Enroll a device with a userless enrollment token
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
On this tab
Devices enrolled with userless enrollment tokens are fully managed devices enrolled without an assigned user. Multiple users can share a single device without entering their credentials. These devices differ from shared devices in the original console, where device users sign in with a shared staging user account. With devices enrolled with a userless enrollment token, no user is assigned to the device.
To enroll, an IT admin must first create a userless enrollment token, then scan the QR code it generates when enrolling the device.
Only the super admin who created the tenant can generate and view userless enrollment tokens.
IT admins should maintain a contact list for each device — for example, the person primarily using it — so they can be reached to receive codes, such as the unenrollment code, in case the device goes offline.
Create a userless enrollment token
A userless enrollment token generates a QR code that you scan when enrolling the device. Devices that enroll through that code join the token’s assigned device group directly, without user credentials. The limit to the number of devices which can scan a single userless enrollment token depends on how you configured the Maximum number of active devices per user field in the GENERAL SETTINGS.
To create a userless enrollment token:
-
Navigate to Settings > ANDROID ENTERPRISE > Userless enrollment tokens. Click CREATE TOKEN.
-
On the Create userless enrollment token dialog, enter a Token name. Names must be unique, under 128 characters, and can’t include the following characters:
&,;,<, and>. -
Under Assign token to group, select an existing device group, or click CREATE DEVICE GROUP to create a new one. If you create a new device group, the Create new device group? dialog opens. Enter a Group name, then click CREATE GROUP. The new group is automatically selected.
Tokens can only be assigned to a manual device group. When you first assign a token, you can assign it to one group only. After the token is created, you can assign it to more groups.
-
For Set token to expire after, select a period after which the token expires and can’t enroll new devices. You can choose from 1 day, 7 days, 15 days, 30 days, 60 days, 90 days, or select Unlimited.
-
Click CREATE.
Enroll a device with a userless enrollment token
To enroll a device with a userless enrollment token, you must enroll a device with the QR code method. Instead of scanning a personalized QR code from an enrollment guide, you must scan the QR code generated by the userless enrollment token. You aren’t directed to enter any user credentials. The device is then enrolled as a fully managed device without an assigned user.
View and manage userless enrollment tokens
You can view and manage tokens on the Userless enrollment tokens tab.
You can search for tokens by token name, token, or status. The token table contains the following columns:
- TOKEN NAME — The name of the token. Click it to view the token’s details where you can view or download the QR code, as well as edit the token’s name or delete the token.
- TOKEN — The token’s unique code.
- DEVICE GROUP — The device group that the token is assigned to.
- STATUS — The status of the token, which can be Valid, Almost expired, or Expired.
- CREATION DATE — The date the token was created.
- EXPIRATION DATE — The date the token expires and can no longer enroll new devices. Expired tokens have no impact on any devices that were enrolled with them.
From the Userless enrollment tokens tab, you can also perform the following actions on a token:
- Renew token — Once a token has the Almost expired or Expired status, you can renew it. On the Renew token dialog, select a new expiration period, then click SAVE.
When you renew a token, its QR code and token code change.
- Delete token — Deletes the token. Click DELETE to confirm your choice. Deleting a token has no impact on any devices that were enrolled with it.
Is this page helpful?
Thank you for your feedback!