Executive summary — An IoT fleet is only as trustworthy as the identity of each device in it, and at a scale of millions, identity cannot be a manual step on a factory line. Treating devices as first-class machine identities is what separates a secure fleet from a botnet in waiting. This article covers provisioning at scale, just-in-time issuance, standards-based enrolment, and the revocation strategies that most deployments neglect. Connected devices now outnumber human users in most enterprises, and each one needs a way to prove what it is before it is trusted with data or commands. The temptation is to ship devices with a shared key or a hard-coded password, which is fast to manufacture and catastrophic to secure: one extracted secret compromises the entire fleet. Machine identity done properly gives every device a unique, verifiable credential from birth to decommissioning. Provisioning at Scale Starts in the Factory The strongest device identity is established during manufacturing, when a unique key pair is generated on the device and a birth certificate is issued and bound to it. This factory provisioning means the device arrives in the field already trustworthy, with a private key that never left the hardware. For fleets numbering in the millions, this has to be automated into the production line rather than performed by hand, which is why identity provisioning is increasingly a design requirement rather than an afterthought. Just-in-Time Provisioning for the Real World Not every device can be fully provisioned at the factory, and supply chains are messy. Just-in-time provisioning fills the gap: when a device first connects to the network, it presents an initial credential and is automatically enrolled for its operational identity, subject to policy. This lets an enterprise onboard devices it did not manufacture and reprovision devices that change ownership, without a technician touching each one. Automating provisioning across a large device fleet? eMudhra's machine identity solutions automate device provisioning, rotation and revocation across fleets of any size. Standards-Based Enrolment: EST and ACME Proprietary enrolment mechanisms age badly and lock an enterprise into a single vendor. Standards make fleets manageable over their long lifespans. The Enrollment over Secure Transport (EST) protocol suits constrained devices, while ACME, familiar from the world of automated web certificates, is increasingly used for device certificates too. The same automation mindset behind automated certificate renewal with ACME applies directly to devices: if renewal requires a human, it will eventually fail. Rotation and the Revocation Problem Long-lived device certificates are a liability, because a key that lives for the device's entire operational life is a key with years of exposure. Rotation, reissuing device certificates on a schedule, limits that exposure, provided it happens without bricking the device. Revocation is the part most deployments underestimate: when a device is compromised, stolen or retired, the fleet needs a reliable way to stop trusting it immediately. This means planning for scalable revocation checking from the outset, whether through short-lived certificates that simply expire or through efficient status protocols. Provision a unique identity per device, never a shared fleet secret. Rotate on a schedule so no credential lives for the device's entire lifespan. Plan revocation early, so a compromised device can be cut off in minutes, not weeks. Because IoT devices increasingly handle data that must remain confidential for years, fleet operators should also weigh how their chosen platform will support post-quantum cryptography as devices in the field outlive today's algorithms. Teams comparing platforms should weigh scale, standards support and revocation capability side by side. GIVE EVERY DEVICE AN IDENTITY YOU CAN TRUST eMudhra automates provisioning, rotation and revocation for IoT fleets of any size, on open standards. Explore eMudhra machine identity or talk to our IoT identity team. Tags: Machine & Agentic Identity Identity and Access Management About the Author eMudhra Limited eMudhra Editorial represents the collective voice of eMudhra, providing expert insights on the latest trends in digital security, cryptographic identities, and digital transformation. Our team of industry specialists curates and delivers thought-provoking content aimed at helping businesses navigate the evolving landscape of cybersecurity and trust services with confidence.