When we make you authenticate
TridentStack Control asks you to verify your identity before actions that can affect many endpoints, change account security, or run scripts. The check helps protect your organization if someone gains access to an active session.
What is the check?
You can verify with a passkey, security key, or authenticator code. After you pass the check, TridentStack Control will not ask again for five minutes while you keep working.
Actions on your endpoints
TridentStack Control asks you to verify before you:
- Install updates on many endpoints at once.
- Reboot endpoints in bulk, start a reboot sequence, or release its next wave.
- Approve a deployment ring's next phase, resume a ring, or un-halt it.
- Deploy a policy object.
- Remove endpoints in bulk.
- Deploy software or remediate vulnerabilities.
- Finish feature upgrades in bulk.
- Choose a reboot option when remediating or installing on one endpoint.
Custom packages
TridentStack Control asks you to verify before you finish uploading a custom package, add a version, edit or archive a version, or edit or delete a package.
Scripts
TridentStack Control always asks you to verify before you write, publish, run, cancel, or automate a script, attach a script to an Endpoint Check, or edit an Endpoint Check that has a script attached. Your verification must be within the last five minutes.
Account security
TridentStack Control asks you to verify before you manage API keys, users and invitations, roles, sign-in settings, or verified domains. It also asks before you add or remove an MFA method, reset a user's MFA, manage clients, or close or restore your account.
What does not ask for a check?
You can reboot a single endpoint, install updates on a single endpoint without choosing a reboot option, approve updates in a policy, change a deployment ring's settings, and view information without another check.
API keys
API keys cannot complete an identity check. A key marked as privileged can install updates, reboot, remove endpoints, or finish feature upgrades in bulk, approve, resume, or un-halt deployment rings, and deploy policy objects through the API. Other keys are refused for these actions.
Software deployment, vulnerability remediation, reboot sequences, scripts, and account security are never available to API keys. Learn how to manage API keys.
First time setup
If you have not set up a second factor, TridentStack Control will ask you to set one up before continuing.