Enrollment keys¶
An enrollment key lets Lookout register devices to a specific client. Each device trades the key for its own credential during installation.
Create a key¶
- Open Clients and find the client.
- Optionally enter a label, such as Initial rollout or Intune.
- Select New enrollment key.
- Copy the key from the dark box at the top of the page.
Keys are shown only once
Trimtab stores only a fingerprint of the key. If you lose it, revoke it and create a new one. Store keys in your password manager or your RMM's secure variables, never in plain-text scripts shared outside your team.
Reuse and revoke¶
- One key can enroll any number of devices for its client. The Uses column counts enrollments.
- Select Revoke when a rollout is finished or a key may have leaked. Devices already enrolled keep working, because each has its own credential.
- To stop a specific device from reporting, revoke the device instead. See Device and tenant pages.
Re-enrolling a device¶
Running the installer again with a key on a device that's already enrolled for the same client replaces its credential instead of creating a duplicate. Its history is kept.