Skip to content

Enrollment keys

An enrollment key lets Lookout register devices to a specific client. Each device trades the key for its own credential during installation.

Create a key

  1. Open Clients and find the client.
  2. Optionally enter a label, such as Initial rollout or Intune.
  3. Select New enrollment key.
  4. Copy the key from the dark box at the top of the page.

Keys are shown only once

Trimtab stores only a fingerprint of the key. If you lose it, revoke it and create a new one. Store keys in your password manager or your RMM's secure variables, never in plain-text scripts shared outside your team.

Reuse and revoke

  • One key can enroll any number of devices for its client. The Uses column counts enrollments.
  • Select Revoke when a rollout is finished or a key may have leaked. Devices already enrolled keep working, because each has its own credential.
  • To stop a specific device from reporting, revoke the device instead. See Device and tenant pages.

Re-enrolling a device

Running the installer again with a key on a device that's already enrolled for the same client replaces its credential instead of creating a duplicate. Its history is kept.