PRIMARY / SECONDARY

Computer Sync & Managed Secondaries

Managed secondaries use a different trust model from ordinary website registration. A Primary approves the device and supplies managed enrollment.

A Business Secondary never uses a retail website registration code. In 0.19.105, changing a managed Secondary from Monitor-Only to Home, Pro, Business or Custom automatically reissues the signed profile-bound enrollment while the Primary remains the registration authority.

V0.19.105 installer behavior: Universal Setup validates the shared workspace, records the Secondary identity, and publishes the managed-control heartbeat without performing the first full backup restore inside the hidden installer process. The first bulk pull runs from the installed application after Setup completes, so a large workspace cannot falsely fail installation with a registration/workspace validation timeout.

Procedure

  1. Install Business as Secondary and connect it to the existing Primary workspace through Computer Sync.
  2. The first successful connection publishes the Secondary identity and the Primary automatically assigns Monitor-Only as the safe first managed profile.
  3. Change Assigned Edition from the Primary when needed. The Primary writes the new policy and matching signed enrollment together; no website activation code is entered on the Secondary.
  4. After Setup finishes, the installed application performs the first bulk pull as a normal Computer Sync operation; large workspace restores are no longer part of hidden installer validation.
  5. The Secondary control plane checks in independently of bulk data sync and applies the new profile automatically. A manual Primary data sync is not required just to complete the edition change.
  6. Computer Sync status, pull/run and recovery remain available to the managed Secondary even when its assigned customer profile does not include the optional retail Computer Sync feature.
  7. Retail registration becomes available only after the Primary explicitly releases/removes the computer or an authorized fresh reset clears the managed identity.