Zero Touch Provisioning (ZTP) for Board, Desk, and Room Series devices
list-menuFeedback?
Zero Touch Provisioning (ZTP) simplifies onboarding for devices by using the device MAC address instead of requiring manual activation-code entry. Administrators can pre-stage devices for shared workspaces or assign them directly to personal user accounts. Supported Webex Edge deployments can also use ZTP with Premises Calling while the device remains registered to the on-premises calling infrastructure.

Disclaimer:

Zero-Touch Provisioning (ZTP) is currently available starting with the 26.5 software image. However, this availability is limited and the feature is not yet considered fully General Availability (GA). Full availability in Control Hub will occur only after the 26.5 image has been distributed through all necessary channels, including the pre-onboard upgrade channel, the on-premises release COP file, and as a factory image on new devices. This phased rollout approach ensures thorough validation and integration before broad customer access.

Key Benefits

  • Automatic Device Registration: Devices can be onboarded using their MAC address when assigned to a shared workspace or personal user account, reducing the need for manual activation-code entry when MAC-address onboarding is used. Supported Webex Edge deployments can use the same process with Premises Calling.
  • Simplified Setup: Leveraging Control Hub’s default settings and pre-configurations, the First Time Wizard (FTW) experience is streamlined, significantly reducing manual steps during physical device setup.
  • Efficient Bulk Operations: Devices can be added in bulk by importing CSV files containing MAC addresses, enabling large-scale deployments with minimal effort.
  • Pre-Activation Capability: Devices can be activated in advance, even before they connect to the network. Devices can be pre-staged for a workspace or personal user account.
  • Reduced Onboarding Complexity: By automating network onboarding and device provisioning, ZTP reduces the time, cost, and complexity traditionally associated with device setup.

Key Terms for Device Onboarding in Control Hub

  • Unclaimed: The device’s MAC address is not registered within your organization.
  • Claimed: The device’s MAC address has been added to your organization.
  • Unassigned: A claimed device that has not yet been linked to a workspace or personal user account.
  • Assigned: A claimed device linked to either a workspace or a personal user account.
  • Pending: The status shown in Control Hub for a device that has been claimed and/or assigned but has not yet come online.
  • Pre-configuration: The process of applying device configuration settings to a pending device before it connects to the network or comes online.
  • Activated: The device has completed the applicable Webex or Webex Edge activation process.
  • Personal device: A device assigned to one user account rather than to a workspace.
  • Webex Edge: A deployment model in which the device remains registered to on-premises infrastructure while receiving supported cloud features and management. See Webex Edge documentation.

Requirements

Ensure your environment meets these requirements before deployment:

  • Software Version: Devices must run RoomOS 26.5.0 or later. RoomOS 11 is not supported.
  • Network Connectivity: Devices require reliable network access with connectivity to Webex services.
  • Configuration Defaults: Define Organization and Location defaults in Control Hub for Time Format, Time Zone, and Language to minimize onboarding prompts during the First Time Wizard (FTW).

For personal mode, the user must already exist in Control Hub before the device is assigned.

For Webex Edge ZTP, CUCM/TFTP discovery must be available where required by the deployment, including DHCP option 150 when it is used. Validate the behavior of AllowDataLogging and resolve any conflicts between CUCM-controlled and Control Hub-controlled configurations before onboarding.

Prerequisites: Upgrading to the Minimum Version for Zero Touch Activation

To upgrade to version 26.5, you will need to manually perform the upgrade for now. In the coming months, a pre-onboard upgrade feature will automate this process, and factory images will be updated accordingly. Until then, customers must upgrade by using the package links or the xcommand interface to install the update, followed by performing a factory reset to complete the process.

Software version during onboarding: If a device is below the FTW onboarding version, ZTP may upgrade it before registration. This upgrade occurs regardless of the workspace software channel, including a channel set through pending-device configuration. After ZTP completes, the workspace’s normal software rules are applied, and the device may be upgraded or downgraded to the version required by that channel. This behavior is expected. Microsoft Teams Rooms devices: If ZTP upgrades an MTR device to a version later than the version assigned to its Microsoft Approved channel, the device does not automatically downgrade while operating in MTR mode.

Package Mapping and Commands

Select the appropriate package based on your hardware. Use the provided xCommand to initiate the upgrade.

Device CategoryPackage Name
Cisco Room Navigatorbifrost.pkg
Newer Products (Codec Pro G2, Desk Pro G2)luna.pkg
Standard RoomOS Endpoints (Room Bar, Room Kit EQ, Board Pro, Desk, Codec Pro)zenith.pkg

For Cisco Room Navigator:


xCommand SystemUnit SoftwareUpgrade URL: "https://binaries.webex.com/collaboration-endpoint-ce-production-stable/20260415114153/bifrost.pkg" Forced: True

For Codec Pro G2 and Desk Pro G2:


xCommand SystemUnit SoftwareUpgrade URL: "https://binaries.webex.com/collaboration-endpoint-ce-production-stable/20260415114153/luna.pkg" Forced: True

For Room Bar, Room Kit EQ, Board Pro, Desk, and Codec Pro:


xCommand SystemUnit SoftwareUpgrade URL: "https://binaries.webex.com/collaboration-endpoint-ce-production-stable/20260415114153/zenith.pkg" Forced: True

Microsoft Teams installations are currently not supported through pkg installers. We are awaiting the release of the required COP (Cisco Option Package) file, which is scheduled to be available by the end of this month.

Initiating Zero Touch Activation through CLI

You can manually trigger the Zero Touch Activation process using the Command Line Interface (CLI) or API. Use the following command to begin the workflow:


xCommand Webex Registration ZeroTouchProvisioning Start SecurityAction: <Harden, NoAction>
Parameters:
Harden: Applies enhanced security settings to the device during the activation process.
NoAction: Proceeds with the activation using the current device security configuration. 

Setup Steps in Control Hub

  1. Configure Defaults

    Setting defaults helps the device skip manual setup steps during onboarding. Navigate to Control Hub and configure the following:

    • Time -> TimeFormat (e.g., 12h/24h)
    • Time -> Zone (e.g., America/New_York)
    • UserInterface -> Language (e.g., English)

    Optionally, assign the workspace to the location where these defaults are configured, or apply the organization-wide defaults.

    Before using Zero Touch Activation, confirm that the device does not require Hybrid Calling. Devices that require Hybrid Calling must be onboarded using the activation-code or manual onboarding workflow.

    Location configuration defaults
  2. Add the device by MAC address
    1. Go to Control Hub ->Devices -> Add Device (or Create Workspace). You can also start from Users, select a user, open the Devices tab, and select Add device.
    2. Select Cisco Room or Desk Device, choose Shared usage or Personal usage, and select MAC Address. Enter the wired Ethernet MAC address, product type, and platform (RoomOS or Microsoft Teams). If you select Microsoft Teams, the platform will be installed automatically upon completion of the wizard.
    3. For a personal device, select the user account to assign it to. For a supported Webex Edge deployment, select Premises Calling when available and follow the configured CUCM/on-premises provisioning path.
    4. If the device is already claimed but unassigned, open the device in Control Hub, select Assign, and choose Assign a device to a user. Claimed devices that have not connected yet appear as Pending.

    Add device by MAC address

    See the section to Locate your device’s physical MAC address label learn how to find the device’s MAC address.

    You can filter all devices that have been claimed, whether they are currently online or offline, by using the Ownership filter on the devices page and selecting Claimed.

    Claimed devices list
  3. Apply Pre-configurations to pending devices (optional, recommended)

    You can apply device-level pre-configurations before the device comes online for any supported configuration by following these steps:

    • Open the pending device page in Control Hub.
    • Click on "All Configurations."
    • Apply the necessary settings.

    During onboarding, the device consumes configuration settings from these sources in hierarchical order:

    • Organization-level defaults
    • Location-level defaults
    • Device-level pre-configurations on the pending device

    Settings defined at any of these levels are applied automatically during the First Time Wizard onboarding flow.

    Pending device page has configuration settings available

    For the automatic onboarding wizard to complete successfully, the following configurations must be set:

    All Devices:

    • Time > TimeFormat (e.g., 12h/24h)
    • Time > Zone (e.g., America/New_York)
    • UserInterface > Language (e.g., English)

    Board Series Only:

    • Audio > Placement (Wallmount, Freestanding)

    Result:

    • Depending on the onboarding method, the device appears as Claimed, Assigned, or Pending. When the device connects, it completes automatic onboarding .
    • It is pre-configured with location and device-level settings.
    • When the factory-reset device connects to the network, it will register and onboard automatically.

Locate your device’s physical MAC address label

If you cannot locate your MAC address, it is typically printed on the product label found on the back or underside of your device. This label often includes other important identifiers such as the serial number and product ID. For many Cisco products, the MAC address label is clearly marked and can be found on the chassis or a label tray. If you are unable to locate it physically, some devices also allow you to view the MAC address through their user interface or web page under product or system information settings.

Locate MAC address

Onboarding Process

Webex Edge supports device-first and cloud-first onboarding sequences. Depending on the deployment, the device may discover CUCM/TFTP settings first and then complete Webex Edge activation, or use its Control Hub assignment before connecting to the on-premises provisioning environment.

Once the device is claimed and assigned in Control Hub:

  1. Ensure the device is factory reset.
  2. Connect the device to the network.
  3. On the Welcome screen, select the automatic onboarding option.
    Device activation in progress
    Device activation in progress
  4. Follow any remaining prompts for items not configured in Control Hub.
    • If you did not complete certain settings during pre-configuration, the setup wizard will prompt you to configure these items during device onboarding.
    • Additionally, complete the necessary hardware setup, such as positioning the camera correctly, to ensure optimal device performance.

If the automatic onboarding option is not shown, verify the following:

  • The MAC address is correctly entered and assigned to the intended workspace or personal user account
  • The device has been factory reset.
  • The device has verified internet access to Webex services.
  • The device is running the minimum required software version (RoomOS 26.5.0+).

Bulk device onboarding (CSV)

Use the bulk onboarding process to claim and assign multiple devices in a single import.

  1. In Control Hub, navigate to Devices and click Add device.
  2. Select Bulk Add Devices.
    Bulk add devices page
    Bulk add devices
  3. From the template dropdown, choose the zero-touch onboarding template and download the CSV file.
    Zero touch template selection
    Zero touch template selection
  4. Populate the CSV file with your device and assignment information, ensuring all required fields are completed. For Personal Mode devices, enter the user’s email address in the Account column. Existing shared and workspace CSV behavior remains unchanged.
  5. Upload the completed CSV file and submit the import.
  6. Open the Tasks page to monitor the import progress and download an error CSV file if any rows fail.
    Bulk import task status
    Bulk import task status
  7. Verify the imported devices in the Devices list, where they may initially appear as Claimed and Pending before their first connection.
    Imported devices in pending state
    Imported devices in pending state

Device Web Page Onboarding (Remote)

Use the device web page for remote onboarding when you do not have physical access to the device interface. This method is especially useful for deployments without a Room Navigator attached, such as Room Bar BYOD and Room Bar Pro BYOD devices.

  1. Open a web browser and enter the device’s IP address in the address bar.
  2. Log in using the username admin with no password.
    Device web page home
    Device web page home
  3. On the device web page, open the system page and click Register to Webex.
    Register to Webex dialog
    Register to Webex
  4. In the registration dialog, click Start Automatic Onboarding to begin the process. Automatic onboarding also supports devices that have been assigned to a personal user account. For supported Webex Edge deployments, the device continues through the configured CUCM/on-premises provisioning path.
    Automatic onboarding started
    Automatic onboarding started
  5. Wait for the onboarding to start. Then, verify the device state and registration status in Control Hub to ensure successful onboarding.

Additional Information

  • This onboarding method enables you to configure and manage devices remotely without needing a physical Room Navigator or direct device interaction.
  • After registration, the device can be managed and monitored through Cisco Webex Control Hub.
  • For Room Bar BYOD devices, this process allows enabling network connectivity and Control Hub registration, which unlocks advanced features such as software management, peripheral visibility, and remote access.
  • Ensure that the device is connected to the network and accessible via its IP address before starting the onboarding process.

This streamlined remote onboarding process helps simplify deployment and management of Cisco collaboration devices in environments where physical access is limited or unavailable.

First Time Wizard (FTW) Behavior

The First Time Wizard (FTW) guides the initial onboarding process for Cisco collaboration devices. Its behavior includes the following key actions:

  • Automatic Onboarding Start: The FTW begins onboarding once the user selects the automatic onboarding option on the Welcome screen. The FTW recognizes whether the device is shared or personal. Personal devices use the assigned user account and do not require manual activation-code entry when MAC-based onboarding is selected. Note that personal mode devices will not finish the wizard until they are unlocked by the intended user. If a pin is set on the user's account, the user will have to unlock it first or go to https://user.webex.com/ to reset their pin. If they do not use a pin, they'll have to pair to the device first (QR code, ultrasound, or usb-c) before unlocking it.
  • Webex Edge Provisioning: For supported deployments, the FTW preserves the CUCM/TFTP provisioning path before completing Webex Edge activation.
  • Use of Configured Defaults: When available, the wizard applies configured defaults such as Language and Time Zone.
  • Application of Preconfigurations: It applies configurations from the Organization, Location, and any pending-device preconfigurations set in Control Hub.
  • Prompting for Missing Settings: The wizard prompts the user to enter any settings that are not already configured in Control Hub.
  • Microsoft Teams Installation: If the Microsoft Teams platform was selected during the Add Device process, the wizard installs Microsoft Teams at the end of the onboarding.
  • Manual Hardware Checks: Certain hardware setup tasks, such as camera positioning, require manual completion by the user.

Limitations and Manual Tasks

  • Physical hardware installation, such as camera positioning and mounting, must still be performed manually.
  • User Hub self-service assignment of a MAC address is not supported.
  • Changing a device between major calling modes after registration is not supported.
  • You may need to manually complete certain First-Time Wizard steps if the corresponding default settings are not configured in Control Hub.
  • Hybrid Calling: Hybrid Calling is not supported through Zero Touch Provisioning. Do not provision devices that require Hybrid Calling using the ZTP workflow. Use the existing activation-code or manual onboarding workflow instead. The Hybrid Calling option does not appear in the ZTP setup flow; this is expected.
  • Zero Touch Pairing is not available in the initial release. Support for this feature is planned for a future update.
  • TLS-intercepting proxies are not currently supported. For Zero Touch Activation to function, the device must establish a direct, trusted connection with Webex services. A simplified trust bootstrap process for these environments is currently in development.
  • For deployments requiring 802.1X or SCEP, certificate enrollment remains a manual process and is handled independently of Zero Touch Activation. While an automated certificate loading tool is currently in development, the current Zero Touch workflow assumes the device has already established network connectivity to Webex services.

Was this article helpful?
Was this article helpful?