Unregistering a Device from Cloud Secure Edge (CSE) Client

Description

Access decisions in Cloud Secure Edge (CSE) depend on accurately identifying who the user is and which device they are using. CSE integrates with your existing Identity Provider (IdP) and device management platforms so that user identity and device posture remain authoritative in their source systems.

During this process, CSE evaluates device trust using Certificate‑based authentication, device trust verification, integrations with device managers such as Intune, Jamf Pro, Kandji, JumpCloud, and Workspace ONE UEM.

However, if a user attempts to log in with a different method or email than the one used during initial registration or if the certificate is missing or incorrectly deployed, authentication errors may occur.

 NOTE: Do NOT Delete Users from the CSE Console. Doing so may trigger additional errors, as it revokes the certificates previously registered with that account.

To confirm if the CSE certificate was installed on Windows:

Managed Certificates - Trusted Root Certification Authorities - Certificates - Locate your CSE private certificate such as “CSEnamePrivateRootCA”

Resolution

How to Unregister a Device from the CSE Client?

Follow these steps when a device needs to be unregistered and re‑registered or when login/authentication issues occur or certificate errors. 

  • Verify User and Email in Your IdP
  • Ensure that:
    • The user exists in your Identity Provider (IdP)
    • The email address matches the one used during initial CSE registration
    • Any required roles or groups are correctly assigned
  • Unregister the Device in the CSE End Client. This action removes the local certificate and resets the device state.
    On the end device:
    • Open the CSE Client
    • Click the Settings gear icon
    • Select your Organization Name
    • Click Unregister Device
    • Click Continue
  • After unregistering, confirm that the CSE Private Root CA certificate was deleted from the device on managed certificates. If it remains present, remove it manually to avoid conflicts during re‑registration.
  • Clear Browser Cache: Clear the browser cache to remove any residual session data that may interfere with authentication or certificate deployment.
  • Re‑register the Device
    • Open the CSE Client
    • Click Register
    • Enter the Invite Code. You can find the invite code in:
        CSE Console → Settings → SonicWall CSE Client

If the Issue Persists:

Please, open a technical CSE support ticket and include:

  • User details (email, IdP)
  • Device OS and version
  • Type of connector (Firewall, Windows, Linux)
  • Debug logs from the affected device

You can revisit debug log analysis for help interpreting the logs.

How to Collect Banyan Debug Logs: https://www.sonicwall.com/support/knowledge-base/how-to-collect-banyan-debug-logs/kA1VN0000000RwL0AU

 

 

Related Articles

  • SonicWall Cloud Secure Edge (CSE) Licensing & Expiration Mega FAQ
    Read More
  • CSE - Legacy Configuration Notice message due to PoP Limit.
    Read More
  • IP Whitelisting Scenarios for SaaS Applications
    Read More
not finding your answers?