Manage devices
Manage your devices throughout the onboarding lifecycle by registering devices, requesting device certificates, organizing devices into groups, and provisioning them to supported cloud platforms. This chapter also includes guided workflows for common onboarding and deployment scenarios to help you securely prepare devices for production.
Topic | Description |
|---|---|
Register devices to establish their identity in Device Trust Manager and prepare them for secure lifecycle management. | |
Issue certificates to establish trusted identities for managed devices. | |
Create and manage divisions to organize your Device Trust Manager environment and control user access to administrative resources. | |
Organize devices into groups to simplify administration, policy assignment, and certificate management. | |
Connect registered devices to supported cloud platforms to enable secure cloud provisioning and identity management. | |
Follow guided, end-to-end workflows for common device onboarding and identity management scenarios, including just-in-time registration, batch device registration, TrustEdge deployment, and TPM-based key management. |
Note
Devices must be registered in Device Trust Manager to enable monitoring, updates, policy enforcement, and fleet management. Registration is required for all devices to be securely managed throughout their lifecycle.
Device properties
Each device includes several key properties that are used for identification and management.
Property | Description |
|---|---|
Device ID | A unique identifier assigned to each device. |
Device group ID | Unique identifier of the associated device group. Every device must be assigned to one device group at registration. |
Key/value attributes | Attributes in the form of key/value pairs that provide additional identification or metadata for the device. These can be used to search, filter, or trigger actions. |
Device attributes
Attributes are key/value pairs that represent various properties of a device, such as Device name, its MAC address, operating system, or location. These attributes allow devices to be identified, organized, and managed.
Device registration
Devices can be registered individually or in batches using a CSV template, with batch registrations processed as jobs. During registration, attributes and device group assignment are specified, ensuring that each device is properly categorized and managed.
Registration method | Description |
|---|---|
Single device | Devices can be manually registered one by one in Device Trust Manager. Devices can also be registered using EST, SCEP, or CMPv2. |
Multiple devices | Multiple devices can be registered at once using a CSV file that defines the device properties, including key/value pairs and group assignment. |
Tip
You can also register a single device or multiple devices using Device Trust Manager Management REST API.
Device lifecycle states
Devices are tracked and managed through various states and statuses that provide insight into their lifecycle and operational status. These states help identify a device’s registration progress, connection health, and ability to interact with Device Trust Manager.
Connection status | Description |
|---|---|
Connected | Device is currently connected to the Rendezvous Service via MQTT. |
Not connected | Device is not connected. The device log shows the timestamp of the last connection. |
Device state | Description |
|---|---|
Registered | Device has obtained its bootstrap credentials and is able to authentication with the Rendezvous Service. |
Provisioned | Device has completed the provisioning process and has applied all assigned policies. |
Enrolled | Device identity is registered, but the device has not yet received a bootstrap certificate. |
Deleted | Device has been deleted and its identity and records removed from Device Trust Manager. |
Device status | |
|---|---|
Enabled | Default state for devices in the Registered or Provisioned state unless manually disabled. |
Disabled | Device is disabled from connecting to Device Trust Manager and prevented from reconnecting until it is manually re-enabled. |
Static groups
A static device group is a set of devices manually managed by administrators. Devices are individually added or removed from the device group, and each device can only belong to one static group at a time.
Characteristic | Description |
|---|---|
Manual assignment | Devices are assigned to static groups during enrollment or through administrative actions. |
Exclusive membership | A device can only belong to one static group at a time. |
Mandatory assignment | All devices must be part of a static group. |
Device group states
A device group can exist in one of two states, depending on its current usage.
State | Description |
|---|---|
Enabled | The default state when a device group is created. Devices can be added to the group and assigned policies are active. |
Disabled | No new devices can be added to the group. Existing devices will continue to operate under the assigned policies. |
Tip
Disabling a device group is useful for phasing out a group without impacting the devices already assigned to it.
Policies and device groups
Device groups use policies to define the rules and configurations that govern device behavior, security, and updates. Policies are assigned to device groups to ensure uniform management across all devices within the group.
Policy type | Description |
|---|---|
Certificate Management Policy | Manage authentication by issuing and renewing certificates, ensuring secure communication between devices. |
Deployment policy | Control the distribution and installation of firmware updates, applications, and configuration changes. |
Security policy | Enforce security measures such as access controls, encryption standards, and compliance with organizational policies. |
Disruptive policies
Disruptive policies are those that alter the operational state of a device, such as firmware updates or configuration changes that require a reboot. These policies can only be applied to static device groups to ensure that changes do not conflict with other policies or actions. Examples of disruptive policies include:
Firmware updates that may restart a device.
Security patches that modify core configurations.
What's Next
Continue to register your devices to establish their identity in Device Trust Manager and prepare them for certificate issuance and lifecycle management.