v26.09
Our biggest release yet,yet. bringingMonths togetherof capabilities we’ve been working onwork behind the scenesscenes, fornow months.ready. WeThis wantedrelease gives you more control over who gets network access, fewer connection settings to getmaintain, themand right. Now they’re ready.Introducing never-before-seen capability: just-in-time, user-attributed trust assessmentsupport for the specificidentity destination being requested, before network access opens. Alongside it, Integrations lets you configure firewall, proxy and cloud connections once, reuse them acrossproviders your Knocs,organization andactually manage credentials in one place.
has.
What's new
Integrations:Trustconfigure once, reuse across Knocs.Engine.Share firewall, proxy and cloud connections, rotate credentials in one place, and trace access problems back to the integration involved. Less copying and pasting. Fewer opportunities to update nine out of ten configurations.
TherePlus area alsoround improvementsof toadmin setup,quality-of-life activity reporting and troubleshooting, plusimprovements, security fixes and dependency updates.
Introducing
Trust Intergrations
Engine
ConfigureA valid login is a firewallgood connectionstart. once.A Usevalid login arriving through a residential proxy deserves a few follow-up questions. The Trust Engine decides what happens next, per user and per destination, before network access opens.
attention. Respond to connections from outside your approved countries or networks, over residential proxies, commercial VPNs or Tor, or from addresses reported malicious by GreyNoise or your own blocked-address lists. Observe, challenge or block. Observe records and lets access continue. Challenge asks for another sign-in, a click, or a shorter access window. Block refuses. The strictest matching response wins. See why. The new Activity view shows who connected, from where, which Knoc and policy applied, and what happened. History keeps the rules that applied at the time, so a later edit does not rewrite yesterday's explanation. Admins can override a refused grant with an audited reason.
Integrations
Until now, each Knoc carried its own copy of the connection details for the system behind it. If tenTen Knocs usedon theone same firewall, thatfirewall meant ten places holding its settings.copies. Integrations bringshold those connections together so multiple Knocs can share the samethat connection details.Your next password rotation should involve considerably less copying, pasting and quiet swearing.
once.
- One connection, many Knocs. Reuse an
existingintegration,integrationits agent and credentials, when creating aKnoc, including its agent and credentials.Knoc. Each Knoc still defines the access it provides. - See
your integrationsthem in one place. Browse the firewalls, cloud services and reverse proxies your Knocsuse, including firewalls running directly on your servers.use. Search, filter andgroup them to find what you need.group. - Activity per integration.
See whichWhich Knocs useanit,integration,whowho'shas beenaccessing them,connecting, grant volumes,averagewait times and failures. Follow a problem from an access path back to the system enforcing it. - A clearer setup experience. The rebuilt Knoc wizard offers existing
integrations as you go,integrations, helps configure new ones, andshowsdiagramsofhow the server, agent andprotectedresource fit together.Handy when the person who knows how it all fits together is on leave.Connection checkshelpcatch setup problemsbefore you finish.early. BringFindexisting configurations together.duplicates.TheFind duplicatestool asksAsk your agents to identify matching connections, thenlets youmerge them into shared integrations whileretainingkeeping their Knoc assignments.It also identifies agents that need updating before they can compare configurations.
Introducing the Trust Engine
A valid login is a good start. A valid login arriving through a residential proxy may deserve a few follow-up questions. The Trust Engine gives you control over what happens next, before network access opens.These decisions are tied to the user and the destination they’re requesting. The same connection can warrant different controls for an everyday application and a sensitive admin service.Create a named policy, choose the conditions that matter, and attach it to the Knocs it should govern. Start with the supplied Passive, Standard and Strict policies, or create your own. Policies are reusable, so you can apply the same rules across several access paths and manage them together.
Decide what deserves attention
Policies can respond to connections from:
Observe Challenge or Block
Each condition has its own response:
Observe is a good place to start if you'd prefer to discover a policy's impact somewhere other than the help-desk queue.If several conditions match, the strictest response applies. You can also leave individual checks off.For example, you could observe commercial VPN use on an everyday application, require another sign-in and a 15-minute access window for a sensitive admin service, and block known malicious addresses on both. We think that's pretty magical, and we think you will too.
See why a decision was made
The new Activity view shows who connected, from where, which Knoc and policy were involved, and what happened. Open a finding to see the checks behind it. The same information is available in session details and relevant blocked-grant records.History keeps the policy details that applied at the time, so changing a rule later doesn't rewrite yesterday's explanation. Useful when "nothing changed" turns out to mean "nothing changed that I remember". Challenges show whether the user has verified, and administrators can override a refused grant with a required, audited reason.Users get clearer feedback too: a verification prompt when they need to act, a connection-checking state while a required lookup finishes, and a visible access limit when a policy shortens their grant.
Control how you roll it
Choose a default policy for new Knocs and assign policies to existing ones as needed. When saving policy changes, review their impact and choose whether to end affected sessions so users sign in under the new rules. Existing access otherwise continues until it ends.Country restrictions are available on the free plan; other restrictions require a paid plan, with provider-backed checks needing the relevant intelligence source. External blocked-address feeds are available as an add-on.
One more thing. More than one
Multiple identity provider
providers
You can now offerOffer several user SAML identity providers on the sameone Knocknoc deployment. Useful for partner access, multiple organisations,organizations, or thatan acquisition whichthat left you with two directories and a very optimistic migration timeline.
directories.
- Each provider gets its own named sign-in button and SAML configuration.
- Accounts
remainstay distinct between providers, even when usernames match. SAML and dynamic groups can be scoped to selected providers. - Existing groups
remainstay scoped to the original provider on upgrade.
Additional user identity providers require an Enterprise licence.license. You can configure up to five alongside the original provider. Read the Authentication guide
Other
Admin Improvements
quality-of-life
We've
an auto-focused search box, exact timestamps on hover, and live "last seen" ages.
Faster Knoc setup. Category suggestions, source restrictions that accept network ranges (CIDR), and Fortinet vsys autofill. Clearer troubleshooting. Grant and revoke errors name the Knoc, ACL and address involved, the Support view has copy buttons, and Knocknoc warns when GELF log forwarding is set up without encryption.How do I upgrade?
UpgradeUpdate the Knocknoc Server and orchestration Agents throughusing yourthe operatingusual system'soperating-system package manageror asinstaller usual.process. See the updates and upgrades guide.
After upgrading, visit Integrations > Find duplicates to consolidate repeated connections. Update the relevant agents first so they can compare their configurations.
Existing Knocs keep their legacy access controls until you assign a trust policy. Assigning a policy replaces those per-Knoc source restrictions and GreyNoise settings for instructions.
access decisions; selecting Legacy restores them.
ReleaseAs date:always, 29thyou Septemberchoose 2026when your Server and Agents update.