Team: Huntress Managed Endpoint Detection and Response (EDR)
Product: Huntress Platform
Summary: Deleting an organization in the Huntress platform automatically revokes its organization key, preventing older deployment mechanisms from recreating the organization and causing unexpected billing.
In this Article
Before Deleting an Organization
What Happens After Deletion
Weekly Summary Escalations
Troubleshooting a Blocked Registration
Frequently Asked Questions
Revocation is Account-specific. Organization Key revocation applies only to the Huntress Account that owned the deleted Organization. The same key value can still be used successfully by a different Huntress Account. An organization key is not globally blocked across the Huntress platform.
Overview
When you delete an organization in the Huntress platform and if you opt-in to key revocation, Huntress revokes (invalidates) the organization key associated with that organization.
After the key is revoked, new Huntress Agent registrations that use the deleted organization key with the same Huntress account are blocked. This prevents older deployment mechanisms from recreating the deleted organization and helps prevent unexpected endpoint billing after a customer is offboarded.
Before Deleting an Organization
Before deleting an organization, find and remove or update any deployment automation that still references the organization key. Common locations include:
Group Policy Objects (GPOs), startup scripts, logon scripts, and scheduled tasks
RMM policies, monitors, components, and installation scripts
PowerShell or batch deployment scripts
VDI or golden-image build processes
Shadow-copy or backup-based deployment workflows
PSA or other third-party automation
API or infrastructure-as-code workflows
If the client is being moved to another organization or Huntress account, update the deployment to use the destination organization’s current key instead of continuing to use the deleted organization’s key.
Deleting an organization is permanent and can affect the Huntress Agents and other services associated with it. For general deletion guidance, see Add, Rename or Delete Organizations.
What Happens After Deletion
The deletion confirmation explains that the organization key will also be revoked if the revoke organizations key checkbox is selected (screenshot below). After deletion with checkbox selected:
The deleted organization key is recorded as revoked for the original Huntress account.
New Huntress Agent registrations using that account and organization key are blocked.
Huntress does not recreate the deleted organization when a registration attempt is blocked.
Registration attempts against the revoked organization key can be shown in the Account Settings experience.
When blocked attempts occur, partner admins receive a weekly summary Escalation showing the deleted organization, affected hostnames, and the number of attempts from each hostname.
Weekly Summary Escalations
When an endpoint attempts to register with a revoked organization key, Huntress creates a weekly summary Escalation for the affected Huntress account.
The weekly summary Escalation:
Appears with the account’s other Escalations and follows the same notification behavior as other Escalations.
Uses email as the default notification.
Includes the deleted organization, the endpoints that attempted to register, and the number of blocked attempts for each endpoint.
Creates one Escalation per revoked organization key. If one account has blocked registration attempts against three different revoked organization keys during the same week, three separate Escalations are created. Each Escalation contains only the endpoints and attempt counts associated with its specific revoked organization key.
Is created only when at least one blocked Huntress Agent registration attempt occurred during the prior week. If there are no attempts, no empty summary Escalation is created.
Automatically resolves at the beginning of the following week, on Monday. This does not necessarily mean the underlying deployment issue has been fixed. If blocked attempts continue, a new weekly summary Escalation is created for the next week.
This Escalation type is fully supported through the Huntress REST API.
You can silence Escalation notifications globally for the account or for an individual revoked organization key. Silencing an Escalation does not unblock the organization key or stop the deployment from attempting registration, so you must still remove or update the old automation.
Troubleshooting a Blocked Registration
If a Huntress Agent will not register after an organization was deleted or moved, complete the following checks:
1. Verify the keys being used
Confirm the following values:
The account key
The organization key used by the installer or deployment automation
The Huntress account and organization where the Huntress Agent is expected to appear
The organization name is a display value. The organization key is the value used during Huntress Agent registration, so confirm it in the actual installer, script, RMM policy, image, or other deployment mechanism. For more information about keys, see Using Account Keys, Organization Keys, and Agent Tags.
2. Check for stale deployment automation
Search the affected environment for the deleted organization key. Pay particular attention to GPOs, scheduled tasks, RMM policies, PowerShell or batch files, VDI images, backup or shadow-copy workflows, and API-based provisioning.
If the endpoint should remain protected, update the deployment to use the correct current account and organization keys. Do not continue retrying the deleted organization key.
3. Review blocked registration activity
Use the revoked-key information in Account Settings, when available, to compare the affected hostnames with the endpoints still receiving the old deployment. The weekly summary Escalation can also help identify where the stale automation is running.
These entries are generally offboarding or deployment cleanup signals. They do not, by themselves, indicate malicious activity.
4. Review Revoked Organization Keys
Log into your Huntress portal and review your currently revoked org keys by going into your "hamburger menu" (top right) > Settings > scroll down to "Revoked Organization Keys".
Frequently Asked Questions
Can I manually recreate the deleted organization with the same key?
Not while that organization key is actively revoked in the same Huntress account. Use the correct current key for a new organization, or remove the revocation. Read "Can I unrevoke the key myself" below.
Example message when attempting to create an org whose key is already revoked:
Does revocation affect another Huntress account that uses the same key value?
No. Revocation is scoped to the account that owned the deleted organization. Another Huntress account can use the same key value.
Does revocation uninstall existing Huntress Agents?
Revocation is a registration control. It blocks new registration attempts that use the revoked account and organization key; it is not an automatic uninstall action for already enrolled Huntress Agents.
Can I unrevoke the key myself?
Yes, log into your Huntress portal and in your "hamburger menu" at the top right > Settings > scroll down to "Revoked Organization Keys".
Is this the same as rotating an account key?
No. This feature is specific to the organization key associated with a deleted organization. Account key rotation is a broader and more disruptive action and is not the normal solution for this scenario.