# Prevent unauthorized devices from connecting to project

**URL:** <https://discuss.blues.com/t/prevent-unauthorized-devices-from-connecting-to-project/1569>\
**Category:** Uncategorized\
**Tags:** security\
**Created:** [August 21, 2023, 4:58pm UTC](https://discuss.blues.com/t/prevent-unauthorized-devices-from-connecting-to-project/1569 "2023-08-21T16:58:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rdimartino](https://avatars.discourse-cdn.com/v4/letter/r/df788c/32.png) [@rdimartino](https://discuss.blues.com/u/rdimartino)\
**Post date:** [August 21, 2023, 4:58pm UTC](https://discuss.blues.com/t/prevent-unauthorized-devices-from-connecting-to-project/1569/1 "2023-08-21T16:58:07Z")

</div>

We had a small surprise when a device we didn’t expect was suddenly showing up in our list of devices on [notehub.io](http://notehub.io). It turned out to be innocuous from a reusing of a code sample that contained the product UID, but it did raise a discussion internally.

Is there a way to prevent a malicious actor who has the product UID from adding devices to our project?

---

<div class="post-metadata">

**Author:** ![RobLauer](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.blues.com/roblauer/32/1567_2.png) [@RobLauer](https://discuss.blues.com/u/RobLauer)\
**Post date:** [August 21, 2023, 8:52pm UTC](https://discuss.blues.com/t/prevent-unauthorized-devices-from-connecting-to-project/1569/2 "2023-08-21T20:52:23Z")

</div>

Hi @rdimartino and welcome to the Blues community!

In short, no, there isn’t a way to prevent someone from using a known ProductUID with their own Notecard. However, you can disable the device through Notehub and contact our support team should this happen.

Of course, for this reason we recommend that ProductUIDs be kept private (e.g. not stored in public source control etc).

Also, while this doesn’t help with the above scenario, you can reserve a specific prefix for your ProductUID if you are interested (head to the **Billing → Prefixes** section. This does make sure that other Notehub accounts can’t use the same prefix.

Rob

---

<div class="post-metadata">

**Author:** ![RobLauer](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.blues.com/roblauer/32/1567_2.png) [@RobLauer](https://discuss.blues.com/u/RobLauer)\
**Post date:** [August 22, 2023, 3:22pm UTC](https://discuss.blues.com/t/prevent-unauthorized-devices-from-connecting-to-project/1569/3 "2023-08-22T15:22:04Z")

</div>

Hi @rdimartino,

I wanted to post a quick follow up after discussing this with a colleague in more detail. For production deployment scenarios, a best practice is to edit your ProductUID and **set a default fleet** to which all new devices are assigned. Also, you can enable “temporarily block incoming connections” which still assigns a device to a fleet, but prevents the new devices from adding any events to the project (note that the text provided here is incorrect, but will be corrected):

 ![image](https://us1.discourse-cdn.com/flex020/uploads/blues/original/1X/1208de5a2367dc7f62dbbcba612b47853c943c0b.png)

And this is the result of a new device connecting, allowing you to triage/approve it by moving it to a proper fleet and enabling connectivity on the device:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/blues/original/1X/a1106ede49984a6c03f2cea32bf8adf145667a35.png)

Hope this helps!  
Rob
