You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
docs: osquery-based enrollment for Fleet, 2026-05-01 API, auto-approval curl
- Enrollment guide: add an osquery-based enrollment section for Fleet, and
move the device API examples to the 2026-05-01 API version.
- Fleet tutorial: describe Linux enrollment as ACME Device Attestation with
the TPM, and show the curl flow for adding Fleet to autoApproveSources via
the Device Enrollment Policy API, since the console doesn't expose it.
- Agent guide and troubleshooting: tighten the wording around
pre-registration and the duplicate-registration symptom.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017MzPzeUonmnLSsg2KvYgAK
Copy file name to clipboardExpand all lines: platform/enrollment-guide.mdx
+11-10Lines changed: 11 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -31,7 +31,7 @@ into your Smallstep inventory:
31
31
You can [manually invite users
32
32
to join your Smallstep team](https://smallstep.com/app/?next=/users/invite),
33
33
and they will be able to self-enroll devices
34
-
using the [Smallstep Agent](./smallstep-agent.mdx).
34
+
using the [Smallstep Agent](./smallstep-agent.mdx)'s `step-agent register` subcommand.
35
35
36
36
By default, administrators
37
37
must approve a new device
@@ -69,32 +69,33 @@ until Smallstep receives an attestation from the device.
69
69
For a concrete example,
70
70
see [Connect Jamf Pro to Smallstep](../tutorials/connect-jamf-pro-to-smallstep.mdx)
71
71
72
+
### Use osquery-based enrollment
73
+
74
+
For [Fleet-managed](../tutorials/connect-fleet-dm-to-smallstep.mdx) Linux and Windows hosts, deploy the Smallstep osquery extension.
75
+
The osquery extension will report each device's TPM Endorsement Key to Fleet.
76
+
Smallstep then syncs the data into your inventory.
77
+
72
78
### Add devices via API
73
79
74
80
You can import devices from any source into Smallstep using our API.
81
+
75
82
Use this when your devices are inventoried in a system that Smallstep can't sync from.
76
-
If Smallstep already syncs your inventory from an MDM,
77
-
don't add the same devices via the API as well:
78
-
the result is a duplicate entry that blocks agent enrollment.
79
-
For Fleet-managed Linux and Windows hosts,
80
-
deploy the [Smallstep osquery extension](../tutorials/connect-fleet-dm-to-smallstep.mdx#linux)
81
-
so that Fleet reports each device's TPM Endorsement Key to Smallstep.
82
83
83
84
Devices added via API are automatically approved.
84
85
but they will not be marked as high-assurance
85
86
until Smallstep receives an attestation from the device.
86
87
87
88
You'll need [an API token](https://smallstep.com/app/?next=/settings/api/tokens/add) with all “device” scopes (put-device, patch-device, etc.).
88
89
89
-
Use the [Add Device](https://gateway.smallstep.com/v2025-01-01/operations/PostDevices) endpoint to create a device.
90
+
Use the [Add Device](https://gateway.smallstep.com/v2026-05-01/operations/PostDevices) endpoint to create a device.
90
91
- For Apple devices, the `permanentIdentifier` must be the device's 9-character serial number.
91
92
- For TPM 2.0 devices, the `permanentIdentifier` must be the TPM Endorsement Key URI, in the format `urn:ek:sha256:ul3sYf6uQ6jVEXAMPLEXoAuHI10U8gTvEJ6bMj95LXI=`. (You can retrieve the EK URI by running `step agent tpm --fingerprint` on the device.)
92
93
- To create and assign a user to a device, fill in the `user` fields.
93
94
94
95
Once added,
95
96
the devices will be automatically approved.
96
97
97
-
You can see the device using the [List Devices](https://gateway.smallstep.com/v2025-01-01/operations/ListDevices) endpoint:
98
+
You can see the device using the [List Devices](https://gateway.smallstep.com/v2026-05-01/operations/ListDevices) endpoint:
Copy file name to clipboardExpand all lines: platform/smallstep-agent.mdx
+2-4Lines changed: 2 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,7 +22,7 @@ Using an MDM? See:
22
22
-[Connect Jamf Pro to Smallstep](../tutorials/connect-jamf-pro-to-smallstep.mdx) (macOS)
23
23
-[Connect Intune to Smallstep](../tutorials/connect-intune-to-smallstep.mdx) (Windows)
24
24
-[Connect Workspace ONE to Smallstep](../tutorials/connect-workspace-one-to-smallstep.mdx) (Windows)
25
-
-[Connect Fleet DM to Smallstep](../tutorials/connect-fleet-dm-to-smallstep.mdx) (macOS, Linux, Windows)
25
+
-[Connect Fleet DM to Smallstep](../tutorials/connect-fleet-dm-to-smallstep.mdx)
26
26
</Alert>
27
27
28
28
Running into trouble? See the [Smallstep Agent troubleshooting guide](./troubleshooting-agent.mdx).
@@ -356,7 +356,7 @@ so a host with no <code>/dev/tpmrm0</code> cannot enroll yet.
356
356
```
357
357
358
358
359
-
## Registering and approving endpoints
359
+
## Registering and approving NixOS endpoints
360
360
361
361
### Self-registration
362
362
@@ -388,8 +388,6 @@ If your devices are inventoried in a system that Smallstep can't sync from, you
388
388
- Select the Smallstep Agents authority
389
389
- Use the sha256 Root fingerprint displayed on this page
390
390
391
-
If Smallstep already syncs your inventory from an MDM that reports each device's TPM Endorsement Key, such as Fleet with the Smallstep osquery extension, skip step 1. The devices are already in your inventory, and adding them again via the API or with `step-agent register` creates a conflicting entry. Write `agent.yaml` as in step 2 and start the agent. It attests with its TPM and is matched to the synced entry. See [Connect Fleet DM to Smallstep](../tutorials/connect-fleet-dm-to-smallstep.mdx#linux) for the full Fleet flow.
Copy file name to clipboardExpand all lines: platform/troubleshooting-agent.mdx
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -99,10 +99,10 @@ The agent may not be installed or may not be running on the device.
99
99
100
100
**Symptom:** "`step-agent register` fails with `unprocessable entity`, or the browser prompts me to register a device that is already in my inventory"
101
101
102
-
The device already exists in your Smallstep inventory. This happens when the device was synced from an MDM that reports its TPM Endorsement Key (for example, Fleet with the Smallstep osquery extension) or was added via the API. `step-agent register` tries to create a second device entry, which conflicts with the existing one.
102
+
This happens when the device was synced from an MDM that reports its TPM Endorsement Key or was added via the API. `step-agent register` tries to create a second device entry, which conflicts with the existing one.
103
103
104
104
**Troubleshooting steps:**
105
-
1. Don't run `step-agent register` on the device. Write the agent configuration file directly and start the agent service. It attests with its TPM and is matched to the existing entry. See [Linux agent configuration](../tutorials/connect-fleet-dm-to-smallstep.mdx#step-5-linux-agent-configuration) in the Fleet tutorial, or [Pre-registration via API](./smallstep-agent.mdx#pre-registration-via-api) in the agent guide.
105
+
1. Don't run `step-agent register` on the device. Write the agent configuration file directly and start the agent service. See [Pre-registration via API](./smallstep-agent.mdx#pre-registration-via-api).
106
106
2. If a duplicate device was created, delete it in the [Smallstep console](https://smallstep.com/app/?next=/devices) and keep the entry that came from the MDM sync or the API.
107
107
3. If the device shows as pending after the agent starts, approve it in the console.
Copy file name to clipboardExpand all lines: tutorials/connect-fleet-dm-to-smallstep.mdx
+57-13Lines changed: 57 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -404,10 +404,13 @@ Once the enrollment report is configured in Fleet, the Smallstep platform needs
404
404
2. In the Smallstep console, edit your Fleet configuration
405
405
3. Set the **Enrollment Query ID** to the numeric ID
406
406
407
+
Your fleet's TPM information will begin syncing to Smallstep.
407
408
408
409
## Step 5. Linux agent configuration
409
410
410
-
Linux does not support MDM configuration profiles, so the SCEP enrollment flow used for macOS and Windows does not apply. Instead, the Smallstep agent on Linux registers directly using TPM attestation. After installing the agent package and the osquery extension, you must configure the agent with your Smallstep team slug and CA fingerprint.
411
+
Linux does not support MDM configuration profiles, so the SCEP enrollment flow used for macOS and Windows does not apply. Instead, the Smallstep agent on Linux uses ACME Device Attestation with the system's TPM.
412
+
413
+
After installing the agent package and the osquery extension, you must configure the agent with your Smallstep team slug and CA fingerprint.
411
414
412
415
When adding a Linux agent package in Fleet, add the following **post-install script** to configure and start the agent:
413
416
@@ -426,14 +429,34 @@ systemctl daemon-reload
426
429
systemctl enable --now step-agent
427
430
```
428
431
432
+
When the agent starts, it attests with the endpoint's TPM. Smallstep matches the attestation to the inventory data you just synced. By default, devices synced from Fleet need admin approval: if the host shows as `pending` in the [Smallstep console](https://smallstep.com/app/?next=/devices), approve it there.
429
433
430
-
When the agent starts, it attests with the host's TPM, and Smallstep matches the attestation to the inventory entry that Fleet synced along with the TPM Endorsement Key. No registration step runs on the host. By default, devices synced from Fleet need admin approval: if the host shows as pending in the [Smallstep console](https://smallstep.com/app/?next=/devices), approve it there. To approve Fleet-synced devices automatically, add `Fleet` to `autoApproveSources` using the [Device Enrollment Policy API](https://gateway.smallstep.com/v2026-05-01/operations/PutDeviceEnrollmentPolicy).
434
+
To approve Fleet-synced devices automatically, add `Fleet`to `autoApproveSources` in your team's device enrollment policy. This setting isn't exposed in the Smallstep console. Use the [Device Enrollment Policy API](https://gateway.smallstep.com/v2026-05-01/operations/PutDeviceEnrollmentPolicy) with an [API token](https://smallstep.com/app/?next=/settings/api/tokens/add) that has the `get-device-enrollment-policy` and `put-device-enrollment-policy` scopes. The `PUT` replaces the whole policy, so fetch the current policy first and resubmit it with `Fleet` added to `autoApproveSources`:
431
435
432
-
<Alertseverity="warning">
433
-
<div>
434
-
Do not run `step-agent register` or `step-agent start --login` on a host that Fleet has already synced to Smallstep, and do not add the host through the Smallstep API. The host is already in your inventory, and registering it again fails with `unprocessable entity` or prompts you to register a duplicate device. The agent configuration above is all the host needs.
435
-
</div>
436
-
</Alert>
436
+
```bash
437
+
set +o history
438
+
echo"Authorization: Bearer [your API token]"> api_headers
@@ -565,13 +588,34 @@ Add the Smallstep agent MSI as Fleet software so it installs on enrollment:
565
588
2. In the Fleet console, go to **Software**, choose **Add software → Custom package**, and upload the MSI
566
589
3. Scope the install to your Windows hosts
567
590
568
-
The agent reads the registry values written in Step 3 on startup, attests with the host's TPM, and Smallstep matches the attestation to the inventory entry that Fleet synced along with the TPM Endorsement Key. By default, devices synced from Fleet need admin approval: if the host shows as pending in the [Smallstep console](https://smallstep.com/app/?next=/devices), approve it there. To approve Fleet-synced devices automatically, add `Fleet` to `autoApproveSources` using the [Device Enrollment Policy API](https://gateway.smallstep.com/v2026-05-01/operations/PutDeviceEnrollmentPolicy).
591
+
On startup, the agent reads the registry values to find the team information, then attests with the endpoint's TPM. Smallstep matches the attestation to the inventory data synced from Fleet.
569
592
570
-
<Alertseverity="warning">
571
-
<div>
572
-
Do not run `step-agent register` or `step-agent start --login` on a host that Fleet has already synced to Smallstep, and do not add the host through the Smallstep API. The host is already in your inventory, and registering it again fails with `unprocessable entity` or prompts you to register a duplicate device. The agent configuration above is all the host needs.
573
-
</div>
574
-
</Alert>
593
+
By default, devices synced from Fleet need admin approval: if the host shows as pending in the [Smallstep console](https://smallstep.com/app/?next=/devices), approve it there. To approve Fleet-synced devices automatically, add `Fleet` to `autoApproveSources` in your team's device enrollment policy. This setting isn't exposed in the Smallstep console. Use the [Device Enrollment Policy API](https://gateway.smallstep.com/v2026-05-01/operations/PutDeviceEnrollmentPolicy) with an [API token](https://smallstep.com/app/?next=/settings/api/tokens/add) that has the `get-device-enrollment-policy` and `put-device-enrollment-policy` scopes. The `PUT` replaces the whole policy, so fetch the current policy first and resubmit it with `Fleet` added to `autoApproveSources`:
594
+
595
+
```bash
596
+
set +o history
597
+
echo"Authorization: Bearer [your API token]"> api_headers
0 commit comments