website/docs/endpoint-devices/authentik-agent/agent-deployment/automated.mdx
authentik Agent can be deployed at scale to multiple devices via Mobile Device Management (MDM) and automation tools.
You must configure your authentik deployment to support the authentik Agent.
If you have already created have an enrollment token, skip to the next section.
This SyncML snippet can be used by Microsoft Intune, Microsoft Endpoint Manager and other MDM tools to deploy the changes required to support the authentik Agent.
The following two registry keys (REG_SZ) are added by the configuration snippet:
HKLM/SOFTWARE/authentik Security Inc./Platform/ManagedConfig/RegistrationTokenHKLM/SOFTWARE/authentik Security Inc./Platform/ManagedConfig/URLThis policy can be used by Apple Business Manager, Fleet, and other MDM tools to deploy the changes required to support the authentik Agent.
:::warning MDM only Apple requires that this policy be applied to a device via an MDM tool. It will not function if manually applied to a device. :::
Upon deploying the authentik Agent to a device, the user will receive a notification asking them to register with authentik. When a user follows the registration they are asked to authenticate with authentik, once authenticated the device is enrolled in authentik and associated with the user.