---
# source: src/content/solutions/en/igel/igel-onboarding-service.md
# route:  /en/solutions/igel/igel-onboarding-service/
title: Onboarding Service
tags: [modern-workplace, automation, managed-services]
vendors: [igel]
summary: A device finds its own management server on first boot. Nobody has to configure it, and nobody has to be in the same building as it.
photoNeed: "An IGEL endpoint in place: a UD Pocket in a laptop, or a thin client at a working desk"
stub: false
draft: false
kind: product
addon: false
sourceNote: soultec.ch/solutions/igel, read 2026-08-30
vendorName: IGEL Onboarding Service
status: current
practice: >
  Draft, not yet reviewed. This is the piece that decides whether a remote rollout is a courier job or a project. We test it with one device on a home connection before ordering the batch, because the failure modes are all network and none of them show up in the lab.
practiceReview: true
---

## What it is

On first boot a device contacts the Onboarding Service and is told which UMS or cloud
environment it belongs to. The person in front of it signs in with their company
credentials, and that registration is what assigns the device to its configuration,
policies and group.

Everything else follows automatically: policies, network configuration, certificates,
software packages.

## What it is for

Shipping hardware to people instead of to a staging bench. A device can go straight from
the distributor to a home office and arrive managed, which is the difference between a
remote rollout and a lot of driving.

It is equally the answer for a site with no IT staff, which is most branch offices.

## What to watch

The device has to reach the service before it is anything at all, so the failure modes are
network ones: captive portals in hotels, a home router with an unusual DNS, a firewall rule
nobody remembers writing. None of those appear on a test bench with a wired connection.
