Skip to main content

May 26, 2026

Zebra Lifeguard OTA Updates

You can keep the Zebra devices in your fleet up to date by using Lifeguard, Zebra's over the air (OTA) security and patching system for its Android devices. Workspace ONE UEM provides native capabilities for applying LifeGuard updates.

Prerequisites

  • Workspace ONE UEM version 2410 or later with modstack.
  • Admin access to a customer type organization group (OG) in the Workspace ONE UEM console.
  • An account with Zebra.com and credentials for the LifeGuard OTA service. Please contact your Zebra representative for more information.
  • Zebra Android 7+ device enrolled in Workspace ONE UEM fully managed mode

Take the following steps to enable Zebra's Lifeguard OTA service.

STEP ONE, Authorize Zebra Lifeguard OTA (one time task)

Take the following steps to authorize, which is typically a one time only task:

  1. In the Workspace ONE UEM console, move to a customer type organization group (OG) that holds your targeted Zebra android devices.

    this screenshot shows the Zebra Lifeguard OTA settings in UEM for a customer OG that has not been authorized yet.

  2. Navigate to Groups & Settings > All Settings > Devices & Users > Android > Zebra LifeGuard OTA.

  3. Select the Authorize button.

    this screenshot shows the Zebra.com login screen. You must already have a username and password from Zebra.com

  4. A new window displays with a Zebra.com sign-in screen. Enter your Zebra.com username and password, then select the Sign In button.

    this screenshot shows the activation code from the Zebra.com login screen.

  5. An activation code displays. Select the Confirm button to proceed.

    this screenshot shows the Request for Approval screen from Zebra.com.

  6. A request for approval screen displays. Select the Allow button to return to Workspace ONE UEM settings.

    this screenshot shows the Zebra Lifeguard OTA settings in UEM for a customer OG that has been freshly authorized.

    Upon returning to Workspace ONE UEM settings, you can see the OG you selected in step 1 is now authorized to service the Zebra devices inside with Lifeguard OTA. Once authorized, the following displays on the Zebra LifeGuard OTA page.

    • Additional steps to enroll devices into the Zebra LifeGuard service, which are detailed in the steps that follow.
    • Your enrollment token and the token expiration date.
    • Refresh Token button: generates a new enrollment token in case of expiration. When you refresh the token, you must both 1) update the application configuration and 2) update the token for claim device.
    • Sync button: immediately syncs the latest device data from Zebra. Note that Workspace ONE UEM syncs automatically on a scheduled basis as well.
    • Delete button: removes anything related to Zebra LifeGuard OTA (all policies, updates, and device data that has been retrieved from Zebra), and any in-progress updates are canceled. Additionally, devices are unenrolled from Zebra LifeGuard OTA (not from Workspace ONE UEM device management).
  7. Select the Sync button to synchronize the customer type OG tenant.

  8. Select the COPY TOKEN link next to the token text to copy the code to the clipboard. You will paste this code later.

STEP TWO, Install the App and Apply the Token (one time task)

Perform the following steps to install the Zebra Lifeguard app and apply the token you copied earlier, which is typically a one time only task:

  1. Push the app Zebra Enrollment Manager from Google Play to all targeted Zebra devices. This app requires Managed Configurations.

    Note: The Zebra Enrollment Manager app must not be deployed as an Internal application as the app might interfere with the enrollment workflow and result in unsuccessful device enrollment.

  2. Paste the enrollment token in the Claim device token text box.

  3. End user must configure permissions profile, granting phone permission to the app (Android 8 only. Phone permission not required for Android 9+).

The below steps are for enrolling managed devices into the Zebra LifeGuard OTA service:

  1. From the Zebra LifeGuard OTA settings page, copy the Enrollment Token or keep it handy as it is needed later.

  2. Add the Zebra Enrollment Manager application under Resources > Apps.

  3. For GMS devices, add this app from Google Play.

  4. For non-GMS devices, reach out to Zebra to obtain the APK file so that the app can be uploaded as an Internal App.

  5. Add an app assignment and configure the Distribution options. Then, go to the Application Configuration.

  6. For Action, select Claim Device. For Claim Device Token, enter the Enrollment Token obtained from the Zebra LifeGuard OTA settings page.

  7. Save and publish the assignment.

STEP THREE, Initiate Lifeguard Update (recurring task)

Updates in LifeGuard OTA are managed using a combination of Policies and Updates.

The Policy is a collection of static settings that stay the same for each update that is installed. It also provides the ability to configure devices for Automatic Updates or Custom Updates.

The Update is used when the Policy is configured for custom updates and includes the actual version of update being installed, as well as the date range for when the update should be applied.

Note: Zebra Lifeguard OTA updates might fail if the same email or admin account is used to register across multiple environments (for example, UAT and Production) or organizational groups (OGs). Zebra considers a single email or admin account as one tenant, which can lead to device conflicts when shared across environments. To avoid this issue, ensure that separate accounts are used for each environment or OG.

These are the high-level steps for configuring LifeGuard OTA updates:

  1. Navigate to Devices & Device Updates then select the Android (Zebra) tab.

  2. Select the Add button

  3. Configure an update policy for each device model and/or group of devices targeted for the update. Only 1 model can be selected for each policy.

    SettingDescription
    Policy NameEnter the name of the policy. Since only a single model can be the target of a policy, including the model in the policy name makes sense.
    DescriptionYou can provide a description of your policy, which can be helpful if you have several policies that, at first glance, appear the same but have important differences.
    GENERAL TAB
    Device ModelThe device model targeted for updates. Only one device model can be selected per policy.
    Smart GroupsSelect the smart groups containing devices targeted for this policy. While it is a best practice to configure smart groups for specific models, the devices are filtered by the selected model automatically before pushing any updates.
    Update TypeSelect Custom or Auto updates.

    * Custom requires that you selet one specific update per custom policy and that custom policy is run once per targeted Zebra device.

    * Auto is a set-it-and-forget-it type of policy. Auto always applies the newest / latest update as soon as it is ready.
    Network TypeType of network allowed to download updates: select from Any (no preference), Wifi, and Celllular.
    Allow Battery ControlsAllows you to configure a minimum battery charge percentage for updates.
    Minimum Battery Limit
    (only visible when Allow Battery Controls is enabled)
    The entry here indicates the minimum battery charge required for download & installation of an update. Opting for a selection here can be useful for especially large updates.
    Require device to be on chargerRequires the device to be on charger for the update installation. This option should be reserved for only the biggest, most complex updates.
    SCHEDULE TAB
    Installation MethodImmediate or Scheduled.
    Device Time Zone
    (only visible when Installation Method is set to Scheduled)
    The device’s time zone used for scheduling.
    Install Start Time
    (only visible when Installation Method is set to Scheduled)
    Time during the day when the install can start.
    Install End Time
    (only visible when Installation Method is set to Scheduled)
    Time during the day after which the install cannot start. Time selected must be at least 30 minutes later than the Install Start Time.
    Auto Update Delay
    (only visible for Auto updates)
    Set the number of days to delay the start of an Auto update.
    Allow User to Postpone
    (only visible for Auto updates)
    Enable this slider to empower the device end user to postpone an Auto update. The device end user is in the best position to know what their workload is, especially their immediate workload. Knowing an update is coming and being able to postpone it can place the end user in a prime position to complete an immediate task quickly without that task competing with an OTA update at the same time.
    Postpone Duration
    (only visible when Allow User to Postpone is enabled)
    Enter the number of hours to postpone the Auto update. Consult with the device end user to determine an optimal length of time for such a postponement.
    Postpone Message
    (only visible when Allow User to Postpone is enabled)
    Once the device end user opts to postpone the update, entering a message here is your opportunity to let the end user know the Postpone Duration you selected, essentially letting them know how long they have to complete their immediate task before the Auto update begins.
    • If Auto updates are selected, then proceed immediately to step 5.

      Note: If you configure automatic updates using Zebra OEMConfig, the device might fail to complete Zebra enrollment. This configuration can conflict with Zebra’s OTA update process and prevent successful device registration. Therefore, Omnissa recommends you do not manage OTA update behavior through Zebra OEMConfig.

    This screenshot shows the Zebra OEMConfig powered by MX assignment not globalized system configuration screen

    • If Custom updates are selected, proceed to the next step.
  4. Configure an update for your custom policy by making the above selections and select Publish. Repeat steps 2 - 5 for each custom policy you want to make.

  5. Select Publish to finalize the update to devices.

Tracking Custom Updates, Zebra LifeGuard OTA

After you configure a custom update, you can track its progress as it filters down through your Zebra device fleet.

  1. Navigate to Devices > Device Updates then select the Android (Zebra) tab.

  2. Select any custom update entry in the list to view the deployment progress. Tracking details include:

    • list of devices which have received the update
    • current status of the update on the device
    • list of pending devices
    • update configuration details

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…