Skip to content

Commit

Permalink
[v16] Add auto-enroll troubleshooting to docs (#47698)
Browse files Browse the repository at this point in the history
* Add auto-enroll troubleshooting to docs

* Call out auto-enroll audit log version

* Update docs with correct Teleport version
  • Loading branch information
codingllama authored Oct 23, 2024
1 parent c85f5ae commit dd5fe30
Showing 1 changed file with 22 additions and 0 deletions.
22 changes: 22 additions & 0 deletions docs/pages/includes/device-trust/troubleshooting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,28 @@ for a different solution, we recommend creating udev rules similar to the ones
shipped by the [TPM2 Software Stack](
https://github.com/tpm2-software/tpm2-tss/blob/ede63dd1ac1f0a46029d457304edcac2162bfab8/dist/tpm-udev.rules#L4).

### Auto enrollment not working

Auto-enrollment ceremonies, due to their automated nature, are stricter than
regular enrollment. Additional auto-enrollment checks include:

1. Verifying device profile data, such as data originated from Jamf, against the
actual device
2. Verifying that the device is not enrolled by another user (auto-enroll cannot
take devices that are already enrolled)

Check you audit log for clues: look for failed "Device Enroll Token Created"
events and see the "message" field in the details (auto-enroll audit log details
available since Teleport v16.4.6).

If you suspect (1) is the issue, compare the actual device against its inventory
definition (`tsh device collect` executed in the actual device vs `tctl get
device/<asset_tag>`). Tweaking the device profile, manual enrollment or waiting
for the next MDM sync may solve the issue.

If you suspect (2), you can unenroll the device using `tctl edit
device/<asset_tag>` and changing the "enroll_status" field to "not_enrolled".

### App access and "access to this app requires a trusted device"

Follow the instructions in the [Web UI troubleshooting section](
Expand Down

0 comments on commit dd5fe30

Please sign in to comment.