Zero-Touch Enrollment not working — configure and verify ZTE for Esper
Android
When setting up new Android devices with Google Zero-Touch Enrollment (ZTE), devices must be correctly linked to an Esper Agent configuration before first boot, or they will complete Android setup without enrolling into Esper.
Why this happens
ZTE works by pre-assigning a Device Policy Controller (DPC) configuration to a device's IMEI or serial number in the Google Zero-Touch Portal before the device is powered on. If the configuration is missing, contains malformed JSON, or is applied after the device has already completed Android setup, ZTE cannot trigger enrollment. The Esper Agent extras JSON must match exactly what Esper Console generates — any modification breaks the handshake.
Before you begin
Confirm all of the following are true before proceeding:
- Devices run Android 8.0 or higher.
- Devices were purchased through a ZTE-authorized reseller or carrier.
- Devices are unboxed or factory reset — ZTE cannot enroll a device that has already completed Android setup.
- You have access to a Google Zero-Touch Portal account (provided by your reseller).
If your devices do not meet these requirements, use QR code or Android for Work (AFW) provisioning instead.
Steps
- Generate the Esper Agent extras JSON in Esper Console. Navigate to Provisioning Templates, then create a new template or open an existing one. Select Zero-Touch Enrollment as the provisioning method. Esper Console will generate an Esper Agent extras JSON. Copy this value exactly as displayed — do not add spaces, line breaks, or alter any characters. Any modification will cause enrollment to fail silently.
- Create a ZTE configuration in the Google Zero-Touch Portal. Go to partner.android.com/zerotouch and sign in with your ZTE account. Navigate to Configurations → Add Configuration. In the EMM DPC field, select Esper Device Policy Controller (com.esper.provisioner). In the DPC Extras field, paste the JSON copied from Esper Console in the previous step. Save the configuration.
- Assign the configuration to your devices. In the Google Zero-Touch Portal, navigate to Devices. Locate each device by IMEI or serial number and apply the configuration created in the previous step. This links the enrollment instructions to the device before it is powered on, so ZTE can detect them automatically at first boot.
- Power on each device and connect to Wi-Fi. Unbox or factory reset the device, then follow the Android setup wizard until the Wi-Fi selection screen. Connect to a stable Wi-Fi network. ZTE will detect the pre-assigned configuration automatically and begin Esper enrollment — no manual input is required beyond Wi-Fi.
-
Verify enrollment in Esper Console.
Navigate to Devices & Groups and confirm the device appears with a status of Online. Open the device record and verify the provisioning method shows Zero-Touch and the correct Blueprint is applied.
Verify: The device should appear in Devices & Groups with status Online within 10 minutes of connecting to Wi-Fi. If the correct Blueprint is shown on the device detail page, enrollment is complete.
Troubleshooting
Device does not appear in Esper Console after first boot
The most common cause is a malformed extras JSON. In the Google Zero-Touch Portal, open the assigned configuration and compare the DPC Extras value character-by-character against what Esper Console displays in Provisioning Templates. Look specifically for trailing spaces, missing escape characters, or line breaks introduced by copy-paste. Correct the configuration, save it, factory reset the device, and power it on again.
Enrollment stalls after the device powers on
ZTE requires Google Play Services to initialize during first boot, which requires a stable internet connection. Confirm the device has full Wi-Fi connectivity with no captive portal or proxy blocking outbound traffic. Also verify no SIM lock or carrier restriction is preventing Google services from reaching the internet.
Device does not appear in the Google Zero-Touch Portal
The device's IMEI or serial number may not be registered in your ZTE account. Contact your device reseller to confirm the device was purchased through a ZTE-enabled channel and that the IMEI has been added to your portal account. Devices not registered by the reseller cannot be enrolled via ZTE.
If this doesn't resolve it
Contact Esper Support and include the following:
- The device IMEI or serial number.
- A screenshot of the ZTE configuration in the Google Zero-Touch Portal, including the full DPC Extras field.
- The provisioning template name from Esper Console.
- The Activity Feed export from Devices & Groups for the affected device, if it appears in the Console at all.
- The approximate time and date of the enrollment attempt and the Wi-Fi network used.
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments