Manage desktop device management configuration

Reset secret keys, edit delegated SCEP URL configurations, or delete configurations and certificate authorities you no longer need.

If you've enabled the Early Access feature Single Certificate for Device Registration, Okta Device Access, and Management Attestation, the Endpoint management tab referenced in the following procedures is named Certificate configuration instead.

Before you begin

Before you edit or delete a configuration, update any app sign-in policies that may be associated with it. Deleting or changing a configuration may prevent users from accessing apps that are managed by an associated app sign-in policy.

If you've enabled the Early Access feature Single Certificate for Device Registration, Okta Device Access, and Management Attestation, remove the certificate authority from the trusted list on the Management Attestation or Device Registration tab and save before you delete it.

Reset a secret key

If you've enabled the Early Access feature Single Certificate for Device Registration, Okta Device Access, and Management Attestation, use the Management attestation tab instead of Endpoint management in the following steps.

  1. In the Admin Console, go to Security > Device integrations.

  2. Click the Endpoint management tab.
  3. Locate the platform configuration for which you want to reset the secret key.
  4. Click the Actions drop-down menu and choose Reset secret key.
  5. Click Reset.

Edit a delegated SCEP URL configuration

  1. In the Admin Console, go to Security > Device integrations.

  2. Click the Endpoint management tab.
  3. Locate the platform configuration you want to edit.
  4. Click the Actions drop-down and choose Edit.
  5. Make your edits.
  6. Click Save.

Delete a device management configuration

Before you delete a configuration, update any app sign-in policies that are associated with it. Deleting a configuration may prevent users from accessing apps that are managed by an associated app sign-in policy.

  1. In the Admin Console, go to Security > Device integrations.

  2. Click the Endpoint management tab.
  3. Locate the platform configuration you want to delete.
  4. Click the Actions drop-down menu and choose Delete.
  5. At the message about first updating associated access policies, click Delete.

View or delete a customer-provided certificate authority

Before you delete a certificate authority, update any app sign-in policies that are associated with it. Deleting a certificate authority may prevent users from accessing applications that are managed by an associated app sign-in policy.

  1. In the Admin Console, go to Security > Device integrations.

  2. Click the Certificate authority tab.
  3. Locate the customer-provided certificate authority you're interested in:
    • To view details about the certificate, click the info icon in the Actions column for the certificate you want to view.
    • To delete your certificate authority:
      1. Click the X in the Actions column for the certificate authority you want to delete.
      2. At the message about first updating associated access policies, click Delete.