Skip to main content

Agent enrollment

The agent is installed from an MSI and joins your tenant with an enrollment token. (With Active Directory you can also let the site connector push it.)

Create a token​

Under Agent enrollment (tenant admins), choose New token:

FieldMeaning
LabelOptional note, e.g. "HQ roll-out September".
Site for new devicesThe site agents enrolled with this token join.
Maximum usesEmpty = unlimited.
Expires after (days)Empty = never.

The token is shown once, together with the MSI download link and the install command. Copy them now; afterwards only a hash of the token is stored.

tip

Use one token per site and roll-out, with an expiry or a use limit, so a leaked token is useless. Revoke it when the roll-out is done. Revoking a token does not affect agents that already enrolled.

Delete a token​

Revoked, expired and used-up tokens stay in the list. A global admin can remove any token for good with Delete on its row:

  1. Click Delete.
  2. Enter your own password (the one of your Entrosity account). The deletion needs it every time, and repeated wrong attempts are rate-limited like sign-in.
  3. Click Delete token.

The password is checked by Entrosity Hub, which hands Axis a confirmation valid for two minutes and one deletion.

After that:

  • The token is gone from the list and can no longer enroll anything.
  • Agents and connectors that already enrolled with it keep working, because they have their own keys.
  • The audit log keeps an enrollment_token.delete entry with who deleted it and a snapshot of the token (never the secret).

Tenant admins do not see Delete, and the API refuses it for them (403); they can still revoke. Deleting the push token that Active Directory sync makes for agent pushes is allowed: a new one is created for the next push.

Install the agent​

Download the MSI from the link shown and install it in an elevated prompt, or through GPO, Intune (Win32 app) or any software distribution:

msiexec /i rmm-agent.msi /qn ENROLLMENT_TOKEN=<token> SERVER_URL=https://hub.entrosity.com/axis
MSI propertyMeaning
ENROLLMENT_TOKENThe token (hidden from MSI logs).
SERVER_URLThe server's public URL, including Axis's path (RMM_PUBLIC_URL, for example https://hub.entrosity.com/axis). Agents enrolled earlier with https://manage.entrosity.com or https://portal.entrosity.com/manage keep working.
  • A failed enrollment rolls the installation back.
  • An MSI installed without the properties installs the service, which waits until rmm-agent.exe enroll --server … --token … is run.
  • /qn hides errors. To see them, add /l*v C:\agent-install.log and look for Return value 3. Delete the log afterwards: it can contain the token.

The device appears under Devices as online within a minute and sends its first inventory.

Re-installing and re-enrolling​

Re-enrolling the same machine (matched by its MachineGuid, then its machine SID) keeps the existing device record and rotates the agent's key. Use this to repair a broken agent or to bring back a decommissioned one.

Enrollment errors​

ErrorHTTPMeaning
enrollment_token_invalid401Unknown token (or a connector token used for an agent).
enrollment_token_exhausted409The token has no uses left.
enrollment_token_expired410The token expired or was revoked.
rate_limited429Too many enrollments from one IP address; the server allows RMM_ENROLL_RATE_PER_MINUTE (default 60) per minute.

See Troubleshooting → An agent does not connect and the agent reference.