Skip to main content

When we make you authenticate

TridentStack Control asks you to verify your identity before actions that can affect many endpoints, change account security, or run scripts. The check helps protect your organization if someone gains access to an active session.

What is the check?​

You can verify with a passkey, security key, or authenticator code. After you pass the check, TridentStack Control will not ask again for five minutes while you keep working.

Actions on your endpoints​

TridentStack Control asks you to verify before you:

  • Install updates on many endpoints at once.
  • Reboot endpoints in bulk, start a reboot sequence, or release its next wave.
  • Approve a deployment ring's next phase, resume a ring, or un-halt it.
  • Deploy a policy object.
  • Remove endpoints in bulk.
  • Deploy software or remediate vulnerabilities.
  • Finish feature upgrades in bulk.
  • Choose a reboot option when remediating or installing on one endpoint.

Custom packages​

TridentStack Control asks you to verify before you finish uploading a custom package, add a version, edit or archive a version, or edit or delete a package.

Scripts​

TridentStack Control always asks you to verify before you write, publish, run, cancel, or automate a script, attach a script to an Endpoint Check, or edit an Endpoint Check that has a script attached. Your verification must be within the last five minutes.

Account security​

TridentStack Control asks you to verify before you manage API keys, users and invitations, roles, sign-in settings, or verified domains. It also asks before you add or remove an MFA method, reset a user's MFA, manage clients, or close or restore your account.

Sensitive tags​

If you can edit settings, you can mark or unmark a tag as sensitive from its page. TridentStack Control asks you to verify your identity when you do this. You must be signed in; API keys cannot change a tag's sensitive status.

When a tag is sensitive, TridentStack Control asks you to verify before manual actions that can reach its endpoints. This includes rebooting endpoints, installing updates, deploying software, running scripts, removing endpoints, and changing endpoint settings. It also includes adding or removing endpoints, changing the tag's name or automation rules, and changing what is attached to the tag. Edits to attached policies, configurations, application settings, and Endpoint Checks also ask for verification.

Some organization-wide changes that can reach every endpoint also ask when your organization has a sensitive tag. Examples include changing pilot rollout settings, unblocking an update, adding a custom package version, deleting a relay, or changing automatic app installation settings for users.

The prompt names the sensitive tag the action reaches. Refreshing updates or inventory, scanning for vulnerabilities, collecting logs, and evaluating compliance or Endpoint Checks do not ask. Scheduled work, including deployment rings, maintenance windows, and automations, runs as normal.

What does not ask for a check?​

You can reboot a single endpoint, install updates on a single endpoint without choosing a reboot option, approve updates in a policy, change a deployment ring's settings, and view information without another check, unless the action reaches a sensitive tag.

API keys​

API keys cannot complete an identity check. A key marked as privileged can install updates, reboot, remove endpoints, or finish feature upgrades in bulk, approve, resume, or un-halt deployment rings, and deploy policy objects through the API. Other keys are refused for these actions.

Software deployment, vulnerability remediation, reboot sequences, scripts, and account security are never available to API keys. Learn how to manage API keys.

For actions that reach a sensitive tag, a standard API key is refused with a message naming the tag. A privileged API key can perform the action, and TridentStack Control records each use in the audit log.

First time setup​

If you have not set up a second factor, TridentStack Control will ask you to set one up before continuing.