Guide · Claude Code

Claude Trusted Devices: How Enrollment Works, How to Check the List, and How to Unblock Remote Control

Last updated: AI-generated

A device enrolls on first access to a Remote Control session, right after a full sign-in. Once that sign-in is more than 18 hours old, Face ID, Touch ID, Windows Hello, or a passkey comes first.

Short version: Trusted Devices is a setting for Team and Enterprise organizations. When it’s on, a browser, phone, or desktop app can only view or steer a Claude Code Remote Control session once the device is enrolled and the sign-in is no more than 18 hours old. A device enrolls on first use after a fresh sign-in. In the terminal it happens automatically with /login.

What Trusted Devices is, and what it isn’t

In the admin console the setting is called Require trusted devices and sits under Remote Control. It ties remote access to a running Claude Code session to two things:

RequirementWhat it means
An enrolled deviceEvery browser, phone, and desktop app gets its own credential. Enrollment is only offered shortly after a full sign-in, never silently in the background.
A recent sign-inThe sign-in must be no more than 18 hours old. After that you confirm presence with Face ID, Touch ID, Windows Hello, or a passkey instead of signing in again.

It applies only to Remote Control, meaning steering a local session from claude.ai, the Claude mobile app, or Claude Desktop. Regular Claude chat, Claude Code in the terminal, and the API are unaffected.

The feature is labeled beta, available on Team and Enterprise only, and off by default. An Owner has to turn it on. It does not exist for Pro and Max accounts.

On biometrics: Face ID and friends run on your device through the operating system or browser, the same way a passkey sign-in works. Anthropic never receives fingerprints or face data. What gets stored is the device’s public key, a display name, the platform, and the enrollment time.

Enrolling a device

A device joins the list the first time you use it for Remote Control:

  1. Sign in to Claude on that device (through SSO if your organization uses it).
  2. Open or steer a Remote Control session, for example on claude.ai/code or in the Claude app.
  3. Claude asks whether to enroll this device. Confirm with Face ID, Touch ID, Windows Hello, or a passkey.

If your sign-in is older than 18 hours, Claude asks you to sign in again first and offers enrollment right after. On a machine without Face ID, Touch ID, or Windows Hello you can use a hardware security key, or simply sign in again instead of stepping up.

In the terminal there is nothing extra to do. The machine running Claude Code gets its credential automatically when you sign in to the CLI:

/login

There is no separate enrollment command.

A new device showed up on the list

The list lives at claude.ai/settings/account under Trusted devices: every enrolled device with its name, platform, and enrollment date.

A new entry always belongs to a full sign-in, because enrollment is offered only shortly after one and never silently in the background. A browser you just set up, a new phone, a new machine: that is what the entry is.

If you don’t recognize the device, remove it. The credential is revoked immediately, and the device can only get back on the list if someone signs in on it again.

Error messages and what to do

MessageCauseFix
Your organization requires Trusted Devices for Remote Control, but this device is not enrolledTrusted Devices is on and this machine hasn’t enrolled yetRun /login in Claude Code; enrollment is part of sign-in
session expired for trusted-device checkSign-in older than 18 hoursRun /login in Claude Code, or confirm with Face ID, Touch ID, Windows Hello, or a passkey when claude.ai or the app prompts you
Remote Control session won’t open on your phone, no error in the terminalThe phone isn’t enrolledSign in on the phone, open the session, confirm enrollment

Managing and removing devices

  • Your own devices: claude.ai/settings/account, section Trusted devices. Removing one revokes its credential immediately. Unused credentials expire on their own, so an old device eventually drops off the list by itself.
  • Lost or stolen device: remove it there. If you can no longer sign in, an admin can trigger Sign out everywhere in the admin console. That revokes every session and every enrolled device; you re-enroll the devices you still have.

For admins: turning it on

  1. Open claude.ai/admin-settings/claude-code. The Require trusted devices toggle sits under the Remote Control setting. Remote Control itself is also off by default on Team and Enterprise.
  2. Turn it on. The setting applies to every member and to Remote Control sessions started afterwards. Sessions already running stay unprotected until they end. There is no per-team or per-project scoping.
  3. Warn members ahead of time. The first access from each device triggers the enrollment prompt; people who don’t expect it easily mistake it for phishing.

Limits

  • Trusted Devices protects Remote Control, not the account. A passkey sign-in for the Claude account itself is a different thing and not part of this feature.
  • The setting is organization-wide. Individual users or projects can’t be exempted.
  • Beta: behavior and UI may change. This guide is rechecked against the docs on the next run.

Changes

  • 2026-09-15: Checked sentence by sentence against the docs and published. Three claims that rested only on issues in the Claude Code repository are gone: the ‘Security alert: new trusted device added’ email, the same machine enrolling over and over, and the limit of one FIDO2 authenticator per account. None of them is in the docs. The email section is now a section about the device list.
  • 2026-09-11: First version, checked against the docs as of September 11, 2026.

Sources