Jump to content

Google Credential Provider (GCPW) - New teacher has started using device. How do I remove old user?


Recommended Posts

Posted

I have just been told that a teacher left a few weeks ago and their laptop has already been handed to a new teacher.

 

With GCPW, the first teacher to log in becomes the 'settings deployment' account.

 

How do I remove the old teachers account from the laptop, and make the current teachers account the 'settings deployment' account?

Posted
1 minute ago, TwistedHelixis said:

I have just been told that a teacher left a few weeks ago and their laptop has already been handed to a new teacher.

 

With GCPW, the first teacher to log in becomes the 'settings deployment' account.

 

How do I remove the old teachers account from the laptop, and make the current teachers account the 'settings deployment' account?

 

I believe (could be totally wrong) this is the downside to using the teachers own accounts to enrol them. I used this method, and used to just completely wipe the device and rebuild it.

 

You can "unenroll" a device from the admin console, however... this only removes selected settings - https://knowledge.workspace.google.com/admin/devices/unenroll-a-device-from-windows-device-management

  • Like 1
Posted

We've taken to providing enrolment accounts for devices and getting our IT team to do the first login with that account before handing devices out.
 

  • Like 2
Posted (edited)
10 minutes ago, paulkerton said:

We've taken to providing enrolment accounts for devices and getting our IT team to do the first login with that account before handing devices out.
 

This is the way^ 

 

If I used it again I would have three enrolment accounts.

 

Student@

Staff@

SLT@

 

Then it doesn't matter who leaves/joins - as the device settings will still be correct for the user, and it won't need to be wiped/unenrolled.

 

@TwistedHelixis - On the link I sent, it does state "If another user enrols in WDM their settings override the existing settings unless the value is Not Configured". But what I am reading from it, is that Bitlocker settings won't change, or any new windows settings you push to it, won't apply (until it's enrolled again).

 

 

Edited by TheHyperTechie
  • Like 1
Posted
3 minutes ago, paulkerton said:

We've taken to providing enrolment accounts for devices and getting our IT team to do the first login with that account before handing devices out.
 

Think Ill start doing this also.

Do you know if there a limit to the amount of devices that the enrollment account can log onto? Would I need multiple enrollment accounts if I have over a specific amount of devices?

Posted
1 minute ago, TwistedHelixis said:

Think Ill start doing this also.

Do you know if there a limit to the amount of devices that the enrollment account can log onto? Would I need multiple enrollment accounts if I have over a specific amount of devices?


I'm not aware of a limit. If there is, we haven't hit one!

Posted
Quote

On the link I sent, it does state "If another user enrols in WDM their settings override the existing settings unless the value is Not Configured". But what I am reading from it, is that Bitlocker settings won't change, or any new windows settings you push to it, won't apply (until it's enrolled again).

 

Ill give this a go for now and let you know how it went.

Posted
Quote

Student@

Staff@

SLT@

 

Pupils are all on Chromebooks and staff all have the same profiles, so I was thinking of creating the accounts based on the device make, just to separate things out a bit.

gcpwDell@

gcpwASUS@

etc

 

Is this OK, or would you still go with staff@ etc?

 

Posted
17 minutes ago, TwistedHelixis said:

 

Pupils are all on Chromebooks and staff all have the same profiles, so I was thinking of creating the accounts based on the device make, just to separate things out a bit.

gcpwDell@

gcpwASUS@

etc

 

Is this OK, or would you still go with staff@ etc?

 

I don't think it really matters to be honest. As it's essentially the same, but I think I just find it easier (for my brain lol) to base the permissions off a user group. But whatever works for you.

  • Like 1
Posted

So I tried to use the Unenroll method posted above. The device does unenroll, but the new teacher never gets to become the master account.

 

Does anyone have any other ideas or steps about changing the main GCPW account on a device?

Posted

So after a few hours of playing, I think it was just the Chrome reg key needing to be deleted.

 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Enrollment > enrollment key

 

After deleting that, logged in and the new teacher is now the main account.

 

Ill reset my test device and run through the process again, as I made a load of changes, so who knows which changes are the correct ones.

Posted

I think another workaround is just deleting the leaver’s local account on the device and then letting the new member of staff sign in. GCPW will then use the next signed in user as the master account.

Posted
42 minutes ago, TheHyperTechie said:

I think another workaround is just deleting the leaver’s local account on the device and then letting the new member of staff sign in. GCPW will then use the next signed in user as the master account.

Ohh that sounds interesting. Are there any steps that need to be completed before deleting the old user?

Posted

So I have managed to move the master profile from the old user to the current user.

 

I believe I can remove some of these steps from the process below, so more testing...

 

Make current user admin in workspace

log onto device as a local admin
Delete reg key HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Enrollment > Delete the Enrollment key.
Reboot the machine.
Login as current user
In workspace delete new device from current users

In workspace unenrol device from old users devices menu
shutdown device until workspace lists the device as unenrolled.
Login as new user

New user should now be the master profile on the device.
 

Posted
14 hours ago, TwistedHelixis said:

OK, deleting the account is a much simpler method.

Glad it worked, not sure why they don't include that in the documentation to be honest. 

 

Lots of weird quirks with GCPW and WDM, that you kind of work out along the way. In my opinion, it's worth the stress though!

Posted (edited)

I have just noticed that in Workspace > Devices, some of my devices now have "Wipe Account", which....

 

Quote

removes corporate data from a Windows device, primarily targeting the user's work profile and associated data, without necessarily affecting personal files on the machine.

 

Has any tested to see if this lets the next user to take over as the master account?

 

Odd that this option is only on some of the devices.

Edited by TwistedHelixis

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...