November 2025 Summaries
10 posts from Kolide
Filter
Month:
Year:
Post Summaries
Back to Blog
Kolide has introduced new features for its Device Trust customers, including Mobile Checks and self-remediation capabilities in its updated Mobile App version 8. These features allow users to ensure their mobile devices meet security standards by verifying enrollment in an organization's Mobile Device Management (MDM) system and checking for issues such as outdated software or lack of passcode protection. The app enables end-users to self-remediate issues directly from their devices, enhancing security by allowing only compliant devices to authenticate. Additionally, administrators can customize remediation instructions with markdown support, ensuring users can easily follow steps to resolve issues. The new MDM Enrollment Verification feature ensures that only devices enrolled in the specified MDM can register and authenticate, with options to block non-compliant devices from future authentications. These updates aim to provide greater flexibility and control, strengthening the security of mobile devices within organizations.
Nov 17, 2025
736 words in the original blog post.
Kolide has introduced an impact preview feature within their Check configuration interface to provide users with critical insights before enabling remediation strategies, such as “Warn then Block.” This tool addresses common customer concerns by displaying how many devices are in various remediation stages, from pre-warning to currently blocked, as well as the potential impact of proposed changes. The interface, updated in real-time, allows users to view and search through devices affected by these changes, ensuring that important devices, such as those belonging to company executives, are not inadvertently blocked. The new feature also ensures the "Don't Block Until..." settings are consistently available, offering users more control and confidence when adjusting their remediation strategies.
Nov 17, 2025
585 words in the original blog post.
1Password and Kolide have announced a collaboration to introduce 1Password Extended Access Management (XAM), a novel approach to identity and access management aimed at addressing the limitations of traditional IAM systems. XAM seeks to bridge the "Access Trust Gap" by providing a flexible, human-centric solution that accommodates the modern hybrid work environment, where employees use diverse applications and devices outside the typical IT visibility. This new system includes unmanaged SaaS app management, insights into Shadow IT, and an expanded concept of Device Trust, allowing IT teams to support employee productivity while maintaining security. Kolide's Device Trust product serves as a central pillar in this initiative, and the solution is set to expand its integration with major identity providers like Google Workspace and Microsoft Entra. The collaboration emphasizes the importance of marrying human motivation with security needs to foster a safer digital world.
Nov 17, 2025
1,539 words in the original blog post.
Kolide has introduced a new feature to enhance device management by preventing the automatic re-enrollment of devices when they are removed from the system. Previously, devices would immediately re-enroll if the Kolide agent was still installed, leading to management challenges. The traditional solution involved using a Device Tombstone, which administrators had to manage manually. The new update allows for a more streamlined process; once a device is removed, a signal is sent to the agent to wipe its local database, remove it from the operating system's auto-start list, and stop its current process, effectively preventing re-enrollment without extensive manual intervention. This improvement is part of Kolide's ongoing investment in developing its agent, showcasing a practical feature aimed at simplifying administrative tasks.
Nov 17, 2025
239 words in the original blog post.
Kolide has introduced new checks designed to seamlessly integrate with 1Password, enhancing security and user experience by ensuring proper usage of 1Password in work environments and facilitating the encryption of SSH keys. The "Require 1Password be Logged into Work Account" check ensures that users have a modern version of 1Password installed, linked to their work account, and running in their browser, with support across various operating systems and major browsers. This check offers customizable instructions and end-user remediation to guide users effectively. Another check, "Require SSH Keys to be Encrypted," simplifies the encryption process by allowing users to import SSH keys directly into 1Password with a single click, utilizing its SSH agent for automatic credential management. Together, these checks demonstrate how Kolide and 1Password can create a more integrated and secure environment through Extended Access Management, with plans for further enhancements in the future.
Nov 17, 2025
701 words in the original blog post.
Kolide has introduced updates to its Device Registration process to accommodate users who do not require Kolide as a possession-based factor for authentication. Traditionally, Kolide's registration required users to prove they were in possession of a previously trusted device, which could be cumbersome, especially if the user wasn't near such a device. To streamline this, the new Device Trust Level setting allows administrators to set the trust level to "None," enabling device registration with just successful authentication via an SSO provider, without needing additional device verification. This change simplifies the registration process, eliminating unnecessary steps like clicking a button to complete registration, thus improving user experience. While this adjustment aids in faster registration, it necessitates additional possession-based factors to protect applications. These updates aim to enhance the rollout process for customers using Kolide alongside Yubikeys and other authentication methods, ensuring app access is conditionally restricted until device issues are resolved.
Nov 17, 2025
470 words in the original blog post.
Kolide has enhanced its Zero Trust Access feature by automating the rechecking of browser updates after a restart, eliminating the need for users to manually initiate the check. This improvement is part of a broader strategy to ensure end-users maintain up-to-date web browsers by continuously monitoring update feeds for popular browsers like Firefox, Chrome, Brave, and Safari. If a device fails to have the latest update, administrators can alert users and potentially block access to sensitive applications until the browser is updated. This approach is preferred over centrally managing browsers, which can lead to data loss during automatic restarts. The update also leverages modern browsers’ ability to restore tabs post-restart and allows Kolide to maintain authentication details for a seamless user experience.
Nov 16, 2025
411 words in the original blog post.
Kolide has introduced several improvements to enhance the user experience for administrators handling Device Registration and Issue Exemption requests. Previously, administrators could approve requests without the option to record reasons for Device Registration approvals and had to retrieve Issue Exemption notes from the Audit Log. Now, administrators can add internal approval notes for both types of requests directly in the approval process, with these notes being clearly visible in the request summary and still accessible in the Audit Log. The registration_requests API has been updated to support the recording of these notes programmatically. Additionally, enhancements have been made to improve the speed and efficiency of loading closed requests, including better pagination and visual updates, to facilitate faster searching and browsing for administrators managing large volumes of requests.
Nov 16, 2025
315 words in the original blog post.
Kolide has introduced an admin settings feature called End-User Remediation to enhance the user experience by managing notifications related to Device Trust login checks. Initially, Kolide's system would repeatedly warn users about potentially blocking device checks during each sign-in, which was cumbersome for frequent logins. To address this, a change was made to automatically bypass these warnings within a 24-hour window, although it lacked customization options. The new feature allows administrators to adjust the default 12-hour period for skipping notifications and decide whether to enable this functionality. It also logs specific events when warnings are skipped, enhancing transparency in the authentication process. This update does not affect out-of-band notifications through the Kolide agent's menubar app, and aims to give administrators better control and confidence in managing the login and remediation flow.
Nov 16, 2025
305 words in the original blog post.
Kolide has enhanced its system to improve the user experience by reducing the delay in recognizing operating system updates after a device reboot, addressing a previous challenge where users were mistakenly informed that updates were not installed. This change aims to make security patch installations more seamless for users across macOS, Windows, and Linux, by promptly acknowledging updates within seconds after a restart, thus avoiding unnecessary rechecks. The updated system prioritizes re-running checks immediately, ensuring that users can authenticate smoothly into Kolide-protected apps without encountering misleading notifications. Additionally, Kolide has extended this immediate update recognition to critical applications like web browsers, acknowledging that a reboot often prompts the necessary updates for these applications. This improvement is expected to enhance user satisfaction by minimizing disruptions and making the update process as unobtrusive as possible.
Nov 16, 2025
488 words in the original blog post.