovisioning signal. It will wipe any remaining corporate data and completely remove the enterprise enrollment lock.
Step 4: The Final Wipe
Although the device is now technically free from your domain, it is best practice to perform a final local wipe (Powerwash) to ensure the local SSD is completely clean before handing it to a surplus vendor.
- On the physical Chromebook, press Ctrl + Alt + Shift + R at the login screen.
- Click Restart.
- When prompted, click Powerwash and confirm.
The device is now a standard, consumer-grade Chromebook, ready for its next owner.