# Device Trust

1Password Device Trust is a Zero Trust security product that verifies device identity and health before granting access to organizational resources.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing AI-assisted query creation in 1Password Device Trust

DevFeed: [Introducing AI-assisted query creation in 1Password Device Trust](<https://devfeed.tech/articles/introducing-ai-assisted-query-creation-in-1password-device-trust-1899.md>)

Original publisher: [Read original article](<https://1password.com/blog/ai-assisted-query-creation-in-1password-device-trust>)

Author: info@1password.com (Evan Sandhu)

Published: 2026-06-23T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [macos](<https://devfeed.tech/tags/macos.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [sql](<https://devfeed.tech/tags/sql.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

1Password Device Trust now includes an AI-assisted query builder that converts plain-English investigations into ready-to-run SQL queries across managed devices. Admins can preview and refine generated queries, choose the devices to query, and use the tool to investigate security and compliance issues without needing advanced SQL expertise.

### Source excerpt

Today we're shipping a new capability directly into 1Password Device Trust that lets admins query their fleets faster, without needing to be SQL experts. Now you can describe what you want to investigate in plain English, and Device Trust generates a ready-to-run SQL query you can execute across your devices in a single click. What Device Trust does 1Password Device Trust gives IT and security teams visibility and control over every device accessing company resources. It continuously checks devices against your security policies, surfacing issues like outdated software, disabled firewalls, and missing encryption, and blocks access when a device falls out of compliance. Under the hood, it uses both osquery and additional proprietary information that collect real-time data directly from endpoints, giving admins a live, queryable view across their devices. That last part is where this new capability comes in. The pain with writing queries today Osquery is powerful, but writing correct, performant SQL takes specialized SQL and DB schema knowledge that most admins don't have on demand, especially during an active investigation. Even experienced users spend time getting syntax right, scoping predicates correctly, and avoiding patterns that are heavy on resources, or return noisy or slow results at scale. This capability clears that barrier while keeping the admin in control. From question to query in seconds To use this AI-assisted query builder, open it from the Device Trust Tools section, describe what you want to find, and leverage it to find real-time information across your fleet. Some examples of what you can ask: "Check all Windows devices to see if PowerShell is disabled" "Which devices have AI desktop apps like ChatGPT, Claude, or Cursor installed?" "Which macOS devices have FileVault disabled?" "Find devices running Chrome older than a specific version" "Which devices have remote-access tools like AnyDesk or TeamViewer installed?" It also works on queries you've

## Welcoming Apono to 1Password

DevFeed: [Welcoming Apono to 1Password](<https://devfeed.tech/articles/welcoming-apono-to-1password-1879.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-acquires-apono>)

Author: info@1password.com (David Faugno)

Published: 2026-06-15T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Device Trust](<https://devfeed.tech/topics/device-trust.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [identity](<https://devfeed.tech/tags/identity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [news](<https://devfeed.tech/tags/news.md>), [saas](<https://devfeed.tech/tags/saas.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password announces its acquisition of Apono to expand 1Password Unified Access with just-in-time privileged access governance. The article explains that growing numbers of machine identities and AI agents require continuously verified, consistently governed access across enterprise environments.

### Source excerpt

Over the past two decades, 1Password has earned the trust of millions of people, more than one million developers, and over 180,000 businesses by helping them secure one of the most fundamental elements of digital life: identity. Today, I'm thrilled to share that 1Password has acquired Apono, and I want to explain why this matters so much to us. Identity is changing. For years, the model was straightforward. Humans logged in, systems responded. Credentials verified who you were, and access controls determined what you could reach. That world is changing quickly. Software is now acting on our behalf. Machine identities far outnumber human identities. AI agents are beginning to retrieve data, execute workflows, provision resources, and make decisions across enterprise environments. The number of actors inside organizations is growing fast, and the systems governing identity and access were not built for this new reality. This is what we hear from customers every day. Businesses of all sizes and their security teams are struggling to get the full leverage of their AI investments while managing the risks brought about by non-deterministic agents accessing critical systems. Organizations want to move faster with AI, but they need confidence that every identity, whether it belongs to a person, a machine, or an agent, is continuously verified and governed consistently. They need to know not only who is requesting access, but what that identity should be allowed to do, under what conditions, and for how long. That challenge is exactly where Apono fits. 1Password has long been the vault that enterprises and their users relied upon to keep their secrets safe. With Apono, we become the access layer. For 1Password Unified Access, this is an important step forward. We already help organizations secure credentials, manage access to SaaS applications, strengthen device trust, and broker credentials at the moment they are needed. Apono's just-in-time privileged access governance co

## Device Trust MCP Server: Natural language queries for your entire fleet

DevFeed: [Device Trust MCP Server: Natural language queries for your entire fleet](<https://devfeed.tech/articles/device-trust-mcp-server-natural-language-queries-for-your-entire-fleet-1916.md>)

Original publisher: [Read original article](<https://1password.com/blog/device-trust-mcp-server-natural-language-queries-for-your-entire-fleet>)

Author: info@1password.com (Evan Sandhu)

Published: 2026-05-14T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [API](<https://devfeed.tech/topics/api.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-tools](<https://devfeed.tech/tags/ai-tools.md>), [api](<https://devfeed.tech/tags/api.md>), [building-1password](<https://devfeed.tech/tags/building-1password.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform](<https://devfeed.tech/tags/platform.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password announces the open-source Device Trust MCP Server, which connects Device Trust data to AI tools such as Claude and ChatGPT. Security and IT teams can query device-fleet status in natural language, with actions logged and auditable, through the MCP ecosystem and the Device Trust API.

### Source excerpt

Today we're releasing the 1Password Device Trust MCP Server, an open-source server that connects your Device Trust data directly to the AI tools your team already uses, like Claude or ChatGPT. It's available now for all customers on Device Trust Connect. As AI agents take on more of the work across your organization, IT and security teams need visibility and control that keeps pace. The Device Trust MCP Server is part of how 1Password is extending that control to the way security teams actually work today, inside AI tools, in plain language, with every action logged and auditable. Once it's running, you can query your entire device fleet without leaving your AI client. Which devices have disk encryption off? Who owns the machines failing compliance checks? How long does it typically take to resolve a specific issue across the fleet? Instead of navigating dashboards or writing custom scripts, you just prompt. What is MCP, and why does it matter? If you use AI tools like Cursor or Claude, you may have already come across the Model Context Protocol (MCP). MCP has become the standard way to connect LLMs and AI agents to data sources and tools. It's an open standard that lets AI tools connect to external data sources and take action on your behalf, with built-in controls over what those tools can access and do. It's supported by every major AI platform, and the ecosystem has grown from around 1,200 servers in early 2025 to over 6,400 today. IT and security practitioners are increasingly doing their work inside AI-powered tools, and MCP is what makes those tools useful for real administrative workflows. The Device Trust MCP Server plugs your device security data into that ecosystem. Instead of switching between tools, admins can stay in their AI client of choice and get answers in seconds. What you can do with the Device Trust MCP Once connected, you can ask questions like: "Which devices are currently failing checks?" "Who owns the devices with disk encryption disabled?"

## Go beyond device health with External Checks in 1Password Device Trust

DevFeed: [Go beyond device health with External Checks in 1Password Device Trust](<https://devfeed.tech/articles/go-beyond-device-health-with-external-checks-in-1password-device-trust-1923.md>)

Original publisher: [Read original article](<https://1password.com/blog/go-beyond-device-health-with-external-checks-in-1password-device-trust>)

Author: info@1password.com (1Password)

Published: 2026-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [external](<https://devfeed.tech/tags/external.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

1Password Device Trust now supports custom External Checks that use signals from third-party systems, such as compliance status, policy acknowledgments, MFA enrollment, and employment status, in access decisions for protected applications.

### Source excerpt

Most organizations already have the policies they need in place. The problem is enforcement. Employees must complete security awareness training, contractors must acknowledge updated agreements, and teams must meet compliance requirements. But the systems that track these requirements rarely connect to the systems that control user and device access. As a result, access is granted even when required conditions haven't been met. That's why we're excited to announce that 1Password Device Trust can now take signals from other systems into account before allowing users to reach sensitive company apps and data. External Checks in Device Trust Until now, 1Password Device Trust focused primarily on device telemetry. That meant administrators could block employees from accessing company resources if their device failed to meet certain requirements, but they couldn't enforce compliance based on signals that live outside of the device. With the ability to create custom External Checks, that changes. Access to protected apps can now depend on: User compliance status Policy acknowledgments MFA enrollment status Active employment status Many other external verification signals Access decisions are no longer limited to what's happening on the device. They reflect whether the user of the device has met required conditions across systems. How External Checks work Administrators configure an External Check by connecting Device Trust to a third-party system via API. That external system becomes a source of truth for a specific requirement, such as whether a user has completed training or acknowledged a required policy. When a user attempts to access a protected application: Device Trust evaluates device posture as it does today. Device Trust sends a request to the configured external system. The external system returns a simple result: pass or fail. Device Trust incorporates that result into the overall access decision. If the check passes, access proceeds normally. If the check fail

## Teleport's December 2024 Newsletter on Database and Production Access Controls

DevFeed: [Teleport's December 2024 Newsletter on Database and Production Access Controls](<https://devfeed.tech/articles/never-trust-an-elf-always-verify-29621.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/december-newsletter-2024/>)

Author: info@goteleport.com (Ben Arent)

Published: 2024-12-24T00:00:00Z

Content type: news

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [database](<https://devfeed.tech/tags/database.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Teleport's December 2024 newsletter uses a Santa and elves theme to discuss database access controls, cloud and database integrations, production access restrictions, device trust, hardware MFA, AWS IAM Identity Center integration, and session monitoring.

### Source excerpt

An online version of Teleport's December 2024 newsletter. Covering the latest news, events, and updates from the Teleport team.

## Device Trust for the Web: The Hard Parts

DevFeed: [Device Trust for the Web: The Hard Parts](<https://devfeed.tech/articles/device-trust-for-the-web-the-hard-parts-29626.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/device-trust-for-web-challenges-and-solutions/>)

Author: info@goteleport.com (Alan Parra)

Published: 2024-07-22T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Web](<https://devfeed.tech/topics/web.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [browser](<https://devfeed.tech/topics/browser.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [browser](<https://devfeed.tech/tags/browser.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [security](<https://devfeed.tech/tags/security.md>), [web](<https://devfeed.tech/tags/web.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

This article explains the challenges of extending Teleport device trust from its CLI client to the Web. It describes how browser isolation prevents direct access to private keys stored in secure hardware and discusses the need for a general-purpose approach that preserves device authentication without requiring Chrome Enterprise.

### Source excerpt

Explore the challenges and solutions in implementing device trust for web applications, including delegated authentication and security measures against attacks.

## Teleport's 2023 product retrospective highlights Device Trust, automatic agent updates, agentless access, and Teleport Team

DevFeed: [Teleport's 2023 product retrospective highlights Device Trust, automatic agent updates, agentless access, and Teleport Team](<https://devfeed.tech/articles/is-santa-an-insider-threat-29622.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/december-newsletter/>)

Author: ben@goteleport.com (Ben Arent)

Published: 2023-12-14T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Amazon EKS](<https://devfeed.tech/topics/amazon-eks.md>), [trust](<https://devfeed.tech/topics/trust.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [ec2](<https://devfeed.tech/tags/ec2.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [releases](<https://devfeed.tech/tags/releases.md>), [retrospective](<https://devfeed.tech/tags/retrospective.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Teleport's 2023 retrospective reviews releases and product highlights, including Device Trust, Windows host support, automatic agent updates, TLS routing, identity and security features, agentless access, and the Teleport Team SaaS offering.

### Source excerpt

A quick retrospective and focus on a few highlights for 2023.

## Enforcing device trust on code changes

DevFeed: [Enforcing device trust on code changes](<https://devfeed.tech/articles/enforcing-device-trust-on-code-changes-9810.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/how-we-enforce-device-trust-on-code-changes/>)

Author: Griffin Choe

Published: 2023-12-08T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Figma](<https://devfeed.tech/topics/figma.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [WebAuthn](<https://devfeed.tech/topics/webauthn.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [figma](<https://devfeed.tech/tags/figma.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [okta](<https://devfeed.tech/tags/okta.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

Figma's security engineering team describes enforcing device trust for code changes merged into GitHub release branches. The approach combines commit signature verification with Okta Device Trust certificates to ensure changes originate from trusted, company-managed devices, while addressing risks from leaked credentials, tokens, and SSH keys.

### Source excerpt

Here's how the Figma security engineering team leveraged commit signatures and Okta Device Trust certificates to protect GitHub release branches.

## Login with Teleport. Teleport as a SAML Identity Provider

DevFeed: [Login with Teleport. Teleport as a SAML Identity Provider](<https://devfeed.tech/articles/login-with-teleport-teleport-as-a-saml-identity-provider-29756.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/login-with-teleport/>)

Author: ben@goteleport.com (Ben Arent)

Published: 2023-04-19T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [XML](<https://devfeed.tech/topics/xml.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Device Trust](<https://devfeed.tech/topics/device-trust.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [identity](<https://devfeed.tech/tags/identity.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Teleport 12.1 enables Teleport Enterprise teams to use Teleport as a SAML SSO identity provider for authenticating to supported external SaaS apps and internal applications.

### Source excerpt

Starting with Teleport 12.1, Teleport Enterprise teams can now use Teleport as a SAML SSO identity provider.

## Going Beyond Network Perimeter Security by Adopting Device Trust

DevFeed: [Going Beyond Network Perimeter Security by Adopting Device Trust](<https://devfeed.tech/articles/going-beyond-network-perimeter-security-by-adopting-device-trust-29594.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/beyond-network-perimeter/>)

Author: alan.parra@goteleport.com (Alan Parra)

Published: 2023-03-23T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Security](<https://devfeed.tech/topics/security.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [security](<https://devfeed.tech/tags/security.md>), [vpn](<https://devfeed.tech/tags/vpn.md>)

### AI overview

This post examines weaknesses in network perimeter security, including VPN and firewall exposure, lateral movement after a breach, and the difficulty of maintaining rules across global hybrid infrastructure. It proposes device trust, supported by device inventory, enrollment, and device-aware authentication, as an alternative.

### Source excerpt

This post explores weaknesses of perimeter security and proposes device trust as an alternative, covering device inventory, enrollment, and device-aware auth.

## Teleport 12

DevFeed: [Teleport 12](<https://devfeed.tech/articles/teleport-12-29891.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-12/>)

Author: kenneth.dumez@goteleport.com (Kenneth DuMez)

Published: 2023-03-03T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [preview](<https://devfeed.tech/tags/preview.md>), [release](<https://devfeed.tech/tags/release.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Teleport 12 introduces Device Trust in preview, allowing administrators to require access from authenticated and trusted devices and integrate device authorization with Teleport RBAC. The release also previews passwordless certificate-based access for local Windows users without Active Directory and adds per-pod RBAC for Kubernetes access.

### Source excerpt

An overview of all of the new features added to Teleport 12. Device Trust, Passwordless Windows Access for Local Users and more.