Testing Device Trust

Learn how to test Device Trust by setting up a blocking Check, failing it, and fixing the issue.

Note

1Password Device Trust was previously named Kolide. You may still see Kolide in some labels, commands, and integrations.

You can test Device Trust by setting up a blocking Check that your device fails, then fixing the issue using Device Trust’s self-service remediation instructions.

Prerequisites

Before you can test Device Trust, follow the steps to connect Device Trust to Okta, Google Workspace, or Entra.

Step 1: Install the Kolide agent and register your device

You’ll be prompted to install the Kolide agent and register your device when you first access an app protected by Device Trust.

  1. Sign in as a user who belongs to the Device Trust Enabled test group you created when you set up Device Trust with your identity provider.
  2. Open an app protected by Device Trust. You’ll be prompted to download the Kolide agent.
  3. Download the installer for your operating system and follow the on-screen instructions. Your device will be automatically registered.

Note

You can use an MDM to pre-install the Kolide agent on your team members’ devices.

Step 2: Set up a blocking check

By default, Device Trust enables a set of Checks that promote universally accepted best practices for device security. These Checks are set to report-only mode until you decide to change their remediation strategy to Notify, Warn then Block, or Block Immediately.

To test the blocking experience, set a Check your device is currently failing to “block immediately”. Then, authenticate to a protected application. Before you’re allowed in, you’ll be required to fix that blocking issue.

If your device isn’t currently failing any Checks, select a Check and read the provided fix instructions, then set up your device to fail them.

We recommend choosing a Check that’s straightforward to fix, like File Extensions Are Not Visible in Finder.

  1. Sign in to Device Trust.
  2. Select Devices.
  3. Select your device to open your device overview page. You’ll see a list of Checks your device is failing on the right side of the page.
  4. Select Details on the Check you want to test.
  5. Select Actions > Edit Check Settings.
  6. In the Remediation Strategy section, select Configure.
  7. Select Block Immediately, then select Save.

Step 3: Fail the check

In a new private browser window, attempt to sign in to an app protected by Device Trust.

Device Trust will notify you that your device is blocked and provide you with instructions for how to fix your device.

If your device doesn’t fail the Check, make sure your device is set up to fail the Check’s self-remediation instructions, then select Recheck device to run the Check again.

Note

By default, Device Trust gives users the option to snooze a Check for 8 hours, at most once a week. You can turn off snoozing.

Step 4: Fix the issue and recheck your device

  1. Select Fix this issue to see instructions for fixing the issue with your device.
  2. Follow the instructions to fix your device, then select Recheck device.

If you successfully fixed the issue, Device Trust will verify that your device is in good shape and redirect you to the app.

Step 5: Change the check’s remediation strategy

After you’ve tested a blocking Check, you can remove the blocking remediation strategy.

  1. In Device Trust, open the Checks tab.
  2. Open the Check you set up to block.
  3. Select Actions > Edit Check Settings and change the Check to Do Nothing or another remediation strategy.

Next steps

After you’ve tested a blocking Check, you can repeat the above process for other remediation strategies, like Warn then Block or Notify Only.

You can then explore other Checks functionality, including:

When you’re ready to roll out Device Trust to more people, add anyone you want to include in testing to your Device Trust-enabled group.



Published: