IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP

Documentation

Connect and enroll an MSP Client

MSP administrator and workstation user · Updated 9 October 2026

Follow the numbered steps, then check the result before continuing. Choose only the procedure that matches your task.

Before you begin

  • Have a running MSP Server using Standard or higher for device-bound enrollment. OFF does not support this enrollment flow.
  • Know the actual server URL and have the client’s customer workspace available. Use a separate existing administrator console to create the customer if necessary.
  • Keep the original Windows account and device throughout request creation and setup import.

1. Create the request on the client workstation

  1. Open Configuration → Settings & Credentials. Find Central MSP Server.
  2. Click 1. Create device request... and save the request file. The request is tied to a key on this workstation and Windows account. Do not create it on the server on behalf of the user.
  3. Send the request to the administrator through your agreed channel. Retain the displayed device-key fingerprint for independent comparison. Do not include unrelated evidence or passwords.
  4. Leave the original account available. Creating another device request creates another identity; wait for the administrator’s response to this request.
Check before continuingThe administrator has the request file, and both parties can independently compare the device-key fingerprint.

2. Approve that device on the server

  1. In MSP Server Administration → Guided security setup, click 5.2 Open device request... and select the file received from the client.
  2. At 5.3, compare the displayed fingerprint with the client through an independent channel. Stop if they differ.
  3. Click 5.4 Refresh customer list. Select the correct customer, then choose Assessor or Auditor. This enrollment path does not create unrestricted MSPAdmin access.
  4. For Standard or Enhanced, continue to approval. For High Assurance or DoD-Aligned, click 5.5a Export request for enterprise CA..., obtain the matching Client Authentication certificate from your CA, then click 5.5b Attach issued client certificate.... Do not use another client’s certificate.
  5. Click 5.6 Approve this device... and save the returned .itaf-setup file. Return it to the requesting user. The setup invitation expires after 30 minutes; coordinate the handoff before approval.
Check before continuingThe user receives one approved setup file for the intended customer and role. The client private key has not been sent to the server.

3. Import and verify on the original client

  1. On the same workstation and Windows account that created the request, return to Settings & Credentials → Central MSP Server. Click 3. Open approved setup... and choose the returned file.
  2. Review the server identity, tenant, customer and role shown during import. For Standard self-signed trust, independently compare the certificate fingerprint before approving trust. For managed CA deployments, install the verified issuer chain through the organization’s approved process.
  3. Complete the import. The setup credential is encrypted to the original device key, so copying the file to a different computer/account does not complete enrollment.
  4. Click 4. Verify Current Secure Connection. Read the connection stages and effective profile. A profile name without Verified is not a completed setup.
  5. Select the expected Active client and Active program at the top of the application. Confirm that the expected workspace appears before editing records.
Check before continuingThe connection is verified at the intended security level, and the user can access only the intended customer scope.

4. Use an existing manual connection

  1. Use this path only if your administrator intentionally issued a manual/legacy connection. Expand Advanced / Manual setup in Settings & Credentials → Central MSP Server.
  2. Enter the administrator-supplied Server URL, Tenant / MSP name and Server API key. For HTTPS, the URL hostname must match the server certificate; do not enter a PostgreSQL port or database password.
  3. If needed, use Import/Trust CA or Server Certificate... to import the independently verified public certificate. Configure mTLS separately under Security & Communications when the server requires it.
  4. Click Save Server Profile, then Test Server. Run Verify Current Secure Connection and inspect all stages. A legacy key does not become device-bound merely because it was saved manually.
Check before continuingThe manual connection passes its tests under the administrator’s intended policy. Each device requiring bound enrollment must use the separate request/approval process.

If something goes wrong

Setup invitation expired

Ask the administrator to issue a replacement through the enrollment workflow. Do not change the computer clock to bypass expiry.

The original key is unavailable

Use the original Windows account/device. If it was replaced or reinstalled, request new enrollment and revoke the obsolete record under Access & TLS.

Customer list is empty

Create the customer using the existing administrative MSP console, then select Refresh customer list in Server Administration.

TLS succeeds but API authentication fails

Check the intended role/customer, credential lifecycle and clock synchronization. Run troubleshooting; a TLS success alone does not validate the API credential.