User guideAgents

Enrollment tokens

A host joins your organization by presenting an enrollment token once, when the agent is installed. After that the host has its own credential, and the token is deleted from it.

Create a token

  1. Open Enrollment in the sidebar (under Administration).

  2. Press Create token.

  3. Fill in:

    Field What it does
    Name Where the token will be used, for example "Production web servers"
    Expires after 1 hour, 24 hours, 7 days or 30 days. Shorter is safer
    Can enroll One endpoint, up to 10, up to 100, or no limit
    Allowed networks Optional. IP ranges in CIDR form, one per line, for example 10.20.0.0/16. Requests from other addresses are refused
    Allowed hostnames Optional. Patterns, one per line, for example web-*. Other hostnames are refused
    Require approval Optional. Each host waits in a queue until an administrator approves it
  4. Press Create token.

The next screen shows the token and the install commands with it filled in, one for each system: Linux, Windows, macOS, and the Debian/Ubuntu and RHEL packages. Copy the one you need with Copy command.

The token is shown only once. If you close the screen without copying it, create a new token.

Approving hosts

With Require approval, a new host appears under Waiting for approval on the Enrollment page instead of under Devices. Press Approve to let it in, or Reject to refuse it. Until then it cannot be patched.

Revoking and deleting

  • Revoke token stops the token from enrolling anything more. Hosts that already enrolled with it keep working. This cannot be undone.
  • Delete token removes it from the list.

Enrollment attempts

The Enrollment attempts list shows every use of a token: accepted, waiting and refused, with the host, its address and the reason. Refusals are highlighted, so a leaked or wrongly scoped token is easy to spot.

Good practice

  • One token per purpose or site, with a short expiry and a use limit.
  • Allowed networks for tokens used inside your own network.
  • Revoke a token as soon as the rollout it was made for is finished.

Next