Trusted-device enrollment now happens when needed rather than only at startup, and records why it ran.
tengu_violin_wood Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.239: on
Read once, for one account on one subscription tier, against v2.1.239. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
Device enrollment records why it ran (proactive, device_bind, or after a server refusal) and whether the organisation required it. For consumer subscribers, and after a server refusal, it will enroll when the org merely allows the policy rather than enforcing it. A new path enrolls on demand just before binding a device session.
- Gated on
tengu_violin_wood, which falls back to off, plus related gates and organisation policy. - The existing opt-out environment variable is still honoured.
[trusted-device] Not enrolled, enrolling for a device-bound session
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.248
Device attestation statuses collapse to three values
Both mention device trust
-
v2.1.246
Machine list says which machine your project is on
Both mention device
-
v2.1.246
Rewritten guidance for machines attached to a session, including upload-only sync
Both mention device