Authorize a device
Bind a new endpoint to your user and organization.
Interactive browser authorization is the standard enrollment flow.
Authorize#
- Start login: run
pulsectl loginon Linux, or choose Continue in Browser in the macOS PulseHA app. - Open the displayed browser page.
- Sign in through the organization’s configured authentication method.
- Enter or confirm the device code and approve the endpoint.
- Return to Network → Devices and wait for the device to leave Pending.
The device is associated with the approving user. Required SSO applies to the browser session.
Troubleshooting#
Expired codes must be restarted from the agent. A Blocked or Archived device must be restored by an authorized operator. Revocation is irreversible; enroll the endpoint again.
Enrollment tokens and workload identity are API-managed options, not Console-generated replacements for this flow.