Every school IT administrator managing Chromebooks eventually arrives at the same question: how do you control 200, 500 or 2,000 devices without touching each one individually?
The answer is Google Admin Console — and the licence that unlocks device management inside it is Chrome Education Upgrade (CEU).
This guide is for school IT administrators and technology coordinators in India. It covers the Admin Console from first login to advanced policy management — everything you need to run a managed Chromebook fleet.
What is Google Admin Console?
Google Admin Console (admin.google.com) is Google's centralised management platform for all Google Workspace services. For schools, it has two main functions:
- User management — create and manage student and teacher Google accounts (included with every Workspace for Education plan, including free Fundamentals)
- Device management — control every Chromebook enrolled in your domain (requires Chrome Education Upgrade per device)
This guide focuses on device management — the part that requires Chrome Education Upgrade.
Before You Start: What You Need
Before enrolling Chromebooks in Admin Console, confirm you have:
| Requirement | Details |
|---|---|
| Google Workspace for Education domain | Even the free Fundamentals tier works |
| Admin account | Super Admin or Device Admin role |
| Chrome Education Upgrade licences | One per Chromebook (perpetual, one-time purchase) |
| Enrolled devices | Chromebooks or ChromeOS Flex devices |
If you don't have Chrome Education Upgrade yet, contact Cloudfy Systems at +91 97600 50555. CEU is a perpetual per-device licence — you pay once, it covers the device for its lifetime.
Step 1: Understand Organisational Units (OUs)
Before enrolling any device, design your Organisational Unit (OU) structure. OUs are folders that let you apply different policies to different groups.
A typical school OU structure:
[YourSchool.edu.in]
├── Students
│ ├── Primary (Classes 1–5)
│ ├── Middle (Classes 6–8)
│ └── Senior Secondary (Classes 9–12)
├── Teachers
├── Admin Staff
└── Labs
├── Computer Lab 1
└── Computer Lab 2
Why this matters: You apply Chromebook policies at the OU level. Primary students get stricter content filtering. Senior secondary students get access to more apps. Teachers get unrestricted browsing. Lab devices might be locked to specific apps only.
Plan this structure before you enroll a single device. Moving devices between OUs later is easy, but setting it up correctly from the start saves time.
Step 2: Enable Chrome Device Management
- Log into admin.google.com with your Super Admin account
- Go to Devices → Chrome → Settings → Device Settings
- Confirm that Chrome Management — Partner Access is enabled
- Verify your domain has active Chrome Education Upgrade licences under Billing → Licences
If licences don't appear, they haven't been applied to your domain yet. Contact your Google for Education partner (Cloudfy) to provision CEU licences.
Step 3: Enroll Chromebooks
There are two methods to enroll Chromebooks into your Admin Console.
Method A: Manual Enrollment (small fleets)
- On the Chromebook, reach the sign-in screen
- Press Ctrl + Alt + E simultaneously — this opens Enterprise Enrollment
- Sign in with an admin account from your school's Google Workspace domain (e.g., admin@yourschool.edu.in)
- The device enrolls and downloads your configured policies automatically
- The device will restart and show the school-managed sign-in screen
This method works for 1–50 devices. For larger fleets, use Zero Touch Enrollment.
Method B: Zero Touch Enrollment (large fleets)
Zero Touch Enrollment (ZTE) is the preferred method for schools procuring 50+ devices.
When Cloudfy supplies your Chromebooks with Chrome Education Upgrade, the devices are registered to your school's domain in Google's Zero Touch portal before they ship.
When a student (or IT admin) turns on the Chromebook and connects to Wi-Fi:
- The device contacts Google's enrollment servers
- Google identifies the device as belonging to your domain
- Your Admin Console policies download automatically
- The device configures itself — no IT staff involvement needed
For ZTE to work, you must:
- Share your domain with your hardware supplier (Cloudfy) at procurement time
- Have your OU structure and policies already configured in Admin Console
Zero Touch Enrollment is available for Chromebook, Chromebook Plus, Chromebox OPS and ChromeOS Flex devices.
Step 4: Configure Device Policies
Once devices are enrolled, apply policies from Devices → Chrome → Settings → Device Settings.
Select the OU you want to configure (e.g., Students → Primary) and set:
Recommended Settings for Student Devices
Sign-in Settings:
- Restrict sign-in to users of the following domain: Set to
@yourschool.edu.in— prevents students from signing in with personal Gmail accounts - Guest mode: Disable — prevents unauthenticated use
Content & Apps:
- URL blocking: Add categories to block (adult content, gaming, social media)
- SafeSearch enforcement: Enforce for all student OUs
- Chrome Web Store permissions: Restrict to school-approved apps only
Device Update Settings:
- Auto-update settings: Allow updates — set to update during school holidays (Friday night to Monday morning)
- Freeze OS updates during exams: Use the release channel freeze option
Kiosk & Single-App Mode:
- For exam devices, you can lock a Chromebook to a single app (e.g., a proctored exam browser)
Recommended Settings for Teacher Devices
- Allow unrestricted browsing
- Enable all Chrome Web Store apps
- Allow guest mode (for presentations on projector Chromebooks)
Step 5: Push Apps and Extensions
Go to Devices → Chrome → Apps & Extensions to manage what appears on student Chromebooks.
Force-Install Apps (students can't remove these)
Recommended force-installed apps for Indian school Chromebooks:
- Google Classroom (if not already installed)
- Google Meet (for online classes)
- Khan Academy (free learning platform)
- Your school's LMS or assessment tool
Block Apps
You can block specific apps and extensions that distract students — games, chat apps, entertainment streaming.
Approved App List
For strict environments (exam labs, primary grades), set the Chrome Web Store to "Only allow installation of apps and extensions from the following list" and whitelist only the apps you've approved.
Step 6: Set Up Safe Browsing & Content Filtering
Go to Devices → Chrome → Settings → User & Browser Settings, select a student OU, and configure:
Safe Browsing:
- Enable Safe Browsing — protects against malicious sites
- Enable Google SafeSearch — filters explicit content from search results
- Enable YouTube Restricted Mode — limits YouTube content to age-appropriate videos
URL Filtering: Use the URL Blacklist and URL Whitelist to block distracting sites and allow specific educational URLs:
Blocked examples:
*://*.instagram.com/*
*://*.tiktok.com/*
*://*.pubg.com/*
*://reddit.com/*
Allowed examples:
*://*.khanacademy.org/*
*://*.ncert.nic.in/*
Step 7: Remote Device Management
View All Enrolled Devices
Go to Devices → Chrome → Devices to see every enrolled Chromebook:
- Serial number
- Last signed-in user
- OS version and compliance status
- Enrollment date and OU assignment
Remote Wipe
If a Chromebook is lost or stolen:
- Find the device in the Devices list
- Click the device → More actions → Wipe Device
- The device factory-resets on its next internet connection — all local data is deleted
This is why CEU is critical for school device fleets. Without it, a stolen Chromebook retains student data indefinitely.
Disable a Device
If a device is stolen and you don't want data wiped (to preserve evidence), use Disable Device — it locks the device and shows a custom message when anyone tries to use it.
Step 8: Device Audit Reports
Go to Devices → Chrome → Reports for fleet-wide visibility:
- Device status report — which devices are active, disabled or returned
- OS update report — which devices need ChromeOS updates
- App and extension usage — which apps students are using
- Login report — which users signed into which devices
Export reports as CSV for procurement audits, insurance claims or school board reporting.
Admin Console for ChromeOS Flex
All the above steps apply identically to ChromeOS Flex devices — old Windows laptops or Macs running ChromeOS Flex with a Chrome Education Upgrade licence.
The only limitation: ChromeOS Flex devices cannot be enrolled using Zero Touch Enrollment (ZTE is hardware-dependent). Manual enrollment (Ctrl + Alt + E) is required for ChromeOS Flex.
Common Admin Console Mistakes to Avoid
| Mistake | What Happens | Fix |
|---|---|---|
| Enrolling devices before configuring policies | Devices enroll but have no policies — need to re-push | Set up OUs and policies first |
| Using a student account to enroll | Device goes into the wrong OU | Always use an admin account for enrollment |
| Blocking YouTube entirely | Teachers can't use video lessons | Use YouTube Restricted Mode + allow specific channels |
| Forgetting to set sign-in restrictions | Students sign in with personal Gmail | Restrict sign-in to school domain |
| Not setting update schedules | Updates interrupt class time | Schedule updates for non-school hours |
Need help setting up Chromebook management for your school?
Cloudfy Systems handles Admin Console configuration, Chrome Education Upgrade licensing and Zero Touch Enrollment for Indian schools. Call +91 97600 50555 or WhatsApp us.
Learn about Chrome Education Upgrade →Frequently Asked Questions
Does Admin Console device management require Chrome Education Upgrade?
Yes. User account management (creating student/teacher accounts, resetting passwords) is included in every Workspace for Education plan. Device management — enrolling Chromebooks, applying device policies, pushing apps and enabling Zero Touch Enrollment — requires Chrome Education Upgrade on each device.
Can I manage ChromeOS Flex devices the same way as Chromebooks?
Yes, with one exception: ChromeOS Flex does not support Zero Touch Enrollment. All other Admin Console features — device policies, app management, remote wipe, content filtering, update management — work identically on ChromeOS Flex devices with a Chrome Education Upgrade licence.
How many devices can I manage in Admin Console?
There is no fixed limit on the number of enrolled devices in Admin Console. Your practical limit is the number of Chrome Education Upgrade licences you have purchased. Each enrolled device consumes one CEU licence.
Can students unenroll their Chromebooks from Admin Console?
No. Once enrolled with Chrome Education Upgrade, a Chromebook cannot be unenrolled by a student. Only a domain Super Admin can unenroll a device from admin.google.com. This is an important security feature.
What happens to the CEU licence if a Chromebook breaks?
The Chrome Education Upgrade licence is tied to the device serial number. If a device is irreparably damaged, you can deprovision it in Admin Console and the licence becomes available to apply to a replacement device. Contact Cloudfy for the exact process for licence transfers.
