You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/iot-dps/how-to-manage-enrollments.md
+6-1Lines changed: 6 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -216,10 +216,15 @@ To remove an enrollment entry:
216
216
217
217
4. In the **Settings** menu, select **Manage enrollments**.
218
218
219
-
5. Select the enrollment entry you want to remove.
219
+
5. Select the enrollment entry you want to remove.
220
220
221
221
6. At the top of the page, select **Delete**.
222
222
223
223
7. When prompted to confirm, select **Yes**.
224
224
225
225
8. Once the action is completed, you'll see that your entry has been removed from the list of device enrollments.
226
+
227
+
> [!NOTE]
228
+
> Deleting an enrollment group doesn't delete the registration records for devices in the group. DPS uses the registration records to determine whether the maximum number of registrations has been reached for the DPS instance. Orphaned registration records still count against this quota. For the current maximum number of registrations supported for a DPS instance, see [Quotas and limits](about-iot-dps.md#quotas-and-limits).
229
+
>
230
+
>You may want to delete the registration records for the enrollment group before deleting the enrollment group itself. You can see and manage the registration records for an enrollment group manually on the **Registration Records** tab for the group in Azure portal. You can retrieve and manage the registration records programmatically using the [Device Registration State REST APIs](/rest/api/iot-dps/service/device-registration-state) or equivalent APIs in the [DPS service SDKs](libraries-sdks.md), or using the [az iot dps enrollment-group registration Azure CLI commands](/cli/azure/iot/dps/enrollment-group/registration).
Copy file name to clipboardExpand all lines: articles/iot-dps/how-to-revoke-device-access-portal.md
+5Lines changed: 5 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -78,6 +78,11 @@ After you finish the procedure, you should see your entry removed from the list
78
78
> [!NOTE]
79
79
> If you delete an enrollment group for a certificate, devices that have the certificate in their certificate chain might still be able to enroll if an enabled enrollment group for the root certificate or another intermediate certificate higher up in their certificate chain exists.
80
80
81
+
> [!NOTE]
82
+
> Deleting an enrollment group doesn't delete the registration records for devices in the group. DPS uses the registration records to determine whether the maximum number of registrations has been reached for the DPS instance. Orphaned registration records still count against this quota. For the current maximum number of registrations supported for a DPS instance, see [Quotas and limits](about-iot-dps.md#quotas-and-limits).
83
+
>
84
+
>You may want to delete the registration records for the enrollment group before deleting the enrollment group itself. You can see and manage the registration records for an enrollment group manually on the **Registration Records** tab for the group in Azure portal. You can retrieve and manage the registration records programmatically using the [Device Registration State REST APIs](/rest/api/iot-dps/service/device-registration-state) or equivalent APIs in the [DPS service SDKs](libraries-sdks.md), or using the [az iot dps enrollment-group registration Azure CLI commands](/cli/azure/iot/dps/enrollment-group/registration).
85
+
81
86
## Disallow specific devices in an enrollment group
82
87
83
88
Devices that implement the X.509 attestation mechanism use the device's certificate chain and private key to authenticate. When a device connects and authenticates with Device Provisioning Service, the service first looks for an individual enrollment with a registration ID that matches the common name (CN) of the device (end-entity) certificate. The service then searches enrollment groups to determine whether the device can be provisioned. If the service finds a disabled individual enrollment for the device, it prevents the device from connecting. The service prevents the connection even if an enabled enrollment group for an intermediate or root CA in the device's certificate chain exists.
Copy file name to clipboardExpand all lines: articles/iot-dps/how-to-unprovision-devices.md
+11-5Lines changed: 11 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -43,12 +43,13 @@ With X.509 attestation, devices can also be provisioned through an enrollment gr
43
43
44
44
To see a list of devices that have been provisioned through an enrollment group, you can view the enrollment group's details. This is an easy way to understand which IoT hub each device has been provisioned to. To view the device list:
45
45
46
-
1. Log in to the Azure portal and click **All resources** on the left-hand menu.
47
-
2. Click your provisioning service in the list of resources.
48
-
3. In your provisioning service, click **Manage enrollments**, then select **Enrollment Groups** tab.
49
-
4. Click the enrollment group to open it.
46
+
1. Log in to the Azure portal and select **All resources** on the left-hand menu.
47
+
2. Select your provisioning service in the list of resources.
48
+
3. In your provisioning service, select **Manage enrollments**, then select the **Enrollment Groups** tab.
49
+
4. Select the enrollment group to open it.
50
+
5. Select the **Registration Records** tab to view the registration records for the enrollment group.
50
51
51
-

52
+

52
53
53
54
With enrollment groups, there are two scenarios to consider:
54
55
@@ -57,6 +58,11 @@ With enrollment groups, there are two scenarios to consider:
57
58
2. Use the list of provisioned devices for that enrollment group to disable or delete each device from the identity registry of its respective IoT hub.
58
59
3. After disabling or deleting all devices from their respective IoT hubs, you can optionally delete the enrollment group. Be aware, though, that, if you delete the enrollment group and there is an enabled enrollment group for a signing certificate higher up in the certificate chain of one or more of the devices, those devices can re-enroll.
59
60
61
+
> [!NOTE]
62
+
> Deleting an enrollment group doesn't delete the registration records for devices in the group. DPS uses the registration records to determine whether the maximum number of registrations has been reached for the DPS instance. Orphaned registration records still count against this quota. For the current maximum number of registrations supported for a DPS instance, see [Quotas and limits](about-iot-dps.md#quotas-and-limits).
63
+
>
64
+
>You may want to delete the registration records for the enrollment group before deleting the enrollment group itself. You can see and manage the registration records for an enrollment group manually on the **Registration Records** tab for the group in Azure portal. You can retrieve and manage the registration records programmatically using the [Device Registration State REST APIs](/rest/api/iot-dps/service/device-registration-state) or equivalent APIs in the [DPS service SDKs](libraries-sdks.md), or using the [az iot dps enrollment-group registration Azure CLI commands](/cli/azure/iot/dps/enrollment-group/registration).
65
+
60
66
- To deprovision a single device from an enrollment group:
61
67
1. Create a disabled individual enrollment for the device.
0 commit comments