Skip to main content

v26.09

Our biggest release yet, bringing together capabilities we’ve been working on behind the scenes for months. We wanted to get them right. Now they’re ready.

Introducing never-before-seen capability: just-in-time, user-attributed trust assessment for the specific destination being requested, before network access opens. Alongside it, Integrations lets you configure firewall, proxy and cloud connections once, reuse them across your Knocs, and manage credentials in one place.

What's new

  • Integrations: configure once, reuse across Knocs. Share firewall, proxy and cloud connections, rotate credentials in one place, and trace access problems back to the integration involved. Less copying and pasting. Fewer opportunities to update nine out of ten configurations.
  • Trust Engine: a successful login still gets a connection check. Just-in-time, user-attributed trust assessment for the destination being requested before network access opens. Detect residential proxies, commercial VPNs, Tor exit nodes and known malicious IPs, then observe, challenge or block according to your policies. If someone signs in with stolen credentials from a connection your policy blocks, that successful login won’t open network access.
  • Multiple identity providers: bring your organizations together. Offer several SAML providers on one Knocknoc deployment, with distinct accounts and provider-scoped groups. Your directory migration can proceed at its own, apparently geological, pace.

There are also improvements to setup, activity reporting and troubleshooting, plus security fixes and dependency updates.

Introducing Intergrations

Configure a firewall connection once. Use it across your Knocs. Rotate its credentials in one place. 

Until now, each Knoc carried its own copy of the connection details for the system behind it. If ten Knocs used the same firewall, that meant ten places holding its settings. Integrations brings those connections together so multiple Knocs can share the same connection details.

Your next password rotation should involve considerably less copying, pasting and quiet swearing.

  • One connection, many Knocs. Reuse an existing integration when creating a Knoc, including its agent and credentials. Each Knoc still defines the access it provides.
  • See your integrations in one place. Browse the firewalls, cloud services and reverse proxies your Knocs use, including firewalls running directly on your servers. Search, filter and group them to find what you need.
  • Activity per integration. See which Knocs use an integration, who's been accessing them, grant volumes, average wait times and failures. Follow a problem from an access path back to the system enforcing it.
  • A clearer setup experience. The rebuilt Knoc wizard offers existing integrations as you go, helps configure new ones, and shows diagrams of how the server, agent and protected resource fit together. Handy when the person who knows how it all fits together is on leave. Connection checks help catch setup problems before you finish.
  • Bring existing configurations together. The Find duplicates tool asks your agents to identify matching connections, then lets you merge them into shared integrations while retaining their Knoc assignments. It also identifies agents that need updating before they can compare configurations.

Introducing the Trust Engine

A valid login is a good start. A valid login arriving through a residential proxy may deserve a few follow-up questions. The Trust Engine gives you control over what happens next, before network access opens.

These decisions are tied to the user and the destination they’re requesting. The same connection can warrant different controls for an everyday application and a sensitive admin service.

Create a named policy, choose the conditions that matter, and attach it to the Knocs it should govern. Start with the supplied Passive, Standard and Strict policies, or create your own. Policies are reusable, so you can apply the same rules across several access paths and manage them together.

Decide what deserves attention

Policies can respond to connections from: 

  • Outside your approved countries or continents.
  • Outside your known IPv4 or IPv6 networks, such as office ranges or your corporate VPN.
  • Residential proxy networks, recognised commercial VPN providers or Tor exit nodes.
  • Addresses reported as malicious by GreyNoise, or found on your configured blocked-address lists.

Location checks can use the IP database bundled with Knocknoc. IPinfo supplies anonymising-network intelligence, while GreyNoise supplies threat intelligence. The Sources page brings provider setup, key validation and service status together. You can use your own provider keys, or keys supplied through your Knocknoc licence where included.

Observe Challenge or Block

Each condition has its own response:

  • Observe: let access continue and record what the policy found. Useful when introducing a control and understanding its impact before enforcing it.
  • Challenge: request another sign-in, require a click for access, shorten the access window, or combine those controls.
  • Block: refuse access and record the reason.

Observe is a good place to start if you'd prefer to discover a policy's impact somewhere other than the help-desk queue.
If several conditions match, the strictest response applies. You can also leave individual checks off.
For example, you could observe commercial VPN use on an everyday application, require another sign-in and a 15-minute access window for a sensitive admin service, and block known malicious addresses on both. We think that's pretty magical, and we think you will too.

See why a decision was made

The new Activity view shows who connected, from where, which Knoc and policy were involved, and what happened. Open a finding to see the checks behind it. The same information is available in session details and relevant blocked-grant records.

History keeps the policy details that applied at the time, so changing a rule later doesn't rewrite yesterday's explanation. Useful when "nothing changed" turns out to mean "nothing changed that I remember". Challenges show whether the user has verified, and administrators can override a refused grant with a required, audited reason.

Users get clearer feedback too: a verification prompt when they need to act, a connection-checking state while a required lookup finishes, and a visible access limit when a policy shortens their grant.

Control how you roll it

Choose a default policy for new Knocs and assign policies to existing ones as needed. When saving policy changes, review their impact and choose whether to end affected sessions so users sign in under the new rules. Existing access otherwise continues until it ends.

Country restrictions are available on the free plan; other restrictions require a paid plan, with provider-backed checks needing the relevant intelligence source. External blocked-address feeds are available as an add-on.

One more thing. More than one identity provider

You can now offer several user SAML identity providers on the same Knocknoc deployment. Useful for partner access, multiple organisations, or that acquisition which left you with two directories and a very optimistic migration timeline.

  • Each provider gets its own named sign-in button and SAML configuration.
  • Accounts remain distinct between providers, even when usernames match. SAML and dynamic groups can be scoped to selected providers.
  • Existing groups remain scoped to the original provider on upgrade.

Additional user identity providers require an Enterprise licence. You can configure up to five alongside the original provider.

Other Improvements

We've also improved integration reliability, made troubleshooting clearer and polished the admin experience. This release includes security fixes and dependency updates too.

How do I upgrade?

Upgrade the Knocknoc Server and Agents through your operating system's package manager as usual. See the updates and upgrades guide for instructions.

Release date: 29th September 2026