Enrollment tokens
A host joins your organization by presenting an enrollment token once, when the agent is installed. After that the host has its own credential, and the token is deleted from it.
Create a token
Open Enrollment in the sidebar (under Administration).
Press Create token.
Fill in:
Field What it does Name Where the token will be used, for example "Production web servers" Expires after 1 hour, 24 hours, 7 days or 30 days. Shorter is safer Can enroll One endpoint, up to 10, up to 100, or no limit Allowed networks Optional. IP ranges in CIDR form, one per line, for example 10.20.0.0/16. Requests from other addresses are refusedAllowed hostnames Optional. Patterns, one per line, for example web-*. Other hostnames are refusedRequire approval Optional. Each host waits in a queue until an administrator approves it Press Create token.
The next screen shows the token and the install commands with it filled in, one for each system: Linux, Windows, macOS, and the Debian/Ubuntu and RHEL packages. Copy the one you need with Copy command.
The token is shown only once. If you close the screen without copying it, create a new token.
Approving hosts
With Require approval, a new host appears under Waiting for approval on the Enrollment page instead of under Devices. Press Approve to let it in, or Reject to refuse it. Until then it cannot be patched.
Revoking and deleting
- Revoke token stops the token from enrolling anything more. Hosts that already enrolled with it keep working. This cannot be undone.
- Delete token removes it from the list.
Enrollment attempts
The Enrollment attempts list shows every use of a token: accepted, waiting and refused, with the host, its address and the reason. Refusals are highlighted, so a leaked or wrongly scoped token is easy to spot.
Good practice
- One token per purpose or site, with a short expiry and a use limit.
- Allowed networks for tokens used inside your own network.
- Revoke a token as soon as the rollout it was made for is finished.