Skip to content

Automatically verify an attested device at self-enrollment #3758

Description

@kchudy

User story

As an admin, I want to choose to verify a device automatically when the user self-enrolls it and it passes attestation, so that I don't have to run manual verification for devices I already trust through the enrollment process.

Acceptance criteria

Test scenarios

  1. With the checkbox checked, the user enrolls a device with a supported TPM → it becomes Attested / Verified.
  2. With the checkbox unchecked, the same enrollment → the device is Attested / Not verified.
  3. With the checkbox checked, the user enrolls a device with no TPM → it is Not attested and not verified.
  4. With the checkbox checked, the user enrolls a device with an unrecognized TPM, then the admin accepts the TPM → the device is Attested manually and not verified.
  5. Open the device's details → the panel shows it was verified automatically at enrollment.
  6. Check the Activity log → the entry shows the automatic verification and the admin who created the token.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions