Understand Device Trust Manager
Get familiar with DigiCert® Device Trust Manager benefits, architecture, user roles, and licensing.
Managed devices
A managed device is a physical device that has a device record in Device Trust Manager. Certificates issued to a managed device are associated with that device record, allowing organizations to track the device in a central inventory and manage it throughout its operational lifecycle.
A device that is manged by Device Trust Manager supports capabilities such as bootstrap certificates for initial onboarding, operational certificates for ongoing authentication, automated certificate workflows, multiple certificates per device, and over-the-air software updates.
Every managed device must belong to a Device group, through which policies, configurations, and updates can be applied consistently.
Registering a managed device consumes one Advanced device license; additional certificates can then be issued to that device without consuming additional licenses.
Registered devices appear under Device management > Devices.
Unmanaged devices
An unmanaged device is a physical device for which Device Trust Manager issues a certificate without creating or referencing a device record. Device Trust Manager manages the certificate, but it does not maintain the underlying device as part of its device inventory.
Consequently, users do not receive device-level tracking, lifecycle management, or ongoing device-management capabilities such as over-the-air updates through that certificate request.
This option is suitable when an organization needs only a certificate-based identity—for example, a Matter Device Attestation Certificate, C2PA claim-signing certificate, or a certificate used during manufacturing or provisioning.
Each issued certificate consumes one Essentials license, and renewing the certificate consumes another license. These certificates are found under Certificate management > Certificates, not under Device management > Devices.