Agent enrollment
The agent is installed from an MSI and joins your tenant with an enrollment token. (With Active Directory you can also let the site connector push it.)
Create a token
Under Agent enrollment (tenant admins), choose New token:
| Field | Meaning |
|---|---|
| Label | Optional note, e.g. "HQ roll-out September". |
| Site for new devices | The site agents enrolled with this token join. |
| Maximum uses | Empty = unlimited. |
| Expires after (days) | Empty = never. |
The token is shown once, together with the MSI download link and the install command. Copy them now; afterwards only a hash of the token is stored.
Use one token per site and roll-out, with an expiry or a use limit, so a leaked token is useless. Revoke it when the roll-out is done. Revoking a token does not affect agents that already enrolled.
Delete a token
Revoked, expired and used-up tokens stay in the list. A global admin can remove any token for good with Delete on its row:
- Click Delete.
- Enter your own password (the one of your Entrosity account). The deletion needs it every time, and repeated wrong attempts are rate-limited like sign-in.
- Click Delete token.
The password is checked by Entrosity Hub, which hands Axis a confirmation valid for two minutes and one deletion.
After that:
- The token is gone from the list and can no longer enroll anything.
- Agents and connectors that already enrolled with it keep working, because they have their own keys.
- The audit log keeps an
enrollment_token.deleteentry with who deleted it and a snapshot of the token (never the secret).
Tenant admins do not see Delete, and the API refuses it for them (403); they can still revoke. Deleting the push token that Active Directory sync makes for agent pushes is allowed: a new one is created for the next push.
Install the agent
Download the MSI from the link shown and install it in an elevated prompt, or through GPO, Intune (Win32 app) or any software distribution:
msiexec /i rmm-agent.msi /qn ENROLLMENT_TOKEN=<token> SERVER_URL=https://hub.entrosity.com/axis
| MSI property | Meaning |
|---|---|
ENROLLMENT_TOKEN | The token (hidden from MSI logs). |
SERVER_URL | The server's public URL, including Axis's path (RMM_PUBLIC_URL, for example https://hub.entrosity.com/axis). Agents enrolled earlier with https://manage.entrosity.com or https://portal.entrosity.com/manage keep working. |
- A failed enrollment rolls the installation back.
- An MSI installed without the properties installs the service, which
waits until
rmm-agent.exe enroll --server … --token …is run. /qnhides errors. To see them, add/l*v C:\agent-install.logand look forReturn value 3. Delete the log afterwards: it can contain the token.
The device appears under Devices as online within a minute and sends its first inventory.
Re-installing and re-enrolling
Re-enrolling the same machine (matched by its MachineGuid, then its
machine SID) keeps the existing device record and rotates the agent's key.
Use this to repair a broken agent or to bring back a decommissioned one.
Enrollment errors
| Error | HTTP | Meaning |
|---|---|---|
enrollment_token_invalid | 401 | Unknown token (or a connector token used for an agent). |
enrollment_token_exhausted | 409 | The token has no uses left. |
enrollment_token_expired | 410 | The token expired or was revoked. |
rate_limited | 429 | Too many enrollments from one IP address; the server allows RMM_ENROLL_RATE_PER_MINUTE (default 60) per minute. |
See Troubleshooting → An agent does not connect and the agent reference.