Description

SRX series devices that are enrolled in the Sky ATP service can be disenrolled for reasons such as troubleshooting purposes, entitlement transfer to a new device, etc.  This article explains how to perform disenrollment when the device is directly enrolled in the ATP cloud.   

Solution

An SRX device can be disenrolled by logging into the ATP cloud portal (Devices > All Devices) and generating a "Disenroll" op script that can be run on the SRX device in operation mode.   Click the disenroll button and copy the appropriate command line. 



Running this command on the SRX device will commit the removal of relevant configuration and delete any associated certificates (device certificiate, trusted root).   

NOTE: Device network access to the ATP cloud service is required in order to use the op script to disenroll.   
NOTE: When a new op script is generated for a realm it becomes the active script and any previous enroll or disenroll scripts are no longer usable.

If it is not possible to access the device (replacement scenario), you can still manually remove the old device from the ATP cloud by logging into the ATP cloud portal and navigating to Devices > All Devices.  Find the "X" above the "License Expires" column. Select a device to delete and click the "X" to remove it from the device list.