How do I set up Chromebooks with Passbeam?
Chromebooks are managed through Google Workspace, as they're not managed by Intune. So you connect the school's Google Admin to Passbeam, then set up four things in Google Admin. Each Chromebook then gets its own certificate and joins the Wi-Fi from the sign-in screen. Nothing needs installing at the school.
Each Chromebook needs a Chrome Education Upgrade or Chrome Enterprise Upgrade licence. Managed school Chromebooks will already have one.
Find the Customer ID. In Google Admin, go to Account → Account settings. It's in the Profile box and starts with C. Copy it, don't type it, as some of the characters look alike.
Connect it in Passbeam. Open the client, go to Certificates → Chromebooks and click Set up Chromebooks. Paste the Customer ID and save. Setup instructions then has every value you need for Google Admin, with copy buttons.
1. The Certificate Authority connection. In Google Admin, go to Devices → Networks → Certificates → Certificate Authority connections and click Add connection. Choose Generic Certificate Authority connection, not SCEP. Give it a name, paste in the service account, the Pub/Sub topic and the configuration identifier from Passbeam, and click Add. This one covers the whole domain.
Ignore Download connector. That's Google's old Windows connector and you don't need it.
2. The certificate provisioning profile. Select the organisational unit your Chromebooks are in, open Certificate provisioning profiles and click Add profile. Pick the connection you just made and tick Chromebooks (by device). Give it a name and a config reference (any short text). Set renewal to 90 days, Authentication type to None and Encryption key type to RSA key - 2048bit.
Use a device certificate for school Chromebooks. It belongs to the Chromebook, not the person, so a shared Chromebook can join the Wi-Fi before anyone signs in.
3. The root certificate. In Passbeam's Setup instructions, download Root CA (.pem). In Google Admin, on the same organisational unit, open Server Certificate Authority certificates and click Add certificate. Upload the .pem file. Google turns the .cer version down with "The uploaded file is invalid, or contains more than one certificate".
Leave all the Enabled for boxes unticked. Those make it trusted for websites as well, and the Wi-Fi doesn't need that. It still shows up in the Wi-Fi settings.
4. The Wi-Fi network. Go to Devices → Networks → Wi-Fi and click Add Wi-Fi, still on the same organisational unit. Tick Chromebooks (by device), enter the name and the SSID exactly as it's broadcast, and tick Automatically connect.
Set Security type to WPA/WPA2/WPA3 Enterprise (802.1X) and the protocol to EAP-TLS. Leave Maximum TLS version on 1.2, the highest Google offers. In Username, put ${CERT_SUBJECT_COMMON_NAME} exactly as written. Google fills in each Chromebook's own name. Choose the root you uploaded as the Server Certificate Authority, paste the server name from Passbeam into Server Certificate Domain Suffix Match, then set Provisioning type to Certificate profile and pick the profile from step 2.
Don't leave Username blank. If you do, the Chromebook says "Error configuring network" and never tries to connect.
Once that's saved, each Chromebook picks the settings up next time it checks in with Google, which can take a little while. Restarting it makes it check straight away. It asks for its certificate, Passbeam issues it, and it joins the Wi-Fi. You'll see each one under Certificates → Chromebooks, and its sign-ins in the Authentication log.
To check a Chromebook, open chrome://certificate-manager. The certificate is under Your certificates → Client certificates from platform. A lot of schools block chrome:// pages. If yours does, add chrome://policy and chrome://certificate-manager as exceptions on the IT team's organisational unit, under URL blocking.
To suspend or revoke a Chromebook, open it in Passbeam. Suspend can be undone, revoke can't. Either one stops it the next time it signs in to the Wi-Fi, and how soon that is depends on Access rules → Re-authentication. Turning its Wi-Fi off and on doesn't always force it, because the access point can let it straight back on.
To give a revoked Chromebook a new certificate, delete the old one in chrome://certificate-manager, then restart the Chromebook on any network with internet. It asks for a new one by itself. When a Chromebook is retired, revoke it in Passbeam as well as removing it in Google Admin.
Related questions
Still stuck? Ask us, or read the rest of the knowledge base.