Skip to main content

Unexpected Devices in Your Level Account

Why attachment scanning can enroll an unexpected device, what access is possible, and how to remove it or rotate your install key.

Introduction

An unknown device in your Level account is usually low risk. It does not give the device or its operator access to your Level account, your existing endpoints, or the Level API.

The access works in the opposite direction: after a device enrolls, your Level account has root or system-level management access to that device.

ℹ️ NOTE: An unknown device does not mean your other devices or your Level account were compromised. Remove the device if you do not recognize it, and ask Level support to rotate your install key if you believe the key was exposed.


Why an unknown device can appear

A common cause is automated attachment scanning. Email and collaboration services such as email providers, Microsoft Teams, Slack, and similar tools may execute MSI or EXE attachments inside a security sandbox to analyze them.

If a Level installer contains your install key and the scanning service runs it, the sandbox can enroll as a device in your Level account. You may then see a temporary or unfamiliar device in your device list even though nobody intentionally installed Level on a production endpoint.

An install key has a narrow purpose. It can enroll new devices into your Level account, but it cannot:

  • Sign in to your Level account

  • Access devices already in your account

  • Authenticate to the Level API

  • Give an enrolled device access to your other endpoints

Because your account receives management access to the newly enrolled device, rather than the device receiving access to your account, the security risk is limited.


Remove an unknown device

If you do not recognize a device, delete it from Level:

  1. Open the Device Listing.

  2. Find the unknown device.

  3. Click the ··· menu at the right end of the device row.

  4. Select Delete.

Deleting the device removes its record from your account. Level also sends the uninstall command to the agent when the device is online.

See Uninstall Level for more detail.


Rotate a compromised install key

If you believe your install key was shared or exposed, contact [email protected]. Level support can rotate the key so the old key can no longer enroll new devices.

Rotating the key does not affect devices that are already installed. It only prevents new enrollments that use the old key.

See Windows Install for more information about what an install key can and cannot do.


FAQ

  • Can an unknown device access my other endpoints? No. Enrolling a device gives your Level account management access to that device. It does not give the device access to your account or to other endpoints.

  • Does an unknown device mean someone signed in to my Level account? No. An install key can enroll a device, but it cannot sign in to Level. Review your sessions separately if you have other evidence of an account compromise. See Securing Level.

  • Why did the device appear after I sent an installer through email, Teams, or Slack? The service may have executed the installer in a security sandbox while scanning the attachment. If the installer contained your install key, the sandbox could enroll in Level.

  • What should I do with the unknown device? Delete it from the Device Listing. If you believe the install key was exposed, contact Level support to rotate it.

  • Does rotating the install key disconnect existing devices? No. Rotation prevents new devices from enrolling with the old key and does not affect agents that are already installed.

Did this answer your question?