Jump to content

Recommended Posts

Posted (edited)

I'm in the process of setting our site up to cope with chromebooks, starting basically from scratch as i'd never used one before today. I have one chromebook on my desk to help me get all this setup.

 

I've walked through these steps: https://support.google.com/chrome/a/answer/7497916?hl=en

 

I've got as far as having a chromebook added to AD, I can login as a domain user etc. I've also got the chromeos and chrome admx templates in AD and i can verify that policies are applying to the device correctly.

 

I've got a few issues though:

1. How do i push a certificate on to these devices? I need to put my smoothwall certificate on to them for MITM

2. How do i restrict the network settings so that students can't play around and connect the wireless to their phone hotspots for example.

3. When i try logging into office 365 on these devices I enter the [email protected] and then i get another "authentication required" pop up login with the address of my adfs server in the address bar. Typing the username and password in there just loops over and over asking for that same login and never actually logs me in. Don't have any issues with this on other devices. (well maybe some iPads and iPhones but i've never had time to look into that)

4. I'm logging in as a domain user, however smoothwall doesn't appear to be able to identify the user that's logged in if i look at the web filter logs coming from that device. I've not set any of the smoothwall google specific settings, not sure what i need there.

 

Any tips for a chromebook noob?

 

EDIT: Fixed #3 with this: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-intranet-forms-based-authentication-for-devices-that-do-not-support-wia seems i just needed to update the list of supported clients

Edited by mrbios
Posted

First of all, for your Chromebooks do you have Chrome Enterprise licenses or Chrome Education licenses?

 

1 and 2, you can do from the chrome device management in the Admin console (admin.google.com)

Posted
First of all, for your Chromebooks do you have Chrome Enterprise licenses or Chrome Education licenses?

 

1 and 2, you can do from the chrome device management in the Admin console (admin.google.com)

 

At the moment I'm on the trial setup of the Chrome Enterprise one while i test things. All the areas that should let me do 1 and 2 are all greyed out and inaccessible on the portal I've got.

 

I've now got two google admin logins, one for the chrome enterprise for active directory integration with the [email protected] login, and one that users are synced to with my proper school domain login. The latter of which has those settings available, but can't be used with active directory logins (not sure why google specify the need for a new account specific to AD integration, but they do)

Posted
Got another problem now, I've got "Enable android applications to be managed through the admin console" enabled, and i've set the identity provider metadata for AD integration from my ADFS server. I've also been on to the managed play store and approved a few apps, enabled the chromeos policies for enable ARC and configure ARC. However when i login to the chromebook and click the playstore it just whirls round and round for ages before eventually just telling me "Something went wrong" with no other information. Anyone else dealt with this before?
  • 8 months later...
Posted
@mrbios Did you manage to get this successfully sorted?

I've just started working with a pair of new chromebooks and having the same issues.

 

Unfortunately not, i ended up resorting to the Gsuite integrated rather than AD integrated route in the end.

 

I did find that even with the Gsuite route, a lot of my issues revolved around ADFS.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...