Fortinet white logo
Fortinet white logo

FortiDLP Agent Deployment Guide

Generating FortiDLP Agent enrollment tokens

Generating FortiDLP Agent enrollment tokens

You must install and enroll the FortiDLP Agent on each device your organization wants to monitor. To get started, you will need to create an enrollment token.

When you create an enrollment token, you simultaneously create an enrollment code and enrollment bundle. The code and bundle contain configuration details for the deployment, which are required to authenticate the FortiDLP Agent on devices and enable communication with the FortiDLP Infrastructure. You can use the code or the bundle when you later complete enrollment, and the same code/bundle can be used to enroll the FortiDLP Agent on multiple devices.

To limit usage, an enrollment token can have a maximum number of uses and/or an expiry. If needed, you can update a token to extend the number of uses and expiry of the associated code/bundle. For details, see Extending FortiDLP Agent enrollment tokens. Alternatively, you can generate a token with an unlimited number of uses that never expires.

Caution

It is pertinent that you protect access to enrollment codes/bundles, as they can be used to gain unauthorized access to the system.

How to generate a FortiDLP Agent enrollment token
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Under Agents, select the Agent deployment tab.
  3. Click Create new token.
  4. In the Create a new enrollment token dialog box, do the following:
    1. In the Description field, type a description to identify the token in the Enrollment tokens table.
    2. Optionally, to assign labels to devices upon enrollment, in the Assign labels upon enrollment list, select one or more labels.
    3. Do one of the following:
      • To allow unlimited use of the token, leave the Unlimited uses toggle on.
      • To limit use of the token:
        1. Turn the Unlimited uses toggle off.
        2. In the Maximum number of uses menu, type or select the maximum number of devices that can be enrolled.
    4. Do one of the following:
      • To allow the token to be used indefinitely, leave the Never expire toggle on.
      • To set an expiry for the token:
        1. Turn the Never expire toggle off.
        2. In the Expiration date menu, select a date for the token's expiry.
    5. Click Create.
      The enrollment code and bundle are created.
  5. In the panel of the token, do one of the following:
    • To use the code, click Copy code.
    • To use the bundle, click Download bundle.

Generating FortiDLP Agent enrollment tokens

Generating FortiDLP Agent enrollment tokens

You must install and enroll the FortiDLP Agent on each device your organization wants to monitor. To get started, you will need to create an enrollment token.

When you create an enrollment token, you simultaneously create an enrollment code and enrollment bundle. The code and bundle contain configuration details for the deployment, which are required to authenticate the FortiDLP Agent on devices and enable communication with the FortiDLP Infrastructure. You can use the code or the bundle when you later complete enrollment, and the same code/bundle can be used to enroll the FortiDLP Agent on multiple devices.

To limit usage, an enrollment token can have a maximum number of uses and/or an expiry. If needed, you can update a token to extend the number of uses and expiry of the associated code/bundle. For details, see Extending FortiDLP Agent enrollment tokens. Alternatively, you can generate a token with an unlimited number of uses that never expires.

Caution

It is pertinent that you protect access to enrollment codes/bundles, as they can be used to gain unauthorized access to the system.

How to generate a FortiDLP Agent enrollment token
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Under Agents, select the Agent deployment tab.
  3. Click Create new token.
  4. In the Create a new enrollment token dialog box, do the following:
    1. In the Description field, type a description to identify the token in the Enrollment tokens table.
    2. Optionally, to assign labels to devices upon enrollment, in the Assign labels upon enrollment list, select one or more labels.
    3. Do one of the following:
      • To allow unlimited use of the token, leave the Unlimited uses toggle on.
      • To limit use of the token:
        1. Turn the Unlimited uses toggle off.
        2. In the Maximum number of uses menu, type or select the maximum number of devices that can be enrolled.
    4. Do one of the following:
      • To allow the token to be used indefinitely, leave the Never expire toggle on.
      • To set an expiry for the token:
        1. Turn the Never expire toggle off.
        2. In the Expiration date menu, select a date for the token's expiry.
    5. Click Create.
      The enrollment code and bundle are created.
  5. In the panel of the token, do one of the following:
    • To use the code, click Copy code.
    • To use the bundle, click Download bundle.