Unattended mode is a configuration in which Tailscale can run without an interactive user session on the machine. The article notes that this setting is stored in local state alongside the machine key, so if that state is removed, the device may lose both its trust record and operational configuration.
What Unattended Mode Is
Unattended mode is a configuration state that lets Tailscale run without an interactive user session on the machine. It is designed for devices that need persistent connectivity even when no one is logged in, which changes how the device’s local trust and runtime state must be managed.
How Unattended Mode Changes Device Behaviour
Compared with a user-tied session, unattended mode shifts Tailscale from a foreground, user-present workflow to a machine-resident one. That matters because the process can start earlier, persist longer, and continue operating after logoff, sleep, or reboot depending on the platform and deployment design.
The practical effect is that the machine is no longer dependent on an active desktop session to maintain network presence. For remote access, automation, or infrastructure use cases, that can be exactly what is needed, but it also means the device state becomes part of the operational security boundary rather than just the user session.
Local State, Trust Record, and Persistence
The key detail in unattended mode is that the configuration is stored in local state alongside the machine key. That makes the local state directory more than a cache: it becomes the place where the device’s trust relationship and operating configuration are preserved.
If that state is removed, the device may lose both its trust record and its operational configuration. In other words, deleting or resetting local state can behave like a partial deprovisioning event, even when the underlying machine still exists. For administrators, that means backup, restore, migration, and disk cleanup procedures can directly affect whether the device remains recognized and functional.
Where Unattended Mode Fits in Operations
Unattended mode is most useful when a machine must remain reachable or managed without a logged-in user, such as a headless server, lab host, or remote system. It is a convenience feature, but it also defines a dependency on durable local state and stable machine identity, so the configuration should be treated as part of the host’s lifecycle rather than a temporary session setting.
Because the mode depends on persisted state, changes to disk images, automation scripts, reimaging workflows, and endpoint hygiene practices can have outsized effects. The term is therefore best understood as a deployment posture, not just a switch.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Unattended mode depends on persisted machine credentials and local trust state. |
| AC-2 — Account Management | The mode changes how a device account is maintained across reboots and logoff. | |
| CM-6 — Configuration Settings | Local state stores the operational configuration that keeps the mode active. | |
| Recommendation — Protect and rotate machine credentials that keep unattended devices authenticated. Track unattended devices as managed accounts with clear lifecycle ownership. Standardize and protect the configuration state that enables unattended operation. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication and Access Control | The term centers on maintaining device trust and access without an interactive session. |
| PR.DS-01 — Data-at-rest is protected | Local state and machine keys are stored persistently on disk in this mode. | |
| Recommendation — Apply access control and identity management to non-interactive device connectivity. Protect stored machine state and credentials at rest on the host. | ||