Everbridge 360™ Device-Token Registration on Windows

2026-10-01 02:06:43 UTC

Device-token registration

Note: Device-token registration is available in Everbridge 360 app version 26.9.0 and later. It is supported for Windows deployments that use the MSI package.

Device-token registration allows an organization to sign users in to the Everbridge 360 app automatically. Users do not need to enter an Everbridge password or complete an interactive single sign-on (SSO) flow.

The app combines an organization device token with an identifier that resolves to each contact.

 

Before you begin

Confirm the following before deploying device-token registration:

  • Your organization has an Organization Code and is licensed for Everbridge 360 Desktop.

  • Each user has an active contact in the organization.

  • You have the Windows MSI package for the Everbridge 360 app and administrator access to your deployment tool.

  • Any user who will test the flow is signed out of the Everbridge 360 app. Automatic sign-in runs only when the app does not already have an account.

Treat a device token like a password. Store it securely, distribute it only through an approved device-management tool, and do not include it in email, support cases, screenshots, or deployment logs.

 

Create a device token

An Organization Administrator creates and manages device tokens in Everbridge Suite.

  1. Sign in to Everbridge Suite and select the required organization.

  1. Go to Settings > Organization > Everbridge Mobile App, then open Device Tokens.

  1. Select Create Device Token.

  1. Enter a descriptive name that identifies the deployment, such as `Windows Corporate Devices`.

  1. Select an expiration date that meets your organization's security policy.

  1. Create the token.

  1. Copy the token immediately and save it in an approved secret-management system. The full token is displayed only when it is created and cannot be retrieved later.

1.png
2.png

Note: If a token is lost, create a replacement. Do not use screenshots or unsecured documents to retain the token.

 

Deploy and manage device-token registration

Use the MSI properties below to configure a new deployment. The MSI creates the Everbridge360 app-configuration values and stores the device token in Windows Credential Manager. To change an existing deployment, see Update the App Configuration. If you use the MSI property USERNAME_REGKEY, see Prepare a registry-sourced identifier (if applicable).

Deploy the MSI

Deploy from an elevated PowerShell session, or configure the same properties in your device-management tool. For registry-source setup, see Prepare a registry-sourced identifier.

Scenario Command
Use the Windows UPN
msiexec /package "C:\Path\To\Everbridge360.msi" /quiet /norestart ORG_CODE="MyOrgCode" DEVICE_TOKEN="PASTE_GENERATED_TOKEN_HERE" USERNAME_SOURCE="upn"
Machine’s username already matches Contact’s username
msiexec /package "C:\Path\To\Everbridge360.msi" /quiet /norestart ORG_CODE="MyOrgCode" DEVICE_TOKEN="PASTE_GENERATED_TOKEN_HERE"
Use a registry value for the Contact’s username
msiexec /package "C:\Path\To\Everbridge360.msi" /quiet /norestart ORG_CODE="MyOrgCode" DEVICE_TOKEN="PASTE_GENERATED_TOKEN_HERE" USERNAME_SOURCE="registry" USERNAME_REGKEY="HKEY_LOCAL_MACHINE\Software\Company\Identity\EverbridgeUsername"
MSI Property Required Description Example
ORG_CODE Yes
The Organization Code for the Everbridge organization.
MyOrgCode
DEVICE_TOKEN Yes
The complete device token copied from Everbridge Suite. See Create a device token.
PASTE_GENERATED_TOKEN_HERE
USERNAME_REGKEY For registry source
The full path of a registry value containing the identifier to match. Required when USERNAME_SOURCE=registry. See Prepare a registry-sourced identifier.
HKEY_LOCAL_MACHINE\Software\Company\Identity\EverbridgeUsername
USERNAME_SOURCE
No
Selects the identifier the Everbridge 360 app uses to find the Contact: username, upn, or registry. If omitted, a configured USERNAME_REGKEY selects registry; otherwise, the machine username is used. See Choose the username source.
upn
USERNAME_MATCH_FIELD
No
Selects the Contact field used to match the identifier from the configured source. Omit it to match the Contact username. See Match the identifier to a Contact field.
ssoIdentity
RESET_USERNAME_MATCHING
Reset only
Set to 1 only to clear the persisted username source, registry path, and username match field during an install, repair, or upgrade. It takes precedence over supplied USERNAME_* properties.
1

Note: ORG_CODE and DEVICE_TOKEN must be supplied together. Supplying only one does not enable device-token registration.

During an install, repair, or upgrade, supplying a USERNAME_SOURCE, USERNAME_REGKEY, or USERNAME_MATCH_FIELD property updates only that persisted setting. Omitting a property preserves its existing value. Use RESET_USERNAME_MATCHING=1 to clear all username-matching settings and return to the default behavior.

The examples show all properties on one line. You can use PowerShell line continuation when needed; enter the properties on one line when required by Microsoft Intune or another deployment tool.

Do not configure the legacy username and password automatic-login values at the same time. If both a username/password configuration and a device-token configuration are present, username/password automatic login takes precedence.

Update the App Configuration

Use the following locations to view or change the app-configuration values. Registry editing can change only the values listed below; it cannot add or replace the device token, which is stored in Windows Credential Manager. For an initial configuration or token rotation, use Deploy the MSI.

Computer\HKEY_CURRENT_USER\SOFTWARE\Everbridge360
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Everbridge360

Note: The MSI creates HKEY_LOCAL_MACHINE\SOFTWARE\Everbridge360 when it writes app-configuration values. To configure values manually, create the appropriate HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE path before adding values from this table.

3.png
Registry Value Required Description Example
enableDeviceToken Yes
A true or false value indicating whether device-token registration is enabled. The MSI sets this value to true when DEVICE_TOKEN is supplied.
true
orgCode Yes
The Organization Code for the Everbridge organization. The MSI populates this value from ORG_CODE.
EverbridgeOrgA
usernameRegKey No
The full path to a separate registry value containing the identifier to match. Required when userNameSource is registry. The MSI populates this value from USERNAME_REGKEY.
HKEY_LOCAL_MACHINE\Software\Company\Identity\EverbridgeUsername
userNameSource No Selects the identifier source: username, upn, or registry. The MSI populates this value from USERNAME_SOURCE. See Choose the username source. upn
usernameMatchField No Selects the Contact field used to match the identifier from the configured source. Omit it to match the Contact username. The MSI populates this value from USERNAME_MATCH_FIELD. See Match the identifier to a Contact field. ssoIdentity

Note: Setting enableDeviceToken to true does not itself supply a device token. The MSI writes these settings to HKEY_LOCAL_MACHINE\SOFTWARE\Everbridge360. When configured manually, a matching value in HKEY_CURRENT_USER\SOFTWARE\Everbridge360 takes precedence for that value.

Choose the username source

The Everbridge 360 app must resolve an identifier for the current user before it can sign the user in. The identifier can be a Windows username, a Windows User Principal Name (UPN), or a value supplied through the Windows registry.
In this section:

  • Machine’s username means the username of the account currently signed in to the desktop.

  • Contact’s username means the username stored in the contact’s record within Everbridge Suite.

  • UPN means the Windows User Principal Name for the signed-in user, which commonly has the format user@company.com.

Choose the source that provides the identifier used to find the Contact.

Choose this Use it when
What to configure
username
The current Windows account name is the identifier.
No additional configuration is required.
upn
The current Windows User Principal Name is the identifier.
Set USERNAME_SOURCE=upn. The signed-in Windows account must have an available UPN.
registry
The identifier is stored in a registry value.
Set USERNAME_SOURCE=registry and USERNAME_REGKEY. The path must include the registry hive, key path, and value name. Example: HKEY_LOCAL_MACHINE\Software\Company\Identity\EverbridgeUsername

To configure the selected source during installation, see Deploy the MSI for command-line and device-management examples.

If you do not set USERNAME_SOURCE, the Everbridge 360 app uses registry when USERNAME_REGKEY is set; otherwise, it uses username. If a registry key is already configured but you want to use the Windows username, set USERNAME_SOURCE=username.

Match the identifier to a Contact field (optional)

Set USERNAME_MATCH_FIELD only when the identifier from the selected source is stored in a Contact field other than the Contact username. The configured field must contain that identifier for every deployed user and identify exactly one Contact.

Set USERNAME_MATCH_FIELD to Use it when Example
Leave unset (default) The identifier from the selected source matches the Contact username. USERNAME_SOURCE=upn, and the Contact username is the user’s UPN.
externalId The identifier matches the Contact external ID. A registry value contains the Contact external ID.
ssoIdentity The identifier matches the Contact SSO identity. USERNAME_SOURCE=upn, and ssoIdentity stores that UPN.
An Additional Information property name The identifier is stored in a unique Additional Information property in Manager Portal. Set the property name that contains the identifier.

Prepare a registry-sourced identifier (if applicable)

Complete this section only when you use a registry-based username source. With USERNAME_SOURCE=username or USERNAME_SOURCE=upn, the Everbridge 360 app resolves the identifier directly from Windows. For a registry-based source, create a separate registry value for each user that contains the identifier used to match that Contact. USERNAME_REGKEY (MSI) and usernameRegKey (Registry Editor) store the path to that registry value, not the identifier itself.

Note: For an MSI deployment, supply that value’s full path through the USERNAME_REGKEY installer property. See Deploy the MSI. The MSI writes the path to usernameRegKey.

Note: Use Registry Editor only when you need to manually add or update the username-matching configuration. For those steps, see Update the App Configuration.

The full path must include:

  • The registry hive

  • The registry key path

  • The registry value name

For example:

HKEY_LOCAL_MACHINE\Software\Company\Identity\EverbridgeUsername

In this example:

  • For an MSI deployment, set USERNAME_REGKEY to HKEY_LOCAL_MACHINE\Software\Company\Identity\EverbridgeUsername. The MSI writes this path to usernameRegKey.

  • Set the data in the referenced registry value to the Contact username when USERNAME_MATCH_FIELD is not configured. When it is configured, set the value to the value in that Contact field instead.

Note: The MSI writes the supplied path to usernameRegKey. It does not create the referenced registry value or set its data. Use your device-management process to create the registry value and populate it with the correct identifier for each managed user. To set usernameRegKey manually, see Update the App Configuration.

The referenced registry value:

  • Must be a string value of type REG_SZ.

  • Must contain the identifier expected by the configured username match field. If no username match field is configured, it must contain the Contact username.

Supported registry hives are:

  • HKEY_CURRENT_USER or HKCU

  • HKEY_LOCAL_MACHINE or HKLM

 

What the user experiences

When a user without an existing app account starts the Everbridge 360 app:

  1. The app uses the configured Organization Code.

  1. The app resolves the configured identifier and signs the user in without requesting a password.

  1. The Everbridge 360 app Home page opens.

Device-token registration also follows this flow for organizations that normally use SSO; the user is not redirected to the organization's identity provider.

Rotate or revoke a device token

Rotate tokens before they expire and whenever a token may have been exposed.

  1. Create a new device token in Everbridge Suite.

  1. Redeploy or repair the MSI with the same ORG_CODE and the new DEVICE_TOKEN.

  1. Verify automatic sign-in on a pilot device.

  1. Complete the deployment to the remaining managed devices.

  1. Delete the previous token from the Device Tokens page.

Deleting or expiring a device token prevents it from being used for future automatic sign-ins. It does not automatically sign out users who are already signed in.

When rotating only a token, you can omit USERNAME_SOURCE, USERNAME_REGKEY, and USERNAME_MATCH_FIELD; their existing persisted values are preserved.

Uninstalling the MSI removes the device-token registration data, including the persisted username-matching settings, from that Machine’s computer. It does not delete the organization token from Everbridge Suite.

Troubleshooting

Symptom What to check
Automatic sign-in does not start.
Confirm the user is signed out and that both ORG_CODE and DEVICE_TOKEN were included in the MSI deployment. Confirm that the configured identifier can be resolved. Remove any legacy automatic-login username and password values.
Username-source settings are not configured correctly.
Confirm that USERNAME_SOURCE is username, upn, or registry. For registry, confirm that USERNAME_REGKEY is a valid HKCU or HKLM registry path. For upn, confirm that the signed-in Windows account has an available UPN.
Automatic Login Failure: The username or device token is invalid.
Confirm that the resolved identifier exactly matches an active Contact in the same organization. If USERNAME_MATCH_FIELD is configured, confirm that it is externalId, ssoIdentity, or an Additional Information property in Manager Portal whose value is unique to one Contact, and that the identifier is stored in that field for the Contact. Confirm that the token belongs to that organization and has not expired or been deleted. Create and deploy a replacement token if necessary.
Organization Code does not exist.
Confirm that ORG_CODE exactly matches the Organization Code configured in Everbridge Suite.
The wrong username appears.
Correct the value referenced by USERNAME_REGKEY, or remove USERNAME_REGKEY if the Machine’s username is the correct Contact’s username.
The deployment works for some users but not others.
Compare each affected user’s resolved identifier with the configured username match field and confirm that their Contact’s account is active.
A replacement token is not being used.
Redeploy or repair the MSI with the same ORG_CODE and the complete new DEVICE_TOKEN, then sign out of the Everbridge 360 app before testing again.

Related articles

 

Was this article helpful?
0 out of 0 found this helpful