Assign certificate management policies to a device group
To perform this action, you must have a user role that contains the Solution administrator permission.
Device groups use policies to define the rules and configurations that govern device behavior, security, and updates. Policies are assigned to device groups to ensure uniform management across all devices within the group.
To complete these steps, make sure you have:
A user account with the Solution Administrator role. This is required to create and manage device groups.
An existing certificate management policy configured to support device registration and management.
In the Device Trust Manager menu, go to Device management > Device groups.
Select the Device group for which you want to assign the certificate management policy.
Open the Device group and go to Policy assignments.
Select Assign policy to open the policy assignment pane.
Select a Policy usage:
Bootstrap: Defines how to issue and manage an initial/birth certificate.
Operational: Issues and manages short-lived X.509 certificates for device-service communication. Operational certificates have a short lifespan, can be revoked, and are obtained using a bootstrap credential.
Enter the Name of the policy assignment.
From the Assign a certificate management policy dropdown list, choose a certificate management policy.
Expand the Device field mapping and map the inventory attributes.
Important
If a certificate management policy uses EST, SCEP, CMPv2, or ACME as the management method, then device field mapping is required.
For bootstrap certificate management policies, field mapping provides the values for identity attributes, which are obtained during certificate requests.
For operational certificate management policies, field mapping provides device identification using the CSR during the certificate issuance request process.
Optionally, choose an Authentication policy to assign to the device group.
Note
If a certificate management policy uses EST, SCEP, CMPv2, or ACME as the management method, then you must choose an authentication policy.
If the certificate management policy already specifies an authentication policy, that policy is applied by default. Selecting a different authentication policy in this setting will override the default configuration.
Optionally, choose a Cloud platform policy to assign to the device group.
Note
You can choose a cloud platform policy:
Only if you have selected policy usage as Operational.
You should already have a cloud platform policy. If you do not, see Create a cloud platform policy .
You must use the same intermediate CA that you have specified in your cloud platform policy here as well.
Select Assign policy.
The newly assigned policy is associated with the device group, and appears under Device management > Device groups.
Tip
You can assign multiple policies to a device group. For example, one for a bootstrap and another for an operational policy.