What does revoking a service key actually stop?
Revoking a key blocks future installs that would have used it. Machines already enrolled with that key carry on working.
Revoking a service key stops it being used to enrol anything new. Any machine already enrolled with that key keeps working exactly as before.
The behaviour surprises people, because it is the opposite of what revoking a credential usually implies. Revoking a key is not a way to cut off machines.
The reason is worth holding onto. The key is how a machine joins, not how it stays connected.
How it works
A service key exists so the same installer can be pushed to many machines without generating a code for each.
Once a machine has enrolled, it has its own identity in the fleet and no longer needs the key.
Revoking the key therefore closes the door to new arrivals and does nothing to anybody already inside.
Cutting off a machine that is already enrolled is a different action: removing that connector from the fleet.
Good to know
A revoked key cannot be un-revoked. Generate a new one if you still need to deploy.
Because a service key is durable and reusable, treat it like any other deployment secret. That is also why revoking it matters when it has been somewhere it should not have been.
What to do next
To stop new machines enrolling with a key, revoke it on the fleet page and generate a fresh one when you next deploy.
To stop a specific machine that is already enrolled, remove that connector instead.
To do both, revoke the key and remove each connector you want disconnected. Neither implies the other.
FAQ
Q: Does revoking disconnect machines that used the key?
A: No. They carry on working.
Q: How do I disconnect a machine?
A: Remove its connector from the fleet.
Q: Can a revoked key be restored?
A: No. Generate a new one.
Q: Who can revoke one?
A: A global or master administrator.
Related pages
Remove a connector covers taking a connector out properly, which revoking a key does not do on its own.