Restrictions

Learn how to restrict Device Trust features and agent data sources for administrators in your organization.

Note

1Password Device Trust was previously named Kolide. You may still see Kolide in some labels, commands, and integrations.

Restrictions allow Device Trust administrators to limit access to certain features or agent data sources within Device Trust.

Restricting features

There are two ways to restrict access to features in Device Trust.

Globally

When you restrict access to a feature, you disable it for every Device Trust administrator regardless of their access level. This means the feature will not be present in the UI and any background capabilities associated with that feature are disabled.

Note

Restricting access to a feature does not stop Device Trust from collecting data associated with that feature. For example, if you disable viewing the Auth Logs, Device Trust will still collect them.

To restrict a feature, follow these steps:

  1. In the Device Trust admin console, click your user avatar in the upper-right corner.
  2. Click Settings.
  3. Click Restrictions in the left sidebar menu.
  4. Tick the checkbox next to the feature(s) you wish to disable.
  5. Click Save (this action will be logged in the audit log).

For A specific user

Device Trust users with Limited Access can either be invited with specific feature restrictions or have features added/removed later.

To restrict a Device Trust admin’s access:

  1. In the Device Trust admin console, click your avatar in the upper-right corner.
  2. Click Settings.
  3. Click Users & Access in the left sidebar menu.
  4. Locate the user you want to restrict and click Edit.
  5. In the modal that opens, make sure the Restricted Access radio button is selected. This will reveal Feature Restrictions options.
  6. Tick the checkbox next to the feature(s) you wish to disable.
  7. Click Save to apply the changes.

Data source restrictions

In addition to disabling access to features, you can also control which osquery tables Device Trust administrators can query within the Live Query, Log Pipeline, and Custom Checks features.

You may not want your teammates to query certain tables because they may contain sensitive information or cause performance issues when queried recklessly (for example, shell_history).

Note

Adding a table to the blocklist DOES NOT impact any queries that already use those tables (including Device Trust’s official Checks); instead, it prevents users from writing any new queries (or updating existing ones) that use the blocklisted tables.

Device Trust global blocklist

Due to serious privacy or stability issues, Device Trust bans the usage of the following osquery tables:

Table NameReason
aslReturns 100k+ rows per device and is depreciated
carvesDevice Trust does not support file carving
dns_cacheLeaks sensitive user information
running_appsExposes in-focus app on macOS, which we consider a privacy overreach
exampleTable exposes no functionality
kolide_app_iconsIntended for Device Trust internal use only
kolide_program_iconsIntended for Device Trust internal use only
kolide_airport_utilExposes BSSID which can be used to pinpoint a person's exact location
kolide_wifi_networksExposes BSSID which can be used to pinpoint a person's exact location
kolide_nmcli_wifiExposes BSSID which can be used to pinpoint a person's exact location
windows_eventlogCauses osquery to hang on Windows when queried

Device Trust suggested blocklist

In addition to the globally blocklisted tables, Device Trust seeds your organization’s Device Trust account with the following suggestions. Unlike the global blocklist, any administrator can remove these restrictions if desired.

Table NameReason
shell_historyOften contains clear-text credentials from engineers using CLI API tools
process_envsWhen run on servers, they can often contain secrets.
quicklook_cacheLeaks user sensitive information
curlCan be used to obtain information from a privileged/internal network

Manage the blocklist

To manage the osquery table blocklist, follow these steps:

  1. In the Device Trust admin console, click your avatar in the upper-right corner.
  2. Click Settings.
  3. Click Restrictions in the left sidebar menu.
  4. Click Add/Remove Tables.

Adding tables

To add a table, click Add Table at the bottom of the modal. In the text field that appears, type the name of the table you wish to add to the blocklist, then click Save.

Removing tables

To remove a table, click the red X next to the table you wish to remove and then click Save.



Published: