Device provisioned to wrong tenant: remove serial from production template and reprovision
Android
Title: Device enrolled in wrong tenant — reprovision to correct tenantWhen a device is provisioned to the wrong Esper tenant (for example, to your Production tenant instead of your QA tenant), the device will appear in the wrong Console, receive the wrong policies, and may be inaccessible to the team that needs it. Resolving this requires removing the device's serial number from the Production provisioning template, factory resetting the device, and reprovisioning it to the correct tenant.
Why this happens
Esper provisioning templates can include an explicit list of serial numbers that lock specific devices to a tenant. If a device serial number is present in a Production template at the time of provisioning, the device will enroll into Production regardless of which tenant you intended it for. Removing the serial number from that template before reprovisioning breaks the association and allows the device to enroll into your QA tenant instead.
Before you begin
You need admin-level access to your Production tenant to complete Steps 1–3. If you only have access to your QA tenant, ask the account holder with the Enterprise Admin role to complete those steps on your behalf. To identify your Enterprise Admin, log in to your QA Esper Console and go to User Management — the Enterprise Admin role will be listed against their account.
Step 1: Remove the device serial from the Production template
- Log in to your Production Esper Console with an account that has provisioning template management permissions.
- Navigate to Provisioning Templates and open each template to search for your device's serial number. A single serial number can appear in more than one template, so check all of them — leaving it in any template will cause the device to re-enroll into Production after the factory reset.
- In each template where the serial number appears, remove it from the Serial Numbers section and save the template.
Step 2: Check Zero-Touch Enrollment and Samsung KME
If your device is registered in Google Zero-Touch Enrollment or Samsung Knox Mobile Enrollment (KME), it will re-enroll into Production automatically after a factory reset, even after you remove it from the Esper template. Check both portals and remove or reassign the device before proceeding.
- Google Zero-Touch Enrollment: Log in to partner.android.com/zerotouch, locate the device by serial number, and either remove it or reassign it to your QA configuration.
- Samsung KME: Log in to the Knox portal, locate the device, and remove or reassign it to your QA profile.
Step 3: Factory reset the device
Use one of the following methods to factory reset the device:
- Via Esper Console: Go to Devices & Groups → [Device Name] → Actions and select Factory Reset.
- Manually on the device: Power off the device, boot into recovery mode using the hardware key combination for your device model, and select Wipe data / Factory reset from the recovery menu.
Step 4: Confirm the QA tenant has a provisioning template for this device
Before reprovisioning, verify that your QA tenant has a provisioning template that accepts this device model. If no template exists, ask your QA tenant admin to create or update one before you proceed. Attempting to provision without a matching template will result in the device either failing to enroll or enrolling without the correct policy applied.
Step 5: Reprovision the device to the QA tenant
- Log in to your QA Esper Console and confirm the provisioning method your QA tenant uses — QR code, Zero-Touch Enrollment, or Samsung KME.
- Follow the provisioning workflow for that method on the device to enroll it into the QA tenant.
Verify
Verify: Log in to your QA Esper Console and navigate to Devices & Groups. The device should appear with a status of Active within 5 minutes of completing provisioning. Confirm that the correct blueprint or policy is applied to the device and that it no longer appears as active in your Production tenant's Devices & Groups view.
If this doesn't resolve it
If the device continues to re-enroll into Production after you have removed it from all templates and from Zero-Touch or KME, contact Esper Support with the following information:
- The device serial number
- The names of all Production provisioning templates you checked
- Confirmation of whether the device is registered in Zero-Touch Enrollment or Samsung KME, and the steps already taken in those portals
- A screenshot of the device's entry in your Production Console's Devices & Groups view
- The Activity Feed log from the device, available at Devices & Groups → [Device Name] → Activity Feed
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments