Skip to main content

Manage devices

Manage your devices throughout the onboarding lifecycle by registering devices, requesting device certificates, organizing devices into groups, and provisioning them to supported cloud platforms. This chapter also includes guided workflows for common onboarding and deployment scenarios to help you securely prepare devices for production.

Tableau 1. Manage devices

Topic

Description

Register devices

Register devices to establish their identity in Device Trust Manager and prepare them for secure lifecycle management.

Request device certificates

Issue certificates to establish trusted identities for managed devices.

Manage divisions

Create and manage divisions to organize your Device Trust Manager environment and control user access to administrative resources.

Manage device groups

Organize devices into groups to simplify administration, policy assignment, and certificate management.

Provision devices to cloud platforms

Connect registered devices to supported cloud platforms to enable secure cloud provisioning and identity management.

Guided workflows

Follow guided, end-to-end workflows for common device onboarding and identity management scenarios, including just-in-time registration, batch device registration, TrustEdge deployment, and TPM-based key management.


Avis

Devices must be registered in Device Trust Manager to enable monitoring, updates, policy enforcement, and fleet management. Registration is required for all devices to be securely managed throughout their lifecycle.

Device properties

Each device includes several key properties that are used for identification and management.

Tableau 2. Device properties

Property

Description

Device ID

A unique identifier assigned to each device.

Device group ID

Unique identifier of the associated device group. Every device must be assigned to one device group at registration.

Key/value attributes

Attributes in the form of key/value pairs that provide additional identification or metadata for the device. These can be used to search, filter, or trigger actions.


Device attributes

Attributes are key/value pairs that represent various properties of a device, such as Device name, its MAC address, operating system, or location. These attributes allow devices to be identified, organized, and managed.

Device registration

Devices can be registered individually or in batches using a CSV template, with batch registrations processed as jobs. During registration, attributes and device group assignment are specified, ensuring that each device is properly categorized and managed.

Tableau 3. Device registration methods

Registration method

Description

Single device

Devices can be manually registered one by one in Device Trust Manager. Devices can also be registered using EST, SCEP, or CMPv2.

Multiple devices

Multiple devices can be registered at once using a CSV file that defines the device properties, including key/value pairs and group assignment.


Astuce

You can also register a single device or multiple devices using Device Trust Manager Management REST API.

Device lifecycle states

Devices are tracked and managed through various states and statuses that provide insight into their lifecycle and operational status. These states help identify a device’s registration progress, connection health, and ability to interact with Device Trust Manager.

Tableau 4. Connection statuses

Connection status

Description

Connected

Device is currently connected to the Rendezvous Service via MQTT.

Not connected

Device is not connected. The device log shows the timestamp of the last connection.


Tableau 5. Device states

Device state

Description

Registered

Device has obtained its bootstrap credentials and is able to authentication with the Rendezvous Service.

Provisioned

Device has completed the provisioning process and has applied all assigned policies.

Enrolled

Device identity is registered, but the device has not yet received a bootstrap certificate.

Deleted

Device has been deleted and its identity and records removed from Device Trust Manager.


Tableau 6. Device statuses

Device status

Enabled

Default state for devices in the Registered or Provisioned state unless manually disabled.

Disabled

Device is disabled from connecting to Device Trust Manager and prevented from reconnecting until it is manually re-enabled.


Static groups

A static device group is a set of devices manually managed by administrators. Devices are individually added or removed from the device group, and each device can only belong to one static group at a time.

Tableau 7. Static group characteristic

Characteristic

Description

Manual assignment

Devices are assigned to static groups during enrollment or through administrative actions.

Exclusive membership

A device can only belong to one static group at a time.

Mandatory assignment

All devices must be part of a static group.


Device group states

A device group can exist in one of two states, depending on its current usage.

Tableau 8. Device group states

State

Description

Enabled

The default state when a device group is created. Devices can be added to the group and assigned policies are active.

Disabled

No new devices can be added to the group. Existing devices will continue to operate under the assigned policies.


Astuce

Disabling a device group is useful for phasing out a group without impacting the devices already assigned to it.

Policies and device groups

Device groups use policies to define the rules and configurations that govern device behavior, security, and updates. Policies are assigned to device groups to ensure uniform management across all devices within the group.

Tableau 9. Device group policy types

Policy type

Description

Certificate Management Policy

Manage authentication by issuing and renewing certificates, ensuring secure communication between devices.

Deployment policy

Control the distribution and installation of firmware updates, applications, and configuration changes.

Security policy

Enforce security measures such as access controls, encryption standards, and compliance with organizational policies.


Disruptive policies

Disruptive policies are those that alter the operational state of a device, such as firmware updates or configuration changes that require a reboot. These policies can only be applied to static device groups to ensure that changes do not conflict with other policies or actions. Examples of disruptive policies include:

  • Firmware updates that may restart a device.

  • Security patches that modify core configurations.

What's Next

Continue to register your devices to establish their identity in Device Trust Manager and prepare them for certificate issuance and lifecycle management.