Theft Recovery
Theft Recovery is new and improved in Admin 2.0! This article will cover:
- How to configure an OU for your missing or stolen devices,
- Install the Theft Recovery app,
- Authorize GoGuardian to sync with the Google Admin Console
- Sync your device information with the Google Admin Console
Note for users of the "Classic View" version of Theft Recovery: Theft Recovery 2.0 requires a slightly different setup and the installation of a new kiosk app. Please follow this guide to ensure a successful migration.
Step 1: Create a Theft Recovery OU for missing devices
A new, custom OU must be created with specific Device Settings in order to use Theft Recovery 2.0. When a device is placed into this OU using the Theft Recovery UI, Theft Recovery Mode will activate.
- Sign in to Google Admin Console
- Click Devices
- Click Chrome
- Click Settings
- Click Device
- The sidebar on the left will contain your OU structure. Click the blue link at the bottom to MANAGE ORGANIZATIONAL UNITS. Create a new sub-OU in the location of your choice. The name of this OU must contain the words "stolen devices." Your OU structure can contain multiple stolen devices OUs as long as they contain the words "stolen devices" and are configured appropriately.
Note: If you have previously configured a stolen devices OU for the "Classic View" version of Theft Recovery, the existing OU can be reused, but make sure that your device settings match the configuration in Step 2 and the new Theft Recovery App is installed.
Step 2: Configure your Stolen Devices OU and Install the Kiosk App
Configure your stolen devices OU to launch the GoGuardian Kiosk App. The App will record geolocation data and take screenshots as the device is used while Theft Recovery mode is active.
- Sign in to Google Admin Console
- Click Devices
- Click Chrome
- Click Settings
- Click Device
- Select your newly created Stolen Devices OU from the sidebar to modify the OU's Device Settings.
VERY IMPORTANT! Ensure that your Stolen Devices OU is selected on the OU sidebar before making these changes!
***If you configure your domain level or any typical OU that contains your devices, it will put every device in that OU into Theft Recovery mode and generate a Theft Recovery session for every device in that OU! Please exercise caution***
Protip: Use CTRL+F or COMMAND+F to easily find the settings - Set Guest Mode to Do not allow guest mode
- Set Sign-In Restriction to Do not allow any user to sign-in
- Set Scheduled Reboot to 1
Note: Once placed in the Theft Recovery OU, a device must be rebooted at least once to launch the App. This setting will force the device to reboot once per day. - Find Kiosk Settings and click the Apps & Extensions Page link
- Click the Yellow + bubble in the bottom right corner and find the add Chrome App or Extension by ID
- Add the App ID alaoimaeafbgfglpffgcidfgbjnekifp
- Select the drop down to change From the Chrome Web Store to From a custom URL
- Add the App URL https://clients2.google.com/service/update2/crx
- Click Add
- Verify that the app, titled Welcome, has been added to the right under Total to Install.
Note: If the Classic View Theft Recovery App, titled Loading, is already installed, remove it from the Kiosk Apps list and replace it with the Welcome App. - Click Save to close the dialog box
- Under Auto Launch Kiosk App, Select the Welcome App from the drop-down menu
- Save the settings by clicking the Save button in the bottom right corner
Step 3: Authorize GoGuardian to sync with Google Admin Console
This will authorize GoGuardian to sync with your Google Admin Console so we can track your stolen devices.
Required G Suite Privileges:
- Admin API Privileges:
- Domain Management
- Organizational Units
- Users
- Admin Console Privileges
- Chrome Management
Configuration Walkthrough
- Sign in to GoGuardian and navigate to the Theft Recovery Dashboard
- Click the menu icon found in the top right corner of the Theft Recovery Dashboard
- Click Authorize With Google to open the authorization tool
- Click the green Authorize button when prompted
- Select your Google Admin Super User account, if signed into multiple Google accounts
- Click the blue Allow button to complete the authorization process
Note: Your Google Admin Account must have the following permissions.
- Provision and delete users on your domain: View and modify details (e.g. name, address, and phone number) and metadata (e.g. login details) of users on your domain
- View metadata (e.g. name and description) of organizational units
- View all your Chrome OS devices' metadata (e.g. mac address, model, and OS version)
- View and update a specific Chrome OS device's metadata
If you're unsure if your account has these permissions, please verify with Google. Otherwise, you may receive an authorization error.
Step 4: Sync Devices from Google Admin Console
This will import all device information from the Google Admin Console.
- Sign in to GoGuardian and navigate to the Theft Recovery Dashboard
- Click the menu icon found in the top right corner of the Theft Recovery Dashboard
- Click Sync Devices
- Click the blue Sync button
Now that Theft Recovery 2.0 is configured, let's test it out!
Comments
0 comments
Article is closed for comments.