Passbeam

How do I set up Chromebooks with Passbeam?

Chromebooks are managed through Google Workspace, as they're not managed by Intune. So you connect the school's Google Admin to Passbeam, then set up four things in Google Admin. Each Chromebook then gets its own certificate and joins the Wi-Fi from the sign-in screen. Nothing needs installing at the school.

Each Chromebook needs a Chrome Education Upgrade or Chrome Enterprise Upgrade licence. Managed school Chromebooks will already have one.

Find the Customer ID. In Google Admin, go to Account → Account settings. It's in the Profile box and starts with C. Copy it, don't type it, as some of the characters look alike.

Account → Account settings. The Customer ID is in the middle and starts with C.

Connect it in Passbeam. Open the client, go to Certificates → Chromebooks and click Set up Chromebooks. Paste the Customer ID and save. Setup instructions then has every value you need for Google Admin, with copy buttons.

Certificates → Chromebooks once it's connected. Setup instructions has everything for Google Admin.
Setup instructions in Passbeam. Copy each value straight into Google Admin.

1. The Certificate Authority connection. In Google Admin, go to Devices → Networks → Certificates → Certificate Authority connections and click Add connection. Choose Generic Certificate Authority connection, not SCEP. Give it a name, paste in the service account, the Pub/Sub topic and the configuration identifier from Passbeam, and click Add. This one covers the whole domain.

Generic, not SCEP. The three values come from Passbeam.

Ignore Download connector. That's Google's old Windows connector and you don't need it.

2. The certificate provisioning profile. Select the organisational unit your Chromebooks are in, open Certificate provisioning profiles and click Add profile. Pick the connection you just made and tick Chromebooks (by device). Give it a name and a config reference (any short text). Set renewal to 90 days, Authentication type to None and Encryption key type to RSA key - 2048bit.

On the organisational unit with your Chromebooks. By device, 90 days, None, RSA 2048.

Use a device certificate for school Chromebooks. It belongs to the Chromebook, not the person, so a shared Chromebook can join the Wi-Fi before anyone signs in.

3. The root certificate. In Passbeam's Setup instructions, download Root CA (.pem). In Google Admin, on the same organisational unit, open Server Certificate Authority certificates and click Add certificate. Upload the .pem file. Google turns the .cer version down with "The uploaded file is invalid, or contains more than one certificate".

This is what the .cer file gets. Use the .pem one.

Leave all the Enabled for boxes unticked. Those make it trusted for websites as well, and the Wi-Fi doesn't need that. It still shows up in the Wi-Fi settings.

The .pem accepted. Leave every Enabled for box unticked.
It sits next to anything you already have there. Nothing else changes.

4. The Wi-Fi network. Go to Devices → Networks → Wi-Fi and click Add Wi-Fi, still on the same organisational unit. Tick Chromebooks (by device), enter the name and the SSID exactly as it's broadcast, and tick Automatically connect.

By device, the SSID exactly as it's broadcast, and Automatically connect.

Set Security type to WPA/WPA2/WPA3 Enterprise (802.1X) and the protocol to EAP-TLS. Leave Maximum TLS version on 1.2, the highest Google offers. In Username, put ${CERT_SUBJECT_COMMON_NAME} exactly as written. Google fills in each Chromebook's own name. Choose the root you uploaded as the Server Certificate Authority, paste the server name from Passbeam into Server Certificate Domain Suffix Match, then set Provisioning type to Certificate profile and pick the profile from step 2.

EAP-TLS, 1.2, the Username variable, the root, the server name, and Certificate profile.
The Wi-Fi values in Passbeam, with copy buttons for the two you type.

Don't leave Username blank. If you do, the Chromebook says "Error configuring network" and never tries to connect.

Once that's saved, each Chromebook picks the settings up next time it checks in with Google, which can take a little while. Restarting it makes it check straight away. It asks for its certificate, Passbeam issues it, and it joins the Wi-Fi. You'll see each one under Certificates → Chromebooks, and its sign-ins in the Authentication log.

The Authentication log. A Chromebook getting on, and the same one refused after it was revoked.

To check a Chromebook, open chrome://certificate-manager. The certificate is under Your certificates → Client certificates from platform. A lot of schools block chrome:// pages. If yours does, add chrome://policy and chrome://certificate-manager as exceptions on the IT team's organisational unit, under URL blocking.

To suspend or revoke a Chromebook, open it in Passbeam. Suspend can be undone, revoke can't. Either one stops it the next time it signs in to the Wi-Fi, and how soon that is depends on Access rules → Re-authentication. Turning its Wi-Fi off and on doesn't always force it, because the access point can let it straight back on.

On the Chromebook's page. Suspend can be undone. Revoke can't.

To give a revoked Chromebook a new certificate, delete the old one in chrome://certificate-manager, then restart the Chromebook on any network with internet. It asks for a new one by itself. When a Chromebook is retired, revoke it in Passbeam as well as removing it in Google Admin.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.