Skip to main content

Enrollment keys

Create a key under Enrollment & config when you want to prepare enrollment separately from adding a device. For the combined install-and-enroll flow, use Add devices.

AVENTAIL / FLEET

Create and revoke enrollment keys

Full view

Enrollment and configuration

Open Enrollment & config. Enrollment keys are grouped in the left-hand card.

Slide 1 of 7: Enrollment and configuration.

Development Control, 2 October 2026. Keys and identifying details are obscured. Use the arrows or progress marks to move between slides.
AVENTAIL / FLEET

Create and revoke enrollment keys

Full view

Enrollment and configuration

Open Enrollment & config. Enrollment keys are grouped in the left-hand card.

Slide 1 of 7: Enrollment and configuration.

Read the enrollment key steps

Enrollment keys​

Fleet keys let devices join the organisation. They do not expire automatically. Fleet Admin and Super Admin can create and revoke them; use a descriptive label to make each key's purpose clear.

  1. Open Fleet operations → Enrollment & config.
  2. Under Enrollment keys, select Create key.
  3. Enter a label and select Create key.
  4. Save the secret in an approved secure location before closing the dialog. Control displays it only once, then retains a masked reference.
  5. Use the generated install or existing-install command when you are ready to enroll a computer. Creating the key alone does not add a device.

The key-only example in this walkthrough had 0 enrollments; the separate key used for the test Mac showed 1 enrollment.

Enroll a device​

Follow Add devices for platform selection, protected key files and checking the enrolled device. Keep keys and generated commands out of screenshots, tickets and shared logs.

If the full key is lost after closing the dialog, create a replacement and revoke the old one. Its masked reference cannot be used to enroll a device.

Revoke a key​

  1. Find the key by its label under Enrollment keys.
  2. Check its enrollment count and make sure no more computers need it.
  3. Select Revoke and read the confirmation before proceeding.
  4. Confirm that the entry is marked revoked.

Revocation prevents new enrollments with that key. The enrolled Mac in this walkthrough stayed online and answered a model request after its key was revoked. Retiring an enrolled device is a separate action.

Read the fleet reports reference

Versions and performance​

Agent versions and Enrollment trend summarise installed versions and recent additions. If the latest release is unavailable, update status is unknown. Missing metrics do not mean zero usage or latency. The current Model performance tab is marked soon.

Cost estimates​

ROI forecast uses your device, request, token, pricing and running-cost assumptions. Record those inputs with the result and compare estimates with actual costs.