Pre-requisites
- Organization owner
- Organization admin
To enroll a device
- Log in to Zoho One. Click Directory icon in the top-right corner.
- In the Admin Panel, click Device Management.
Click Get Started.
- Follow
the steps displayed for downloading and installing Zoho One agent
according to the type of operating system you use.
To add more devices, click Enroll Device.
Prerequisites for agent installation
For macOS devices
- Make sure you have admin credentials.
- The device you're attempting to enroll must not be bound by Active Directory.
- The device must support any of the versions specified on the enrollment page.
- You
need admin privileges with secure token access. Also, an Active
Directory-bound mobile account must be converted to a local account
before installing the agent. Make sure you enable full disk access for
the agent to be downloaded. This can only be done through an admin
account.
Important note for macOS Tahoe 26.1 and later:
Due
to a temporary macOS issue, the Zoho One agent will not appear
automatically in your Full Disk Access settings. The installer will
guide you to locate and select it manually. Please follow the on-screen
prompt and the steps below when prompted.
For Linux device
- Make sure you have admin credentials.
- The device you're attempting to enroll must not be bound by Active Directory.
- The device must support any of the versions specified on the enrollment page.
- The package libnotify_bin has to be installed.
For Windows devices
- Make sure you have admin credentials.
- The device you're attempting to enroll must not be bound by Active Directory.
- The device must support any of the versions specified on the enrollment page.
- Make
sure you install the latest version of Visual Studio Redistributable on
the device to be enrolled. You can download it from this site.
- In Group Policy Editor, the following policies must be disabled:
- Interactive logon: Don't display last signed-in
- Interactive logon: Require Windows Hello for Business or smart card
Path:
Edit group policy → Computer configuration → Windows settings →
Security settings → Local policies → Security options → Interactive
logon policies
A Microsoft Outlook account must not be used as a local account while assigning a user.
Steps for installation
For macOS
- Copy the Installation Key and click Download Agent. Once the download is complete, install the agent by following the on-screen prompts.
- Extract the downloaded zip file and double click the .pkg, the ZD agent installation window pops up.
- The installation window prompts for an "Installation Key". Enter the key in the dialog box and continue.
- This key can be obtained from device management panel under macOS section.

Installation window pops up to enter your secure token-enabled admin local account credentials. Grant Full Disk access to zagent-one when prompted.
If you don't see the Zoho One binary listed in Full Disk Access:
- Navigate to System Settings → Privacy & Security → Full Disk Access
- Make sure you have admin permissions to make the changes.
- Click the + button.
- Press Command + Shift + G to open Go to Folder.
- Enter: /opt/ZohoDirectory/bin/zagent-one.
- Click Go.
- Select zagent-one and click Open.
- Alternatively,
you can drag and drop the zagent-one file directly into the Full
Disk Access window. The binary will not appear in the Full Disk Access
list even after adding it. This is expected behavior. The installation
will automatically resume once the permission is applied.
- Once the agent installation is successful, the device should be available and manageable in the Device Management panel.
For Linux
- Switch to the Linux enrollment page. Copy both the Installation Key and the Linux agent download script.
- Open the Terminal or Command Prompt on the device in which you want to install the Linux agent.
- Enter
the copied Linux agent download script. A message asking for your login
password to verify the installation will appear. Type in the password
to proceed.

- When prompted, enter the Installation key.
For Windows
- Click Download Agent.
Once the download is complete, extract the corresponding zip file at
its location. Make sure file extraction at the appropriate location is
done properly, otherwise agent installation will end up unsuccessful.
- Double-click the One-Windows-Agent.msi file and install the agent by following the on-screen prompts.
- The
device is enrolled once the installation is complete. You can find the
name of the enrolled device listed in the Device Management tab.
There's no involvement of any installation keys here, unlike the other two platforms mentioned above.