Skip to content
All guidesGetting started

Enroll a phone or tablet (Cybermatic Device Trust)

Each mobile device gets its own one-time enrollment, delivered by QR code or email, through the Cybermatic Device Trust app.

  1. 1Before you begin. Mobile enrollment works differently from the device agent. A device-agent token can enroll an entire fleet; a mobile enrollment is one-time and binds to the first device that uses it. That means one enrollment per phone or tablet, and each is revocable on its own. You need: a workspace administrator account, and the person's phone in hand or their email address.
  2. 2Step 1 — Create the enrollment. 1. Open Settings → Agents → Mobile. 2. Optionally fill in owner name, employee email, department, ownership (corporate-owned or BYOD), and criticality. These are optional and simply pre-label the asset so it arrives already identified rather than needing tidying later. 3. Select Create enrollment. You get a QR code and a link, valid for one device — it stays usable until it's used or revoked. 4. If you entered an employee email, you can have the invitation sent directly to them.
  3. 3Step 2 — On the phone or tablet. Install the Cybermatic Device Trust app from the App Store or Google Play. Open it and either scan the QR code from the dashboard or tap the emailed link. The device enrolls itself and sends its first report. BYOD note worth telling employees plainly: the app reports device security posture — things like OS version, whether the device is encrypted, whether a passcode is set, and whether it has been jailbroken or rooted. It does not read messages, photos, location, or browsing.
  4. 4Step 3 — Verify. The device appears under Assets within a minute, labelled with whatever identity fields you supplied. Posture problems — an out-of-date OS, no passcode, a jailbroken device — appear as findings tied to that device, and close automatically once fixed. In Settings → Agents → Mobile, each enrollment shows its state: invited, enrolled, or revoked.
  5. 5Troubleshooting. The QR code or link does not work — enrollments are single-use and bind to the first device that uses them. If it shows already enrolled, or the invitation was revoked, create a fresh one. Wrong person enrolled it — revoke that enrollment in Settings → Agents → Mobile and issue a new one. Revoking stops the device reporting. Replacing someone's phone — create a new enrollment for the new device and revoke the old one; they are independent.

Tip: Fill in owner and department when you create the enrollment. It takes seconds and saves identifying the device later, when nobody remembers whose it was.

More in Getting started