The agent will not enroll until it can prove which organization it belongs to. The enrollment key is that proof. The gateway then gives the machine its own device credential. The key is not a login for a technician, and it is not one code per device.
A key is shown once when you create it. Store it in the RMM job or a password manager. The agent reads it from MSPILOT_ENROLLMENT_KEY only.
There are two kinds:
- A client key joins machines to that one client. Create it on the client’s Deployment tab. The button says Create key when you have no global key, and Create client key when a global key already covers the client.
- A global key covers every client. Create it under Organization → General → Global enrollment key. Paste one script on an RMM policy that spans clients. Machines the RMM already knows land in the matching client. Machines the RMM does not know wait under Devices → Unassigned until you assign them. A global key cannot be created for a Standalone organization, because nothing there can pick the client.
Either key counts as the Deployment step being done, once the seat cap is set. You do not need both. Prefer the global key when one script should cover the fleet. Use a client key when you want a smaller blast radius, or when the organization is Standalone.
At the seat cap, the enroll does not fail the RMM job. The machine waits for approval instead of taking a seat it does not have. Last modified on September 24, 2026