# Enrollment keys

Source: [https://docs.aventail.co.uk/docs/fleet/keys-and-analytics](https://docs.aventail.co.uk/docs/fleet/keys-and-analytics)

Create a key under **Enrollment & config** when you want to prepare enrollment separately from adding a device. For the combined install-and-enroll flow, use [Add devices](https://docs.aventail.co.uk/docs/fleet/overview).

### Create and revoke enrollment keys

Development Control, 2 October 2026. Keys and identifying details are obscured.

1.  **Find enrollment keys**
    
    Use Create key at the bottom of this card. Existing entries show labels, enrollment counts and revocation state.
    
    [Screenshot: Enrollment keys card — close-up from Enrollment and configuration.](https://docs.aventail.co.uk/img/guides/context/fleet-enrollment.png)
    
2.  **Create a key independently**
    
    Under Enrollment & config, select Create key. Add a descriptive label and create the key; this alone does not enroll a device.
    
    [Screenshot: Create a fleet key dialog with its Label field and Create key action.](https://docs.aventail.co.uk/img/control/fleet-2026-10-02/enrollment-create-key.png)
    
3.  **Copy the one-time secret**
    
    Save the key securely before closing. Use it later with the generated install or existing-install command.
    
    Shared key notice shown with the value hidden. This screenshot-only key was revoked immediately after capture.
    
    [Screenshot: One-time fleet key notice telling the user to copy the key before closing, with the key value obscured.](https://docs.aventail.co.uk/img/control/fleet-2026-10-02/enrollment-key-created.png)
    
4.  **Revoke the key when finished**
    
    Select Revoke beside the intended label and read the confirmation. It prevents further enrollment with this key; enrolled devices keep working.
    
    [Screenshot: Revocation confirmation identifying the Documentation key-only example, with key reference obscured.](https://docs.aventail.co.uk/img/control/fleet-2026-10-02/enrollment-revoke-confirmation.png)
    
5.  **Check the revoked status**
    
    Both temporary documentation keys show revoked. Their counts distinguish key creation alone from the key used to enroll the Mac.
    
    [Screenshot: Enrollment keys showing the two documentation labels, zero and one enrollments, and revoked statuses.](https://docs.aventail.co.uk/img/control/fleet-2026-10-02/enrollment-keys-revoked.png)
    

**Read the enrollment key steps**

## Enrollment keys

Fleet keys let devices join the organisation. They do not expire automatically. **Fleet Admin** and **Super Admin** can create and revoke them; use a descriptive label to make each key's purpose clear.

1.  Open **Fleet operations → Enrollment & config**.
2.  Under **Enrollment keys**, select **Create key**.
3.  Enter a label and select **Create key**.
4.  Save the secret in an approved secure location before closing the dialog. Control displays it only once, then retains a masked reference.
5.  Use the generated install or existing-install command when you are ready to enroll a computer. Creating the key alone does not add a device.

The key-only example in this walkthrough had **0 enrollments**; the separate key used for the test Mac showed **1 enrollment**.

## Enroll a device

Follow [Add devices](https://docs.aventail.co.uk/docs/fleet/overview#create-a-key-and-enroll) for platform selection, protected key files and checking the enrolled device. Keep keys and generated commands out of screenshots, tickets and shared logs.

If the full key is lost after closing the dialog, create a replacement and revoke the old one. Its masked reference cannot be used to enroll a device.

## Revoke a key

1.  Find the key by its label under **Enrollment keys**.
2.  Check its enrollment count and make sure no more computers need it.
3.  Select **Revoke** and read the confirmation before proceeding.
4.  Confirm that the entry is marked **revoked**.

Revocation prevents new enrollments with that key. The enrolled Mac in this walkthrough stayed online and answered a model request after its key was revoked. Retiring an enrolled device is a [separate action](https://docs.aventail.co.uk/docs/fleet/dashboard#retiring-a-device).

**Read the fleet reports reference**

## Versions and performance

**Agent versions** and **Enrollment trend** summarise installed versions and recent additions. If the latest release is unavailable, update status is unknown. Missing metrics do not mean zero usage or latency. The current **Model performance** tab is marked **soon**.

## Cost estimates

**ROI forecast** uses your device, request, token, pricing and running-cost assumptions. Record those inputs with the result and compare estimates with actual costs.
