# Hardware-backed device identity for Fleet

Fleet delivers real-time visibility and orchestration across diverse device fleets. Smallstep adds hardware-backed device identity to enforce trust for developer workflows, AI-enabled tools, and MCP-based automation.

Easy device revocation

Automated cert lifecycle

Eliminate credential theft

Enhanced Visibility & Compliance

Cross-OS Device Attestation

Open & Extensible Architecture

## Even the best MDMs alone aren't enough

When Smallstep is added to Fleet, a device's hardware identity becomes an authentication factor. Instead of relying solely on shared secrets and user credentials, Smallstep silently verifies device trust —blocking unauthorized machines without adding friction for users.

Together Smallstep and Fleet can:

- Support hardware device attestation
- Support ACME device attestation
- Support conditional access
- Support device inventory
- Check if a device is real or a cloned VM

## Fleet seamlessly integrates with Smallstep

## Zero-touch device configuration

Smallstep automatically pushes secure configuration profiles and credentials for Wi-Fi, VPN, and SaaS apps to all verified devices. Your IT team enjoys streamlined, error-free enrollments, freeing them from tedious manual processes while ensuring robust, reliable security across your entire device fleet.

## Hands-free certificate management

Say goodbye to manual certificate renewals and revocation headaches. Smallstep proactively monitors certificate lifecycles—automatically renewing credentials before expiration and immediately revoking access for offboarded or compromised devices. Reduce administrative overhead, eliminate manual errors, and keep device security always up-to-date.

## Get the data sheet

When Smallstep is added to Fleet, a device's hardware identity becomes an authentication factor. Instead of relying solely on shared secrets and user credentials, Smallstep silently verifies device trust, blocking unauthorized machines without adding friction for users.

[Download](https://7748242.fs1.hubspotusercontent-na1.net/hubfs/7748242/1-pagers/Fleet%20%2B%20Smallstep.pdf)

## Strengthen your Fleet inventory

Passwords and posture checks alone can’t guarantee that devices in your Fleet device inventory are trusted. Hardware-backed keys and attestation dramatically raise the bar against attackers. Learn how hardware-backed device identity can add cryptographic device proof to your MDM posture.

## FAQs Smallstep + Fleet

### What is the Smallstep + FleetDM integration?

### What problem does this integration solve?

### How does FleetDM work with Smallstep?

### What types of devices are supported?

### What certificates does Smallstep issue through FleetDM?

### How is this different from certificate enrollment via SCEP?

### Does this replace FleetDM or Smallstep?

### Can this integration be used for Zero Trust access?

### What happens when a device is decommissioned?

### Who is this integration best for?
