Skip to content

Commit 46f6ea2

Browse files
committed
Updates based on Hunter's feedback
1 parent 6f5f20e commit 46f6ea2

File tree

1 file changed

+19
-13
lines changed

1 file changed

+19
-13
lines changed

platform/enrollment-guide.mdx

Lines changed: 19 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ description: There are several ways to add your devices to Smallstep. In this gu
66

77
In this guide,
88
we'll talk about different approaches you can take
9-
as you build yout device inventory in Smallstep.
9+
as you build your device inventory in Smallstep.
1010

1111
It's worth restating the overall goal of this process:
1212
To build a high-assurance device inventory,
@@ -32,9 +32,8 @@ and they will be able to self-enroll devices
3232
using the [Smallstep Desktop App](./smallstep-app.mdx)
3333
or the [Smallstep Agent for Linux](./smallstep-agent.mdx).
3434

35-
As the administrator,
36-
by default,
37-
you must approve each new device
35+
By default, administrators
36+
must approve a new device
3837
before it can access any of your resources.
3938
You can change this in [Team Settings](https://smallstep.com/app/?next=/settings/team).
4039

@@ -49,9 +48,8 @@ via single sign-on,
4948
using the [Smallstep Desktop App](./smallstep-app.mdx)
5049
or the [Smallstep Agent for Linux](./smallstep-agent.mdx).
5150

52-
As the administrator,
53-
by default,
54-
you must approve each new device
51+
By default, administrators
52+
must approve a new device
5553
before it can access any of your resources.
5654
You can change this in [Team Settings](https://smallstep.com/app/?next=/settings/team).
5755

@@ -62,8 +60,10 @@ Once an MDM is synced,
6260
you can deploy the Smallstep Agent to your endpoints
6361
to enable high-assurance protections.
6462

65-
Devices synced from an MDM inventory do not require manual approval.
66-
But, they will not be marked as high-assurance until Smallstep receives an attestation from the device.
63+
Devices synced from an MDM inventory
64+
are automatically approved,
65+
but they will not be marked as high-assurance
66+
until Smallstep receives an attestation from the device.
6767

6868
For a concrete example,
6969
see [Connect Jamf Pro to Smallstep](../tutorials/connect-jamf-pro-to-smallstep.mdx)
@@ -73,8 +73,9 @@ see [Connect Jamf Pro to Smallstep](../tutorials/connect-jamf-pro-to-smallstep.m
7373

7474
You can import devices from any source into Smallstep using our API.
7575

76-
Devices added via API do not require manual approval.
77-
But, they will not be marked as high-assurance until Smallstep receives an attestation from the device.
76+
Devices added via API are automatically approved.
77+
but they will not be marked as high-assurance
78+
until Smallstep receives an attestation from the device.
7879

7980
#### Example: I have a list of device identifiers
8081

@@ -83,10 +84,15 @@ For each device, use the [Save Collection Instance](https://gateway.smallstep.co
8384
- For Apple devices, the `instanceID` must be the device's serial number.
8485
- For TPM 2.0 devices, the `instanceID` must be the TPM Endorsement Key URI, in the format `urn:ek:sha256:ul3sYf6uQ6jVEXAMPLEXoAuHI10U8gTvEJ6bMj95LXI=`. (You can retrieve the EK URI by running `step agent tpm --fingerprint` on the device.)
8586

86-
For the body of the request, use the following value, replacing `[email protected]` with the device owner's email address:
87+
For the body of the request,
88+
create a user using the following value
89+
(replacing `[email protected]` with the device owner's email address):
8790

8891
```
8992
{ "data": { "smallstep:identity": "[email protected]" } }
9093
```
9194

92-
Once added, you'll see the device in your Smallstep dashboard, under Recent Devices, and it will be automatically approved.
95+
Once added,
96+
you'll see the device in your Smallstep dashboard,
97+
under Recent Devices,
98+
and it will be automatically approved.

0 commit comments

Comments
 (0)