In late June 2026, Anthropic added a new security option to Claude, its AI assistant. It’s called “Trusted Devices,” and it targets one specific function: remote control of Claude Code sessions, the company’s own coding tool. The idea comes down to one sentence. Before picking up a session on a phone, in a browser, or on another machine, the user has to prove they’re on a device that’s already recognized and that they authenticated recently.
That might sound like something only development teams need to worry about. But the logic behind this update applies to any business that lets employees log into sensitive tools from outside the office. Tying access to a known device, rather than just an account that’s open somewhere, is exactly the habit we recommend to small and medium businesses in Quebec. Here’s what Claude just introduced, and what you can take away from it for your own IT fleet.
Quick answer: Anthropic added “Trusted Devices” to Claude Code. To control a session remotely, you now need an enrolled device and a login less than 18 hours old, confirmed by Face ID, Touch ID, Windows Hello, or a passkey. The underlying principle (tying access to a known device, not just an account) is a solid security practice any SMB can apply.
1. What Claude just added
To understand what’s new here, it helps to know what remote control in Claude Code actually is. According to Anthropic’s official documentation, this feature lets you start a work session on your computer, then pick it up from a phone, tablet, or browser on another machine. The session keeps running locally, on your own machine. The phone or browser is just a window into that session.
That’s convenient, but it raises an obvious security question: who can open that window? Until now, being logged into the right account was enough. “Trusted Devices” adds a second barrier. Once an administrator turns the option on, a team member can only view or control a remote session if two conditions are met:
- Their device (each browser, phone, or desktop app counts separately) has to be enrolled, meaning registered as a known device during an actual login.
- Their last login has to be less than 18 hours old. Past that window, they confirm their presence with Face ID, Touch ID, Windows Hello, or a passkey.
In other words, a stolen username and password are no longer enough to take over a remote session. You also need physical possession of an already-recognized device, and a recent biometric check. The feature is currently in beta and available on Team and Enterprise plans, off by default until an administrator switches it on.

2. How it actually works
The process is deliberately unobtrusive for the user. The first time an employee wants to control a remote session from a new device, they’re asked to enroll it. Enrollment is only offered right after a full login, so a device never quietly joins the trusted list in the background without the person noticing.
Day to day, if the device is enrolled and the login is recent, the employee sees nothing extra. Once their login passes the 18-hour mark, they get a single biometric confirmation prompt. Anthropic makes an important point about privacy here: the verification happens on the device itself, handled by the operating system or browser. The company never receives or stores any fingerprint or facial data. Only the device’s public key and a few basic details (name, platform, enrollment date) are kept.
Management stays in the hands of the user and the administrator. Each team member can view their list of enrolled devices and revoke one in a couple of clicks, say if they lose their phone. On the admin side, a “log out everywhere” command instantly cuts off every session and device tied to a given member. An unused device also eventually falls off the list on its own, since its credentials expire if they’re never renewed.
3. Why this Claude update matters to an SMB
You might not use Claude Code in your business at all. The principle behind it, though, applies to nearly every tool you run. The big weakness in a lot of remote access setups is that they rely on nothing more than an open account: as long as someone knows the password, they’re in. That’s exactly what phishing and credential theft exploit, two of the most common doors into an SMB’s data.
What Claude has put in place here is the idea that access should be tied to a known device and a recent authentication, not just an account. It’s the same logic behind the practices we roll out for our clients: two-factor authentication, passkeys, device compliance checks before a connection is allowed, and the ability to cut off a lost device’s access instantly. If you want to build this kind of protection around your own tools, that’s the core of our work in managed IT services.
Remote work makes the point even clearer. The moment an employee logs into your systems from home, a coffee shop, or a personal phone, the account alone tells you very little about whether that login is legitimate. The device tells you a lot more. A company as large as Anthropic is putting this protection on its most sensitive feature. That’s a good signal for you too.

4. What you can apply right now
You don’t need a specific tool to adopt this approach. Here are a few concrete steps, in the spirit of “Trusted Devices,” that most SMBs can put in place:
- Turn on two-factor authentication for your critical accounts, starting with Microsoft 365 and your remote access tools.
- Move to passkeys or biometrics where the tool allows it, instead of relying on a password alone.
- Restrict sensitive logins to managed, compliant devices (up-to-date system, encryption on, antivirus in place).
- Keep your list of authorized devices current, and revoke a lost, stolen, or departed employee’s device right away.
- Set a reasonable session length, so a forgotten login doesn’t stay valid indefinitely.
None of these steps require an overhaul of your IT setup. Most rely on tools you already own, especially within the Microsoft 365 ecosystem. If you’re not sure where to start or how to check what’s already in place, a quick look from our team is often enough to spot the weak points. You can reach us through our contact page to talk it over.
Frequently Asked Questions
What is Claude Code’s remote control feature?
It’s a feature that lets you start a Claude coding session on your computer, then pick it up from a phone, tablet, or browser on another machine. The session keeps running locally, on the original machine. The remote device just serves as a window to follow and control it.
Is “Trusted Devices” available to everyone?
No. According to Anthropic, the feature is in beta and limited to Team and Enterprise plans. It’s off by default, and an organization administrator has to turn it on. It only affects remote control: regular chat with Claude, terminal usage, and API calls are not affected.
Can Anthropic see my biometric data?
No, according to the documentation. Verification (Face ID, Touch ID, Windows Hello, or a passkey) happens directly on the device, handled by the operating system or browser. Anthropic only stores the device’s public key and basic details like name, platform, and enrollment date. No fingerprint or facial image is ever transmitted.
Protecting your access, without the headache
The takeaway here is simple: strong access doesn’t rely on a password alone, it also depends on a known device and a recent verification. That’s exactly the kind of protection we put in place for SMBs in Trois-Rivieres, the Mauricie region, and across Quebec. To take a look at your remote access and security setup, check out our IT services for SMBs or reach out through our contact page. We’ll review your situation and lay out clear next steps.