Your tenant's device registration codes are used when installing the ControlUp for Desktops Agent or Agent Manager to enroll a new device. This article describes how to create and manage your registration codes.
New codes are generated using a stronger and more secure algorithm. If your tenant was created after July 21, 2026, you already have a new code by default and don't need to switch codes. If your tenant was created on or before July 21, 2026, you're still using a legacy code and need to switch.
To improve your security, all legacy codes will automatically expire on August 31, 2026. Before that date, you must create a new code and update your deployment resources to use it. If you don't create a new code, you won't be able to register new devices to ControlUp.
You can confirm which type of code you have by checking its length: new codes are 64 characters, legacy codes are 40 characters.
Current devices stay registered
Changing your registration codes does not affect devices that are already registered in your tenant. Registration codes are used only when a device first registers with your tenant.
Updates required when you create a new code
When you create a new code, you must update all your deployment resources to use the new code. Your old code remains active until it expires or you delete it, giving you time to implement these changes:
Replace any old Device Registration Codes with the new one in all your deployment resources as listed below.
Check whether you deploy the Agent through the Agent Manager or direct Agent installation. If you aren’t sure which method you use, read below to learn more.
If you use the Agent Manager, replace any Agent Manager installation files with the latest version that supports the new codes (2.17.8.394 for Windows and 2.18.2.3268 for macOS). Download the latest version from the Downloads page.
If you use direct Agent installation, you don’t need to update your Agent version. The current Agent versions already support the new codes.
Make sure you update your code and Agent Manager files (if used) in every applicable area such as:
Installation scripts
Deployment commands
Golden images
Virtual machine templates
MDM profiles (for example Intune for Windows and Jamf for macOS)
Thin client configurations
ChromeOS extension settings (See ChromeOS Deployment for details.)
How to create a new code
Permission required
To create and delete codes, you must have the Manage device registration code permission located under Device Permissions > Configuration > Agent Registration. This permission is included in the default Admin role. Viewing the Agent Registration page to see your existing codes requires the permission Show Agent Download Page.
Go to Devices > Configuration > Agent Registration.
You see all Device Registration Codes created for this tenant..png)
Click Create new.
Optionally enter a Description for the new Device Registration Code, for example a code you are using for testing.
Select whether you want to designate an Expires after duration or Never expires. If you select Expires after, you must select a Duration.
After you create the new code, it appears in the table.Update each of your deployment resources listed above with the new code.
After you have fully implemented the new code, Delete your old code. Note: deleting a code can’t be undone.
Best practice: You should not keep multiple codes active for a long period of time. You should fully switch to the new code as soon as possible and then delete the old code when you are finished.
Note: The installation commands on the Downloads page are prepopulated with your tenant name and registration code. They are automatically updated to include your most recently created code.
How to switch existing devices to the new code
Re-registering your devices to switch to the new code is not required. Currently enrolled devices continue to work even after you generate a new code.
If you need to delete and re-register a device, make sure you perform the following steps to re-register the device using your new code:
Uninstall the Agent and the Agent Manager (if used). You can use our uninstall scripts for Windows and macOS.
If you use the Agent Manager (available for Windows and macOS), download the latest version from the Downloads page. Only the latest versions support the new stronger codes.
Reinstall the Agent Manager or Agent using the new code. Note that for macOS, you must first unmount any existing installers before you install the new Agent Manager.
Understanding Agent Manager vs. direct Agent installation
Windows and macOS:
Windows and macOS support both deployment options (Agent Manager and direct Agent installation).
When you deploy the Agent Manager, it automatically installs the Agent and keeps the Agent updated according to your version control settings. The Agent Manager file is agentmanagersetup.msi for Windows or ControlUp Agent Manager.dmg for macOS. If you use ControlUp’s built-in version control, it means you have the Agent Manager installed. This is the most common deployment method for Windows and macOS.
Some customers choose not to use the Agent Manager and instead deploy the Agent directly and control versioning using separate deployment software. If you use this method, you install the Agent directly using a sipagentx.xx.x.xxxx.msi or ControlUp Agent vx.xx.x.xxxx.dmg file.
All other operating systems:
Direct Agent installation is the only available deployment option.