Create a key under Enrollment & config when you want to prepare enrollment separately from adding a device. For the combined install-and-enroll flow, use Add devices.
AVENTAIL / FLEET
Create and revoke enrollment keys
1 / 7
Full view
Enrollment and configuration
Open Enrollment & config. Enrollment keys are grouped in the left-hand card.
Find the section
Enrollment keys card
The outlined area is shown close up on the next slide.
Close-up
Find enrollment keys
Use Create key at the bottom of this card. Existing entries show labels, enrollment counts and revocation state.
Slide 04
Create a key independently
Under Enrollment & config, select Create key. Add a descriptive label and create the key; this alone does not enroll a device.
Slide 05
Copy the one-time secret
Save the key securely before closing. Use it later with the generated install or existing-install command.
Shared key notice shown with the value hidden. This screenshot-only key was revoked immediately after capture.
Slide 06
Revoke the key when finished
Select Revoke beside the intended label and read the confirmation. It prevents further enrollment with this key; enrolled devices keep working.
Slide 07
Check the revoked status
Both temporary documentation keys show revoked. Their counts distinguish key creation alone from the key used to enroll the Mac.
Slide 1 of 7: Enrollment and configuration.
Development Control, 2 October 2026. Keys and identifying details are obscured. Use the arrows or progress marks to move between slides.Read the enrollment key steps
Fleet keys let devices join the organisation. They do not expire automatically. Fleet Admin and Super Admin can create and revoke them; use a descriptive label to make each key's purpose clear.
Open Fleet operations → Enrollment & config.
Under Enrollment keys, select Create key.
Enter a label and select Create key.
Save the secret in an approved secure location before closing the dialog. Control displays it only once, then retains a masked reference.
Use the generated install or existing-install command when you are ready to enroll a computer. Creating the key alone does not add a device.
The key-only example in this walkthrough had 0 enrollments; the separate key used for the test Mac showed 1 enrollment.
Follow Add devices for platform selection, protected key files and checking the enrolled device. Keep keys and generated commands out of screenshots, tickets and shared logs.
If the full key is lost after closing the dialog, create a replacement and revoke the old one. Its masked reference cannot be used to enroll a device.
Check its enrollment count and make sure no more computers need it.
Select Revoke and read the confirmation before proceeding.
Confirm that the entry is marked revoked.
Revocation prevents new enrollments with that key. The enrolled Mac in this walkthrough stayed online and answered a model request after its key was revoked. Retiring an enrolled device is a separate action.
Agent versions and Enrollment trend summarise installed versions and recent additions. If the latest release is unavailable, update status is unknown. Missing metrics do not mean zero usage or latency. The current Model performance tab is marked soon.
ROI forecast uses your device, request, token, pricing and running-cost assumptions. Record those inputs with the result and compare estimates with actual costs.