# Announcing 1Password®

## Extended Access Management

Kolide Device Trust is now part of 1Password® Extended Access Management. Check out the blog post by former Kolide CEO Jason Meller to learn about the next evolution in user-first security.

[Read the Announcement](https://www.kolide.com/blog/introducing-1password-extended-access-management-with-kolide)

## Self-Remediation via Okta
Engage end-users during auth to self-remediate issues

## Security & Compliance Checks
Monitor your entire Linux, Mac, and Windows fleet

## Device Inventory
Your fleet represented in thousands of data points

## Implement Zero Trust Access
Prevent unsecure devices from accessing your apps

## Achieve 100% Device Compliance
Measure, achieve, and maintain your compliance goals

## Gain Fleet Visibility
Become "all knowing" across Linux, Mac, and Windows

## What Are Unattended Upgrades?

The Unattended Upgrades feature of Ubuntu (and other Debian-based distros) ensures that important security patches for installed packages are automatically downloaded and installed without needing any manual intervention from an end-user (hence the word unattended).

A common misconception about this feature is that when enabled, it will cause your device to regularly automatically restart. This is not true unless you specifically opt-in to that behavior by going through the following steps:

1. Opening the `/etc/apt/apt.conf.d/50unattended-upgrades` config file
2. Explicitly setting `Unattended-Upgrade::Automatic-Reboot "true"`
3. Installing the optional `update-notifier-common` package.

For more information, please read [Ubuntu’s Documentation](https://help.ubuntu.com/community/AutomaticSecurityUpdates).

## Do I Really Need Unattended Upgrades?

Like most things on Linux, there are strong debates for and against enabling Ubuntu’s unattended upgrades package.

The primary argument against a solution like `unattended-upgrades` is that by automatically upgrading packages on a Linux device, one day, [a less stable package may install and cause stability or user-experience issues](https://engineering.backmarket.com/when-unattended-upgrades-were-really-unattended-8e9cb28bbee). While this argument is technically valid, the fact remains that without this package installed and enabled, it’s far more likely that a Linux device will host software with severe and remotely exploitable security vulnerabilities. This is especially true for end-user devices running Linux.

Further bolstering the argument for turning it on, Canonical (the creators of Ubuntu) has opted to pre-install the `unattended-upgrades` package and enable it across the Ubuntu operating system. We highly recommend users keep this setting on.

## How To Enable Unattended Upgrades

### From the User Interface (Gnome Desktop)

By default, Ubuntu Desktop installations include an app called **Software & Updates** (internally referred to as `update-manager`). This program is capable of modifying the requisite files on your device to ensure Unattended Upgrades are correctly enabled.

To use it, simply follow these steps.
1. Launch the Software & Updates app (you can also run `update-manager` from the terminal).
2. Once opened, select the **Updates** tab.
    
3. Ensure the **When there are security updates** option is set to **Download and install automatically**. Complete any authentication prompts if they are displayed.
4. Click **Close**.

### From the Terminal

1. Verify the package is installed with `sudo apt-get install unattended-upgrades -y`
2. Run `sudo dpkg-reconfigure -plow unattended-upgrades` which will then display the following interactive prompt:
    
3. Select **yes**. Once completed, the app will create the file `/etc/apt/apt.conf.d/20auto-upgrades` with the correct settings. There may be an existing/conflicting installation screen that looks like the screenshot below. If you see that screen, simply replace the file with the new version to get the default behavior.

## How To Determine If Unattended Upgrades Is Enabled with Osquery

Osquery (an open-source tool for querying the state of the OS) is capable of reading the contents of specific configuration files like `/etc/apt/apt.conf.d/20auto-upgrades` using an integration with the Augeas configuration parsing project.

Osquery uses SQL to query the system’s current state. Assuming you have [the correct lens installed](https://github.com/kolide/launcher/blob/669854121a1f2ac00d8506f74710b939a6066e8f/pkg/augeas/assets/lenses/aptconf.aug), you can use Osquery SQL you can use the following query to get the determine if Unattended upgrades is configured correctly.

```
SELECT
  MAX(CASE WHEN label='Update-Package-Lists' THEN value END) as update_package_list,
  MAX(CASE WHEN label='Unattended-Upgrade' THEN value END) as unattended_upgrade,
FROM augeas
WHERE path = '/etc/apt/apt.conf.d/20auto-upgrades'
```

## How Does Kolide Remediate This Problem?

This problem cannot be remediated through traditional automation with tools like an MDM. You need to be able to stop devices that fail this check from authenticating to your SaaS apps and then give end-users precise instructions on how to unblock their device.

Kolide's Okta Integration does exactly that. Once integrated in your sign-in flow, Kolide will automatically associate devices with your users' Okta identities. From there, it can block any device that exhibits this problem and then provide the user, step-by-step instructions on how to fix it. Once fixed, Kolide immediately unblocks their device.
