Skip to content

[v18] Enforce device trust check post-MFA and log as AppSessionStart#63149

Merged
21KennethTran merged 1 commit intobranch/v18from
kennethtran/v18-devicetrust
Jan 30, 2026
Merged

[v18] Enforce device trust check post-MFA and log as AppSessionStart#63149
21KennethTran merged 1 commit intobranch/v18from
kennethtran/v18-devicetrust

Conversation

@21KennethTran
Copy link
Contributor

@21KennethTran 21KennethTran commented Jan 26, 2026

Rejects app session requests for untrusted devices after MFA and generates an AppSessionStart failure event in audit logs.

Backports #62019

changelog: Ensure application session rejections for untrusted devices are consistently audited as AppSessionStart failures after MFA

@github-actions
Copy link

github-actions bot commented Jan 26, 2026

Amplify deployment status

Branch Commit Job ID Status Preview Updated (UTC)
kennethtran/v18-devicetrust 18772f8 6 ✅SUCCEED kennethtran-v18-devicetrust 2026-01-30 20:26:41

@codingllama
Copy link
Contributor

It looks like v18 is missing a backport for #62523 (we don't necessarily backport changes like that unless there is a reason for it, which we now have).

My preference would be to backport it separately, then base this one on top of that.

I was also going to ask, which I would anyway, that you test the changes manually before merging (both binary and Web UI). It's important to do that for all backports, so we don't inadvertently break an actual numbered release.

@codingllama
Copy link
Contributor

@codingllama
Copy link
Contributor

@21KennethTran, the backport has landed. You can rebase this now.

@21KennethTran
Copy link
Contributor Author

21KennethTran commented Jan 27, 2026

@codingllama, Thank you for getting that backport out. I tested out the changes manually with success as well.

@21KennethTran 21KennethTran force-pushed the kennethtran/v18-devicetrust branch from 9147ce0 to 18772f8 Compare January 30, 2026 20:21
@21KennethTran 21KennethTran added this pull request to the merge queue Jan 30, 2026
Merged via the queue into branch/v18 with commit 5e8e075 Jan 30, 2026
44 checks passed
@21KennethTran 21KennethTran deleted the kennethtran/v18-devicetrust branch January 30, 2026 21:15
@aadc-dev aadc-dev mentioned this pull request Feb 2, 2026
21KennethTran added a commit that referenced this pull request Feb 5, 2026
21KennethTran added a commit that referenced this pull request Feb 5, 2026
21KennethTran added a commit that referenced this pull request Feb 5, 2026
github-merge-queue bot pushed a commit that referenced this pull request Feb 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

audit-log Issues related to Teleports Audit Log backport documentation size/md ui

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Comments