Category filter
Open vs Authenticated Enrollment for Zebra Link-OS Printers
TL;DR
Hexnode UEM provides two enrollment modes for Zebra Link-OS Printers: Open Enrollment and Authenticated Enrollment. Open Enrollment assigns the printer to a selected default user without requiring credentials during enrollment, while Authenticated Enrollment uses a Local User or Self Enrollment request and can require a pre-shared key configured in the Hexnode UEM portal. Use Open Enrollment for controlled, technician-led provisioning and Authenticated Enrollment when the organization needs to validate enrollment through an approved user or enrollment credential.
This article helps administrators choose the appropriate Zebra Link-OS Printer enrollment method before generating and sending enrollment instructions to a printer.
What this article covers
This article explains the operational and security differences between Open Enrollment and Authenticated Enrollment for Zebra Link-OS Printers in Hexnode UEM.
- Authentication behavior for each enrollment method
- User-assignment behavior
- Supported provisioning devices
- Pre-shared key requirements
- Enrollment-file handling
- Enrollment validation steps
- Common Zebra Printer enrollment issues
For detailed, end-to-end enrollment instructions, see Zebra Printer enrollment in Hexnode UEM.
Compare Zebra Printer enrollment methods
This table compares Open Enrollment and Authenticated Enrollment for Zebra Printers in Hexnode UEM, including authentication, supported provisioning devices, user assignment, and recommended use cases.
| Enrollment factor | Open Enrollment | Authenticated Enrollment |
|---|---|---|
| Authentication during enrollment | No credentials are required during the enrollment process. | Uses a selected enrollment request type: Local User or Self Enrollment as Local User. |
| User assignment | The administrator selects a domain and default user before generating the enrollment commands file. | The selected enrollment request type determines the user-assignment workflow. |
| Supported provisioning device | Android, iOS, or Windows device. | Windows device. |
| Zebra Printer Setup Utility | Required. | Required. |
| Pre-shared key | Not required for the Open Enrollment workflow. | May be required when Pre-shared key authentication is selected in Enrollment Settings > Security > Zebra Printer enrollment authentication password. |
| Best suited for | Controlled batch provisioning, staging, warehouse setup, and technician-led enrollment. | Enrollment workflows that require authentication or an approved credential before printer enrollment. |
| Enrollment-file handling | Download the Open Enrollment commands file and send it to the printer. | Download the Authenticated Enrollment commands file. Update the username and pre-shared key fields when required, then send the file to the printer. |
| Printer behavior after commands are received | The printer restarts and enrolls in Hexnode UEM. | The printer restarts and enrolls in Hexnode UEM. |
Note: Zebra Printer enrollment is supported on devices running Link-OS 5.0 or later.
Choose the right enrollment method
Use the following decision table before generating a Zebra Printer enrollment commands file.
This table helps administrators select Open Enrollment or Authenticated Enrollment based on their Zebra Printer provisioning requirements.
| If the organization needs to… | Recommended method | Reason |
|---|---|---|
| Provision printers quickly at a staging location | Open Enrollment | A technician can send the enrollment file without entering credentials on the printer. |
| Assign every printer to one known operational user | Open Enrollment | The administrator selects a default user in the Hexnode UEM portal before creating the enrollment file. |
| Enroll printers using a mobile provisioning device | Open Enrollment | The workflow supports Android and iOS devices paired with the Zebra Printer over Bluetooth. |
| Require enrollment authentication | Authenticated Enrollment | The workflow uses a Local User or Self Enrollment request type. |
| Use a Zebra Printer enrollment pre-shared key | Authenticated Enrollment | The enrollment commands file can be updated with the username and configured pre-shared key. |
| Provision printers through a Windows-based IT process | Open Enrollment or Authenticated Enrollment | Both workflows support Zebra Printer Setup Utility on Windows. |
| Limit unauthenticated printer onboarding | Authenticated Enrollment | The workflow introduces an authentication-controlled enrollment path. |
How Open Enrollment works
Open Enrollment allows an administrator to enroll a Zebra Printer without entering authentication credentials during the printer enrollment process.
Before generating the enrollment commands file, the administrator selects the following:
- Open Enrollment as the authentication mode.
- A Domain.
- A default user from the selected domain.
Navigate to:
Enroll > Platform-Specific > Zebra Printer > Zebra Printer Enrollment
Then select Open Enrollment.
Result: Hexnode UEM generates an enrollment commands file associated with the selected domain and default user.
The enrollment commands file can be sent to the Zebra Printer using either of the following methods:
- An Android or iOS device paired with the printer through Bluetooth.
- A Windows device using Zebra Printer Setup Utility.
After the Zebra Printer receives the commands file, the printer restarts and enrolls in Hexnode UEM.
When to use Open Enrollment
Open Enrollment is appropriate when:
- A central IT team provisions printers before shipping them to sites.
- A warehouse or retail staging team enrolls multiple printers in a controlled environment.
- Printers are assigned to a shared operational user.
- A technician must enroll printers from an Android or iOS device.
- The organization does not require an authentication check during the printer-enrollment action.
Caution: Open Enrollment does not require credentials during the enrollment process. Limit access to the enrollment commands file and use Open Enrollment only in controlled provisioning workflows.
How Authenticated Enrollment works
Authenticated Enrollment creates a Zebra Printer enrollment workflow that uses one of the following enrollment request types:
- Local User
- Self Enrollment as Local User
Navigate to:
Enroll > Platform-Specific > Zebra Printer > Zebra Printer Enrollment
Then select Authenticated Enrollment and choose the required enrollment request type.
Result: Hexnode UEM generates an enrollment commands file for the selected authenticated enrollment workflow.
Authenticated Enrollment is completed from a Windows device using Zebra Printer Setup Utility. The administrator downloads the enrollment commands file, connects the Zebra Printer to the Windows device, configures printer connectivity, and sends the enrollment file to the printer.
When the Zebra Printer enrollment authentication method uses a pre-shared key, the administrator must update the downloaded enrollment commands file before sending it to the printer.
This table identifies the fields that administrators must validate in a Zebra Printer Authenticated Enrollment commands file when pre-shared key authentication is enabled.
| Field | Required value |
|---|---|
| Username | The required username for the selected enrollment workflow. |
| Password | The organization’s pre-shared key configured in the Hexnode UEM portal. |
Configure the pre-shared key in:
Enrollment Settings > Security > Zebra Printer enrollment authentication password
Result: The Zebra Printer receives the authenticated enrollment commands, restarts, and enrolls in Hexnode UEM.
When to use Authenticated Enrollment
Authenticated Enrollment is appropriate when:
- The organization requires an authentication-controlled printer onboarding process.
- The printer must be enrolled through a Local User or Self Enrollment workflow.
- The organization uses a pre-shared key to protect Zebra Printer enrollment.
- Printer enrollment is performed from an approved Windows-based provisioning workstation.
- The organization needs to limit the use of enrollment commands files outside the intended provisioning process.
Important: If the Zebra Printer enrollment authentication method uses a pre-shared key, the downloaded enrollment commands file must contain the correct username and pre-shared key before it is sent to the printer.
Prerequisites for both enrollment methods
Before enrolling a Zebra Printer, confirm the following requirements.
- The Zebra Printer runs Link-OS 5.0 or later.
- The Zebra Printer is powered on.
- The printer can be configured for wired or wireless network connectivity.
- The provisioning technician has access to the Hexnode UEM portal.
- Zebra Printer Setup Utility is available on the provisioning device.
- The printer can connect to the Hexnode UEM portal after receiving the enrollment commands.
- For Windows provisioning, the Zebra Printer can be connected through USB and detected by Zebra Printer Setup Utility.
Additional prerequisites for Open Enrollment
- Bluetooth is enabled on the Android or iOS device.
- The Android or iOS device is paired with the Zebra Printer.
- Zebra Printer Setup Utility is installed on the Android or iOS device.
Additional prerequisites for Authenticated Enrollment
- A Windows device is available.
- The required enrollment request type has been selected.
- The correct username is available.
- The pre-shared key is available when the organization uses pre-shared-key authentication.
Enrollment security considerations
This table compares the security considerations for Open Enrollment and Authenticated Enrollment of Zebra Printers.
| Security consideration | Open Enrollment | Authenticated Enrollment |
|---|---|---|
| Enrollment credentials entered during provisioning | No. | May be required. |
| Default user assignment | Selected by the administrator before file generation. | Determined by the selected Local User or Self Enrollment workflow. |
| Enrollment file protection | Important because the file can enroll printers without credentials. | Critical because the file can contain authentication-related enrollment information. |
| Appropriate provisioning environment | Controlled staging or technician-led setup. | Controlled Windows-based provisioning workflow. |
| Recommended access control | Restrict file access to authorized technicians. | Restrict file access, pre-shared key access, and provisioning-workstation access. |
Warning: Do not share Zebra Printer enrollment commands files through unsecured communication channels. Treat downloaded enrollment files as provisioning assets and provide them only to authorized administrators or technicians.
Validate Zebra Printer enrollment
After the enrollment commands file is sent to the Zebra Printer, validate enrollment from both the Hexnode UEM portal and the device.
-
Allow the Zebra Printer to restart after receiving the enrollment commands.
Result: The printer applies the received configuration and attempts to communicate with Hexnode UEM.
-
Confirm that the Zebra Printer has network connectivity.
Result: The printer can reach the Hexnode UEM portal and complete enrollment.
-
In the Hexnode UEM portal, navigate to
Manage > Devices.Result: The enrolled Zebra Printer appears in the managed device list.
-
Open the Zebra Printer device details page.
Result: The administrator can review device information, policies, remote actions, and Action History for the enrolled printer.
-
Apply a non-disruptive configuration or use a supported diagnostic action.
Result: The administrator confirms that the enrolled printer can receive Hexnode UEM policies or actions.
Troubleshoot Zebra Printer enrollment
This table lists common Zebra Printer enrollment issues, probable causes, recommended resolutions, and validation steps.
| Symptom | Likely cause | Resolution | Validation |
|---|---|---|---|
| The Zebra Printer does not appear in Hexnode UEM | The enrollment commands file was not sent successfully or the printer cannot reach the Hexnode UEM portal. | Recheck the enrollment file, printer network settings, and selected enrollment method. | Confirm that the printer appears in Manage > Devices after the printer restarts. |
| The Android or iOS device cannot discover the Zebra Printer | Bluetooth pairing was not completed or the printer Bluetooth mode is not active. | Press and hold the printer Feed button for five seconds until the Bluetooth icon blinks, then repeat the pairing process. | Confirm that the Zebra Printer appears in the mobile device Bluetooth list and Zebra Printer Setup Utility. |
| Zebra Printer Setup Utility does not detect the printer on Windows | The printer is not connected correctly, required drivers are missing, or the printer list has not refreshed. | Reconnect the printer through USB, install required drivers, then select Refresh Printer List or Install New Printer. | Confirm that the printer appears in the Printers list in Zebra Printer Setup Utility. |
| Authenticated Enrollment fails after the file is sent | The username or pre-shared key is missing, incorrect, or not aligned with the selected enrollment request type. | Review the enrollment commands file and update the required fields with the correct values. | Confirm that the printer restarts and appears in Hexnode UEM. |
| The printer remains offline after enrollment | The printer does not have a valid wired or wireless connection. | Review printer connectivity settings and restart the printer if required. | Confirm that the printer reconnects to the network and reports to Hexnode UEM. |
Frequently Asked Questions
What is the difference between Open Enrollment and Authenticated Enrollment for Zebra Printers?
Open Enrollment does not require credentials during the Zebra Printer enrollment process and assigns the printer to a selected default user. Authenticated Enrollment uses a Local User or Self Enrollment request type and can require a pre-shared key.
Can I use an Android or iOS device for Authenticated Enrollment?
No. The Authenticated Enrollment workflow uses a Windows device with Zebra Printer Setup Utility.
Can I use a Windows device for Open Enrollment?
Yes. The Open Enrollment workflow supports Zebra Printer enrollment through Zebra Printer Setup Utility on a Windows device.
When should I use Open Enrollment?
Use Open Enrollment when authorized technicians provision printers in a controlled environment and the printers can be assigned to a selected default user without requiring credentials during enrollment.
When should I use Authenticated Enrollment?
Use Authenticated Enrollment when the organization requires an authentication-controlled printer enrollment process, uses Local User or Self Enrollment workflows, or protects printer enrollment with a pre-shared key.
Where is the Zebra Printer enrollment pre-shared key configured?
Configure the Zebra Printer enrollment pre-shared key in Enrollment Settings > Security > Zebra Printer enrollment authentication password.
Does every Authenticated Enrollment workflow require a pre-shared key?
No. Update the enrollment commands file with a username and pre-shared key only when the organization has selected Pre-shared key authentication for Zebra Printer enrollment.
What happens after the Zebra Printer receives the enrollment commands file?
The Zebra Printer restarts, applies the received configuration, and attempts to enroll with the Hexnode UEM portal.
Can I enroll additional Zebra Printers from the same Windows provisioning device?
Yes. Connect the next printer through USB, select Refresh Printer List or Install New Printer in Zebra Printer Setup Utility, configure connectivity, and repeat the applicable enrollment workflow.